<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>rootkit &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/rootkit/</link>
	<description>Feed of posts on WordPress.com tagged "rootkit"</description>
	<pubDate>Sun, 19 Jul 2009 13:48:16 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Spam and Botnets &ndash; Who&rsquo;s Responsible?]]></title>
<link>http://billmullins.wordpress.com/2009/07/13/spam-and-botnets-whos-responsible/</link>
<pubDate>Mon, 13 Jul 2009 15:44:06 +0000</pubDate>
<dc:creator>Bill Mullins</dc:creator>
<guid>http://billmullins.wordpress.com/2009/07/13/spam-and-botnets-whos-responsible/</guid>
<description><![CDATA[ A fairly recent survey on Internet security released by the National Cyber Security Alliance (NCSA)]]></description>
<content:encoded><![CDATA[ A fairly recent survey on Internet security released by the National Cyber Security Alliance (NCSA)]]></content:encoded>
</item>
<item>
<title><![CDATA[RootKit Revealer]]></title>
<link>http://musictechgames.wordpress.com/2009/07/10/rootkit-revealer/</link>
<pubDate>Fri, 10 Jul 2009 09:37:48 +0000</pubDate>
<dc:creator>Tyler</dc:creator>
<guid>http://musictechgames.wordpress.com/2009/07/10/rootkit-revealer/</guid>
<description><![CDATA[What is a RootKit you ask? *Sigh* Well, it&#8217;s a file or running process that hides itself from ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>What is a RootKit you ask? *Sigh* Well, it&#8217;s a file or running process that hides itself from the OS. Some viruses use rootkits to secretly run on your system and not even be seen by antivirus programs.</p>
<p>You aren&#8217;t totally f#%*ed if you get one. There are apps used to detect rootkits&#8230; but how? Well the rootkits instruct the system kernel(Google it&#8230;) to not show these files to the OS. What the rootkit detector does is look at the drive without refering to the system kernel, and compare the list from the kernel to what it sees on the drive the drive. Kinda confusing, huh? </p>
<p>RootKit Revealer, by Sysinternals is one great rootkit detector. Google for a download of it(I don&#8217;t feel like typing the link!), and give it a run! Who knows what could be on your system?</p>
<p>Later bros and sistas!!<br />
-Tyler   </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exklusiv ab dem 01.07.2009: 25% auf Norman Security Suite!]]></title>
<link>http://insidesoftwarenews.wordpress.com/2009/07/02/exklusiv-ab-dem-01-07-2009-25-auf-norman-security-suite/</link>
<pubDate>Thu, 02 Jul 2009 07:30:10 +0000</pubDate>
<dc:creator>InsideSoftwarenews</dc:creator>
<guid>http://insidesoftwarenews.wordpress.com/2009/07/02/exklusiv-ab-dem-01-07-2009-25-auf-norman-security-suite/</guid>
<description><![CDATA[ 
25 % Rabatt auf Norman Security Suite: Nur EUR 36.75 anstelle von EUR 49.00.
Angebot exklusiv ab d]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p> </p>
<p><a href="http://send.onenetworkdirect.net/z/34593/CD109991"><img class="alignleft size-full wp-image-201" title="norman security suite image" src="http://insidesoftwarenews.wordpress.com/files/2009/06/norman-security-suite-image.jpg" alt="norman security suite image" width="94" height="121" /></a>25 % Rabatt auf Norman Security Suite: Nur EUR 36.75<span style="text-decoration:line-through;"><span style="color:#ff0000;"> anstelle von EUR 49.00.</span></span></p>
<p><span style="color:#000000;"><strong>Angebot exklusiv ab dem 01.07.2009 gültig! </strong></span></p>
<p><span style="color:#000000;">Geben Sie den folgenden Coupon Code ein, um 25% zu sparen: <strong>25OFFSSEU</strong></span></p>
<p><span style="color:#000000;"><a href="http://send.onenetworkdirect.net/z/34593/CD109991">Hier klicken, um Norman Security Suite direkt beim Hersteller zu kaufen.</a></span></p>
<p>Die Norman Security Suite besteht aus einer Reihe von Sicherheitsprogrammen, die vor Bedrohungen aus dem Internet, wie z. B. Viren, Würmern, Trojanern, Spyware und Hackern schützt. Die verschiedenen Programme schützen vor unangemessenem Inhalt, Rootkits und anderen böswilligen Aktivitäten gegen jeden PC, sei es beim Online-Banking, beim Chatten, beim Empfang von E-Mails, beim Gaming oder beim Surfen im Internet.</p>
<p>Die wichtigsten Funktionen im Überblick:</p>
<ul>
<li>Virenschutz</li>
<li>Norman SandBox</li>
<li>Rootkit-Identifikation</li>
<li>Anti-Spyware</li>
<li>Kindersicherung</li>
<li>Personal Firewall</li>
<li>Schutz vor Pharming-Angriffen</li>
</ul>
<p><a href="http://send.onenetworkdirect.net/z/34593/CD109991">Hier klicken, um Norman Security Suite direkt beim Hersteller zu kaufen.</a></p>
<p style="text-align:center;"><a href="http://send.onenetworkdirect.net/z/34591/CD109991/"><img src="http://send.onenetworkdirect.net/42/109991/34591/" border="0" alt="25% Rabatt Norman Security Suite. Jetzt Kaufen. Co" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xem tin Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt]]></title>
<link>http://linhkienmaytinh.wordpress.com/2009/06/26/xem-tin-ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat/</link>
<pubDate>Fri, 26 Jun 2009 08:55:14 +0000</pubDate>
<dc:creator>vietsmall</dc:creator>
<guid>http://linhkienmaytinh.wordpress.com/2009/06/26/xem-tin-ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat/</guid>
<description><![CDATA[Ứng dụng Microsoft Security Essentials (MSE) đem đến cho người sử dụng hệ thống bảo vệ cơ bản trước ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php" title="Xem tin Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt"><img src="http://www.viencanh.com/images/tintuc/thumb100x100/mse-giao-dien.jpg" class="alignleft" title="Xem tin Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt" alt="Xem tin Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt" /></a>Ứng dụng Microsoft Security Essentials (MSE) đem đến cho người sử dụng hệ thống bảo vệ cơ bản trước các nguy cơ virus, Trojan, rootkit và spyware.<!--more--><br />
<table style="width:1px;" border="0" cellspacing="0" cellpadding="3" align="center">
<tbody>
<tr>
<td><a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php" title="Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt"><img src="http://www.viencanh.com/images/tintuc/mse-download.jpg" border="1" alt="http://www.microsoft.com/security_essentials/" width="450" height="240" /></a></td>
</tr>
<tr>
<td class="Image" align="center">Phần mềm MSE được cung cấp tại địa chỉ http://www.microsoft.com/security_essentials.</td>
</tr>
</tbody>
</table>
<p>Microsoft hy vọng MSE, cho download <a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php">miễn phí</a> từ website của hãng và tự động cập nhật cho người dùng, sẽ tạo dựng được chỗ đứng trong một thị trường đã có nhiều đối thủ cạnh tranh hùng mạnh.</p>
<p>&#8220;Những đánh giá ban đầu cho thấy bản beta phần mềm bảo mật của Microsoft hoạt động kém hơn so với các sản phẩm chống virus miễn phí hiện hành, và kém xa so với các chương trình bản quyền&#8221;, một báo cáo của hãng Symantec viết.</p>
