<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-31886761</id><updated>2012-02-10T06:58:56.425+05:30</updated><category term='future'/><category term='Win32/Spy.Bzub.NAC'/><category term='education'/><category term='Win32/Stration.ET'/><category term='f-secure'/><category term='PC.climate'/><category term='developing'/><category term='in'/><category term='storm'/><category term='email virus'/><category term='class'/><category term='computer'/><category term='malware'/><category term='virus'/><category term='worm'/><category term='video'/><category term='100$'/><category term='world'/><category term='games'/><category term='advocates'/><category term='trojan'/><category term='professor'/><category term='prediction'/><category term='laptop'/><title type='text'>Deepak Krishnan</title><subtitle type='html'>The Tech Mastermind</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-31886761.post-6211245858549079916</id><published>2007-03-08T23:20:00.000+05:30</published><updated>2007-03-08T23:22:35.713+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Win32/Spy.Bzub.NAC'/><category scheme='http://www.blogger.com/atom/ns#' term='email virus'/><title type='text'>Win32/Spy.Bzub.NAC</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;        &lt;td class="Text"&gt;Trojan-Spy.Win32.BZub.bs (Kaspersky), Spy-Agent.ak (McAfee), Infostealer.Bzup (Symantec) &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;        &lt;td class="Text"&gt;trojan &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;        &lt;td class="Text"&gt;80600 B &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;        &lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;        &lt;td class="Text"&gt;1.1707 &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;        &lt;td class="Text"&gt;Win32/Spy.BZub.NAC is a trojan that steals passwords and other sensitive information. &lt;/td&gt;      &lt;/tr&gt;    &lt;/tbody&gt; &lt;/table&gt; &lt;br /&gt;&lt;br /&gt; &lt;p class="Text Subtitle"&gt;&lt;b&gt;Installation&lt;/b&gt;&lt;/p&gt;  &lt;span class="Text"&gt;The following file is dropped in the %system% folder: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;agent_dq.dll&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;p class="Text"&gt;It is a Browser Helper Object for Internet Explorer. Size of the file is 60928 B. &lt;/p&gt;  &lt;p class="Text"&gt;&lt;br /&gt; The following Registry entries are set: &lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73364D99-1240-4dff-B11A-67E448373048}]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;InprocServer32]&lt;br /&gt; (Default) = "%system%\ipv6mons.dll"&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;InprocServer32]&lt;br /&gt; "ThreadingModel" = "apartment"&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;InprocServer32]&lt;br /&gt; "Enable Browser Extensions" = "yes"&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;Parameters\&lt;/span&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;FirewallPolicy\&lt;/span&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;StandardProfile\AuthorizedApplications\List]&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;"C:\Program Files\Internet Explorer\IEXPLORE.EXE" = "C:\Program Files\Internet Explorer\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;IEXPLORE.EXE:*:Enabled:Internet Explorer&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\loadnet_insll]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\worg]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\cmpid]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\forwas]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\h]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\nw]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\wspopp]&lt;br /&gt;&lt;br /&gt; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;&lt;span class="codeSample"&gt;browser helper obJects\{73364D99-1240-4dff-B11A-67E448373048}]&lt;/span&gt;&lt;br /&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="Text Subtitle"&gt;&lt;br /&gt; &lt;b&gt;Information stealing&lt;/b&gt;&lt;/p&gt;  &lt;span class="Text"&gt;The trojan collects various information when Internet Explorer is being used to access the following sites:&lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;app/ueberweisung.input.do,app/ueberweisung.prep.do&lt;br /&gt; banking.postbank.de,&lt;br /&gt; banking.postbank.de/app/finanzstatus.reduziert.init.do,&lt;br /&gt; banking.postbank.de/app/kontoumsatz.umsatz.init.do,&lt;br /&gt; banking.postbank.de/app/legitimation.input.do,&lt;br /&gt; banking.postbank.de/app/ueberweisung.quittung.do,&lt;br /&gt; e-gold.com/acct/acct.asp,&lt;br /&gt; https://*.netbank.commbank.com.au/netbank/bankmain,&lt;br /&gt; https://banking.postbank.de/app/finanzstatus.init.do,&lt;br /&gt; https://banking.postbank.de/app/kontoumsatz.umsatz.init.do,&lt;br /&gt; https://banking.postbank.de/app/welcome.do,&lt;br /&gt; https://signin.ebay*/ws/eBayISAPI.dll,postbank.de&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;Some information is found in local files too. The following information is collected: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;passwords ,URLs visited ,HTML forms content ,computer name ,computer IP, address ,Outlook Express accounts data ,digital certificates&lt;br /&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;The data is saved in the %system% folder in the following files: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;form.txt,info.txt,shot.html&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;The trojan can upload the information to a remote machine. The FTP protocol is used.&lt;br /&gt; &lt;br /&gt; &lt;/span&gt; &lt;p class="Text Subtitle"&gt;&lt;b&gt;Other information&lt;/b&gt;&lt;/p&gt;  &lt;span class="Text"&gt;The trojan may attempt to delete all files on the C: drive and various program files.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-6211245858549079916?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/6211245858549079916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=6211245858549079916' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/6211245858549079916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/6211245858549079916'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/03/win32spybzubnac.html' title='Win32/Spy.Bzub.NAC'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-300442712282351097</id><published>2007-03-08T23:05:00.000+05:30</published><updated>2007-03-08T23:19:30.442+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Win32/Stration.ET'/><category scheme='http://www.blogger.com/atom/ns#' term='email virus'/><title type='text'>Win32/Stration.ET</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;        &lt;td class="Text"&gt;Email-Worm.Win32.Warezov.gen (Kaspersky), W32/Stration@MM (McAfee), W32.Stration@mm (Symantec) &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;        &lt;td class="Text"&gt;worm &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;        &lt;td class="Text"&gt;116320 B &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;        &lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;        &lt;td class="Text"&gt;1.1775 &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;        &lt;td class="Text"&gt;Win32/Stration.ET is a worm that spreads via e-mail. &lt;/td&gt;      &lt;/tr&gt;    &lt;/tbody&gt; &lt;/table&gt;  &lt;span class="Text"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;Installation&lt;/strong&gt;  &lt;span class="Text"&gt; :When executed, the %windir% copies itself in the folder using the following filename :&lt;/span&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt; t2serv.exe&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span class="Text"&gt; The following files are dropped in the same folder: &lt;/span&gt;   &lt;div class="codeSample" style="margin-left: 40px;"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;t2serv.dll &lt;/span&gt;&lt;br /&gt; &lt;span style="font-family:Courier New, Courier, mono;"&gt;t2serv.wax&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family:Courier New, Courier, mono;"&gt;t2serv.s&lt;/span&gt;&lt;/div&gt;  &lt;p style="margin-left: 40px;"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;span class="Text"&gt; The following files are dropped in the %system% folder: &lt;/span&gt; &lt;p style="margin-left: 40px;" class="codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;kbdaqosn.dll &lt;/span&gt;&lt;br /&gt; &lt;span style="font-family:Courier New, Courier, mono;"&gt;mqpeh323.dll &lt;/span&gt;&lt;br /&gt; &lt;span style="font-family:Courier New, Courier, mono;"&gt;vjoyslay.exe&lt;/span&gt;&lt;/p&gt;    &lt;span class="Text"&gt; In order to be executed on every system start, the worm sets the following Registry entry: &lt;/span&gt; &lt;p style="margin-left: 40px;" class="Text codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt; "t2serv" = "%windir%\t2serv s"&lt;/span&gt;&lt;/p&gt;    &lt;span class="Text"&gt; The following Registry entry is set: &lt;/span&gt; &lt;p style="margin-left: 40px;" class="Text codeSample"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]&lt;br /&gt; "AppInit_DLLs" = "kbdaqosn.dll e1.dll"&lt;/span&gt;&lt;/p&gt;    &lt;span class="Text"&gt; A Notepad window with random text is displayed. &lt;/span&gt;   &lt;p class="Text Subtitle"&gt;&lt;strong&gt;Spreading via e-mail&lt;/strong&gt;&lt;/p&gt;  &lt;span class="Text"&gt; E-mail addresses for further spreading are searched for in local files with one of the following extensions: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;.adb,.asp,.cfg,.cgi,.dbx,.dhtm,.eml,.htm,.html,.jsp,.mbx,.mdx,&lt;br /&gt; .msg,.nch,.ods,.oft ,.php,.sht,.shtm,.stm,.tbb ,.txt,.uin .wab,.wsh,.xls,.xml&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; Addresses containing the following strings are avoided: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;.edu,.gov,.mil,@avp,@foo,admin,anyone@,apache,berkeley,bsd,bugs@&lt;br /&gt; cafee,certific,contact,contract@,example,fido,ftp,gnu,gold-certs&lt;br /&gt; google,help,help@,ibm.com,icrosoft,info@,kasp,kernel,linux,local&lt;br /&gt; master,mozilla,mydomai,news,nobody,noone,noreply,panda,pgp,privacy&lt;br /&gt; rating,rfc-ed,ripe.,root@,samples,secure,sendmail,service,somebody&lt;br /&gt; someone,spam,support,unix,update,update,usenet,winrar,winzip,www&lt;br /&gt; xx,you,your&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; Strings from the following 4 lists may be used to form the sender address: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;sec,serv,secur,adam ,alice ,anna ,betty ,bob ,brenda ,brent brian,carol ,claudia ,craig ,cyber ,dan ,dave ,david ,debby den,Donn,frank,george,gerhard,helen,james,jane,jayson,jerry&lt;br /&gt; jim,joe,john,karen,linda,lisa,mancy,maria,ruth,sandra,sharon&lt;br /&gt; Susan,adams,allen,anderson,baker,carter,clark,garcia,gonzalez,&lt;br /&gt; green,,hall,harris,hernandez,hill,jackson,jeremy,joe,kenneth&lt;br /&gt; king,lee,lewis,lopez,martin,martinez,miller,molly,moore,nelson&lt;br /&gt; robinson,,robyn,rodriguez,scott,shaan,taylor,thomas,thompson&lt;br /&gt; walker,white,wilson,wright ,young,areainc.com,,logoluso.com&lt;br /&gt; heatwave.com,megaman.com,scholzes.com,guierfence.com,tjh.com&lt;br /&gt; phazen.net,fcradio.net,niet.com,gametemple.com,midmich.net&lt;br /&gt; vieng.com,elamex.com,sycamorepd.com,selectplans.com&lt;br /&gt; motorsportwarehouse.com,telcan.com,iinet.net.au,firstclassmoving.com&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; Subject of the message is one of the following: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;Mail server report,Server Report,Mail Delivery System,test&lt;br /&gt; picture,hello,Status,Error,Good day,Mail Transaction Failed&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; Body of the message is one of the following: &lt;/span&gt; &lt;p style="font-style: italic;"&gt;&lt;span style="font-family:Courier New, Courier, mono;font-size:85%;"&gt;&lt;span class="codeSample"&gt;Mail transaction failed. Partial message is available. &lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;The message contains Unicode characters and has been sentas a binary attachment.&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;The message cannot be represented in 7-bit ASCII encodingand has been sent as a binary attachment&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Mail server report.&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Our firewall determined the e-mails containing worm copies are being sent from your computer.&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Nowadays it happens from many computers, because this is a new virus type (Network Worms).&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Using the new bug in the Windows, these viruses infect the computer unnoticeably.&lt;/span&gt;&lt;br /&gt;  &lt;span class="codeSample"&gt;After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail&lt;/span&gt;&lt;br /&gt;  &lt;span class="codeSample"&gt;addresses&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Please install updates for worm elimination and your computer restoring.&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;span class="codeSample"&gt;Best regards,&lt;/span&gt;&lt;br /&gt;  &lt;span class="codeSample"&gt;Customers support service&lt;/span&gt;&lt;br /&gt; &lt;/span&gt;&lt;/p&gt;  &lt;span class="Text"&gt; The attachment is either an executable of the worm, or a ZIP archive containing it. Its filename is one of the following: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;body,data,doc,docs,document,file,message,readme,test,text,Update-KB-abcd-x86&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The "abcd" stands for a variable four digit number. If an archive is attached, the name has the following extension: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;.zip&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; If an executable is attached, a double extension may be used. The first is one of the following: &lt;/span&gt; &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;&lt;span class="codeSample"&gt;dat,&lt;/span&gt;&lt;span class="codeSample"&gt;doc,&lt;/span&gt;&lt;span class="codeSample"&gt;elm,&lt;/span&gt;&lt;span class="codeSample"&gt;log,&lt;/span&gt;&lt;span class="codeSample"&gt;msg,&lt;/span&gt;&lt;span class="codeSample"&gt;txt&lt;/span&gt;&lt;br /&gt; &lt;/span&gt;&lt;/p&gt;  &lt;span class="Text"&gt; The second is one of the following: &lt;/span&gt;   &lt;p class="Text"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;&lt;span class="codeSample"&gt;bat,&lt;/span&gt;&lt;span class="codeSample"&gt;cmd,&lt;/span&gt;&lt;span class="codeSample"&gt;exe,&lt;/span&gt;&lt;span class="codeSample"&gt;pif,&lt;/span&gt;&lt;span class="codeSample"&gt;scr&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;&lt;span class="codeSample"&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;Other information&lt;/strong&gt;&lt;/p&gt;  &lt;span class="Text"&gt; The worm quits immediately if any of the following applications is detected: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;Outpost Firewall,McAfee Personal Firewall,Kerio Winroute Firewall,ZoneAlarm,Sygate Personal Firewall,Norton Internet Security&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The following programs are terminated: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;nod32krn,avginet,avgupsvc,upgrader,drwebupw,spiderml,autodown&lt;br /&gt; kav,mcupdate,tbmon,wuauclt,wuauclt1,wupdmgr&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The worm contains a list of URLs. It tries to download several files from the addresses. The files are then executed.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-300442712282351097?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/300442712282351097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=300442712282351097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/300442712282351097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/300442712282351097'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/03/win32strationet.html' title='Win32/Stration.ET'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-8391947660696071087</id><published>2007-01-19T18:58:00.000+05:30</published><updated>2007-02-11T11:30:44.845+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='prediction'/><category scheme='http://www.blogger.com/atom/ns#' term='PC.climate'/><category scheme='http://www.blogger.com/atom/ns#' term='future'/><title type='text'>Your PCs forecast climate future</title><content type='html'>&lt;table style="text-align: left; margin-left: 0px; margin-right: auto;" border="0" cellpadding="0" cellspacing="0" width="629"&gt;&lt;tbody&gt;                            &lt;tr&gt;                     &lt;td valign="top" width="416"&gt;                                                    &lt;span style="font-size:85%;"&gt;       &lt;!-- S BO --&gt; &lt;!-- S IIMA --&gt;     &lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="203"&gt;    &lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;         &lt;!-- E IIMA --&gt; &lt;!-- S SF --&gt; &lt;b&gt;A computer model of climate run on home PCs in conjunction with the BBC has yielded its first results.&lt;/b&gt; &lt;/span&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;About 250,000 people downloaded software from climateprediction.net onto their home computers, each running a single simulation of the future. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The results suggest the UK could be about 3C warmer than now in 75 years' time, agreeing with other models. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Full details will be revealed at the weekend in a BBC TV programme presented by Sir David Attenborough. &lt;!-- E SF --&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;Big spread&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Members of the scientific team say they have been staggered by the level of interest shown in the project. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"When it started, we said to ourselves that we would be happy if 10,000 people took part," said Nick Faull, climateprediction.net project co-ordinator. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"So to see more than 10 times as many signing up was fantastic," he told the BBC News website &lt;/span&gt;&lt;/p&gt;&lt;p&gt;  &lt;span style="font-size:85%;"&gt;         &lt;!-- S IBOX --&gt;&lt;!-- E IBOX --&gt; Users were spread across 171 countries. About two-thirds were in the UK; a number of countries including Surinam, Swaziland and Togo were represented by single users. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Each downloaded a software pack from climateprediction.net which ran when their computer was otherwise idle, with results being fed back to the central server. Each simulation required about three months of computing time on an average PC. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The model itself was developed by the Hadley Centre, part of the UK Meteorological Office, and usually runs on giant supercomputers. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"The main difference is that when you run it in in-house, you can get a wider range of information out because you have much greater resources to store and transfer data," commented Vicky Pope, head of the climate prediction programme at the Met Office. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"It's mainly been done as an educational tool, although the output is useful." &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Distributed computing has been used before, notably by the Search for Extra-Terrestrial Intelligence (Seti), where several million people have downloaded software enabling them to analyse data from observations of distant stars for signs of alien life. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="203"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;    &lt;div&gt;     &lt;img src="http://newsimg.bbc.co.uk/media/images/41319000/jpg/_41319986_laptopbbc203.jpg" alt="Hands at a laptop keyboard.  Image: BBC" border="0" height="152" hspace="0" vspace="0" width="203" /&gt;     &lt;div class="cap"&gt;Climateprediction.net uses the power of thousands of ordinary PCs&lt;/div&gt;    &lt;/div&gt;    &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;Within bounds&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The responses from this project have now been analysed by the team, which is funded by the Natural Environment Research Council and closely linked to Oxford University. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;For 2020, the prediction is that temperatures in Britain will be about 1.2C warmer than in the 1970s, chosen as the baseline for this project. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Temperatures are already almost 1C warmer than in the 1970s, so the rise over the next decade or so will be small if the model is right. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;In 2050, they will be about 2.5C higher than the 1970s; while by 2080, the figure could be 4C. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The predictions are not exact; and the further from the present day you look, the greater variability there is, so that by 2080 the rise could be as low as 2C or as high as 6C. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Along with higher temperatures the model predicts greater variability in rainfall, with increased risks of floods and of long dry periods. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"These figures basically support the scientific consensus at the moment," observed Dr Faull &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"What makes it especially interesting is that we have included changes to the Sun's output, based on what it has done over the last century; and we find it doesn't make much difference. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"The idea that such changes could influence climate over and above the human influence we don't find very likely." &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The model also produced predictions for the climate globally, but these are under wraps at the moment as the team awaits formal publication in a scientific journal. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The state of the global consensus will become clearer in early February when the Intergovernmental Panel on Climate Change (IPCC), the body charged with collating scientific data, publishes the first segment of its fourth assessment report. &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;courtesy: BBC News&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-8391947660696071087?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/8391947660696071087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=8391947660696071087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/8391947660696071087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/8391947660696071087'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/your-pcs-forecast-climate-future.html' title='Your PCs forecast climate future'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-621465830856891739</id><published>2007-01-19T18:55:00.000+05:30</published><updated>2007-01-19T18:58:00.309+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='f-secure'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='computer'/><category scheme='http://www.blogger.com/atom/ns#' term='storm'/><title type='text'>Storm Worm hits computers around the world</title><content type='html'>&lt;p&gt;HELSINKI (Reuters) - Computer virus writers started to use raging European storms on Friday to attack thousands of computers in an unusual real-time assault, head of research at Finnish data security firm F-Secure (FSC1V.HE: &lt;a href="http://stocks.us.reuters.com/stocks/overview.asp?symbol=FSC1V.HE&amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Quote&lt;/a&gt;, &lt;a href="http://stocks.us.reuters.com/stocks/fullDescription.asp?symbol=FSC1V.HE&amp;WTmodLoc=NewsArt-C1-ArticlePage1" class=""&gt;Profile&lt;/a&gt; , &lt;a href="http://stocks.us.reuters.com/stocks/analystResearch.asp?symbol=FSC1V.HE&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Research&lt;/a&gt;) told Reuters.