<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC antimalware RSS Feed</title>
 <link>http://www.maximumpc.com/tags/antimalware</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Symantec Releases Public Beta of Norton Internet Security 2010 and AntiVirus 2010</title>
 <link>http://www.maximumpc.com/article/news/symantec_releases_public_beta_norton_internet_security_2010_and_antivirus_2010</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;Many of our readers were taken off-guard when we rated Norton Internet Security 2009 a 9/Kickass in last year&#039;s &lt;a href=&quot;/article/features/protect_your_pc_from_guys_like_this&quot;&gt;antivirus roundup&lt;/a&gt;, and we even admit to being surprised at Norton&#039;s transformation from a resource-heavy sloth to a lean and competent antimalware package. We hope the trend continues, and we&#039;ll have a chance to see if it does now that Symatec has released beta versions of its upcoming 2010 releases to the public.&lt;/p&gt;
&lt;p&gt;The new version features a new protection model codenamed Quorum and will put a heavier focus on reputation-based malware detection. While it won&#039;t replace existing signature-based detection for known threats, Norton says the reputation model can detect zero-day malware that&#039;s never been seen before. &lt;/p&gt;
&lt;p&gt;&amp;quot;Our new approach changes the rules by both enhancing traditional security techniques to make them more aggressvie and by making it dramatically more difficult for attackers to evade detection by simply changing their malware,&amp;quot; &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2349613,00.asp&quot;&gt;said Rowan Trollope&lt;/a&gt;, Symantec senior vice president, Consumer Business Unit. &lt;/p&gt;
&lt;p&gt;Other features include an overhaul to parental control and spam filtering, more detailed information provided by Norton Insight, which identifies known good programs for faster scanning, and a new feature called Autopsy, which is designed to help the user understand what just happened when Norton automatically removes an infection.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.norton.com/nis2010beta&quot;&gt;Norton Internet Security 2010 Beta&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.norton.com/nav2010beta&quot;&gt;Norton Antivirus 2010 Beta&lt;/a&gt;&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/NIS_2010_Beta.png&quot; width=&quot;415&quot; height=&quot;282&quot; /&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Symantec&lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/symantec_releases_public_beta_norton_internet_security_2010_and_antivirus_2010#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/antimalware">antimalware</category>
 <category domain="http://www.maximumpc.com/geek_tested/antivirus">antivirus</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3220">AV</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8522">internet security 2010</category>
 <category domain="http://www.maximumpc.com/geek_tested/norton">norton</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3806">symantec</category>
 <pubDate>Fri, 03 Jul 2009 17:19:54 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">6859 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Fake Microsoft Update Email Can Ruin Your Evening - Stop It Now!</title>
 <link>http://www.maximumpc.com/article/fake_microsoft_update_email_can_ruin_your_evening_stop_it_now</link>
 <description>&lt;!--paging_filter--&gt;&lt;h4&gt;Heed This &amp;quot;Warning&amp;quot; - And You&#039;ll Be Sorry&lt;/h4&gt;
&lt;p&gt;Security vendor Sunbelt Software&#039;s blog reports that a fake warning to &amp;quot;update your P.C. in maximum 12 hours otherwise your Windows will be Expired&amp;quot; is making the email rounds. While the message (visible &lt;a href=&quot;http://sunbeltblog.blogspot.com/2008/01/fake-ms-update.html&quot;&gt;here&lt;/a&gt;) has all of the earmarks of a fake (including broken English), it might convince some technical novices that they&#039;d better get clicking. If they do click, what happens? They download &lt;a href=&quot;http://research.sunbelt-software.com/threatdisplay.aspx?name=IRC.Backdoor.Trojan&amp;amp;threatid=45277&quot;&gt;IRC.Backdoor.Trojan&lt;/a&gt;, an old threat that can still take over a system. It&#039;s disguised as &lt;b&gt;updateWindows.exe&lt;/b&gt;. You can learn more about how it works by reading PacketShack.org&#039;s &lt;a href=&quot;http://www.packetshack.org/index.php?page=fDDoS&quot;&gt;analysis&lt;/a&gt;. &lt;/p&gt;
&lt;h4&gt;Removing IRC.Backdoor.Trojan&lt;/h4&gt;
&lt;p&gt;
There are a large number of variants of this nasty bit of malware, as this &lt;a href=&quot;http://www.tek-tips.com/viewthread.cfm?qid=1431507&amp;amp;page=1&quot;&gt;Tek-Tips thread&lt;/a&gt; suggests. It also goes by &lt;a href=&quot;http://www.sunbelt-software.com/ihs/alex/vt21888123888.pdf&quot;&gt;many different names&lt;/a&gt; depending upon the antivirus vendor, including Win32.HackTool (eSafe), Backdoor.IRC.Zapchast (F-Secure and Kaspersky), Riskware.HideWindow.B (Webwasher-Gateway), and many others (link requries a PDF reader). Some antivirus programs may have difficulty removing it.
