<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2601096556187183895</id><updated>2012-03-04T13:05:30.483+01:00</updated><category term='Ransomware backup security'/><title type='text'>LucBeirens</title><subtitle type='html'>Hoping to create a safer cyber space ... My very personal blog with my very personal opinion about matters that I'm interested in :
Cyber security, cybercrime, computer forensics, social media and much more... Texts likely to be in Dutch, English or French</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>13</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-8387793575121182940</id><published>2012-02-23T21:28:00.002+01:00</published><updated>2012-02-23T21:35:29.214+01:00</updated><title type='text'>Voulez-vous continuer à surfer sur internet après le 07 mars 2012 ?</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Merci à Stéphane Alloisio&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;@AlloisioS et Laurent Bounameau&amp;nbsp;@Bounameau_L pour la traduction !&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Prenez le temps de lire cet article et devérifier que vous n'êtes pas victime du malware "DNS-Changer !"&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Si vous ne le faites pas, vous pourriez rencontrer des problèmes avecdiverses applications internet à partir du 8 mars 2012.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Si vous n'avez pas envie de lire tout l'article, faites au moins le test de la configuration DNS de votre PC en visitant un des sites web de test :&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;le site &lt;a href="http://dns-ok.be/"&gt;&lt;span style="color: lime;"&gt;DNS-OK.be&lt;/span&gt;&lt;/a&gt; du Computer Emergency Response Team Belge (en Français / Néerlandais) ou&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;le site &lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;dns-changer.eu&lt;/span&gt;&lt;/a&gt; (en Allemand, Anglais, Danois et Espagnol)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Mais peut-être, il est mieux de continuer à lire ...&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Dans cet article, je vais essayer d'exposerde manière simple un certain nombre de principes du fonctionnement d'internetde sorte que tout le monde comprenne &lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;précisément le problème et la manière dont onpeut le résoudre. Tout à avoir avec DNS....&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Qu'est-ce qu'un DNS ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Un &lt;span style="color: lime;"&gt;D&lt;/span&gt;omain&lt;span style="color: lime;"&gt;N&lt;/span&gt;ame &lt;span style="color: lime;"&gt;S&lt;/span&gt;erviceserver peut être considéré comme un bottin (répertoire) des noms de domaine.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Un nom de domaine est un nom plus facile àretenir que la véritable adresse d'un serveur sur internet. &lt;br /&gt;Plus facile pour les gens, mais pas pour les ordinateurs!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Afin de pouvoir communiquer les uns avecles autres, chaque ordinateur sur Internet dispose d'une adresse IP (InternetProtocol address) unique. &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Lorsque vous entrez un nom de domaine (parex.: microsoft.com) dans votre navigateur internet, ce dernier va demander à unserveur DNS vers quelle adresse IP il doit être redirigé.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le serveur DNS va spécifier l'adresse IP relative au nom de domaine et ainsipermettre à votre navigateur d'établir la communication avec la page web quevous avez sollicité (ex: 207.46.232.182 pour microsoft.com).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Les mails ainsi que d'autres applicationsinternet utilisent également les services DNS.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Quel DNS j'utilise ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Heureusement, les utilisateurs finaux nedoivent en principe pas s'inquiéter du serveur DNS utilisé par leur PC.&lt;br /&gt;Dans la majorité des cas, l'adresse IP du serveur DNS est configuréeautomatiquement par le fournisseur d'accès internet (ISP) lorsl'installation/configuration du service internet.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Généralement, vous utilisez donc le serveurDNS de votre fournisseur d'accès internet.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Simple et sans souci.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-fNed3W7KSvs/T0abcKLrLPI/AAAAAAAAWJY/9onV1sY8UA0/s1600/DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-fNed3W7KSvs/T0abcKLrLPI/AAAAAAAAWJY/9onV1sY8UA0/s640/DNS+configuration+IPv4+markering.PNG" width="548" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Chez la plupart des fournisseurs d'accèsles paramètres DNS de votre connexion internet sont configurés comme ci-dessus.Néanmoins, même si ce n'est pas comme ça chez vous, cela ne signifie pas pourautant qu'il y a un problème.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;&lt;br clear="all" style="mso-special-character: line-break; page-break-before: always;" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Quel est donc le problème ? &lt;br /&gt;Le malware DNS-changer!