&lt;/p&gt;&lt;p&gt;The virus, which the company named "Storm Worm" is sent to hundreds of thousands of email addresses globally, with the e-mail's subject line saying "230 dead as storm batters Europe."&lt;/p&gt;&lt;p&gt;The attached file contains the so-called malware that can infiltrate computer systems.&lt;/p&gt;&lt;p&gt;"What makes this exceptional is the timely nature of the attack," Mikko Hypponen, head of research at F-Secure said.&lt;/p&gt;     &lt;p&gt; &lt;/p&gt;&lt;p&gt;Hypponen said thousands of computers around the world, most in private use, had been affected.&lt;/p&gt;&lt;p&gt;He said most users would not notice the malware, or trojan, which creates a back door to the computer that can be exploited later to steal data or to use the computer to post spam.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Courtesy: Reuters&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-621465830856891739?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/621465830856891739/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=621465830856891739' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/621465830856891739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/621465830856891739'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/storm-worm-hits-computers-around-world.html' title='Storm Worm hits computers around the world'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-1367914507773295378</id><published>2007-01-13T15:50:00.000+05:30</published><updated>2007-01-13T15:54:40.714+05:30</updated><title type='text'>Digital home seen boosting PCs; price an obstacle</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://today.reuters.com/misc/GenImage.aspx?uri=2007-01-12T135151Z_01_N09215079_RTRUKOP_2_PICTURE0.jpg&amp;resize=w192"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 206px; height: 310px;" src="http://today.reuters.com/misc/GenImage.aspx?uri=2007-01-12T135151Z_01_N09215079_RTRUKOP_2_PICTURE0.jpg&amp;resize=w192" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;LAS VEGAS (Reuters) - High-definition TVs, supercharged gaming computers and sophisticated audio equipment on display at this week's Consumer Electronics Show in Las Vegas are likely to drive new computer hardware demand, but high prices may deter some consumers.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;From high-end PCs to gaming microchips and data storage equipment, scores of product categories stand to gain from the arrival of the long-awaited, long-hyped, digital home.&lt;/p&gt;&lt;p&gt;This year at CES, the biggest U.S. show of its type, PC makers Hewlett-Packard Co. (HPQ.N: &lt;a href="http://stocks.us.reuters.com/stocks/overview.asp?symbol=HPQ.N&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Quote&lt;/a&gt;, &lt;a href="http://stocks.us.reuters.com/stocks/fullDescription.asp?symbol=HPQ.N&amp;WTmodLoc=NewsArt-C1-ArticlePage1" class=""&gt;Profile&lt;/a&gt; , &lt;a href="http://stocks.us.reuters.com/stocks/analystResearch.asp?symbol=HPQ.N&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Research&lt;/a&gt;) and Dell Inc. (DELL.O: &lt;a href="http://stocks.us.reuters.com/stocks/overview.asp?symbol=DELL.O&amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Quote&lt;/a&gt;, &lt;a href="http://stocks.us.reuters.com/stocks/fullDescription.asp?symbol=DELL.O&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1" class=""&gt;Profile&lt;/a&gt; , &lt;a href="http://stocks.us.reuters.com/stocks/analystResearch.asp?symbol=DELL.O&amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Research&lt;/a&gt;) displayed digital homes at the show using their computers, monitors, printers and TVs.  &lt;/p&gt;   &lt;p&gt; &lt;/p&gt;&lt;p&gt;The companies have turned to calling the PC a "home server," the hub of a network of wirelessly connected devices sending Internet video, high-definition movies, TV programs, music, photos and documents from one room to another.&lt;/p&gt;&lt;p&gt;Even computer disk drive makers such as Seagate Technology (STX.N: &lt;a href="http://stocks.us.reuters.com/stocks/overview.asp?symbol=STX.N&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Quote&lt;/a&gt;, &lt;a href="http://stocks.us.reuters.com/stocks/fullDescription.asp?symbol=STX.N&amp;WTmodLoc=NewsArt-C1-ArticlePage1" class=""&gt;Profile&lt;/a&gt; , &lt;a href="http://stocks.us.reuters.com/stocks/analystResearch.asp?symbol=STX.N&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Research&lt;/a&gt;) and Japan's Hitachi Ltd. (6501.T: &lt;a href="http://stocks.us.reuters.com/stocks/overview.asp?symbol=6501.T&amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Quote&lt;/a&gt;, &lt;a href="http://stocks.us.reuters.com/stocks/companyNews.asp?symbol=6501.T&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1" class=""&gt;NEWS&lt;/a&gt; , &lt;a href="http://stocks.us.reuters.com/stocks/analystResearch.asp?symbol=6501.T&amp;amp;WTmodLoc=NewsArt-C1-ArticlePage1"&gt;Research&lt;/a&gt;) see opportunity in consumer electronics as high-definition video, photos and music require ever-greater amounts of data storage. Hitachi last week unveiled a record-breaking disk drive capable of holding 1 terabyte, or 1,000 gigabytes, of data.&lt;/p&gt;&lt;p&gt;COST IS THE RUB&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-1367914507773295378?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/1367914507773295378/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=1367914507773295378' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/1367914507773295378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/1367914507773295378'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/digital-home-seen-boosting-pcs-price.html' title='Digital home seen boosting PCs; price an obstacle'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-8052694234038984222</id><published>2007-01-13T15:47:00.000+05:30</published><updated>2007-01-13T15:50:01.838+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='video'/><category scheme='http://www.blogger.com/atom/ns#' term='advocates'/><category scheme='http://www.blogger.com/atom/ns#' term='games'/><category scheme='http://www.blogger.com/atom/ns#' term='class'/><category scheme='http://www.blogger.com/atom/ns#' term='professor'/><category scheme='http://www.blogger.com/atom/ns#' term='in'/><title type='text'>University Professor Advocates Video Games in Class</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span id="ctl00_MainContent_lblSummary" class="ArticleSummary"&gt;Current style of education is too old says a university professor&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;p class="MsoNormal"&gt;According to David Williamson Shaffer, an education science professor at the University of Wisconsin-Madison, &lt;a href="http://www.extremetech.com/article2/0,1558,2082433,00.asp"&gt;school kids should be allowed to play video games in school&lt;/a&gt;. Shaffer says that video games will provide a higher order of learning for today's generation of kids who are tech savvy.&lt;/p&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;p class="MsoNormal"&gt;Shaffer told reporters that the current way our education system works -- at least in North America -- is centuries old and was designed for the industrial revolution rather than the information age. Shaffer feels that today's education system is simply lacking in terms of innovation. This is what Shaffer says will prevent kids from competing with those who have been in the work force for years.&lt;/p&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;p class="MsoNormal"&gt;While many people will disagree with Shaffer, he did indicate that innovation in education will drive innovation in the industry. "People think that the way we teach kids in schools is the natural way we should learn. But young people in the United States today are being prepared for standardized jobs in a world that will, very soon, punish those who can't innovate. We simply can't 'skill and drill' our way to innovation," expressed Shaffer.&lt;/p&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;p class="MsoNormal"&gt;One of Shaffer's primary concerns is that he feels U.S. students are falling behind compared to students in rising countries such as China and India. According to Shaffer, kids should be allowed to browse the web, instant message each other and even use their iPods during class lesson -- although he did fail to mention any negative impacts this might have on kids paying attention to what's being taught. In one positive way, if a child was feeling that his teacher was moving too slow with a particular subject, he or she could simply “&lt;a href="http://dailytech.com/article.aspx?newsid=3834"&gt;Google&lt;/a&gt;” it as the teacher continues to speak.&lt;/p&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;/span&gt;&lt;span id="ctl00_MainContent_lblBody"&gt;&lt;p class="MsoNormal"&gt;Shaffer is currently working on developing educational games that will help students learn about subjects such as history, chemistry, physics and other topics. Shaffer will start to promote his computer game-focused education system to various schools starting in March of this year.&lt;/p&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-8052694234038984222?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/8052694234038984222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=8052694234038984222' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/8052694234038984222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/8052694234038984222'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/university-professor-advocates-video.html' title='University Professor Advocates Video Games in Class'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-2201205944549276696</id><published>2007-01-13T15:46:00.000+05:30</published><updated>2007-01-13T15:47:40.404+05:30</updated><title type='text'>Connecting the digital home</title><content type='html'>&lt;p&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;It has long been promised that the PC will become the entertainment hub of the home. However, the problem with this vision is that our computers tend to sit in the bedroom and means getting those movies, music and pictures the last few metres to the living room is a real pain. &lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;  &lt;!-- S IIMA --&gt; &lt;span style="font-size:85%;"&gt;    &lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="203"&gt;    &lt;tbody&gt;&lt;tr&gt;&lt;td&gt;    &lt;div&gt;     &lt;img alt="Teenager watching TV" src="http://newsimg.bbc.co.uk/media/images/42442000/jpg/_42442821_tv_afp203.jpg" border="0" height="152" hspace="0" vspace="0" width="203" /&gt;     &lt;div class="cap"&gt;Many devices deliver content from your PC to your TV&lt;/div&gt;    &lt;/div&gt;    &lt;/td&gt;&lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;         &lt;!-- E IIMA --&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;This year's CES - the world's largest consumer gadget show - boasts a wealth of new kit which aims to make it easier to access digital media around the home - and in particular on TV screens. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Ideas on what should be at the centre of it all vary, from PC-based media centres, digital video recorders or even video game consoles. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Microsoft is promoting its Xbox 360 as the place to store and access movies and songs. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"Xbox 360 is at its heart, the world's best games console and we're continuing to sell it very well. But we also know that people have it connected to their TV, and that means they want to see movies," said Robert Bach of Microsoft. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"So we've added a Download Movie service, we've added an HD DVD movie player to it. You want to play music, so you can take your MP3 player or Zune player, and plug it in and see your music. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"Here we're announcing that you can take IPTV digital TV services and run them on top of an Xbox 360." &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;It should be pointed out that the downloads are only available to those that have a hard drive for their Xbox 360.  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Sony's PS3 console does something similar. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;  &lt;!-- S IIMA --&gt; &lt;span style="font-size:85%;"&gt;    &lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="203"&gt;    &lt;tbody&gt;&lt;tr&gt;&lt;td&gt;    &lt;div&gt;     &lt;img alt="Apple TV" src="http://newsimg.bbc.co.uk/media/images/42442000/jpg/_42442883_appletvap203b.jpg" border="0" height="152" hspace="0" vspace="0" width="203" /&gt;     &lt;div class="cap"&gt;Apple TV streams music and movies from a computer to a TV &lt;/div&gt;    &lt;/div&gt;    &lt;/td&gt;&lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;         &lt;!-- E IIMA --&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Microsoft's ambitions also include its Media Centre software which has not made the impact some had hoped for. It will now get a boost by being integrated into all but the most basic versions of Microsoft's new PC operating system - Vista. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The consumer versions of Vista is scheduled for launch on 30 January.  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Apple is getting in on the act too. At the MacWorld show Apple boss Steve Jobs gave more details of Apple TV - the set-top box which uses iTunes to stream media to a television. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Various launches at CES suggest that moving files around the house should be easy. We have more choices now than ever before - hardwire Ethernet cables, Bluetooth or wi-fi. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Netgear's new Digital Entertainer set-top box is one of several here that let you stream HD pictures from your PC over wi-fi to the TV. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;But obstructions and interference may hamper a steady picture. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;Compatibility&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Presuming we can move our digital media files around without too much problem, you then have to consider the alphabet soup which is compression formatting - or codecs - which allow all your devices to understand each other, otherwise you will not see a thing. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"Many of the files that people would like to buy and download, including movies and TV shows, are actually protected with what's called DRM, that is Digital Rights Management software," said Josh Bernoff an analyst from Forrester Research. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"A lot of this software is incompatible with some of these devices. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"So for example, if you buy a movie or TV show from iTunes it'll work fine on your iPod but it's unlikely to work on, say, your Xbox 360 that happens to be connected to the same setup." &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Slowly this is changing. For instance, last month if you had bought a rights-protected Windows music file it would not have played on Sonos' high-end multi-room streaming system. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;After a year of negotiations Sonos' hardware can now support those files. Now the boss of Sonos wants Apple to also open up, claiming it is customers who lose out. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"I think it's unbelievably frustrating because you purchase the music expecting to be able to play it where you would like to play it and then you find out later that this is not quite the case," said John MacFarlane of Sonos. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"That's not, generally, well explained at the point of purchase."  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The steady march of technology is also helping break down these barriers. For instance, a new PC to TV chip by start-up Quartics might help audio and video streaming compatibility. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt; It allows any files your laptop can read to be streamed over wi-fi to your TV or digital projector.  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;It is hoped the chip - which can be updated with any new video formats as they emerge - will be integrated into some TVs by the end of the year. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Many companies are supporting a set of standardised formats through industry groups like the Digital Living Network Alliance (DLNA). &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;And the new faster 802.11n standard for wi-fi should soon be ratified, which will help boost consumers' confidence in streaming video. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;But for now it might be best to take all the hype with a pinch of salt.&lt;/span&gt;&lt;/p&gt; &lt;!-- E BO --&gt; &lt;span style="font-size:85%;"&gt;                        &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-2201205944549276696?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/2201205944549276696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=2201205944549276696' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/2201205944549276696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/2201205944549276696'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/connecting-digital-home.html' title='Connecting the digital home'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-4855358434354654847</id><published>2007-01-13T15:40:00.000+05:30</published><updated>2007-01-13T15:46:33.327+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='laptop'/><category scheme='http://www.blogger.com/atom/ns#' term='education'/><category scheme='http://www.blogger.com/atom/ns#' term='world'/><category scheme='http://www.blogger.com/atom/ns#' term='100$'/><category scheme='http://www.blogger.com/atom/ns#' term='developing'/><title type='text'>$100 laptop could sell to public</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;The backers of the One Laptop Per Child project are looking at the possibility of selling the machine to the public. &lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;One idea would be for customers to have to buy two laptops at once - with the second going to the developing world. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Five million of the laptops will be delivered to developing nations this summer, in one of the most ambitious educational exercises ever undertaken. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Michalis Bletsas, chief connectivity officer for the project, said eBay could be a partner to sell the laptop. &lt;!-- E SF --&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"If we started selling the laptop now, we would do very good business," Mr Bletsas, speaking at the Consumer Electronics Show, told BBC News. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;         &lt;!-- S IBOX --&gt;  &lt;table style="width: 37px; height: 36px;" align="right" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr&gt;&lt;td style="vertical-align: top;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="5"&gt;&lt;br /&gt;&lt;/td&gt;                      &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;       &lt;!-- E IBOX --&gt;          "But our focus right now is on the launch in the developing world."  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Nicholas Negroponte, chairman and founder of the OLPC group, emphasised that the launch to the poorest parts of the world was the organisation's main task. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Of plans to sell the machine, he said: "Many commercial schemes have been considered and proposed that may surface in 2008 or beyond, one of which is 'buy 2 and get 1'." &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;Durable&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The laptop has been developed to be as low cost, durable and as simple to use as possible.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The eventual aim is to sell the machine to developing countries for $100 but the current cost of the machine is about $150. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The first countries to sign up to buying the machine, which is officially dubbed XO, include Brazil, Argentina, Uruguay, Nigeria, Libya, Pakistan and Thailand. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The XO's software has been designed to work specifically in an educational context. It has built-in wireless networking and video conferencing so that groups of children can work together. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;  &lt;span style="font-size:85%;"&gt;         &lt;!-- S IBOX --&gt;  &lt;table style="width: 208px; height: 108px;" align="right" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr&gt;             &lt;td width="5"&gt;&lt;img alt="" src="http://newsimg.bbc.co.uk/shared/img/o.gif" border="0" height="1" hspace="0" vspace="0" width="5" /&gt;&lt;/td&gt;             &lt;td class="sibtbg"&gt;                                                                                &lt;div&gt;  &lt;div class="mva"&gt;    &lt;b&gt;[The industry] should look to connect th next five and a half billion. &lt;/b&gt;&lt;br /&gt; &lt;/div&gt;     &lt;/div&gt;                                                            &lt;div class="mva"&gt;  &lt;div&gt;Michalis Bletsas, chief connectivity officer, One Laptop Per Child&lt;/div&gt;   &lt;/div&gt;                              &lt;/td&gt;         &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;       &lt;!-- E IBOX --&gt;          &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The project is also working to ensure that children using the laptop around the world can be in contact. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"I'd like to make sure that kids all around the world start to communicate. It will be a very interesting experiment to see what will happen when we deploy a million laptops in Brazil and a million laptops in Namibia." &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;'Glue'&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The OLPC project is working with Google who will act as "the glue to bind all these kids together".  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;  &lt;!-- S IIMA --&gt; &lt;span style="font-size:85%;"&gt;    &lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="203"&gt;    &lt;tbody&gt;&lt;tr&gt;&lt;td&gt;    &lt;div&gt;     &lt;img alt="One Laptop Per Child machine" src="http://newsimg.bbc.co.uk/media/images/42432000/jpg/_42432231_olpctwo203.jpg" border="0" height="152" hspace="0" vspace="0" width="203" /&gt;     &lt;div class="cap"&gt;The machine is close to a final design&lt;/div&gt;    &lt;/div&gt;    &lt;/td&gt;&lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;         &lt;!-- E IIMA --&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Google will also help the children publish their work on the internet so that the world can observe the "fruits of their labour", said Mr Bletsas. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt; He said that the hope was to put the machine on sale to the general public "sometime next year".  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"How to do that efficiently without adding to the cost is difficult," he said. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt; "We're discussing it with our partner eBay. We need to minimise supply chain cost , which is pretty high in the western world." &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;Philanthropic organisation&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;Mr Bletsas said that a philanthropic organisation would be formed to organise the orders and delivery of the laptops. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt; "It's much more difficult to do this than making the laptop," he said.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;The aim is to connect the buyer of the laptop with the child in the developing world who receives the machine. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"They will get the e-mail address of the kid in the developing world  that they have, in effect, sponsored." &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt; Mr Bletsas was speaking amidst the festival of consumerism taking place on the show floor of CES.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;He said he hoped that the laptop project would help children enrich their lives to the extent that one day they could become consumers of the types of technologies on display in Las Vegas. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;'Castigated'&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;But he castigated the industry for being unambitious in its plan to "connect the next billion people". &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"They should look to connect the next five and a half billion.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"The way to do it is not to try and deploy tried and trusted technology but to try and develop technology specifically targeted to the developing world." &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;He said that OLPC was ensuring that laptops were being deployed to areas where there was internet access.  &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"We are trying to help the governments - that ranges from donating resources, to making sure that we work with them and that they don't consider the laptop as something that can work in a disconnected environment. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"It's vitally important that children are connected. My ambition is that we will get them connect to a vast amount of information that is unavailable to them. &lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;"It will stimulate their interest in looking further - not waiting for some teacher or an adult."&lt;!-- E BO --&gt;                         &lt;/span&gt;       &lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-4855358434354654847?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/4855358434354654847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=4855358434354654847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/4855358434354654847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/4855358434354654847'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2007/01/100-laptop-could-sell-to-public.html' title='$100 laptop could sell to public'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116646466264585887</id><published>2006-12-18T23:26:00.000+05:30</published><updated>2006-12-18T23:27:43.023+05:30</updated><title type='text'>'You' named Time's person of 2006</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;b&gt;"You" have been named as Time magazine's Person of the Year for the growth and influence of user-generated content on the internet.&lt;/b&gt; &lt;/span&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The US magazine praised the public for "seizing the reins of the global media" and filling the web's virtual world. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Time has been giving its controversial awards since 1927, aiming to identify those who most affect the news. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Iranian President Mahmoud Ahmadinejad, Chinese leader Hu Jintao and North Korea's Kim Jong-il were 2006 runners. &lt;!-- E SF --&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Microsoft founder Bill Gates, his wife Melinda and rock star Bono won the accolade last year and recent winners also include President George W Bush in 2004, and "The American Soldier" in 2003. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;&lt;b&gt;'Wresting power'&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;The magazine said naming a collectivity rather than an individual reflected the way the internet was shifting the balance of power within the media through blogs, videos and social networks. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;  &lt;span style="font-size:85%;"&gt;         &lt;!-- S IBOX --&gt;  &lt;table align="right" border="0" cellpadding="0" cellspacing="0" width="208"&gt;  &lt;tbody&gt;&lt;tr&gt;             &lt;td width="5"&gt;&lt;br /&gt;&lt;/td&gt;             &lt;td class="sibtbg"&gt;&lt;br /&gt;&lt;/td&gt;         &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;       &lt;!-- E IBOX --&gt;          &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Time cited websites such as YouTube, Facebook, MySpace and Wikipedia, which allow users to interact with the web by uploading and publishing their own comments, videos, pictures and links. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"It's about the many wresting power from the few and helping one another for nothing and how that will not only change the world, but also change the way the world changes," Time magazine's Lev Grossman writes. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Time praised the tool that made such broad collaboration possible - the web. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;"It's a tool for bringing together the small contributions of millions of people and making them matter," Mr Grossman said. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Time aims to pick "the person or persons who most affected the news and our lives, for good or for ill".  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-size:85%;"&gt;Previous winners have often sparked controversy - including Adolf Hitler in 1938 and, in 1979, Iran's Ayatollah Khomeini. &lt;/span&gt;&lt;/p&gt; -------&lt;br /&gt;Courtesy:&lt;br /&gt;BBC Technology&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116646466264585887?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116646466264585887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116646466264585887' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646466264585887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646466264585887'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/12/you-named-times-person-of-2006.html' title='&apos;You&apos; named Time&apos;s person of 2006'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116646451296321684</id><published>2006-12-18T23:24:00.000+05:30</published><updated>2006-12-18T23:26:32.910+05:30</updated><title type='text'>Browser Smackdown: Firefox vs. IE vs. Opera vs. Safari</title><content type='html'>&lt;p&gt;Four experts go head-to-head (to-head-to-head) to defend their Web browser of choice in an opinionated free-for-all.&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;December 06, 2006 &lt;/b&gt;  &lt;a href="http://www.computerworld.com/" target="_blank"&gt;(Computerworld)&lt;/a&gt; -- People may be passionate about their favorite sports team, but if you really want to get them fired up, ask what Web browser they use. &lt;/p&gt;&lt;p&gt;There's the "if it ain't broke, don't fix it" crowd who tend to stick with the browser that's included with their operating system -- Microsoft's Internet Explorer on Windows and Apple's Safari on the Mac. There are the "I've just gotta be me" folks who prefer lesser-known browsers, such as Opera from Opera Software. And there are the "live free or die" open-source true believers who champion Mozilla's Firefox above its commercial counterparts.&lt;/p&gt;  &lt;p&gt;Then there are those people who simply demand the best browsing experience there is. They'll defend their favorite browser to the death because they think it kicks all the other browsers' butts in terms of elegance, features, security and so on. But if a better option comes along, they'll happily switch and speak out just as loudly for their new browser of choice. At &lt;i&gt;Computerworld&lt;/i&gt;, we fall into this camp, always looking for the Next Great Browser.&lt;/p&gt;    &lt;table bgcolor="#ffffff" border="0" cellpadding="0" cellspacing="0" width="250"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td width="3"&gt;&lt;br /&gt;&lt;/td&gt; &lt;td align="center"&gt; &lt;hr align="center"   width="234" style="font-size:78%;color:black;"&gt; &lt;span style="font-weight: bold; color: rgb(155, 3, 0);font-size:14;" &gt;Browser Smackdown&lt;/span&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;  &lt;tr&gt; &lt;td width="3"&gt;&lt;br /&gt;&lt;/td&gt; &lt;td&gt; &lt;p&gt;&lt;img src="http://www.computerworld.com/common/images/site/features/2006/122006/browser_ff_logo_sm.gif" alt="Firefox logo" align="left" border="0" height="45" hspace="2" width="45" /&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005614&amp;amp;pageNumber=2"&gt;Firefox 2&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;Simply put, Firefox is the best browser of all, says Scot Finnie.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;img src="http://www.computerworld.com/common/images/site/features/2006/122006/browser_ie_logo_sm.gif" alt="IE logo" align="left" border="0" height="45" hspace="2" width="45" /&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005614&amp;amp;pageNumber=4"&gt;Internet Explorer 7&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;IE enjoys 80% market share for good reason, says Preston Gralla.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;img src="http://www.computerworld.com/common/images/site/features/2006/122006/browser_op_logo_sm.gif" alt="Opera logo" align="left" border="0" height="43" hspace="2" width="45" /&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005614&amp;amp;pageNumber=6"&gt;Opera 9&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;It's all about features, claims Dennis Fowler, and Opera's got the most.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;img src="http://www.computerworld.com/common/images/site/features/2006/122006/browser_sf_logo_sm.gif" alt="Safari logo" align="left" border="0" height="45" hspace="2" width="45" /&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005614&amp;amp;pageNumber=8"&gt;Safari 2&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;On the Mac, Safari is untouchable, according to Ken Mingis.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;img src="http://www.computerworld.com/computerworld/images/clear.gif" border="0" height="2" width="1" /&gt;&lt;br /&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005705"&gt;Side-by-Side Comparison&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;Get a peek at how each browser handles key features and functions.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://www.computerworld.com/action/poll.do?command=showPoll&amp;pollID=9005694"&gt;Reader Poll&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-size:11;" &gt;Vote for your favorite browser.&lt;/span&gt;&lt;/p&gt;  &lt;hr align="center" color="black" size="1" width="234"&gt; &lt;/td&gt; &lt;td height="12" width="16"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;In terms of market share, the winner is obvious. Most estimates show Internet Explorer commanding between 80% and 85% of the browser market, with Firefox trailing at somewhere between 8% and 13%. Safari is the third most popular browser, with approximately 2% to 4% market share, followed by Opera and AOL's Netscape, with around 1% each.&lt;/p&gt;  &lt;p&gt;But in terms of quality, there's no clear winner right now. For years, Internet Explorer lagged far behind the competition in both features and security, but the October launch of IE7, a fairly radical overhaul of the aged browser, has brought it up to par with the rest. Almost simultaneously, Mozilla released Firefox 2.0, a less ambitious update that nevertheless made some important and well-thought-out improvements.&lt;/p&gt;  &lt;p&gt;Meanwhile, Safari (currently in Version 2.04) and Opera (in Version 9.02, with 9.1 on the way) have been quietly improving and innovating away from the spotlight. Thus, for the first time in years, the top browsers are roughly equal. (Note: We chose to leave Netscape out of our browser roundup. In our testing, we found it too buggy and unstable for serious consideration.)&lt;/p&gt;  &lt;p&gt;So which browser should you use? Which is really best? To help you decide, we asked four power users to do battle in support of their chosen browser: Scot Finnie for Firefox, Preston Gralla for Internet Explorer, Dennis Fowler for Opera and Ken Mingis for Safari.&lt;/p&gt;  &lt;p&gt;Each expert is positive that his browser is the best and will try his hardest to convince you of that. These are not rational, disengaged reviews; these are opinionated essays meant to sway your point of view.&lt;/p&gt;  &lt;p&gt;When you've read all the arguments and looked at our &lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005705"&gt;side-by-side comparison of features&lt;/a&gt;&lt;/b&gt;, you make the call by voting in our &lt;b&gt;&lt;a href="http://www.computerworld.com/action/poll.do?command=showPoll&amp;amp;pollID=9005694"&gt;best browser poll&lt;/a&gt;&lt;/b&gt;. You can also &lt;b&gt;&lt;a href="mailto:editor@computerworld.com?subject=browser_smackdown"&gt;drop us a line&lt;/a&gt;&lt;/b&gt; and let us know what you think.&lt;/p&gt;  &lt;p&gt;Many readers have objected to &lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005614&amp;amp;pageNumber=5#numbers"&gt;Preston Gralla's assertion&lt;/a&gt;&lt;/b&gt; that Internet Explorer's commanding market share shows that users are happiest with that browser. For their comments, see &lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9005813"&gt;Readers say IE's market-share numbers depend on how, and what, you count&lt;/a&gt;&lt;/b&gt;. Other readers have taken this opportunity to let us know which browsers they particularly love or hate, and why. You'll find those engaging responses in &lt;b&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9005900"&gt;Readers smack back on Web browsers&lt;/a&gt;&lt;/b&gt;.&lt;/p&gt;  &lt;i&gt;--&lt;br /&gt;Courtesy:&lt;br /&gt;ComputerWorld.com&lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116646451296321684?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116646451296321684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116646451296321684' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646451296321684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646451296321684'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/12/browser-smackdown-firefox-vs-ie-vs.html' title='Browser Smackdown: Firefox vs. IE vs. Opera vs. Safari'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116646426085745829</id><published>2006-12-18T23:17:00.000+05:30</published><updated>2006-12-18T23:21:01.796+05:30</updated><title type='text'>The 2006 Geminid Meteor Shower</title><content type='html'>&lt;table border="0" cellpadding="0" cellspacing="0" width="600"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align="left" width="571"&gt;&lt;br /&gt;&lt;/td&gt;                 &lt;td align="right" width="124"&gt; &lt;span class="storyTitle"&gt; &lt;/span&gt;                                     &lt;br /&gt;&lt;/td&gt;               &lt;/tr&gt;               &lt;tr&gt;                  &lt;td colspan="2"&gt;                    &lt;!-- Body starts --&gt;                   &lt;div class="storylink" align="center"&gt; &lt;strong&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;font-size:85%;"&gt;                      &lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;                   &lt;span style="font-family:Arial, Helvetica, sans-serif;font-size:85%;"&gt;                    &lt;!-- Begin Alternates --&gt;                   &lt;/span&gt;                    &lt;p&gt; &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;                      &lt;strong&gt;Dec.                      12 , 2006:&lt;/strong&gt; The best meteor shower of the year peaks                      this week on Dec. 13th and 14th.&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;a href="http://science.nasa.gov/headlines/y2006/images/geminids/Brock1.jpg"&gt;&lt;img src="http://science.nasa.gov/headlines/y2006/images/geminids/Brock1_med.jpg" alt="see caption" align="right" border="1" height="323" hspace="10" width="270" /&gt;&lt;/a&gt;"It's                      the Geminid meteor shower," says Bill Cooke of NASA's                      Meteoroid Environment Office in Huntsville, Alabama. "Start                      watching on Wednesday evening, Dec. 13th, around 9 p.m. local                      time," he advises. "The display will start small                      but grow in intensity as the night wears on. By Thursday morning,                      Dec. 14th, p&lt;/span&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;eople                      in dark, rural areas could see one or two meteors every minute."&lt;/span&gt;&lt;/p&gt;                   &lt;p class="detailImageDesc"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;strong&gt;Right:&lt;/strong&gt;                      Geminid meteors photographed in Dec. 2004 by Jason A.C. Brock                      of Roundtimber, Texas. [&lt;a href="http://spaceweather.com/meteors/gallery_13dec04.htm"&gt;More&lt;/a&gt;]&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;The                      source of the Geminids is a mysterious object named 3200 Phaethon.                      "No one can decide what it is," says Cooke. &lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;The                      mystery, properly told, begins in the 19th century: Before                      the mid-1800s there were no Geminids, or at least not enough                      to attract attention. The first Geminids appeared suddenly                      in 1862, surprising onlookers who saw dozens of meteors shoot                      out of the constellation Gemini. (That's how the shower gets                      its name, the Geminids.)&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Astronomers                      immediately began looking for a comet. Meteor showers result                      from debris that boils off a comet when it passes close to                      the Sun. When Earth passes through the debris, we see a meteor                      shower. &lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;For                      more than a hundred years astronomers searched in vain for                      the parent comet. Finally, in 1983, NASA's Infra-Red Astronomy                      Satellite (IRAS) spotted something. It was several kilometers                      wide and moved in about the same orbit as the Geminid meteoroids.                      Scientists named it 3200 Phaethon.&lt;/span&gt;&lt;/p&gt;                   &lt;table align="right" border="0" cellpadding="3" cellspacing="0" width="130"&gt;                     &lt;tbody&gt;&lt;tr&gt;                        &lt;td width="100%"&gt; &lt;table align="center" border="1" cellpadding="5" cellspacing="0" width="115"&gt;                           &lt;tbody&gt;&lt;tr&gt;                              &lt;td bg style="color:#ffffff;"&gt; &lt;div align="center"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;a href="http://science.nasa.gov/news/subscribe.htm"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;                                &lt;/div&gt;&lt;/td&gt;                           &lt;/tr&gt;                         &lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;                     &lt;/tr&gt;                   &lt;/tbody&gt;&lt;/table&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Just                      one problem: Meteor showers are supposed to come from comets,                      but 3200 Phaethon seems to be an asteroid. It is rocky (not                      icy, like a comet) and has no obvious tail. Officially, 3200                      Phaethon is catalogued as a "PHA"—a potentially                      hazardous asteroid whose path misses Earth's orbit by only                      2 million miles.&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;If                      3200 Phaethon is truly an asteroid, with no tail, how did                      it produce the Geminids? "Maybe it bumped up against                      another asteroid," offers Cooke. "A collision could                      have created a cloud of dust and rock that follows Phaethon                      around in its orbit."&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;This                      jibes with studies of Geminid fireballs. Some astronomers                      have studied the brightest Geminid meteors and concluded that                      the underlying debris must be rocky. Density estimates range                      from 1 to 3 g/cm&lt;sup&gt;3&lt;/sup&gt;. That's much denser than flakes                      of comet dust (0.3 g/cm&lt;sup&gt;3&lt;/sup&gt;), but close to the density                      of rock (3 g/cm&lt;sup&gt;3&lt;/sup&gt;).&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;So,                      are the Geminids an "asteroid shower"?&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Cooke                      isn't convinced. 3200 Phaethon might be a comet after all--"an                      extinct comet," he says. The object's orbit carries it                      even closer to the Sun than Mercury. Extreme solar heat could've                      boiled away all of Phaethon's ice long ago, leaving behind                      this rocky skeleton "that merely looks like an asteroid."&lt;/span&gt;&lt;/p&gt;                   &lt;p&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;In                      short, no one knows. It's a mystery to savor under the stars—the                      &lt;em&gt;shooting&lt;/em&gt; stars—this Thursday morning. &lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;courtesy:&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116646426085745829?