<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GuruOfSales &#187; virus</title>
	<atom:link href="http://www.guruofsales.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.guruofsales.com</link>
	<description></description>
	<lastBuildDate>Sun, 24 Jul 2011 05:34:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>A new worm infecting over 9 million PCs</title>
		<link>http://www.guruofsales.com/general/geek-stuff/665/a-new-worm-infecting-over-9-million-pcs/</link>
		<comments>http://www.guruofsales.com/general/geek-stuff/665/a-new-worm-infecting-over-9-million-pcs/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 17:16:50 +0000</pubDate>
		<dc:creator>GuruOfSales</dc:creator>
				<category><![CDATA[Geek stuff]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.guruofsales.com/web-20/tools/665/a-new-worm-infecting-over-9-million-pcs</guid>
		<description><![CDATA[Note: This post was origanly posted on the Yahoo blog by Christopher Null. Christopher is one of my all time favorite tech blogger.As my efforts continue to fight spam/junk/viruses as in this post, here is the exact post by Christopher from this link: Judging from the complaints and questions filling my inbox, Windows security looks [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.guruofsales.com%2Fgeneral%2Fgeek-stuff%2F665%2Fa-new-worm-infecting-over-9-million-pcs%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.guruofsales.com%2Fgeneral%2Fgeek-stuff%2F665%2Fa-new-worm-infecting-over-9-million-pcs%2F&amp;source=GuruOfSales&amp;style=normal&amp;service=is.gd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><b>Note</b>: <i>This post was origanly posted on the Yahoo blog by <a target="_blank" href="http://tech.yahoo.com/blogs/null;_ylt=AoaloJGZ3B3V7VQ3H_jE9YTxMJA5">Christopher Null</a>. Christopher is one of my all time favorite tech blogger.<br />As my efforts continue to fight spam/junk/viruses as <a target="_blank" href="http://www.guruofsales.com/general/586/twitter-is-under-hackers-attack-spoof-messages">in this post</a>, here is the exact post by Christopher from this <a target="_blank" href="http://tech.yahoo.com/blogs/null/116396">link</a></i>:
<div align="center"><img style="max-width: 800px; float: none;" src="http://guruofsales.com/wp-content/uploads/2009/01/wormshot.jpg" /></p>
<div align="left">
<blockquote>Judging from the complaints and questions filling my inbox, Windows security looks like it&#8217;s already on track for its worst year this decade. The latest attack is a worm called Downandup, Downadup, Kido!, or Conficker (all the same thing), and it primarily seems to be being delivered via infected USB drives.
<p>How&#8217;s it work? By tricking you into running the virus by modifying the way &#8220;autorun&#8221; works when you plug in a drive. Look closely at the screenshot above and you&#8217;ll see two entries for &#8220;Open folder to view files.&#8221; The one at the top is a phony entry that actually installs the virus on your machine&#8230; but of course it&#8217;s the default selection that pops up when you plug in a drive. Once installed, the virus spreads like crazy via a separate flaw in Windows networking system (now patched, so be sure to run Windows Update if you haven&#8217;t lately) and can quickly infect a whole office. F-Secure has <a href="http://www.f-secure.com/weblog/archives/00001586.html">more analysis </a>on the clever way it tricks you into installing the malware yourself.</p>
<p>How bad has it gotten? Estimates range from <a href="http://topnews.us/content/22591-downandup-worm-hits-35-million-windows-pcs-4-days">3.5 million infected</a> in the first four days after it bean spreading to <a href="http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=212901058&amp;subSection=All+Stories">9 million impacted</a>&#8230; and gettng worse. By now I figure the numbers could top 15 or 20 million.</p>
<p>From an antivirus standpoint, fixing Downandup isn&#8217;t easy. The worm is particularly problematic because of the tricky way it involves the user in installing the software, bypassing auto-installation safeguards, plus its sophisticated way of avoiding detection, as it morphs its code constantly (using randomized elements) to make traditional, signature-based detection almost impossible. </p>
<p>Your best strategy for avoiding Downandup? Turn off AutoPlay/AutoRun on your computer (with Windows XP, <a href="http://www.microsoft.com/windowsxp/Downloads/powertoys/Xppowertoys.mspx">TweakUI</a> is the easiest way to do it). If you do see an AutoPlay dialog box like the one above, just close it and eject the disc or thumbdrive; browsing the drive manually for individual files should keep you uninfected, but you&#8217;re best off not using the drive at all. And of course, make sure your system is fully patched via Windows Update.</p>
<p>What if you already have Downandup infecting your machine? Try your standard antivirus utility as a fix. If that doesn&#8217;t work, F-Secure has a <a href="http://www.f-secure.com/weblog/archives/00001588.html">removal tool</a> that should get rid of it. Good luck out there.</p>
</blockquote>
<p></p>
<p>You can follow his blog <a target="_blank" href="http://tech.yahoo.com/blogs/null;_ylt=AvMnKoRPYs2JEPUA_uWL7NPxMJA5">here</a>.</p>
<p>If you’re not following me on Twitter yet, do so by <a href="http://twitter.com/guruofsales" rel="nofollow" target="_blank">going here</a>.<br />And if you are not an RSS subscriber yet, do so by <a href="http://feeds.feedburner.com/guruofsales" rel="nofollow" target="_blank">going here</a>.</p>
</div>
</div>
<p>Technorati Tags: <a class="performancingtags" href="http://technorati.com/tag/virus" rel="tag">virus</a>, <a class="performancingtags" href="http://technorati.com/tag/worm" rel="tag">worm</a>, <a class="performancingtags" href="http://technorati.com/tag/Yahoo" rel="tag">Yahoo</a>, <a class="performancingtags" href="http://technorati.com/tag/blog" rel="tag">blog</a>, <a class="performancingtags" href="http://technorati.com/tag/tech" rel="tag">tech</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.guruofsales.com/general/geek-stuff/665/a-new-worm-infecting-over-9-million-pcs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

