<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Restore Store</title>
	<atom:link href="http://therestorestore.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://therestorestore.wordpress.com</link>
	<description>Computer Solutions and More</description>
	<lastBuildDate>Fri, 02 Jul 2010 01:32:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='therestorestore.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The Restore Store</title>
		<link>http://therestorestore.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://therestorestore.wordpress.com/osd.xml" title="The Restore Store" />
	<atom:link rel='hub' href='http://therestorestore.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Boot Sector Virus proves challenging &#8211; and yet not challenging</title>
		<link>http://therestorestore.wordpress.com/2010/07/02/boot-sector-virus-proves-challenging-and-yet-not-challenging/</link>
		<comments>http://therestorestore.wordpress.com/2010/07/02/boot-sector-virus-proves-challenging-and-yet-not-challenging/#comments</comments>
		<pubDate>Fri, 02 Jul 2010 01:32:49 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=652</guid>
		<description><![CDATA[So, a repeat client of mine came across the good &#8216;ol Sinowal virus. (read about it here). He switched over to a different antivirus, one provided by his ISP, namely F-secure. F-Secure began popping up alerts that he had this boot record virus. (before F-Secure, he was using Avast! antivirus. Oh, how far Avast has [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=652&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So, a repeat client of mine came across the good &#8216;ol Sinowal virus. (read about it <a href="http://www.f-secure.com/v-descs/trojan-psw_w32_sinowal_cp.shtml">here</a>). He switched over to a different antivirus, one provided by his ISP, namely F-secure. F-Secure began popping up alerts that he had this boot record virus.</p>
<p>(before F-Secure, he was using Avast! antivirus. Oh, how far Avast has fallen&#8230;. It used to be my favorite)</p>
<p>Not knowing what to do for sure, he called The Restore Store. Before calling me, he called the ISP, since they were the ones providing the A/V that detected it. They said he was hosed and it was serious. I concurred.</p>
<p>I had read a lengthy article a while ago about the nature of this virus, Sinowal, aka mebroot.</p>
<p>F-Secure wasn&#8217;t offering to remove the MBR virus, only indicating that it was there. I did some research and, after doing a thorough backup, began to apply the tools commonly used to deal with this virus.</p>
<p>The problem was, nothing was detecting it. F-Secure was adamant it was there, but &#8220;official&#8221; sinowal hunting mbr scanning tools were saying everything was fine.</p>
<p>Was it a false positive? Doubtful, F-Secure is a good outfit, but still&#8230;</p>
<p>I booted to a recovery console and used &#8220;fixboot&#8221; and &#8220;fixmbr&#8221; to no avail. Thinking it was a false positive even more.</p>
<p>Growing frustrated I disabled F-Secure and installed Avira. Avira immediately hit on it and I now had corroboration.  Avira did not offer to remove it.</p>
<p>Since Microsoft Security Essentials is my favorite A/V at the moment I removed Avira and installed that. A quick scan by MSE revealed sinowal as well.</p>
<p>Good!</p>
<p>And, MSE offered to remove it. BONUS!</p>
<p>I removed the sucker and uninstalled MSE. I rebooted the machine and F-Secure, which was still there, did not indicate the virus was back.</p>
<p>I am now proceeding to do a thorough hard drive scan to make sure the drive is sound, as it is an older machine. Then, I will &#8220;nuke and pave&#8221; and do a clean install of windows. I have my DBAN cd out, ready to go. Probably not necessary, I may not use it&#8230;</p>
<p>I think I&#8217;ll be putting on MSE, the customer can put on F-Secure if he wishes, but for me MSE earned it&#8217;s keep again today.</p>
<p>Side note: I had the pleasure of removing Norton 360 along with a truckload of viruses that were on a system today, restoring the simple ability of accessing the internet. I&#8217;ve also had the pleasure of removing various abominations from McAfee this week as well.</p>
<p>The feel of the system after simply removing McAfee is analogous to driving a small truck after just having been towing an overloaded trailer with it. It feels light, sporty, responsive, like a whole new machine ready to spring into action with the slightest touch&#8230; It&#8217;s exhilirating. Almost a high for me. Am I becoming addicted to removing norton and mcafee? Hmmm&#8230;..</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/652/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=652&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/07/02/boot-sector-virus-proves-challenging-and-yet-not-challenging/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>Never assume an intelligent customer will not make stupid mistakes</title>
