<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Step by Step In Dealing With Conficker</title>
	<atom:link href="http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Sun, 14 Mar 2010 21:15:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: jvortega</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-31</link>
		<dc:creator>jvortega</dc:creator>
		<pubDate>Tue, 31 Mar 2009 19:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-31</guid>
		<description>Scan the network for Conficker. &lt;a href=&quot;http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/&quot; target=&quot;_blank&quot;&gt;http://blog.sekiur.com/2009/03/conficker-gets-rea...&lt;/a&gt; 
&lt;a href=&quot;http://www.dshield.org/diary.html?storyid=6097&quot; target=&quot;_blank&quot;&gt;http://www.dshield.org/diary.html?storyid=6097&lt;/a&gt; &amp; &lt;a href=&quot;http://honeynet.org/node/388&quot; target=&quot;_blank&quot;&gt;http://honeynet.org/node/388&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Scan the network for Conficker. <a href="http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/" target="_blank"></a><a href="http://blog.sekiur.com/2009/03/conficker-gets-rea.." rel="nofollow">http://blog.sekiur.com/2009/03/conficker-gets-rea..</a>.<br />
<a href="http://www.dshield.org/diary.html?storyid=6097" target="_blank">http://www.dshield.org/diary.html?storyid=6097</a> &amp; <a href="http://honeynet.org/node/388" target="_blank">http://honeynet.org/node/388</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jvortega</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-27</link>
		<dc:creator>jvortega</dc:creator>
		<pubDate>Fri, 27 Mar 2009 07:20:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-27</guid>
		<description>That&#039;s an excellent question. Variant C does a much better job at preventing security products from removing it, thus further testing is required. 
&quot;Like Conficker B,  C incorporates logic to defend itself from security products that would otherwise attempt to detect and remove it.     C spawns a security product disablement thread.  This thread disables critical host security services, such as Windows defender, as well as Windows services that deliver security patches and software updates.  These changes effectively prevent the victim host from receiving automated software updates. The thread disables security update notifications and deactivates safeboot mode as a future reboot option.  This first thread then spawns a new security process termination thread, which continually monitors for and kills processes whose names match a blacklisted set of 23 security products, hot fixes, and security diagnosis tools......&quot; &lt;a href=&quot;http://mtc.sri.com/Conficker/addendumC/&quot; target=&quot;_blank&quot;&gt;http://mtc.sri.com/Conficker/addendumC/&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>That&#039;s an excellent question. Variant C does a much better job at preventing security products from removing it, thus further testing is required.<br />
&quot;Like Conficker B,  C incorporates logic to defend itself from security products that would otherwise attempt to detect and remove it.     C spawns a security product disablement thread.  This thread disables critical host security services, such as Windows defender, as well as Windows services that deliver security patches and software updates.  These changes effectively prevent the victim host from receiving automated software updates. The thread disables security update notifications and deactivates safeboot mode as a future reboot option.  This first thread then spawns a new security process termination thread, which continually monitors for and kills processes whose names match a blacklisted set of 23 security products, hot fixes, and security diagnosis tools&#8230;&#8230;&quot; <a href="http://mtc.sri.com/Conficker/addendumC/" target="_blank">http://mtc.sri.com/Conficker/addendumC/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jessie</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-26</link>
		<dc:creator>Jessie</dc:creator>
		<pubDate>Tue, 24 Mar 2009 07:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-26</guid>
		<description>This scripts can remove which variants of Conficker? Including Conficker.C? </description>
		<content:encoded><![CDATA[<p>This scripts can remove which variants of Conficker? Including Conficker.C?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: josh</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-25</link>
		<dc:creator>josh</dc:creator>
		<pubDate>Tue, 24 Feb 2009 18:24:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-25</guid>
		<description>really nice script.. too bad i found it AFTER i created my own :P </description>
		<content:encoded><![CDATA[<p>really nice script.. too bad i found it AFTER i created my own <img src='http://blog.sekiur.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jvortega</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-21</link>
		<dc:creator>jvortega</dc:creator>
		<pubDate>Fri, 13 Feb 2009 00:13:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-21</guid>
		<description>Thanks. I appreciate your input very much.  </description>
		<content:encoded><![CDATA[<p>Thanks. I appreciate your input very much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GovernmentSecurity</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-20</link>
		<dc:creator>GovernmentSecurity</dc:creator>
		<pubDate>Thu, 12 Feb 2009 22:59:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-20</guid>
		<description>Great article and some very nice detailed instructions. Promoted to our frontpage. </description>
		<content:encoded><![CDATA[<p>Great article and some very nice detailed instructions. Promoted to our frontpage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Dugar</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/comment-page-1/#comment-18</link>
		<dc:creator>Peter Dugar</dc:creator>
		<pubDate>Thu, 05 Feb 2009 05:16:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sekiur.com/?p=722#comment-18</guid>
		<description>Is there any way to scan a network for the worm. </description>
		<content:encoded><![CDATA[<p>Is there any way to scan a network for the worm.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