<p>Trong khi đó, J.R Smith, Giám đốc điều hành hãng AVG, thì cho rằng việc Microsoft tham gia vào thị trường ứng dụng bảo mật sẽ càng làm cho người tiêu dùng bối rối hơn trong việc sử dụng các giải pháp bảo vệ máy tính.</p>
<table style="width:1px;" border="0" cellspacing="0" cellpadding="3" align="center">
<tbody>
<tr>
<td><a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php" title="Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt"><img src="http://www.viencanh.com/images/tintuc/mse-giao-dien.jpg" border="1" alt="Giao diện của MSE." width="450" height="240" /></a></td>
</tr>
<tr>
<td class="Image" align="center">Giao diện của <a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php">MSE</a>.</td>
</tr>
</tbody>
</table>
<p>Hiện thời, 75 nghìn bản thử nghiệm <a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php">MSE</a> mang tên mã là Morro sẽ được phát hành ở bốn nước Mỹ, Brazil, Trung Quốc, Israel và đến cuối năm nay sẽ có mặt ở các quốc gia khác.</p>
<p>Trước đây, Microsoft từng bị chỉ trích vì không tích hợp phần mềm bảo mật miễn phí vào Windows. Sau đó, hãng này đã cung cấp gói bảo mật Windows Live OneCare nhưng không thành công vì thu hút quá ít người sử dụng và sau đó đã phải ngưng phát triển.</p>
<p><strong>Minh Hồng </strong>
<p> </p>
</p>
<p> <b>Bài viết liên quan</b><br />
<table class="table" width="100%">
<tr>
<td valign="top"><a href="http://www.viencanh.com/cau-hinh-co-ban-cho-may-tinh-chay-windows-7-n6339.php" target="_blank"><img src="http://www.viencanh.com/images/tintuc/thumb100x100/p134.jpg" /></a><br /><a href="http://www.viencanh.com/cau-hinh-co-ban-cho-may-tinh-chay-windows-7-n6339.php" target="_blank">Cấu hình cơ bản cho máy tính chạy Windows 7</a></td>
<td valign="top"><a href="http://www.viencanh.com/intel-thay-the-core-2-duo-bang-i3-i5-va-i7-n9332.php" target="_blank"><img src="http://www.viencanh.com/images/tintuc/thumb100x100/b1133.jpg" /></a><br /><a href="http://www.viencanh.com/intel-thay-the-core-2-duo-bang-i3-i5-va-i7-n9332.php" target="_blank">Intel thay thế Core 2 Duo bằng i3, i5 và i7</a></td>
<td valign="top"><a href="http://www.viencanh.com/nguoi-dung-vn-chiu-ton-that-372-ty-dong-moi-thang-vi-virus-n6457.php" target="_blank"><img src="http://www.viencanh.com/images/tintuc/thumb100x100/b622.jpg" /></a><br /><a href="http://www.viencanh.com/nguoi-dung-vn-chiu-ton-that-372-ty-dong-moi-thang-vi-virus-n6457.php" target="_blank">Người dùng VN chịu tổn thất 372 tỷ đồng mỗi tháng vì virus</a></td>
<td valign="top"><a href="http://www.viencanh.com/tuyen-tap-laptop-doanh-nhan-cua-hp-n6280.php" target="_blank"><img src="http://www.viencanh.com/images/tintuc/thumb100x100/hp-1.jpg" /></a><br /><a href="http://www.viencanh.com/tuyen-tap-laptop-doanh-nhan-cua-hp-n6280.php" target="_blank">Tuyển tập laptop doanh nhân của HP</a></td>
</tr>
</table>
<p> <b>Nguồn: viencanh.com</b> <a href="http://www.viencanh.com/ban-thu-nghiem-phan-mem-diet-virus-cua-microsoft-ra-mat-n9706.php" target="_blank">Bản thử nghiệm phần mềm diệt virus của Microsoft ra mắt</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET Smart Security V 3.0.684 Türkçe Full]]></title>
<link>http://ajanslive.wordpress.com/2009/06/25/eset-smart-security-v-3-0-684-turkce-full/</link>
<pubDate>Thu, 25 Jun 2009 17:05:18 +0000</pubDate>
<dc:creator>ajanslive</dc:creator>
<guid>http://ajanslive.wordpress.com/2009/06/25/eset-smart-security-v-3-0-684-turkce-full/</guid>
<description><![CDATA[

ESET Smart Security kişisel güvenlik duvarı, antispam, ve ESET NOD32 Antivirus tarafından da sunul]]></description>
<content:encoded><![CDATA[

ESET Smart Security kişisel güvenlik duvarı, antispam, ve ESET NOD32 Antivirus tarafından da sunul]]></content:encoded>
</item>
<item>
<title><![CDATA[Eset NOD32 Antivirus 3.0.684 Türkçe (32 Bit) Sınırsız]]></title>
<link>http://ajanslive.wordpress.com/2009/06/25/eset-nod32-antivirus-3-0-684-turkce-32-bit-sinirsiz/</link>
<pubDate>Thu, 25 Jun 2009 16:57:42 +0000</pubDate>
<dc:creator>ajanslive</dc:creator>
<guid>http://ajanslive.wordpress.com/2009/06/25/eset-nod32-antivirus-3-0-684-turkce-32-bit-sinirsiz/</guid>
<description><![CDATA[
Antivirüs yazılımı denince akla &#8220;NOD32&#8243; gelir. ESET NOD32 Antivirus, ödüllü ThreatSense]]></description>
<content:encoded><![CDATA[
Antivirüs yazılımı denince akla &#8220;NOD32&#8243; gelir. ESET NOD32 Antivirus, ödüllü ThreatSense]]></content:encoded>
</item>
<item>
<title><![CDATA[The Great Botnet of China]]></title>
<link>http://larimdame.wordpress.com/2009/06/25/the-great-botnet-of-china/</link>
<pubDate>Thu, 25 Jun 2009 04:45:05 +0000</pubDate>
<dc:creator>larimdame</dc:creator>
<guid>http://larimdame.wordpress.com/2009/06/25/the-great-botnet-of-china/</guid>
<description><![CDATA[I was disappointed to hear that Green Dam, the mandatory porn fltering software that China was deman]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I was disappointed to hear that Green Dam, the mandatory porn fltering software that China was demanding be installed on every computer in China, has been delayed. repots has been that it was a very flawed piece of software, easily hacked and repurposed. Of course, the problem lies with its very nature of being a rootkit wrapped in a low bidder wrapper. </p>
<p>Nobody believes that Green Dam is solely to stamp out internet porn. It&#8217;s being pushed far too hard by far too important people to b just about porn. It&#8217;s clearly a trojan horse, designed to monitor and track an increasingly restive population. The only surprise here is that an authoritative government like the Communist Party has taken so long to try this out.</p>
<p>The problem, of course, is that you are intentionally infecting computers with a Trojan Horse. If you intentionally build a root level backdoor, it&#8217;s only a matter of time before that backdoor is compromised. And once that happens, anybody can bust in through the backdoor and take over millions of computers. And millions of computers tied together instantly becomes a collosal, if albiet a bit slow, supercomputer. They call these things botnets (our few surviving descendants will eventually come to call it SkyNet, after the coming robot apocolpyse, of course).</p>
<p>Criminal hackers expend a great deal of time and creativity to build these things from scratch. Increasingly sophisticated viruses, clever human behavior exploits, operating system vulenerabilities; these are all routinely leveraged to spread malicious code. Code that secretly takes over your humble pc, and adds it to a criminal botnet that takes down titans of web commrce, hiolds businesses hostage, and fills the ether with countless pieces of spam. And now China is on the verge of building the biggest one in the world, only with the added bonus of being able to be hijacked easily.</p>
