<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AndrewSaysHello.com &#187; bot</title>
	<atom:link href="http://www.andrewsayshello.com/tag/bot/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.andrewsayshello.com</link>
	<description>Andrew&#039;s Website for Lots-o-Fun and Junk!</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:20:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Symantec Warns of Cyber Attacks Worse Than Love Bug!</title>
		<link>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/</link>
		<comments>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/#comments</comments>
		<pubDate>Mon, 10 May 2010 02:12:59 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[love bug]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[messagelabs]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1141</guid>
		<description><![CDATA[A decade after the Love Bug virus attacked millions of computers worldwide and put the Philippines in the IT world map in a negative way, computer security experts have noticed that today&#8217;s computer attacks are more malicious than the original computer security threat. In its April 2010 security report, Symantec said it has detected 36,208 unique strains [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/"></g:plusone></div><p>A decade after the Love Bug virus attacked millions of computers worldwide and put the Philippines in the IT world map in a negative way, computer security experts have noticed that today&#8217;s computer attacks are more malicious than the original computer security threat.</p>
<p>In its April 2010 security report, Symantec said it has detected 36,208 unique strains of malware that were designed to carry out targeted attacks.</p>
<p>MessageLabs, which was acquired by Symantec later, was the first one to raise the alert on the Love Bug virus, which was designed to overwrite and destroy data. The virus came in the form of a message attachment when, once opened, sent itself to the addresses of the email recipient and spread on from there.</p>
<p>Ten years since Symantec Hosted Services, then MessageLabs, intercepted 13,000 copies of the virus in a single day on 4 May 2000, MessageLabs Intelligence said it now stops 1.5 million copies of malicious e-mails each day.</p>
<p>&#8220;Although mass mailing viruses like the Love Bug are rare today, cyber criminals&#8217; techniques have evolved to more malicious, highly targeted attacks and they are motivated less by achievement and credibility than by financial gain and identity theft,&#8221; Symantec said in a statement. &#8220;On 4 May, 2000, 1 in 28 e-mails contained the Love Bug virus. By comparison, 1 in 287.2 e-mails contained a virus on 9 April 2010, the peak for April. In April 2010 overall, MessageLabs Intelligence intercepted 36,208 unique strains of malware.&#8221;</p>
<p>&#8220;The Love Bug was operating in the wake of the Melissa virus, a similarly destructive worm from the previous year,&#8221; said MessageLabs Intelligence senior analyst Paul Wood. &#8220;Back then, users were less savvy, regarding the dangers posed by suspicious e-mail attachments and e-mails from unknown senders. The general public was also less aware of issues such as spam and denial of service attacks.&#8221;</p>
<h2><strong>Bot Attacks<span style="font-weight: normal; font-size: 13px;"> </span></strong></h2>
<p>The April 2010 MessageLabs Intelligence Report also revealed that Rustock has surpassed Cutwail as the biggest botnet both in terms of the amount of spam it sends and the amount of active bots under its control.</p>
<p>The report noted that Rustock has reduced the output of individual bots by 65 per cent but increased the number of active bots by 300 per cent, thus, making up for the decreased output. Meanwhile, Cutwail has reduced in size to 600,000 bots from two million bots in May 2009 and is now responsible for only four per cent of all spam. &#8220;Rustock remains the largest spam-sending botnet responsible for 32.8 per cent of all spam,&#8221; the report read.</p>
<p>&#8220;Affected by the closure of ISP Real Host in August 2009, Cutwail likely lost the ability to update some of its bots causing its numbers to diminish greatly without the ability to recover,&#8221; said Wood. &#8220;As a result, Rustock has taken over significant volumes from spammers by undercutting the market with greater capacity and lower operational costs.&#8221;</p>
<h2><strong>Spam<span style="font-weight: normal; font-size: 13px;"> </span></strong></h2>
<p>Worldwide, the spam rate this month was pegged at 89.9 per cent, a drop of 0.8 per cent from the previous month. In the region, Malaysia and Singapore also saw a drop in the spam rate to 87.7 per cent, and 87.6 per cent respectively, the report added.</p>
<p>&#8220;Spam is more commonly sent from computers running Windows than from those running other operating systems,&#8221; Wood said. &#8220;However, spam not identified as coming from botnets was seen in lower proportions coming from Windows machines than from known botnets.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Instant Messaging Worm Spreading Fast!</title>
		<link>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/</link>
		<comments>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/#comments</comments>
		<pubDate>Tue, 04 May 2010 23:19:20 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[bkis]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[im]]></category>
		<category><![CDATA[instant message]]></category>
		<category><![CDATA[kazaa]]></category>
		<category><![CDATA[limewire]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[palevo]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[yahoo messenger]]></category>
		<category><![CDATA[yimfoca]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1138</guid>
		<description><![CDATA[A smiley-faced instant message with a photo link posing as if it&#8217;s from someone on your buddy list is actually spreading misery worldwide in the form of a worm on Yahoo Instant Messenger: The IM ultimately delivers a worm that allows an attacker to take over the victim&#8217;s machine, not to mention spread itself among [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/"></g:plusone></div><p>A smiley-faced instant message with a photo link posing as if it&#8217;s from someone on your buddy list is actually spreading misery worldwide in the form of a worm on Yahoo Instant Messenger: The IM ultimately delivers a worm that allows an attacker to take over the victim&#8217;s machine, not to mention spread itself among the victim&#8217;s contact list.</p>
