<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NuGiE Go NgeBloG &#187; conficker</title>
	<atom:link href="http://www.nugie.web.id/tag/conficker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.nugie.web.id</link>
	<description>Informasi Bisnis dan Internet</description>
	<lastBuildDate>Mon, 14 Nov 2011 15:25:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>PCMAV Express for Conficker</title>
		<link>http://www.nugie.web.id/2009/03/pcmav-express-for-conficker.html</link>
		<comments>http://www.nugie.web.id/2009/03/pcmav-express-for-conficker.html#comments</comments>
		<pubDate>Tue, 24 Mar 2009 06:57:37 +0000</pubDate>
		<dc:creator>nugie</dc:creator>
				<category><![CDATA[Anti Virus]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[PCMAV]]></category>
		<category><![CDATA[Remove Conficker]]></category>

		<guid isPermaLink="false">http://www.nugie.web.id/?p=132</guid>
		<description><![CDATA[Is your computer infected with the virus Conficker (aka Kido or Downadup)?  If yes, whether you have used the popular anti-virus, but can not afford Conficker thoroughly cleaned with? No sad especially disappointed. Media PC is now, as the market-leader in computer magazines, the PCMAV Express Conficker for that at this time is * the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="PCMAV" src="http://virusindonesia.com/wp-content/uploads/2009/03/pcmavexpress_conficker.png" alt="" width="400" height="271" /></p>
<p>Is your computer infected with the virus Conficker (aka Kido or Downadup)?  If yes, whether you have used the popular anti-virus, but can not afford Conficker thoroughly cleaned with? No sad especially disappointed. <em>Media PC</em> is now, as the <em>market-leader</em> in computer magazines, the PCMAV Express Conficker for that at this time is * the only * special Conficker superior antivirus in the world capable of providing complete solutions in the virus.  And this proves that antivirus PCMAV is always the pride of Indonesia, although the virus is faced by foreign-nan sophisticated.</p>
<p><strong></strong> <strong>NOTE:</strong> Due to the complexity of handling Conficker this virus, mainly due to the implementation of <em>rootkit</em> technology is a relatively neat and &#8220;beautiful&#8221;, <em>scan engine</em> architecture PCMAV 2.0 standards that are not designed and are not prepared to handle new types of virus such as this. Therefore why PCMAV Express for this Conficker present pending the rising <em>PC Media</em> magazine 05/2009 which will load the latest release PCMAV.</p>
<p>Unlike the other anti-virus, PCMAV for Conficker Express is designed specifically for the special and can identify 100% accurately and thoroughly eradicate Conficker to the &#8220;radical&#8221;, even though this virus has <em>antidebugging</em> techniques, <em>anti-VM, double-layer</em> and <em>obfuscated code rootkit</em> (invisible), which include sophisticated and complex.<span id="more-132"></span></p>
<p>Please note that, despite PCMAV Express is able to identify accurately, and the 3 variants of Conficker (Conficker.A, B, &amp; B-1) that we get from the many faithful readers of the magazine <em>PC Media,</em> but only 2 main variants (Conficker.A &amp; B) is known and we believe has spread to such an extent of hundreds of thousands of PC in the country.  So not true that at the time that this virus Conficker entry has until hundreds of thousands of variants. Info astray this speculation is only a handful of resellers / vendors / amatiran the antivirus did not have sufficient competence to analyze the virus is really quite complex. Despite that, not closed possibility there will be new variants Conficker. Please tell to edit if you find it.</p>
<p>In addition, if there are other antivirus as if so many are able to detect this virus variants (up to tens of dozens), it can be ascertained that the antivirus has been terkecoh by engineering <em>obfuscated code</em> that applies to this virus, or can be also due to the inability of the technical antivirus is the only simple to understand techniques pendeteksian / amateur using hash (CRC, MD5, SHA).And technically, this type of antivirus will Conficker <em>beaten</em> so active in memory.</p>
<p>The first and the only one in Indonesia, PCMAV Express for Conficker equipped with the latest technology <em>RootScan</em> smart-nan, who is able to safely penetrate through to the ring0 <em>(kernel-mode)</em> to detect virus with technology rootkit. This is the main key to be able to eradicate anti-rootkit similar Conficker. Any Sehebat an antivirus in the world, during the active and capable Conficker hiding in ring0, all the power and business anti-virus to detect and cleared most of the configuration of the system will be quite useless. And sepengetahuan our new Express PCMAV this is the only antivirus Conficker special in the world who use sophisticated techniques such nan-unique to this virus from the herd with a secure memory.</p>
