<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>From the Mind of Marc... &#187; Malware</title>
	<atom:link href="http://mdpblog.mdpsystems.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://mdpblog.mdpsystems.com</link>
	<description>Advice and insights from a computer authority</description>
	<pubDate>Wed, 21 Apr 2010 18:47:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Free way to avoid web-based malware.</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/20/free-way-to-avoid-web-base-malware/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/20/free-way-to-avoid-web-base-malware/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:58:20 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[New Products]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[avg]]></category>

		<category><![CDATA[security software]]></category>

		<category><![CDATA[web surfing]]></category>

		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=104</guid>
		<description><![CDATA[AVG is now providing its LinkScanner product free to download. LinkScanner will scan web pages as you surf and warn you if a page you visit is trying to install malware or is compromised in some way. It&#8217;s a good idea to use it, considering that the web is the most popular way to deliver [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.avg.com" target="_blank">AVG</a> is now providing its <a href="http://blogs.pcmag.com/securitywatch/2009/04/fight_malware_on_the_web_with.php" target="_blank">LinkScanner product free to download</a>. LinkScanner will scan web pages as you surf and warn you if a page you visit is trying to install malware or is compromised in some way. It&#8217;s a good idea to use it, considering that the web is the most popular way to deliver malware these days. You can read a quick overview of the product <a href="http://www.appscout.com/2009/04/_avg_technologies_today_announ.php" target="_blank">here</a> and download it at <a href="http://linkscanner.avg.com/" target="_blank">http://linkscanner.avg.com</a>. There is free support available from AVG at <a href="http://freeforum.avg.com/" target="_blank">http://freeforum.avg.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/20/free-way-to-avoid-web-base-malware/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Conficker is alive.</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 13:13:46 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[PC Magazine]]></category>