&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;En tant qu'utilisateur, c'est en touteconfiance que vous pensez accéder au vrai site correspondant au nom de domaineque vous avez entré dans votre navigateur.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Pourtant il est régulier que lescybercriminels cherchent à rediriger les utilisateurs vers une fausse copie dusite web dans le but de s'emparer de leurs données d'accès (nom d'utilisateur,mot de passe,...).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Habituellement, les cybercriminelsutilisent la technique bien connue du "phishing" avec&amp;nbsp; un message spam contenant un lien vers lefaux site web. Heureusement, de moins en moins d'utilisateurs finaux tombentdans ce piège.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Suite à cette diminution, certainscybercriminels ont mis en place un système plus évolué pour amener lesutilisateurs vers de fausses copies de sites ou des sites de petites annonces .Il s'agit du botnet DNS-changer.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De diverses manières, ils infectent lesordinateurs des utilisateurs finaux avec un malware qui va en modifier lesparamètres, de sorte que ces ordinateurs ne s'adressent plus, pour obtenirl'adresse IP correspondant au nom de domaine, au serveur DNS du fournisseurd'accès, mais bien à un serveur DNS contrôlé par les cybercriminels.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le serveur DNS criminel fonctionne comme unserveur DNS normal, mis à part pour les noms de domaine pour lesquels lescybercriminels ont créé de fausses copies destinées à leurs manœuvresfrauduleuses envers les utilisateurs finaux. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Donc,&amp;nbsp;aussi longtemps que l'utilisateur infecté ne surfe pas sur une des fauxsites, il ne remarque pas qu'il utilise le serveur DNS entre les mains des criminelscar pour tout les autres noms de domaine, il &amp;nbsp;renvoie l'adresse IP correcte. En outre, dansla majorité des cas l'utilisateur ne se rend même pas compte qu'il surfe sur unfaux site.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RuMRtWhVcII/T0abbA_NJYI/AAAAAAAAWJU/T3YgXNczWzQ/s1600/Criminele+DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-RuMRtWhVcII/T0abbA_NJYI/AAAAAAAAWJU/T3YgXNczWzQ/s640/Criminele+DNS+configuration+IPv4+markering.PNG" width="548" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Si votre configuration désigne l'une adresseIP figurant dans la liste suivante comme serveur DNS, alors vous êtes victimedu malware DNS-changer&amp;nbsp;(le x pouvant être remplacé par n'importe quel chiffre entre 0 et 255).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;b&gt;64.28.176.x&lt;br /&gt;67.210.0.x&lt;br /&gt;77.67.83.x&lt;br /&gt;85.255.112.x&lt;br /&gt;93.188.160.x&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;&lt;br clear="all" style="mso-special-character: line-break; page-break-before: always;" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;Quelle est la taille du Botnet DNS-changer&lt;br /&gt;et que va-t-il se passer le 7 mars?&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Sur la période allant de 2009 au 9 novembre2011, les cybercriminels ont étendu leur botnet&amp;nbsp;DNS- changer, lequel compte environs 4 millions d'ordinateurs infectés répartisdans 100 pays différents et dont les paramètres DNS renvoient vers un serveurDNS criminel.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le 09 novembre 2011, le FBI, encollaboration avec la NASA et le Hightech Crime Team Hollandais, a arrêté 6cybercriminels estoniens. &amp;nbsp;Dans le mêmetemps, ils ont pris le contrôle des serveurs DNS criminels. &amp;nbsp;Ces serveurs DNS n'ont pas été mis horsservice immédiatement. Le FBI avec plusieurs entreprises de sécurité ontremplacé les serveurs DNS criminels par des serveurs DNS "propres"renvoyant pour chaque nom de domaine l'adresse IP correcte.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le FBI a déclaré qu'il maintiendrait cesserveurs DNS "propres" pour une période de 4 mois. Ces serveurs DNSdevraient donc, en principe, être mis hors service le 8 mars 2012.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="FR-BE"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Chaqueordinateur qui, à ce moment là, utiliserait encore un de ces serveurs DNS, ne recevraplus aucun service DNS. &amp;nbsp;Les applicationsinternet utilisant des noms de domaines ne fonctionneront donc plus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Environs 500.000 ordinateurs infectés setrouvent aux USA. Cela veut dire que 3,5 millions se trouvent à l'extérieur desUSA et doivent donc être adaptés à la date d'échéance pour continuer àfonctionner !&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;En Allemagne, il semble actuellement que 33.000ordinateurs soient infectés. Il n'y a aucune évaluation du nombre d'ordinateursinfectés en Belgique.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;Vous pouvez lire les rapports du FBI sur lelien suivant:&lt;br /&gt;&lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf"&gt;&lt;span lang="NL-BE"&gt;&lt;span style="color: lime;"&gt;http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang="FR-BE" style="color: #0070c0;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Comment tester les paramètres de son PC etsavoir si il a été infecté par le malware DNS-changer?