		<link>http://therestorestore.wordpress.com/2010/06/23/never-assume-an-intelligent-customer-will-not-make-stupid-mistakes/</link>
		<comments>http://therestorestore.wordpress.com/2010/06/23/never-assume-an-intelligent-customer-will-not-make-stupid-mistakes/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 01:34:06 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=648</guid>
		<description><![CDATA[So, I provided a new computer to a public service agency when their old one died. This particular agency is one of the top 3 jobs which all young boys want to be when they grow up. So, the &#8220;chief&#8221; of this public department was installing microsoft office on this new computer, which I had [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=648&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So, I provided a new computer to a public service agency when their old one died. This particular agency is one of the top 3 jobs which all young boys want to be when they grow up.</p>
<p>So, the &#8220;chief&#8221; of this public department was installing microsoft office on this new computer, which I had taken great pains to get prepared for them as much as possible. They had special software that ran the database for their department, transferred all reports, updates, put in the old HD in case I missed something, delivered, set up, so on, so on.</p>
<p>But, they hadn&#8217;t provided THEIR copy of ms office, and hey, how hard can it be. The ever resourceful &#8220;chief&#8221; of this department eagerly volunteered to install it himself, once he dug it out of wherever it was that they couldn&#8217;t find at the time I was building it.</p>
<p>So I get a call today while I was out, and returned his call when I got back. He was attempting to install &#8220;office&#8221; but something didn&#8217;t look right. When I called him back, he said &#8220;hey, I put in the key it asked for and it seems to be taking off&#8221; &#8220;Ok, no problem, if you get stuck just give me a call&#8221; &#8220;Ok, I&#8217;ll do that.&#8221;</p>
<p>Fast forward 30 minutes. He calls, and says he finished installing &#8220;office&#8221;, but now office isn&#8217;t showing up anywhere and it&#8217;s now asking him to register windows. I&#8217;m stunned, so I head over.</p>
<p>As it turns out, the shiny holographic disk he was using to install &#8220;office&#8221; was actually the shiny holographic disk for &#8220;windows&#8221; and he had just wiped out his freshly set up computer. Ouch!</p>
<p>Luckily he didn&#8217;t format anything. I had him up and running again in about 1.5 hours, but as the disk was sp2 there will be some updating to do.</p>
<p>When he realized what he had done, he adamantly proclaimed that I will be doing everything 100% from now on, and not him. We both lol&#8217;d.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/648/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=648&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/06/23/never-assume-an-intelligent-customer-will-not-make-stupid-mistakes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>Digital Photocopiers Loaded With Secrets</title>
		<link>http://therestorestore.wordpress.com/2010/05/04/digital-photocopiers-loaded-with-secrets/</link>
		<comments>http://therestorestore.wordpress.com/2010/05/04/digital-photocopiers-loaded-with-secrets/#comments</comments>
		<pubDate>Tue, 04 May 2010 13:00:11 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=643</guid>
		<description><![CDATA[Your Office Copy Machine Might Digitally Store Thousands of Documents That Get Passed on at Resale By Armen Keteyian // At a warehouse in New Jersey, 6,000 used copy machines sit ready to be sold. CBS News chief investigative correspondent Armen Keteyian reports almost every one of them holds a secret. Nearly every digital copier [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=643&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>Your Office Copy Machine Might Digitally Store Thousands of  Documents That Get Passed on at Resale</h2>
<div>By  Armen Keteyian</div>
<div>//</p>
<ul>
<li> <a href="http://www.cbsnews.com/video/watch/?id=6412572n"><img src="http://i.i.com.com/cnwk.1d/i/tim//2010/04/19/419_eve_keteyian_244x183.jpg" border="0" alt="" width="244" height="183" /></a><!-- longtext start--></li>
</ul>
</div>
<p>At a warehouse in New  Jersey, 6,000 used copy machines sit ready to be sold. <strong>CBS News  chief investigative correspondent Armen Keteyian</strong> reports almost  every one of them holds a secret.</p>
<p>Nearly every digital copier built since 2002 contains a hard drive &#8211;  like the one on your personal computer &#8211; storing an image of every  document copied, scanned, or emailed by the machine.</p>
<p>In the process, it&#8217;s turned an office staple into a digital  time-bomb packed with highly-personal or sensitive data.</p>
