<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security FAQs &#187; The Conficker Worm</title>
	<atom:link href="http://www.security-faqs.com/category/koobface-conficker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.security-faqs.com</link>
	<description>Security FAQs - answers to common questions about antivirus and other infosec issues.</description>
	<lastBuildDate>Thu, 29 Jul 2010 08:00:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Conficker, The Biggest Botnet On The Internet, Has Been Destroyed. Or Has It?</title>
		<link>http://www.security-faqs.com/conficker-the-biggest-botnet-on-the-internet-has-been-destroyed-or-has-it.html</link>
		<comments>http://www.security-faqs.com/conficker-the-biggest-botnet-on-the-internet-has-been-destroyed-or-has-it.html#comments</comments>
		<pubDate>Mon, 05 Apr 2010 21:50:48 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.security-faqs.com/?p=16439</guid>
		<description><![CDATA[Dead or alive, Conficker was certainly an attention whore last year.<p><a href="http://www.security-faqs.com/conficker-the-biggest-botnet-on-the-internet-has-been-destroyed-or-has-it.html">Conficker, The Biggest Botnet On The Internet, Has Been Destroyed. Or Has It?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Last year everyone waited for the worst to happen.</p>
<p>We were certain that a new piece of malware would be the biggest thing to hit the internet in a long time and that nothing would be the same afterwards.</p>
<p>I am, of course, talking about the infection known as the Conficker worm and how it was supposed to activate on April 1st of last year.</p>
<p><a href="http://www.security-faqs.com/wp-content/uploads/2010/04/Has-Conficker-been-destroyed.jpg"><img class="aligncenter size-full wp-image-16454" title="Has Conficker been destroyed?" src="http://www.security-faqs.com/wp-content/uploads/2010/04/Has-Conficker-been-destroyed.jpg" alt="" width="560" height="300" /></a></p>
<h2>We&#8217;ve Nuked It! Haven&#8217;t We?</h2>
<p>There are certain blogs that are saying that Conficker and the associated botnet are now dead and that no-one is coming back for them <em>(typically, I&#8217;ve forgotten where I&#8217;ve read that so feel free to drop links to such posts if you can find them)</em>.</p>
<p>Whether this is 100% true is not known right now, but what is known is that it has not made a sound lately.</p>
<p>That said, the worm was able to infect the largest amount of computers we have ever seen and now it is just sitting around, waiting for action.</p>
<p>Opinion amongst security experts is divided on whether the Conficker botnet is actually dead or not, though many lessons can be learned either way, as eloquently described in SC Magazines article, &#8220;<a href="http://mobile.scmagazineuk.com/one-year-since-conficker-failed-to-flicker-into-action-what-have-we-learned/marticle/167006/">One  year since Conficker failed to flicker into action, what have we  learned?</a>&#8221; <em>(Thanks to <a href="http://twitter.com/DanRaywood">Dan Raywood</a> for that link)</em></p>
<p>Some people believe that it is still active though and just waiting for people to turn their heads enough to let it rise up again.</p>
<h3>Conficker, The Attention Whore</h3>
<p>Since the worm was able to infect so many computers it received a lot of attention from both the security community and the press.</p>
<p>So much so that it is still a hot topic over a year after it first grabbed the headlines.</p>
<p>Conficker became such big news that Microsoft offered a $250,000 reward for anyone who could offer information about who created the original infection.</p>
<p>So far the money has not been collected and the creators are still on the loose.</p>
<p><strong>Dead Or Alive?</strong></p>
<p>So, <a href="http://news.cnet.com/8301-27080_3-20001449-245.html?part=rss&amp;tag=feed&amp;subj=News-Security">is Conficker just playing dead</a> <em>(thanks for the link <a href="http://twitter.com/davkal">davkal</a>)</em>, or has it really gone for good?</p>
<p>The only way that a botnet can truly be considered destroyed is if it is wiped off of every computer that was infected.</p>
<p>If it is still sat on peoples&#8217; computers, even if just lying dormant, then it lives on.</p>
<p>A dormant botnet can be woken, and not just by the original creators &#8211; it could also be taken over by someone who has reverse engineered the program in order to take control of it for themselves.</p>
<p>Even a rogue government, for example, could decide to cause trouble for the world&#8217;s internet community by taking over the botnet for a short amount of time.</p>
<p>Whatever the case, the botnet is just sitting there waiting for someone to turn it on.</p>
<p>Of course the likelihood of that diminishes by the day &#8211; the creators of the worm are likely too scared to actually use it now &#8211; if they do, they will have many government organizations from around the world coming after them!</p>