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Peut-être êtes-vous parmi les 3,5 millionsd'autres...&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Pour tester votre PC concernant DNS-changer, le&amp;nbsp; CERT.be (Computer EmergencyResponse Team) a mis en ligne un site de test.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Tester maintenant votre ordinateur sur : &lt;/span&gt;&lt;a href="http://dns-ok.be/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span lang="NL-BE"&gt;&lt;span style="color: lime;"&gt;http://dns-ok.be/&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;Le Anti-Botnet Advisory Center allemand aégalement mis en ligne le site web suivant: &lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;http://dns-changer.eu/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;.&lt;/span&gt;&lt;span lang="FR-BE"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Si votre ordinateurest effectivement infecté par le malware DNS-changer, il y a alors de forteschances que d'autres malwares (programmes malveillants) soient installés surcelui-ci.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Faites alors un scan complet de votreordinateur avec un logiciel antivirus à jour.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;Vous pouvez également trouver de l'aide sur lesite allemand suivant: &lt;/span&gt;&lt;span lang="FR-BE"&gt;&lt;a href="https://www.botfrei.de/en/"&gt;&lt;span style="color: lime;"&gt;https://www.botfrei.de/en/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang="FR-BE" style="color: #0070c0;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Etes-vous victime? &lt;br /&gt;Aidez à garder cescriminels en prison !&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;S'il apparaît clairement que votre ordinateura été infecté par le malware DNS-changer, vous pouvez aider le FBI à renforcerson dossier en vous signalant comme victime.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Pour ce faire, le FBI a mis en ligne unsite en anglais. Le signalement dure quelques minutes, mais fourni des élémentssupplémentaires au FBI qui peuvent aider à garder ces cybercriminels pluslongtemps derrière les barreaux.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE"&gt;Vous pouvez vous signaler comme victime viale lien suivant: &lt;a href="https://forms.fbi.gov/dnsmalware"&gt;&lt;span lang="NL-BE"&gt;&lt;span style="color: lime;"&gt;https://forms.fbi.gov/dnsmalware&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang="FR-BE" style="color: #0070c0;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Dans l'espoir d'avoir contribué&amp;nbsp; à la sécurité ...&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;Keep it safe ! &lt;/span&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span lang="FR-BE" style="line-height: 115%;"&gt;Luc&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-8387793575121182940?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/8387793575121182940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/voulez-vous-continuez-surfer-sur.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/8387793575121182940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/8387793575121182940'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/voulez-vous-continuez-surfer-sur.html' title='Voulez-vous continuer à surfer sur internet après le 07 mars 2012 ?'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-fNed3W7KSvs/T0abcKLrLPI/AAAAAAAAWJY/9onV1sY8UA0/s72-c/DNS+configuration+IPv4+markering.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-1679187725232934950</id><published>2012-02-23T17:50:00.001+01:00</published><updated>2012-02-23T17:50:44.115+01:00</updated><title type='text'>Mise à jour - ransomware policier - ecops - detection - remédiation</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;L'analyse&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt;&amp;nbsp;forensique&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR"&gt;&lt;span class="hps"&gt;duvirus&lt;/span&gt; &lt;span class="hps"&gt;dont j’avais parlé&lt;/span&gt; &lt;span class="hps"&gt;dans un&lt;/span&gt;&lt;span class="hps"&gt;précédent post&lt;/span&gt; &lt;span class="hps"&gt;est en cours&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;Quelques résultats&lt;/span&gt;&lt;/span&gt;&lt;span class="shorttext"&gt;&lt;span lang="FR"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;intéressants&lt;/span&gt;&lt;/span&gt;&lt;span class="shorttext"&gt;&lt;span lang="FR"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;àconnaître&amp;nbsp;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l0 level1 lfo1; text-indent: -18.0pt;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;la variante eCops de ce ransomware &lt;b&gt;&lt;span style="color: lime;"&gt;ne crypte pas&lt;/span&gt;&lt;/b&gt;&amp;nbsp;les données de l'utilisateur ;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;le virus communique avec un &lt;b&gt;&lt;span style="color: lime;"&gt;botnet&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;a