<p>In addition, PCMAV Express this can Conficker and the clean settingan system that has been infected and able to restore it to its original state, including re-enable <em>services</em> that it turn off. Difficult to find another antivirus Conficker in the world that have this ability, such as: clean and complete!</p>
<p>In addition, analysis of complete virus Conficker, which is still a hot topic discussions antivirus researchers around the world, will be published in the magazine <em>PC Media</em> 05/2009 and its latest release PCMAV is capable of it. <em>So, keep-in-touch</em> ! FAQ summaries and analysis of this virus will soon be added in this blog. <em>So, keep-in-touch!</em></p>
<p><strong></strong> <strong>Rules of Use:</strong></p>
<ol>
<li>Make sure your users have Administrator equivalent rights.</li>
<li> Disable the antivirus installed in order not to disrupt PCMAV Express.</li>
<li> Make sure that your computer before * not * connected to the network or the Internet during the scan.</li>
<li> Once completed, it is recommended to restart and re-scan (if necessary).</li>
<li> After the virus was successfully dituntaskan, immediately <a title="Microsoft Security Bulletin MS08-067 - Critical" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">update / patch</a> your Windows. PCMAV Express is also able to detect when your computer is not in the patch.</li>
<li> Make sure all the PC that is connected in the network have also been free Conficker, before you return the PC connected to the network.</li>
<li> Make sure the Administrator password on the right of your PC is not easy to guess, because Conficker have the ability to penetrate the &#8220;guess&#8221; the password to the Administrator with the vocabulary that is common in kamusnya. Change your password with a combination of alphabet and numerical order is not easy to guess.</li>
<li> If steps 3-7 above do not follow you correctly, then most likely Conficker can attack again, as well as any anti-virus you use.</li>
</ol>
<p><a title="Download PCMAV Express for Conficker" href="http://64.233.189.132/translate_c?hl=en&amp;ie=UTF-8&amp;sl=id&amp;tl=en&amp;u=http://www.sendspace.com/file/p6nx1q&amp;usg=ALkJrhhb1UcEjV6xJ20TwinCC-yYN64Iyg" target="_blank">Download Now!</a></p>
<p>Source : <a href="http://virusindonesia.com/2009/03/22/pcmav-express-for-conficker/" target="_blank"><em><strong>http://www.virusindonesia.com</strong></em></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nugie.web.id/2009/03/pcmav-express-for-conficker.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Collaborates With Industry to Disrupt Conficker Worm</title>
		<link>http://www.nugie.web.id/2009/02/microsoft-collaborates-with-industry-to-disrupt-conficker-worm.html</link>
		<comments>http://www.nugie.web.id/2009/02/microsoft-collaborates-with-industry-to-disrupt-conficker-worm.html#comments</comments>
		<pubDate>Thu, 12 Feb 2009 09:11:21 +0000</pubDate>
		<dc:creator>nugie</dc:creator>
				<category><![CDATA[Anti Virus]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Information]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[reward]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.nugie.web.id/?p=112</guid>
		<description><![CDATA[Microsoft offers $250,000 reward for Conficker arrest and conviction. REDMOND, Wash. &#8211; Feb. 12, 2009 - Today, Microsoft Corp. announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the Conficker (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within [...]]]></description>
			<content:encoded><![CDATA[<h2>Microsoft offers $250,000 reward for Conficker arrest and conviction.</h2>
<p><strong>REDMOND, Wash. &#8211; Feb. 12, 2009 -</strong> Today, Microsoft Corp. announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the Conficker (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the Domain Name System, Microsoft coordinated a response designed to disable domains targeted by Conficker. Microsoft also announced a $250,000 reward for information that results in the arrest and conviction of those responsible for illegally launching the Conficker malicious code on the Internet.</p>
<p>&#8220;As part of Microsoft&#8217;s ongoing security efforts, we constantly look for ways to use a diverse set of tools and develop methodologies to protect our customers,&#8221; said George Stathakopoulos, general manager of the Trustworthy Computing Group at Microsoft. &#8220;By combining our expertise with that of the broader community we can expand the boundaries of defense to better protect people worldwide.&#8221;</p>