&lt;/p&gt;
&lt;p&gt;
If you&#039;re working on an infected computer and can&#039;t get rid of it, one Tek-Tips poster recommends using the free &lt;a href=&quot;http://support.f-secure.com/enu/home/ols.shtml&quot;&gt;F-Secure online scanner&lt;/a&gt;. You must use IE6 or IE7 with ActiveX enabled to use the F-Secure scanner, and it runs on Windows XP or 2000 (a beta version is available for Windows Vista users).
&lt;/p&gt;
&lt;h4&gt;What Not to Click &lt;/h4&gt;
&lt;p&gt;
Tired of fixing virus and malware infections? Remind your family, friends, co-workers (and anybody else who thinks you&#039;re a technology genius) of the rules for staying out of trouble online:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Don&#039;t &lt;/b&gt;click links purporting to come from PayPal, eBay, or your local bank or credit union&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Always &lt;/b&gt;log into Windows Update, e-commerce and similar sites manually&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Hover &lt;/b&gt;the mouse over links in an email or web page to find out where it will really take you&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Ignore&lt;/b&gt; logos and artwork when attempting to determine if an email or website is legit - they&#039;re easily stolen and reused&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
These can be summarized in one rule: &lt;a href=&quot;/article/safer_browsing&quot;&gt;Think before you click!&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/fake_microsoft_update_email_can_ruin_your_evening_stop_it_now#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/antimalware">antimalware</category>
 <category domain="http://www.maximumpc.com/geek_tested/antivirus">antivirus</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2759">fake email</category>
 <category domain="http://www.maximumpc.com/geek_tested/malware">malware</category>
 <category domain="http://www.maximumpc.com/geek_tested/news">news</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2760">sunbelt</category>
 <category domain="http://www.maximumpc.com/geek_tested/trojan_horse">Trojan Horse</category>
 <category domain="http://www.maximumpc.com/geek_tested/virus">virus</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/xss">XSS</category>
 <pubDate>Tue, 22 Jan 2008 21:25:52 -0600</pubDate>
 <dc:creator>Mark Soper</dc:creator>
 <guid isPermaLink="false">1821 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Storm Worm Strikes Again - and Blasts from the Past, Part 1</title>
 <link>http://www.maximumpc.com/article/storm_worm_strikes_again_and_blasts_from_the_past_part_1</link>
 <description>&lt;!--paging_filter--&gt;&lt;h4&gt;Storm Worm Prepares to Rings Out 2007...&lt;/h4&gt;
&lt;p&gt;UK&amp;#39;s &lt;strong&gt;the Register &lt;/strong&gt;website &lt;a href=&quot;http://www.theregister.co.uk/2007/12/27/storm_worm_seasonal_attacks/&quot;&gt;reports&lt;/a&gt; that the Storm Worm, which first surfaced in January 2007, has been making the rounds again, first with email messages sent out on December 24th containing links to scantily clad young women in Santa Claus suits, and since then with messages directing users to a malicious website called uhavepostcard.com.&lt;br /&gt;
&lt;h4&gt;...Just as It Rung In 2007&lt;/h4&gt;
&lt;p&gt;How bad is the Storm Worm? While the Storm Worm (so named because its &lt;a href=&quot;http://www.f-secure.com/f-secure/pressroom/news/fs_news_20070119_1_eng.html&quot;&gt;original version&lt;/a&gt; used the subject line &amp;#39;230 dead as storm batters Europe&amp;#39;), points users to various fake websites for various types of downloads, the malware is always some variant of the Small.DAM Trojan. Small.DAM installs the wincom32 service and turns the computer into a member of a botnet network that can send thousands of emails in a few minutes. The &lt;a href=&quot;http://en.wikipedia.org/wiki/Storm_Worm&quot;&gt;Wikipedia entry&lt;/a&gt; for Storm Worm contains plenty of references to its history and variants.&lt;br /&gt;
&lt;h4&gt;Calming the &amp;#39;Storm&amp;#39;&lt;/h4&gt;
&lt;p&gt;Stop the Storm Worm by using up-to-date antivirus and antimalware programs, and remind your less technically-adept friends and families that &lt;strong&gt;Santa Claus doesn&amp;#39;t encourage naughty behavior&lt;/strong&gt; and that &amp;#39;free&amp;#39; &lt;strong&gt;postcard messages from unfamiliar servers always have a high cost&lt;/strong&gt;.&lt;br /&gt;
&lt;h4&gt;My Favorite Blog Posts from 2007, Numbers 10-7&lt;/h4&gt;
