<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5516322715162168389</id><updated>2012-01-24T11:47:56.480-08:00</updated><category term='worldwide'/><category term='Downadup'/><category term='manual removal'/><category term='remover'/><category term='atack'/><category term='1 of 3'/><category term='technical details'/><category term='removal tool'/><category term='virus'/><category term='worm'/><category term='kido'/><category term='windows'/><category term='conficker'/><category term='español'/><category term='symantec removal tool'/><category term='remove'/><title type='text'>Downadup  Conficker Worm</title><subtitle type='html'>Info related to this worm, how started, how to fixed, everything you need to know!!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-4269697666838175372</id><published>2009-04-01T11:21:00.000-07:00</published><updated>2009-04-01T11:23:28.457-07:00</updated><title type='text'>Microsoft offers $250,000 bounty for Conficker creators</title><content type='html'>&lt;p style="font-family: verdana;"&gt; Microsoft has placed at $250,000 (£172,000) bounty on the head of the people    behind a computer virus that infected more than 15 million machines.  &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  The worm, known variously as Conficker, Downadup and Kido, burrowed its way    into an estimated 15 million computers worldwide, providing hackers,    spammers and cybercriminals with a 'back door' into people's machines, and    making Windows users vulnerable to identity fraud and ID theft.  &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;  &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;The virus takes advantage of a vulnerability in the operating system to    burrow deep into the computer's files, folders and System Registry, which    stores settings and options for Windows. Once installed, hackers and    spammers are able to remotely download more malicious programs to the    computer, or even use the worm to help install software that will enable    them to track and steal security information, such as banking logins or    credit card information. &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  The software company is offering a reward for information that leads to the    capture and conviction of the virus authors, because it views the worm as a    criminal attack.  &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  "This development shouldn't surprise anyone," said Graham Cluley, a senior    technology consultant for anti-virus firm Sophos. "Microsoft's reputation is    badly shaken whenever a computer virus causes widespread problems for its    users. &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  "Offering substantial rewards can do no harm. If a culprit isn't found then    Microsoft hasn't lost anything, and it may just entice some members of the    computer underground to come forward with information. People considering    releasing malware in the future should take careful note of this and think    again." &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  It's not the first time Microsoft has offered a reward for information    leading to the capture of a cybercriminal. In November 2003, it slapped a    $500,000 bounty on the authors of the Blaster and Sobig worms, and in May    2004, it paid $250,000 to a group of informants who enabled the prosecution    of Sven Jaschan, the German teenager of the Sasser and Netsky viruses.  &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  "The big question is whether the Conficker bounty is big enough," said    Cluley. "$250,000 may have been enough to identify Sven Jaschan, a German    teenager infecting computers for kicks.  &lt;/p&gt; &lt;p style="font-family: verdana;"&gt;  "But is it going to be enough to encourage someone to inform on an organised    criminal gang, making large amounts of money out of malware?" &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-4269697666838175372?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/4269697666838175372/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/04/microsoft-offers-250000-bounty-for.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/4269697666838175372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/4269697666838175372'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/04/microsoft-offers-250000-bounty-for.html' title='Microsoft offers $250,000 bounty for Conficker creators'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-6475221385049323083</id><published>2009-01-21T20:49:00.000-08:00</published><updated>2009-01-21T20:50:55.914-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Windows worm trickery for Vista</title><content type='html'>&lt;p style="font-family: verdana;" class="first"&gt;&lt;b&gt;The Conficker virus has opened a new can of worms for security experts.&lt;/b&gt; &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;Drives such as USB sticks infected with the virus trick users into installing the worm, according to researchers. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;The "Autoplay" function in Vista and early versions of Windows 7 automatically searches for programs on removable drives. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;However, the virus hijacks this process, masquerading as a folder to be opened. When clicked, the worm installs itself. &lt;!-- E SF --&gt;&lt;/p&gt;&lt;p style="font-family: verdana;"&gt;It then attempts to contact one of a number of web servers, from which it could download another program that could take control of the infected computer. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;&lt;b&gt;Bad guys&lt;/b&gt; &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;The worm is unusually clever in the way that it determines what server to contact, according to F-Secure's chief research officer Mikko Hypponen. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;"It uses a complicated algorithm which changes daily and is based on timestamps from public websites such as Google.com and Baidu.com," said Mr Hypponen in a blog post. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;"This makes it impossible and/or impractical for us good guys to shut them all down — most of them are never registered in the first place. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;"However, the bad guys only need to predetermine one possible domain for tomorrow, register it, and set up a website — and they then gain access to all of the infected machines," he added. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;It has also emerged that the virus automatically disables the automatic updates to Windows that would prevent further infection. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;As the virus - also known as Downadup - has spread to an estimated 9 million computers globally, a number of high-profile instances of the virus have arisen. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;The Ministry of Defence has been battling an outbreak of the virus across its network for more than two weeks, and on Tuesday a network of hospitals across Sheffield told technology website The Register that more than 800 of their computers had been infected. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;Users are urged to download the KB958644 Security Update from Microsoft to mitigate the risk of infection. