<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Web watchers warn of new Storm attack</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/</link>
	<description>A SearchSecurity.com blog</description>
	<pubDate>Fri, 27 Nov 2009 10:45:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Apple User</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-361</link>
		<dc:creator>Apple User</dc:creator>
		<pubDate>Tue, 14 Aug 2007 00:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-361</guid>
		<description>And yet, all you IDIOTS just keep using Windoze! When will you wise up and join the masses already making a huge exodus to Macs?

You bring it on yourselve... really.

Have fun!</description>
		<content:encoded><![CDATA[<p>And yet, all you IDIOTS just keep using Windoze! When will you wise up and join the masses already making a huge exodus to Macs?</p>
<p>You bring it on yourselve&#8230; really.</p>
<p>Have fun!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin White</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-360</link>
		<dc:creator>Justin White</dc:creator>
		<pubDate>Mon, 13 Aug 2007 14:38:33 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-360</guid>
		<description>RE: *.exe’s DON’T belong in emails! and Windows People!
Just don’t open the attachment!
The exploit points them to a website via a link in the e-mail or the user must manually paste the url into a web browser. Their are no attachments or .exe's involved. Am I wrong??</description>
		<content:encoded><![CDATA[<p>RE: *.exe’s DON’T belong in emails! and Windows People!<br />
Just don’t open the attachment!<br />
The exploit points them to a website via a link in the e-mail or the user must manually paste the url into a web browser. Their are no attachments or .exe&#8217;s involved. Am I wrong??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: psiborg999</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-359</link>
		<dc:creator>psiborg999</dc:creator>
		<pubDate>Thu, 02 Aug 2007 03:45:22 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-359</guid>
		<description>This is really just a Microsoft exploit.
I use Linux ONLY and my antivirus (KLAMAV) fount it on-the-fly and quarantined it. No intervention was necessary.  Info as follows:

EXPLOIT:  Trojan.Small-3263

The payload file "ecard.exe" was sent in two different emails, both arriving within seconds of each other, from:

dgreetings.com and riversongs.com  

Set blocking filters accordingly.

Windows People!  
Just don't open the attachment!

*.exe's DON'T belong in emails!</description>
		<content:encoded><![CDATA[<p>This is really just a Microsoft exploit.<br />
I use Linux ONLY and my antivirus (KLAMAV) fount it on-the-fly and quarantined it. No intervention was necessary.  Info as follows:</p>
<p>EXPLOIT:  Trojan.Small-3263</p>
<p>The payload file &#8220;ecard.exe&#8221; was sent in two different emails, both arriving within seconds of each other, from:<br />
&nbsp;&lt;a href="http://dgreetings.com" title="http://dgreetings.<br />
" target="_blank"&gt;dgreetings.com&lt;/a&gt; and&nbsp;&lt;a href="http://riversongs.com" title="http://riversongs. " target="_blank"&gt;riversongs.com&lt;/a&gt;  </p>
<p>Set blocking filters accordingly.</p>
<p>Windows People!<br />
Just don&#8217;t open the attachment!</p>
<p>*.exe&#8217;s DON&#8217;T belong in emails!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-358</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Fri, 27 Jul 2007 14:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-358</guid>
		<description>Found this, found a way to remove it.  Here is goes.

1. Disable System Restore

2. Boot into safe mode (possibly didn't try doing it without) 

3. Once in safe mode go to device manager (in system properties) 

4. Click view and 'Show Hidden Devices'

5. Find the device under 'non plug and play devices' that looks suspicious, i've seen variants that start Windev - fourrandom characters - fourrandomcharacters, and some that start vdo - somethings - something

6.  Uninstall this device

7.  Browse to your C:\windows\system32 directory and find the file name that corresponds to the device that was shown in device manager and delete it

8.  Search the registry for that same string, and delete all references, there hsould be one in current config, and somewhere else I believe,


THis process worked for me, hopefully it will work for other people</description>
		<content:encoded><![CDATA[<p>Found this, found a way to remove it.  Here is goes.</p>
<p>1. Disable System Restore</p>
<p>2. Boot into safe mode (possibly didn&#8217;t try doing it without) </p>
<p>3. Once in safe mode go to device manager (in system properties) </p>
<p>4. Click view and &#8216;Show Hidden Devices&#8217;</p>
<p>5. Find the device under &#8216;non plug and play devices&#8217; that looks suspicious, i&#8217;ve seen variants that start Windev - fourrandom characters - fourrandomcharacters, and some that start vdo - somethings - something</p>
<p>6.  Uninstall this device</p>
<p>7.  Browse to your C:\windows\system32 directory and find the file name that corresponds to the device that was shown in device manager and delete it</p>
<p>8.  Search the registry for that same string, and delete all references, there hsould be one in current config, and somewhere else I believe,</p>
<p>THis process worked for me, hopefully it will work for other people</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stan</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-357</link>
		<dc:creator>Stan</dc:creator>
		<pubDate>Tue, 10 Jul 2007 12:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-357</guid>
		<description>Here is another variant - this one directs you to 76.111.xxx.xx

From : jtb@stpaul.com
Subject : Spyware Alert!