<p>If you&#8217;re in the identity theft business it seems this would be a  pot of gold.</p>
<p><a href="http://www.cbsnews.com/stories/2010/04/19/eveningnews/main6412439.shtml">Read the rest here.</a></p>
<p><a href="http://www.computerworld.com/s/article/9013104/Photocopiers_The_newest_ID_theft_threat">And more here.</a></p>
<p><a href="http://www.thestar.com/news/gta/article/781567--high-tech-copy-machines-a-gold-mine-for-data-thieves">Still more here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/643/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/643/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/643/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=643&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/05/04/digital-photocopiers-loaded-with-secrets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>

		<media:content url="http://i.i.com.com/cnwk.1d/i/tim//2010/04/19/419_eve_keteyian_244x183.jpg" medium="image" />
	</item>
		<item>
		<title>Malware Registry Entry Points:</title>
		<link>http://therestorestore.wordpress.com/2010/04/13/malware-registry-entry-points/</link>
		<comments>http://therestorestore.wordpress.com/2010/04/13/malware-registry-entry-points/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 14:13:05 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/2010/04/13/malware-registry-entry-points/</guid>
		<description><![CDATA[Most trojans, worms, backdoors, and such make sure they will be run after a reboot by introducing autorun keys and values into the Windows registry. Some of these registry locations are better documented than others and some are more commonly used than others. One of the first steps to take when doing forensic analysis is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=642&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Most trojans, worms, backdoors, and such make  sure they will be run after a reboot by introducing autorun keys and  values into the Windows registry. Some of these registry locations are  better documented than others and some are more commonly used than  others. One of the first steps to take when doing forensic analysis is  to check the most obvious places in the registry for modifications.</p>
<p>What  are the most commonly used registry launchpoints then? We wanted to  find out so we picked a collection of several thousand samples of  malware and checked which launchpoints they were using. The results are  presented in the diagram below. It should be noted that some of the  samples used multiple launchpoints.</p>
<p>Read the rest<a href="http://www.f-secure.com/weblog/archives/00001207.html"> here:</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/642/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=642&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/04/13/malware-registry-entry-points/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>AVprofit: Rogue AV + Zeus = $</title>
		<link>http://therestorestore.wordpress.com/2010/03/25/avprofit-rogue-av-zeus/</link>
		<comments>http://therestorestore.wordpress.com/2010/03/25/avprofit-rogue-av-zeus/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 14:55:48 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=638</guid>
		<description><![CDATA[An amazing article about how the &#8220;bad guys&#8221; are making some serious coin with malware&#8230; The presence of rogue anti-virus products, also known as scareware, on a Microsoft Windows computer is often just the most visible symptom of a more serious and insidious system-wide infection. To understand why, it helps to take a peek inside [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=638&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An amazing article about how the &#8220;bad guys&#8221; are making some serious coin with malware&#8230;</p>
<div id="greet_block">
<div>
<div>
</div>
</div>
</div>
<p>The  presence of rogue anti-virus products, also known as <a href="http://voices.washingtonpost.com/securityfix/2009/09/what_to_do_when_rogue_anti-vir.html" target="_blank">scareware</a>, on a Microsoft Windows computer is often  just the most visible symptom of a more serious and insidious  system-wide infection. To understand why, it helps to take a peek inside  some of the more popular rogue anti-virus distribution networks that  are paying people to peddle scareware alongside far more invasive  threats.</p>
<p>Read the rest of this <a href="http://www.krebsonsecurity.com/2010/03/avprofit-rogue-av-zeus/">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/638/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=638&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/03/25/avprofit-rogue-av-zeus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>malware botnets have the largest &#8220;cloud&#8221;</title>
		<link>http://therestorestore.wordpress.com/2010/03/23/malware-botnets-have-the-largest-cloud/</link>
