<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>From the Mind of Marc... &#187; PC Magazine</title>
	<atom:link href="http://mdpblog.mdpsystems.com/tag/pc-magazine/feed/" rel="self" type="application/rss+xml" />
	<link>http://mdpblog.mdpsystems.com</link>
	<description>Advice and insights from a computer authority</description>
	<pubDate>Wed, 21 Apr 2010 18:47:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Conficker is alive.</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 13:13:46 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[PC Magazine]]></category>

		<category><![CDATA[rootkit]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[Trend Micro]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=94</guid>
		<description><![CDATA[It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday according to TrendLabs, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the TrendLabs [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_blank">according to TrendLabs</a>, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the <a href="Trend now detects this new Conficker variant as WORM_DOWNAD.E. Some interesting things (well at least in our perspective) found are:     1. (Un)Trigger Date – May 3, 2009, it will stop running    2. Runs in random file name and random service name    3. Deletes this dropped component afterwards    4. Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs    5. Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request    6. Connects to the following sites:           * Myspace.com           * msn.com           * ebay.com           * cnn.com           * aol.com  It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.  Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb" target="_blank">TrendLabs blog</a>:</p>
<p><span style="color: #0000ff;">Trend now detects this new Conficker variant as <a onclick="javascript:pageTracker._trackPageview('/outgoing/threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P');" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P">WORM_DOWNAD.E</a>. Some interesting things (well at least in our perspective) found are:</span></p>
<ol>
<li><span style="color: #0000ff;">(Un)Trigger Date – May 3, 2009, it will stop running</span></li>
<li><span style="color: #0000ff;">Runs in random file name and random service name</span></li>
<li><span style="color: #0000ff;">Deletes this dropped component afterwards</span></li>
<li><span style="color: #0000ff;">Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs</span></li>
<li><span style="color: #0000ff;">Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request</span></li>
<li><span style="color: #0000ff;">Connects to the following sites: </span>
<ul>
<li><span style="color: #0000ff;">Myspace.com</span></li>
<li><span style="color: #0000ff;">msn.com</span></li>
<li><span style="color: #0000ff;">ebay.com</span></li>
<li><span style="color: #0000ff;">cnn.com</span></li>
<li><span style="color: #0000ff;">aol.com</span></li>
</ul>
</li>
</ol>
<p><span style="color: #0000ff;">It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.</span></p>
<div id="TixyyLink" style="overflow: hidden;"><span style="color: #0000ff;"><br />
Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb">http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb</a></span></div>
<div style="overflow: hidden;"></div>
<div style="overflow: hidden;">If you think you might be infected, use the <a href="http://www.joestewart.org/cfeyechart.html" target="_blank">Conficker eye chart</a> to confirm, and follow the <a href="http://blogs.pcmag.com/securitywatch/2009/04/infected_with_conficker_heres.php" target="_blank">PC Mag Security Blog steps</a> to help remove it; or give us a call.</div>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
