<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CM Technologies</title>
	<atom:link href="http://www.cmsecuretech.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cmsecuretech.com</link>
	<description></description>
	<lastBuildDate>Fri, 11 May 2012 13:14:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Countdown to July 9 &#8220;Internet Doomsday&#8221;: Is your network safe?</title>
		<link>http://www.cmsecuretech.com/2012/05/02/countdown-to-july-9-internet-doomsday-is-your-network-safe/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=countdown-to-july-9-internet-doomsday-is-your-network-safe</link>
		<comments>http://www.cmsecuretech.com/2012/05/02/countdown-to-july-9-internet-doomsday-is-your-network-safe/#comments</comments>
		<pubDate>Wed, 02 May 2012 12:30:43 +0000</pubDate>
		<dc:creator>pozole</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Hijack]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.cmsecuretech.com/?p=295</guid>
		<description><![CDATA[In late 2011, an international law enforcement task force disabled one of the largest botnets ever seen(1). This botnet was [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cmsecuretech.com/wp-content/uploads/2012/05/earth_impact.jpg" rel="lightbox[post-295]" title=""><img class="size-medium wp-image-301 alignright" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 0px;" title="earth_impact" src="http://www.cmsecuretech.com/wp-content/uploads/2012/05/earth_impact-217x300.jpg" alt="" width="217" height="300" /></a></p>
<p><strong>In late 2011, an international law enforcement task force disabled one of the largest botnets ever seen(1). This botnet was facilitated by a DNS Changer Malware(2), known under various names such as TDSS, TDL4, Alureon, and others.</strong></p>
<p>This malware changes the user’s DNS server settings to replace the ISP’s good DNS servers with rogue DNS servers operated by the cybercriminals in order to facilitate spamming and further malware infections of the victim’s computer.</p>
<p>The rogue DNS servers have been replaced by clean DNS servers, but after July 9 these servers will be taken offline, meaning that computers that are still infected with TDSS will lose access to the internet. Up to 350,000 computers are estimated to be affected in this manner.</p>
<h3>How to check for infection</h3>
<p>The FBI is recommending that users seek help from IT professionals, among other sources. If you would like to perform checks for yourself or your clients, a variety of “are you infected?” web sites have been enabled. A list of international sites is found here:<br />
<a href="http://www.dcwg.org/detect/" target="_blank">http://www.dcwg.org/detect/</a></p>
<h3>How to fix infected computers</h3>
<p>If a computer is found to be infected, there are a variety of free tools that will specifically deal with this threat. A listing of these tools can be found here:<br />
<a href="http://www.dcwg.org/fix/" target="_blank">http://www.dcwg.org/fix/</a></p>
<p>If you require free assistance in checking and disinfecting multiple machines on a network, please contact us immediately at: virus at cmsecuretech dot com.</p>
<h3>Network Malware Reporter Beta</h3>
<p>We are beta testing a network malware analysis tool, which creates reports that can help you automatically verify that an entire network is clean using 4 of today’s top antimalware engines. If you would like to participate in the beta test, please contact us at virus at cmsecuretech dot com.</p>
<p><span style="text-decoration: underline;"><strong>Sources:</strong></span></p>
<p>1.Esthost Taken Down – Biggest Cybercriminal Takedown in History |<br />
<a href="http://blog.trendmicro.com/esthost-taken-down-biggest-cybercriminal-takedown-in-history/" target="_blank">http://blog.trendmicro.com/<wbr>esthost-taken-down-biggest-<wbr>cybercriminal-takedown-in-<wbr>history/</wbr></wbr></wbr></a></p>
<p>2. FBI Report: DNS Changer Malware (Adobe Acrobat) |<br />
<a href="http://www.fbi.gov/DNS-changer-malware.pdf" target="_blank">http://www.fbi.gov/DNS-<wbr>changer-malware.pdf</wbr></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cmsecuretech.com/2012/05/02/countdown-to-july-9-internet-doomsday-is-your-network-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Removal Simplified with HitmanPro</title>
		<link>http://www.cmsecuretech.com/2012/03/27/malware-removal-simplified-with-hitmanpro/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malware-removal-simplified-with-hitmanpro</link>
		<comments>http://www.cmsecuretech.com/2012/03/27/malware-removal-simplified-with-hitmanpro/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 11:00:23 +0000</pubDate>
		<dc:creator>Carlos Zevallos</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[antivirus cloud]]></category>
		<category><![CDATA[Antivirus Free]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[zeus]]></category>
		<category><![CDATA[Cloud Detection]]></category>
		<category><![CDATA[HitmanPro]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.cmsecuretech.com/?p=211</guid>
		<description><![CDATA[ If you service small or medium business customers, sooner or later you get the call:  The company owner or a [...]]]></description>
			<content:encoded><![CDATA[<p><strong> If you service small or medium business customers, sooner or later you get the call:  The company owner or a salesman comes back from an extended trip with a laptop rendered unusable by a stubborn rootkit infection. None of the usual quick techniques such as booting into safe mode or using removal tools seem to help, and the client is unwilling to reformat the computer.</strong></p>