<p>I was looking rather forward the day when trillions of Green Dam computers went online, and were promptly taken over by Eastern European criminal gangs. It would have been fun to see the entire Internet come crashing down before a tsunami of spam and ddos attacks. I was looking forward to the ironic collapse of the Great Firewall of China under the botnet flood of the Green Dam. </p>
<p>*sigh* don&#8217;t these people know anything? The solution to the internet problem lies in the same solution as the political problem: central control. Ban computers and move everyone to either ultra thin-net clients or old school server terminals. I&#8217;m sure IBM would would be more than happy to sell China bunches of old school mainframes to run the whole show. Of course, getting the thing to scale will be tough, plus that whole human rights thing. But there&#8217;ll be plenty of money to compensate for both, and that&#8217;s what really matters, no?</p>
<p>In the meantime, I guess all we can do is sit back and wait for them to &#8220;fix&#8221; Green Dam, and wait for the eventual botnet storm.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Лечим компьютер от вирусов. Если ваш антивирус не справился...]]></title>
<link>http://mutaboot.wordpress.com/2009/06/24/%d0%bb%d0%b5%d1%87%d0%b8%d0%bc-%d0%ba%d0%be%d0%bc%d0%bf%d1%8c%d1%8e%d1%82%d0%b5%d1%80-%d0%be%d1%82-%d0%b2%d0%b8%d1%80%d1%83%d1%81%d0%be%d0%b2-%d0%b5%d1%81%d0%bb%d0%b8-%d0%b2%d0%b0%d1%88-%d0%b0%d0%bd/</link>
<pubDate>Wed, 24 Jun 2009 12:54:39 +0000</pubDate>
<dc:creator>rocksett286</dc:creator>
<guid>http://mutaboot.wordpress.com/2009/06/24/%d0%bb%d0%b5%d1%87%d0%b8%d0%bc-%d0%ba%d0%be%d0%bc%d0%bf%d1%8c%d1%8e%d1%82%d0%b5%d1%80-%d0%be%d1%82-%d0%b2%d0%b8%d1%80%d1%83%d1%81%d0%be%d0%b2-%d0%b5%d1%81%d0%bb%d0%b8-%d0%b2%d0%b0%d1%88-%d0%b0%d0%bd/</guid>
<description><![CDATA[Бывают такие случаи, когда установленный антивирус не справился со своими обязанностями или есть под]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Бывают такие случаи, когда установленный антивирус не справился со своими обязанностями или есть подозрение на заражение. Как выловить и избавиться от зловредов в таком случае? Очень просто, сторонними утилитами.<br />
Для начала вам следует скачать нужные инструменты для обнаружения и лечения.<br />
<em>ссылки ведут на страницы скачивания с сайтов производителей. утилиты совершенно бесплатные</em><br />
Первым делом нужно скачать AVZ. <a href="http://z-oleg.com/avz4.zip">скачиваем тут</a></p>
<p>AVZ &#8211; обнаруживает и удаляет следующие виды вредоносного ПО:<br />
    *  SpyWare и AdWare<br />
    * Dialer (Trojan.Dialer)<br />
    * Троянских программ<br />
    * BackDoor модулей<br />
    * Сетевых и почтовых червей<br />
    * TrojanSpy, TrojanDownloader, TrojanDropper<br />
есть встроенная система обнаружения Rootkit, детектор клавиатурных шпионов (Keylogger) и троянских DLL, нейроанализатор, встроенный анализатор Winsock SPI/LSP настроек, встроенный анализатор открытых портов TCP/UDP, проверка и лечение потоков NTFS и множество вспомогательных сервисов по настройке, очистке, восстановлению системы.</p>
<p>Далее нам нужно скачать GMER 1.0.15.14972 <a href="http://www.gmer.net/#files">скачиваем тут</a></p>
<p>Основное назначение GMER это rootkit detector детектор rootkit и поиск скрытых процессов.</p>
<p>Теперь, когда все нужные инструменты для обнаружения и удаления у нас есть, надо научиться ими пользоваться.</p>
<p>Если у вас есть подозрения на заражение, то вам в первую очередь стоит отключить службу восстановления системы. Потом вам нужно подготовиться к скану AVZ. Для этого вам следует обновить базы AVZ, потом вам нужно отключить интернет, выгрузить ваш антивирус и фаервол (если есть), далее вам нужно запустить все браузеры, которыми вы пользуетесь. Теперь все готово к скану и можно запускать AVZ.<br />
<strong>Настройки для скана:</strong><br />
Область поиска &#8211; активный диск (на котором находится система) С &#8211; ставим галочку, можно поставить галки на все дисководы , так же должны стоять галочки на ПРОВЕРЯТЬ ЗАПУЩЕННЫЕ ПРОЦЕССЫ, ЭВРИСТИЧЕСКАЯ ПРОВЕРКА СИСТЕМЫ, ПОИСК ПОТЕНЦИАЛЬНЫХ УЯЗВИМОСТЕЙ.<br />
Далее на вкладке Типы файлов нужно выставить галки на ПОТЕНЦИАЛЬНО ОПАСНЫЕ ФАЙЛЫ, ПРОВЕРЯТЬ ПОТОКИ NFTS, ПРОВЕРЯТЬ АРХИВЫ<br />
На вкладке Параметры поиска нужно помимо тех галок, что стоят по умолчанию, проставить галки на ПОИСК ПОРТОВ ТРОЯНСКИХ ПРОГРАММ, АВТОМАТИЧЕСКИ ИСПРАВЛЯТЬ СИСТЕМНЫЕ ОШИБКИ, уровень эвристики нужно оставить на среднем.<br />
На вкладке МЕТОДИКА ЛЕЧЕНИЯ нужно поставить галку на ВЫПОЛНЯТЬ ЛЕЧЕНИЕ, последние два пункта прописать как &#8220;спросить у пользователя&#8221;<br />
Теперь можно запускать сканирование. В процессе сканирования AVZ будет обнаруживать и удалять вредоносные процессы. В конце будет полный отчет.<br />
После скана и лечения вам понадобиться перезагрузка компьютера, что вы должны будете сделать.</p>
<p>Если даже после манипуляций с AVZ у вас остались подозрения или вы просто хотите проверить компьютер на предмет полного отсутствия скрытых процессов и руткитов, то можете запустить скан GMER &#8211; ом. Для запуска скана вам нужно так же отключить интернет, и выгрузить все свои антивирусы и фаерволы.<br />
Перед запуском скана в главном окне GMER вам нужно проставить галочки на все типы файлов. Далее можно запускать скан.<br />
Если у вас в списке процессов не будет пометок красным цветом, то ваш компьютер полностью чист от скрытых вредоносных процессов, если GMER пометит какие-либо процессы красным, то вам нужно щёлкнуть правой кнопкой мыши на этом процессе и нажать на появившемся меню или остановку процесса или удаление.<br />
Описанные мною &#8211; это основные функции утилит, и расчитаны они на простых пользователей, и их как правило хватает для обнаружения и лечения. Если вы считаете, что не очень сильно разбираетесь в компьютерах, то ограничьтесь пожалуйста теми действиями, что тут описаны!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uma definição que me veio à cabeça sobre [T]DSS]]></title>
<link>http://bykillerxd.wordpress.com/2009/06/17/uma-definicao-que-me-veio-a-cabeca-sobre-tdss/</link>
<pubDate>Wed, 17 Jun 2009 18:53:53 +0000</pubDate>
<dc:creator>Killer XD</dc:creator>
<guid>http://bykillerxd.wordpress.com/2009/06/17/uma-definicao-que-me-veio-a-cabeca-sobre-tdss/</guid>
<description><![CDATA[Eu estava navegando normalmente pelo Tech Support Forum, apenas prestando atenção no modo em que ele]]></description>
<content:encoded><![CDATA[Eu estava navegando normalmente pelo Tech Support Forum, apenas prestando atenção no modo em que ele]]></content:encoded>
</item>
<item>
<title><![CDATA[Vírus, Spyware e afins]]></title>
<link>http://toniinfocorp.wordpress.com/2009/06/17/virus-spyware-e-afins/</link>
<pubDate>Wed, 17 Jun 2009 05:57:07 +0000</pubDate>
<dc:creator>toniinfo</dc:creator>
<guid>http://toniinfocorp.wordpress.com/2009/06/17/virus-spyware-e-afins/</guid>