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116646426085745829/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116646426085745829' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646426085745829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116646426085745829'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/12/2006-geminid-meteor-shower.html' title='The 2006 Geminid Meteor Shower'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116358783483497939</id><published>2006-11-15T16:11:00.000+05:30</published><updated>2006-11-15T16:24:06.843+05:30</updated><title type='text'>A new e-mail worm : Win32/Stration.AA</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;&lt;td class="Text"&gt;Email-Worm.Win32.Warezov.o (Kaspersky) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;&lt;td class="Text"&gt;worm &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;&lt;td class="Text"&gt;136 kB &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;&lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;&lt;td class="Text"&gt;1.1735 &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;&lt;td class="Text"&gt;Win32/Stration.AA is a worm that spreads via e-mail. &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span class="Text"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="Subtitle"&gt;&lt;strong&gt;Installation&lt;/strong&gt;&lt;/p&gt;&lt;span class="Text"&gt; When executed, the worm copies itself in the %windir% folder using the following filename: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;rsmbx.exe&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; The following files are dropped in the same folder: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;rsmbx.dll&lt;br /&gt;rsmbx.gfx&lt;br /&gt;rsmbx.wax&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; The following files are dropped in the %system% folder: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;cmut449c14b7.dll&lt;br /&gt;hpzl449c14b7.exe&lt;br /&gt;msji449c14b7.dll&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; In order to be executed on every system start, the worm sets the following Registry entry: &lt;/span&gt;&lt;p class="Text codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"rsmbx" = "%windir%\rsmbx.exe s"&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt; The following Registry entry is set: &lt;/span&gt;&lt;p class="Text codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]&lt;br /&gt;"AppInit_DLLs" = "msji449c14b7.dll"&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt; A Notepad window with random text is displayed.&lt;/span&gt;&lt;br /&gt;&lt;span style="color:red;"&gt; &lt;/span&gt; &lt;p class="Subtitle"&gt;&lt;strong&gt;Spreading via e-mail&lt;/strong&gt;&lt;/p&gt;&lt;span class="Text"&gt; E-mail addresses for further spreading are searched for in local files with one of the following extensions: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;.adb,.asp,.cfg,.cgi,.dbx,.dhtm,.eml,.htm,.html,.jsp,.mbx,.mdx,.mht,.mmf,.msg,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;.nch,.ods,.oft,.php,.sht,.shtm,.stm,.tbb,.txt,.uin,.wab,.wsh,.xls,.xml&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; Addresses containing the following strings are avoided: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;.edu,.gov,.mil,@avp,@foo,admin,anyone@,berkeley,bsd,bugs@,cafee,certific,contact,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;contract@,example,fido,gnu,gold-certs,google,help,help@,ibm.com,icrosoft,info@,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;kasp,kernel,linux,local,master,mozilla,mydomai,news,nobody,noone,noreply,panda,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;pgp,pch,privacy,rating,rfc-ed,ripe.,root@,samples,secure,sendmail,service,smbdy,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;smn,spam,support,unix,update,update,,usnt,winrar,winzip,www,xx,yu,yur&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; Strings from the following three lists may be used to form the sender address: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;adam,alice,anna,betty,bob,brenda,brent,brian,carol,claudia,craig,cyber,dan,dave,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;david,debby,den,Donn,frank,george,gerhard,helen,helen,james,jane,jayson,jerry,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;jim,joe,john,karen,linda,lisa,mancy,maria,ruth,sandra,sharon,Susan,adams,allen,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;anderson,baker,carter,clark,garcia,gonzalez,green,hall,harris,hernandez,hill,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;jackson,jeremy,joe,kenneth,king,lee,lewis,lopez,martin,martinez,miller,molly,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;moore,nelson,robinson,robyn,rodriguez,scott,shaan,taylor,thomas,thompson,walker,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;white,wilson,wright,young&lt;br /&gt;&lt;br /&gt;gmail.com,inbox.com,fasmail.fm,yahoo.com,mail.aim.com,mail.lycos.com,care2.com,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;goowy.com,hotmail.com,email.myway.com&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; Random strings may be used instead. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Text"&gt; Subject of the message is one of the following: &lt;/span&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;hello,&lt;/span&gt;&lt;span class="codeSample"&gt;picture,&lt;/span&gt;&lt;span class="codeSample"&gt;Server Report,&lt;/span&gt;&lt;span class="codeSample"&gt;Status,&lt;/span&gt;&lt;span class="codeSample"&gt;test,&lt;/span&gt;&lt;span class="codeSample"&gt;Good day,&lt;/span&gt;&lt;span class="codeSample"&gt;Error,&lt;/span&gt;&lt;span class="codeSample"&gt;Mail, Delivery System,&lt;/span&gt;&lt;span class="codeSample"&gt;Mail Transaction Failed&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt; Body of the message is one of the following: &lt;/span&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;Mail transaction failed. Partial message is available.&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;The message contains Unicode characters and has been sentas a binary attachment.&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;The message cannot be represented in 7-bit ASCII encodingand has been sent as a binary attachment&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt; The attachment is an executable of the worm. Its filename is one of the following: &lt;/span&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;body,&lt;/span&gt;&lt;span class="codeSample"&gt;data,&lt;/span&gt;&lt;span class="codeSample"&gt;doc,&lt;/span&gt;&lt;span class="codeSample"&gt;docs,&lt;/span&gt;&lt;span class="codeSample"&gt;document,&lt;/span&gt;&lt;span class="codeSample"&gt;file,&lt;/span&gt;&lt;span class="codeSample"&gt;message,&lt;/span&gt;&lt;span class="codeSample"&gt;readme,&lt;/span&gt;&lt;span class="codeSample"&gt;test,&lt;/span&gt;&lt;span class="codeSample"&gt;text&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt; A double extension is used. The first one is one of the following: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;dat,doc,elm,log,msg,txt&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; The second one is one of the following: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;bat,cmd,exe,pif,scr&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116358783483497939?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116358783483497939/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116358783483497939' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116358783483497939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116358783483497939'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/11/new-e-mail-worm-win32strationaa.html' title='A new e-mail worm : Win32/Stration.AA'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116160418922786960</id><published>2006-10-23T17:18:00.000+05:30</published><updated>2006-11-15T16:30:40.133+05:30</updated><title type='text'>A trojan virus : Win32/Spy.Bzub.NAC</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;        &lt;td class="Text"&gt;Trojan-Spy.Win32.BZub.bs (Kaspersky), Spy-Agent.ak (McAfee), Infostealer.Bzup (Symantec) &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;        &lt;td class="Text"&gt;trojan &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;        &lt;td class="Text"&gt;80600 B &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;        &lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;        &lt;td class="Text"&gt;1.1707 &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;        &lt;td class="Text"&gt;Win32/Spy.BZub.NAC is a trojan that steals passwords and other sensitive information. &lt;/td&gt;      &lt;/tr&gt;    &lt;/tbody&gt; &lt;/table&gt;&lt;br /&gt;&lt;b&gt;Installation&lt;/b&gt;&lt;br /&gt;&lt;span class="Text"&gt;The following file is dropped in the %system% folder: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;agent_dq.dll&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;p class="Text"&gt;It is a Browser Helper Object for Internet Explorer. Size of the file is 60928 B. &lt;/p&gt;  &lt;p class="Text"&gt;&lt;br /&gt;The following Registry entries are set: &lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73364D99-1240-4dff-B11A-67E448373048}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;InprocServer32]&lt;br /&gt;(Default) = "%system%\ipv6mons.dll"&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;InprocServer32]&lt;br /&gt;"ThreadingModel" = "apartment"&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73364D99-1240-4dff-B11A-67E448373048}\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;InprocServer32]&lt;br /&gt;"Enable Browser Extensions" = "yes"&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;Parameters\&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;FirewallPolicy\&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;StandardProfile\AuthorizedApplications\List]&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;"C:\Program Files\Internet Explorer\IEXPLORE.EXE" = "C:\Program Files\Internet Explorer\&lt;/span&gt;&lt;/p&gt;  &lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;IEXPLORE.EXE:*:Enabled:Internet Explorer&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\loadnet_insll]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\worg]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\cmpid]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\forwas]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\h]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\nw]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load\wspopp]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;browser helper obJects\{73364D99-1240-4dff-B11A-67E448373048}]&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="Text Subtitle"&gt;&lt;b&gt;Information stealing&lt;/b&gt;&lt;/p&gt;  &lt;span class="Text"&gt;The trojan collects various information when Internet Explorer is being used to access the following sites:&lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;app/ueberweisung.input.do,app/ueberweisung.prep.do&lt;br /&gt;banking.postbank.de,&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;e-gold.com/acct/acct.asp&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;,&lt;br /&gt;banking.postbank.de/app/finanzstatus.reduziert.init.do&lt;br /&gt;banking.postbank.de/app/kontoumsatz.umsatz.init.do&lt;br /&gt;banking.postbank.de/app/legitimation.input.do&lt;br /&gt;banking.postbank.de/app/ueberweisung.quittung.do&lt;br /&gt;https://*.netbank.commbank.com.au/netbank/bankmain&lt;br /&gt;https://banking.postbank.de/app/finanzstatus.init.do&lt;br /&gt;https://banking.postbank.de/app/kontoumsatz.umsatz.init.do&lt;br /&gt;https://banking.postbank.de/app/welcome.do&lt;br /&gt;https://signin.ebay*/ws/eBayISAPI.dll,&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;postbank.de&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;Some information is found in local files too. The following information is collected: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;passwords, URLs visited, HTML forms content, computer name, computer IP, address,Outlook Express accounts data, digital certificates&lt;/p&gt;  &lt;/blockquote&gt;&lt;br /&gt;&lt;span class="Text"&gt;The data is saved in the %system% folder in the following files: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;form.txt,info.txt,shot.html&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;The trojan can upload the information to a remote machine. The FTP protocol is used.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;p class="Text Subtitle"&gt;&lt;b&gt;Other information&lt;/b&gt;&lt;/p&gt;  &lt;span class="Text"&gt;The trojan may attempt to delete all files on the C: drive and various program files.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116160418922786960?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116160418922786960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116160418922786960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116160418922786960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116160418922786960'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/trojan-virus-win32spybzubnac.html' title='A trojan virus : Win32/Spy.Bzub.NAC'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116116555621822277</id><published>2006-10-18T15:27:00.000+05:30</published><updated>2006-10-18T15:29:16.316+05:30</updated><title type='text'>Joke.Poltergeist</title><content type='html'>Updated: October 17, 2006 03:50:28 PM GDT&lt;br /&gt;Type: Joke Program&lt;br /&gt;Risk Impact: Low&lt;br /&gt;Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XPWhen the program runs, it performs the following actions:&lt;br /&gt;Creates the following folder:C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox\Profiles\[RANDOM STRING]\extensions\{c3a73ed1-d3e3-436d-8867-1b599c8c30f9}&lt;br /&gt;Creates the following files:&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox\Profiles\[RANDOM STRING]\extensions.ini&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox\Profiles\[RANDOM STRING]\extensions.rdf&lt;br /&gt;May change some additional configuration files in the following folders:&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox\Profiles\[RANDOM STRING]&lt;br /&gt;%UserProfile%\Local Settings\Application Data\Mozilla\Firefox\Profiles\[RANDOM STRING]Note: %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).&lt;br /&gt;Adds an entry to the following log file:%ProgramFiles%\Mozilla Firefox\install.logNote: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.&lt;br /&gt;Opens the following local TCP ports and waits for incoming connections:&lt;br /&gt;666&lt;br /&gt;13013&lt;br /&gt;Allows a remote user to connect to the computer and execute any of the following commands:&lt;br /&gt;Display an alert message&lt;br /&gt;Redirect Firefox to a new location&lt;br /&gt;Play a sound file&lt;br /&gt;Shake the open windows&lt;br /&gt;Replace words in the viewed Web sites&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116116555621822277?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116116555621822277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116116555621822277' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116116555621822277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116116555621822277'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/jokepoltergeist.html' title='Joke.Poltergeist'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116116499452323979</id><published>2006-10-18T15:17:00.000+05:30</published><updated>2006-10-18T15:19:55.450+05:30</updated><title type='text'>New threat !!! W32.Wikedir@mm</title><content type='html'>Discovered: October 17, 2006&lt;br /&gt;Updated: October 17, 2006 03:44:30 PM PDT&lt;br /&gt;Type: Worm&lt;br /&gt;Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XPW32.Wikedir@mm is a worm that spreads through email and file sharing networks. The worm installs a copy of &lt;a href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2002-042612-1006-99"&gt;Backdoor.Evilbot&lt;/a&gt; on to the compromised computer.&lt;br /&gt;Protection&lt;br /&gt;Virus Definitions (LiveUpdate™ Daily) October 18, 2006&lt;br /&gt;Virus Definitions (LiveUpdate™ Weekly) October 18, 2006&lt;br /&gt;Virus Definitions (Intelligent Updater) October 18, 2006&lt;br /&gt;Virus Definitions (LiveUpdate™ Plus) October 18, 2006&lt;br /&gt;Threat Assesment&lt;br /&gt;Wild&lt;br /&gt;Wild Level: Low&lt;br /&gt;Number of Infections: 0 - 49&lt;br /&gt;Number of Sites: 0 - 2&lt;br /&gt;Geographical Distribution: Low&lt;br /&gt;Threat Containment: Easy&lt;br /&gt;Removal: Easy&lt;br /&gt;Damage&lt;br /&gt;Damage Level: Low&lt;br /&gt;Payload: Spreads through email and file sharing networks.&lt;br /&gt;Distribution&lt;br /&gt;Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116116499452323979?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116116499452323979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116116499452323979' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116116499452323979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116116499452323979'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/new-threat-w32wikedirmm.html' title='New threat !!! W32.Wikedir@mm'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116099655586386305</id><published>2006-10-16T16:23:00.000+05:30</published><updated>2006-10-16T16:47:36.203+05:30</updated><title type='text'>I am great!!!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/3913/3475/1600/Deepak.0.jpg"&gt;&lt;img style="CURSOR: pointer" alt="" src="http://photos1.blogger.com/blogger/3913/3475/400/Deepak.jpg" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116099655586386305?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116099655586386305/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116099655586386305' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116099655586386305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116099655586386305'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/i-am-great.html' title='I am great!!!'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116063839885749024</id><published>2006-10-12T13:01:00.000+05:30</published><updated>2006-11-15T16:49:21.280+05:30</updated><title type='text'>Win32/VB.NEI</title><content type='html'>&lt;table style="width: 100%;" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr class="Text"&gt;&lt;td style="width: 125px; vertical-align: top;"&gt;&lt;span style="font-weight: bold;"&gt;Aliases:&lt;/span&gt;&lt;/td&gt; &lt;td style="vertical-align: top;"&gt; &lt;p&gt;Win32.Worm.VB.TB (Bitdefender), W32/MyWife.d@MM (McAfee),Kama Sutra, Email-Worm.Win32.Nyxem.e (Kaspersky), W32.Blackmal.E@mm (Symantec)&lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;tr class="Text"&gt; &lt;td width="125"&gt;&lt;strong&gt;Type&lt;/strong&gt;:&lt;/td&gt; &lt;td&gt; Mass-mailing E-mail worm&lt;/td&gt; &lt;/tr&gt; &lt;tr class="Text"&gt; &lt;td width="125"&gt;&lt;strong&gt;Systems affected:&lt;/strong&gt;&lt;/td&gt; &lt;td style="vertical-align: top;"&gt; &lt;p&gt;Windows 95, Windows 98, Windows Me, Windows NT, Windows 2000, Windows Server 2003, Windows XP&lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;p class="Text"&gt;  &lt;/p&gt;Upon execution the worm copies itself into the %System% folder as “scanregw.exe”, “update.exe”, “winzip.exe” and places another copy of itself “rundll16.exe” in the %Windows% folder.   &lt;p class="Text"&gt;The worm also creates a zero-byte zipfile using the name of the original executable file, opens this in the explorer, and creates a mutex “HGFSMUTEX” in the second file instance (rundll16.exe).&lt;/p&gt; &lt;p class="Text"&gt;Note: %System% denotes Windows System directory (e.g. C:\WINDOWS\SYSTEM32) as they differ on various versions of Microsoft Windows.&lt;/p&gt;&lt;p class="Text"&gt;  &lt;/p&gt;  &lt;p class="Text"&gt;  &lt;/p&gt;The worm is able to determine MSN Messenger / Yahoo Pager Accounts. It will send emails, for example, with picture previews to contacts using the correct Messenger display name and current Messenger email address.&lt;br /&gt;&lt;p class="Text"&gt;  &lt;/p&gt; &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt; E-mail harvesting&lt;/span&gt; &lt;/p&gt;   &lt;p&gt;&lt;span class="Text"&gt;The worm collects e-mail addresses from files in the internet cache folders which use one of the following extensions:&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="codeSample"&gt;*.HTM, *.DBX, *.EML, *.MSG, *.OFT, *.NWS, *.VCF, *.MBX, *.IMH, *.TXT, *.MSF&lt;/span&gt; &lt;/p&gt;  &lt;p class="Text"&gt; The worm avoids e-mail addresses which contain parts of the following list: &lt;/p&gt; &lt;p&gt;&lt;span class="codeSample"&gt;SYMANTEC, MCAFEE, VIRUS, TREND, PANDA, SECUR,&lt;/span&gt;&lt;span class="codeSample"&gt;SPAM, NORTON, ANTI, CILLIN, CA.COM, KASPER, TRUST,&lt;/span&gt;&lt;span class="codeSample"&gt;AVG, GROUPS.MSN, NOMAIL.YAHOO.COM, SCRIBE, EEYE&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;MICROSOFT, @HOTMAIL, @HOTPOP, @YAHOOGROUPS&lt;/span&gt; &lt;/p&gt;  &lt;p class="Text"&gt; &lt;span class="Subtitle"&gt;E-mail subjects&lt;/span&gt; &lt;/p&gt; &lt;p class="Text"&gt;  &lt;/p&gt; &lt;p class="Text"&gt; Email subject lines are randomly selected from the following list: &lt;/p&gt;   &lt;p class="Text"&gt; &lt;span class="codeSample"&gt;My photos, &lt;/span&gt;&lt;span class="codeSample"&gt;The Best Videoclip Ever, &lt;/span&gt;&lt;span class="codeSample"&gt;School girl fantasies gone bad, &lt;/span&gt;&lt;span class="codeSample"&gt;A Great Video, &lt;/span&gt;&lt;span class="codeSample"&gt;Fuckin Kama Sutra pics, &lt;/span&gt;&lt;span class="codeSample"&gt;Arab sex DSC-00465.jpg, &lt;/span&gt;&lt;span class="codeSample"&gt;give me a kiss, &lt;/span&gt;&lt;span class="codeSample"&gt;*Hot Movie*, &lt;/span&gt;&lt;span class="codeSample"&gt;Fw: Funny :), &lt;/span&gt;&lt;span class="codeSample"&gt;Fwd: Photo, &lt;/span&gt;&lt;span class="codeSample"&gt;Fwd: image.jpg, &lt;/span&gt;&lt;span class="codeSample"&gt;Fw: Sexy, &lt;/span&gt;&lt;span class="codeSample"&gt;Fw:, &lt;/span&gt;&lt;span class="codeSample"&gt;Fw: Picturs, &lt;/span&gt;&lt;span class="codeSample"&gt;Fw: DSC-00465.jpg, &lt;/span&gt;&lt;span class="codeSample"&gt;Word file, &lt;/span&gt;&lt;span class="codeSample"&gt;eBook.pdf, &lt;/span&gt;&lt;span class="codeSample"&gt;the file &lt;/span&gt;&lt;span class="codeSample"&gt;Part 1 of 6 Video clipe, &lt;/span&gt;&lt;span class="codeSample"&gt;You Must View This Videoclip!, &lt;/span&gt;&lt;span class="codeSample"&gt;Miss Lebanon 2006, &lt;/span&gt;&lt;span class="codeSample"&gt;Re:,&lt;/span&gt;&lt;span class="codeSample"&gt;Re: Sex Video&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Message Body&lt;/span&gt; &lt;/p&gt;  &lt;p class="Text"&gt;The e-mail might contain one of the following message texts: &lt;/p&gt;     &lt;p class="Text"&gt;Hot XXX Yahoo Groups, F!ckin Kama Sutra pics, ready to be F!CKED ;), VIDEOS! FREE! (US$ 0,00), Please see the file., i just any one see my photos., It's Free :), how are you?, i send the details., OK ?, Note: forwarded message attached., forwarded message attached., &gt;&gt; forwarded message, ----- forwarded message -----, &lt;span class="Subtitle"&gt;E-mail Attachments&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;The worm attaches one of the following file names with a copy of itself: &lt;/p&gt;  &lt;p class="Text"&gt;  &lt;/p&gt; &lt;p class="Text"&gt; &lt;span class="codeSample"&gt;007.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;04.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;photo.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;School.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;DSC-00465.Pif, &lt;/span&gt;&lt;span class="codeSample"&gt;DSC-00465.pIf, &lt;/span&gt;&lt;span class="codeSample"&gt;image04.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;677.