<p>As cyberthreats have rapidly evolved, a greater level of industry coordination and new tactics for communication and threat mitigation are required. To optimize the multiple initiatives being employed across the security industry and within academia, Microsoft helped unify these broad efforts to implement a community-based defense to disrupt the spread of Conficker.<span id="more-112"></span></p>
<p>Along with Microsoft, organizations involved in this collaborative effort include ICANN, NeuStar, VeriSign, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from Georgia Tech, the Shadowserver Foundation, Arbor Networks and Support Intelligence.</p>
<p>&#8220;The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together,&#8221; said Greg Rattray, chief Internet security advisor at ICANN. &#8220;ICANN represents a community that&#8217;s all about coordinating those kinds of efforts to keep the Internet globally secure and stable.&#8221;</p>
<p>&#8220;Microsoft&#8217;s approach combines technology innovation and effective cross-sector partnerships to help protect people from cybercriminals,&#8221; Stathakopoulos said. &#8220;We hope these efforts help to contain the threat posed by Conficker, as well as hold those who illegally launch malware accountable.&#8221;</p>
<p>More information about how to protect yourself from Conficker can be found at <a href="http://www.microsoft.com/conficker">http://www.microsoft.com/conficker</a>. Customers interested in learning more about staying safe online can visit <a href="http://www.microsoft.com/protect">http://www.microsoft.com/protect</a>.</p>
<p>Microsoft&#8217;s reward offer stems from the company&#8217;s recognition that the Conficker worm is a criminal attack. Microsoft wants to help the authorities catch the criminals responsible for it. Residents of any country are eligible for the reward, according to the laws of that country, because Internet viruses affect the Internet community worldwide. Individuals with information about the Conficker worm should contact their international law enforcement agencies.</p>
<p>Founded in 1975, Microsoft (Nasdaq &#8220;MSFT&#8221;) is the worldwide leader in software, services and solutions that help people and businesses realize their full potential.</p>
<p><em>Note to editors:</em> If you are interested in viewing additional information on Microsoft, please visit the Microsoft Web page at <a href="http://www.microsoft.com/presspass">http://www.microsoft.com/presspass</a> on Microsoft&#8217;s corporate information pages. Web links, telephone numbers and titles were correct at time of publication, but may since have changed. For additional assistance, journalists and analysts may contact Microsoft&#8217;s Rapid Response Team or other appropriate contacts listed at <a href="http://www.microsoft.com/presspass/contactpr.mspx">http://www.microsoft.com/presspass/contactpr.mspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nugie.web.id/2009/02/microsoft-collaborates-with-industry-to-disrupt-conficker-worm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker worm spikes, infects 1.1 million PCs in</title>
		<link>http://www.nugie.web.id/2009/01/conficker-worm-spikes-infects-11-million-pcs-in.html</link>
		<comments>http://www.nugie.web.id/2009/01/conficker-worm-spikes-infects-11-million-pcs-in.html#comments</comments>
		<pubDate>Thu, 29 Jan 2009 09:01:07 +0000</pubDate>
		<dc:creator>nugie</dc:creator>
				<category><![CDATA[Anti Virus]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.nugie.web.id/?p=110</guid>
		<description><![CDATA[The Conficker worm is back with a vengeance, infecting over one million systems in the past 24 hours. The refined version of this malware scans networks for weakly protected machines and actively attempts to spread itself via USB thumb drives. Neither feature was present in the original version, and so far, the attack is working. [...]]]></description>
			<content:encoded><![CDATA[<p>The Conficker worm is back with a vengeance, infecting over one million systems in the past 24 hours. The refined version of this malware scans networks for weakly protected machines and actively attempts to spread itself via USB thumb drives. Neither feature was present in the original version, and so far, the attack is working.</p>
<p><img class="aligncenter" title="conflicker worm" src="http://static.arstechnica.com/images/conflicker_worm.png" alt="" width="580" height="436" /></p>