&lt;p&gt;Here are my favorite &amp;#39;blasts from the past&amp;#39; from 2007: the blog posts that gathered lots of diggs and/or comments while shedding more light on difficult subjects. &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;10. &lt;a href=&quot;/article/vistas_user_account_control_nags_are_useful_believe_it_or_not&quot;&gt;Vista&amp;#39;s User Account Control &amp;#39;Nags&amp;#39; Are Useful – Believe It or Not&lt;/a&gt; This story from May 10 pointed out some of the hidden benefits of Vista&amp;#39;s User Account Control feature, garnering 8 diggs in the process. &lt;/li&gt;
&lt;li&gt;9. &lt;a href=&quot;/article/microsoft_patch_tuesday_knocks_out_skype_what_can_we_learn_from_this&quot;&gt;Microsoft Patch Tuesday Knocks Out Skype - What Can We Learn From This?&lt;/a&gt; With millions of users (not to mention Maximum PC&amp;#39;s podcast) affected by VoIP provider Skype&amp;#39;s outage in August, there were plenty of users asking &amp;quot;what happened?&amp;quot; As a result of the comments on this story, I dug deeper, resulting in my next nominee: &lt;/li&gt;
&lt;li&gt;8. &lt;a href=&quot;/article/skype_to_users_microsoft_good_my_bad_we_fixed_all_better_now&quot;&gt;Skype to Users: Microsoft Good, My Bad, We Fixed, All Better Now&lt;/a&gt; My investigation of exactly how Skype works (it combines peer-to-peer and distributed network features) also garnered a lot of comments and concerns from readers. &lt;/li&gt;
&lt;li&gt;7. &lt;a href=&quot;/article/use_a_sony_usb_fingerprint_reader_and_thumbdrive_get_a_rootkit_free&quot;&gt;Use a Sony USB Fingerprint Reader and Thumbdrive, Get a Rootkit Free!&lt;/a&gt; I wasn&amp;#39;t the only one who was shocked to see that Sony was up to its old tricks again with this story from August. It gathered 5 diggs as well as a bunch of comments from readers. See page 2 to read my proposed &lt;a href=&quot;/article/use_a_sony_usb_fingerprint_reader_and_thumbdrive_get_a_rootkit_free?page=0%2C1&quot;&gt;&amp;quot;Bill of Rootkit Rights,&amp;quot;&lt;/a&gt; designed to promote transparency and honesty about rootkits. With some versions of the Storm Worm using rootkit techniques to hide themselves, it may be time to review this story again. Next time, numbers 6-4. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;--------------------------------------------------------- &lt;/p&gt;
&lt;p&gt;Gift card burning a hole in your pocket? From digital photography to home networking, from Windows Vista to Windows XP, and other subjects, Mark&amp;#39;s written outstanding books that make you smarter about technology - and make you smile in the process. Mark&amp;#39;s books are available from &lt;a href=&quot;http://www.amazon.com/s/ref=nb_ss_gw/105-0148866-3158872?url=search-alias%3Dstripbooks&amp;amp;field-keywords=Mark+Edward+Soper&quot;&gt;Amazon.com&lt;/a&gt;, &lt;a href=&quot;http://search.barnesandnoble.com/booksearch/results.asp?WRD=Mark+Edward+Soper&amp;amp;z=y&quot;&gt;Barnes &amp;amp; Noble&lt;/a&gt;, &lt;a href=&quot;http://www.booksamillion.com/ncom/books?id=3988139117645&amp;amp;type=author&amp;amp;find=mark+Edward+Soper&quot;&gt;Books-a-Million&lt;/a&gt;, &lt;a href=&quot;http://www.amazon.com/s/ref=nb_ss_bgi/102-5615647-0519300?url=search-alias%3Dstripbooks&amp;amp;field-keywords=Mark+Edward+Soper&quot;&gt;Borders&lt;/a&gt;, &lt;a href=&quot;http://www.target.com/gp/search/602-6031497-7675038?field-keywords=Mark+Edward+Soper&amp;amp;url=index%3Dbooks-ta&amp;amp;ref=sr_bx_1_16&quot;&gt;Target&lt;/a&gt;, &lt;a href=&quot;http://www.powells.com/s3?kw=&amp;amp;title=&amp;amp;author=Mark+Edward+Soper&amp;amp;publisher=&amp;amp;section=&amp;amp;class=0&amp;amp;binding=0&amp;amp;sort=by_relevance&amp;amp;location=0&amp;amp;received_date=0&amp;amp;perpage=25&quot;&gt;Powells&lt;/a&gt; and other fine stores everywhere. &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/storm_worm_strikes_again_and_blasts_from_the_past_part_1#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/antimalware">antimalware</category>
 <category domain="http://www.maximumpc.com/geek_tested/antivirus">antivirus</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/storm_worm">storm worm</category>
 <category domain="http://www.maximumpc.com/geek_tested/worm">worm</category>
 <pubDate>Thu, 27 Dec 2007 22:17:27 -0600</pubDate>
 <dc:creator>Mark &amp;amp;#39;Marcus Soperus&amp;amp;#39; Soper</dc:creator>
 <guid isPermaLink="false">1727 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
