<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>techcosupport.com &#187; Malware</title>
	<atom:link href="http://techcosupport.com/press/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://techcosupport.com/press</link>
	<description>Techco Support Site - Helping your business grow through Technology, Training and Coaching</description>
	<lastBuildDate>Fri, 30 Dec 2011 10:40:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Bredolab Botnet Still Active</title>
		<link>http://techcosupport.com/press/bredolab-botnet-still-active/</link>
		<comments>http://techcosupport.com/press/bredolab-botnet-still-active/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 19:25:07 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=1012</guid>
		<description><![CDATA[<p>More Tax Payment malware news today, with a resurgence of the Bredolab botnet. </p> <p>Our MessageLabs Anti-Virus Service reported a suspicious email, similar to the Tax Spam Malware Warning yesterday. The message title once again was Your Tax Payment ID [Random Number] is failed</p> <p>This time Symantec reported it as Trojan.Bredolab, which is a likely <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/bredolab-botnet-still-active/">Bredolab Botnet Still Active</a></span>]]></description>
			<content:encoded><![CDATA[<p>More Tax Payment <strong>malware</strong> news today, with a resurgence of the <strong>Bredolab botnet</strong>.  </p>
<p>Our MessageLabs Anti-Virus Service reported a suspicious email, similar to the <a href="http://techcosupport.com/press/tax-spam-malware-warning/" title="Tax Spam Malware Warning" target="_blank">Tax Spam Malware Warning</a> yesterday.  The message title once again was Your Tax Payment ID [Random Number] is failed</p>
<p>This time Symantec reported it as Trojan.Bredolab, which is a likely resurfacing of a Bredolab botnet.</p>
<p>The Bredolab botnet was partially dismantled in November 2010 through the seizure by Dutch law enforcement agents of 143 command and control servers, effectively removing the botnet herder&#8217;s ability to control the botnet centrally.  Although the botnet&#8217;s size and capacity has been severely reduced by the law enforcement intervention.</p>
<p>A PC infected with Bredolab shows a number of effects as the malware:</p>
<ul>
<li>Downloads more malware on to the compromised computer</li>
<li>Lowers the security settings on the infected computer</li>
<li>May result in file deletion</li>
</ul>
<p>If your anti virus software or mail gateway informs you that it has detected Bredolab, follow the instructions and do not open any affected files.  To make sure that your machine does not get infected keep your anti virus software switched on and the signatures up to date.</p>
<p>Further resources </p>
<ul>
<li><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-052907-2436-99" title="Symantec Labs Trojan.Bredolab" target="_blank">Symantec Labs Trojan.Bredolab</a></li>
<li><a href="http://en.wikipedia.org/wiki/BredoLab_botnet" title="xxx" target="_blank">BredoLab botnet on Wikipedia</a></li>
<li><a href="http://www.zdnet.com/blog/security/dutch-police-shut-down-bredolab-botnet/7573" title="xxx" target="_blank">Dutch police shut down Bredolab botnet</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/bredolab-botnet-still-active/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/bredolab-botnet-still-active/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tax Spam Malware Warning</title>
		<link>http://techcosupport.com/press/tax-spam-malware-warning/</link>
		<comments>http://techcosupport.com/press/tax-spam-malware-warning/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 21:52:39 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Tax]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=1005</guid>
		<description><![CDATA[<p>The spam filters are currently working overtime catching dubious email messages about tax payments having failed. As you might expect, this is a Tax Spam Malware Warning, so take care before opening anything that tells you that Your Tax Payment failed.</p> <p>This email, which purports to be from US tax payment service Electronic Federal Tax <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/tax-spam-malware-warning/">Tax Spam Malware Warning</a></span>]]></description>
			<content:encoded><![CDATA[<p>The <strong>spam</strong> filters are currently working overtime catching dubious email messages about tax payments having failed. As you might expect, this is a <strong>Tax Spam Malware Warning</strong>, so take care before opening anything that tells you that Your Tax Payment failed.</p>