<p>It has been over a month since we heard much about Conficker, but the worm has reappeared with a vengeance over the past seven days. According to Finnish security company F-Secure, more than one million PCs have been infected with the worm (also known as Kido or Downadup) in the past 24 hours, with a total of 3.52 million machines infected worldwide. According to F-Secure, that 3.52 million is a conservative estimate.</p>
<p>The problem isn&#8217;t so much with the older version of Conficker (now known as Conficker.A) but with a new flavor, dubbed Conficker.B. Ars spoke with Roger Halbheer, Chief Security Advisor of Microsoft&#8217;s EMEA (Europe, Middle East, and Africa); he&#8217;s been monitoring (and writing) about the current spread of infections. The skyrocketing infection rate is actually being caused by several factors; Roger describes Conficker.B as a &#8220;beast,&#8221; and Microsoft has built the following diagram to demonstrate how the worm functions.<span id="more-110"></span></p>
<p>Once run or given access to an unprotected machine, Conficker.B begins searching for other systems or shares within the local network that it can infect. Shared systems, removable drives, or unpatched systems are all eligible targets, as are machines with weak passwords. This last bit is an important new feature of Conficker.B; a complete list of the passwords it checks for can be found here. If Conficker.B manages to successfully guess a  password, it moves in and continues hunting for new targets. Microsoft summarizes the new strain as follows:</p>
<blockquote><p>Worm:Win32/Conficker.B is a worm that infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. It may also spread via removable drives and weak administrator passwords. It disables several important system services and security products.</p></blockquote>
<p>Roger confirmed that the Malicious Software Removal Tool (MSRT) has checked for and removed Conficker.B since December 29, 2008, but it&#8217;s not possible to access any Microsoft website once Conficker.B has infected a system; the worm blocks access to multiple domains based on string identification. If you&#8217;ve got a system that&#8217;s infected, you&#8217;ll need to download the latest MSRT from Microsoft on a clean system and run it manually.</p>
<p>Not all AV scanners currently detect Conficker.B, even if they&#8217;ve been updated to detect Conficker.A-I don&#8217;t have a list of specific solutions that can&#8217;t currently catch the new worm, but all of Microsoft&#8217;s antimalware/antivirus products-Forefront, OneCare, and the Online Safety Scanner-will find Conficker.B if it&#8217;s present (and you somehow haven&#8217;t noticed). If there&#8217;s a scrap of good news in all this, it&#8217;s that Conficker.B is not a subtle worm.</p>
<p>Roger has provided some additional coverage on the worm that may be useful. First and foremost, he recommends installing MS08-067-this will not remove an existing infection, but it will guard against attack from either version of the agent, provided you aren&#8217;t using weak passwords.</p>
<p>When Conficker.A first appeared, we raised the question of whether or not Microsoft should force updates in certain situations, and what those situations might be. In this case, even unilaterally enforced updates wouldn&#8217;t solve the problem of weak passwords, but it would have undoubtedly cut the number of new infections we are seeing today. The size of that reduction would be the point on which the value of forced updates would turn, and of course, that&#8217;s the one thing we can&#8217;t predict; there are holes in existing AV products that would allow Conficker.B through, and the worm will attack and infect machines using weak passwords. Depending on how you view the situation; this second strain could reinforce the need for mandatory updates or blow a hole in the argument.</p>
<p>Part of the reason for the problem, however, must inevitably come back upon the users, IT administrators, or managers that opted not to install the patch. As Roger writes: &#8220;If you decide not to roll out a security update which is so critical that we decide to go out of band, you play Russian Roulette with your network&#8230;The same is actually true if you do not run and maintain an appropriate Anti-Malware solution&#8230;Now, if we look at Conficker.B: This is really an ugly beast: You need just one infected machine in your network in order to have it spread across your network fast and aggressively. You can get it even through a USB-stick&#8230;it just needs one unpatched/infected machine.&#8221;</p>
<p>Indeed. Based on the characteristics of a worm such as this, even mandatory updates would only be one facet of prevention.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nugie.web.id/2009/01/conficker-worm-spikes-infects-11-million-pcs-in.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