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;New_Document_file.pif, &lt;/span&gt;&lt;span class="codeSample"&gt;eBook.PIF, &lt;/span&gt;&lt;span class="codeSample"&gt;document.pif&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;or with one of these encoded attachments:&lt;/p&gt;  &lt;span class="codeSample"&gt;Video_part.mim, &lt;/span&gt;&lt;span class="codeSample"&gt;Attachments00.HQX, &lt;/span&gt;&lt;span class="codeSample"&gt;Attachments001.BHX, &lt;/span&gt;&lt;span class="codeSample"&gt;Attachments[001].B64 &lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;3.92315089702606E02.UUE, &lt;/span&gt;&lt;span class="codeSample"&gt;SeX.mim, &lt;/span&gt;&lt;span class="codeSample"&gt;Sex.mim, &lt;/span&gt;&lt;span class="codeSample"&gt;Original Message.B64, &lt;/span&gt;&lt;span class="codeSample"&gt;WinZip.BHX, &lt;/span&gt;&lt;span class="codeSample"&gt;eBook.Uu, &lt;/span&gt;&lt;span class="codeSample"&gt;Word_Document.hqx, ,&lt;/span&gt;&lt;span class="codeSample"&gt;Word_Document.uu &lt;/span&gt; &lt;blockquote class="Text"&gt;&lt;span class="codeSample"&gt; &lt;/span&gt;  &lt;/blockquote&gt;&lt;p class="Text"&gt;After decoding the encoded archive contains one of the following executables:&lt;/p&gt;   &lt;p class="Text"&gt; &lt;span class="codeSample"&gt;New Video,zip {spaces} .sCr, &lt;/span&gt;&lt;span class="codeSample"&gt;Attachments,zip {spaces} .SCR, &lt;/span&gt;&lt;span class="codeSample"&gt;Atta[001],zip {spaces} .SCR,&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;Clipe,zip {spaces} .sCr, &lt;/span&gt;&lt;span class="codeSample"&gt;WinZip,zip {spaces} .scR, &lt;/span&gt;&lt;span class="codeSample"&gt;Adults_9,zip {spaces} .sCR, &lt;/span&gt;&lt;span class="codeSample"&gt;Photos,zip {spaces} .sCR, &lt;/span&gt;&lt;span class="codeSample"&gt;Attachments[001],B64 {spaces} .sCr, &lt;/span&gt;&lt;span class="codeSample"&gt;392315089702606E-02,UUE {spaces} .scR&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;SeX,zip {spaces} .scR, &lt;/span&gt;&lt;span class="codeSample"&gt;WinZip.zip {spaces} .sCR, &lt;/span&gt;&lt;span class="codeSample"&gt;ATT01.zip {spaces} .sCR, &lt;/span&gt;&lt;span class="codeSample"&gt;Word.zip {spaces} .sCR&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;Note: {space} represents a large number of blank spaces.&lt;/p&gt; &lt;p class="Text"&gt;  &lt;/p&gt;&lt;span class="Text"&gt;&lt;/span&gt;   &lt;p class="Text"&gt;  &lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt; Payload:&lt;/span&gt;&lt;br /&gt;The worm will start a timer on every 3rd of the month to overwrite files with the following file extensions: &lt;/p&gt; &lt;p&gt; &lt;span class="codeSample"&gt;*.doc, *.xls, *.mdb, *.mde, *.ppt, *.pps, *.zip, *.rar, *.pdf, *.psd, *.dmp&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116063839885749024?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116063839885749024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116063839885749024' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116063839885749024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116063839885749024'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/win32vbnei.html' title='Win32/VB.NEI'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-116063801526888232</id><published>2006-10-12T12:55:00.000+05:30</published><updated>2006-11-15T16:52:36.046+05:30</updated><title type='text'>New threat : Win32/Viking.AU</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;        &lt;td class="Text"&gt;Worm.Win32.Viking.ah (Kaspersky), W32.Looked.P (Symantec) &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;        &lt;td class="Text"&gt;virus &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;        &lt;td class="Text"&gt;48 kB &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;        &lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;        &lt;td class="Text"&gt;1.1776 &lt;/td&gt;      &lt;/tr&gt;      &lt;tr&gt;        &lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;        &lt;td class="Text"&gt;Win32/Viking.AU is a prepending virus. It is able to spread via shared folders. &lt;/td&gt;      &lt;/tr&gt;    &lt;/tbody&gt; &lt;/table&gt;&lt;strong&gt;Installation&lt;/strong&gt;  &lt;span class="Text"&gt;&lt;br /&gt;&lt;br /&gt;When executed, the virus copies itself in the %windir% folder using the following filename: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;rundl132.exe&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The following files are dropped in the same folder: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;Dll.dll&lt;br /&gt;Logo1_.exe&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The following Registry entries are set: &lt;/span&gt; &lt;p class="Text"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;[HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows]&lt;/span&gt;&lt;br /&gt; &lt;span class="codeSample"&gt;"load" = "%windir%\rundl132.exe"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; &lt;span class="codeSample"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Soft\DownloadWWW]&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;"auto" = "1" &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="Text"&gt; &lt;/p&gt;  &lt;span class="Subtitle"&gt;Spreading&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text"&gt;The virus searches for executables on local drives. Only files with the following names are infected: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;ACDSee4.exe,ACDSee5.exe,ACDSee6.exe,AgzNew.exe,Archlord.exe,AutoUpdate.exe,&lt;br /&gt;autoupdate.exe,BNUpdate.exe,Datang.exe,editplus.exe,EXCEL.EXE,flashget.exe,&lt;br /&gt;foxmail.exe,FSOnline.exe,GameClient.exe,install.exe,jxonline_t.exe,&lt;br /&gt;launcher.exe,lineage.exe,LineageII.exe,MHAutoPatch.exe,Mir.exe,msnmsgr.exe,&lt;br /&gt;msnmsgr.exe,Mu.exe,my.exe,NATEON.exe,NSStarter.exe,Patcher.exe,patchupdate.exe&lt;br /&gt;QQ.exe,Ragnarok.exe,realplay.exe,run.exe,setup.exe,Silkroad.exe,Thunder.exe&lt;br /&gt;ThunderShell.exe,TTPlayer.exe,Uedit32.exe,Winrar.exe,WINWORD.EXE,woool.exe,&lt;br /&gt;zfs.exe&lt;/span&gt;&lt;/p&gt;&lt;p&gt;If a folder name matches one of the following strings, files inside it are not, infected: &lt;/p&gt;  &lt;/blockquote&gt;&lt;span class="Text"&gt;&lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;Windows NT,Program Files,WindowsUpdate,Windows Media Player&lt;br /&gt;Outlook Express,Internet Explorer,ComPlus Applications, NetMeeting,Common Files,Messenger,Microsoft Office, InstallShield Installation Information,MSN,Microsoft, Frontpage,Movie Maker,MSN Gaming Zone,system,system32,winnt&lt;br /&gt;windows,Recycled,Documents and Settings,System Volume Information&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; When searching a folder a hidden file is created in it. Its name is the following: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;_desktop.ini&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt;The virus also searches for executables in shared folders of remote machines. Filenames are not checked, any executable can be infected. &lt;/span&gt;&lt;br /&gt; &lt;span class="Text"&gt;The virus file is prepended to host executables. When an infected file is executed, the virus drops the host in a temporary file and executes it. &lt;/span&gt; &lt;p class="Text"&gt; &lt;/p&gt;  &lt;p class="Text Subtitle"&gt;&lt;strong&gt;Other information&lt;/strong&gt;&lt;/p&gt;  &lt;span class="Text"&gt; The following programs are terminated: &lt;/span&gt; &lt;blockquote class="Text codeSample"&gt;   &lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;EGHOST.EXE,IPARMOR.EXE,KAVPFW.EXE,MAILMON.EXE,mcshield.exe,RavMon.exe&lt;br /&gt;Ravmond.EXE,regsvc.exe&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;  &lt;span class="Text"&gt; The virus contains a list of URLs. It tries to download several files from the addresses. The files are then executed.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-116063801526888232?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/116063801526888232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=116063801526888232' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116063801526888232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/116063801526888232'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/10/new-threat-win32vikingau.html' title='New threat : Win32/Viking.AU'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115962700387133325</id><published>2006-09-30T20:04:00.000+05:30</published><updated>2006-11-15T17:05:16.580+05:30</updated><title type='text'>Virus Alert: Win32/Scano.NBC</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;&lt;td class="Text"&gt;Email-Worm.Win32.Scano.x (Kaspersky), W32/Areses.f (McAfee), W32.Areses.Q (Symantec) &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;&lt;td class="Text"&gt;worm &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;&lt;td class="Text"&gt;approximately 20 kB &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;&lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;&lt;td class="Text"&gt;1.1749 &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;&lt;td class="Text"&gt;Win32/Scano.NBC is a worm that spreads via e-mail and shared folders. &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;strong&gt;Installation&lt;br /&gt;&lt;/strong&gt;&lt;span class="Text"&gt; When executed, the worm copies itself in the %windir% folder using the following filename: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;csrss.exe&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; The following Registry entry is set: &lt;/span&gt;&lt;p class="Text"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;"Debugger" = "%windir%\csrss.exe"&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="Text"&gt; &lt;/p&gt; &lt;p class="Text Subtitle"&gt;&lt;strong&gt;Spreading via e-mail&lt;/strong&gt;&lt;/p&gt;&lt;span class="Text"&gt; E-mail addresses for further spreading are searched for in local files with one of the following extensions:&lt;/span&gt;.adb,.asp,.cfg,.cgi,.dbx,.dhtm,.dhtml,.eml,.htm,.html,.jsp,.mbx,.mdx,.mht,.mmf,.mra,&lt;br /&gt;.msg,.nch,.ods,.oft,.php,.pl,.sht,.shtm,.stm,&lt;span style="font-family:Courier New,Courier,mono;"&gt;.tbb,.txt,.uin,.wab,.wsh,.xls,.xml&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Text"&gt; Addresses containing the following strings are avoided: &lt;/span&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;2003,&lt;/span&gt;&lt;span class="codeSample"&gt;2004,&lt;/span&gt;&lt;span class="codeSample"&gt;2005,&lt;/span&gt;&lt;span class="codeSample"&gt;2006,&lt;/span&gt;&lt;span class="codeSample"&gt;---,&lt;/span&gt;&lt;span class="codeSample"&gt;..,&lt;/span&gt;&lt;span class="codeSample"&gt;.0,&lt;/span&gt;&lt;span class="codeSample"&gt;.00,&lt;/span&gt;&lt;span class="codeSample"&gt;.1,&lt;/span&gt;&lt;span class="codeSample"&gt;.2,&lt;/span&gt;&lt;span class="codeSample"&gt;.3,&lt;/span&gt;&lt;span class="codeSample"&gt;.4,&lt;/span&gt;&lt;span class="codeSample"&gt;.5,&lt;/span&gt;&lt;span class="codeSample"&gt;.6,&lt;/span&gt;&lt;span class="codeSample"&gt;.7,&lt;/span&gt;&lt;span class="codeSample"&gt;.8,&lt;/span&gt;&lt;span class="codeSample"&gt;.9,&lt;/span&gt;&lt;span class="codeSample"&gt;.gif,&lt;/span&gt;&lt;span class="codeSample"&gt;.qmail&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;@.,&lt;/span&gt;&lt;span class="codeSample"&gt;@avp.,&lt;/span&gt;&lt;span class="codeSample"&gt;@example.,&lt;/span&gt;&lt;span class="codeSample"&gt;@foo,&lt;/span&gt;&lt;span class="codeSample"&gt;@iana,&lt;/span&gt;&lt;span class="codeSample"&gt;@messagelab,&lt;/span&gt;&lt;span class="codeSample"&gt;@microsoft,&lt;/span&gt;&lt;span class="codeSample"&gt;@subscribe,&lt;/span&gt;&lt;span class="codeSample"&gt;abuse,&lt;br /&gt;admin,&lt;/span&gt;&lt;span class="codeSample"&gt;anyone@,&lt;/span&gt;&lt;span class="codeSample"&gt;bsd,&lt;/span&gt;&lt;span class="codeSample"&gt;bugs@,&lt;/span&gt;&lt;span class="codeSample"&gt;cafee,&lt;/span&gt;&lt;span class="codeSample"&gt;certific,&lt;/span&gt;&lt;span class="codeSample"&gt;contract@,&lt;/span&gt;&lt;span class="codeSample"&gt;feste,&lt;/span&gt;&lt;span class="codeSample"&gt;free-av,&lt;/span&gt;&lt;span class="codeSample"&gt;f-secur&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;gold-certs@,&lt;/span&gt;&lt;span class="codeSample"&gt;google,&lt;/span&gt;&lt;span class="codeSample"&gt;help@,&lt;/span&gt;&lt;span class="codeSample"&gt;icrosoft,&lt;/span&gt;&lt;span class="codeSample"&gt;info@,&lt;/span&gt;&lt;span class="codeSample"&gt;kasp,&lt;/span&gt;&lt;span class="codeSample"&gt;linux,&lt;/span&gt;&lt;span class="codeSample"&gt;listserv,&lt;/span&gt;&lt;span class="codeSample"&gt;local,&lt;/span&gt;&lt;span class="codeSample"&gt;&lt;br /&gt;Mailer-Daemon@,&lt;/span&gt;&lt;span class="codeSample"&gt;news,&lt;/span&gt;&lt;span class="codeSample"&gt;nobody@,&lt;/span&gt;&lt;span class="codeSample"&gt;noone@,&lt;/span&gt;&lt;span class="codeSample"&gt;noreply,&lt;/span&gt;&lt;span class="codeSample"&gt;ntivi,&lt;/span&gt;&lt;span class="codeSample"&gt;panda,&lt;/span&gt;&lt;span class="codeSample"&gt;pgp,&lt;/span&gt;&lt;span class="codeSample"&gt;postmaster@,&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;rating@,&lt;/span&gt;&lt;span class="codeSample"&gt;root@,&lt;/span&gt;&lt;span class="codeSample"&gt;samples,&lt;/span&gt;&lt;span class="codeSample"&gt;sopho,&lt;/span&gt;&lt;span class="codeSample"&gt;spam,&lt;/span&gt;&lt;span class="codeSample"&gt;spm111@,&lt;/span&gt;&lt;span class="codeSample"&gt;support,&lt;/span&gt;&lt;span class="codeSample"&gt;torvalds@,&lt;/span&gt;&lt;span class="codeSample"&gt;unix,&lt;/span&gt;&lt;span class="codeSample"&gt;update,&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt;winrar,&lt;/span&gt;&lt;span class="codeSample"&gt;winzip&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Text"&gt;The attachment is an executable of the worm. A HTA dropper script is used. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Text"&gt;The filename has the following extension: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;.hta&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p class="Text"&gt;&lt;strong&gt;Spreading via shared folders&lt;/strong&gt;&lt;/p&gt;&lt;span class="Text"&gt; The worm searches for various shared folders. A name matches if it contains one of the following strigns:&lt;/span&gt;&lt;span class="codeSample"&gt;bear,&lt;/span&gt;&lt;span class="codeSample"&gt;donkey,&lt;/span&gt;&lt;span class="codeSample"&gt;download,&lt;/span&gt;&lt;span class="codeSample"&gt;ftp,&lt;/span&gt;&lt;span class="codeSample"&gt;htdocs,&lt;/span&gt;&lt;span class="codeSample"&gt;http,&lt;/span&gt;&lt;span class="codeSample"&gt;icq,&lt;/span&gt;&lt;span class="codeSample"&gt;kazaa,&lt;/span&gt;&lt;span class="codeSample"&gt;lime,&lt;/span&gt;&lt;span class="codeSample"&gt;log,&lt;/span&gt;&lt;span class="codeSample"&gt;morpheus,&lt;/span&gt;&lt;span class="codeSample"&gt;mule&lt;/span&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;&lt;span class="codeSample"&gt;pub,&lt;/span&gt;&lt;span class="codeSample"&gt;shar,&lt;/span&gt;&lt;span class="codeSample"&gt;source,&lt;/span&gt;&lt;span class="codeSample"&gt;&lt;br /&gt;upload&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Text"&gt; These include folders shared by various instant messengers and P2P programs. The executables of the worm are copied there using the following filenames: &lt;/span&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;1,1001 Sex and more.rtf,3D Studio Max 6 3dsmax,ACDSee 10 full,Adobe Photoshop 10 full,Adobe Premiere 10,Ahead Nero 8&lt;br /&gt;Altkins Diet.doc,American Idol.doc,anthrax.doc,Arnold, Schwarzenegger.jpg,Best Matrix Screensaver new,Britney sex xxx.jpg,Britney Spears and Eminem porn.jpg,Britney Spears blowjob.jpg,Britney Spears cumshot.jpg,Britney Spears fuck.jpg,Britney Spears full album.mp3,Britney Spears porn.jpg,Britney Spears Sexy archive.doc,Britney Spears Song text archive.doc,Britney Spears.jpg,Britney Spears.mp3&lt;br /&gt;Clone DVD 6,Cloning.doc,Cracks &amp;amp; Warez Archiv,Dark Angels new,Dictionary English 2004 - France.doc,DivX 8.0 final&lt;br /&gt;Doom 3 release 2,DrWeb 4.7 Full installer,E-Book, Archive2.rtf,Eminem blowjob.jpg,Eminem full album.mp3, Eminem Poster.jpg,Eminem sex xxx.jpg,Eminem Sexy, archive.doc.Eminem Spears porn.jpg.Eminem.mp3&lt;br /&gt;From me with love,Full album all.mp3,Gimp 1.8 Full with Key&lt;br /&gt;Harry Potter 1-6 book.txt,Harry Potter 5.mpg&lt;br /&gt;Harry Potter all e.book.doc,Harry Potter and the Sorcerer's Stone game,Harry Potter e book.doc,Harry Potter game,Harry Potter.doc,How to hack new.doc,Internet Explorer 9 setup&lt;br /&gt;Kaspersky Internet Security 6.1 KeyALL,Kaspersky`s Pub 6.0 Ultimate,Kazaa Lite 4.0 new,Kazaa new,Keygen 4 all new&lt;br /&gt;Learn Programming 2004.doc,Lightwave 9 Update,Magix Video Deluxe 5 beta,Matrix 3 .mpg,Microsoft Office 2003 Crack best,Microsoft WinXP Crack full,MS Service Pack 6,Norton Antivirus 2005 beta,Nostradamus.doc,Opera 11 free,Osama Bin Laden.jpg,Osama bin Laden.mpg,Partitionsmagic 10 beta,Porno Screensaver britney,RFC, compilation.doc,Ringtones.doc, Ringtones.mp3,Saddam Hussein.jpg,Screensaver2,Serials, edition.txt,Smashing the stack full.rtf,source code,Star Office 9,Taliban,Teen Porn 15.jpg,The Sims 4 beta,Ulead Keygen 2004,Vista review.doc,Visual Studio Net Crack all,&lt;br /&gt;WinAmp 13 full with sources,Windows 2003 crack,Windows Vista Sourcecode.doc,Windows XP crack,WinXP eBook,newest.doc,World Trade Center last video.mpeg&lt;br /&gt;XXX hardcore pics.jpg,Yellow Pages&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; The filenames have one of the following extensions: &lt;/span&gt;&lt;p class="codeSample"&gt;&lt;span style="font-family:Courier New,Courier,mono;"&gt;.exe,.pif,.scr&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115962700387133325?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115962700387133325/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115962700387133325' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115962700387133325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115962700387133325'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/virus-alert-win32scanonbc.html' title='Virus Alert: Win32/Scano.NBC'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115943182420074015</id><published>2006-09-28T13:52:00.000+05:30</published><updated>2006-09-28T13:53:44.596+05:30</updated><title type='text'>A new Virus threat : Win32/Bacalid</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;&lt;td class="Text"&gt;virus &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;&lt;td class="Text"&gt;approximately 35 kB &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;&lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;&lt;td class="Text"&gt;1.1767 &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;&lt;td class="Text"&gt;Win32/Bacalid is a polymorphic file infector. &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span class="Text"&gt;&lt;span class="Subtitle"&gt;Description :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;A DLL file is dropped in the %temp% folder. Its filename may be one of the following: &lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;vcab.dll&lt;br /&gt;vgod.dll&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;span class="Text"&gt; Size of the file is approximately 30 kB. The library is loaded and injected in all processes. &lt;/span&gt;&lt;p class="Text"&gt; The virus checks for code page used on the system. If it is set to 936 (Simplified Chinese), the virus quits and hands control over to the host executable. &lt;/p&gt; &lt;p class="Text"&gt; In order to ensure that only one instance of the virus is running, it creates an Event object. Its name is one of the following: &lt;/p&gt;&lt;blockquote class="Text codeSample"&gt;&lt;p&gt;&lt;span style="font-family:Courier New, Courier, mono;"&gt;WINGOOD&lt;br /&gt;WINXPGOD&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p class="Text"&gt; The virus infects executables accesed by Explorer.exe as well as files found on local and network drives. &lt;/p&gt; &lt;p&gt;&lt;span class="Text"&gt; The virus contains a list of URLs. It tries to download several files from the addresses. The files are then executed.&lt;/span&gt; &lt;/p&gt;&lt;span class="Text"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115943182420074015?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115943182420074015/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115943182420074015' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115943182420074015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115943182420074015'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/new-virus-threat-win32bacalid.html' title='A new Virus threat : Win32/Bacalid'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115840693126434504</id><published>2006-09-16T17:11:00.000+05:30</published><updated>2006-09-16T17:12:15.106+05:30</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/3913/3475/1600/matrix%20Isoft%20copy.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/3913/3475/320/matrix%20Isoft%20copy.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115840693126434504?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115840693126434504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115840693126434504' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115840693126434504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115840693126434504'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/blog-post.html' title=''/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115840633652010960</id><published>2006-09-16T17:00:00.000+05:30</published><updated>2006-09-16T17:02:46.893+05:30</updated><title type='text'>Win32/Scano.AQ : A New Virus</title><content type='html'>&lt;table cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="Text" width="200"&gt;Aliases:&lt;/td&gt;&lt;td class="Text"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Type of infiltration:&lt;/td&gt;&lt;td class="Text"&gt;worm &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Size:&lt;/td&gt;&lt;td class="Text"&gt;23011 bytes&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Affected platforms:&lt;/td&gt;&lt;td class="Text"&gt;Microsoft Windows &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Signature database version:&lt;/td&gt;&lt;td class="Text"&gt;1.1741 &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class="Text" width="200"&gt;Short description:&lt;/td&gt;&lt;td class="Text"&gt;Win32/Scano.AQ is a worm that spreads via e-mail and shared folders.  &lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" class="Text Subtitle"&gt;Installation &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Text"&gt;When executed, the worm copies itself in the %windir% folder using the following filename: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt;&lt;span class="codeSample"&gt; csrss.exe&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt;In order to be executed on every system start, the worm sets the following Registry entry:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text codeSample"&gt;[SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;&lt;span class="codeSample"&gt; "Application" = "%windir%\csrss.exe" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text"&gt;The following Registry entry is set:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text codeSample"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]&lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;&lt;span class="codeSample"&gt; "Debugger" = "%windir%\csrss.exe" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text"&gt;The following entries are deleted form the Registry:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text codeSample"&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\BootExecute&lt;/span&gt;&lt;br /&gt;&lt;span class="Text codeSample"&gt; HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\PendingFileRenameOperations &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;&lt;span class="Subtitle" style="font-weight: bold;"&gt;Spreading via e-mail &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="Text"&gt;E-mail addresses for further spreading are searched for in local files with one of the following extensions: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;.adb&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .asp&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .cfg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .cgi&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .dbx&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .dhtm&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .dhtml&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .eml&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .htm&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .html&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .jsp&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .mbx&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .mdx&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .mht&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .mmf&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .mra&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .msg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .nch&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .ods&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .oft&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .php&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .pl&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .sht&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .shtm&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .stm&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .tbb&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .txt&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .uin&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .wab&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .wsh&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .xls&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .xml&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;Addresses containing the following strings are avoided: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;---&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; -0&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; ..