<description><![CDATA[Diariamente milhares de computadores são infectados por alguma &#8220;praga virtual&#8220;. Mas]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;">Diariamente milhares de computadores são infectados por alguma &#8220;<strong>praga virtual</strong>&#8220;. Mas&#8230; Você sabe diferência-las?<br />
Neste <em>post</em> vamos falar um pouco sobre estas pragas e difini-las&#8230;</p>
<p><em><span style="color:#ff0000;"><strong>Malware</strong></span></em><span style="color:#ff0000;">:</span></p>
<p style="text-align:justify;">Combinação das palavras inglesas <em>malicious</em> e <em>software</em>, ou seja, programas maliciosos. São programas e comandos feitos para diferentes propósitos: apenas infiltrar um computador ou sistema, causar danos e apagar dados, roubar informações, divulgar serviços, etc. Desta forma, <em>malware </em>engloma programas maliciosos e invasivos.</p>
<p style="text-align:justify;">Geralmente atuam no computador sem que o usuário o perceba.</p>
<p>Os <em>malwares </em>se dividem em outras categorias, e provavelmente vão continuar se dividindo à medida que malfeitores descobrirem e inventarem novas maneiras de ataques a computadores. Essas categorias incluem vírus, <em>worms</em>, <em>trojans</em>, <em>rootkits</em>, <em>spywares</em>, <em>adwares </em>e outras categorias menos conhecidas.</p>
<p><img class="aligncenter size-thumbnail wp-image-1613" title="Segurança da Informação" src="http://toniinfocorp.wordpress.com/files/2009/06/seguranca-da-informacao.jpg?w=150" alt="Segurança da Informação" width="150" height="148" /></p>
<ul>
<li><strong><span style="color:#ffff00;">Vírus:</span></strong></li>
</ul>
<p style="text-align:justify;">Os vírus são os programas mais utilizados para causar danos, roubar informações, etc.</p>
<p style="text-align:justify;">Eles se diferenciam dos outros <em>malwares </em>por sua capacidade de infectar um sistema, fazer cópias de si mesmo e tentar se espalhar para outros computadores, da mesma maneira que um vírus biológico faz.</p>
<p style="text-align:justify;">Vírus são típicos de arquivos anexos de emails. Isso acontece porque quase sempre é necessário que um vírus seja acionado através de uma ação do usuário.</p>
<p style="text-align:justify;">Um dos vírus mais perigosos já registrados foi o “ILOVEYOU”, uma carta de amor que se espalhou por email e é considerada responsável pela perda de mais de cinco bilhões de dólares em diversas empresas.</p>
<ul>
<li><strong><span style="color:#ffff00;"><em>Worm</em>:</span></strong></li>
</ul>
<p style="text-align:justify;">Trata-se de um programa malicioso que se utiliza de uma rede para se espalhar por vários computadores sem que nenhum usuário interfira neste processo (aí está a diferença entre vírus e <em>worm</em>).</p>
<p style="text-align:justify;">Os <em>worms </em>(verme, em inglês) são perigosos pois podem ser disparados, aplicados e espalhados em um processo totalmente automático e não precisar se anexar a nenhum arquivo para isso. Enquanto vírus buscam modificar e corromper arquivos, os <em>worms</em>, costumam consumir banda de uma rede.</p>
<ul>
<li><strong><span style="color:#ffff00;"><em>Trojan</em>:</span></strong></li>
</ul>
<p style="text-align:justify;"><em>Trojan</em>, forma abreviada de <em>Trojan Horse</em> (cavalo de tróia, em português), é um conjunto de funções desenvolvido para executar ações indesejadas e escondidas. Pode ser, por exemplo, um arquivo que você baixou como um protetor de telas, mas, depois da instalação, diversos outros programas ou comandos também foram executados.</p>
<p style="text-align:justify;">Isso significa que nem todo trojan prejudica um computador, pois, em alguns casos, ele apenas instala componentes dos quais não temos conhecimento, forçadamente. Daí a relação com o cavalo de tróia, historicamente falando. Você recebe um conteúdo que acha ser uma coisa, mas ele se desenrola em outras coisas que você não esperava ou não foi alertado.</p>
<ul>
<li><strong><span style="color:#ffff00;"><em>Rootkits</em>:</span></strong></li>
</ul>
<p style="text-align:justify;">Os <em>rootkits </em>englobam alguns dos mais escabrosos <em>malwares </em>já conhecidos. Isso porque eles tentam obter o controle de um sistema operacional sem o consentimento do usuário e sem serem detectados.</p>
<p style="text-align:justify;">O grande &#8220;mérito&#8221; do rootkit é sua capacidade de se esconder de quase todos os programas antivírus através de um avançado código de programação. Mesmo que um arquivo rootkit seja encontrado, em alguns casos ele consegue impedir que você o delete. Em resumo, os rootkits são a maneira mais eficiente para invadir um sistema sem ser pego.</p>
<ul>
<li><strong><span style="color:#ffff00;"><em>Spyware</em>:</span></strong></li>
</ul>
<p style="text-align:justify;">Spy, em inglês, significa espião, e foi com essa característica que os spywares surgiram. No começo, os spywares monitoravam páginas visitadas e outros hábitos de navegação para informar os autores. De posse dessas informações, tais autores podiam atingir os usuários com mais eficiência em propagandas, por exemplo.</p>
<p style="text-align:justify;">Porém, com o tempo, os <em>spywares </em>também foram utilizados para roubo de informações pessoais (como logins e senhas) e também para a modificação de configurações do computador (como página home do seu navegador).</p>
<ul>
<li><span style="color:#ffff00;"><strong><em>Adware</em>:</strong></span></li>
</ul>
<p style="text-align:justify;">Geralmente não prejudica seu computador, mas te enche o saco, com certeza. <em>Adwares </em>são programas que exibem, executam ou baixam anúncios e propagandas automaticamente e sem que o usuário possa interferir.</p>
<p style="text-align:justify;">Hoje, os adwares são considerados como uma categoria de software, diferenciando-se de freewares (programas gratuitos) e <em>demos </em>ou <em>trials </em>(programas para testar), uma vez que eles têm a intenção de divulgação, e não de prejudicar um computador.</p>
<p>Bom&#8230;</p>
<p>Estes são as principais categorias de <em>malwares </em>existentes!<br />
Fique atento e previna-se!   =]</p>
<h6><span style="color:#999999;">[Fonte: Baixaki]</span></h6>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft To Launch Free Anti-virus Named ‘Morro’ Soon]]></title>
<link>http://balgates.wordpress.com/2009/06/12/microsoft-to-launch-free-anti-virus-named-%e2%80%98morro%e2%80%99-soon/</link>
<pubDate>Fri, 12 Jun 2009 13:27:21 +0000</pubDate>
<dc:creator>Bala</dc:creator>
<guid>http://balgates.wordpress.com/2009/06/12/microsoft-to-launch-free-anti-virus-named-%e2%80%98morro%e2%80%99-soon/</guid>
<description><![CDATA[Microsoft Corp in a quest to provide complete security to its OS users would soon be launching its o]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Microsoft Corp in a quest to provide complete security to its OS users would soon be launching its own antivirus app Code named-‘Morro’. Microsoft also informed that the early version of the product is currently tested by its employees and would soon make a beta product available online before going for a launch at the end of 2009.</p>
