<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetworkJew &#187; malware</title>
	<atom:link href="http://networkjew.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://networkjew.com</link>
	<description>Network tips, news and technology.</description>
	<lastBuildDate>Tue, 31 Jan 2012 15:40:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Conficker Sells Out!</title>
		<link>http://networkjew.com/2009/04/10/conficker-sells-out/</link>
		<comments>http://networkjew.com/2009/04/10/conficker-sells-out/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 13:46:13 +0000</pubDate>
		<dc:creator>Network Jew</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker update]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://networkjew.com/2009/04/10/conficker-sells-out/</guid>
		<description><![CDATA[<a href="http://networkjew.com/2009/04/10/conficker-sells-out/"><img align="left" hspace="5" width="150" height="150" src="http://networkjew.com/wp-content/plugins/thumbnail-for-excerpts/tfe_no_thumb.png" class="alignleft wp-post-image tfe" alt="" title="" /></a>]]></description>
			<content:encoded><![CDATA[<p>After lying dormant for a week, then mysteriously downloading encrypted content, Conficker is now starting to actually show its true colors. It wants to sell you something. Great.</p>
<p><a href="http://www.f-secure.com/weblog/archives/00001652.html">From F-Secure</a>:</p>
<p># On April 8th a new update was made available to Conficker.C infected machines via the P2P network<br />
# The new file, which we call Conficker.E, is executed and co-exists alongside the old infection<br />
# It re-introduces spreading via the MS08-067 vulnerability. Spreading functionality was removed in Conficker.C and the gang behind this maybe realized they made a mistake and added it again.<br />
# There&#8217;s a possible connection to Waledac, a spambot. Some Conficker.C infected computers connected to a well known Waledac domain and downloaded Waledac from there.<br />
# There&#8217;s also a connection to rogue anti-virus products as we&#8217;ve seen it end up on Conficker.C infected machines. The rogue product was Spyware Guard 2008.<br />
# Conficker.E deletes itself if the date is May 3, 2009 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://networkjew.com/2009/04/10/conficker-sells-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Update &#8211; It&#8217;s Doing Something</title>
		<link>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/</link>
		<comments>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 16:04:31 +0000</pubDate>
		<dc:creator>Network Jew</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Home Networking]]></category>
		<category><![CDATA[How-Tos]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security Links]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Top 10]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker update]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://networkjew.com/?p=242</guid>
		<description><![CDATA[<a href="http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/"><img align="left" hspace="5" width="150" src="http://networkjew.com/wp-content/uploads/2009/03/worm-225x157.jpg" class="alignleft wp-post-image tfe" alt="worm" title="worm" /></a>]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-217" href="http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/worm/"><img class="alignleft size-thumbnail wp-image-217" title="worm" src="http://networkjew.com/wp-content/uploads/2009/03/worm-225x157.jpg" alt="worm 225x157 Conficker Update   Its Doing Something" width="225" height="157" /></a>Well, April 1st came and went without the Internet exploding. All seemed calm on the waters until today when, apparently, infected Conficker PC&#8217;s began downloading new encrypted binaries and checking to see if various websites were up.</p>
<p>According to Trend Micro&#8217;s summary:</p>
<blockquote><p>Two things can be summed up from the events that transpired:</p>
<p>1. As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP. The Conficker/Downad P2P communications is now running in full swing!<br />
2. Conficker-Waledac connection? Possible, but we still have to dig deeper into this…</p></blockquote>
<p><a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CCEjrkH5">Here&#8217;s a link to more information from Trend Micro</a></p>
<p>Here&#8217;s a link to the conficker &#8220;eye test&#8221; &#8211; it&#8217;ll let you know if your machine is infected or not.</p>
<p>http://www.talkbiz.com/confickertest/</p>
]]></content:encoded>
			<wfw:commentRss>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