<p>It may well be that the creators of Conficker botnet could have decided that, even though they had a brilliant plan, that it is just too risky to follow through with it.</p>
<p>Right now they have two choices to make &#8211; they can retain their civil liberties by never turning it on, or they can become instant <a title="the different types of hacker" href="http://www.security-faqs.com/what-are-the-main-differences-between-hackers-and-crackers.html">black hat hacking</a> heroes by activitating it whilst running the risk of some serious jail time.</p>
<p><strong>Do you believe Conficker still poses a threat?</strong></p>
<p><a href="http://www.security-faqs.com/conficker-the-biggest-botnet-on-the-internet-has-been-destroyed-or-has-it.html">Conficker, The Biggest Botnet On The Internet, Has Been Destroyed. Or Has It?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=16439&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/conficker-the-biggest-botnet-on-the-internet-has-been-destroyed-or-has-it.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Conficker Worm Proved To Be The Biggest Problem In 2009</title>
		<link>http://www.security-faqs.com/the-conficker-worm-proved-to-be-the-biggest-problem-in-2009.html</link>
		<comments>http://www.security-faqs.com/the-conficker-worm-proved-to-be-the-biggest-problem-in-2009.html#comments</comments>
		<pubDate>Thu, 14 Jan 2010 13:00:14 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=12494</guid>
		<description><![CDATA[First found in the wild at the end of 2008, this worm quickly spread to users of the Microsoft Windows operating system family.<p><a href="http://www.security-faqs.com/the-conficker-worm-proved-to-be-the-biggest-problem-in-2009.html">The Conficker Worm Proved To Be The Biggest Problem In 2009</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense--></p>
<p>One thing about the year 2009 is that it saw it&#8217;s share of online threats.</p>
<p>As a matter of fact, there were probably more threats seen in 2009 than in any year prior.</p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2010/01/theres-money-in-conficker.jpg"><img class="aligncenter size-full wp-image-12497" title="theres money in conficker" src="http://www.scamtypes.com/wp-content/uploads/2010/01/theres-money-in-conficker.jpg" alt="theres money in conficker" width="560" height="300" /></a></p>
<p>There are more and more hackers that are seeing the financial benefits that can be made by introducing new exploits to the average computer user.</p>
<p>Also, there are a lot more hacker kits that are available.</p>
<p>They allow a person who is not skilled in creating an exploit to have the ability to use one anyway.</p>
<p>All of these factors mixed together made 2009 and dangerous year on the Internet.</p>
<h2>The Conficker Worm</h2>
<p>None of the threats  that were out there caused more problems than the conficker worm.</p>
<p>This worm took traction in 2009 and wouldn&#8217;t stop.</p>
<p>The <a title="is conficker the most advanced virus?" href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">conficker worm</a> could be easily one of the worse infections that has spread through the Internet for the entire decade, not just 2009.</p>
<p>First found in the wild at the end of 2008, this worm quickly spread to users of the Microsoft Windows operating system family.</p>
<p>After the worm was first discovered, it was hard to stop the infection on user&#8217;s computers because the worm itself kept transforming.</p>
<p>The creators of the worm would monitor recent developments that would hopefully help stop the spread of it and they adjusted accordingly.</p>
<p>This is part of the reason why the worm goes by so many different names.</p>
<p>Besides Conflicker, it also known as Downup and the Kido worm.</p>
<p>The worm was able to spread so much and so quick that <a title="$250,000 bounty" href="http://www.security-faqs.com/microsoft-offers-250000-bounty-in-hunt-for-conficker-writer.html">Microsoft offered a huge bounty</a> on the heads of whoever wrote the worm.</p>
<p>They were determined to eliminate the threat if not by technology, then through old fashion police work.</p>
<p>They were able to discover what region of the world the worm was originating from, but they were not able to find the person or persons responsible for it.</p>
<h3>Antivirus Avoidance</h3>
<p>For a long time, antivirus software was not able to get rid of every variant of the worm.</p>
<p>Now they all claim to be able to detect and dispose of the worm on a users system.</p>
<p>This seems to be true since the spread of the worm has rapidly decreased in the last couple of months.</p>
<p>The worm was so successful that there is no doubt that the creators of it are working on a 2.0 version.</p>
<p>Since they haven&#8217;t been caught, they get the chance to work on all of the mistakes they made.</p>
<p>This time, they can make it even more untraceable.</p>
<p>Out of all the malware that was released in the past year, the Conficker worm proved to be the biggest pest.</p>
<p>It was able to baffle network administrators and security professionals everywhere.</p>