&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .0&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .00&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .1&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .2&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .4&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .5&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .6&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .7&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .8&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .9&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .gif&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; .qmail&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @.&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @avp.&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @example.&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @foo&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @iana&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @messagelab&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @microsoft&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; @subscribe&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 0000&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 2003&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 2004&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 2005&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 2006&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; abuse&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; admin&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; anyone@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; bsd&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; bugs@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; cafee&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; certific&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; contract@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; f-secur&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; feste&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; free-av&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; gold-certs@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; google&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; help@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; icrosoft&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; info@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; kasp&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; linux&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; listserv&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; local&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Mailer-Daemon@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; news&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; nobody@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; noone@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; noreply&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; ntivi&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; panda&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; pgp&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; postmaster@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; rating@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; root@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; samples&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; sopho&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; spam&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; spm111@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; support&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; torvalds@&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; unix&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; update&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; winrar&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; winzip&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;Subject of the message is one of the following: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;He, where are you?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi! I'm waiting you online today!&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi! Please write to me urgently!&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi!!! How's the mood?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, drop me a line!!!&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, what's up?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: Call me!&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: How's the mood?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: When you're gonna answer me?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: Where are you?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: Where have you been?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Re: write to me!&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; When you're gonna answer me?&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Will you be online today?&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;Body of the message is one of the following: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;Hi!!!!! You haven't been writing for a long time. I began to worry) Where have you been? You remember, you've asked a progy from me? I've finally found it, so here it is. Check it out if this is what you've been looking for... bye&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, what's up? Will you show up online today?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Drop me a line in ICQ, ok? Btw, I'm sending you the docs you've been looking for, find them attached. Check them out, ok?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; I'm coming to you tomorrow, ok? When you are going to be home?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; You remember, you've asked some docs. Please find them attached. Check and see what's inside. That's it. Bye, till tomorrow...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; You disappeared again. If you come online, drop me a line, ok?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Btw, I sent you those docs that you've been looking for. Check them out. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, give me a call just when you got the message! I'm tired of waiting. Btw, I'm sending that program that you've been looking for. Check it out. Appears to be that one. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, what's up? If you have time tomorrow, please come over. After midday. By the way, don't forget to check the enclosed documents. Bye. See you tomorrow.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, I got a free day tomorrow, and I'm waiting for you. Please come after midday. By the way, I'm sending you the documents that you've been asking for. Read them out... Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, how are you? What are your plans today? If you have time, please come over, and don't forget to check the program attached. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, what's you gonna do today? I'll come over tonight! By the way, don't give anyone this funny program I'm sending. Check it out. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, I found that program you asked for. Find it attached. Bye.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, I saw you around today, but you didn't noticed me ( If you're gonna be at home, give a call, ok? By the way, check this file I'm sending. A very interesting program...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; What's up! You haven't been writing for a long time&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; I got news. I've finally that program you needed&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; I'm sending it out. Use it. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, drop me a line today, ok? And see the program I'm sending. Bye!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi, drop me a line if you can. Btw, I have a new ICQ. Please don't forget to check the attached documents. Bye.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Hi! How are you? Drop me a line if you can. I found your documents and I'm emailing them to you. Bye.&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;The attachment is an executable of the worm. Its filename is one of the following: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;Archive&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; backup&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; confidential&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; COOL&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Document&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; File&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Fotos&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; images&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Important&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Message&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; New&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Passwords&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; private&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; README&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Readme&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; secret&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; your_documents&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;If an e-mail is being composed in Outlook Express, the worm can attach a copy of itself to the message. A HTA dropper script is used. &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" class="Text Subtitle"&gt;Spreading via shared folders &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;&lt;br /&gt;The worm searches for various shared folders. A name matches if it contains one of the following strigns: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;bear&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; donkey&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; download&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; ftp&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; htdocs&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; http&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; icq&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; kazaa&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; lime&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; morpheus&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; mule&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; pub&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; shar&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; source&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; upload&lt;/span&gt; &lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;span class="Text"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Text"&gt;These include folders shared by various instant messengers and P2P programs. Worm executables are copied there using the following filenames: &lt;/span&gt; &lt;blockquote class="Text"&gt; &lt;blockquote&gt; &lt;span class="codeSample"&gt;1&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 1001 Sex and more.rtf&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; 3D Studio Max 6 3dsmax&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; ACDSee 10 full&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Adobe Photoshop 10 full&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Adobe Premiere 10&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Ahead Nero 8&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Altkins Diet.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; American Idol.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; anthrax.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Arnold Schwarzenegger.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Best Matrix Screensaver new&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney sex xxx.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears and Eminem porn.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears blowjob.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears cumshot.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears fuck.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears full album.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears porn.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears Sexy archive.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears Song text archive.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Britney Spears.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Clone DVD 6&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Cloning.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Cracks &amp;amp; Warez Archiv&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Dark Angels new&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Dictionary English 2004 - France.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; DivX 8.0 final&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Doom 3 release 2&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; E-Book Archive2.rtf&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem blowjob.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem full album.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem Poster.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem sex xxx.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem Sexy archive.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem Spears porn.jpg &lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Eminem.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Full album all.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Gimp 1.8 Full with Key&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter 1-6 book.txt&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter 5.mpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter all e.book.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter and the Sorcerer&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter e book.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter game&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Harry Potter.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; How to hack new.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Internet Explorer 9 setup&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Kazaa Lite 4.0 new&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Kazaa new&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Keygen 4 all new&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Learn Programming 2004.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Lightwave 9 Update&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Magix Video Deluxe 5 beta&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Matrix 3 .mpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Microsoft Office 2003 Crack best&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Microsoft WinXP Crack full&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; MS Service Pack 6&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Norton Antivirus 2005 beta&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Nostradamus.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Opera 11 free&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Osama Bin Laden.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Osama bin Laden.mpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Partitionsmagic 10 beta&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Porno Screensaver britney&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; RFC compilation.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Ringtones.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Ringtones.mp3&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Saddam Hussein.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Screensaver2&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Serials edition.txt&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Smashing the stack full.rtf&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; source code&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Star Office 9&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Taliban&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Teen Porn 15.jpg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; The Sims 4 beta&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Ulead Keygen 2004&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Vista review.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Visual Studio Net Crack all&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; WinAmp 13 full with sources&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Windows 2003 crack&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Windows Vista Sourcecode.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Windows XP crack&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; WinXP eBook newest.doc&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; World Trade Center last video.mpeg&lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; XXX hardcore pics.jpg &lt;/span&gt;&lt;br /&gt;&lt;span class="codeSample"&gt; Yellow Pages&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt; &lt;/blockquote&gt;&lt;span class="Text"&gt; NOD32 detected Win32/Scano.AQ using advanced heuristics.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115840633652010960?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115840633652010960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115840633652010960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115840633652010960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115840633652010960'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/win32scanoaq-new-virus.html' title='Win32/Scano.AQ : A New Virus'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115805741932512646</id><published>2006-09-12T16:01:00.000+05:30</published><updated>2006-09-12T16:22:50.703+05:30</updated><title type='text'>The Die Hard Virus</title><content type='html'>&lt;p class="Text"&gt;This &lt;a href="http://ve.nod32.ch/system/polym.php"&gt;polymorphic&lt;/a&gt;, &lt;a href="http://ve.nod32.ch/system/steal.php"&gt;stealth&lt;/a&gt;, &lt;a href="http://ve.nod32.ch/system/com.php"&gt;COM&lt;/a&gt; and &lt;a href="http://ve.nod32.ch/system/exe.php"&gt;EXE&lt;/a&gt; infector increases the length of infected file by 4000 bytes. When an infected file is executed the virus gets activated and it tunnels vectors of the interrupts INT 10h, INT 13h and INT 21h. It is not destructive but from time to time it exhibits its presence. On certain days, depending on the date, it sends to the equipment of standard error {usually the screen} and to AUX the following string:&lt;/p&gt; &lt;p class="codeSample"&gt;SW Error&lt;/p&gt; &lt;p class="Text"&gt;Depending on generation (must be higher than 15) and on the graphic card mode (mode 13h) the virus writes violet letters &lt;span class="textIta"&gt;SW&lt;/span&gt; on the screen. It modifies the beginning of source texts in the assembler and pascal so that after compiling the program it displays on the screen two characters with ASCII codes 209 and 165 and terminates the program. That creates an impression that the source code is erroneous.&lt;br /&gt; On files being manipulated in this way the virus implements the &lt;a href="http://ve.nod32.ch/system/steal.php"&gt;stealth&lt;/a&gt; technology. As a result the modification is not seen as long as the virus is active in memory. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115805741932512646?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115805741932512646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115805741932512646' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805741932512646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805741932512646'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/die-hard-virus.html' title='The Die Hard Virus'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115805710858667361</id><published>2006-09-12T15:57:00.000+05:30</published><updated>2006-09-12T16:01:48.590+05:30</updated><title type='text'>The Bill Gates Virus</title><content type='html'>&lt;p class="Text"&gt;This virus comes from Italy. It is a parasitic, &lt;a href="http://ve.nod32.ch/system/polym.php"&gt;polymorphic&lt;/a&gt;, &lt;a href="http://ve.nod32.ch/system/resi.php"&gt;resident&lt;/a&gt; &lt;a href="http://ve.nod32.ch/system/com.php"&gt;COM&lt;/a&gt; infector. It identifies itself as a ”&lt;span class="textIta"&gt;semi-&lt;a href="http://ve.nod32.ch/system/steal.php"&gt;stealth&lt;/a&gt;&lt;/span&gt;” virus and that is more or less correct. It infects files larger than 400 and smaller than 62000 bytes. Increase in length is about 2 kB. It avoids programs which have as first 4 characters one of the following strings &lt;span class="textIta"&gt;TBAV, TBSC, TBCL, TBDR, F-PR, F-TE, SVIR, SCAN, CLEA, VSHI, MSAV, VSAF, CPAV, VWAT, IBMA, NAV., FIND, TOOL, AVSC, DISK, DE.E, DEBU&lt;/span&gt; or &lt;span class="textIta"&gt;TD.E&lt;/span&gt;. The virus may surprise us in October with writing data from BIOS into first two sectors of hard disk in the following form:&lt;/p&gt; &lt;p class="codeSample"&gt;the [BillGates] Virus is power-on!! Have you got a BACKUP of your HD??!?&lt;br /&gt;  [BillGates] Virus : RamResident .COM Infector Semi-Stealth Virus,&lt;br /&gt;   Variable Crypto-Key and, Polymorphic Encryption!!&lt;br /&gt;  (c) Microsoft&lt;br /&gt;  Written in COSENZA (Italy, April 1995)&lt;br /&gt;  Freddie (Mercury) lives...somewhere in time&lt;/p&gt; &lt;p class="Text"&gt;The last sentence is a paraphrase of the text in the virus Dark Avenger, which goes like this:&lt;/p&gt; &lt;p class="codeSample"&gt; &lt;/p&gt; Eddie lives...... Somewhere in Time!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115805710858667361?