<blockquote><p>The most common type of infection can include a trojan downloader and connection to a command and control server, which eventually will drop the most telltale sign of infection: <a href="http://www.microsoft.com/security/pc-security/antivirus-rogue.aspx">scareware</a>.  One <a href="http://www.econ.ucsb.edu/~doug/researchpapers/Underground%20Economy%20of%20Fake%20AV%20Software.pdf">source </a> estimates that <strong>scareware nets upwards of $130 million dollars a year by tricking PC  users into paying for a fake antivirus solution to remove the virus that it itself has caused.</strong>  These can be difficult to remove, as they include updater and watchdog services that prevent them from being disabled.  Add a <a href="http://www.webopedia.com/TERM/R/rootkit.html">rootkit </a>component and possibly an <a href="http://www.symantec.com/connect/blogs/are-mbr-infections-back-fashion-infographic">MBR infection</a> and you have your work cut out for you.</p></blockquote>
<p>Today is the first part of a series designed to help the SMB Consultants deal with the increasingly complex malware threat effectively and highlight new tools and techniques in the process.</p>
<p>When it is difficult to get direct access to kill malware processes, one tool that we keep in our toolbox is <a href="http://www.surfright.nl/en">HitmanPro</a>, by Surfright. One of the reasons for this is because it can run in “Force Breach” mode, which comes in handy when malware has subverted the explorer shell and prevents you from turning it off.</p>
<p>If you are not familiar with HitmanPro, it’s a powerful anti-malware tool that uses the detection and removal technologies of several commercial AV vendors on an on-demand basis.  It will remove malware for free for 30 days once installed, and is perfect for those malware cleanup emergencies. This tool has many interesting features, but today we are going to focus on force breach mode.</p>
<p><strong> Download (Amazon S3)</strong></p>
<div>
<div>32 Bit Windows</div>
<div>
<p><a href="https://s3.amazonaws.com/Softwaredownload/Surfright/HitmanPro36.exe">https://s3.amazonaws.com/Softwaredownload/Surfright/HitmanPro36.exe</a></p>
<p>64 Bit Windows</p>
<p><a href="https://s3.amazonaws.com/Softwaredownload/Surfright/HitmanPro36_x64.exe">https://s3.amazonaws.com/Softwaredownload/Surfright/HitmanPro36_x64.exe</a></p>
</div>
</div>
<div></div>
<p><a href="http://www.cmsecuretech.com/wp-content/uploads/2012/03/2.-FORCE-BREACH2-e1332455188252.png" rel="lightbox"><img class="alignnone size-medium wp-image-222" title="FORCE BREACH" src="http://www.cmsecuretech.com/wp-content/uploads/2012/03/2.-FORCE-BREACH2-300x168.png" alt="" width="300" height="168" /></a></p>
<p>1. After downloading copying Hitman Pro to the infected computer, simply hold down the left CTRL key while launching Hitman Pro.  Once the splash screen appears, you can let go of the CTRL key.  You may notice the windows system tray may disappear, this is because it kills all non-essential processes when it enters force breach mode.</p>
<p>&nbsp;</p>
<p><a href="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_05-Mar.-26-20.55.png" rel="lightbox[post-211]" title=""><img class="alignnone size-medium wp-image-232" title="HMP 3.6 Splash Screen" src="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_05-Mar.-26-20.55-300x237.png" alt="" width="300" height="237" /></a></p>
<p>2. Once the splash screen comes up, you will  have the option to start up Hitman Pro in several modes, including something the makers call “Early Warning Scoring” mode (We’ll cover this in a future newsletter). For now, try the default scan. and click ‘Next’</p>
<p>&nbsp;</p>
<p><a href="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_06-Mar.-26-20.55.png" rel="lightbox[post-211]" title=""><img class="alignnone size-medium wp-image-233" title="Scanning" src="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_06-Mar.-26-20.55-300x237.png" alt="" width="300" height="237" /></a></p>
<p>3. Hitman will connect to the cloud and perform its tasks.  If malware has subverted DNS, Hitman will test for this and automatically get around this problem. Once items have been detected, you can activate Hitman Pro free for 30 days and remove the infection.  We have double checked with Surfright and they confirmed that using Hitman for a 3rd party is permitted under their licensing terms.</p>
<p>&nbsp;</p>
<p><a href="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_07-Mar.-26-20.55.png" rel="lightbox[post-211]" title=""><img class="alignnone size-medium wp-image-235" title="Detected" src="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_07-Mar.-26-20.55-300x237.png" alt="" width="300" height="237" /></a>   <a href="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_11-Mar.-26-20.58.png" rel="lightbox[post-211]" title=""><img class="alignnone size-medium wp-image-254" title="Disinfected" src="http://www.cmsecuretech.com/wp-content/uploads/2012/03/ScreenHunter_11-Mar.-26-20.58-300x237.png" alt="" width="300" height="237" /></a></p>
<p>4. Hitman will perform malware removal and cleanup.  Depending on the infection, you might have to restart the computer.  If there are remnants of the infection left, it should be much easier to handle with traditional antivirus tools and techniques at this point.</p>
<p>&nbsp;</p>
<p>Below is a video that shows the entire process (Previous version 3.5)</p>
<p>
<object width="425" height="344">
<param name="movie" value="http://www.youtube.com/v/m6eRWTv2STk?version=3&amp;theme=dark&amp;fs=0&amp;cc_load_policy=1&amp;iv_load_policy=1&amp;modestbranding=0"></param>
<param name="allowScriptAccess" value="always"></param>
<embed src="http://www.youtube.com/v/m6eRWTv2STk?version=3&amp;theme=dark&amp;fs=0&amp;cc_load_policy=1&amp;iv_load_policy=1&amp;modestbranding=0" type="application/x-shockwave-flash" allowScriptAccess="always" width="425" height="344"></embed>
</object>
</p>
<p>&nbsp;</p>
<hr />

