<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Downad/Conficker, who&#8217;s the April Fool?</title>
	<atom:link href="http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Thu, 11 Mar 2010 04:04:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: bodo unger</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-4063</link>
		<dc:creator>bodo unger</dc:creator>
		<pubDate>Fri, 08 Jan 2010 02:17:37 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-4063</guid>
		<description>The writer of the conficker virus is Mario Fiege a German in the Philippines. he is working with glavmed.com.stimul-cash.com , rx-promotion.com , spamit.com. He is pretending to be a russian in the internet while hacking domains,,hijacking forums and sending millions of email spam out of malware ghettos like asian.
He is using proxyway.com</description>
		<content:encoded><![CDATA[<p>The writer of the conficker virus is Mario Fiege a German in the Philippines. he is working with glavmed.com.stimul-cash.com , rx-promotion.com , spamit.com. He is pretending to be a russian in the internet while hacking domains,,hijacking forums and sending millions of email spam out of malware ghettos like asian.<br />
He is using proxyway.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 2010 – Year Of The Zombie Cloud? &#124; Business Computing World</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-4020</link>
		<dc:creator>2010 – Year Of The Zombie Cloud? &#124; Business Computing World</dc:creator>
		<pubDate>Wed, 16 Dec 2009 09:41:48 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-4020</guid>
		<description>[...] the first half of the year, the Conficker worm (also known as Downadup or Kido) stole all the headlines in the malware world. Eventually the [...]</description>
		<content:encoded><![CDATA[<p>[...] the first half of the year, the Conficker worm (also known as Downadup or Kido) stole all the headlines in the malware world. Eventually the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ReleaseTest &#187; Conficker with 10M victims, April 1 update soon</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-3863</link>
		<dc:creator>ReleaseTest &#187; Conficker with 10M victims, April 1 update soon</dc:creator>
		<pubDate>Mon, 12 Oct 2009 04:00:02 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-3863</guid>
		<description>[...] &#8220;The Conficker worm is going to change its operation a bit, but that&#8217;s unlikely to cause anything visible on 1 April,&#8221; F-Secure said. The company also noted that only the latest version of the malware, known as &#8216;Conficker C&#8217;, which constitutes a small percentage of total infections, would be carrying out any instructions on 1 April. &#8220;The truth is that Conficker is not set to activate a specific payload on 1 April. Rather, Conficker will begin to attempt to contact the 50,000-a-day potential call-home web servers from which it may receive updates.&#8221;  Malware creation has evolved into a lucrative business since Melissa, and most experts believe that Conficker&#8217;s update will be the first step in a spam run or other money-making activity, rather than an old-fashioned attempt at internet mayhem. &#8220;The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment,&#8221; wrote Trend Micro senior security advisor Rik Ferguson in a blog post. [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8220;The Conficker worm is going to change its operation a bit, but that&#8217;s unlikely to cause anything visible on 1 April,&#8221; F-Secure said. The company also noted that only the latest version of the malware, known as &#8216;Conficker C&#8217;, which constitutes a small percentage of total infections, would be carrying out any instructions on 1 April. &#8220;The truth is that Conficker is not set to activate a specific payload on 1 April. Rather, Conficker will begin to attempt to contact the 50,000-a-day potential call-home web servers from which it may receive updates.&#8221;  Malware creation has evolved into a lucrative business since Melissa, and most experts believe that Conficker&#8217;s update will be the first step in a spam run or other money-making activity, rather than an old-fashioned attempt at internet mayhem. &#8220;The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment,&#8221; wrote Trend Micro senior security advisor Rik Ferguson in a blog post. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 60 Minutes Conficker and Malware Report &#124; Software News Daily</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-3730</link>
		<dc:creator>60 Minutes Conficker and Malware Report &#124; Software News Daily</dc:creator>
		<pubDate>Wed, 16 Sep 2009 17:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-3730</guid>
		<description>[...] up harmful links that will in fact deliver the worm to the very people looking to remove it. In its detailed report of the different instances of Conficker, Trend Micro states that internet based virus scans will [...]</description>
		<content:encoded><![CDATA[<p>[...] up harmful links that will in fact deliver the worm to the very people looking to remove it. In its detailed report of the different instances of Conficker, Trend Micro states that internet based virus scans will [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twitter Trackbacks for Downad/Conficker, who’s the April Fool? » CounterMeasures [trendmicro.eu] on Topsy.com</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-3593</link>
		<dc:creator>Twitter Trackbacks for Downad/Conficker, who’s the April Fool? » CounterMeasures [trendmicro.eu] on Topsy.com</dc:creator>
		<pubDate>Mon, 24 Aug 2009 07:30:10 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-3593</guid>
		<description>[...] Downad/Conficker, who’s the April Fool? » CounterMeasures  countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool &#8211; view page &#8211; cached  A Trend Micro Blog. Rik Ferguson and others blog about security related issues &#8212; From the page [...]</description>
		<content:encoded><![CDATA[<p>[...] Downad/Conficker, who’s the April Fool? » CounterMeasures  countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool &ndash; view page &ndash; cached  A Trend Micro Blog. Rik Ferguson and others blog about security related issues &mdash; From the page [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joey</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-121</link>
		<dc:creator>joey</dc:creator>
		<pubDate>Wed, 01 Apr 2009 14:45:54 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-121</guid>
		<description>okay I also will Say this The Person who made is Is almost 85% sure using a IRC infection meted.. that sends cmds to a irc server.. by the maker ... IF its a private IRC then noone can find the orignal maker. of it.. No Matter what.. about the Data sending i don&#039;t think there will be.. maybe Just websites and a few others things to send the virus out to more people but thats about it..

