<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC sunbelt RSS Feed</title>
 <link>http://www.maximumpc.com/tags/sunbelt</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Fake Microsoft Update Email Can Ruin Your Evening - Stop It Now!</title>
 <link>http://www.maximumpc.com/article/fake_microsoft_update_email_can_ruin_your_evening_stop_it_now</link>
 <description>&lt;!--paging_filter--&gt;&lt;h4&gt;Heed This &amp;quot;Warning&amp;quot; - And You&#039;ll Be Sorry&lt;/h4&gt;
&lt;p&gt;Security vendor Sunbelt Software&#039;s blog reports that a fake warning to &amp;quot;update your P.C. in maximum 12 hours otherwise your Windows will be Expired&amp;quot; is making the email rounds. While the message (visible &lt;a href=&quot;http://sunbeltblog.blogspot.com/2008/01/fake-ms-update.html&quot;&gt;here&lt;/a&gt;) has all of the earmarks of a fake (including broken English), it might convince some technical novices that they&#039;d better get clicking. If they do click, what happens? They download &lt;a href=&quot;http://research.sunbelt-software.com/threatdisplay.aspx?name=IRC.Backdoor.Trojan&amp;amp;threatid=45277&quot;&gt;IRC.Backdoor.Trojan&lt;/a&gt;, an old threat that can still take over a system. It&#039;s disguised as &lt;b&gt;updateWindows.exe&lt;/b&gt;. You can learn more about how it works by reading PacketShack.org&#039;s &lt;a href=&quot;http://www.packetshack.org/index.php?page=fDDoS&quot;&gt;analysis&lt;/a&gt;. &lt;/p&gt;
&lt;h4&gt;Removing IRC.Backdoor.Trojan&lt;/h4&gt;
&lt;p&gt;
There are a large number of variants of this nasty bit of malware, as this &lt;a href=&quot;http://www.tek-tips.com/viewthread.cfm?qid=1431507&amp;amp;page=1&quot;&gt;Tek-Tips thread&lt;/a&gt; suggests. It also goes by &lt;a href=&quot;http://www.sunbelt-software.com/ihs/alex/vt21888123888.pdf&quot;&gt;many different names&lt;/a&gt; depending upon the antivirus vendor, including Win32.HackTool (eSafe), Backdoor.IRC.Zapchast (F-Secure and Kaspersky), Riskware.HideWindow.B (Webwasher-Gateway), and many others (link requries a PDF reader). Some antivirus programs may have difficulty removing it.
&lt;/p&gt;
&lt;p&gt;
If you&#039;re working on an infected computer and can&#039;t get rid of it, one Tek-Tips poster recommends using the free &lt;a href=&quot;http://support.f-secure.com/enu/home/ols.shtml&quot;&gt;F-Secure online scanner&lt;/a&gt;. You must use IE6 or IE7 with ActiveX enabled to use the F-Secure scanner, and it runs on Windows XP or 2000 (a beta version is available for Windows Vista users).
&lt;/p&gt;
&lt;h4&gt;What Not to Click &lt;/h4&gt;
&lt;p&gt;
Tired of fixing virus and malware infections? Remind your family, friends, co-workers (and anybody else who thinks you&#039;re a technology genius) of the rules for staying out of trouble online:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Don&#039;t &lt;/b&gt;click links purporting to come from PayPal, eBay, or your local bank or credit union&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Always &lt;/b&gt;log into Windows Update, e-commerce and similar sites manually&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Hover &lt;/b&gt;the mouse over links in an email or web page to find out where it will really take you&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Ignore&lt;/b&gt; logos and artwork when attempting to determine if an email or website is legit - they&#039;re easily stolen and reused&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
These can be summarized in one rule: &lt;a href=&quot;/article/safer_browsing&quot;&gt;Think before you click!&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/fake_microsoft_update_email_can_ruin_your_evening_stop_it_now#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/antimalware">antimalware</category>
 <category domain="http://www.maximumpc.com/geek_tested/antivirus">antivirus</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2759">fake email</category>
 <category domain="http://www.maximumpc.com/geek_tested/malware">malware</category>
 <category domain="http://www.maximumpc.com/geek_tested/news">news</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2760">sunbelt</category>
 <category domain="http://www.maximumpc.com/geek_tested/trojan_horse">Trojan Horse</category>
 <category domain="http://www.maximumpc.com/geek_tested/virus">virus</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/xss">XSS</category>
 <pubDate>Tue, 22 Jan 2008 21:25:52 -0600</pubDate>
 <dc:creator>Mark Soper</dc:creator>
 <guid isPermaLink="false">1821 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
