<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	>

<channel>
	<title>Ask Ed Hudson.com &#187; Viruses</title>
	<atom:link href="http://askedhudson.com/category/viruses/feed/" rel="self" type="application/rss+xml" />
	<link>http://askedhudson.com</link>
	<description></description>
	<lastBuildDate>Fri, 20 Jan 2012 18:00:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	

		<copyright>Hudson Enterprises, Inc.</copyright>
		<itunes:author>Ed Hudson</itunes:author>
		<itunes:summary>Ask Ed Hudson.com | Business Tips | Technical Tips</itunes:summary>
		<itunes:explicit>No</itunes:explicit>
		<itunes:block>No</itunes:block>
		<itunes:category text="Business">
			<itunes:category text="Management &amp; Marketing" />
		</itunes:category>
		<itunes:category text="Education">
			<itunes:category text="Training" />
		</itunes:category>
		<itunes:category text="Technology">
			<itunes:category text="Tech News" />
		</itunes:category>
		
		<item>
		<title>Don&#039;t Let Conficker Ruin Your April Fool&#039;s Day</title>
		<link>http://askedhudson.com/dont-let-conficker-ruin-your-april-fools-day</link>
		<comments>http://askedhudson.com/dont-let-conficker-ruin-your-april-fools-day#comments</comments>
		<pubDate>Mon, 30 Mar 2009 15:46:05 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Current]]></category>
		<category><![CDATA[Tech Tips]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[malicious software removal]]></category>
		<category><![CDATA[malicious software removal tool]]></category>
		<category><![CDATA[microsoft tool]]></category>
		<category><![CDATA[microsoft windows]]></category>
		<category><![CDATA[patch microsoft]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://askedhudson.com/?p=745</guid>
		<description><![CDATA[<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">By now, hopefully EVERYONE has heard of &#034;Conficker&#034;. If not.. you have very little time to make sure you don&#039;t become &#034;The Fool&#034; this April 1st.</span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Computers infected with the infamous Conficker worm will start scanning the Internet for instructions this April Fools&#039; Day, and the results might not leave you feeling like it was a funny joke.</span></span></p>
<p><a href="http://askedhudson.com/dont-let-conficker-ruin-your-april-fools-day" class="more-link">More on Don&#039;t Let Conficker Ruin Your April Fool&#039;s Day</a></p>


]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">By now, hopefully EVERYONE has heard of &#034;Conficker&#034;. If not.. you have very little time to make sure you don&#039;t become &#034;The Fool&#034; this April 1st.</span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Computers infected with the infamous Conficker worm will start scanning the Internet for instructions this April Fools&#039; Day, and the results might not leave you feeling like it was a funny joke.</span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">CBS&#039;s &#034;60 Minutes&#034; ran a piece on Conficker last night, and my phone has been ringing off the hook today from clients concerned about whether they should be concerned.</span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">To that question I would answer, &#034;Relax, but be vigilant.&#034;<br />
</span></span></p>
<p style="text-align: justify;">
<div><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Some analysists estimate that 54% of the affected computers that already have the Conficker worm sitting there waiting to do whatever it is the creator has designed it to do, are machines in China, Russia, India, Brazil, and Argentina, where many people use unauthorized Windows knockoffs. (Microsoft doesn&#039;t provide all its patches to unlicensed copies of Windows, leaving the vulnerable machines free to attack.)</span></span></span></span></div>
</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">If you have a legitimate copy of Windows, and you have installed the patch Microsoft released back in October 2008, you &#034;should be&#034; fine. Just to make sure, <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">double check that you&#039;ve got the patch installed on your machine</a>. (MS08-067)</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">The update in question was probably installed in late October or November of last year; look for Security Update for Microsoft Windows (KB958644). If this patch isn&#039;t installed, browse to <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0d5f9b6e-9265-44b9-a376-2067b73d6a03&amp;DisplayLang=en" target="_blank">Microsoft&#039;s Download Center </a>to retrieve and install it.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">If your PC is blocked from visiting this site, use a noninfected PC to download the patch to a removable medium and install the update on the wormed PC from that device.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Next, run Microsoft&#039;s Malicious Software Removal Tool (MSRT). The latest version of this Microsoft tool identifies and removes all of the Conficker variants I&#039;ve heard about. The easiest way to get MSRT is through Windows Update, but if you can&#039;t get through to that service on the infected PC, borrow a computer and <a href="http://www.microsoft.com/security/malwareremove/default.mspx" target="_blank">download the tool from Microsoft&#039;s site</a>.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Another sure tipoff that your computer may already be infected is if you have trouble connecting to your Anti-Virus update site. One of the things Conflicker (and it&#039;s variants) was programmed to do was to block you from accessing updates to your Anti-Virus program site.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">If your PC is already infected and you can&#039;t access your AV Update site, a technical trick might enable you to visit a site that Conficker is blocking. Instead of entering the site&#039;s domain name in your browser&#039;s address bar, enter the site&#039;s dotted-decimal IP address instead, which Conficker doesn&#039;t seem to interfere with.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">One way to learn the IP address of a Web site: using an uninfected PC, open a Firefox window and install the <a href="https://addons.mozilla.org/en-US/firefox/addon/590" target="_blank">Show IP</a> browser extension. With this extension enabled, the IP address of whatever site you&#039;re visiting shows up in the browser&#039;s status bar.</span></span></span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Of course, if you navigate to a site using its IP address and then click a link, the site will probably use a spelled-out domain name in the link. Conficker would block the resulting page, which you&#039;d have to replace manually with its dotted-decimal equivalent. A pain in the butt for sure, but a lot less painful than the alternatives if you are already infected.</span></span></span></span></p>
<div>
<p style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Third-party applications, especially media players, are more likely to suffer from security holes than Windows itself is. The security firm Secunia.com offers a free scan, informing you when your PC is running an insecure version of an application that has a security patch available.</span></span></span></p>
<div>
<p style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">the Secunia Software Inspector offers three options: (a) a free online scan; (b) a free download for individual users; and (c) a LAN utility for IT adminstrators. (I use the free online scan).</span></span></span></p>
<div>
<p style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">I run Secunia Inspector every time they send me an email that something needs to be checked. They have an email sign up box after you do a scan the first time that will notify you automatically when updates need to be checked. I highly recommend everyone using this site.<br />
<a href="http://secunia.com/vulnerability_scanning/" target="_blank">http://secunia.com/vulnerability_scanning/</a></span></span></span></p>
<div><span style="font-family: arial,helvetica,sans-serif;"></span></div>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;"></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">It&#039;s best to strengthen your defenses before April 1st rather than waiting to see what bad things might happen. </span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Good luck on Wednesday! </span></span></p>
<p style="text-align: justify;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Until Next Time&#8230;</span></span> </p>
<p> </p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: medium;">Ed</span></span></p>
<p></span></span></p>
</div>
</div>
</div>


