<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Gibni - The Prime &#187; Security</title> <atom:link href="http://www.gibni.com/category/security/feed" rel="self" type="application/rss+xml" /><link>http://www.gibni.com</link> <description>Providing Solutions.</description> <lastBuildDate>Fri, 20 Jan 2012 15:31:33 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Emergency code</title><link>http://www.gibni.com/emergency-code</link> <comments>http://www.gibni.com/emergency-code#comments</comments> <pubDate>Fri, 28 Aug 2009 14:44:26 +0000</pubDate> <dc:creator>Gi</dc:creator> <category><![CDATA[Blogging]]></category> <category><![CDATA[Informatique - Computers]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Web Development]]></category> <category><![CDATA[Wordpress]]></category> <category><![CDATA[Web Developpment]]></category> <category><![CDATA[Website Optimization]]></category><guid isPermaLink="false">http://www.gibni.com/?p=915</guid> <description><![CDATA[Who to call in case of website emergency? Due to some yet unknown issue, WordPress version 2.8.2 might be causing server errors. Lunarpages, my &#8220;current&#8221; and might become &#8220;ex&#8221; webhosting company, shut down Gibni.com yesterday without any prior notice, saying they&#8217;ve taken &#8230; <a href="http://www.gibni.com/emergency-code">Continue reading <span class="meta-nav">&#8594;</span></a><br /><a target="_blank" href="http://www.gdstarrating.com/"><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" /></a><br />]]></description> <content:encoded><![CDATA[<h2>Who to call in case of website emergency?</h2><p>Due to some yet unknown issue, WordPress version 2.8.2 might be causing server errors.</p><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.lunarpages.com/" >Lunarpages</a>, my &#8220;current&#8221; and might become &#8220;ex&#8221; webhosting company, <strong>shut down Gibni.com</strong> yesterday without any prior notice, saying they&#8217;ve taken an emergency action, as the &#8220;index.php&#8221; script in my wordpress root was using huge server resources, and could cause a server crash.</p><p> <strong>First</strong> problem is, not only they changed the &#8220;index.php&#8221; permissions to &#8220;000&#8243;  (no read permissions) but they took ownership of the file, so neither I could make any changes to the file, nor analyze it for troubleshooting.</p><p><br class="spacer_" /><span id="more-915"></span></p><p><strong>Secondly</strong>, they made the domain return an &#8220;internal server error&#8221; to all visitors.</p><p><br class="spacer_" /></p><p><strong>Third</strong>, they did not manage to put an &#8220;under maintenance&#8221; page at the root untill the issue is solved.</p><p><br class="spacer_" /></p><p>Anyway, thanks to my linux skills, I managed to put an &#8220;under maintenance&#8221; page for Gibni, and get the site back online very soon.</p><p><br class="spacer_" /></p><p>Until I figure out what caused wordpress to eat server resources, and was it really wordpress or Lunarpages&#8217;s poor servers and administration, was it the running theme which ran without any issue for months or even the plugins installed on wordpress a year ago; I&#8217;ve decided to switch back to wordpress default theme and upgrade to wordpress 2.8.4.</p><p> After all, I believe that you should now:</p><p><br class="spacer_" /></p><ul><li> Enjoy Gibni, Ad free!</li><li> Always have a maintenance page and an emergency code, just in case!</li><li> Be careful choosing your webhosting company!</li></ul> <br /><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.gdstarrating.com/" target="_blank" ><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" title="Emergency code" alt="powered Emergency code" /></a><br />]]></content:encoded> <wfw:commentRss>http://www.gibni.com/emergency-code/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Windows Delayed Write Failed Error &#8211; Solutions</title><link>http://www.gibni.com/windows-delayed-write-failed-solutions</link> <comments>http://www.gibni.com/windows-delayed-write-failed-solutions#comments</comments> <pubDate>Fri, 31 Jul 2009 21:22:18 +0000</pubDate> <dc:creator>Gi</dc:creator> <category><![CDATA[Informatique - Computers]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[2009]]></category> <category><![CDATA[Computers]]></category> <category><![CDATA[desktop computers]]></category> <category><![CDATA[Hardware]]></category> <category><![CDATA[Windows XP]]></category><guid isPermaLink="false">http://www.gibni.com/?p=632</guid> <description><![CDATA[This article describes the Windows Delayed Write Failed error, and gives you all the possible solutions for this issue, with great details. <a href="http://www.gibni.com/windows-delayed-write-failed-solutions">Continue reading <span class="meta-nav">&#8594;</span></a><br /><a target="_blank" href="http://www.gdstarrating.com/"><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" /></a><br />]]></description> <content:encoded><![CDATA[<h1>Window Delayed Write Failed ? Solutions are here!