<p>If you have any questions regarding HitmanPro or want to request a free NFR license (Consultants only) please send us a message.</p>
<!-- Fast Secure Contact Form plugin 3.1.5.4 - begin - FastSecureContactForm.com -->
<div id="FSContact2" style="width:375px;">
<form action="http://www.cmsecuretech.com/feed/#FSContact2" id="si_contact_form2" method="post">
<div style="text-align:left;">
<span class="required"> *</span>(denotes required field)
   </div>

         <div>
               <input type="hidden" name="si_contact_CID" value="1" />
        </div>

        <div style="text-align:left; padding-top:5px;">
                <label for="si_contact_name2">Name:<span class="required"> *</span></label>
        </div>
        <div style="text-align:left;">
                <input style="text-align:left; margin:0;" type="text" id="si_contact_name2" name="si_contact_name" value=""  size="40" />
        </div>

        <div style="text-align:left; padding-top:5px;">
                <label for="si_contact_email2">E-Mail Address:<span class="required"> *</span></label>
        </div>
        <div style="text-align:left;">
                <input style="text-align:left; margin:0;" type="email" id="si_contact_email2" name="si_contact_email" value=""  size="40" />
        </div>

        <div style="text-align:left; padding-top:5px;">
                <label for="si_contact_ex_field2_1">Company<span class="required"> *</span></label>
        </div>
        <div style="text-align:left;">
                <input style="text-align:left; margin:0;" type="text" id="si_contact_ex_field2_1" name="si_contact_ex_field1" value=""  size="40" />
        </div>

        <div style="text-align:left; padding-top:5px;">
                <label for="si_contact_message2">Message:<span class="required"> *</span></label>
        </div>
        <div style="text-align:left;">
                <textarea style="text-align:left; margin:0;" id="si_contact_message2" name="si_contact_message"  cols="30" rows="10"></textarea>
        </div>