<p>This email, which purports to be from US tax payment service Electronic Federal Tax Payment System (EFTPS), claims that the recipient&#8217;s tax payment has been rejected due to a submission error. The message, which includes a sender address and link that are seemingly valid EFTPS addresses, asks the recipient to click a link in order to review details about the error. </p>
<p>Obviously the email is not from the EFTPS, and the link in the message has been disguised so that it appears to point to the genuine EFTPS website. In fact, it is a phishing scam designed to steal personal information from recipients. A sample of the email appear below:<br />
<code><br />
<blockquote>
Your Tax Payment ID [random number] is failed</p>
<p>Your Federal Tax Payment ID: 32127292 has been rejected.<br />
Return Reason Code R21 - The identification number used in the Company Identification Field is not valid.</p>
<p>Please, check the information  to get details about your company payment in transaction contacts section:</p>
<p>attach name = report.18653.pdf</p>
<p>In other way forward information to your accountant adviser.<br />
EFTPS:<br />
The Electronic Federal Tax Payment System<br />
PLEASE NOTE: Your tax payment is due regardless of EFTPS online availability. In case of an emergency, you can always make your tax payment by calling the EFTPS.</p></blockquote>
<p></code></p>
<p>Attempting to open the attached file will result in a malware loader executing.  This is detected by Sophos Anti-Virus as &#8216;Virus/Spyware Mal/FakeAV-OQ.</p>
<p>The gramatical errors should give you a clue to the bogus source of this Tax Spam Malware. Do not click on any links in this email or download any attachments. Flag as spam and press delete!</p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/tax-spam-malware-warning/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/tax-spam-malware-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Scripts Added To Websites</title>
		<link>http://techcosupport.com/press/malware-scripts-added-to-websites/</link>
		<comments>http://techcosupport.com/press/malware-scripts-added-to-websites/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 22:19:31 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=994</guid>
		<description><![CDATA[<p>A couple of our customers have experienced hacks to their websites this last week, with malicious code (or malware) added to several pages. Normal visitors to the site have a little extra script added when they load the page, which good antivirus software will identify as a malware script. Kaspersky Labs identifies the Trojan loader <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/malware-scripts-added-to-websites/">Malware Scripts Added To Websites</a></span>]]></description>
			<content:encoded><![CDATA[<p>A couple of our customers have experienced hacks to their <strong>websites</strong> this last week, with malicious code (or <strong>malware</strong>) added to several pages.  Normal visitors to the site have a little extra <strong>script</strong> added when they load the page, which good antivirus software will identify as a <strong>malware script</strong>.  Kaspersky Labs identifies the <strong>Trojan</strong> loader as Heur: Trojan <strong>Script</strong> Generic, which is a generic <strong>Trojan</strong> loader identified by a heuristic algorithm.  Alternatively, it may be identified as as Blackhole Exploit kit by other AV products.</p>
<p>Analysis of samples of the inserted code show some common strings, which can be used to find the script on an <strong>infected website</strong>.  This appears to have been inserted by an automated script loader, probably a bot using brute force to guess FTP passwords.</p>
<blockquote><p>
<code>< b o d y>< d i v id="w3stats"><br />
< s c r i p t language="JavaScript" type="text/javascript"><br />
<strong>window.w3ssss</strong>=function(){<br />
=== Script Link and other code removed ===<br />
CheckBody();<br />
< / s c r i p t >< / b o d y >< / h t m l ></code></p></blockquote>
<p>A quick Google search reveals that quite a few sites have had this little addition.  If you find that you have been infected, carry out the following actions as soon as possible:</p>
<ul>
<li>Search the code on each page for the string &#8220;window.w3ssss&#8221;</li>
<li>Remove the offending code from all of the pages where it has been installed</li>
<li>Change all your site passwords, including FTP</li>
<li>Monitor the site regularly for reinfection</li>
</ul>
<p>Thousands of website owners are unaware that their sites are hacked and infected with malware scripts.  Here are a few useful links to help:</p>
<ul>
<li><a href="https://www.google.com/search?q=window.w3ssss" title="Search Google for hacked sites" target="_blank">Search Google for hacked sites</a></li>