<p>Researchers at BitDefender, BKIS, and Symantec today each separately warned Yahoo Messenger users about the worm attack, which is rapidly growing. Catalin Coisoi, senior malware and virus researcher for BitDefender, based in Romania, says his team has seen infection rates as high as 500 percent per hour in his home country since they first spotted it last week. &#8220;Today it started spreading like wildfire,&#8221; Coisoi says.</p>
<p>He says the socially engineered message appears to be capitalizing on the May 1 national holiday in Romania. &#8220;People expect to see pictures [from their friends and colleagues] after a national holiday,&#8221; he says. But he also expects the worm to make inroads in the U.S. today and tomorrow, with potential victims coming off of a weekend.</p>
<p>The worm &#8212; known as <a href="http://www.malwarecity.com/blog/extremely-aggressive-worm-chokes-instant-messaging-806.html" target="new">Palevo by BitDefender</a>, <a href="http://blog.bkis.com/en/new-worm-spreading-via-yahoo-messenger/" target="new">W32.Ymfocard.fam.Botnet by BKIS</a>, and <a href="http://www.symantec.com/connect/blogs/new-yahoo-messenger-worm" target="new">W32.Yimfoca by Symantec</a> &#8212; is a new variant of an existing worm. In the Yahoo IM attack, it tricks the user into saving what appears to be a JPG or GIF file, but instead is a malicious executable.</p>
<p>BitDefender says the worm contains a backdoor, which lets an attacker take over the victim&#8217;s compromised machine, to install more malware, steal files, intercept passwords, and launch spam or other malware attacks on other systems. It&#8217;s also spreading the way the infamous Conficker worm has done, via network shares and removable USB drives using the Autorun feature. When an infected memory stick gets loaded into a machine with Autorun enabled or unprotected, the machine can automatically be infected with the worm.</p>
<blockquote><p>&#8220;You can do anything you want with a backdoor &#8212; keylogging to search for passwords, or it could be a botnet,&#8221; Coisoi says. &#8220;It offers the attacker full system access.&#8221;</p></blockquote>
<p>It also spreads via peer-to-peer sharing sites, such as Kazaa and LimeWire which are all too easy to pack these types of files in with movies files and software cracks.</p>
<p>The good news: Because it drops an .exe file, it requires the user to run it for it to go live. According to Symantec, once the worm is run, it adds itself to the Windows Firewall list, stops the Windows Update service, and configures itself such that it runs each time the system boots. The worm automatically sends itself to everyone on the victim&#8217;s contact list.</p>
<blockquote><p>&#8220;The nature of this attack is nothing new, because some worms already used this way of attack,&#8221; BKIS researchers blogged. &#8220;However, it is always potentially dangerous to [unaware] users. Bad guys have integrated some phishing elements to trick [the] user into clicking the link and then opening the downloaded file.&#8221;</p></blockquote>
<p>So basically, if someone sends you a link via an instant message out of the blue, it might be best to double check with them what exactly they are sending you, so you don&#8217;t fall victim to this new worm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top 10 Signs Your Computer May be Part of a Botnet!</title>
		<link>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/</link>
		<comments>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 19:08:33 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1131</guid>
		<description><![CDATA[There are few signs that indicate your computer is part of a botnet that might not be indicating something else. Any malware can cause almost all of the same symptoms that a bot can. Sometimes conflicts between programs or corrupted files can cause the same symptoms as well, but still, there are some signs that [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/"></g:plusone></div><p>There are few signs that indicate your computer is part of a botnet that might not be indicating something else. Any malware can cause almost all of the same symptoms that a bot can. Sometimes conflicts between programs or corrupted files can cause the same symptoms as well, but still, there are some signs that should not be ignored. So, in no particular order…</p>
<p><strong>1)    Your fan kicks into overdrive when your computer is idle</strong><br />
This can indicate that a program is running without your knowledge and using a fair amount of resources. Of course this could also be a bunch of Microsoft updates being installed. Another problem that can cause the fan to kick in like that is excessive dirt in the computer or a failing CPU fan.</p>
<p><strong>2)    Your computer takes a long time to shut down, or won’t shut down properly</strong><br />
Oftentimes malicious software has bugs in it that can cause a variety of symptoms, including long shut down times of a failure to shut down. Unfortunately, operating system bugs and conflicts with legitimate programs may cause the same symptom.</p>
<p><strong>3)    You see a list of outbound Wall posts you didn’t send on your Facebook page (see below)</strong></p>
<p><strong><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam.jpg" rel="lightbox[1131]"><img class="aligncenter size-medium wp-image-1132" title="facebookspam" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam-242x300.jpg" alt="" width="242" height="300" /></a></strong></p>
<p><strong><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam.jpg" rel="lightbox[1131]"></a><span style="font-weight: normal;">There are few reasons other than malicious software or having your account hacked that would cause this problem. If you see this happening, you definitely want to change your password and make sure you computer is not infected. Best to make sure your computer is not infected before changing your password!!! Don’t use your Facebook password on multiple sites!!!</span></strong></p>