<div id="attachment_388" class="wp-caption aligncenter" style="width: 330px"><img src="http://balgates.wordpress.com/files/2009/06/morro2.jpg" alt="The Anti-Virus Software" title="Morro" width="320" height="320" class="size-full wp-image-388" /><p class="wp-caption-text">The Anti-Virus Software</p></div>
<p>Anti-virus app ‘Morro’ would provide full–time protection from several types of malicious software including viruses, spyware, rootkits and trojans .Although many are terming it as stripped down version of earlier shelved Live OneCare.</p>
<p>This news assumes significance as this antivirus would be completely free and would provide higher level of security due to close knit approach with Windows OS.Microsoft may be able to provide a great solution due to control over anonymous usage statistics of millions of PC’s.</p>
<p>This has sound alarms for commercial Anti-virus companies like Symantec,kaspersky and McAfee, earning majority of their revenues by protecting Windows PCs all these years. These companies also has significant presence in enterprise security market and attracts huge revenues from it.</p>
<p>Today many users are forced to buy paid anti-virus to fight higher level of threats unleashed by malicious programmes and viruses.The availability of anti-virus app by Microsoft itself would avoid the security dilemma faced by OS users and may also increase its legal OS sales in emerging markets.</p>
<p>Microsoft through this initiative is trying to ramp up confidence amongst its customers, at the same time opening up a new revenue stream in future.The move may be late timed but indeed serve great purpose for users craving about better anti-virus integration in windows OS.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bravia Postcard: Spam war gestern]]></title>
<link>http://11tech.wordpress.com/2009/05/26/bravia-postcard-spam-war-gestern/</link>
<pubDate>Tue, 26 May 2009 06:31:24 +0000</pubDate>
<dc:creator>jirmann</dc:creator>
<guid>http://11tech.wordpress.com/2009/05/26/bravia-postcard-spam-war-gestern/</guid>
<description><![CDATA[Faszinierend, wie im vermeintlichen Dienst an der Menschheit Produkte und Services entwickelt werden]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://11tech.wordpress.com/files/2009/05/sony_bravia_postcard.jpg"><img class="alignleft size-medium wp-image-1839" title="sony_bravia_postcard" src="http://11tech.wordpress.com/files/2009/05/sony_bravia_postcard.jpg?w=300" alt="sony_bravia_postcard" width="300" height="209" /></a>Faszinierend, wie im vermeintlichen Dienst an der Menschheit Produkte und Services entwickelt werden, die der jeweilige Erfinder für einen Segen halten mag, bei deren Präsentation aber alle anderen &#8220;Oh weh&#8221; schreien.</p>
<p>Zumindest geht&#8217;s mir so, wenn ich sehe, was sich Sony für seine Bravia-Fernseher gerade wieder ausgedacht hat &#8211; zum Glück nur für Japan.<!--more--></p>
<p>Dort nämlich soll es möglich sein, dass die stolzen Besitzer besagter TV-Geräte digitale Postkarten von Gott und der Welt &#8211; nein, halt &#8211; nur von bestimmten Sony-Handys (wer hätte das gedacht?) empfangen könne.</p>
<p>Voraussetzung ist allein ein Bravia mit Internetzugang, und schon kommen die Bravia Postcards ins Haus geflattert.</p>
<p>Aber ach, wird es bei dem nett gemeinten Urlaubsgruß bleiben, den man am Bildschirm empfangen, lesen, vergrößern und mittels Fernbedienung beantworten kann?</p>
<p>Wird es nicht vielmehr so sein, dass dann auch im heimischen Wohnzimmer in die Meldungen des Tagesschausprechers Mitteilungen hereinplatzen, die mitnichten Botschaften von den Lieben in der Ferne sind, sondern Werbung für die Vergrößerung der primären Geschlechtsorgane? Nachher auch noch mit NSFW-Bildmaterial illustriert? Zumal der Dienst auch noch gratis ist?</p>
<p>Ich sag erstmal: Sony, hinsetzen, nachdenken! Das Root Kit war schon nix, aber hier sehe ich echte Katastrophen auf die Kunden zurollen. Zum Glück erstmal nur in Japan, wie gesagt. [dieter]</p>
<p>[via <a href="http://www.crunchgear.com/2009/05/25/sony-japan-integrates-postcard-function-into-bravia-tvs/" target="_blank">CrunchGear</a>]</p>
<p><a href="http://11tech.wordpress.com/files/2009/05/sony_bravia_postcard2.png"><img class="alignleft size-full wp-image-1840" title="sony_bravia_postcard2" src="http://11tech.wordpress.com/files/2009/05/sony_bravia_postcard2.png" alt="sony_bravia_postcard2" width="305" height="322" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Panda Anti-Rootkit:detectar y eliminar rootkits.]]></title>
<link>http://panaceapc.com/2009/05/25/panda-anti-rootkitdetectar-y-eliminar-rootkits/</link>
<pubDate>Mon, 25 May 2009 17:38:51 +0000</pubDate>
<dc:creator>panaceapc</dc:creator>
<guid>http://panaceapc.com/2009/05/25/panda-anti-rootkitdetectar-y-eliminar-rootkits/</guid>
<description><![CDATA[Panda Anti-Rootkit es un programa gratuito y portable(no requiere instalacion)que analizara tu siste]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong><img class="alignright size-medium wp-image-3817" title="panda" src="http://panaceapc.wordpress.com/files/2009/05/panda1.jpg?w=300" alt="panda" width="289" height="179" />Panda Anti-Rootkit</strong> es un programa <strong>gratuito</strong> y portable(no requiere instalacion)que analizara tu sistema en busca de <a href="http://es.wikipedia.org/wiki/Rootkit">Rootkits</a> y en caso de encontrarlos poder eliminarlos.Un programa muy sencillo para mantenerte alerta de este tipo de amenazas.</p>
<p><a href="http://www.download.com/Panda-Anti-Rootkit/3000-2239_4-10717196.html?part=dl-PandaAnti&#38;subj=dl&#38;tag=button">descargar Panda Anti-Rootkit</a></p>
<p>visto en:<a href="http://www.bloginformatico.com/panda-anti-rootkit-programa-gratuito-para-eliminar-rootkits.php">bloginformatico</a></p>
<p><a href="http://bitacoras.com/anotaciones/http://panaceapc.com/2009/05/25/panda-anti-rootkitdetectar-y-eliminar-rootkits/"></a></p>
<p><a href="http://bitacoras.com/anotaciones/http://panaceapc.com/2009/05/25/panda-anti-rootkitdetectar-y-eliminar-rootkits/"><img style="vertical-align:middle;border:0;" title="Votar esta anotación en Bitacoras.com" src="http://widgets.bitacoras.com/votar/mini/http://panaceapc.com/2009/05/25/panda-anti-rootkitdetectar-y-eliminar-rootkits/" alt="votar" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rootkits de cuarta generación]]></title>
<link>http://writeonlymode.wordpress.com/2009/05/24/rootkits-de-cuarta-generacion/</link>
<pubDate>Sun, 24 May 2009 08:02:04 +0000</pubDate>
<dc:creator>igandekoa</dc:creator>
<guid>http://writeonlymode.wordpress.com/2009/05/24/rootkits-de-cuarta-generacion/</guid>