<li><a href="http://sitecheck.sucuri.net/scanner/" title="xxx" target="_blank">Free website malware &#038; blacklist scan</a></li>
<li><a href="http://www.unmaskparasites.com/" title="xxx" target="_blank">Check your site using Unmask Parasites</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/malware-scripts-added-to-websites/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/malware-scripts-added-to-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ACH Spam With Malware Attachment</title>
		<link>http://techcosupport.com/press/ach-spam-with-malware-attachment/</link>
		<comments>http://techcosupport.com/press/ach-spam-with-malware-attachment/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 20:05:01 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=922</guid>
		<description><![CDATA[<p>The spam filters have been busy over the last couple of days, with a number of Emails with the title of ACH NOTIFICATION and ACH Payment [Number] Rejected. In each case the email contains an attachment purporting to be a self extracting PDF file.</p> <p>Of course, on closer examination the supposed self extracting PDF file <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/ach-spam-with-malware-attachment/">ACH Spam With Malware Attachment</a></span>]]></description>
			<content:encoded><![CDATA[<p>The spam filters have been busy over the last couple of days, with a number of Emails with the title of ACH NOTIFICATION and ACH Payment [Number] Rejected.  In each case the email contains an attachment purporting to be a self extracting PDF file.</p>
<p>Of course, on closer examination the supposed self extracting PDF file is a malware down-loader, no doubt ready and waiting to connect you to one or more bot nets.  This is a common scenario with a spammed-out trojan down-loader triggering the execution of multiple pieces of malware on the unwitting user&#8217;s computer.  In this case, Sophos anti virus detects the file and identifies it as Mal/BredoZp-B.  For a detailed analysis of the activities of the spam payload, see the article on the ACH spam campaign by M86 security labs via the link below.</p>
<p>Automated Clearing House (ACH) is an electronic network for financial transactions in the United States.  As usual with this type of spam and associated malware, ACH have no connection with the email, so there is little point in blocking the sender&#8217;s address, in our case ach.01 at nacha.org.</p>
<p>Once again our advice is that you should not open any unexpected emails, or unsolicited attachments, as in this case it will attempt to infect your Windows computer.  Just press delete and double check that your anti-virus software is up to date.</p>
<p>Resources relating to ACH Spam With Malware Attachment:</p>
<ul>
<li><a href="http://techcosupport.com/spamsamples/AchNotification.html" title="Sample ACH Notification email (Deactivated)" target="_blank">Sample ACH Notification email (Deactivated)</a></li>
<li><a href="http://nakedsecurity.sophos.com/2011/08/30/fdic-notification-malware/" title="Sophos Naked Security blog entry FDIC notification malware attack spammed out" target="_blank">Sophos Naked Security blog entry FDIC notification malware attack spammed out</a></li>
<li><a href="http://labs.m86security.com/2011/09/an-analysis-of-the-ach-spam-campaign/" title=" M86 security labs analysis of the ACH spam campaign" target="_blank">M86 security labs analysis of the ACH spam campaign</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/ach-spam-with-malware-attachment/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/ach-spam-with-malware-attachment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uniform Traffic Ticket Malware Spam</title>
		<link>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/</link>
		<comments>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 20:20:31 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=887</guid>
		<description><![CDATA[<p>If you live anywhere except the City of New York you may have been surprised to receive an email recently, which claims to come from the New York State Department of Motor Vehicles. Even if you aren&#8217;t based in the United States, or even don&#8217;t drive a car, you may well see the posting which <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/">Uniform Traffic Ticket Malware Spam</a></span>]]></description>
			<content:encoded><![CDATA[<p>If you live anywhere except the City of New York you may have been surprised to receive an email recently, which claims to come from the New York State Department of Motor Vehicles.  Even if you aren&#8217;t based in the United States, or even don&#8217;t drive a car, you may well see the posting which poses as a &#8220;<strong>Uniform Traffic Ticket</strong>&#8221; and says that you are charged with speeding at 7:25 AM on the 5th July 2011.</p>