<div style="text-align:left; padding-top:5px;"> </div>
 <div style="width:250px; height:65px; padding-top:2px;">
    <img class="ctf-captcha" id="si_image_ctf2" style="border-style:none; margin:0; padding:0px; padding-right:5px; float:left;" src="http://www.cmsecuretech.com/wp-content/plugins/si-contact-form/captcha/securimage_show.php?prefix=ml6OoTviTOgrEuqD" width="175" height="60" alt="CAPTCHA Image" title="CAPTCHA Image" />
    <input id="si_code_ctf_2" type="hidden" name="si_code_ctf_2" value="ml6OoTviTOgrEuqD" />
    <div id="si_refresh_ctf2">
      <a href="#" rel="nofollow" title="Refresh Image" onclick="si_contact_captcha_refresh('2','noaudio','/wp-content/plugins/si-contact-form/captcha','http://www.cmsecuretech.com/wp-content/plugins/si-contact-form/captcha/securimage_show.php?prefix='); return false;">
      <img src="http://www.cmsecuretech.com/wp-content/plugins/si-contact-form/captcha/images/refresh.png" width="22" height="20" alt="Refresh Image" style="border-style:none; margin:0; padding:0px; vertical-align:bottom;" onclick="this.blur();" /></a>
   </div>
   </div>

      <div style="text-align:left; padding-top:5px;">
                <label for="si_contact_captcha_code2">CAPTCHA Code:<span class="required"> *</span></label>
        </div>
        <div style="text-align:left;">
                <input style="text-align:left; margin:0; width:50px;" type="text" value="" id="si_contact_captcha_code2" name="si_contact_captcha_code"  size="6" />
       </div>


<div style="text-align:left; padding-top:2px;">
  <input type="hidden" name="si_contact_action" value="send" />
  <input type="hidden" name="si_contact_form_id" value="2" />
  <input type="submit" id="fsc-submit-2" style="cursor:pointer; margin:0;" value="Submit" /> <input type="reset" id="fsc-reset-2" style="cursor:pointer; margin:0;" value="Reset" onclick="return confirm('Do you really want to reset the form?')"  />

</div>

</form>
</div>
<!-- Fast Secure Contact Form plugin 3.1.5.4 - end - FastSecureContactForm.com -->
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cmsecuretech.com/2012/03/27/malware-removal-simplified-with-hitmanpro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flaw in IE Can Compromise Your Computer</title>
		<link>http://www.cmsecuretech.com/2010/01/06/flaw-in-ie-can-compromise-your-compute/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=flaw-in-ie-can-compromise-your-compute</link>
		<comments>http://www.cmsecuretech.com/2010/01/06/flaw-in-ie-can-compromise-your-compute/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 02:33:57 +0000</pubDate>
		<dc:creator>meleyjian</dc:creator>
		
		<guid isPermaLink="false">http://www.cmsecuretech.com/?p=44</guid>
		<description><![CDATA[It is early in the new year and Microsoft has taken some serious hits in their public image. Just when [...]]]></description>
			<content:encoded><![CDATA[<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.571em; margin-left: 0px; padding: 0px;">It is early in the new year and Microsoft has taken some serious hits in their public image.</p>
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.571em; margin-left: 0px; padding: 0px;">Just when they released, probably their <a style="text-decoration: underline; color: #2361a1; padding: 0px; margin: 0px;" title="is Windows 7 a security success?" href="http://www.security-faqs.com/windows-7-has-improved-security-features-built-in.html">most secured operating system ever</a>, we now see that there are more holes in the Microsoft family that we have to worry about.</p>
<h2 style="margin-top: 1.833em; margin-right: 0px; margin-bottom: 0.611em; margin-left: 0px; font-weight: bold; color: #111111; font-size: 1.286em; line-height: 1.222em; padding: 0px;">More Problems With Internet Explorer</h2>
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.571em; margin-left: 0px; padding: 0px;">A couple of months ago, there was a flaw found in the Internet Explorer family of browsers. It affected all versions. Microsoft released a fix and all was thought to be well in the world. But it turns out this is not true. There has been another major flaw found when it comes to the <a style="text-decoration: underline; color: #2361a1; padding: 0px; margin: 0px;" title="problems always seem to follow IE" href="http://www.security-faqs.com/phasing-out-internet-explorer-6-is-the-first-step-towards-closing-a-big-security-hole.html">Internet Explorer</a> browser.</p>
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.571em; margin-left: 0px; padding: 0px;">
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.571em; margin-left: 0px; padding: 0px;">Read the full article <a href="http://www.security-faqs.com/flaw-in-internet-explorer-can-turn-your-computer-into-a-file-server-without-your-knowledge.html">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cmsecuretech.com/2010/01/06/flaw-in-ie-can-compromise-your-compute/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Street View Car Tracked by GPS</title>
		<link>http://www.cmsecuretech.com/2010/01/05/google-street-view-car-tracked-by-gps/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-street-view-car-tracked-by-gps</link>
		<comments>http://www.cmsecuretech.com/2010/01/05/google-street-view-car-tracked-by-gps/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 19:27:27 +0000</pubDate>
		<dc:creator>meleyjian</dc:creator>
		