<p><a href="http://www.security-faqs.com/the-conficker-worm-proved-to-be-the-biggest-problem-in-2009.html">The Conficker Worm Proved To Be The Biggest Problem In 2009</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=12966&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/the-conficker-worm-proved-to-be-the-biggest-problem-in-2009.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Conficker &#8211; How To Kill DLL Files And Delete Registry Keys And Values</title>
		<link>http://www.security-faqs.com/conficker-how-to-kill-dll-files-and-delete-registry-keys-and-values.html</link>
		<comments>http://www.security-faqs.com/conficker-how-to-kill-dll-files-and-delete-registry-keys-and-values.html#comments</comments>
		<pubDate>Wed, 14 Oct 2009 21:30:50 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=11295</guid>
		<description><![CDATA[Find out how you can manually remove the Conficker virus from your system.<p><a href="http://www.security-faqs.com/conficker-how-to-kill-dll-files-and-delete-registry-keys-and-values.html">Conficker &#8211; How To Kill DLL Files And Delete Registry Keys And Values</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/10/Deleting-Conficker-registry-keys-and-values.jpg"><img class="aligncenter size-full wp-image-11301" title="Deleting Conficker registry keys and values" src="http://www.scamtypes.com/wp-content/uploads/2009/10/Deleting-Conficker-registry-keys-and-values.jpg" alt="Deleting Conficker registry keys and values" width="350" height="300" /></a></p>
<p>The Conficker virus is now known by many names, including -</p>
<ul>
<li>W32/Conficker.worm</li>
<li> Win32/Conficker.A</li>
<li> W32.Downadup</li>
<li> Downadup</li>
<li> Kido</li>
<li>Confiker</li>
</ul>
<p>but it doesn&#8217;t really matter what you call it &#8211; it is a total and far-reaching menace that has spread far and wide across the internet.</p>
<p><a href="http://www.youtube.com/watch?v=eoAYsGV5MkY"><img src="http://img.youtube.com/vi/eoAYsGV5MkY/default.jpg" width="130" height="97" border=0></a></p>
<p>Exploiting flaws found in <a title="applying the Conficker patch" href="http://www.security-faqs.com/how-do-i-apply-the-conficker-patch.html">Windows MS08-067 vulnerability</a>, Conficker continues to infect machines worldwide and may now be installed on as many as 15 million computers across the globe.</p>
<p><a href="http://www.youtube.com/watch?v=9Zr-nE74VQc"><img src="http://img.youtube.com/vi/9Zr-nE74VQc/default.jpg" width="130" height="97" border=0></a></p>
<p>If you are unfortunate enough to become infected with Conficker then you will probably quickly discover that you cannot access security websites and that services such as Windows Security Center, Windows Error Reporting and Windows Defender have been disabled.</p>
<p>Not only that but Conficker has the ability to spread itself to other vulnerable computers via many means, including networks and external drives.</p>
<p>So, if one computer in a network is infected, then all the others are likely to become infected too.</p>
<p>Microsoft has released a patch to fix the Windows vulnerability and here is how you can manually remove Conficker from your system -</p>
<h2>Killing off the Conficker DLL files</h2>
<p>This is a fairly simple task, as detailed below -</p>
<blockquote><p>1. Right-click the Explorer.exe process and choose the option “Properties”.<br />
2. Click on the “Threads” Tab, locate and highlight the Conficker DLL files listed below.<br />
3. To kill Conficker DLL files, click the “Kill” button.<br />
4. Kill the following Conficker DLL files:</p>
<p>%All Users Application Data%\[RANDOM FILE NAME].dll<br />
%Program Files%\Movie Maker\[RANDOM FILE NAME].dll<br />
%Program Files%\Internet Explorer\[RANDOM FILE NAME].dll<br />
%Temp%\[RANDOM FILE NAME].dll<br />
vhoinp.dll<br />
%System%\[RANDOM FILE NAME].dll</p></blockquote>
<h3>Deleting Conficker Registry Keys and Values</h3>
<p>1. Right-click on your Desktop &gt; select “New” option &gt; select “Text Document” (.txt file) option.<br />
2. Rename the .txt file as a .reg file and call it “Delete_Registry_Conficker_Entities.reg”. This renamed .reg file is a command that creates a shortcut to your Windows registry and allows you to easily delete registry values.<br />
3. Right-click and select the “Edit” option.<br />
4. Copy and paste the Conficker keys listed below -</p>
<blockquote><p>[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\vhoinp.dll]<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\vhoinp.dll]<br />
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\vhoinp.dll]</p></blockquote>
<p>5. In the menu bar, go to “File” &gt; select “Save” &gt; then click the “X” button to close the file.<br />
6. Double-click on the .reg file.<br />
7. When the message box appears saying “Are you sure you want to add the information in C:DOCUME~1%username%DesktopDELETE~1.REG to the registry?”, click the “Yes” button.<br />
8. When the message box appears saying “Information in C:DOCUME~1%username%DesktopDELETE~1.REG has been successfully entered into the registry.”, click the “OK” button.<br />