<p>People may be tempted to open the attachment out of curiosity, or even alarm if they have been driving in New York City, but do not, or you may end up with a computer infected with malware.  </p>
<p>However, the message is certainly not from New York State Police and the attachment does not contain a speeding ticket. In fact, the attachment contains a trojan that, if opened, can install itself on the user’s computer. Typically, such trojans are able to contact a remote server and download further malware that can steal information from the infected computer and allow criminals to control it from afar.</p>
<p>The email sender address has been reported as automailer.nnn, no-reply.nnn and info.nnn, all purportedly at nyc.gov.  It goes without saying that the New York State Police and the New York State Department of Motor Vehicles have nothing to do with this email, and this should be treated as all Viruses and Spyware.  The New York State Police Computer Crime Unit has issued a <strong>Hoax E-mail Alert</strong> dealing with the <strong>Uniform Traffic Ticket Malware Spam</strong>.</p>
<p>The attached file, which is called something like Ticket-O64-211.zip, Ticket-728-2011.zip, or just Ticket.zip, is designed to download further malicious code onto your computer and compromise your security.  Sophos anti-virus products detect the malware payload as Mal/ChepVil-A, while the CyberCrime &#038; Doing Time Blog identifies that the malware connects to a Russian domain and downloads files called &#8220;/ftp/g.php&#8221; and &#8220;pusk3.exe&#8221;.</p>
<p>The <strong>Uniform Traffic Ticket Malware Spam</strong> email is probably the work of a Botnet, which is a group of computers infected with malicious software and controlled as a group without the owners&#8217; knowledge.  The network of private computers, sometimes known as zombies or robots, run autonomously and automatically to send out spam emails to encourage users to open virus or Trojan infected attachments. This means that it is pointless blocking the sender, as the sender address is forged, and unrelated to the actual computer used to send the email. </p>
<p>We recommend that you delete the e-mail it and not forward it to anyone else. Make sure that you have active anti-virus software, and have your firewall switched on.  Of course you should only open e-mails from familiar and trusted sources;  if you really have been speeding in New York City, the New York State Department of Motor Vehicles will certainly find a way to let you know!</p>
<p>For further information on this subject:</p>
<ul>
<li><a href="http://garwarner.blogspot.com/2011/08/new-york-city-uniform-traffic-ticket.html" title="Click here to see an image of the email on CyberCrime &#038; Doing Time Blog" target="_blank">Click here to see an image of the email on CyberCrime &#038; Doing Time Blog</a></li>
<li><a href="http://www.facebook.com/SophosSecurity" title="Check out the Sophos Security Facebook page" target="_blank">Check out the Sophos Security Facebook page</a></li>
<li><a href="http://troopers.ny.gov/Public_Information/2011_News_Releases/07-06-11_Hoax_E-mail_Alert.cfm" title=" See the New York State Police Computer Crime Unit Hoax E-mail Alert" target="_blank">See the New York State Police Computer Crime Unit Hoax E-mail Alert</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of Emails Bearing Gifts</title>
		<link>http://techcosupport.com/press/beware-of-emails-bearing-gifts/</link>
		<comments>http://techcosupport.com/press/beware-of-emails-bearing-gifts/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 21:40:33 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[UPS Notification Virus]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=852</guid>
		<description><![CDATA[<p>Have you seen an email entitled UPS notification? Have you received an unexpected email telling you about a parcel sent your home address, when you have nothing on order? Do you feel excited at the thought of getting an unexpected gift?</p> <p>Unfortunately, that is not a mysterious present in the post, but a piece of <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/beware-of-emails-bearing-gifts/">Beware of Emails Bearing Gifts</a></span>]]></description>
			<content:encoded><![CDATA[<p>Have you seen an email entitled <strong>UPS notification</strong>? Have you received an unexpected email telling you about a parcel sent your home address, when you have nothing on order? Do you feel excited at the thought of getting an unexpected gift?</p>