</h1><p><br class="spacer_" /><span style="color: #808080;">This topic is researched, tested and written by <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.amirhmoradi.com/" >Amir Hossein Moradi</a>.</span><br class="spacer_" /></p><p><img class="size-thumbnail wp-image-653 alignleft" title="harddriveicon" src="http://www.gibni.com/wp-content/uploads/2009/04/harddriveicon-150x150.png" alt="harddriveicon 150x150 Windows Delayed Write Failed Error   Solutions" width="54" height="54" /></p><p>This is the third article on the Windows Delayed Write Failed error occurring with hard drives (mostly external ones with USB/Firewire/Network connections). On 28th December 2007, I wrote the<strong> <a href="http://www.gibni.com/windows-delayed-write-failed-solved" >Windows &#8211; Delayed Write Failed &#8211; Solved!</a> </strong>article which had more than 190,000 views, and helped many users till date. On 9th June 2008, the second article on this topic &#8211; <strong><a href="http://www.gibni.com/windows-delayed-write-failed-2" >Windows Delayed Write Failed &#8211; Latest Solution</a></strong> &#8211; which had more than 34,000 views till date, was out and is still getting many users out of trouble.<span id="more-632"></span></p><p><br class="spacer_" /></p><p>Now, it&#8217;s time to write the <strong>3rd article</strong> and sum up all possible solutions for the <strong>Windows Delayed Write Failed error</strong>.</p><p><br class="spacer_" /></p><h2><a href="http://www.gibni.com/?attachment_id=656" rel="attachment wp-att-656" ><img class="size-full wp-image-656 alignnone" title="about_write_delayed_failed" src="http://www.gibni.com/wp-content/uploads/2009/04/ip_icon_04_icon_sample.jpg" alt="ip icon 04 icon sample Windows Delayed Write Failed Error   Solutions" width="48" height="48" /></a>About Delayed Write:</h2><p>Windows uses a special subsystem for certain disk functions, which caches write operations and performs them when the system is idle. This can improve system performance, but it’s typically turned off by default. The term for this kind of operation is “delayed writing”.</p><p><br class="spacer_" /></p><p>You can see how write-caching is handled for a particular volume by right-clicking on the icon for the drive in the “Disk drives” subtree of the Device Manager and selecting the Policies tabs. The options typically are “Optimize for quick removal” (everything is written to the drive immediately) and “Optimize for performance” (writes are cached).</p><p><br class="spacer_" /></p><h2><img class="size-full wp-image-656 alignnone" title="about_write_delayed_failed" src="http://www.gibni.com/wp-content/uploads/2009/04/ip_icon_04_icon_sample.jpg" alt="ip icon 04 icon sample Windows Delayed Write Failed Error   Solutions" width="48" height="48" />About the error:</h2><p>&#8220;Windows Delayed Write Failed&#8221; error occurs usually when the caching process gets interrupted or the files to be cached get corrupted, either because of a drive failure, a cable failure, or a USB interface fail!</p><p>This error might happen to brand new drives as well as good working old ones.</p><p><br class="spacer_" /></p><h2><img class="alignnone size-full wp-image-657" title="write_delayed_cause" src="http://www.gibni.com/wp-content/uploads/2009/04/earth-alert-48x48.png" alt="earth alert 48x48 Windows Delayed Write Failed Error   Solutions" width="48" height="48" />Cause:</h2><p>This error might be caused by several factors:</p><p><br class="spacer_" /></p><ul><li>Cache settings</li><li>System Restore settings</li><li>Device drivers</li><li>Media error, drive failure</li><li>USB/Firewire host controllers</li><li>Drive overheating</li><li>Mis-configured BIOS settings</li><li>Ultra Direct Memory Access (UDMA) mis-configuration</li><li>Unmatched cables</li><li>Faulty cables</li><li>Memory parity conflict</li><li>Power management drivers</li></ul><p><span style="color: #ff0000;"> </span></p><p><strong><span style="color: #ff0000;">On the next page(s) I&#8217;ll discuss all the working and possible solutions to this issue</span>.