		<comments>http://therestorestore.wordpress.com/2010/03/23/malware-botnets-have-the-largest-cloud/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 16:03:20 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/2010/03/23/malware-botnets-have-the-largest-cloud/</guid>
		<description><![CDATA[Who&#8217;s got the biggest cloud in the tech universe? Google? Pretty big, but no. Amazon? Lots and lots of servers, but not even close. Microsoft? They&#8217;re just getting started. Household names all, but their capacity pales to that of the biggest cloud on the planet, the network of computers controlled by the Conficker computer worm. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=636&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Who&#8217;s got the biggest cloud in the tech universe? Google? Pretty big,  but no. Amazon? Lots and lots of servers, but not even close. <a href="http://www.networkworld.com/community/node/58631">Microsoft</a>?  They&#8217;re just getting started.</p>
<p>Household names all, but their capacity pales to that of the biggest  cloud on the planet, the network of computers controlled by the <a href="http://www.networkworld.com/news/2009/103009-after-one-year-conficker-infects.html">Conficker</a> computer worm. Conficker controls 6.4 million computer systems in 230  countries, more than 18 million CPUs and 28 terabits per second of  bandwidth, said Rodney Joffe, senior vice president and senior  technologist at the infrastructure services firm <a href="http://www.neustar.biz/">Neustar</a>.</p>
<p>Read the rest <a href="http://www.networkworld.com/community/node/58829">here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/636/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=636&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/03/23/malware-botnets-have-the-largest-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>Ripping on the mainstream security software</title>
		<link>http://therestorestore.wordpress.com/2010/03/22/ripping-on-the-mainstream-security-software/</link>
		<comments>http://therestorestore.wordpress.com/2010/03/22/ripping-on-the-mainstream-security-software/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 14:07:25 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=632</guid>
		<description><![CDATA[Back Story, for you bored people out there- I used to subscribe to the &#8220;Langa Letter&#8221; by Fred Langa. He merged with Windows Secrets a few years ago. I got THIS in a e-newsletter: http://windowssecrets.com/2010/03/18/01 saying how awesome the various internet security suites are, including McAfee. I was &#8220;horrified&#8221; to say the least.  These people [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=632&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Back Story, for you bored  people out there-  I used to subscribe to the &#8220;Langa Letter&#8221; by Fred  Langa.  He merged with Windows Secrets a few years ago.  I got THIS in a  e-newsletter: <a rel="nofollow" href="http://windowssecrets.com/2010/03/18/01" target="_blank">http://windowssecrets.com/2010/03/18/01</a> saying how awesome the  various internet security suites are, including McAfee.</p>
<p>I was &#8220;horrified&#8221; to say the least.  These people are supposed to be competent??!?</p>
<p>So, I  replied with THIS:</p>
<p>I have to ask, don&#8217;t be offended &#8211; how much  did McAfee pay you to say their software was worth more than the $0.50  CD it&#8217;s written on?  I routinely fix computers by removing the atrocity  that is all things McAfee.  McAfee has been worthless since I first had  the misfortune of encountering it in 1999&#8230;.</p>
<p>Norton is only slightly better than  McAfee because the entry level Antivirus doesn&#8217;t immediately mess up  systems.  However, the Internet Security product and 360 product are  horrible, I have personally fixed mysterious network issues and poor  system performance on more systems than I can remember &#8211; by simply  removing it.</p>
<p>The computing professionals that are in the trenches  day to day know first hand that Norton and McAfee &#8220;security&#8221; products  look good on paper but don&#8217;t stack up when the rubber hits the road.</p>
<p>To  which THEY replied:</p>
<p>Thanks for the e-mail, I&#8217;ve shared it with  the editorial team.</p>
<p>Best wishes,</p>
<p>Stephanie Small<br />
Research  Director<br />
WindowsSecrets.com<br />
Editor@WindowsSecrets.com</p>
<p>So, since I have the same exact discussion nearly every day, I went onto CNET and posted THIS as a review for Norton Internet Security 2010.  I plan to do this more often, until they reply, as per <a href="http://therestorestore.wordpress.com/2010/02/03/a-restore-store-rant/">this post</a>.</p>