href="http://fr.wikipedia.org/wiki/Botnet" target="_blank"&gt;(*)&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;&lt;br /&gt;À l'heure actuelle&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt;, il y a 13 &lt;span class="hps"&gt;cassignalés à la&lt;/span&gt; &lt;span class="hps"&gt;FCCU&lt;/span&gt;. Nous demandons toujours aux &lt;span class="hps"&gt;victimes&lt;/span&gt; &lt;span class="hps"&gt;d’aller déposer plainte auprès de lapolice&lt;/span&gt; &lt;span class="hps"&gt;locale&lt;/span&gt; &lt;span class="hps"&gt;ou auprès d’une&lt;/span&gt;&lt;span class="hps"&gt;unité régionale de lutte contre la criminalité informatique&lt;/span&gt;&lt;span class="hps"&gt;(&lt;/span&gt;RCCU) &lt;span class="hps"&gt;de&lt;/span&gt; &lt;span class="hps"&gt;lapolice judiciaire fédérale&lt;/span&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;D’autres&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;victimes de&lt;/span&gt; &lt;span class="hps"&gt;virussemblables&lt;/span&gt; se so&lt;span class="hps"&gt;nt également manifestées&lt;/span&gt;. &lt;span class="hps"&gt;Pour plus d'informations&lt;/span&gt;, lisez &lt;span class="hps"&gt;mon post&lt;/span&gt;&lt;span class="hps"&gt;du 6 Janvier&lt;/span&gt; &lt;span class="hps"&gt;2012 (en NL)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="font-family: Arial, Helvetica, sans-serif; font-size: large; text-indent: -18pt;"&gt;&lt;a href="http://lucbeirens.blogspot.com/2012/01/tijd-om-een-backup-te-maken-en-deze-in.html"&gt;&lt;span lang="NL-BE" style="color: lime;"&gt;http://lucbeirens.blogspot.com/2012/01/tijd-om-een-backup-te-maken-en-deze-in.html&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;Détectionpar les produits anti-virus&lt;/span&gt;&lt;u style="font-size: x-large;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;Entretemps, la&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;FCCU&lt;/span&gt; aenvoyé &lt;span class="hps"&gt;un échantillon&lt;/span&gt; &lt;span class="hps"&gt;du malware&lt;/span&gt; &lt;span class="hps"&gt;à&lt;/span&gt; &lt;span class="hps"&gt;l'&lt;/span&gt;industrie des anti-virus.&lt;br /&gt;&lt;span class="hps"&gt;&lt;br /&gt;Il est actuellement déjà&lt;/span&gt; &lt;span class="hps"&gt;reconnu etintercepté par&lt;/span&gt; &lt;span class="hps"&gt;plus de la moitié&lt;/span&gt; &lt;span class="hps"&gt;desanti-virus&lt;/span&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: x-large;"&gt;Désinfectiondu virus ?&lt;/span&gt;&lt;span style="font-size: large; text-decoration: underline;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;Plusieurs de nos partenaires&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;travaillent sur&lt;/span&gt;&lt;span class="hps"&gt;une&lt;/span&gt; &lt;span class="hps"&gt;solution&lt;/span&gt; afin d’aider les&lt;span class="hps"&gt; victimes&lt;/span&gt; &lt;span class="hps"&gt;du virus&lt;/span&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;Pour Microsoft&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;Windows XP&lt;/span&gt;, &lt;span class="hps"&gt;il existe déjà une&lt;/span&gt; &lt;span class="hps"&gt;méthode disponible&lt;/span&gt;.&amp;nbsp; Celle&lt;span class="hps"&gt;-ci peut&lt;/span&gt; &lt;span class="hps"&gt;être consultée&lt;/span&gt; &lt;span class="hps"&gt;à l'adresse:&lt;/span&gt; &lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://goo.gl/OTfwz"&gt;&lt;span lang="FR" style="color: lime;"&gt;http://goo.gl/OTfwz&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="hps"&gt;&lt;span lang="FR" style="color: #333333;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;Dès que&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;d'autres solutions&lt;/span&gt; serontdisponibles, je les publierai à nouveau.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Un vidéo d'instuction pour la désinfection a été fait par Ted van Emmerik (a.k.a Maxstar) de PCwebplus.nl (en NL&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span lang="NL"&gt;&lt;a href="http://www.pcwebplus.nl/phpbb/viewtopic.php?f=222&amp;amp;t=5905"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif;"&gt;http://www.pcwebplus.nl/phpbb/viewtopic.php?f=222&amp;amp;t=5905&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR"&gt;&lt;br /&gt;&lt;span class="hps"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span lang="FR"&gt;&lt;span class="hps" style="color: lime;"&gt;&lt;b&gt;REMARQUE&lt;/b&gt;&lt;/span&gt;: &lt;span class="hps"&gt;suite au fait que le virus&lt;/span&gt;&lt;span class="hps"&gt;soit contrôlé par&lt;/span&gt; &lt;span class="hps"&gt;un botnet&lt;/span&gt;, &lt;span class="hps"&gt;il est probable que&lt;/span&gt; &lt;span class="hps"&gt;d'autres logiciels malveillants&lt;/span&gt;&lt;span class="hps"&gt;aient été installés sur votre ordinateur&lt;/span&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span class="hps"&gt;&lt;span lang="FR"&gt;&lt;br /&gt;Il est donc impératif&lt;/span&gt;&lt;/span&gt;&lt;span lang="FR"&gt; &lt;span class="hps"&gt;que votre PC&lt;/span&gt;&lt;span class="hps"&gt;soit&lt;span style="color: #333333;"&gt; &lt;/span&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;entièrement&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="color: lime;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span class="hps"&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;scanné&lt;/span&gt;&lt;/b&gt;&lt;span style="color: #333333;"&gt; &lt;/span&gt;afin de détecterd’autres virus éventuels&lt;/span&gt;. &lt;span class="hps"&gt;Si votre&lt;/span&gt; &lt;span class="hps"&gt;PC&lt;/span&gt; contient des &lt;span class="hps"&gt;informations hautementconfidentielles,&lt;/span&gt; &lt;span class="hps"&gt;ou est utilisé pour&lt;/span&gt; &lt;span class="hps"&gt;des affaires importantes&lt;/span&gt;, &lt;span class="hps"&gt;je vous conseille de&lt;/span&gt;&lt;span class="hps" style="color: lime;"&gt;&lt;b&gt;réinstaller complètement&lt;/b&gt;&lt;/span&gt; &lt;span class="hps"&gt;l’ordinateur enquestion &lt;/span&gt;!