9. The Conficker registry keys have now been deleted from your registry.</p>
<p>Hopefully that should do the trick for you and you can continue surfing <a title="Conficker countermeasures" href="http://www.security-faqs.com/conficker-countermeasures.html">without being bothered by Conficker again</a> &#8211; just remember to keep your operating system fully patched and updated!</p>
<p><a href="http://www.security-faqs.com/conficker-how-to-kill-dll-files-and-delete-registry-keys-and-values.html">Conficker &#8211; How To Kill DLL Files And Delete Registry Keys And Values</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=11295&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/conficker-how-to-kill-dll-files-and-delete-registry-keys-and-values.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Do I Remove Conficker After It Disables My Antivirus?</title>
		<link>http://www.security-faqs.com/how-do-i-remove-conficker-after-it-disables-my-antivirus.html</link>
		<comments>http://www.security-faqs.com/how-do-i-remove-conficker-after-it-disables-my-antivirus.html#comments</comments>
		<pubDate>Fri, 09 Oct 2009 21:00:02 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10936</guid>
		<description><![CDATA[One of the first steps that all of the different variants of the virus take is to disable all anti-virus software and updates that you may have on your operating system.<p><a href="http://www.security-faqs.com/how-do-i-remove-conficker-after-it-disables-my-antivirus.html">How Do I Remove Conficker After It Disables My Antivirus?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/10/antivirus-disabled-by-conficker-virus.jpg"><img class="aligncenter size-full wp-image-10937" title="antivirus disabled by conficker virus" src="http://www.scamtypes.com/wp-content/uploads/2009/10/antivirus-disabled-by-conficker-virus.jpg" alt="antivirus disabled by conficker virus" width="560" height="300" /></a></p>
<p>The Conficker virus differs from other viruses online because it is one of the few malicious worms that have already learned how to protect themselves from deletion.</p>
<p>One of the first steps that all of the different variants of the virus take is to disable all <a title="the best 10 free antivirus programs" href="http://www.security-faqs.com/the-top-10-free-antivirus-of-2009.html">antivirus software</a> and updates that you may have on your operating system.</p>
<p>This ensures that the hole it entered through stays open so that it can continue to host and download files on your computer without any interference.</p>
<p>Additionally, once you have the Conficker virus, it pays close attention to your browsing habits, disabling your entry to any websites such as Microsoft or anti-virus websites that could help you rid your system of it.</p>
<p>So, if the virus itself prevents you from reaching any type of aid, how do you get rid of it once you have it?</p>
<p>Well, there is no set way to remove the <a title="Conficker may be the most advanced virus ever" href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">Conficker virus</a> from your computer since there are different variants that attack in different manners but there are a few basic tips that may help you remove it on your own before it destroys your operating system.</p>
<p>Many people have found a way around its limited browsing stipulations by having a friend email them an anti-virus download or the Conficker security patch.</p>
<p>While you may no longer be able to access a downloadable removal service for the virus from your computer, you are still able to access software in your email, so this may be an effective way to attack the virus.</p>
<p>You may also consider taking your computer to a computer repair technician if you are suspicious you have the Conficker virus because the longer you allow it to feed on your system the more irreparable the damage it is likely to cause.</p>
<p>If all else fails, reformatting is always effective, but be careful when transferring files to an external storage space because <a title="Conficker B" href="http://www.security-faqs.com/conficker-b.html">variant B of the Conficker virus</a> will ride along on your storage card to make sure it can re-infect your computer when you reload your files.</p>
<p><a href="http://www.security-faqs.com/how-do-i-remove-conficker-after-it-disables-my-antivirus.html">How Do I Remove Conficker After It Disables My Antivirus?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10936&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/how-do-i-remove-conficker-after-it-disables-my-antivirus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Is The Conficker Cabal?</title>
		<link>http://www.security-faqs.com/what-is-the-conficker-cabal.html</link>
		<comments>http://www.security-faqs.com/what-is-the-conficker-cabal.html#comments</comments>
		<pubDate>Mon, 05 Oct 2009 22:00:13 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10924</guid>