</strong></p><p> <br /><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.gdstarrating.com/" target="_blank" ><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" title="Windows Delayed Write Failed Error   Solutions" alt="powered Windows Delayed Write Failed Error   Solutions" /></a><br />]]></content:encoded> <wfw:commentRss>http://www.gibni.com/windows-delayed-write-failed-solutions/feed</wfw:commentRss> <slash:comments>18</slash:comments> </item> <item><title>Making money online, avoiding the scams</title><link>http://www.gibni.com/making-money-online-how-to-avoid-scams</link> <comments>http://www.gibni.com/making-money-online-how-to-avoid-scams#comments</comments> <pubDate>Tue, 05 May 2009 20:10:05 +0000</pubDate> <dc:creator>Gi</dc:creator> <category><![CDATA[Blogging]]></category> <category><![CDATA[Informatique - Computers]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Web Development]]></category> <category><![CDATA[Wordpress]]></category> <category><![CDATA[Internet]]></category> <category><![CDATA[Web Developpment]]></category> <category><![CDATA[Website Optimization]]></category><guid isPermaLink="false">http://www.gibni.com/?p=764</guid> <description><![CDATA[Making money online&#8230; Making money online is one of the most researched topics for many of web developpers, bloggers and website owners. It takes a lot of efforts to produce quality content and get enough traffic, to be able to rank &#8230; <a href="http://www.gibni.com/making-money-online-how-to-avoid-scams">Continue reading <span class="meta-nav">&#8594;</span></a><br /><a target="_blank" href="http://www.gdstarrating.com/"><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" /></a><br />]]></description> <content:encoded><![CDATA[<h2>Making money online&#8230;</h2><p>Making money online is one of the most researched topics for many of web developpers, bloggers and website owners. It takes a lot of efforts to produce<strong> quality content and get enough traffic</strong>, to be able to <strong>rank better in search results</strong> and improve your different ranking factors. After a while of being online, website owners will get advertising offers from different companies, which might be interesting at first.</p><p>Well, this is a good sign, as it means that <strong>your site is getting some interest</strong> and attention; but it&#8217;s also an alert, warning you to <strong>be cautious</strong>.</p><p><br class="spacer_" /><span id="more-764"></span></p><p>There are lots of scams out there, which try to fool you by offering great business opportunities and make you run some ads or malicious scripts on your website. They (the scammers) will try to get detailed information about you, your website, personal details and even your bank account(s). <img class="size-thumbnail wp-image-765 alignright" title="scam" src="http://www.gibni.com/wp-content/uploads/2009/05/scam23-150x150.jpg" alt="scam23 150x150 Making money online, avoiding the scams" width="150" height="150" /></p><p><br class="spacer_" /></p><h2>You Should be carefull&#8230;</h2><p>You would get an email, from an unknown party, who shows interest in your website and usually represents himself as an advertising company who wants to buy some ad space, or publish some content on your website (or blog) for one of his clients.</p><p>First thing to do is : <strong>DO NOT reply</strong> with your personal information and  DO NOT show that you&#8217;re very interested!</p><p>Second, start to gather some information about the company who sent you the email. See its <strong>WHOIS record</strong> (you can use <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://internic.net/whois.html" >InterNIC WHOIS</a> ) to find out more about the website owner, registrar, their address, and phone numbers if any.</p><p>Use your favorite search engine to find out more about the company, visit their website, check their &#8220;About us&#8221; page, check their portfolio, recent clients, latest works&#8230;</p><p>Look for user reviews on the company, search to find out if &#8221; <strong>{the company name} + scam</strong> &#8221; returns anything in your search engine? Search and investigate a little bit to keep your website (blog) safe from advertisement scams.</p><p>Use <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.siteadvisor.com/" >SiteAdvisor form McAffee</a> to check if the website is a safe website or not.</p><p>If you come across any types of scams, just <strong>DO NOT reply to their emails and ignore them</strong>. You would help other website owners and bloggers if you write a post on how to identify scams and spams and how to avoid scams.</p><p><strong>You can share this post and link back to it from your website (given that you mention the source).</strong></p><p><br class="spacer_" /></p><p>Recently I&#8217;ve came across a <strong>scam from Production-Time.com</strong> . They&#8217;ve sent me an email in French, in which they shown interest in Gibni.com and asked me to reply if I wanted some more information.</p><p>I&#8217;ve done a WHOIS research and some investigation and found out that the email, even if it was well personalised, has been sent to thousands of people and some website owners have already announced Promotion-Time.com as a scam. I&#8217;ve found a detailed article about this scam in <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://epn.dk/teknologi2/computer/sikkerhed/article1608859.ece" >EPN.dk</a>, which I <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://translate.google.com/translate?prev=hp&amp;hl=en&amp;js=n&amp;u=http%3A%2F%2Fepn.dk%2Fteknologi2%2Fcomputer%2Fsikkerhed%2Farticle1608859.ece&amp;sl=auto&amp;tl=en" >translated to English</a> to be able to understand it.