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-6475221385049323083?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/6475221385049323083/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/windows-worm-trickery-for-vista.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/6475221385049323083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/6475221385049323083'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/windows-worm-trickery-for-vista.html' title='Windows worm trickery for Vista'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-3725695456974725892</id><published>2009-01-21T20:47:00.000-08:00</published><updated>2009-01-21T20:48:47.318-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='technical details'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='worldwide'/><title type='text'>New variant of the worm</title><content type='html'>&lt;span style="font-family: verdana;"&gt;According to Kaspersky Lab's security analyst Eddy Willems said that a new strain of the worm was complicating matters. &lt;/span&gt;&lt;p style="font-family: verdana;"&gt;"There was a new variant released less than two weeks ago and that's the one causing most of the problems," said Mr Willems &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;"The replication methods are quite good. It's using multiple mechanisms, including USB sticks, so if someone got an infection from one company and then takes his USB stick to another firm, it could infect that network too. It also downloads lots of content and creating new variants though this mechanism. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;"Of course, the real problem is that people haven't patched their software," he added. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-3725695456974725892?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/3725695456974725892/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/new-variant-of-worm.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/3725695456974725892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/3725695456974725892'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/new-variant-of-worm.html' title='New variant of the worm'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-3667991107457693605</id><published>2009-01-16T21:43:00.001-08:00</published><updated>2009-01-16T21:54:50.270-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='symantec removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='español'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='remover'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Como remover gusano downadup - conficker</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Para todos los hispanohablantes, aqui tambien encontraran información sobre como eliminar este peligroso virus que ha alcanzado a un gran numero de computadoras en los ultimos días.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;El eliminarlo es sumamente sencillo, solo sigue los siguientes pasos:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;1) Descarga la herramienta para eliminar el gusano desde la siguiente direccion: &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe"&gt;http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe&lt;/a&gt;&lt;a style="font-family: verdana;" href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe"&gt;.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;2) Guarda el archivo en una ubicación conveniente, tal como el escritorio de Windows.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;3) Cierra todos los programas que tengas abiertos&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;4) Si estas conectado a una red, o tienes una conexión permanente a internet, desconecta tu computadora de la red y del internet.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;5) Si estas usando Windows Me o XP desactiva la opción de restaurar sistema.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;6) Localiza el archivo que acabas de descargar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;7) Doble click en el archivo FixDownadup.exe para comenzar a ejecutar la herramienta removedora.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;8) Click en comenzar para comenzar con el proceso y luego deja corriendo la herramienta. NOTA: Si tienes algun problema mientras corre la herramiento, o parece que no elimino el gusano, reinicia tu computadora en modo seguro y ejecuta la herramienta de nuevo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;9) Reinicia tu computadora&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;10) Corre de nuevo la herramienta removedora para que estes seguro de que tu sistema esta limpio.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;11) Si estas usando Windows Me o XP vuelve a activar la opción de Restaurar Sistema&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;12) Si estas conectado a una red o tienes conexion permanente a internet reconecta tu computadora a la red o al internet.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;13) Corre LiveUpdate para que estes seguro de que estas usando la version más actual de antivirus.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Espero que estos pasos te sirvan ;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-3667991107457693605?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/3667991107457693605/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/como-remover-gusano-downadup.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/3667991107457693605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/3667991107457693605'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/como-remover-gusano-downadup.html' title='Como remover gusano downadup - conficker'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-1217810832733898647</id><published>2009-01-16T21:23:00.000-08:00</published><updated>2009-01-16T21:26:47.278-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='remove'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='manual removal'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Manual removal of Downadup - Conficker - Kido</title><content type='html'>&lt;span style="font-family: verdana;"&gt;The manual removal of this worm is really easy, just follow those steps:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-family: verdana;"&gt;Manual Removal&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;1) Disable System Restore (Windows Me/XP).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;2) Update the virus definitions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;3) Run a full system scan.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;4) Delete any values added to the registry.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-1217810832733898647?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/1217810832733898647/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/manual-removal-of-downadup-conficker.