<description><![CDATA[Microsoft Inc. forma parte de la conspiración mundial, del contubernio, del Número de la Bestia y de]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignleft size-full wp-image-240" title="Rootkitcode" src="http://writeonlymode.wordpress.com/files/2009/05/rootkitcode.jpg" alt="Rootkitcode" width="400" height="242" />Microsoft Inc. forma parte de la conspiración mundial, del contubernio, del Número de la Bestia y de toda suerte de manejos relacionados con ese comodín mediático que denominamos el Eje del Mal, otorgándole después el significado que mejor convenga. Pero no por sus oscuras manipulaciones para limitar la competrencia empresarial, porque de eso nadie se ve libre ni justificado para lanzar la primera piedra. Todos, salvo Linus Torvalds, han sido cocineros antes que monjes. Y algunos incluso madamas de burdel. No, lo que convierte a los sistemas operativos de Microsoft en un <em>heile Welt</em> burgués apoyado sobre cimientos tenebrosos es la conjunción de dos hechos que constituyen el signo de los tiempos: primero, casi todo el mundo tiene Windows 2000, XP o Vista instalado en su ordenador, y lo utiliza para casi todo: el ocio, el trabajo, los negocios, las relaciones interpersonales y la seguridad nacional. Segundo, los sistemas poseen unas determinadas características de diseño y funcionamiento (hasta cierto punto inevitables) que los hacen vulnerables al ataque de los <a href="http://www.baquia.com/noticias.php?id=10363">rootkits</a>.</p>
<p>¿Hemos leído bien? ¿Nos está diciendo que los virus no son la principal lacra del universo Windows? Pues eso, ni más ni menos. Los virus, la publicidad no deseada y el spam se combaten mal que bien con la prudencia del usuario y software especializado. Pero para comprender lo que significa la amenaza de los rootkits, imagine que su ordenador le miente ocultando archivos o falseando la cifra sobre espacio disponible en el disco duro, que le espía y le roba sus datos, que cuando usted no mira realiza tareas de fondo a las órdenes de una red delictiva o de una agencia gubernamental. Imagínese que no hay modo de detectarlo, salvo llamando a la experta en software maligno Joanna Rutkowska, de la empresa <a href="http://www.invisiblethings.org/">Invisible Things</a>. Entonces sí que comenzará a preocuparse.</p>
<p>Los primeros rootkits fueron diseñados a finales de los 80 del siglo pasado para sistemas Unix, y consistían en versiones modificadas de comandos típicos como &#8216;ls&#8217; o &#8216;ps&#8217;, que al ser ejecutados ocultaban los archivos y procesos del pirata. Para protegerse de ellos los administradores solían comparar los programas instalados con listas de hashes o utilizar comandos &#8216;limpios&#8217; desde diskettes o CD-ROMs. Hacia el cambio de milenio comenzaron a extenderse los denominados rootkits de segunda generación, en los que se modificaba el flujo de ejecución a base de alterar las estructuras de datos del kernel, más difíciles de detectar, ya que el sistema engañaba al usuario aun estando limpios los comandos.</p>
<p>Los rootkits de tercera generación, mucho más recientes, son capaces de alterar las estructuras de datos del kernel de modo dinámico, modificando la memoria a través del objeto //PhysicalMemoryDevice. Finalmente existe una cuarta generación de software malicioso, descubierto en 2006, que explota las características hardware de virtualización de los nuevos procesadores de AMD, funcionando en modo hipervisor por debajo del propio sistema operativo. Asi, un rootkit como <a href="http://en.wikipedia.org/wiki/Blue_Pill_(malware)">blue pill</a>, diseñado por <a href="http://en.wikipedia.org/wiki/Joanna_Rutkowska">Joanna Rutkowska </a>para MS-Vista, podría atrapar una instancia en ejecución del sistema operativo en una máquina virtual, actuando como <a href="http://es.wikipedia.org/wiki/Hipervisor">hipervisor</a> y obteniendo un control absoluto de la máquina. La única defensa practicable contra este tipo de rootkits consiste en desactivar en la BIOS las extensiones de virtualización.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online Malware Scanners &ndash; An Extra Layer of Protection]]></title>
<link>http://billmullins.wordpress.com/2009/05/20/online-malware-scanners-an-extra-layer-of-protection/</link>
<pubDate>Wed, 20 May 2009 15:43:56 +0000</pubDate>
<dc:creator>Bill Mullins</dc:creator>
<guid>http://billmullins.wordpress.com/2009/05/20/online-malware-scanners-an-extra-layer-of-protection/</guid>
<description><![CDATA[ The one thing we know for sure about today’s malware is; it’s very smart. It’s so smart that it oft]]></description>
<content:encoded><![CDATA[ The one thing we know for sure about today’s malware is; it’s very smart. It’s so smart that it oft]]></content:encoded>
</item>
<item>
<title><![CDATA[a-squared Emergency USB Stick 4.5.0.1]]></title>
<link>http://dinucody.wordpress.com/2009/05/15/a-squared-emergency-usb-stick-4-5-0-1/</link>
<pubDate>Fri, 15 May 2009 10:42:12 +0000</pubDate>
<dc:creator>Alin</dc:creator>
<guid>http://dinucody.wordpress.com/2009/05/15/a-squared-emergency-usb-stick-4-5-0-1/</guid>
<description><![CDATA[&#160;&#160; Scriam cu ceva vreme in urma pe aici despre acest program antispyware excelent si iata ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>&#160;&#160; Scriam cu ceva vreme in urma pe <a href="http://dinucody.wordpress.com/2009/01/28/a-squared-free-40038/">aici</a> despre acest program antispyware excelent si iata ca intre timp a aparut o noua versiune care pe langa faptul ca aduce diverse imbunatatiri vine si in versiunea portabila pentru USB-uri .</p>
<p><a href="http://dinucody.files.wordpress.com/2009/05/asquared.jpg"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="a-squared" border="0" alt="a-squared" src="http://dinucody.files.wordpress.com/2009/05/asquared_thumb.jpg?w=659&#038;h=459" width="659" height="459" /></a> </p>
<p><a href="http://dinucody.files.wordpress.com/2009/05/asquared2.jpg"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="a-squared2" border="0" alt="a-squared2" src="http://dinucody.files.wordpress.com/2009/05/asquared2_thumb.jpg?w=659&#038;h=456" width="659" height="456" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NTVDM ha rilevato un errore di sistema...]]></title>
<link>http://unpodimondo.wordpress.com/2009/05/12/ntvdm-ha-rilevato-un-errore-di-sistema/</link>
<pubDate>Tue, 12 May 2009 12:22:56 +0000</pubDate>
<dc:creator>unpodimondo</dc:creator>
<guid>http://unpodimondo.wordpress.com/2009/05/12/ntvdm-ha-rilevato-un-errore-di-sistema/</guid>
<description><![CDATA[Foto &quot;die computer die 2.22.07&quot; by kmevans - flickr
Da alcune settimane, quando sul mio pc]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div class="wp-caption alignnone" style="width: 510px"><img title="die computer die 2.22.07" src="http://farm1.static.flickr.com/163/399406599_4ff46da682.jpg" alt="Foto die computer die 2.22.07 by kmevans - flickr" width="500" height="375" /><p class="wp-caption-text">Foto &#34;die computer die 2.22.07&#34; by kmevans - flickr</p></div>