</p><p>Here&#8217;s the a part of the email they&#8217;ve sent me:</p><blockquote><p><br class="spacer_" /></p><p><span style="font-size: small;">Bonjour,<br /> J&#8217;aimerais vous faire part d&#8217;une proposition commerciale à propos de votre site Web, qui pourrait très fort vous intéresser.<br /> En effet, ma société Promotion-Time, souhaiterait vous rémunérer pour la publication d&#8217;une petite publication textuelle sur votre site pour un de nos clients.<br /> Il s&#8217;agit d’une annonce francophone ciblée qui convient à certaines pages de votre site.<br /> N’hésitez pas à me contacter si vous avez besoin de plus amples informations.</p><p>Sincèrement,<br /> Francq Petit<br /> francqp@promotion-time.com</p><p>Si vous ne souhaitez plus recevoir d’emails de Promotion-Time, répondez à cet email avec comme sujet : STOP.<br /> It is possible to continue this correspondence in English, if you prefer to do so.<br /> </span></p></blockquote><p><span style="font-size: small;"><br /> </span></p><p>Here in this post, you can help the community by letting other know about the scams you faced and also know about scams already running on the internet. Type in the information you have in the comments section (Be carefull not to spam the comments section) .</p><p><br class="spacer_" /></p><p>Making money online, avoiding the scams, aims to help you avoid scams, help spread the word and show your support.</p> <br /><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.gdstarrating.com/" target="_blank" ><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" title="Making money online, avoiding the scams" alt="powered Making money online, avoiding the scams" /></a><br />]]></content:encoded> <wfw:commentRss>http://www.gibni.com/making-money-online-how-to-avoid-scams/feed</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Remove Conficker (Downup, Downadup or Kido)</title><link>http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido</link> <comments>http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido#comments</comments> <pubDate>Fri, 27 Feb 2009 16:50:31 +0000</pubDate> <dc:creator>Gi</dc:creator> <category><![CDATA[Informatique - Computers]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Computers]]></category> <category><![CDATA[Conficker]]></category> <category><![CDATA[Internet]]></category> <category><![CDATA[Urgent]]></category><guid isPermaLink="false">http://www.gibni.com/?p=550</guid> <description><![CDATA[About Conficker: If you ever heard about Microsoft (the maker of Windows and a full bundle of problems attached to it), and if you have already heard about Conficker, or also called Downup, Downadup or Kido, I suppose that you&#8217;ve already taken steps on &#8230; <a href="http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido">Continue reading <span class="meta-nav">&#8594;</span></a><br /><a target="_blank" href="http://www.gdstarrating.com/"><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" /></a><br />]]></description> <content:encoded><![CDATA[<h2><span style="font-size: large;">About Conficker:</span></h2><p>If you ever heard about Microsoft (the maker of Windows and a full bundle of problems attached to it), and if you have already heard about <strong><span style="color: #ff0000;">Conficker</span></strong>, or also called <strong>Downup</strong>, <strong>Downadup or Kido, </strong>I suppose that you&#8217;ve already taken steps on protecting yourself and your friends from this computer worm (or computer virus as some may call it!).</p><p><br class="spacer_" /></p><p>I&#8217;m writing this <span style="text-decoration: underline;">urgent post</span> to warn everyone and help my dear visitors protect themselves and repair their infected computers.<span id="more-550"></span></p><p><strong><span style="text-decoration: underline;">Please spread the word and get people to read this article so you can help and save them! (<br /><script src="http://w.sharethis.com/widget/?tabs=web%2Cpost%2Cemail&amp;charset=utf-8&amp;style=default&amp;publisher=c4ada1f9-a5a2-4ccb-88b1-fc5d2f11ceda&amp;embeds=true" type="text/javascript"></script><br /> Immediately)<br /> </span></strong></p><p><br class="spacer_" />Conficker was born in October 2008, and targets Microsoft Windows Operating systems, so if you run Windows on your computer, <strong>YOU ARE A TARGET</strong> FOR CONFICKER! So, let&#8217;s get straight to the point, that is how to know if you&#8217;re already infected and how to remove the worm and how to protect yourself from later infections. <br class="spacer_" /></p><h2><span style="font-size: large;">Symptomes of infection according to </span><span style="font-size: large;"><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://en.wikipedia.org/wiki/Conficker" >Wikipedia</a> are:</span></h2><ul><li>Account lockout policies being reset automatically.