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/1217810832733898647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/1217810832733898647'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/manual-removal-of-downadup-conficker.html' title='Manual removal of Downadup - Conficker - Kido'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-9076925916202549161</id><published>2009-01-16T21:15:00.000-08:00</published><updated>2009-01-16T21:20:32.492-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='symantec removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='technical details'/><category scheme='http://www.blogger.com/atom/ns#' term='remove'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Technical details of worm Downadup - Conficker</title><content type='html'>&lt;div style="font-family: verdana;"&gt; &lt;strong&gt;Discovered: &lt;/strong&gt;November 21, 2008&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;strong&gt;Updated: &lt;/strong&gt;November 24, 2008 9:37:07 AM&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;strong&gt;Also Known As: &lt;/strong&gt;Win32/Conficker.A [Computer Associates], W32/Downadup.A [F-Secure], Conficker.A [Panda Software], Net-Worm.Win32.Kido.bt [Kaspersky]&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;strong&gt;Type: &lt;/strong&gt;Worm&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;strong&gt;Infection Length: &lt;/strong&gt;62,976 bytes&lt;/div&gt; &lt;div&gt; &lt;strong style="font-family: verdana;"&gt;Systems Affected: &lt;/strong&gt;&lt;span style="font-family: verdana;"&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Once executed, the worm copies itself as the following file:&lt;/span&gt; &lt;span style="font-family: verdana;"&gt;%System%\[RANDOM FILE NAME].dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Next, the worm deletes any user-created System Restore points.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;It creates the following service:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Name: netsvcs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;ImagePath: %SystemRoot%\\system32\\svchost.exe -k netsvcs&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Then the worm creates the following registry entry:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters\"ServiceDll" = "[PathToWorm]"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The worm connects to the following URLs to obtain IP address of the compromised computer:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.getmyip.org&lt;br /&gt;http://getmyip.co.uk&lt;br /&gt;http://checkip.dyndns.org&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Next, the worm downloads a file from the following URL and executes it:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;[http://]trafficconverter.biz/4vir/antispyware/loada[REMOVED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The worm then creates a http server on the compromised computer on a random port, for example:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://[EXTERNAL IP ADDRESS OF INFECTED MACHINE]:[RANDOM PORT]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The worm then sends this URL as part of its payload to remote computers.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Upon successful exploitation, the remote computer will then connect back to this URL and download the worm.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;In this way, each exploited computer can spread the worm itself, as opposed to downloading from a predetermined location.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Next, the worm connects to a UPnP router and opens the http port.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;It then attempts to locate the network device registered as the Internet gateway on the network and opens the previously mentioned [RANDOM PORT] in order to allow access to the compromised computer from external networks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The worm then attempts to download a data file from the following URL:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;[http://]www.maxmind.com/download/geoip/database/GeoIP.[REMOVED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-family: verdana;"&gt;&lt;/strong&gt;&lt;span style="font-family: verdana;"&gt;The worm spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.securityfocus.com/bid/31874"&gt;BID 31874&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Next, the worm attempts to contact the following sites to obtain the current date:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http://www.w3.org&lt;br /&gt;http://www.ask.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.yahoo.com&lt;br /&gt;http://www.google.com&lt;br /&gt;http://www.baidu.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;It uses the date information to generate a list of domain names.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The worm then contacts these domains in an attempt to download additional files onto the compromised computer.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-9076925916202549161?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/9076925916202549161/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/technical-details-of-worm-downadup.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/9076925916202549161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/9076925916202549161'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/technical-details-of-worm-downadup.html' title='Technical details of worm Downadup - Conficker'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-2563468796634607506</id><published>2009-01-16T21:10:00.000-08:00</published><updated>2009-01-16T21:13:33.902-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='symantec removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='remove'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Another remover tool - Symantec removal tool</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Now this tool come from Symantec, one of the world liders on security software.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;You can download from here:&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe"&gt;&lt;br /&gt;http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-2563468796634607506?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/2563468796634607506/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/another-remover-tool-symantec-removal.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/2563468796634607506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/2563468796634607506'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/another-remover-tool-symantec-removal.html' title='Another remover tool - Symantec removal tool'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-1309476056832329231</id><published>2009-01-16T21:04:00.000-08:00</published><updated>2009-01-16T21:06:10.488-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='remove'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>W32.Downadup Removal Tool 1.0.3</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Check this site where you cand find a removal tool to solve the infection of the Downadup - Conficker worm:&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://www.softpedia.com/get/Antivirus/W32-Downadup-Removal-Tool.shtml"&gt;&lt;br /&gt;http://www.softpedia.com/get/Antivirus/W32-Downadup-Removal-Tool.shtml&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-1309476056832329231?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/1309476056832329231/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/w32downadup-removal-tool-103.