Dear Customer,

Our robot has detected an abnormal activity from your IP adress on sending e-mails. Probably it is connected with the last epidemic of a worm which does not have official patches at the moment.

We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked.

Abuse Team Robot</description>
		<content:encoded><![CDATA[<p>Here is another variant - this one directs you to 76.111.xxx.xx</p>
<p>From : &nbsp;&lt;a href="mailto:jtb@stpaul.com" title="mailto:jtb@stpaul.com"&gt;jtb at stpaul.com&lt;/a&gt;<br />
Subject : Spyware Alert!</p>
<p>Dear Customer,</p>
<p>Our robot has detected an abnormal activity from your IP adress on sending e-mails. Probably it is connected with the last epidemic of a worm which does not have official patches at the moment.</p>
<p>We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked.</p>
<p>Abuse Team Robot</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Storm malware posing as fake security warnings &#8212; Security Bytes</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-356</link>
		<dc:creator>Storm malware posing as fake security warnings &#8212; Security Bytes</dc:creator>
		<pubDate>Mon, 09 Jul 2007 12:47:07 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-356</guid>
		<description>[...] The Storm malware is using yet another trick in its endless push for world domination. Two weeks ago Storm passed itself off as a greeting card from family members to trick people into clicking on malicious URLs in their email inbox. Last week it tried to use patriotic messages to dupe people into getting infected. [...]</description>
		<content:encoded><![CDATA[<p>[...] The Storm malware is using yet another trick in its endless push for world domination. Two weeks ago Storm passed itself off as a greeting card from family members to trick people into clicking on malicious URLs in their email inbox. Last week it tried to use patriotic messages to dupe people into getting infected. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chris jarrett</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-355</link>
		<dc:creator>chris jarrett</dc:creator>
		<pubDate>Wed, 04 Jul 2007 18:42:02 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-355</guid>
		<description>Because it is a javascript exploit using the NoScript plugin for Firefox will prevent infection unless you click the link.  It will also cut down on lagging background scripting while making Firefox all that more secure.</description>
		<content:encoded><![CDATA[<p>Because it is a javascript exploit using the NoScript plugin for Firefox will prevent infection unless you click the link.  It will also cut down on lagging background scripting while making Firefox all that more secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Brenner</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-354</link>
		<dc:creator>Bill Brenner</dc:creator>
		<pubDate>Tue, 03 Jul 2007 11:05:45 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-354</guid>
		<description>I'm not 100% certain about how this might affect Linux, but everything I've been told so far indicates that this is primarily a problem for Windows users running either Internet Explorer or Firefox.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not 100% certain about how this might affect Linux, but everything I&#8217;ve been told so far indicates that this is primarily a problem for Windows users running either Internet Explorer or Firefox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chris jarrett</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-353</link>
		<dc:creator>chris jarrett</dc:creator>
		<pubDate>Mon, 02 Jul 2007 22:04:56 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-353</guid>
		<description>Will this exploit affect Firefox or just internet explorer and what about the affect of it on Linux and other alternate operating systems?</description>
		<content:encoded><![CDATA[<p>Will this exploit affect Firefox or just internet explorer and what about the affect of it on Linux and other alternate operating systems?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stan</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes/web-watchers-warn-of-new-storm-attack/#comment-352</link>
		<dc:creator>Stan</dc:creator>
		<pubDate>Mon, 02 Jul 2007 20:10:19 +0000</pubDate>
		<guid isPermaLink="false">http://security.blogs.techtarget.com/2007/06/29/web-watchers-warn-of-new-storm-attack/#comment-352</guid>
		<description>Here are two more IP's that are propagating this stuff.  

I got the domain names from   http://www.arin.net/whois/

this one is from Amsterdam - ripe.net
82.39.44.93 

this one is a USA Comcast address
24.3.223.219 

I haven't followed the links just made a note of them.</description>
		<content:encoded><![CDATA[<p>Here are two more IP&#8217;s that are propagating this stuff.  </p>
<p>I got the domain names from  &nbsp;&lt;a href="http://www.arin.net/whois/" title="http://www.arin.net/whois/" target="_blank"&gt;http://www.arin.net/whois/&lt;/a&gt;</p>
<p>this one is from Amsterdam -&nbsp;&lt;a href="http://ripe.net" title="http://ripe. " target="_blank"&gt;ripe.net&lt;/a&gt;<br />
82.39.44.93 </p>
<p>this one is a USA Comcast address<br />
24.3.223.219 </p>
<p>I haven&#8217;t followed the links just made a note of them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- dynamic -->