&lt;span style="color: #333333;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-1679187725232934950?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/1679187725232934950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/mise-jour-ransomware-policier-ecops.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/1679187725232934950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/1679187725232934950'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/mise-jour-ransomware-policier-ecops.html' title='Mise à jour - ransomware policier - ecops - detection - remédiation'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-3876940652644154151</id><published>2012-02-23T15:10:00.004+01:00</published><updated>2012-02-23T18:00:36.352+01:00</updated><title type='text'>Update politie ransomware - ecops - Antivirus detectie</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De forensische analyse van het virus waar ik in een eerdere post over berichtte is aan de gang.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Enkele bevindingen die interessant zijn om te weten :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;de eCops variant van deze ransomware &lt;span style="color: lime;"&gt;versleutelt&lt;/span&gt; de gegevensbestanden van de gebruiker &lt;span style="color: lime;"&gt;NIET&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;het virus communiceert met een &lt;span style="color: lime;"&gt;botnet&lt;/span&gt;&amp;nbsp;&lt;span style="color: lime;"&gt;&lt;a href="http://nl.wikipedia.org/wiki/Botnet" target="_blank"&gt;(*)&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Op dit ogenblik zijn er 13 dossiers aangemeld bij FCCU. Aan slachtoffers worden nog steeds gevraagd om hierover een klacht neer te leggen bij de Lokale politie of bij de regionale computer crime units (RCCU) van de Federale gerechtelijke politie.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Er zijn ook nog slachtoffers van andere gelijkaardige virussen die zich hebben aangemeld. V&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;oor meer informatie hierover kijk naar mijn post van 6 januari 2012 :&amp;nbsp;&lt;/span&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;http://lucbeirens.blogspot.com/2012/01/tijd-om-een-backup-te-maken-en-deze-in.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Detectie door antivirus-producten&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Ondertussen heeft FCCU een sample van het virus overgemaakt aan de Antivirus industrie.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Het virus wordt inmiddels reeds door meer dan de helft van de Antivirus herkend en onderschept.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Ontsmetting van het virus ?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Verschillende partners werken op dit ogenblik aan een remedie om de slachtoffers van het virus te helpen.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Voor MS Windows XP is er reeds een methode beschikbaar.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;U kan deze raadplegen op :&amp;nbsp;&lt;span style="color: lime;"&gt;http://goo.gl/OTfwz&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;En met dank aan&amp;nbsp;Ted van Emmerik (a.k.a Maxstar) van PCwebplus.nl ook een instructievideo hiervoor :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span lang="NL"&gt;&lt;a href="http://www.pcwebplus.nl/phpbb/viewtopic.php?f=222&amp;amp;t=5905"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;http://www.pcwebplus.nl/phpbb/viewtopic.php?f=222&amp;amp;t=5905&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Zodra er andere oplossingen zijn, hoort u hierover.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;LET OP&lt;/span&gt;&lt;/b&gt; : gezien het virus wordt aangestuurd via een botnet is de kans reëel dat er nog andere kwaadaardige software werd geïnstalleerd. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Het is dus absoluut noodzakelijk dat de volledige PC wordt gescand op virussen. &amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Bevat deze PC voor u zeer vertrouwelijke informatie of gebruikt u deze voor belangrijke bedrijfsactiviteiten, dan is het aangewezen om de PC &lt;/span&gt;&lt;b style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="color: lime;"&gt;volledig te herinstalleren !&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-3876940652644154151?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/3876940652644154151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/update-politie-ransomware-ecops.