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115805710858667361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115805710858667361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805710858667361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805710858667361'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/bill-gates-virus.html' title='The Bill Gates Virus'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115805675596293166</id><published>2006-09-12T15:53:00.000+05:30</published><updated>2006-10-18T15:22:22.773+05:30</updated><title type='text'>Be Positive!!!</title><content type='html'>This speech was delivered during the commencement exercises of the&lt;br /&gt;University of Philippines graduating class of 2003 by Mr. Butch Jimenez,&lt;br /&gt;the youngest commencement speaker in the university's history. He once&lt;br /&gt;dreamed of doing so, and it came true !!! Students wished they had a pencil&lt;br /&gt;or paper to jot down notes during the speech; some even wished they have&lt;br /&gt;a tape recorder. Some members of the faculty found his speech practical,&lt;br /&gt;refreshing and funny.&lt;br /&gt;&lt;br /&gt;Butch Jimenez, head of PLDT's media and strategic communications department,&lt;br /&gt;delivered this speech at the UP Diliman Class 2003 commencement exercises.&lt;br /&gt;What's better than .....&lt;br /&gt;By Butch Jimenez&lt;br /&gt;&lt;br /&gt;As college students, you're just about to set sail into the real world.&lt;br /&gt;As you prepare for the battleground of life, you'll hear many speeches,&lt;br /&gt;read tons of books and get miles of advise telling you to work hard, dream&lt;br /&gt;big, go out and do something for yourself, and have a vision.&lt;br /&gt;&lt;br /&gt;Not bad advise, really. In fact, following these nuggets of truth may&lt;br /&gt;just bring you to the top. But as I've lived my life over the years, I&lt;br /&gt;have come to realise that it is great to dream big, have a vision, make&lt;br /&gt;a name, and work hard. But guess what : There's something better than&lt;br /&gt;that -&lt;br /&gt;&lt;br /&gt;So my message today simply asks the question,&lt;br /&gt;what's better than ...?&lt;br /&gt;&lt;br /&gt;What's better than being negative ?&lt;br /&gt;&lt;br /&gt;Let's start off with something really simple.&lt;br /&gt;What's better than a long speech ? No doubt, a short one. So, you guys&lt;br /&gt;are in luck because I intend to keep this short.&lt;br /&gt;&lt;br /&gt;Now, let me take you through a very simple math exam. I'll rattle off&lt;br /&gt;a couple of equations, and you tell me what you observe about them. Be&lt;br /&gt;mindful of the instruction. You are to tell me what you observe about&lt;br /&gt;the equations.&lt;br /&gt;&lt;br /&gt;Here it goes : 3+4=7, 9+2=11, 8+4=13 and 6+6=12.&lt;br /&gt;Tell me, what do you observe ?&lt;br /&gt;&lt;br /&gt;Every time I conduct the test, more than 90 percent of the participants&lt;br /&gt;immediately say, 8+4 is NOT 13, it's 12&lt;br /&gt;That's true an they are correct. But they could have also observed that&lt;br /&gt;the three other equations were right. That 3+4 is 7, that 9+2 is 11, and&lt;br /&gt;that 6+6 is 12&lt;br /&gt;&lt;br /&gt;What's my point ? Many people immediately focus on the negative instead&lt;br /&gt;of the positive. Most of us focus on what's wrong with other people more&lt;br /&gt;than what's right about them. Examine those four equations. Three were&lt;br /&gt;right an only one was wrong. But what is the knee-jerk observation ?&lt;br /&gt;The wrong equation.&lt;br /&gt;&lt;br /&gt;If 10 people you didn't know were to walk through that door, most of you&lt;br /&gt;would describe those people by what's negative about them. He's fat.&lt;br /&gt;He's balding. Oh, the short one. Oh, the skinny girl. etc.&lt;br /&gt;&lt;br /&gt;Get the point ? It's always he negative we focus on and not the positive.&lt;br /&gt;You'll definitely experience this in the Corporate World. You do a hundred&lt;br /&gt;good things and one mistake-guess what? Chances are, your attention will&lt;br /&gt;be called on that one mistake..&lt;br /&gt;&lt;br /&gt;So what's better than focusing on the negative ?&lt;br /&gt;&lt;br /&gt;Believe me, it focusing on the positive. And if this world could learn&lt;br /&gt;to focus on the positive more than the negative, it would be a much nicer&lt;br /&gt;place to live in.&lt;br /&gt;&lt;br /&gt;What's better than working hard ?&lt;br /&gt;&lt;br /&gt;We have always been told to work hard. Our parents say that, our teachers&lt;br /&gt;say that, and our principal say that. But there's something better than&lt;br /&gt;merely working hard. It's working SMART.&lt;br /&gt;&lt;br /&gt;It's taking time to understand the situation, and coming out with an&lt;br /&gt;effective&lt;br /&gt;and efficient solution to get more done with less time and effort. As&lt;br /&gt;the Japanese say, "There's always a better way."&lt;br /&gt;&lt;br /&gt;One of the most memorable case studies I came across with as I studied&lt;br /&gt;Japanese management at Sophia University in Tokyo was the case of the empty&lt;br /&gt;soap box, which happened in one of Japan's biggest cosmetic companies.&lt;br /&gt;The company received a complaint that a customer had bought a box of soap&lt;br /&gt;that was empty. It immediately isolated the problem to the assembly line,&lt;br /&gt;which transported all the packaged boxes of soap to the delivery department.&lt;br /&gt;For some reason, one soap box went through the assembly line empty.&lt;br /&gt;Management&lt;br /&gt;tasked its engineers to solve the problem. Post-haste, the engineers worked&lt;br /&gt;hard to devise an X-ray machine with high-resolution monitors manned by&lt;br /&gt;two to ensure they were not empty. No doubt, they worked hard and they&lt;br /&gt;worked fast. But a rank-and-file employee that was posed the same problem&lt;br /&gt;came out with another solution. He bought a strong industrial electrical&lt;br /&gt;fan and pointed it at the assembly line. He switched the fan on, an as&lt;br /&gt;each soap box passed the fan, it simply blew the empty boxes out of the&lt;br /&gt;line. Clearly, the engineers worked hard, but the rank-and-file employee&lt;br /&gt;worked smart. So what's better than merely working hard? It's working smart.&lt;br /&gt;Having said that, it is still important to work hard. If you could combine&lt;br /&gt;both working hard an working smart, you would possess a major factor toward&lt;br /&gt;success.&lt;br /&gt;&lt;br /&gt;What's better than dreaming big ?&lt;br /&gt;&lt;br /&gt;I will bet my next month's salary that many have encouraged you to dream&lt;br /&gt;big. Maybe even to reach for the stars and aim high. I sure heard that&lt;br /&gt;about a million times right before I graduated from this university.&lt;br /&gt;So I did. I did dream big. I did aim high. I did reach for the stars.&lt;br /&gt;No doubt, it works. In fact, the saying is true "If you aim for nothing,&lt;br /&gt;that's exactly what you'll hit : nothing."&lt;br /&gt;&lt;br /&gt;But there's something better than dreaming big.&lt;br /&gt;Believe me, I got shocked myself. And I learned it from the biggest dreamer&lt;br /&gt;of all time Walt Disney.&lt;br /&gt;&lt;br /&gt;When it comes to dreaming big. Walt is the man. No bigger dreams were&lt;br /&gt;fulfilled than his. Every leadership book describes him as the ultimate&lt;br /&gt;dreamer. In fact, the principle of dreaming and achieving is the core&lt;br /&gt;message of the Disney hit son, "When You Wish Upon a Star". "When&lt;br /&gt;you wish upon a star, makes no difference who you are; anything your heart&lt;br /&gt;desires will come to you. If your heart is in your dream, no request is&lt;br /&gt;too extreme. When you wish upon a star, as dreamers do, " as Jiminy&lt;br /&gt;Cricket sang. But is that what he preached in Disney company? Dream?&lt;br /&gt;Imagineering...Well,&lt;br /&gt;not exactly. Kinda , but not quite. The problem with dreaming is if that's&lt;br /&gt;all you do, you'll really get nowhere. Infact, you may just fall asleep&lt;br /&gt;and never wake up. The secret to Disney's success is not just dreaming,&lt;br /&gt;it's IMAGINEERING.&lt;br /&gt;&lt;br /&gt;You won't find this word in a dictionary. It's purely a Disney word.&lt;br /&gt;Those who engage in imagineering are called imaginers. The word combines&lt;br /&gt;the words "imagination" and "engineering". In the book&lt;br /&gt;" Imagineers," Disney's CEO, Michael Eisner, claims that "imaginers&lt;br /&gt;turn impossible dreams into real magic." Walt Disney explained there&lt;br /&gt;is really no secret to this approach. They just keep moving&lt;br /&gt;forward-opening&lt;br /&gt;new doors and doing new things, because they are curious. And it is this&lt;br /&gt;curiosity that leads them down new paths. They always dream, explore&lt;br /&gt;and experiment. In short, imagineering is the blending of creative&lt;br /&gt;imagination&lt;br /&gt;and technical know-how.&lt;br /&gt;&lt;br /&gt;Eiser expouns on this thought by saying that "Not only re imaginers&lt;br /&gt;curious, they are courageous, outrageous, and this creativity is&lt;br /&gt;contagious."&lt;br /&gt;The big difference with imaginers is that they dream an then they DO !&lt;br /&gt;So don't just be a dreamer, be an imagineer.&lt;br /&gt;What's better than vision ?&lt;br /&gt;&lt;br /&gt;You must have all been given a lecture at one time or another about the&lt;br /&gt;importance of having a vision. Even leadership expert John Maxwell says&lt;br /&gt;that an indispensable quality of a leader is to have a vision. It is also&lt;br /&gt;very clear that&lt;br /&gt;Without vision, people perish." So no doubt about it, having a vision&lt;br /&gt;is important to success. But surprise ! There's something more potent than&lt;br /&gt;a vision. It's a CAUSE. If all you're doing is trying to reach your&lt;br /&gt;vision an you're pitted against someone fighting for a cause, chances&lt;br /&gt;are you'll lose. The Vietnam War is a classic example. Literally with&lt;br /&gt;sticks and stones, the Viet Cong beat the heavily armed US Army to&lt;br /&gt;surrender,&lt;br /&gt;primarily because the US has a vision to win the war, but the Vietnamese&lt;br /&gt;were fighting for a cause.&lt;br /&gt;&lt;br /&gt;In the realm of business, many leaders have visions of making their company&lt;br /&gt;No. 1, or grabbing market share, or forever increasing profits.&lt;br /&gt;&lt;br /&gt;Nothing really wrong with that vison, but take the example of Sony founder&lt;br /&gt;Akio Morita. He did not just have a vision to build the biggest electronics&lt;br /&gt;company in the world. In his biography, " Made in Japan" he&lt;br /&gt;reveals that the real reason he set up Sony was to help rebuild his country,&lt;br /&gt;which had just been bettered by war. He had a cause he was fighting for.&lt;br /&gt;His vision to be an electronics giant was secondary.&lt;br /&gt;What's the difference between a vision and a cause?&lt;br /&gt;Here's what sets them apart.&lt;br /&gt;&lt;br /&gt;· No one is wiling to die for a vision. People will die for a cause.&lt;br /&gt;· You possess a vision. A cause possesses you.&lt;br /&gt;· A vision lies in your hands. A cause lies in your heart.&lt;br /&gt;· A vision involves sacrifice. A cause involves the ultimate sacrifice.&lt;br /&gt;&lt;br /&gt;Just a word of caution. You must have the right vision, and you must be&lt;br /&gt;fighting for the right cause. In the end, right will always win out.&lt;br /&gt;&lt;br /&gt;It may take time, and it may take long. But if you have the right vision&lt;br /&gt;and are fighting for the right cause, you will prevail. If not, no matter&lt;br /&gt;how sincere you are, if you are not fighting for what is right, you will&lt;br /&gt;ultimately fail.&lt;br /&gt;&lt;br /&gt;It is said : "To whom much is given, much is required."&lt;br /&gt;&lt;br /&gt;Having been given the opportunity to study in UP, no doubt, much has been&lt;br /&gt;given to you in terms of an excellent education. Don't forget that in&lt;br /&gt;return, much is now required of you to use that education not just for&lt;br /&gt;yourself, but for others.&lt;br /&gt;And as you move up and start reaching the pinnacle of success, even more&lt;br /&gt;will be required of you to look at the welfare of others, of society and&lt;br /&gt;of the country.&lt;br /&gt;&lt;br /&gt;A final review :&lt;br /&gt;&lt;br /&gt;· What's better than focusing on the negative ?&lt;br /&gt;Focus on the positive&lt;br /&gt;&lt;br /&gt;· What's better than working hard ?&lt;br /&gt;Its working smart&lt;br /&gt;&lt;br /&gt;· What's better than doing something for yourself ?&lt;br /&gt;Doing something for your country&lt;br /&gt;&lt;br /&gt;· What's better than a vision ?&lt;br /&gt;A cause&lt;br /&gt;&lt;br /&gt;· What's better than a long speech ?&lt;br /&gt;Definitely, a short one&lt;br /&gt;&lt;br /&gt;"Life is what we make it, always has been, always will be."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115805675596293166?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115805675596293166/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115805675596293166' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805675596293166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115805675596293166'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/be-positive.html' title='Be Positive!!!'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115782051992368318</id><published>2006-09-09T22:16:00.000+05:30</published><updated>2006-09-09T22:18:56.156+05:30</updated><title type='text'>Virus Bulletin : Win32/Sober.Y</title><content type='html'>&lt;p&gt; &lt;span class="Text"&gt;Sober.Y is a typical mass mailing E-mail worm, the size is 55390 bytes and the worm is runtime compressed by UPX, an executable runtime packer, and then patched to avoid normal unpacking.&lt;/span&gt;&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Installation and Autostart Techniques&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;Upon execution, it displays the following faked error message box:&lt;/p&gt;   &lt;p class="Text"&gt;&lt;img style="width: 196px; height: 128px;" alt="" src="http://ve.nod32.ch/worms/sobery-2.jpg" /&gt;&lt;/p&gt;   &lt;p class="Text"&gt;The worm then copies itself in the “%windir%\WinSecurity\” folder as “services.exe”, “smss.exe” and “csrss.exe”. It creates the folder “WinSecurity” when it doesn’t exist. &lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: %windir% denotes Windows directory (e.g. C:\WINDOWS) and %system% denotes Windows System directory (e.g. C:\WINDOWS\SYSTEM32) as they differ on various versions of Microsoft Windows.&lt;/p&gt;   &lt;p class="Text"&gt;The worm, running as “services.exe” then locks “services.exe” in it's own process and starts two other worm instances, “smss.exe” and “csrss.exe”, from this process.&lt;br /&gt; Sober.Y uses exclusive file locking technologies to prevent an antivirus program from opening and scanning files once the worm runs active in memory. The result is that no file reading actions can be performed on the worm executable.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Important Note&lt;/span&gt;: As with all previous Sober Versions with exclusive lock, Sober.Y changes exactly one byte in the file header of the exclusively loaded files at position 0xA0. Once the worm does run, the three executables differ in the MD5 checksum. The worm uses this flag as an infection marker. If this byte is not 0x09 the worm will display the following faked Symantec live updater message box:&lt;/p&gt;   &lt;p class="Text"&gt;&lt;img style="width: 190px; height: 133px;" alt="" src="http://ve.nod32.ch/worms/sobery-1.jpg" /&gt;&lt;/p&gt;   &lt;p class="Text"&gt;Three other files are created in the same folder: "socket1.ifo", "socket2.ifo", "socket3.ifo" containing a mime encoded email copy of the worm’s zip file (75996 bytes in size).&lt;/p&gt;   &lt;p class="Text"&gt;Every process tries to attach its own copy to outgoing emails. For example, services.exe, process 1, will attach socket1.ifo, and csrss.exe, process 3, will attach socket3.ifo.&lt;/p&gt;   &lt;p class="Text"&gt;The files "mssock1.dli", "mssock2.dli", "mssock3.dli" and “winmem1.ory”, “winmem2.ory”, winmem3.ory” are used for collecting harvested email addresses. &lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y also creates Starter.run and might create sysonce.tst and nichtnem.nop depending on the system.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Important Note&lt;/span&gt;: Sober.Y adds the numbers “1”, “2”, “3” depending on the running process instance to the filenames. Instance 1 is always the main instance of the worm (services.exe). The worm is able to perform several multitask operations, such as collecting different email styles and combining different email addresses found by previous sober process instances (for example, instance 3 can use collected data from instances 2 and 1).&lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y also creates several files in the %system% folder:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;nonrunso.ber&lt;br /&gt; langeinf.lin&lt;br /&gt; filesms.fms&lt;br /&gt; runstop.rst&lt;br /&gt; rubezahl.rub&lt;br /&gt; bbvmwxxf.hml&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;These files are not malicious and therefore not detected as part of the worm. Sober uses this Zero-Byte files to overwrite previous sober version copies.&lt;/p&gt;   &lt;p class="Text"&gt;The worm adds the following registry keys to the registry to make sure that it runs every time windows is started:&lt;/p&gt;   &lt;p class="codeSample"&gt; HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt; “{Space}Windows” = “%WINDOWS%\WinSecurity\services.exe”&lt;/p&gt;   &lt;p class="codeSample"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt; “_Windows” = “%WINDOWS%\WinSecurity\services.exe”&lt;/p&gt;   &lt;p class="Text"&gt;The worm continuously watches for the presence of these registry keys and recreates them if they are no longer present. This is done via Visual Basic Timer Interrupt polling.&lt;/p&gt;   &lt;p class="Text"&gt; &lt;span class="Subtitle"&gt;E-mail Harvesting&lt;/span&gt;&lt;span class="Text"&gt;:&lt;/span&gt;&lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y scans all fixed disks and collects E-mail addresses from files which match one of the following file extensions:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt; &lt;strong&gt;pmr phtm stm slk inbox imb csv bak imh xhtml imm imh cms nws vcf ctl dhtm cgi&lt;br /&gt; pp ppt msg jsp oft vbs uin ldb abc pst cfg mdw mbx mdx mda adp nab fdb vap dsp&lt;br /&gt; ade sln dsw mde frm bas adr cls ini ldif log mdb xml wsh tbb abx abd adb pl rtf mmf&lt;br /&gt; doc ods nch xls nsf txt wab eml hlp mht nfo php asp shtml dbx &lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt; &lt;span class="Subtitle"&gt;E-mail Sender&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;The sender’s e-mail addresses are spoofed and may appear to be sent by a familiar source.&lt;br /&gt; This worm uses its own SMTP (Simple Mail Transfer Protocol) engine to mass-mail copies of itself to other e-mail addresses.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;E-mail Subjects&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;E-mail subjects are chosen depending on the recipient's address&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt; Your Password&lt;br /&gt; Registration Confirmation&lt;br /&gt; smtp mail failed&lt;br /&gt; Mail delivery failed&lt;br /&gt; hi, ive a new mail address&lt;br /&gt; You visit illegal websites&lt;br /&gt; Your IP was logged&lt;br /&gt; Paris Hilton &amp; Nicole Richie&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;for German speaking domains:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt; Ihr Passwort&lt;br /&gt; Account Information&lt;br /&gt; SMTP Mail gescheitert&lt;br /&gt; Mailzustellung wurde unterbrochen&lt;br /&gt; Ermittlungsverfahren wurde eingeleitet&lt;br /&gt; Sie besitzen Raubkopien&lt;br /&gt; RTL: Wer wird Millionaer&lt;br /&gt; Sehr geehrter Ebay-Kunde&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;The worm makes this language selection based on the following domain suffixes:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;de, ch, at, li or if the email destination is gmx.&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Message Body&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;The e-mail contains one of the following message texts:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;Account and Password Information are attached!&lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;This is an automatically generated Delivery Status Notification.&lt;br /&gt; SMTP_Error&lt;br /&gt; I'm afraid I wasn't able to deliver your message.&lt;br /&gt; This is a permanent error; I've given up. Sorry it didn't work out.&lt;br /&gt; The full mail-text and header is attached!&lt;br /&gt;   &lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;hey its me, my old address dont work at time. i dont know why?!&lt;br /&gt; in the last days ive got some mails. i' think thaz your mails but im not sure!&lt;br /&gt; plz read and check ...&lt;br /&gt; cyaaaaaaa&lt;br /&gt;   &lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Dear Sir/Madam,&lt;br /&gt; we have logged your IP-address on more than 30 illegal Websites.lease answer our questions!&lt;br /&gt; The list of questions are attached.&lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Yours faithfully,&lt;br /&gt; Steven Allison&lt;br /&gt; Department Office Admin Mail Post&lt;br /&gt; *** Federal Bureau of Investigation -FBI-&lt;br /&gt; *** 935 Pennsylvania Avenue, NW, Room 3220&lt;br /&gt; *** Washington, DC 20535&lt;br /&gt; ++++ Central Intelligence Agency -CIA-&lt;br /&gt; ++++ Office of Public Affairs&lt;br /&gt; ++++ Washington, D.C. 20505&lt;br /&gt; ++++ phone: (703) 482-0623&lt;br /&gt; ++++ 7:00 a.m. to 5:00 p.m., US Eastern time&lt;br /&gt;   &lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;The Simple Life:&lt;br /&gt; View Paris Hilton &amp; Nicole Richie video clips , pictures &amp;amp;amp; more ;)&lt;br /&gt; Download is free until Jan, 2006!&lt;br /&gt; Please use our Download manager.&lt;/strong&gt;&lt;br /&gt;   &lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;or for German speaking domains:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt; &lt;strong&gt;Ihre Nutzungsdaten wurden erfolgreich geaendert. Details entnehmen Sie bitte dem Anhang.&lt;br /&gt; *** {http://}www.{Sender Domain}&lt;br /&gt; *** E-Mail: PassAdmin &lt;/strong&gt;&lt;/p&gt;        &lt;p&gt; &lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Bei uns wurde ein neues Benutzerkonto mit dem Namen beantragt.&lt;br /&gt; Um das Konto einzurichten, benoetigen wir eine Bestaetigung, dass die bei der Anmeldung angegebene e-Mail-Adresse stimmt.&lt;br /&gt; Bitte senden Sie zur Bestaetigung den ausgefuellten Anhang an uns zurueck.&lt;br /&gt; Wir richten Ihr Benutzerkonto gleich nach Einlangen der Bestaetigung ein und verstaendigen Sie dann per e-Mail, sobald Sie Ihr Konto benutzen koennen.&lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Vielen Dank,&lt;br /&gt; Ihr Ebay-Team&lt;/strong&gt;&lt;/p&gt;        &lt;p&gt; &lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Sehr geehrte Dame, sehr geehrter Herr,&lt;br /&gt; das Herunterladen von Filmen, Software und MP3s ist illegal und somit strafbar.&lt;br /&gt; Wir moechten Ihnen hiermit vorab mitteilen, dass Ihr Rechner unter der IP&lt;br /&gt; erfasst wurde. Der Inhalt Ihres Rechner wurde als Beweismittel sichergestellt und es wird ein Ermittlungsverfahren gegen Sie eingleitet.&lt;br /&gt; Die Strafanzeige und die Moeglichkeit zur Stellungnahme wird Ihnen in den naechsten Tagen schriftlich zugestellt.