<p style="text-align:justify;">Da alcune settimane, quando sul mio pc lanciavo delle vecchie applicazioni DOS a 16 bit, mi appariva il seguente messaggio:</p>
<p style="text-align:justify;"><span style="color:#ff0000;"><strong>NTVDM ha rilevato un errore di sistema.<br />
NTVDM ha rilevato un errore di sistema c0h. Scegliere &#8220;Chiudi&#8221; per terminare.</strong></span></p>
<p style="text-align:justify;"><span style="color:#000000;">Dopo aver fatto un po&#8217; di ricerche a vuoto, sono riuscito a scoprire che ero stato infettato da un rognosissimo Master Boot Record <a href="http://it.wikipedia.org/wiki/Rootkit" target="_blank">&#8220;rootkit&#8221;</a></span> che colpisce soprattutto utenti italiani e cechi e che potrebbe essere installato da qualche script malevolo preso da Internet&#8230;</p>
<p style="text-align:justify;">Per la loro natura i rootkit sono particolarmente difficili da trovare e infatti,  come potete leggere da Wikipedia:</p>
<blockquote>
<p style="text-align:justify;">Un rootkit [...] è un programma software creato per avere il controllo completo sul sistema senza bisogno di autorizzazione da parte di utente o amministratore. Recentemente alcuni virus informatici si sono avvantaggiati della possibilità di agire come rootkit (processo, file, chiave di registro, porta di rete) all&#8217;interno del sistema operativo. [...] I rootkit sono molto difficili da rilevare e da rimuovere con i normali software Antivirus.</p>
<p style="text-align:right;"><a href="http://it.wikipedia.org/wiki/Rootkit" target="_blank"><em>tratta dalla voce &#8220;Rootkit&#8221; su Wikipedia</em></a></p>
</blockquote>
<p style="text-align:justify;">Pur avendo l&#8217;antivirus aggiornatissimo e passando spesso vari antispyware e altri software, se non avessi ricevuto i messaggi dell&#8217;NTVDM, non mi sarei mai accorto di essere stato infettato. Non vi sto ad elencare tutta la trafila che ho fatto, ma vi segnalo i siti e i  software che ho usato per la rimozione&#8230;</p>
<ul>
<li>Ho capito di essere stato infettato dal roootkit leggendo questo post sul forum di <a href="http://www.howtofixcomputers.com/forums/windows-xp/ntvdm-error-c0h-232704.html" target="_blank">How to fix computers</a>.</li>
<li>Ho trovato le istruzioni e i link ai software per  rimuovere il rootkit sul forum di <a href="http://www.hwupgrade.it/forum/showthread.php?t=1715546" target="_blank">Hardware Upgrade</a> e ringrazio vivamente l&#8217;autore delle note, il tecnico  Marco Giuliani alias Eraser (Malware Analyst per Prevx).</li>
<li>Dopo le opportune verifiche sulla pulizia del pc, ho installato su Firefox l&#8217;estensione <a href="https://addons.mozilla.org/it/firefox/addon/722#reviews" target="_blank">&#8220;No script&#8221;</a> che dovrebbe aumentare la sicurezza tenendo sottocontrollo gli script che si incontrano navigando, ma al momento mi sembra un po&#8217; troppo invadente e limitante per la navigazione (compreso l&#8217;aggiornamento di questo blog). Farò un po&#8217; di rodaggio e poi vi farò sapere se l&#8217;estensione funziona oppure no&#8230;</li>
</ul>
<p>Grazie a chi, tramite i forum, mi ha dato una mano.</p>
<p style="text-align:justify;">
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Análisis de las copias pirata de Windows 7]]></title>
<link>http://lanoticiatecnologicadelasemana.wordpress.com/2009/05/09/windows7pirata/</link>
<pubDate>Sat, 09 May 2009 15:35:20 +0000</pubDate>
<dc:creator>jlopez</dc:creator>
<guid>http://lanoticiatecnologicadelasemana.wordpress.com/2009/05/09/windows7pirata/</guid>
<description><![CDATA[Fecha: 10 de mayo de 2009
Desde antes de que el martes pasado se lanzara la RC (Release Candidate ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>Fecha: 10 de mayo de 2009</strong></p>
<p><img class="alignleft size-full wp-image-438" style="margin:10px;" title="windows-logo" src="http://lanoticiatecnologicadelasemana.wordpress.com/files/2009/05/windows-logo.jpg" alt="windows-logo" width="128" height="128" />Desde antes de que el martes pasado se lanzara la RC (<a href="http://es.wikipedia.org/wiki/Release_Candidate">Release Candidate &#8211; Versión Candidata</a>) oficial de Windows 7 que <a href="http://www.microsoft.com/windows/windows-7/download.aspx">se puede descargar e instalar de forma gratuita desde el website de Microsoft</a>, no han parado de aparecer por la red numerosas copias pirata de Windows 7 que son mucho más peligrosas de lo que pudiéramos sospechar en un principio.</p>
<p>En palabras de Joe Williams, Director General de Microsoft: &#8220;Durante los últimos días, hemos sabido que existen distibuciones clandestinas de Windows 7 destinadas a infectar el PC del cliente con virus&#8221;. El peligro que entrañan estas copias pirtata radica más en el codigo que se autoinstala que en las funcionalidades que pueda proporcionar en sí, ya que aunque estas no se ven limitadas en la mayoría de los casos, el usuario se autoinfecta al instalarlas sin saberlo.</p>
<p>Las distribuciones de Windows infectadas son por regla general las copias del Windows 7 RC (Release Candidate) que se descarga vía Torrent. El fichero descargado contiene un troyano embebido en el fichero setpup.exe que se autoextrae generando dos ficheros: setup.exe y codec.exe. El troyano está en el fichero codec.exe. En comentarios de algunos foros se ha identificado al troyano como Falder, un <a href="http://en.wikipedia.org/wiki/Scareware">scareware</a> que nos informa de que tenemos virus en el equipo y nos sugiere la descarga de un falso antivirus que se instala en el PC escondiéndose mediante un <a href="http://es.wikipedia.org/wiki/Rootkit">rootkit</a> de productos antivirus reales, permitiendo el manejo remoto del PC por parte del intruso. Falder es complicado de eliminar como se puede ver <a href="http://www.bleepingcomputer.com/forums/lofiversion/index.php/t43051.html%5B/t217346.html">aquí</a>.</p>
<p>Conviene destacar por otra parte, que Windows 7 y las nuevas actualizaciones de Vista, han cambiado el sistema antipiratería anterior de Microsoft (<a href="http://es.wikipedia.org/wiki/Ventajas_de_Windows_Original">WGA &#8211; Windows Genuine Advantage</a>) por un nuevo sistema denominado WAT (Windows Activation Technologies) que a grandes rasgos dejará un margen de 30 días a los usuarios en los que detecte copias ilegales del sistema opeartivo, tras lo cual empezará a desactivar funcionalidades del sistema operativo como Aero Glass, ReadyBoot o BitLocker. Microsoft espera disminuir el número de copias piratas del sistema operativo, que se estima en la actualidad en 1/3 del total de las que funcionan en PCs en todo el mundo. Esta nueva versión, según declaraciones de Microsoft, tiene en consideración demandas de los usuarios como la activación de las imagenes virtualizadas del sistema operativo o la activación de volúmenes para varios sistemas operativos, que no habían sido tenidas en cuenta por su predecesor WGA.</p>