<h3>I am a computing  professional. I repair them, build them, network them, and virus removal  is my specialty. I have personally FIXED many many computers by  REMOVING NORTON INTERNET SECURITY 2010 and earlier. Norton Internet  Security (and 360) is WORTHLESS JUNK. Your system might be protected at  first, but after a few mon&#8230;ths the hackers will figure it out and you  will have only a false sense of security.Norton 2009 worked  well until the middle of the year, then it was laughably worthless &#8211; I  was fixing 4 or 5 computers AT ONCE all with Norton 2009 and all with  really bad malware infections.</p>
<p>People pay good money for this  junk, and then pay me to fix their computers &#8211; by removing viruses this  software DOES NOT STOP.  I also charge them to remove the junk norton  software because when it breaks, it breaks your network connection.</p>
<p>I&#8217;ve  had people bring in their computers because their ISP told them their  network card was broken.  No, they had norton 2010 and it was broken.  I  removed Norton, fixed the network stack, removed the viruses (malware)  and they were good to go.  SHAMEFUL.</p>
<p>Microsoft Security  Essentials is FREE and it works better than this junk.  I am telling  everyone I know this information.</p>
<p>I tell people that MSE is free,  works better and WON&#8217;T break their computers, and they look at me  stunned.  THEY DIDN&#8217;T KNOW they could have good protection for FREE.   They know now, and now you do too.</p>
<p>The rogue security software  (fake antivirus like Antivirus 360 or Internet Security 2010) is a  rampant problem.  You can get these rogues no matter what, some (or  most) CANNOT be stopped.</p>
<p>If there is a burden on the user to be  careful, AS WELL AS a certain amount of chance, why pay for security  when you can be in the same boat and NOT break your computer, for free?</h3>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/632/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=632&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/03/22/ripping-on-the-mainstream-security-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>rogue database</title>
		<link>http://therestorestore.wordpress.com/2010/03/17/rogue-database/</link>
		<comments>http://therestorestore.wordpress.com/2010/03/17/rogue-database/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 14:37:59 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=629</guid>
		<description><![CDATA[http://roguedatabase.net/RogueDL.php I had a customer call me today and complain that the Microsoft Security Essentials icon was missing.  After talking with them for a minute, he mentioned he had &#8220;Malware Professional 5.0&#8243; installed.  Huh? He informed me that he paid $30 for it, and came across it from Priform CCleaner&#8217;s website.  I don&#8217;t know about [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=629&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>http://roguedatabase.net/RogueDL.php</p>
<p>I had a customer call me today and complain that the Microsoft Security Essentials icon was missing.  After talking with them for a minute, he mentioned he had &#8220;Malware Professional 5.0&#8243; installed.  Huh?</p>
<p>He informed me that he paid $30 for it, and came across it from Priform CCleaner&#8217;s website.  I don&#8217;t know about that, but I do know that Malware Professional 5.0 is a rogue.</p>
<p>My guess is that MP5 killed MSE.  Also, it was not on the Add/Remove programs list either.</p>
<p>I informed the customer as such and encouraged him to dispute the charge and get a different CC# on that account.</p>
<p>Yikes.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/629/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/629/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/629/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=629&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/03/17/rogue-database/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>Criminals Hide Payment-Card Skimmers Inside Gas Station Pumps</title>
		<link>http://therestorestore.wordpress.com/2010/02/23/criminals-hide-payment-card-skimmers-inside-gas-station-pumps/</link>
		<comments>http://therestorestore.wordpress.com/2010/02/23/criminals-hide-payment-card-skimmers-inside-gas-station-pumps/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 14:06:48 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=624</guid>
		<description><![CDATA[Wave of recent bank-card skimming incidents demonstrate how sophisticated the scam has become Feb 22, 2010 &#124; 05:20 PM By Kelly Jackson Higgins DarkReading Criminals hid bank card-skimming devices inside gas pumps &#8212; in at least one case, even completely replacing the front panel of a pump &#8212; in a recent wave of attacks that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=624&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><!-- teaser (dek) copy --><strong> Wave of recent bank-card skimming incidents demonstrate how  sophisticated the scam has become </strong></p>
<p><!-- / teaser (dek) copy -->Feb 22, 2010 | 05:20 PM</p>
<p><strong>By Kelly Jackson Higgins</strong><br />