&lt;br /&gt; Aktenzeichen NR.:#&lt;br /&gt; (siehe Anhang)&lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Hochachtungsvoll&lt;br /&gt; i.A. Juergen Stock&lt;br /&gt; --- Bundeskriminalamt BKA&lt;br /&gt; --- Referat LS 2&lt;br /&gt; --- 65173 Wiesbaden&lt;br /&gt; --- Tel.: +49 (0)611 - 55 - 12331 oder&lt;br /&gt; --- Tel.: +49 (0)611 - 55 – 0&lt;/strong&gt;&lt;/p&gt;        &lt;p&gt; &lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;Glueckwunsch: Bei unserer EMail Auslosung hatten Sie und weitere neun Kandidaten Glueck.&lt;br /&gt; Sie sitzen demnaechst bei Guenther Jauch im Studio!&lt;br /&gt; Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.&lt;/strong&gt;&lt;/p&gt;        &lt;p class="Text"&gt;&lt;strong&gt;+++ RTL interactive GmbH&lt;br /&gt; +++ Geschaeftsfuehrung: Dr. Constantin Lange&lt;br /&gt; +++ Am Coloneum 1&lt;br /&gt; +++ 50829 Koeln&lt;br /&gt; +++ Fon: +49(0) 221-780 0 oder&lt;br /&gt; +++ Fon: +49 (0) 180 5 44 66 99&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;E-mail Attachments&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;The worm attaches to a German recipient's domain with a self-copy as:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;{TXT1}.zip&lt;br /&gt; {TXT1}-TextInfo.zip&lt;br /&gt; Email.zip&lt;br /&gt; Email_text.zip&lt;br /&gt; {TXT2}.zip&lt;br /&gt; Akte{TXT2}.zip&lt;br /&gt; {TXT3}.zip&lt;br /&gt; {TXT3}_Text.zip&lt;br /&gt; Ebay.zip&lt;br /&gt; Ebay-User_RegC.zip&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: {TXT1} represents one of the following text: &lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;Service&lt;br /&gt; Webmaster&lt;br /&gt; Postman&lt;br /&gt; Info&lt;br /&gt; Hostmaster&lt;br /&gt; Postmaster&lt;br /&gt; Admin&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: {TXT2} represents one of the following text: &lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;Downloads&lt;br /&gt; BKA&lt;br /&gt; Internet&lt;br /&gt; Post&lt;br /&gt; Anzeige&lt;br /&gt; BKA.Bund&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: {TXT3} represents one of the following text:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;Kandidat&lt;br /&gt; WWM&lt;br /&gt; Auslosung&lt;br /&gt; Casting&lt;br /&gt; Gewinn&lt;br /&gt; Info&lt;br /&gt; RTL-Admin&lt;br /&gt; RTL&lt;br /&gt; Webmaster&lt;br /&gt; RTL-TV&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;or as:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;reg_pass.zip&lt;br /&gt; reg_pass-data.zip&lt;br /&gt; mail.zip&lt;br /&gt; mail_body.zip&lt;br /&gt; mailtext.zip&lt;br /&gt; list{random}.zip&lt;br /&gt; question_list{random}.zip&lt;br /&gt; downloadm.zip&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;to all other domains.&lt;/p&gt;   &lt;p class="Text"&gt;The worm avoids emails which contain one of the following strings:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;-dav&lt;br /&gt; .dial.&lt;br /&gt; .kundenserver.&lt;br /&gt; .ppp.&lt;br /&gt; .qmail@&lt;br /&gt; .sul.t-&lt;br /&gt; @arin&lt;br /&gt; @avp&lt;br /&gt; @ca.&lt;br /&gt; @example.&lt;br /&gt; @foo.&lt;br /&gt; @from.&lt;br /&gt; @gmetref&lt;br /&gt; @iana&lt;br /&gt; @ikarus.&lt;br /&gt; @kaspers&lt;br /&gt; @messagelab&lt;br /&gt; @nai.&lt;br /&gt; @panda&lt;br /&gt; @smtp.&lt;br /&gt; @sophos&lt;br /&gt; @www&lt;br /&gt; abuse&lt;br /&gt; announce&lt;br /&gt; antivir&lt;br /&gt; anyone&lt;br /&gt; anywhere&lt;br /&gt; bellcore.&lt;br /&gt; bitdefender&lt;br /&gt; clock&lt;br /&gt; detection&lt;br /&gt; domain.&lt;br /&gt; emsisoft&lt;br /&gt; ewido.&lt;br /&gt; free-av&lt;br /&gt; freeav&lt;br /&gt; ftp.&lt;br /&gt; gold-certs&lt;br /&gt; google&lt;br /&gt; host.&lt;br /&gt; icrosoft.&lt;br /&gt; ipt.aol&lt;br /&gt; law2&lt;br /&gt; linux&lt;br /&gt; mailer-daemon&lt;br /&gt; mozilla&lt;br /&gt; mustermann@&lt;br /&gt; nlpmail01.&lt;br /&gt; noreply&lt;br /&gt; nothing&lt;br /&gt; ntp-&lt;br /&gt; ntp.&lt;br /&gt; ntp@&lt;br /&gt; office&lt;br /&gt; password&lt;br /&gt; postmas&lt;br /&gt; reciver@&lt;br /&gt; secure&lt;br /&gt; service&lt;br /&gt; smtp-&lt;br /&gt; somebody&lt;br /&gt; someone&lt;br /&gt; spybot&lt;br /&gt; sql.&lt;br /&gt; subscribe&lt;br /&gt; support&lt;br /&gt; t-dialin&lt;br /&gt; t-ipconnect&lt;br /&gt; test@&lt;br /&gt; time&lt;br /&gt; user@&lt;br /&gt; variabel&lt;br /&gt; verizon.&lt;br /&gt; viren&lt;br /&gt; virus&lt;br /&gt; whatever@&lt;br /&gt; whoever@&lt;br /&gt; winrar&lt;br /&gt; winzip&lt;br /&gt; you@&lt;br /&gt; yourname&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;if found, the worm will not add this email to the harvested email address collecting file.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Process Termination&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y has encrypted part of its code, where it tries to terminate several security related programs, such as cleaner tools. For instance, if a user tries to run McAfee’s cleaner tool “Stinger.Exe”, the worm displays this faked message box:&lt;/p&gt;   &lt;p class="Text"&gt;&lt;img style="width: 349px; height: 177px;" alt="" src="http://ve.nod32.ch/worms/sobery-3.jpg" /&gt;&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: This also applies to Microsoft’s Malicious Removal Tool “MRT.EXE”&lt;/p&gt;   &lt;p class="Text"&gt;Depending on the system setup, the worm might also try to delete Symantec live updater related executables and copies itself as the updater file, so that the worm is started every time that liveupdate is scheduled.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Date and Time Synchronizing&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y tries to connect to the following servers in order to retrieve the correct date and time to avoid manipulated times on virtual test environment systems and to check for a present internet connection:&lt;/p&gt;   &lt;blockquote&gt;      &lt;p class="Text"&gt;&lt;strong&gt;Rolex.PeachNet.edu&lt;br /&gt; clock.psu.edu&lt;br /&gt; cuckoo.nevada.edu&lt;br /&gt; gandalf.theunixman.com&lt;br /&gt; nist1.datum.com&lt;br /&gt; ntp-1.ece.cmu.edu&lt;br /&gt; ntp-2.ece.cmu.edu&lt;br /&gt; ntp-sop.inria.fr&lt;br /&gt; ntp.lth.se&lt;br /&gt; ntp.massayonet.com.br&lt;br /&gt; ntp.metas.ch&lt;br /&gt; ntp.pads.ufrj.br&lt;br /&gt; ntp0.cornell.edu&lt;br /&gt; ntp1.arnes.si&lt;br /&gt; ntp1.theremailer.net&lt;br /&gt; ntp2.ien.it&lt;br /&gt; ntp2b.mcc.ac.uk&lt;br /&gt; ntp2c.mcc.ac.uk&lt;br /&gt; ntp3.fau.de&lt;br /&gt; ntps1-1.uni-erlangen.de&lt;br /&gt; ptbtime2.ptb.de&lt;br /&gt; rolex.usg.edu&lt;br /&gt; st.ntp.carnet.hr&lt;br /&gt; sundial.columbia.edu&lt;br /&gt; swisstime.ethz.ch&lt;br /&gt; tick.greyware.com&lt;br /&gt; time-a.timefreq.bldrdoc.gov&lt;br /&gt; time-ext.missouri.edu&lt;br /&gt; time.chu.nrc.ca&lt;br /&gt; time.ien.it&lt;br /&gt; time.kfki.hu&lt;br /&gt; time.mit.edu&lt;br /&gt; time.nist.gov&lt;br /&gt; time.nrc.ca&lt;br /&gt; time.windows.com&lt;br /&gt; time.xmission.com&lt;br /&gt; timelord.uregina.ca&lt;br /&gt; tock.keso.fi&lt;br /&gt; utcnist.colorado.edu&lt;br /&gt; vega.cbk.poznan.pl&lt;br /&gt; time.windows.com&lt;/strong&gt;&lt;/p&gt;   &lt;/blockquote&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;TCP/IP Patching&lt;/span&gt;:&lt;/p&gt;   &lt;p class="Text"&gt;Sober.Y also tries to patch the TCPIP.SYS driver of Windows NT based systems:&lt;/p&gt;   &lt;p class="codeSample"&gt;%System%\drivers\TCPIP.SYS&lt;br /&gt; %System%\dllcache\TCPIP.SYS&lt;br /&gt; %Windir%\ServicePackFiles\i386\TCPIP.SYS&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Note&lt;/span&gt;: The worm is surprisingly able to patch different versions of the TCPIP.SYS file (build 2180, build 2505, build 2631 and build 2685) by modifying the CRC sum of the file and changing the number of allowed half-open connections. This patching will actually work only on Windows XP systems (Service Pack 2) and Windows 2003 Server Systems.&lt;/p&gt;   &lt;p class="Text"&gt;&lt;span class="Subtitle"&gt;Background&lt;/span&gt;: This technology was introduced in Germany by lvllord, a german tools programmer ( &lt;a href="http://www.lvllord.de/"&gt;http://www.lvllord.de&lt;/a&gt; ) in the year 2004, exactly the date when the first sober worms started using this technology.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115782051992368318?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115782051992368318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115782051992368318' title='23 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115782051992368318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115782051992368318'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/09/virus-bulletin-win32sobery.html' title='Virus Bulletin : Win32/Sober.Y'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>23</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115462633162212190</id><published>2006-08-03T23:00:00.000+05:30</published><updated>2006-08-03T23:02:11.636+05:30</updated><title type='text'>All about Web 2.0</title><content type='html'>&lt;table border="0" cellpadding="0" cellspacing="0" width="380"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2" width="100%"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;b&gt;&lt;/b&gt;  &lt;p&gt;There are many definitions being thrown about. Ask around, and you'll get answers like "blogs", "RSS", "rich graphical capabilities", "video and rich interaction", "interacting with voice commands". &lt;/p&gt;&lt;p&gt;To put it simply, the Internet industry is approaching "graduation" and looking ahead to identify new applications that will enhance the online user experience. &lt;/p&gt;&lt;p&gt;Companies like Microsoft and Google are introducing new tools and technologies that enable us to create more interactive Web sites and to collaborate more easily with one another when we're online.  &lt;/p&gt;&lt;p&gt;These emerging technologies are part of the natural evolution of the Internet, where Web sites in the early days were largely brochureware and their content didn't change frequently. Today, blogs and community sites are the rage, because they turn Web surfers into active users. &lt;/p&gt;&lt;p&gt;But if the focus of Web 2.0 is on the online user and enhancing the user experience, then perhaps the focus of the next era should also be about making it simpler, easier, and faster. We seem to be piling on more features into everything, including mobile phones, computers and Web sites, without making it easier for the user to get to them. Give me a feature that doesn't require more than three clicks to get to it, or doesn't take me a whole afternoon to learn. &lt;/p&gt;&lt;p&gt;For businesses, Web 2.0 is relevant, because more people are going online, and there is no better time than now to use the Internet to engage their existing and potential customers, as well as business partners. What do you think?&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115462633162212190?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115462633162212190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115462633162212190' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115462633162212190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115462633162212190'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/08/all-about-web-20.html' title='All about Web 2.0'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115435088974284388</id><published>2006-07-31T18:26:00.000+05:30</published><updated>2006-07-31T18:31:29.750+05:30</updated><title type='text'>The $100 laptop</title><content type='html'>&lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" border="0" cellpadding="0" cellspacing="0" width="380"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2" width="100%"&gt;&lt;h2 class="nhl" style="margin-left: 6px;"&gt;The $100 laptop moves closer to reality&lt;/h2&gt;           &lt;/td&gt;     &lt;/tr&gt;  &lt;tr&gt;     &lt;/tr&gt;     &lt;tr&gt;&lt;td colspan="2"&gt;  &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td colspan="2"&gt; &lt;p&gt;&lt;b&gt;A low-cost computer for the masses moved one step closer to reality on  Wednesday.&lt;/b&gt;  &lt;/p&gt;&lt;p&gt;&lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fweb.media.mit.edu%2F%7Enicholas&amp;siteId=22&amp;amp;oId=2100-1040-5884683&amp;ontId=1040&amp;amp;lop=nl.ex" target="_blank"&gt;&lt;/a&gt;Nicholas Negroponte, the co-founder of the Media Lab at the  Massachusetts Institute of Technology, detailed specifications for a $100  windup-powered laptop targeted at children in developing nations.&lt;/p&gt; &lt;p&gt;Negroponte, who laid out his original proposal at the World Economic Forum in  Davos, Switzerland, in January, said MIT and his nonprofit group, called One Laptop Per Child&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;, is in discussions with five  countries--Brazil, China, Thailand, Egypt and South Africa--to distribute up to  15 million test systems to children.&lt;/p&gt;&lt;!-- IMAGE CODE --&gt;&lt;!-- END IMAGE CODE --&gt; &lt;p&gt;In addition, Massachusetts is working with MIT on a plan to distribute the  laptops to schoolchildren, Negroponte said.&lt;/p&gt; &lt;p&gt;"This is the most important thing I have ever done in my life," Negroponte  said on Wednesday during a presentation at Technology Review's Emerging  Technologies Conference at MIT. "Reception has been incredible. The idea is  simple. It's an education project, not a laptop project. If we can make  education better--particularly primary and secondary schools--it will be a  better world."&lt;/p&gt; &lt;p&gt;He said a goal of the project is to make the low-cost PC idea a grassroots  movement that will spread in popularity, like the Linux operating system or the  Wikipedia free online encyclopedia. "This is open-source education. It's a big  issue."&lt;/p&gt; &lt;p&gt;Negroponte said the idea is that governments will pay roughly $100 for the  laptops and will distribute them for free to students. &lt;/p&gt; &lt;p&gt;The proposed design of the machines calls for a 500MHz processor, 1GB of  memory and an innovative dual-mode display that can be used in full-color mode,  or in a black-and-white sunlight-readable mode. The display makes the laptop  "both an electronic book and a laptop," he said.&lt;/p&gt; &lt;p&gt;One display design being considered is a flat, flexible printed display  developed at MIT's Media Lab. Negroponte said the technology can be used to  produce displays that cost roughly 10 cents per square inch. "The target is $12  for a 12-inch display with near-zero power consumption," he said.&lt;/p&gt; &lt;p&gt;Power for the new systems will be provided through either conventional  electric current, batteries or by a windup crank attached to the side of the  notebooks, since many countries targeted by the plan do not have power in remote  areas, Negroponte said.&lt;/p&gt;&lt;!-- STORY TEASE --&gt;&lt;!-- END STORY TEASE --&gt; &lt;p&gt;The machines, which will run a version of the Linux operating system, will  also include other applications, some developed by MIT researchers, as well as  country-specific software. "Software has gotten too fat and unreliable, so we  started with Linux," he said.&lt;/p&gt; &lt;p&gt;For connectivity, the systems will be Wi-Fi- and cell phone-enabled, and will  include four USB ports, along with built-in "mesh networking," a peer-to-peer  concept that allows machines to share a single Internet connection.&lt;/p&gt; &lt;p&gt;"In emerging nations, the issue is not connectivity," Negroponte said. "That  was the issue, but there are many people working on it, (thanks to) global  competitiveness. But for education, the roadblock is the laptop."&lt;/p&gt; &lt;p&gt;Five companies are working with MIT to develop an initial 5 million to 15  million test units within the year: Google, Advanced Micro Devices, News Corp.,  Red Hat and BrightStar, Negroponte said. He said the current plan is to produce  100 million to 150 million units by 2007.&lt;/p&gt; &lt;p&gt;Negroponte admits that his goals are ambitious. Currently, the world  production of laptops is just under 50 million, he said.&lt;/p&gt; &lt;p&gt;While the initial goal of the project is to work with governments, Negroponte  said MIT is considering licensing the design or giving it to a third-party  company to build commercial versions of the PC. "Those might be available for  $200, and $20 or $30 will come back to us to make the kids' laptops. We're still  working on that," he said.&lt;/p&gt; &lt;p&gt;Others have launched low-cost PC ideas in the past, though MIT's project may  be the most ambitious. &lt;/p&gt; &lt;p&gt;Last year, Advanced Micro Devices announced plans for its Personal Internet  Connector--a prototype with a price tag of at least $185, with no display. And an  Indian company called Novatium said it plans to offer a stripped-down home  computer for about $70 or $75. &lt;/p&gt; &lt;p&gt;In addition, Microsoft's antipiracy-minded Steve Ballmer  last year called for a move toward the $100 PC for developing nations.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;(CNetNews.com)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115435088974284388?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115435088974284388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115435088974284388' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115435088974284388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115435088974284388'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/07/100-laptop.html' title='The $100 laptop'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115435050859078592</id><published>2006-07-31T18:19:00.000+05:30</published><updated>2006-07-31T18:25:08.606+05:30</updated><title type='text'>Virus Alert  (Bin Laden Trojan)</title><content type='html'>&lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" border="0" cellpadding="0" cellspacing="0" width="380"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2" width="100%"&gt;&lt;h2 class="nhl" style="margin-left: 6px;"&gt;&lt;span style="font-style: italic; font-weight: normal;font-size:85%;" &gt;&lt;span style="font-family: georgia;"&gt;(CNetNews.com)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/h2&gt;&lt;h2 class="nhl" style="margin-left: 6px;"&gt;Bin Laden Trojan quickly constrained&lt;br /&gt;&lt;/h2&gt;           &lt;/td&gt;     &lt;/tr&gt;  &lt;tr&gt;     &lt;/tr&gt;     &lt;tr&gt;&lt;td colspan="2"&gt;  &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td colspan="2"&gt; &lt;p&gt;&lt;b&gt;A spam e-mail that promises pictures of a captured Osama bin Laden but  carries a malicious attachment has failed to spread widely, security experts  said Friday.&lt;/b&gt;  &lt;/p&gt;&lt;p&gt;Millions of copies of various versions of the e-mail were mass-mailed on  Thursday, representatives from F-Secure and McAfee said. All versions of the  message announced that the al-Qaida leader had been seized and included an  attachment called "pics" that, when opened, attempted to download a worm to the  victim's PC, the antivirus companies said. &lt;/p&gt; &lt;p&gt;If the download is successful, the worm will attempt to start propagating by  e-mailing itself, said Craig Schmugar, virus research manager at McAfee. It can  also set the victim's computer up to be used as a relay for spam, he said. &lt;/p&gt; &lt;p&gt;Part of one of the spam messages seen by F-Secure read: "Turn on your TV.  Osama Bin Laden has been captured. While CNN has no pictures at this point of  time, the military channel (PPV) released some pictures. I managed to capture a  couple of these pictures off my TV. Ive attached a slideshow containing all the  pictures I managed to capture." &lt;/p&gt;&lt;!-- STORY TEASE --&gt;&lt;!-- END STORY TEASE --&gt; &lt;p&gt;Though the Osama bin Laden e-mail was widely spammed, neither McAfee nor  F-Secure had seen many reports of the worm. "That indicates that most people are  identifying the suspicious spam or blocking it," Schmugar said. &lt;/p&gt; &lt;p&gt;Ero Carrera, an antivirus researcher at F-Secure, agreed. "The initial  numbers made us think that it could be a big outbreak, but in the end it was  nothing more than just a big seed," he said, referring to a large number of  initial spam messages. &lt;/p&gt; &lt;p&gt;This is not the first time Osama bin Laden's name has been used in an attempt  to trick users to open a malicious file. Last year, a message claiming to  contain pictures of the al-Qaida leader committing suicide  surfaced in Internet news groups. The supposed picture file launched a Trojan to  hijack the user's PC. &lt;/p&gt; &lt;p&gt;Saddam Hussein "death" photos have also been used as worm bait. &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115435050859078592?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115435050859078592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115435050859078592' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115435050859078592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115435050859078592'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/07/virus-alert-bin-laden-trojan.html' title='Virus Alert  (Bin Laden Trojan)'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115426212562861051</id><published>2006-07-30T17:48:00.000+05:30</published><updated>2006-07-30T17:52:05.643+05:30</updated><title type='text'>Myself</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/3913/3475/1600/digitalMe.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/3913/3475/400/digitalMe.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115426212562861051?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115426212562861051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115426212562861051' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115426212562861051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115426212562861051'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/07/myself_30.html' title='Myself'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115426049284921821</id><published>2006-07-30T17:22:00.000+05:30</published><updated>2006-07-30T17:24:52.850+05:30</updated><title type='text'>My Hobbies</title><content type='html'>I love fiddling with computers. I know Visual Basic, C++, Photoshop and love learning new softwares and programming languages. I also like stamp collection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115426049284921821?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115426049284921821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115426049284921821' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115426049284921821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115426049284921821'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/07/my-hobbies.html' title='My Hobbies'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31886761.post-115425991119285441</id><published>2006-07-30T17:09:00.000+05:30</published><updated>2006-07-30T17:15:11.200+05:30</updated><title type='text'>Myself</title><content type='html'>Hello&lt;br /&gt;I am Deepak Krishnan and  this is my personal blog. I am a computer enthusiast and loves programming and gaming. I am currently studying in Kendriya Vidyalaya in my XIIth standard. I am 17 yrs old. I am currently residing in Palakkad (Kerala).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31886761-115425991119285441?l=deepakkrishnansblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deepakkrishnansblog.blogspot.com/feeds/115425991119285441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31886761&amp;postID=115425991119285441' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115425991119285441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31886761/posts/default/115425991119285441'/><link rel='alternate' type='text/html' href='http://deepakkrishnansblog.blogspot.com/2006/07/myself.html' title='Myself'/><author><name>Deepu</name><uri>http://www.blogger.com/profile/15974402061133220735</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