<p>No obstante todo lo anterior, quien quiera descargar la última RC de Windows 7 lo puede hacer de forma segura desde <a href="http://www.microsoft.com/windows/windows-7/download.aspx">aquí</a>, y precisará de un PC con estos requerimientos mínimos:</p>
<ul>
<li>1 GHz processor (32- o 64-bits)</li>
<li>1 GB de RAM (32-bit); 2 GB de RAM (64-bit)</li>
<li>16 GB de espacio en el disco durao (32-bit); 20 GB de espacio en el disco duro (64-bit)</li>
<li>Dispositivo DirectX 9 de gráficos con WDDM 1.0 o superior.</li>
</ul>
<p>Por cierto que entre las curiosidades de este nuevo sistema operativo, yo destacaría el modo XP, que instala una máquina virtual XP con todos los requisitos, licencia incluida, y que se puede descargar desde <a href="http://www.microsoft.com/windows/virtual-pc/download.aspx">aquí</a> y permite funcionar como si tuviéramos instalado el sistema operativo XP. Lo curioso de esto es que existe modo XP y no exista modo Vista.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don&rsquo;t Have WOT (Web of Trust) Internet Browser Add-on? Then How Do You Know Where You Are on the Internet?]]></title>
<link>http://billmullins.wordpress.com/2009/05/08/dont-have-wot-web-of-trust-internet-browser-add-on-then-how-do-you-know-where-you-are-on-the-internet/</link>
<pubDate>Fri, 08 May 2009 14:58:12 +0000</pubDate>
<dc:creator>Bill Mullins</dc:creator>
<guid>http://billmullins.wordpress.com/2009/05/08/dont-have-wot-web-of-trust-internet-browser-add-on-then-how-do-you-know-where-you-are-on-the-internet/</guid>
<description><![CDATA[ Would you wander through a risky neighborhood that you were unfamiliar with? One which might possib]]></description>
<content:encoded><![CDATA[ Would you wander through a risky neighborhood that you were unfamiliar with? One which might possib]]></content:encoded>
</item>
<item>
<title><![CDATA[McAfee descobre rootkit que torna máquina vulnerável ao Conficker.]]></title>
<link>http://bykillerxd.wordpress.com/2009/05/07/mcafee-descobre-rootkit-que-torna-maquina-vulneravel-ao-conficker/</link>
<pubDate>Thu, 07 May 2009 17:53:14 +0000</pubDate>
<dc:creator>Killer XD</dc:creator>
<guid>http://bykillerxd.wordpress.com/2009/05/07/mcafee-descobre-rootkit-que-torna-maquina-vulneravel-ao-conficker/</guid>
<description><![CDATA[Um rootkit descoberto na semana passada pela McAfee está explorando arquivos executáveis e HTML comp]]></description>
<content:encoded><![CDATA[Um rootkit descoberto na semana passada pela McAfee está explorando arquivos executáveis e HTML comp]]></content:encoded>
</item>
<item>
<title><![CDATA[ Programadores desafiam “rootkit indetectavel”]]></title>
<link>http://juancarloscunha.wordpress.com/2009/05/06/programadores-desafiam-%e2%80%9crootkit-indetectavel%e2%80%9d/</link>
<pubDate>Wed, 06 May 2009 21:16:41 +0000</pubDate>
<dc:creator>juancarloscunha</dc:creator>
<guid>http://juancarloscunha.wordpress.com/2009/05/06/programadores-desafiam-%e2%80%9crootkit-indetectavel%e2%80%9d/</guid>
<description><![CDATA[Em prol disso, os Pesquisadores de segurança: Peter Ferrie (Symantec), Nate Lawson (Root Labs),
Dino]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Em prol disso, os Pesquisadores de segurança: Peter Ferrie (Symantec), Nate Lawson (Root Labs),<br />
Dino Dai Zovi e Thomas Ptacek (Matasano Security), criaram um desafio que ocorreria na conferencia Black Hat, porém a Rutkowska atribuiu condições.<br />
Rutkowska diz querer com 5 laptops para que as chances de detectar o Rootkit sejam diminuídas em 3%. Também exigiu que o software de detecção não use mais de 90% de CPU ou muito menos trave o computador de teste, também exigiu que o código-fonte das ferramentas de detecção seja divulgado a todos.<br />
A programadora fez uma exigência mais absurda, Pedindo a quantia de 384 mil dólares para pagar 2 pessoas para desenvolver o”Blue Pill( “Rootkit”).<br />
Um dos pesquisadores de segurança que criaram o desafio, diz: o detector levou um mês para desenvolver e analisa que, se o rootkit de Rutkowska levaria 12 meses (duas pessoas trabalhando seis meses), há uma clara vantagem na detecção. Ele acha que rootkits que funcionam na camada onde o Blue Pill opera são muito complicados de se desenvolver, e isto abre portas para meios de detecção.<br />
Rutkowska alega que o dinheiro necessário para pagar os custos de desenvolvimento do Blue Pill poderia ser facilmente obtido, considerando-se que virtualização é hoje um grande negócio e haveria muitas empresas interessadas em provar que não existem grandes riscos de segurança associados com a tecnologia.<br />
SAIBA MAIS SOBRE: <a href="http://www.bondfaro.com.br/categorias?id=6631&#38;lkout=1&#38;site_origem=7874647">ROOTKIT</a><br />
O desafio inicial proposto pelo grupo seria com apenas 2 <a href="http://www.bondfaro.com.br/categorias?id=6424&#38;lkout=1&#38;site_origem=7874647">laptops</a>. Rutkowska teria que infectar um deles com o Blue Pill. Se o detector de rootkit desenvolvido pelo grupo não funcionasse, ela poderia ficar com o laptop. O grupo aceitou todas as exigências adicionais feitas por ela, com exceção do dinheiro. “Por que nós pagaríamos 384 mil para comprar um rootkit que nós já sabemos que podemos detectar?”, escreveu Ptacek no blog da Matasano.<br />
O grupo de segurança irá desvendar e ilustrar suas descobertas e código gratuitamente na conferência <a href="http://www.bondfaro.com.br/categorias?id=2506&#38;lkout=1&#38;site_origem=7874647">Black Hat</a>, mesmo que Rutkowska não participe do desafio.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Watch your steps: Leaked copies of Windows 7 RC contain Trojan.....]]></title>
<link>http://smokeys.wordpress.com/2009/05/06/watch-your-steps-leaked-copies-of-windows-7-rc-contain-trojan/</link>
<pubDate>Wed, 06 May 2009 16:55:14 +0000</pubDate>
<dc:creator>Smokey</dc:creator>
<guid>http://smokeys.wordpress.com/2009/05/06/watch-your-steps-leaked-copies-of-windows-7-rc-contain-trojan/</guid>
<description><![CDATA[By ComputerWorld &#8211; Gregg Keizer  05 May
Pirated copies of Windows 7 Release Candidate (RC) on ]]></description>
<content:encoded><![CDATA[By ComputerWorld &#8211; Gregg Keizer  05 May
Pirated copies of Windows 7 Release Candidate (RC) on ]]></content:encoded>
</item>
<item>
<title><![CDATA[Rootkit Virut ajuda Conficker]]></title>
<link>http://alxmedeiros.wordpress.com/2009/04/28/rootkit-virut-ajuda-conficker/</link>
<pubDate>Tue, 28 Apr 2009 17:05:53 +0000</pubDate>
<dc:creator>alxmedeiros</dc:creator>
<guid>http://alxmedeiros.wordpress.com/2009/04/28/rootkit-virut-ajuda-conficker/</guid>
<description><![CDATA[Um rootkit descoberto na semana passada pela McAfee é capaz de explorar arquivos executáveis e HTML ]]></description>
<content:encoded><![CDATA[Um rootkit descoberto na semana passada pela McAfee é capaz de explorar arquivos executáveis e HTML ]]></content:encoded>
</item>

</channel>
</rss>