		<category><![CDATA[rootkit]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[Trend Micro]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=94</guid>
		<description><![CDATA[It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday according to TrendLabs, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the TrendLabs [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_blank">according to TrendLabs</a>, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the <a href="Trend now detects this new Conficker variant as WORM_DOWNAD.E. Some interesting things (well at least in our perspective) found are:     1. (Un)Trigger Date – May 3, 2009, it will stop running    2. Runs in random file name and random service name    3. Deletes this dropped component afterwards    4. Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs    5. Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request    6. Connects to the following sites:           * Myspace.com           * msn.com           * ebay.com           * cnn.com           * aol.com  It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.  Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb" target="_blank">TrendLabs blog</a>:</p>
<p><span style="color: #0000ff;">Trend now detects this new Conficker variant as <a onclick="javascript:pageTracker._trackPageview('/outgoing/threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P');" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P">WORM_DOWNAD.E</a>. Some interesting things (well at least in our perspective) found are:</span></p>
<ol>
<li><span style="color: #0000ff;">(Un)Trigger Date – May 3, 2009, it will stop running</span></li>
<li><span style="color: #0000ff;">Runs in random file name and random service name</span></li>
<li><span style="color: #0000ff;">Deletes this dropped component afterwards</span></li>
<li><span style="color: #0000ff;">Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs</span></li>
<li><span style="color: #0000ff;">Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request</span></li>
<li><span style="color: #0000ff;">Connects to the following sites: </span>
<ul>
<li><span style="color: #0000ff;">Myspace.com</span></li>
<li><span style="color: #0000ff;">msn.com</span></li>
<li><span style="color: #0000ff;">ebay.com</span></li>
<li><span style="color: #0000ff;">cnn.com</span></li>
<li><span style="color: #0000ff;">aol.com</span></li>
</ul>
</li>
</ol>
<p><span style="color: #0000ff;">It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.</span></p>
<div id="TixyyLink" style="overflow: hidden;"><span style="color: #0000ff;"><br />
Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb">http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb</a></span></div>
<div style="overflow: hidden;"></div>
<div style="overflow: hidden;">If you think you might be infected, use the <a href="http://www.joestewart.org/cfeyechart.html" target="_blank">Conficker eye chart</a> to confirm, and follow the <a href="http://blogs.pcmag.com/securitywatch/2009/04/infected_with_conficker_heres.php" target="_blank">PC Mag Security Blog steps</a> to help remove it; or give us a call.</div>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Happy April Fool&#8217;s Day</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 20:51:52 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[conficker]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=77</guid>
		<description><![CDATA[So April 1st is here, and the end of the world has not been brought about by the Conficker worm&#8230; as far as we know. However, Conficker is still around, and if you are not sure whether or not you have it, it&#8217;s better to be safe. PC Magazine has put together a checklist of [...]]]></description>
			<content:encoded><![CDATA[<p>So April 1st is here, and the end of the world has not been brought about by the Conficker worm&#8230; as far as we know. However, Conficker is still around, and if you are not sure whether or not you have it, it&#8217;s better to be safe. PC Magazine has put together a checklist of steps to make sure your machine is not infected; it&#8217;s available <a href="http://www.pcmag.com/article2/0,2817,2344170,00.asp" target="_blank">here</a>. If you just want to download the scanning and removal tools, you can get them from the Conficker Working Group site <a href="http://www.confickerworkinggroup.org/wiki/pmwiki.php?n=ANY.RepairTools" target="_blank">here</a>. And make sure you have installed the latest Windows updates and any updates for your security software (you DO have security software right?!?!?).</p>
<p>PS- This is NOT an April Fool&#8217;s joke.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macs attacked again&#8230; through pirated software.</title>
		<link>http://mdpblog.mdpsystems.com/2009/03/30/macs-attacked-again-through-pirated-software/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/03/30/macs-attacked-again-through-pirated-software/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 18:57:23 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=75</guid>
		<description><![CDATA[A while back, Adobe was getting ready to release its Creative Suite 4. A pirated version of the software showed up on file-sharing networks, where a Mac version was available, and bundled with a Trojan horse. Unsuspecting users who installed it were immediately infected. In January, researchers found more malware in pirated versions of Apple&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>A while back, Adobe was getting ready to release its Creative Suite 4. A pirated version of the software showed up on file-sharing networks, where a Mac version was available, and bundled with a Trojan horse. Unsuspecting users who installed it were immediately infected. <a href="http://blogs.pcmag.com/securitywatch/2009/01/mac_malware_found_in_pirated_i.php" target="_blank">In January, researchers found more malware in pirated versions of Apple&#8217;s new iWorks &#8216;09</a>. And once again, <a href="http://blogs.pcmag.com/securitywatch/2009/03/new_malware_for_macs.php" target="_blank">pirated software for the Mac is being passed around embedded with malware</a>. A good rule of thumb is that you should never install pirated versions of anything (on Windows or Macs) because it is illegal, and usually comes with malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/03/30/macs-attacked-again-through-pirated-software/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Downadup = 4/1 (or: Conficker set to do something on April 1)</title>
		<link>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 18:45:29 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=73</guid>
		<description><![CDATA[Conficker (also known as Downadup) is a pretty nasty worm that has three known variations (A, B, and most recently C). It gets onto your machine through a Windows security flaw that was patched in October of 2008, and is programmed to call a sequence of control servers for updates and presumably other nasty activities. [...]]]></description>
			<content:encoded><![CDATA[<p>Conficker (also known as Downadup) is a pretty nasty worm that has three known variations (A, B, and most recently C). It gets onto your machine through a Windows security flaw that was patched in October of 2008, and is programmed to call a sequence of control servers for updates and presumably other nasty activities. Recently, Kaspersky Labs, a security software and research company, was able to figure out the list of names the worm would check for updates and teamed with <a href="http://www.opendns.com" target="_self">OpenDNS</a> to block these attempts. Now researchers are saying that the worm is programmed to do something on April 1. What that is, they don&#8217;t know; they only know that it is set to &#8220;call home&#8221; on that day. Fortunately, there are many <a href="http://blogs.pcmag.com/securitywatch/2009/03/the_most_important_things_to_k.php#more" target="_blank">ways to remove the worm</a> if you&#8217;ve been infected. And as always, keeping your antivirus and antispyware software up-to-date and installing Windows updates will help protect your machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Reminder!!!</title>
		<link>http://mdpblog.mdpsystems.com/2009/03/16/reminder/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/03/16/reminder/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 00:05:27 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=68</guid>
		<description><![CDATA[Over the past couple of months, I&#8217;ve seen a lot of machines infected with malware. In about 80% of the cases, I&#8217;ve had to completely reinstall Windows to clear up the problems. Not only is this time consuming (It takes 2-3 days depending on how busy we are) but it&#8217;s also expensive for the customer. [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past couple of months, I&#8217;ve seen a lot of machines infected with malware. In about 80% of the cases, I&#8217;ve had to completely reinstall Windows to clear up the problems. Not only is this time consuming (It takes 2-3 days depending on how busy we are) but it&#8217;s also expensive for the customer. So much can be avoided by running the latest internet security suite (I recommend Norton Internet Security 2009, available <a title="Norton Internet Security 2009" href="https://shop.symantecstore.com/servlet/ControllerServlet?Action=DisplayPage&amp;Env=BASE&amp;Locale=en_US&amp;SiteID=symnahho&amp;id=QCShoppingCartPage" target="_blank">here</a>) and keeping it up to date. If you think your machine is infected, run a scan using your security software. If you don&#8217;t think you&#8217;re running the latest version, you can do a free scan using Spyware Doctor (available from PC Tools <a title="PC Tools Spyware Doctor" href="http://www.pctools.com/spyware-doctor/download/" target="_blank">here</a>) or Trend Micro&#8217;s online scanning tool (on our website <a title="MDP Systems LLC website" href="http://www.mdpsystems.com/virusalerts/virus_alerts.html" target="_blank">here</a>, then click Free Tools). As always, if you have any questions or need help, just give us a call.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/03/16/reminder/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Getting spammed by CNN and Microsoft&#8230;</title>
		<link>http://mdpblog.mdpsystems.com/2008/08/11/getting-spammed-by-cnn-and-microsoft/</link>
		<comments>http://mdpblog.mdpsystems.com/2008/08/11/getting-spammed-by-cnn-and-microsoft/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 20:33:31 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[computer]]></category>

		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=32</guid>
		<description><![CDATA[A new round of spam has been showing up in inboxes the past 2 weeks. The first round purports to come from CNN, with the subjects &#8220;Daily Top Ten&#8221; or &#8220;My Custom Alerts&#8221;; the other looks like it is from admin@microsoft.com and has the subject &#8220;Internet Explorer 7&#8243;. The gotcha in the CNN spam is [...]]]></description>
			<content:encoded><![CDATA[<p>A new round of spam has been showing up in inboxes the past 2 weeks. The first round purports to come from CNN, with the subjects &#8220;Daily Top Ten&#8221; or &#8220;My Custom Alerts&#8221;; the other looks like it is from admin@microsoft.com and has the subject &#8220;Internet Explorer 7&#8243;. The gotcha in the CNN spam is a link to supposed CNN videos that require you to download and install &#8220;Flash Player&#8221;; of course the download is actually malware and will infect your computer. As always, never open any unsolicited email, even if it seems to come from a legimate source.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2008/08/11/getting-spammed-by-cnn-and-microsoft/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