		<description><![CDATA[The Conficker Cabal was the nickname given to an ad hoc partnership, led by Microsoft, to fight the Conficker virus.<p><a href="http://www.security-faqs.com/what-is-the-conficker-cabal.html">What Is The Conficker Cabal?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/10/The-Conficker-Cabal.jpg"><img class="aligncenter size-full wp-image-10925" title="The Conficker Cabal" src="http://www.scamtypes.com/wp-content/uploads/2009/10/The-Conficker-Cabal.jpg" alt="The Conficker Cabal" width="560" height="300" /></a></p>
<p>The Conficker Cabal was the nickname given to an ad hoc partnership, led by Microsoft, to fight the <a title="4 ways of stopping the Conficker virus" href="http://www.security-faqs.com/do-you-know-the-4-ways-of-stopping-the-confiker-virus.html">Conficker virus</a>.</p>
<p>Back in February Microsoft announced a partnership with various technology industry leaders and academia which was to implement a coordinated, global response to the Conficker worm.</p>
<p>Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the Domain Name System, Microsoft coordinated a response designed to disable domains targeted by Conficker.</p>
<p>Shortly afterwards Microsoft also announced a $250,000 reward in return for information that would result in the arrest and conviction of those responsible for illegally launching the Conficker virus.</p>
<p>The organisations partnering with Microsoft in this cabal, which has since been renamed due to the negative connotations of that name, include the following -</p>
<ul>
<li>ICANN</li>
<li> NeuStar</li>
<li> VeriSign</li>
<li> CNNIC</li>
<li> Afilias</li>
<li> Public Internet Registry</li>
<li> Global Domains International Inc.</li>
<li> M1D Global</li>
<li> AOL</li>
<li> Symantec</li>
<li> F-Secure</li>
<li> ISC</li>
<li> Arbor Networks</li>
</ul>
<p>Eight months on and there are still <a title="no arrests despite a $250,000 bounty being offered by Microsoft" href="http://www.security-faqs.com/microsoft-offers-250000-bounty-in-hunt-for-conficker-writer.html">no arrests</a> in connection to the Conficker menace.</p>
<p><a href="http://www.security-faqs.com/what-is-the-conficker-cabal.html">What Is The Conficker Cabal?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10924&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/what-is-the-conficker-cabal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why You Shouldn’t Disregard The Conficker Virus Just Yet</title>
		<link>http://www.security-faqs.com/why-you-shouldn%e2%80%99t-disregard-the-conficker-virus-just-yet.html</link>
		<comments>http://www.security-faqs.com/why-you-shouldn%e2%80%99t-disregard-the-conficker-virus-just-yet.html#comments</comments>
		<pubDate>Tue, 29 Sep 2009 12:00:49 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10789</guid>
		<description><![CDATA[Thought to have been developed in Germany, since the root of the name ‘ficken’ is a German obscenity, and the domain it uses has been tracked to Ukraine, the Conficker virus is a very powerful computer worm that has infected millions of computers since it emerged in October 2008.<p><a href="http://www.security-faqs.com/why-you-shouldn%e2%80%99t-disregard-the-conficker-virus-just-yet.html">Why You Shouldn’t Disregard The Conficker Virus Just Yet</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/09/Conficker-April-Fool.jpg"><img class="aligncenter size-full wp-image-10791" title="Conficker April Fool" src="http://www.scamtypes.com/wp-content/uploads/2009/09/Conficker-April-Fool.jpg" alt="Conficker April Fool" width="560" height="300" /></a></p>
<p>You may have disregarded the warnings about the <a title="Conficker is no April fool" href="http://www.security-faqs.com/will-you-be-laughing-at-confiker-cs-exploits-on-april-fools-day.html">Conficker virus the day before April 1st</a> as just another exaggerated epidemic like Y2K.</p>
<p>However, if you are lucky enough to have avoided infection up to now it may be time to take the warning a little more seriously because the Conficker virus is a very real crippling agent that can destroy your computer system if activated.</p>
<p>Thought to have been developed in Germany, since the root of the name ‘ficken’ is a German obscenity, and the domain it uses has been tracked to Ukraine, the Conficker virus is a very powerful computer worm that has infected millions of computers since it emerged in October 2008.</p>
<p>It is estimated that, since then, between 9 and 15 million computers have been infected by the Conficker virus, and the number is still growing exponentially as its variants gather strength and continue to grow.</p>
<p>There are <a title="Conficker A.B,C and D" href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html"><span style="text-decoration: line-through;">four</span> five known variants of the Conficker virus</a>, all of which are designed to open the door for each other should one find its way onto your computer.</p>