]]></content:encoded>
			<wfw:commentRss>http://askedhudson.com/dont-let-conficker-ruin-your-april-fools-day/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Don&#039;t Fall for This Scam!</title>
		<link>http://askedhudson.com/dont-fall-for-this-scam</link>
		<comments>http://askedhudson.com/dont-fall-for-this-scam#comments</comments>
		<pubDate>Fri, 08 Feb 2008 17:20:48 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[marketing]]></category>

		<guid isPermaLink="false">http://ebawebs.com/blog/ebawebs/2008/02/08/dont-fall-for-this-scam/</guid>
		<description><![CDATA[<p>This is EXACTLY the kind of thing MX Logic will stop before you have a chance to click on it and self-inflict all sorts of damage on your computer!</p>
<p>&#160;</p>
<p>If you get something like this&#8230; DO NOT OPEN IT!&#160;&#160; DO NOT FALL FOR THIS!!!&#160;&#160;&#160; DO NOT CLICK ON ANY LINKS BELOW THIS LINE IN THIS POST!!!</p>
<p><a href="http://askedhudson.com/dont-fall-for-this-scam" class="more-link">More on Don&#039;t Fall for This Scam!</a></p>


]]></description>
			<content:encoded><![CDATA[<p>This is EXACTLY the kind of thing MX Logic will stop before you have a chance to click on it and self-inflict all sorts of damage on your computer!</p>
<p>&nbsp;</p>
<p>If you get something like this&#8230; DO NOT OPEN IT!&nbsp;&nbsp; DO NOT FALL FOR THIS!!!&nbsp;&nbsp;&nbsp; DO NOT CLICK ON ANY LINKS BELOW THIS LINE IN THIS POST!!!</p>
<p>&nbsp;</p>
<p>postcards.org</p>
<p>&nbsp;<br />
You have just received a virtual<br />
postcard from a family member!<br />
.<br />
You can pick up your postcard at<br />
the following web address:<br />
.<br />
http://www.postcards.org/?d21-sea-sunset<br />
.<br />
If you can&#039;t click on the web address<br />
above, you can also<br />
visit 1001 Postcards at http://www.postcards.org/postcards/<br />
and enter your pickup code, which is: d21-sea-sunset<br />
.<br />
(Your postcard will be available<br />
for 60 days.)<br />
.<br />
We hope you enjoy your postcard, and if you do,<br />
please take a moment<br />
to send a few yourself!<br />
You can do so by visiting this web address:<br />
http://www2.postcards.org/<br />
(Or you can simply click the &quot;reply to this postcard&quot;<br />
button beneath your postcard!)<br />
.<br />
We hope you like the postcard !<br />
.<br />
Regards,<br />
1001 Postcards<br />
http://www.postcards.org/postcards/ </p>
<p>&nbsp;</p>
<p><strong><font size="4">Clciking on the postcard someone in your family SUPPOSEDLY sent you will unleash all sorts of havoc on your computer!&nbsp; DON&#039;T DO IT!</font></strong></p>
<p><strong></strong></p>
<p>Check Here Monday for a VALUABLE RESOURCE you can use to speed your way through the Social Marketing Maze!!</p>
<p>&nbsp;</p>
<p>Have a Great Weekend!</p>
<p>&nbsp;</p>
<p>Ed</p>
<p>&nbsp;</p>
<p>&nbsp;</p>


]]></content:encoded>
			<wfw:commentRss>http://askedhudson.com/dont-fall-for-this-scam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