And also it can be someone also on there pc like me .. typing away there life.. on a computer.. and Using there internet to connect to the victoms but most worms use IRC .... Newer ones.. so Yeah...

thanks for reading 

joey</description>
		<content:encoded><![CDATA[<p>okay I also will Say this The Person who made is Is almost 85% sure using a IRC infection meted.. that sends cmds to a irc server.. by the maker &#8230; IF its a private IRC then noone can find the orignal maker. of it.. No Matter what.. about the Data sending i don&#8217;t think there will be.. maybe Just websites and a few others things to send the virus out to more people but thats about it..</p>
<p>And also it can be someone also on there pc like me .. typing away there life.. on a computer.. and Using there internet to connect to the victoms but most worms use IRC &#8230;. Newer ones.. so Yeah&#8230;</p>
<p>thanks for reading </p>
<p>joey</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-99</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Tue, 31 Mar 2009 12:34:35 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-99</guid>
		<description>Hi Robert,

Yes, this is absolutely a recurring problem. If you have a machine that is infected, then in most cases it will not be possible to use that particular machine to download repair tools from most domains associated with security. The best course of action is to use a machine that is not infected to make the download, then use some kind of removable media to get the fix tools to the infected machine. Make sure that removable media is write-protected before you put it into the infected machine.</description>
		<content:encoded><![CDATA[<p>Hi Robert,</p>
<p>Yes, this is absolutely a recurring problem. If you have a machine that is infected, then in most cases it will not be possible to use that particular machine to download repair tools from most domains associated with security. The best course of action is to use a machine that is not infected to make the download, then use some kind of removable media to get the fix tools to the infected machine. Make sure that removable media is write-protected before you put it into the infected machine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Burntwing</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-97</link>
		<dc:creator>Robert Burntwing</dc:creator>
		<pubDate>Tue, 31 Mar 2009 11:53:31 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-97</guid>
		<description>If the virus is blocking AV sites, how would one download the sysclean tool from trend micro?</description>
		<content:encoded><![CDATA[<p>If the virus is blocking AV sites, how would one download the sysclean tool from trend micro?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Latest Antivirus Updates &#187; What Will Go DOWNAD on April 1?</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-88</link>
		<dc:creator>Latest Antivirus Updates &#187; What Will Go DOWNAD on April 1?</dc:creator>
		<pubDate>Mon, 30 Mar 2009 11:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-88</guid>
		<description>[...] Downad/Conficker, who’s the April Fool? [...]</description>
		<content:encoded><![CDATA[<p>[...] Downad/Conficker, who’s the April Fool? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: What Will Go DOWNAD on April 1?</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/comment-page-1/#comment-86</link>
		<dc:creator>What Will Go DOWNAD on April 1?</dc:creator>
		<pubDate>Mon, 30 Mar 2009 10:21:57 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311#comment-86</guid>
		<description>[...] Downad/Conficker, who’s the April Fool? [...]</description>
		<content:encoded><![CDATA[<p>[...] Downad/Conficker, who’s the April Fool? [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