<p>Although the variants have different destructive paths into your personal laptop, once they fix themselves into your operating system they open the door for strong strands so that your computer can be taken over.</p>
<p>Most people who have the Conficker virus are unaware of its presence until they notice that they can no longer update their computer software or until their operating system crashes.</p>
<p>This is because the Conficker virus works in the background downloading files and using your computer system as a host computer to continue spreading itself throughout the Internet world.</p>
<p>This is one reason why it has been a struggle to trace the origins of the Conficker virus, because once it finds a host computer it simply exhausts all its available resources, using it as a command center, and then moves on.</p>
<p>Thus, if you are not aware of its presence in your computer, you can continue to use most of your Internet functions until it has used all your resources and crashes the operating system leaving your computer worthless and inoperable.</p>
<p><a href="http://www.security-faqs.com/why-you-shouldn%e2%80%99t-disregard-the-conficker-virus-just-yet.html">Why You Shouldn’t Disregard The Conficker Virus Just Yet</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10789&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/why-you-shouldn%e2%80%99t-disregard-the-conficker-virus-just-yet.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker: The Most Advanced Virus Ever?</title>
		<link>http://www.security-faqs.com/conficker-the-most-advanced-virus-ever.html</link>
		<comments>http://www.security-faqs.com/conficker-the-most-advanced-virus-ever.html#comments</comments>
		<pubDate>Thu, 24 Sep 2009 12:33:35 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10640</guid>
		<description><![CDATA[Elegant and widespread - is Conficker the most advanced virus we have seen so far?<p><a href="http://www.security-faqs.com/conficker-the-most-advanced-virus-ever.html">Conficker: The Most Advanced Virus Ever?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/06/confiker-infection.jpg"><img class="aligncenter size-full wp-image-7807" title="confiker-infection" src="http://www.scamtypes.com/wp-content/uploads/2009/06/confiker-infection.jpg" alt="confiker-infection" width="300" height="272" /></a></p>
<p>There is a bit of an argument going on within the ranks of the Digirati.</p>
<p>Everyone is trying to decide if the <a title="Conficker worm" href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">Conficker Worm</a> is the most advanced virus ever created.</p>
<p>Arguments can be made for other previously released viruses that have wreaked havoc on computer networks and caused billions of dollars in damage.</p>
<h2>Elegant Design</h2>
<p>Even the most experienced programmers agree that Conficker has a very elegant design and that nobody seems to be able figure out exactly how it works.</p>
<p>Other experts state that they have never seen anything like it.</p>
<p>However, there are some contenders as far as the speed of the virus and the monetary damage it causes are concerned.</p>
<h3>Vs. Nimda 2001</h3>
<p>Released on 18 September, 2001, Nimda became the fastest spreading virus of the time and found its way into thousands of computers in 22 minutes.</p>
<p>Nimda used an email propagation scheme that had a file attachment “README.EXE” and was the worst virus up to that date.</p>
<h3>Vs. SQL Slammer 2003</h3>
<p>On 25 January, 2003, SQL Slammer reared its ugly head and began to slow down Internet traffic by causing <a title="denial of service" href="http://www.security-faqs.com/dos-vs-ddos-what-is-the-difference.html">denial of service attacks</a> on host computers.</p>
<p>The virus quickly spread to over 75,000 computers within 10 minutes and completely shut down the Internet in South Korea.</p>
<h3>Vs. Storm 2007</h3>
<p>The Storm Worm was released on 19 January, 2007 and within 72 hours was held accountable for 8% of all malware infections worldwide.</p>
<p>Storm also used an email propagation scheme with an email that had the title: “230 dead as storm batters Europe.”</p>
<p>During those 72 hours there were 6 different attacks performed by the <a title="the Storm Worm" href="http://www.security-faqs.com/malware-that-changed-the-world-the-storm-worm.html">Storm Worm</a>.</p>
<h2>Technologically Advanced?</h2>
<p>Is Conficker the most advanced virus ever?</p>
<p>Most experts would say yes. However, the monetary damage done by Conficker has been pale in comparison to other previous malware attacks.</p>
<p>Only time will tell whether Conficker is the most advanced virus or not&#8230;</p>
<p><a href="http://www.security-faqs.com/conficker-the-most-advanced-virus-ever.html">Conficker: The Most Advanced Virus Ever?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10640&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/conficker-the-most-advanced-virus-ever.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The A,B,C And D Of Conficker Precautions</title>
		<link>http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html</link>