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3876940652644154151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3876940652644154151'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/update-politie-ransomware-ecops.html' title='Update politie ransomware - ecops - Antivirus detectie'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-3088034667792039128</id><published>2012-02-21T14:51:00.001+01:00</published><updated>2012-02-23T22:39:15.005+01:00</updated><title type='text'>Belgische versie van politie ransomware blokkeert gebruikers over het hele land</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: x-large;"&gt;Kwaadaardige software blokkeert PC's vaneindgebruikers en lijkt afkomstig van eCops&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Sinds enkele dagenblijken steeds meer mensen slachtoffer te worden van een kwaadaardige softwaredie de PC van de slachtoffers blokkeert.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De geblokkeerde PCbeeld onderstaande schermen af :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s1600/top.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="530" src="http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s640/top.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-X-9TCcK4mkY/T0awc0YMCsI/AAAAAAAAWJ0/ZuoKoOOOFEQ/s1600/bottom.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="340" src="http://1.bp.blogspot.com/-X-9TCcK4mkY/T0awc0YMCsI/AAAAAAAAWJ0/ZuoKoOOOFEQ/s640/bottom.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Hoewel het scherm laatgeloven dat de blokkering is gebeurd door de eCops omwille van overtredingen vande Belgische wetgeving, is dit geenszins het geval.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Achter deze blokkeringzitten cybercriminelen die u er op deze wijze ertoe willen brengen om aan hengeld over te maken.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://2.bp.blogspot.com/-NtkWpd0YE1I/T0av1vl5nfI/AAAAAAAAWJs/FtDNuD8ga_4/s1600/pay.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="132" src="http://2.bp.blogspot.com/-NtkWpd0YE1I/T0av1vl5nfI/AAAAAAAAWJs/FtDNuD8ga_4/s640/pay.png" width="640" /&gt;&lt;/a&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Wijze van verspreiding - schadelijkeeffecten &lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De personen die eendergelijk scherm afgebeeld zien op hun PC, zijn slachtoffer van een infectievan hun PC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Uit de eersteverklaringen van slachtoffers, blijkt dat de meesten werden geïnfecteerdterwijl ze online spelletjes speelden. Na het heropstarten van de PC kregen zijhet scherm dat de PC blokkeert.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Andere gekende maniervoor verspreiding van dergelijke virussen zijn: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;- via een bijlage ineen e-mail&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;- via illegale kopiesvan software die wordt verspreid in peer-to-peer netwerken&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;- via berichten insociale netwerken zoals Facebook die doorverwijzen naar websites om video's tebekijken.&amp;nbsp; (Die website meldt dan dat jevideosoftware moet worden bijgewerkt en toont een setup-popup.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De PC van hetslachtoffer wordt geblokkeerd en enkel het scherm met de betalingsmogelijkheidzijn nog toegankelijk.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Momenteel hebben wegeen verder zicht op de verdere effecten die deze kwaadaardige softwareveroorzaakt.&amp;nbsp; De eerste analyse van de PCvan een slachtoffer is thans aan de gang.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Gekende gevallen in het buitenland&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Soortgelijke gevallenzijn reeds gekend in het buitenland.&amp;nbsp;Daar bleek deze software niet alleen de PC van het slachtoffer teblokkeren maar ook alle gebruikersbestanden op de PC te vercijferen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Het slachtoffer krijgthierdoor geen toegang meer tot zijn bestanden.&amp;nbsp;Beschikt de gebruiker op dat ogenblik niet over een backup, dan wordtwerken wel heel moeilijk.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Ervaring uit debuitenlandse dossiers tonen aan dat slachtoffers die betaalden, vaak niet eenseen code kregen om hun systeem te deblokkeren of te ontcijferen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Wat te doen als je nog geen slachtofferbent ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Installeer eenantivirus&lt;/span&gt;, update naar de laatste versie en voer onmiddellijk een &lt;span style="color: lime;"&gt;scan &lt;/span&gt;uit vanje volledige PC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Maak een backup &lt;/span&gt;van uwgegevens op een externe harde schijf en bewaar deze daarna zonder dat de hardeschijf nog is gekoppeld aan je systeem.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Wat te doen als je slachtoffer bent ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;i&gt;Onmiddellijke acties&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Neem een foto&lt;/span&gt; van allemogelijk afbeeldbare schermen van je PC en bewaar deze om bij je dossier tevoegen.