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/1309476056832329231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/1309476056832329231'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/w32downadup-removal-tool-103.html' title='W32.Downadup Removal Tool 1.0.3'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-7507655230957245290</id><published>2009-01-16T20:39:00.000-08:00</published><updated>2009-01-16T20:48:25.283-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='1 of 3'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='worldwide'/><title type='text'>1 of 3 Windows computers are vulnerable to worm</title><content type='html'>According to Qualys Inc. about 30% of the machines have not yet been patched with the "out of cycle" fix Microsoft provided Oct. 23 as security update MS08-067.&lt;br /&gt;&lt;br /&gt;Nearly a third of all Windows systems remain unpatched 80 days after Microsoft rolled out an emergency fix for the Downadup worm. &lt;p&gt; Based on scans of several hundred thousand customer-owned Windows PCs, &lt;a title="Qualys Inc." href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Qualys+Inc."&gt;&lt;/a&gt;Qualys Inc concluded that "The unpatched numbers went down significantly around the 30-day mark," said&lt;a title="Wolfgang Kandek" href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Wolfgang+Kandek"&gt;&lt;/a&gt; &lt;a title="Wolfgang Kandek" href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Wolfgang+Kandek"&gt;&lt;/a&gt;Wolfgang Kandek, Qualys' chief technology officer, "when less than 50% were unpatched. After that, it went down a little slower. As of yesterday, 30% of the machines are unpatched." &lt;/p&gt;&lt;p&gt; With nearly a third of all Windows systems still vulnerable, it's no surprise that the "Downadup" worm has been able to score such a success, Kandek said. "These slow [corporate] patch cycles are simply not acceptable," he said. "They lead directly to these high-infection rates." &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-7507655230957245290?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/7507655230957245290/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/1-of-3-windows-computers-are-vulnerable.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/7507655230957245290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/7507655230957245290'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/1-of-3-windows-computers-are-vulnerable.html' title='1 of 3 Windows computers are vulnerable to worm'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-9059976808286907775</id><published>2009-01-16T20:33:00.000-08:00</published><updated>2009-01-16T20:35:35.580-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='worldwide'/><title type='text'>How Conficker - Downadup - Kido works??</title><content type='html'>&lt;p style="font-family: verdana;"&gt;This worm works by searching for a Windows executable file called "services.exe" and then becomes part of that code. &lt;/p&gt;&lt;p style="font-family: verdana;"&gt;It then copies itself into the Windows system folder as a random file of a type known as a "dll". It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service. &lt;/p&gt;&lt;span style="font-family: verdana;"&gt;Once the worm is up and running, it creates an HTTP server, resets a machine's System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker's web site&lt;br /&gt;&lt;br /&gt;---&lt;br /&gt;So, guys, keep on eye on this virus!!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-9059976808286907775?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/9059976808286907775/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/how-conficker-downadup-kido-works.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/9059976808286907775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/9059976808286907775'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/how-conficker-downadup-kido-works.html' title='How Conficker - Downadup - Kido works??'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-7976308253112958019</id><published>2009-01-16T20:17:00.000-08:00</published><updated>2009-01-16T20:25:23.826-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='kido'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='worldwide'/><title type='text'>More than 3 millions infected!!</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Acording to different sources, the number of infected computers with the worm Conficker, Downadup, or Kido is now 3.5 millions worldwide, this number is growing in the last hours.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;According to F-Secure these are the countries with most infected computers around the world:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: verdana;" class="bull"&gt;China 38,277&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Brazil 34,814&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Russia 24,526&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;India 16,497&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Ukraine 14,767&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Italy 13,115&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Argentina 11,675&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Korea 11,117&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;Romania 8,861&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;United States 3,958&lt;/div&gt;   &lt;div style="font-family: verdana;" class="bull"&gt;United Kingdom 1,789&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-7976308253112958019?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/7976308253112958019/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/more-than-3-millions-infected.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/7976308253112958019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/7976308253112958019'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/more-than-3-millions-infected.html' title='More than 3 millions infected!!'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5516322715162168389.post-6537507358237464303</id><published>2009-01-16T20:13:00.001-08:00</published><updated>2009-01-16T20:14:37.492-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Downadup Conficker Virus Info</title><content type='html'>&lt;span style="font-family: verdana;"&gt;On this site i will be posting information related to this new virus that has infected more than 1 million of windows computers on the last days&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5516322715162168389-6537507358237464303?l=downadup-conficker.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://downadup-conficker.blogspot.com/feeds/6537507358237464303/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/downadup-conficker-virus-info.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/6537507358237464303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5516322715162168389/posts/default/6537507358237464303'/><link rel='alternate' type='text/html' href='http://downadup-conficker.blogspot.com/2009/01/downadup-conficker-virus-info.html' title='Downadup Conficker Virus Info'/><author><name>Ive</name><uri>http://www.blogger.com/profile/07897853417187047904</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