</li><li>Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services are automatically disabled.</li><li>Domain controllers respond slowly to client requests.</li><li>System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.</li><li>On websites related with antivirus software, Windows system updates cannot be accessed.</li><li>Launches a brute force dictionary attack against administrator passwords to help it spread through ADMIN$ shares, making choice of sensible passwords advisable.</li></ul><p><br class="spacer_" />The worm spreads through movable drives (USB Flash drives, Memory cards, network drives, shared devices with storage memory and networks (the internet, your office&#8217;s LAN, your home&#8217;s network&#8230;) <strong><span style="color: #ff0000;">Conficker</span></strong> uses the Autorun feature (if you can call it a feature!! <img src='http://www.gibni.com/wp-includes/images/smilies/icon_smile.gif' alt="icon smile Remove Conficker (Downup, Downadup or Kido)" class='wp-smiley' title="Remove Conficker (Downup, Downadup or Kido)" /> ) of Windows and a specially crafted RPC query to spread it self. more information and advanced technical details on how the worm operates is available on my other post: <span style="color: #808080;">Conficker Worm, Advanced Technical Details</span> (Coming Soon)</p><p> </p><p><strong>On the next page(s) I&#8217;ll discuss detailed solution to remove the Conficker virus and Patch your computer&#8230;</strong></p><h2><span style="font-size: large;">Remove and Patch:</span></h2><p>Here&#8217;s how I did remove the virus for my friends and patched their computers so they won&#8217;t get infected again by this worm! <br class="spacer_" /></p><h3>1 &#8211; First of all you need to disable the Autorun &#8220;feature&#8221; of your computer so that it won&#8217;t run CDs, DVDs and USBs automatically.</h3><p><a href="http://www.gibni.com/conficker/conficker" rel="attachment wp-att-572" ><img class="aligncenter size-medium wp-image-572" title="conficker" src="http://www.gibni.com/wp-content/uploads/2009/02/conficker-300x292.png" alt="conficker 300x292 Remove Conficker (Downup, Downadup or Kido)" width="300" height="292" /></a> To do that, Microsoft provides a well describe article that you may read and apply for your Windows. Click : <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://support.microsoft.com/kb/967715/" >http://support.microsoft.com/kb/967715/</a> But if you&#8217;re already infected, you may not be able to access the Microsoft&#8217;s download page to download the required files. <br class="spacer_" />I provide you another workaround which was initally described on <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.us-cert.gov/cas/techalerts/TA09-020A.html"  target="_blank">US-CERT website</a> :</p><h2>First, download the <a href="http://www.gibni.com/dl/autorun_patch.reg" >autorun_patch.reg</a> file and run it. This file contains the following code and is applied to your Windows Registry:</h2><p><code>REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf] @="@SYS:DoesNotExist"</code> <br class="spacer_" /></p><ul><li><em>If you don&#8217;t want to download the file, then;</em></li></ul><p><em>To import the above value to your registry, perform the following steps:</em></p><ol><li><em>Copy the text above</em></li><li><em>Paste the text into Windows Notepad </em></li><li><em>Save the file as <tt>"autorun_patch.reg"</tt> Note: In certain circumstances, Notepad may automatically add a <tt>.txt</tt> extension to saved files. To ensure that the file is saved with the proper extension, select <strong>All Files</strong> in the &#8220;Save as type:&#8221; section of the &#8220;Save As&#8221; dialog. </em></li><li><em>Navigate to the file location </em></li><li><em>Double-click on the file to import it into the Windows registry </em></li></ol><p><strong>According to </strong><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.us-cert.gov/cas/techalerts/TA09-020A.html"  target="_blank">US-CERT website</a><strong>,</strong><em> Microsoft Windows also caches the AutoRun information from mounted devices in the <tt>MountPoints2</tt> registry key. It&#8217;s recommended restarting Windows after making the registry change so that any cached mount points are reinitialized in a way that ignores the <tt>Autorun.inf</tt> file. Alternatively, the following registry key may be deleted:</em></p><ul style="PADDING-LEFT: 30px"> <tt><em>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2</em></tt></ul><p><em>Once these changes have been made, all of the AutoRun code execution scenarios described above will be mitigated because Windows will no longer parse <tt>Autorun.inf</tt> files to determine which actions to take. Further details are available in the </em><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.cert.org/blogs/vuls/2008/04/the_dangers_of_windows_autorun.html" ><em>CERT/CC Vulnerability Analysis blog</em></a><em>.