<strong><em>DarkReading</em></strong></p>
<p><!--body--><!-- droplet bean="/cmp/shared/apps/search/droplets/HighlightKeywords"&gt;--></p>
<p>Criminals hid bank card-skimming devices inside gas pumps &#8212; in at least  one case, even completely replacing the front panel of a pump &#8212; in a  recent wave of attacks that demonstrate a more sophisticated, insidious  method of stealing money from unsuspecting victims filling up their gas  tanks.</p>
<p>Some 180 gas stations in Utah, from Salt Lake City to Provo, were  reportedly found with these skimming devices  <a href="http://www.abc4.com/content/news/tagr/story/Police-warn-of-credit-card-skimming-at-gas/se4lev5CkkaTEsYIL57Uxw.cspx" target="new">sitting inside the gas pumps</a>. The scam was first  discovered when a California bank&#8217;s fraud department discovered that  multiple bank card victims reporting problems had all used the same gas  pump at a 7-Eleven store in Utah.</p>
<p>Card skimming has been on the rise during the past year, with most  attackers rigging or replacing merchant card readers with their own  sniffer devices or ATM machines. The devices typically include a  scanner, transmitter, camera, and, most recently, Bluetooth- or  wireless-enabled links that shoot the stolen data back to the bad guys.</p>
<p>Read the whole article <a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=223100233&amp;cid=RSSfeed">here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/624/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/624/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/624/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=624&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/02/23/criminals-hide-payment-card-skimmers-inside-gas-station-pumps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
		<item>
		<title>Attackers going after end users rather than servers</title>
		<link>http://therestorestore.wordpress.com/2010/02/23/attackers-going-after-end-users-rather-than-servers/</link>
		<comments>http://therestorestore.wordpress.com/2010/02/23/attackers-going-after-end-users-rather-than-servers/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 14:04:20 +0000</pubDate>
		<dc:creator>restorestore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://therestorestore.wordpress.com/?p=622</guid>
		<description><![CDATA[The Web traffic study also finds issues with botnets, corporate policies, and outdated browsers By Paul Krill, InfoWorld February 22, 2010 08:01 PM ET Rather than targeting Web and email servers, attackers these days are prone to going after enterprises from the inside out, compromising end user systems and then using them to access confidential [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=622&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="article_subtitle">The Web traffic study also  finds issues with botnets, corporate policies, and outdated browsers</div>
<div id="article_author">By Paul Krill, InfoWorld<br />
February 22,  2010 08:01 PM ET</div>
<p>Rather than targeting Web and email servers, attackers  these days are prone to going after enterprises from the inside out,    compromising end user systems and then using them to access  confidential data, according to a Web traffic analysis report    by security-as-a-service provider Zscaler.</p>
<p>Based on a recent study of traffic passing through its global  network,  <a href="http://www.infoworld.com/whitepapers/c/Zscaler">Zscaler&#8217;s</a> &#8220;State of the Web &#8212; Q4 2009&#8243; report also notes trends including issues  with botnets, corporate Internet access policies,    and the use of the Internet Explorer 6 browser. Officially being  released on Tuesday, the study analyzes Web traffic volumes    covering several thousand Web transactions per second and hundreds of  billions of Web transactions.</p>
<p>Zscaler found attackers were prone to embedding JavaScript or  malicious iframes to pull content from an attacker&#8217;s server,    whereupon the content is rendered in a user&#8217;s browser, said Mike  Geide, senior security researcher at Zscaler, in an interview    on Monday.</p>
<p>Read the whole article <a href="http://www.networkworld.com/news/2010/022310-attackers-going-after-end-users.html">here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therestorestore.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therestorestore.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therestorestore.wordpress.com/622/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therestorestore.wordpress.com&amp;blog=9995088&amp;post=622&amp;subd=therestorestore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://therestorestore.wordpress.com/2010/02/23/attackers-going-after-end-users-rather-than-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ccd9951ed5d0b0781ea9d63baf6bac3e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">restorestore</media:title>
		</media:content>
	</item>
	</channel>
</rss>