<p>Unfortunately, that is not a mysterious present in the post, but a piece of malicious software, or malware, called the <strong>UPS Notification Virus</strong>. This is an automated attempt to install a Trojan on your computer, which is a piece of software that would connect to a medium risk domain in Russia and subsequently download all manner of undesirable additions to your computer.</p>
<p>If you are fortunate enough to operate behind a corporate firewall and email gateway this will be intercepted by the mail scanning software, and all you will get is an email with the subject line something like: <strong>WARNING. Someone tried to send you a potential virus or unauthorized code</strong>. If you see this message you need to do nothing further; the threat has been eliminated by the software.</p>
<p>At home, if you have up to date anti-virus software installed, you may see the email with an additional marker like [Quarantined], or a message from the anti-virus software manufacturers indicating that the threat has been removed. In this event you need to do nothing further except keep your anti-virus software current.</p>
<p>However, if you access your email by a webmail client, and do not subscribe to an anti virus service, then you may see an email in your inbox with the subject of <strong>UPS notification</strong>. Preview of the email will show you something like this:</p>
<blockquote><p>Dear customer.</p>
<p>The parcel was sent your home address.<br />
And it will arrive within 3 business day.</p>
<p>More information and the tracking number are attached in document below.</p>
<p>Thank you.<br />
© 1994-2011 United Parcel Service of America, Inc.</p></blockquote>
<p>In this event, <strong>DELETE</strong> the email and do not attempt to open the attachment. UPS may sometimes send emails, but generally does not include attachments. If you see this email on a company computer then please additionally inform the local ICT helpdesk, to alert them so that they can investigate how the message reached you.</p>
<p>Remember</p>
<ul>
<li>Only disclose your email address to known individuals and organizations</li>
<li>Only open email and attachments from known and trusted sources</li>
<li>If in doubt, check with your local IT department or support person if you are not sure that an email is genuine</li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/beware-of-emails-bearing-gifts/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/beware-of-emails-bearing-gifts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee Security Scan Problems</title>
		<link>http://techcosupport.com/press/mcafee-security-scan-problems/</link>
		<comments>http://techcosupport.com/press/mcafee-security-scan-problems/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 19:34:09 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[PC]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[Remove Security Scan]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=544</guid>
		<description><![CDATA[<p>It was reported by one of our Windows XP users that they were getting a message from McAfee Security Scan® with a request to Check My Security Status. As we protect all of our Windows PCs using McAfee, this message was not out of place, and the user clicked Scan Now. The alarm bells started <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/mcafee-security-scan-problems/">McAfee Security Scan Problems</a></span>]]></description>
			<content:encoded><![CDATA[<p>It was reported by one of our Windows XP users that they were getting a message from McAfee Security Scan® with a request to Check My Security Status.  As we protect all of our Windows PCs using McAfee, this message was not out of place, and the user clicked Scan Now.  The alarm bells started when the Security Scan reported that there was no anti-virus software installed, which just is not true.</p>
<p>A cursory glance (right click on the Shield in the system tools) shows that VirusScan Enterprise was alive and well on his machine, and the consol showed that the last auto-update was successful.  Initial attempts to uninstall the unwanted program using Control Panel, Add or Remove Programs were unsuccessful.  Googling the phrase <strong>How do I get rid of McAfee Security Scan</strong> turned up several suggestions involving booting into Safe Mode or installing anti-malware programs.  There were also several suggestions that McAfee Security Scan is downloaded with an update to Adobe Reader, which our user had recently installed.</p>
<p>This is the removal method which worked for us:</p>
<ul>
<li>Run <strong>msconfig</strong> using the Start, Run dialoge</li>
<li>When msconfig has loaded, click on the <strong>Startup</strong> tab</li>
<li>Find the entry for <strong>McAfee Security Scan</strong>, and uncheck the box</li>
<li>Then click on <strong>Apply</strong></li>
</ul>