</em> <sup>[ref:US-CERT]</sup> <br class="spacer_" /></p><h3>2 &#8211; Disable System Restore:</h3><p>Steps for Windows XP:</p><ol><li><ol><li><em>Click Start. </em></li><li><em>Right-click My Computer, and then click Properties. </em></li><li><em>On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.  If you do not see the System Restore tab, you are not logged on to Windows as an Administrator.</em></li><li><em>Click Apply.</em></li><li><em>When you see the confirmation message, click Yes.</em></li><li><em>Click OK.</em></li></ol></li></ol><p><br class="spacer_" /></p><h3>3 &#8211; Install Microsoft Security Update [KB958644] for your Operating System:</h3><p>Go to this page and download the right update based on your Windows Operating System version: <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" >http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</a> In case you cannot access Microsoft website for any reason, I provide you mirror downloads here on Gibni.com: For Windows XP SP2 and Windows Xp SP3 (English) : [<a href="http://www.gibni.com/dl/WindowsXP-KB958644-x86-ENU.exe" >Mirror on Gibni</a>] For Windows Vista and Windows Vista SP1 (English): [<a href="http://www.gibni.com/dl/Windows6.0-KB958644-x86.msu" >Mirror on Gibni</a>] Once downloaded, (open/double click/run/execute) the file and procceed with the installation.</p><p> </p><h3>4- Download the Conficker Removal Tool of your choice:</h3><p>You should download a Removal Tool (listed bellow), then save it to a convenient location like your Windows Desktop.</p><h4>There are free <span style="color: #ff0000;">Conficker Removal tools </span>provided by:</h4><ul><li>Microsoft Malicious Software Removal Tool (En) : [<a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/downloads/info.aspx?na=90&amp;p=&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=ad724ae0-e72d-4f54-9ab3-75b8eb148356&amp;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f4%2fA%2fA%2f4AA524C6-239D-47FF-860B-5B397199CBF8%2fwindows-kb890830-v2.7.exe" >Direct Download</a>] or use the [<a href="http://www.gibni.com/dl/windows-kb890830-v2.7.exe" >Mirror on Gibni</a>]</li><li>ESET: [<a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://download.eset.com/special/EConfickerRemover.exe" >Direct Download</a>] or use the [<a href="http://www.gibni.com/dl/ESETConfickerRemover.exe" >Mirror on Gibni</a>]</li><li>Symantec : [<a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe" >Direct Download</a>] or use the [<a href="http://www.gibni.com/dl/SymantecFixDownadup.exe" >Mirror on Gibni</a>]</li><li>BitDefender : [<a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.bitdefender.com/site/Downloads/downloadFile/1584/FreeRemovalTool" >Direct Download</a>] or use the [<a href="http://www.gibni.com/dl/bitd_removal-antidownadup.zip" >Mirror on Gibni</a>]</li></ul><p><br class="spacer_" /></p><h3>5 - Now, the next step is to check your computer for infection and clean it!</h3><ol><li>Once you have the Removal Tool file, (if neseccary save your work and) <strong>close ALL programs and running sotftware</strong>.</li><li>Disconnect your computer (PC) by <strong>PHYSICALLY disconnecting</strong> the network cable or switching OFF the Wi-Fi adapter you have.   <em>(You may need to go to Control Panel&gt;Network Connections then right-click on each network connection available and select &#8220;Disable&#8221;)</em></li><li>Then <strong>run</strong> (double-click/open/execute call it what you like!) the Conficker Removal Tool you have!</li><li>Then <strong>restart your computer</strong> once the Conficker Removal Tool&#8217;s job is done.</li></ol><p> </p><p><strong>Follow all the instructions for the conficker removal process. The remaining steps are on the next page(s) &#8230;</strong></p><h3>6 - Install( or update) a good Security solution</h3><p>I would personally recommend BitDefender Total Security 2009 (<a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.bitdefender.com" >http://www.bitdefender.com</a>)</p><p> </p><h3>7 - Turn System Restore back ON!</h3><p>You may want to run the Conficker Removal Tool again to be sure your PC is clean. <span style="color: #ff0000;">Keep your Windows and Antivirus UP-TO-DATE!!!! (Check once a month manually at least)</span></p><p> </p><h3><span style="color: #000000;">8 &#8211; Feel GREAT!</span></h3><p><br class="spacer_" />That&#8217;s it. Digg this article by using the &#8220;ShareThis&#8221; button or the Digg It button either below the post, or at the beginning of the post, to help others stay safe. <strong><span style="text-decoration: underline;">Please spread the word and get people to read this article so you can help and save them! (<br /><script src="http://w.sharethis.com/widget/?tabs=web%2Cpost%2Cemail&amp;charset=utf-8&amp;style=default&amp;publisher=c4ada1f9-a5a2-4ccb-88b1-fc5d2f11ceda&amp;embeds=true" type="text/javascript"></script><br /> Immediately)<br /> </span></strong></p><p><br class="spacer_" /></p><p>You can send it by email to your friends and familly by using the ShareThis button too.