		<comments>http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html#comments</comments>
		<pubDate>Sat, 19 Sep 2009 10:19:55 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10634</guid>
		<description><![CDATA[By having the Conficker virus already disabling malware protection on a PC, it could leave the PC open to other malware attacks.<p><a href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">The A,B,C And D Of Conficker Precautions</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/06/confiker-infection.jpg"><img class="aligncenter size-full wp-image-7807" title="confiker-infection" src="http://www.scamtypes.com/wp-content/uploads/2009/06/confiker-infection.jpg" alt="confiker-infection" width="300" height="272" /></a></p>
<p>Currently there are four versions or levels of the <a title="The Conficker virus" href="http://www.security-faqs.com/do-you-know-the-4-ways-of-stopping-the-confiker-virus.html">Conficker Virus</a> — A, B, C, and D &#8211; that are steadily infecting Windows’ Operation Systems worldwide.</p>
<p>Conficker affects Windows 2000, XP, Vista and Windows 7 Beta as well some Windows server platforms such as 2000, 2008 and 2008 R2 Beta.</p>
<p>Basically what the virus does is it disables the computer’s ability to defend itself from malware.</p>
<p>There are Conficker precautions that a Windows user can take in order to prevent any of the Conficker levels from infecting a computer.</p>
<h3>Using Windows Live Update</h3>
<p>Most private Windows PC owners can prevent the Conficker Virus from attacking their computer by simply making sure that the Automatic Update feature is turned on for their PC.</p>
<p>To do this simply press the “Start” button; open the “Control Panel”; go to “Windows  Security Center” and make sure that “Automatic updating” is turned on.</p>
<p>This will ensure that the PC has received the necessary out-of-band patch.</p>
<h3>Using Group Policy</h3>
<p>Group Policy is a way in which networks can prevent the Conficker Virus from attacking PCs at the workplace.</p>
<p>Using Group Policy will negate Conficker’s activities by removing users from the “Administrator” list. Doing this means that it will be very unlikely for the virus to attack a PC on a network.</p>
<h3>Third Party Protection</h3>
<p>Third party software developers that specialize in anti-virus and malware protection have developed their own patches that scan for and remove the Conficker worm.</p>
<p>Some of these applications will run the scan automatically and others will have a scan-on-demand feature.</p>
<h3>Conclusion</h3>
<p>Many people believe that the current levels of the worm are just a prelude of things to come.</p>
<p>By having the Conficker virus already disabling malware protection on a PC, it could leave the PC open to other malware attacks.</p>
<p>It is best to make sure that precautions against Conficker have been taken so that there are no security issues later on.</p>
<p><a href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">The A,B,C And D Of Conficker Precautions</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10634&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How Do I Remove The Conficker Virus?</title>
		<link>http://www.security-faqs.com/how-do-i-remove-the-conficker-virus.html</link>
		<comments>http://www.security-faqs.com/how-do-i-remove-the-conficker-virus.html#comments</comments>
		<pubDate>Tue, 15 Sep 2009 10:02:14 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=11106</guid>
		<description><![CDATA[If you are one of the millions who have recently found the Conficker virus on their computer, it is likely that your only concern now is how to get rid of it.<p><a href="http://www.security-faqs.com/how-do-i-remove-the-conficker-virus.html">How Do I Remove The Conficker Virus?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense--></p>
<p>If you are one of the millions who have recently found the Conficker virus on their computer, it is likely that your only concern now is how to get rid of it.</p>
<p>First off, you deserve kudos for diagnosing its presence on your system since many people overlook the dormant but deadly virus until it is too late and their operating systems have been destroyed.</p>
<p>However, the fact that you have been observant and caught it out does not mean that your worries are over; in fact, they have probably just begun.</p>
<p>For starters, if you have more than one computer in your home you should not transfer any removable devices between the computers until you have <a title="Conficker removal tools" href="http://www.security-faqs.com/3-more-confiker-removal-tools.html">deleted the Conficker virus</a>.</p>
<p>This is because the virus has a Variant B which will hide in removable devices and then attack during an auto-run function.</p>
<p>So your very initial action should be to control the reach of the Conficker virus within your own home.</p>
<p>Next, because the Conficker virus will disable your anti-virus programs and automatic updates, you need to out think the strand by downloading anti-virus software in your email.</p>