		<guid isPermaLink="false">http://www.cmsecuretech.com/?p=32</guid>
		<description><![CDATA[Sticking a GPS track on the Street View car is the way to find out where it is&#8230; Want to [...]]]></description>
			<content:encoded><![CDATA[<p>Sticking a GPS track on the Street View car is the way to find out where it is&#8230;</p>
<p>Want to know where the Google Street View car is? In the UK, there was a collaborative effort to <a style="border-collapse: collapse; color: #005689; text-decoration: underline; background-repeat: no-repeat no-repeat; padding: 0px; margin: 0px;" href="http://www.guardian.co.uk/media/pda/2008/jul/21/thegooglestreetviewcarspo">track it through pictures and crowdsourced maps</a>when it was over here collecting the pictures for Google Nostalgia (ah, those days when Woolworths was open).</p>
<p>Full article is <a href="http://www.guardian.co.uk/technology/blog/2010/feb/08/google-street-view-car-gps-tracking-germany">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cmsecuretech.com/2010/01/05/google-street-view-car-tracked-by-gps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China Shuts Down Hacker Training Web Site</title>
		<link>http://www.cmsecuretech.com/2010/01/05/china-shuts-down-hacker-training-web-site/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=china-shuts-down-hacker-training-web-site</link>
		<comments>http://www.cmsecuretech.com/2010/01/05/china-shuts-down-hacker-training-web-site/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 17:30:31 +0000</pubDate>
		<dc:creator>meleyjian</dc:creator>
		
		<guid isPermaLink="false">http://www.cmsecuretech.com/?p=27</guid>
		<description><![CDATA[China has closed what it claims to be the largest hacker training website in the country and arrested three of its [...]]]></description>
			<content:encoded><![CDATA[<p><a style="text-decoration: underline; color: #003bb0; cursor: pointer;" title="China" href="http://www.pcmag.com/topic/0,2944,t=China&amp;s=25306,00.asp">China</a> has closed what it claims to be the largest hacker <a style="text-decoration: underline !important; color: #006400 !important; font-weight: normal !important; font-size: 12px; border-bottom-color: #006400 !important; border-bottom-width: 0.075em !important; border-bottom-style: solid !important; padding-bottom: 1px !important; background-color: transparent !important;" href="http://www.pcmag.com/article2/0,2817,2358899,00.asp#" target="_blank">training</a> website in the country and arrested three of its members, domestic media reported on Monday.</p>
<p>The &#8220;Black Hawk Safety Net&#8221; website taught hacking techniques and provided <a style="text-decoration: underline !important; color: #006400 !important; font-weight: normal !important; font-size: 12px; border-bottom-color: #006400 !important; border-bottom-width: 0.075em !important; border-bottom-style: solid !important; padding-bottom: 1px !important; background-color: transparent !important;" href="http://www.pcmag.com/article2/0,2817,2358899,00.asp#" target="_blank">malicious software</a> downloads for its 12,000 members in exchange for a fee, the Wuhan Evening News newspaper reported this weekend, citing police in Huanggang, just east of Wuhan.</p>
<p>Read the full article <a href="tp://www.pcmag.com/article2/0,2817,2358899,00.asp">here</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cmsecuretech.com/2010/01/05/china-shuts-down-hacker-training-web-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

