<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Nerds On Site Blog &#124; Business Technology Partners &#124; IT Support &#187; USB Virus</title>
	<atom:link href="http://www.nerdsonsite.com/blog/tag/usb-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nerdsonsite.com/blog</link>
	<description>Nerds On Site - Local Nerds... Powered by a Global TEAM</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:11:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Nerds On Site Client Podcast. We interview Nerds On Site SME clients about what they do and how they make sure of technology to increase their business productivity!</itunes:summary>
	<itunes:author>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile.jpg" />
	<itunes:owner>
		<itunes:name>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:name>
		<itunes:email>nerdcast@nerdsonsite.com</itunes:email>
	</itunes:owner>
	<managingEditor>nerdcast@nerdsonsite.com (Nerds On Site Blog | Business Technology Partners | IT Support)</managingEditor>
	<copyright>Copyright 2009 Nerds On Site Inc.</copyright>
	<itunes:subtitle>Nerds On Site - Local Nerds... Powered by a Global TEAM</itunes:subtitle>
	<itunes:keywords>nerds on site, nerds, nerd, podcast, client</itunes:keywords>
	<image>
		<title>Nerds On Site Blog | Business Technology Partners | IT Support &#187; USB Virus</title>
		<url>http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile_128.jpg</url>
		<link>http://www.nerdsonsite.com/blog</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
		<item>
		<title>New Windows Worm Will Spread Via USB Drives</title>
		<link>http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 15:45:25 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[USB Virus]]></category>
		<category><![CDATA[windows worm]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5171</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/' addthis:title='New Windows Worm Will Spread Via USB Drives '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>There is a new Window attack against Windows that exploits a vulnerability Windows .lnk files (all those shortcuts on the desktop, in the start menu, and elsewhere are .lnk (link) files). Currently, this attack is being spread via USB drives, and is not a network attack. In theory, though, it could also be spead via [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/' addthis:title='New Windows Worm Will Spread Via USB Drives ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/' addthis:title='New Windows Worm Will Spread Via USB Drives '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F07%2F20%2Fnew-windows-worm-will-spread-via-usb-drives%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F07%2F20%2Fnew-windows-worm-will-spread-via-usb-drives%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/07/virus.bmp" rel="shadowbox[sbpost-5171];player=img;" title="virus" rel="lightbox[5171]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/07/virus.bmp" alt="" title="virus" width="120" height="120" class="alignright size-full wp-image-5173" /></a><br />
There is a new Window attack against Windows that exploits a vulnerability Windows .lnk files (all those shortcuts on the desktop, in the start menu, and elsewhere are .lnk (link) files). Currently, this attack is being spread via USB drives, and is not a network attack. In theory, though, it could also be spead via network shares or WebDAV. All versions of Windows are vulnerable, including fully patched versions of Windows 7 and Server 2008.</p>
<p>Current versions of the attack utilize a rootkit to hide the malicious files on both the USB drive and on infections machines. Simply inserting an infected USB drive into a Windows computer ahd viewing its contents is generally all it takes to spread the infection. Any other USB drive that is inserted will also be infected. Initial samples of this &#8220;worm&#8221; (so classified because it can spread without any specific user action) are targeted attacks &#8211; looking specifically for software that is used to manage large distributed systems, such as power plants and manufacturing facilities. Broader attacks are almost sure to follow.</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/07/newtech.jpg" rel="shadowbox[sbpost-5171];player=img;" title="newtech" rel="lightbox[5171]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/07/newtech-150x150.jpg" alt="" title="newtech" width="120" height="120" class="alignleft size-thumbnail wp-image-5177" /></a>USB &#8220;drives&#8221; (which can incude other devices, such as smart phones, which incorporate solid state drives) are an increasingly dangerous vector for the spread of malware. &#8220;Thumb drives&#8221; or &#8220;USB sticks&#8221; have become a cheap, compact, and easy means of moving large amounts of data between computers. Smart phones are becoming ubiquitous and are commonly plugged into multiple computers to sync email, contact lists, and calendars.</p>
<p>One of the drivers that the rootkit installs is as signed driver &#8211; signed by Realtek Semiconductor Corp., a legitimate company. This is a good example of why it is so important to protect certificate private keys. Verisign has since revoked the compromised certificate. AV vendors are also scrambling to add this to the list of threats their products will detect.</p>
<p>We will have to wait to see how widespread the attacks which exploit this vulnerability become. Microsoft has not released any date for a fix. There are workarounds, but some of them will preclude the use of Sharepoint, a service upon which many organizations depend. The best solution is to implement some form of endpoint security. Endpoint security is used to lock down USB and other devices by limiting their ability to write files. Endpoint security can also limiting what can be written to external devices as part of a Datat Loss Prevention program.</p>
<p>One additional note &#8211; any systems running on Windows 2000 or Window XP without SP3 will NOT receive updates to patch this flaw &#8211; ever. Microsoft has officially ended support for those operating system.</p>
<p>Want to read more?<a title="krebsonsecurity.com" href="http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/" target="_blank"><br />
</a><a title="krebsonsecurity.com" href="http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/  " target="_blank">krebsonsecurity.com</a><br />
<a title="computerworld.com" href="http://www.computerworld.com/s/article/9179299/Microsoft_confirms_nasty_Windows_zero_day_bug?taxonomyId=17&amp;pageNumber=1" target="_blank">www.computerworld.com</a></p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>July 20, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/' addthis:title='New Windows Worm Will Spread Via USB Drives ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/07/20/new-windows-worm-will-spread-via-usb-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