<br class="spacer_" /></p><p><br class="spacer_" /></p><p><br class="spacer_" /></p><h3>-Read More here:</h3><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://en.wikipedia.org/wiki/Conficker" >http://en.wikipedia.org/wiki/Conficker</a></p><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;tabid=1" >http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;tabid=1</a></p><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.eset.com/threat-center/blog/?p=511" >http://www.eset.com/threat-center/blog/?p=511</a></p><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html" >http://www.bitdefender.com/VIRUS-1000462-en&#8211;Win32.Worm.Downadup.Gen.html</a></p><p><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;src=sec_doc_nam" >http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;src=sec_doc_nam</a></p> <br /><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.gdstarrating.com/" target="_blank" ><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" title="Remove Conficker (Downup, Downadup or Kido)" alt="powered Remove Conficker (Downup, Downadup or Kido)" /></a><br />]]></content:encoded> <wfw:commentRss>http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido/feed</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Conficker</title><link>http://www.gibni.com/conficker</link> <comments>http://www.gibni.com/conficker#comments</comments> <pubDate>Thu, 26 Feb 2009 13:50:44 +0000</pubDate> <dc:creator>Gi</dc:creator> <category><![CDATA[Informatique - Computers]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Computers]]></category> <category><![CDATA[Conficker]]></category> <category><![CDATA[Internet]]></category> <category><![CDATA[Urgent]]></category><guid isPermaLink="false">http://www.gibni.com/?p=567</guid> <description><![CDATA[About Conficker: On October 23, 2008, Microsoft released a critical security update, MS08-067, to resolve a vulnerability in the Server service of Windows that, at the time of release, was facing targeted, limited attack. The vulnerability could allow an anonymous attacker &#8230; <a href="http://www.gibni.com/conficker">Continue reading <span class="meta-nav">&#8594;</span></a><br /><a target="_blank" href="http://www.gdstarrating.com/"><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" /></a><br />]]></description> <content:encoded><![CDATA[<h2><span style="font-size: large;">About Conficker:</span></h2><p>On October 23, 2008, Microsoft released a critical security update, <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" >MS08-067</a>, to resolve a vulnerability in the Server service of Windows that, at the time of release, was facing targeted, limited attack. The vulnerability could allow an anonymous attacker to successfully take full control of a vulnerable system through a network-based attack, the sort of vectors typically associated with network &#8220;worms.&#8221; Since the release of <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" >MS08-067</a>, the Microsoft Malware Protection Center (MMPC) has identified two variants of <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker" >Win32/Conficker</a> in the wild to date:</p><ul><li><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm:Win32/Conficker.A" >Worm:Win32/Conficker.A</a>: identified by the MMPC on November 21, 2008</li><li><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm:Win32/Conficker.B" >Worm:Win32/Conficker.B</a>: identified by the MMPC on December 29, 2008</li></ul><p>(Source: http://technet.microsoft.com/en-us/security/dd452420.aspx )<span id="more-567"></span></p><p><br class="spacer_" /></p><p>For detailed &#8220;<strong>How to remove Conficker worm</strong>&#8221; instructions, visit this post: <a href="http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido" >How to Remove Conficker</a> (On Gibni)</p><p><br class="spacer_" /></p><p><br class="spacer_" /></p><p>If you ever heard about Microsoft (the maker of Windows and a full bundle of problems attached to it), and if you have already heard about <strong><span style="color: #ff0000;">Conficker</span></strong>, or also called <strong>Downup</strong>, <strong>Downadup or Kido, </strong>I suppose that you’ve already taken steps on protecting yourself and your friends from this computer worm (or virus as some may call it!).