<p>This will prevent the application from reloading next time you start up.  Next you need to uninstall the application:</p>
<ul>
<li>Call up <strong>Windows Task Manager</strong></li>
<li>Click on the <strong>Applications</strong> tab</li>
<li>Click on <strong>McAfee Security Scan</strong> then click the <strong>End Task</strong> button</li>
<li>Fire up <strong>Control Panel</strong> then double click <strong>Add or Remove Programs</strong></li>
<li>Wait a minute and McAfee Security Scan will relaunch and appear again in Task Manager, just like malware!</li>
<li>In Task Manager,  click <strong>McAfee Security Scan</strong>, then  <strong>End Task</strong> again</li>
<li>In Control Panel, immediately click <strong>Change</strong> for McAfee Security Scan, then <strong>Remove</strong></li>
</ul>
<p>If you have found this program installing itself without your conscious intent or consent we suggest that you voice your disapproval to Adobe.  If enough people post their disapproval of this forced installation of annoying software to Adobe, they might just change their policy.</p>
<p>To any Adobe directors reading this, let me be the first to admit that you market some brilliant software, which is a credit to your company.  Why risk your excellent corporate image with this offensive and shoddy software installation tactic?</p>
<p>For anyone else who is installing or upgrading Adobe Flash or Reader, take special note that there is an optional McAfee Scan listed in the installation that must be unchecked if you do not want to install McAfee Security Scan.</p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/mcafee-security-scan-problems/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/mcafee-security-scan-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Parliamentary computers infected by Conficker worm</title>
		<link>http://techcosupport.com/press/parliamentary-computers-infected-by-conficker-worm/</link>
		<comments>http://techcosupport.com/press/parliamentary-computers-infected-by-conficker-worm/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 17:33:28 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=280</guid>
		<description><![CDATA[<p>The House of Commons internal computer network has been infected by the &#8220;Conficker&#8221; worm and has had to ban its users from attaching outside storage, such as USB memory sticks, in case it gets reinfected. An estimated 10 million PCs worldwide have also been infected and experts fear next week will see problems worsen. For <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/parliamentary-computers-infected-by-conficker-worm/">Parliamentary computers infected by Conficker worm</a></span>]]></description>
			<content:encoded><![CDATA[<p>The House of Commons internal computer network has been infected by the &#8220;Conficker&#8221; worm and has had to ban its users from attaching outside storage, such as USB memory sticks, in case it gets reinfected.  An estimated 10 million PCs worldwide have also been infected and experts fear next week will see problems worsen. For more on this story, see the article <a href="http://www.guardian.co.uk/technology/2009/mar/27/conficker-downadup-parliament-virus-april-1"><strong>House of Commons network hit by Conficker computer worm</strong></a> from <a href="http://www.guardian.co.uk/">guardian.co.uk</a></p>
<p>If your computer is infected with this worm, you may not experience any symptoms, or you may experience any of the following symptoms: </p>
<ul>
<li>Account lockout policies are being tripped. </li>
<li>Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender, and Error Reporting Services are disabled. </li>
<li>Domain controllers respond slowly to client requests.</li>
<li>The network is congested. </li>
<li>Various security-related Web sites cannot be accessed. </li>
</ul>
<p>For more information about Win32/Conficker.b, visit the following Microsoft Malware Protection Center Web page <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker">http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker</a></p>
<p>Network managers can also stop Conficker from spreading by using Group Policy, and creating a policy that applies to all computers in a specific organizational unit (OU), site, or domain in your environment. For more details on this process see <a href="http://support.microsoft.com/kb/962007" title="Microsoft Help and Support Article ID 962007"><strong>Microsoft Help and Support Article ID 962007</strong></a></p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/parliamentary-computers-infected-by-conficker-worm/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/parliamentary-computers-infected-by-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