<p><strong>4)    Programs are running very slowly</strong><br />
This can be a sign that hidden programs are using a lot of your computer’s resources. This also can be a sign of other problems. On Windows systems if there are 10,000 files or more in a single directory it can really bring a system to a crawl.</p>
<p><strong>5)    You cannot download operating system updates</strong><br />
This is a symptom you cannot ignore. Even if it isn’t a bot or other malware, if you don’t keep your system patched your computer probably will get infected.</p>
<p><strong>6)    You cannot download antivirus software updates / visit vendors’ websites</strong><br />
Malware often tries to prevent antivirus software from running or being installed. An inability to update your antivirus software or visit the vendor’s web site is a pretty strong indicator of malware.</p>
<p><strong>7)    Internet access slows to a crawl</strong><br />
If a bot is using your computer to send massive amounts of spam or participate in an attack against other computers, or to upload or download a lot of data it can make your internet access very slow.</p>
<p><strong>8)    Your friends and family have received e-mail message from you that you did not send</strong><br />
This can be a sign of a bot, other malicious software, or that your webmail account has been hacked.</p>
<p><strong>9)    You receive pop-up windows and advertisements even when you are not using a web browser</strong><br />
While this is a classic sign of adware, bots can install adware on your computer. You definitely want to get this problem taken care of.</p>
<p><strong>10)    Windows Task manager shows programs with very cryptic names or descriptions</strong> (the highlighted line is the example)</p>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager.jpg" rel="lightbox[1131]"><img class="aligncenter size-medium wp-image-1133" title="taskmanager" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager-300x118.jpg" alt="" width="300" height="118" /></a></p>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager.jpg" rel="lightbox[1131]"></a>Using task manager requires some skill and research. Sometimes legitimate software uses cryptic names as well. An entry in task manager is generally not enough to identify a program as being bad. This can help you find bad programs, but many additional steps must be performed to validate you findings. Killing processes and deleting files or registry entries because you “think” it is a bot or other malware can result in the inability to even boot your computer. Be very careful of making assumptions and acting on them.</p>
<p>Although this doesn&#8217;t cover everything that could mean you are part of a botnet, this is a good list of the major signs you will see, and means you need to get your computer cleaned ASAP!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Shuts Down Global Spam Network!</title>
		<link>http://www.andrewsayshello.com/technology/microsoft-shuts-down-global-spam-network/</link>
		<comments>http://www.andrewsayshello.com/technology/microsoft-shuts-down-global-spam-network/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 14:42:33 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[commad and control]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[operation b49]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=986</guid>
		<description><![CDATA[Microsoft has won court approval to shut down a global network of computers which it says is responsible for more than 1.5bn spam messages every day. A US judge granted the firm&#8217;s request to shut down 277 internet domains, which it said were used to &#8220;command and control&#8221; the so-called Waledac botnet. A botnet is a [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/microsoft-shuts-down-global-spam-network/"></g:plusone></div><p>Microsoft has won court approval to shut down a global network of computers which it says is responsible for more than 1.5bn spam messages every day. A US judge granted the firm&#8217;s request to shut down 277 internet domains, which it said were used to &#8220;command and control&#8221; the so-called Waledac botnet.</p>
<p>A botnet is a network of infected computers under the control of hackers.</p>
<p>The firm said that closing the domains would mean that up to 90,000 PCs would stop receiving orders to send out spam.</p>
<p>A recent analysis by the firm found that between 3-21 December &#8220;approximately 651 million spam e-mails attributable to Waledac were directed to Hotmail accounts alone&#8221;. It said it was one of the 10 largest botnets in the US.</p>
<p>Machines in a botnet have usually been infected by a computer virus or worm. Typically, users do not know their machine has been hijacked.</p>
<p>Microsoft said that although it had effectively shut down the network, thousands of computers would still be infected with malware and advised people to run anti-virus software. The court order was part of what was called &#8220;Operation b49&#8243;.</p>
<p>Along with intelligence organisation Shadowserver, the University of Washington and security firm Symantec, Microsoft managed to get a court in Alexandria, Virginia, to force Verisign, which manages the .com domain, to temporarily switch off the domains.</p>
<p>Microsoft said it was the result of months of investigation and described it as a legal first.</p>
<blockquote><p>&#8220;This action has quickly and effectively cut off traffic to Waledac at the .com or domain registry level, severing the connection between the command and control centres of the botnet and most of its thousands of zombie computers around the world.&#8221;</p></blockquote>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/02/Botnet-graphic.gif" rel="lightbox[986]"><img class="aligncenter size-full wp-image-987" title="Botnet graphic" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/02/Botnet-graphic.gif" alt="" width="466" height="400" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/microsoft-shuts-down-global-spam-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