</p><p><a href="http://www.gibni.com/conficker/conficker_final" rel="attachment wp-att-573" ><img class="aligncenter size-medium wp-image-573" title="conficker_final" src="http://www.gibni.com/wp-content/uploads/2009/02/conficker_final-300x225.png" alt="conficker final 300x225 Conficker" width="300" height="225" /></a></p><p><strong>On February 12, 2009, Microsoft announced a U.S. $250,000 reward for information</strong> that results in the arrest and conviction of those responsible for illegally launching the Conficker malicious code on the Internet. Microsoft&#8217;s reward offer stems from the company&#8217;s recognition that the Conficker worm is a criminal attack. Microsoft wants to help the authorities catch the criminals responsible for it. Residents of any country are eligible for the reward, according to the laws of that country, because Internet viruses affect the Internet community worldwide. ( http://technet.microsoft.com/en-us/security/dd452420.aspx )</p><p><br class="spacer_" /></p><p><a href="http://www.gibni.com/conficker/graph-conb1" rel="attachment wp-att-570" ><img class="size-medium wp-image-570 alignright" title="graph-conb1" src="http://www.gibni.com/wp-content/uploads/2009/02/graph-conb1-215x300.jpg" alt="graph conb1 215x300 Conficker" width="215" height="300" /></a></p><h3>According to Yahoo Tech news:</h3><p>&#8220;The criminals behind the widespread <span id="lw_1235416368_0" class="yshortcuts">Conficker worm</span> have released a new version of the malware that could signal a major shift in the way the worm operates.</p><p>The new variant, dubbed Conficker B++, was spotted three days ago by <span id="lw_1235416368_1" class="yshortcuts">SRI International researchers</span>, who <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://mtc.sri.com/Conficker/" >published</a> details of the new code on Thursday. To the untrained eye, the new variant looks almost identical to the previous version of the worm, Conficker B. But the B++ variant uses new techniques to download software, giving its creators more flexibility in what they can do with infected machines.</p><p>The new B++ variant uses the same algorithm to look for rendezvous points, but it also gives the creators two new techniques that skip them altogether. That means that the Cabal&#8217;s most successful technique could be bypassed.&#8221;</p><p>Also known as Downadup, Conficker spreads using a variety of techniques. It exploits a dangerous <a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" >Windows bug</a> to attack computers on a local area network, and it can also spread via USB devices such as cameras or storage devices. All variants of Conficker have now infected about 10.5 million computers, according to SRI.</p><p><br class="spacer_" /></p><h3>Here&#8217;re some statistics according to SRI:  <span style="font-size: medium;">( http://mtc.sri.com/Conficker/ )</span><br /></h3><p><br class="spacer_" /></p><p><span style="font-weight: bold;">Total IP Addresses: </span>10,512,451 <big><br /> </big><span style="font-weight: bold;">Total Conficker A  IPs</span>:    4,743,658<big><br /> </big><span style="font-weight: bold;">Total Conficker B  IPs</span>:     6,767,602<big><br /> </big><span style="font-weight: bold;">Total Conficker AB IPs</span>:   1,022,062<big></big><span style="font-weight: bold;">OS Breakdown: </span><big><br /> </big>WinNT=0, 2000=163395, WinXP=10189556, 2003 Srv=75361, Vista=82495, Win98=44, Win95=32, WinCE=3, Other=1565<big></big><span style="font-weight: bold;">Browser Breakdown: </span><big><br /> </big>IE5=26,525, IE6=7,494,466, IE7=2,988,039, FireFox=893, Opera=150, Safari=166, Netscape=12</p><p><br class="spacer_" /></p><p><br class="spacer_" /></p><p><a href="http://www.gibni.com/conficker/conficker-2009-01-29-countries" rel="attachment wp-att-571" ><img class="aligncenter size-medium wp-image-571" title="conficker-2009-01-29-countries" src="http://www.gibni.com/wp-content/uploads/2009/02/conficker-2009-01-29-countries-300x193.png" alt="conficker 2009 01 29 countries 300x193 Conficker" width="300" height="193" /></a></p><p>SRI says that China is the most infected country by Conficker, and follow Brazil and Russia.</p><p>I&#8217;ve noticed that Indonesia, Thailand and India are some of the most infected countries today and people are actively searching about this virus/worm.</p><p>To note that more than <strong>9 million computers are infected</strong> worldwide till date!</p><p>For detailed &#8220;<strong>How to remove Conficker worm</strong>&#8221; instructions, visit this post: <a href="http://www.gibni.com/remove-conficker-microsoft-worm-virus-kido" >How to Remove Conficker</a> (On Gibni)</p> <br /><a target="_blank" rel="nofollow" href="http://www.gibni.com/goto/http://www.gdstarrating.com/" target="_blank" ><img src="http://www.gibni.com/wp-content/plugins/gd-star-rating/gfx/powered.png" border="0" width="80" height="15" title="Conficker" alt="powered Conficker" /></a><br />]]></content:encoded> <wfw:commentRss>http://www.gibni.com/conficker/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 11/55 queries in 0.140 seconds using disk: basic
Object Caching 2113/2152 objects using disk: basic

Served from: www.gibni.com @ 2012-02-08 04:38:51 -->