<p>The virus will prevent you from accessing any anti-virus websites that offer you the security patch to eliminate the threat or download the software to destroy it.</p>
<p>However, it will not prevent you from opening your email so if you send yourself a download to erase the Conficker virus from another source you should be able to access and start the download to clean your system.</p>
<p>If this does not work, you may want to take your computer to a computer expert who specializes in deleting viruses because you may need to have your computer reformatted, which can be a dangerous job for a computer novice.</p>
<p>Plus, if the job is not properly executed, you risk losing your data as well as re-infecting your system again with the <a title="What does the Conficker virus do?" href="http://www.security-faqs.com/what-does-the-conficker-worm-do-exactly.html">Conficker virus</a> once reformatting is complete.</p>
<p><a href="http://www.security-faqs.com/how-do-i-remove-the-conficker-virus.html">How Do I Remove The Conficker Virus?</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=11106&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/how-do-i-remove-the-conficker-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Countermeasures</title>
		<link>http://www.security-faqs.com/conficker-countermeasures.html</link>
		<comments>http://www.security-faqs.com/conficker-countermeasures.html#comments</comments>
		<pubDate>Tue, 08 Sep 2009 10:35:48 +0000</pubDate>
		<dc:creator>Lee</dc:creator>
				<category><![CDATA[The Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.scamtypes.com/?p=10726</guid>
		<description><![CDATA[Some more handy tips on how you can counter the dreaded Conficker virus.<p><a href="http://www.security-faqs.com/conficker-countermeasures.html">Conficker Countermeasures</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><!--adsense#chitika--></p>
<p><a href="http://www.scamtypes.com/wp-content/uploads/2009/01/stop-the-confiker-virus2.jpg"><img class="aligncenter size-full wp-image-4417" title="stop-the-confiker-virus2" src="http://www.scamtypes.com/wp-content/uploads/2009/01/stop-the-confiker-virus2.jpg" alt="stop-the-confiker-virus2" width="350" height="300" /></a></p>
<p>The <a title="Is Conficker the most advanced virus?" href="http://www.security-faqs.com/the-abc-and-d-of-conficker-precautions.html">Conficker virus</a> is one of the most infectious and one of the hardest viruses to detect that has hit the Internet.</p>
<p>There are a number of ways to counteract this newest threat and an even greater number of ways to transport this worm to other machines and networks.</p>
<p>Currently, it is estimated that some 9.5 million computers worldwide are infected.</p>
<p>It has the capability of deflecting traces as well as transporting itself via USB memory sticks allowing it to spread even faster and through networks that are normally secured from outside threats.</p>
<p>Once inside your machine it resets restore points, creates registry values, and even generates hundreds of domains to prevent the hacker file download domain from being known.</p>
<p>Mutations of this worm have already been found and once activated it can give the hacker full administrative rights to your computer.</p>
<p>There are a few things that you can do to help protect yourself from getting this worm.</p>
<p>The first thing is to <a title="Conficker and Vista" href="http://www.security-faqs.com/what-every-vista-user-needs-to-know-about-the-conficker-virus.html">update Windows</a>.</p>
<p>Every so often, and especially when threats such as this come out, Microsoft offers security updates that are designed to protect your computer.</p>
<p>Many people do not realize the importance of these security updates and so do not install them.</p>
<p>This leaves your computer vulnerable to these types of threats.</p>
<p>The next step is to download a remover program from a trusted source and scan your system to ensure that you have not already been infected with the Conficker worm.</p>
<p>Even with the security updates protecting your computer, you should scan your computer often and make sure to keep your antivirus and remover tools updated.</p>
<p>These are the best methods to help prevent your computer from becoming infected and removing any infections which may already be present.</p>
<p>It is also a good idea to <a title="Conficker can be spread via USB drives" href="http://www.security-faqs.com/do-you-know-the-4-ways-of-stopping-the-confiker-virus.html">scan USB flash drives</a> and other media before installing any files onto your computer.</p>
<p><a href="http://www.security-faqs.com/conficker-countermeasures.html">Conficker Countermeasures</a> is a post from: <a href="http://www.security-faqs.com">Security FAQs</a></p>
<img src="http://www.security-faqs.com/?ak_action=api_record_view&id=10726&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.security-faqs.com/conficker-countermeasures.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