&lt;br /&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Noteer &lt;span style="color: lime;"&gt;welke acties &lt;/span&gt;jelaatst op je systeem hebt uitgevoerd en het tijdstip.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;Betaal NIET&lt;/span&gt;&lt;/b&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;i&gt;Klacht&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Je kan als slachtoffervan deze kwaadaardige software klacht neerleggen bij de lokale politie envragen om FCCU hiervan in te lichten.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Heb je al betaald, komdan zeker klacht neerleggen met alle informatie omtrent de bestemmeling van debetaling en omtrent de reactie vanwege de cybercriminelen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Verdere acties &lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;FCCU zal coördinatieuitvoeren tussen de verschillende dossiers om zo snel mogelijk een beter zichtte krijgen op de omvang van de infectie en van de technische aspecten ervan.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Zodra er meer informatie gekend is, zullen navolgende berichten wordenverspreid.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-3088034667792039128?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/3088034667792039128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/belgische-versie-van-politie-ransomware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3088034667792039128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3088034667792039128'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/belgische-versie-van-politie-ransomware.html' title='Belgische versie van politie ransomware blokkeert gebruikers over het hele land'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s72-c/top.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-4108915199859685670</id><published>2012-02-21T14:51:00.000+01:00</published><updated>2012-02-23T22:36:54.119+01:00</updated><title type='text'>Version belge d'un ransomware policier bloque des utilisateurs dans tout le pays</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;b&gt;Un logiciel malveillant bloque les PC des utilisateurs et semble provenird’eCops&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL" style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Depuis quelquesjours, il semble que de plus en plus de personnes soient victimes d’un logicielmalveillant&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt; qui bloque le PC desvictimes.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le PC bloqué montreles écrans suivants : &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s1600/top.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="530" src="http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s640/top.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-X-9TCcK4mkY/T0awc0YMCsI/AAAAAAAAWJ0/ZuoKoOOOFEQ/s1600/bottom.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="340" src="http://1.bp.blogspot.com/-X-9TCcK4mkY/T0awc0YMCsI/AAAAAAAAWJ0/ZuoKoOOOFEQ/s640/bottom.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Bien que l’écranlaisse croire que le PC est bloqué par eCops pour des infractions à lalégislation belge, ce n’est pas le cas.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Derrière tout cela, setrouvent des cybercriminels qui veulent vous amener à leur verser de l’argent.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-NtkWpd0YE1I/T0av1vl5nfI/AAAAAAAAWJs/FtDNuD8ga_4/s1600/pay.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://2.bp.blogspot.com/-NtkWpd0YE1I/T0av1vl5nfI/AAAAAAAAWJs/FtDNuD8ga_4/s640/pay.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Diffusion – effets dommageables&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Les personnes quivoient un tel écran sur leur PC sont victime d’une infection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le virus seraitdiffusé notamment via des sites de jeux en ligne. Les personnes téléchargent àleur insu le logiciel malveillant et lors du redémarrage de leur PC, ces écransapparaissent. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;D’autres manières généralement utilisées sont :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Via l’annexe d’unemail&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Via des copiesillégales de softwares qui sont diffusées dans les réseaux de peer-to-peer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Via des messages dansles réseaux sociaux comme Facebook qui vous redirigent vers des sites web afinde regarder des vidéos (ces sites signalent qu’un plugin vidéo doit êtreinstallé pour voir la vidéo en question&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;et un popup d’installation apparaît).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Le PC de la victimeest bloqué et seul l’écran pour effectuer le paiement est encore accessible. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Pour le moment, nousn’avons pas de vue sur d’autres effets provoqués par le logiciel malicieux. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;La première analyse du PC d’une victime est en cours de réalisation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Cas connus à l’étranger&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Des cas similaires sesont produits à l’étranger. Dans ces cas connus, le logiciel ne bloque pasuniquement le PC de la victime mais encrypte également les données de cettedernière.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;La victime n’a doncplus du tout d’accès à ses données. Si à ce moment, l’utilisateur n’avait pasde backup de ses données, alors cela se complique fortement pour lui.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;L’expérience del’étranger nous apprend que les victimes qui ont payé n’ont souvent pas reçu decode pour débloquer ou décrypter leur système.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Que faire si vous n’êtes pas encore victime?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Installez unantivirus&lt;/span&gt;, mettez-le à jour et effectuez &lt;span style="color: lime;"&gt;un scan &amp;nbsp;antivirus&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;complet&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;devotre PC.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Faites un backup&lt;/span&gt;de vos données sur un support externe et conservez-le non connecté à votresystème actuel.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Que faire si vous êtes victime ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;i&gt;Action immédiate&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Prenez une photo&lt;/span&gt;de votre écran et conservez-la pour la rajouter à votre dossier.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;span style="color: lime;"&gt;Notez lesdernières actions&lt;/span&gt; entreprises sur votre système ainsi que les heurescorrespondantes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;b&gt;Ne payez PAS.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;i&gt;Plainte&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;En tant quevictime de ce logiciel malveillant, vous pouvez déposer plainte à la policelocale et demander à en informer la FCCU.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Si vous avez déjàpayé, venez certainement déposer plainte avec toutes les informationsconcernant le destinataire du paiement et la suite donnée par les cybercriminels.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="NL"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;&lt;b&gt;Actions ultérieures&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;La FCCU va faire lacoordination des différents dossiers afin d’avoir une meilleure vue surl’ampleur de l’infection et ses aspects techniques.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Dès que nous auronsplus d’informations, nous les diffuserons.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-4108915199859685670?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/4108915199859685670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/version-belge-dun-ransomware-policier.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/4108915199859685670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/4108915199859685670'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/version-belge-dun-ransomware-policier.html' title='Version belge d&apos;un ransomware policier bloque des utilisateurs dans tout le pays'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-XleFjRfkStk/T0awdpkNmiI/AAAAAAAAWJ8/l0ydVRMfyTo/s72-c/top.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-5354001000876048823</id><published>2012-02-18T18:32:00.001+01:00</published><updated>2012-02-18T19:27:11.931+01:00</updated><title type='text'>Do you want to continue to browse and mail after the 7th of March ?</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;Take your time to read through this article and to check if you are victim of the malicious DNS-changer malware ! &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="color: lime;"&gt;If you do not do that, then it could well be that from March 7th on, your browsing and e-mail applications will no longer work !&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;If you do not want to read through the complete article, then at least test your PC's DNS-configuration settings just by visiting&amp;nbsp;one of the special test websites of :&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;the Belgian governmental CERT, the Computer Emergency Response Team : &lt;a href="http://dns-ok.be/"&gt;&lt;span style="color: lime;"&gt;DNS-OK.be&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;(in French/Dutch) or &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;the Geman Anti-botnet Advisory Centre &lt;div&gt;&lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;http://dns-changer.eu/&lt;/span&gt;&lt;/a&gt;&amp;nbsp;(in German, English, Danish&amp;nbsp;and Spanish)&lt;/div&gt;&lt;/span&gt;&lt;div&gt;&lt;/div&gt;&lt;/span&gt;&lt;div&gt;&lt;/div&gt;&lt;/span&gt;&lt;div&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;But perhaps it is better to read on ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;In this article I'll try to explain in simple terms some principles of the functioning of the internet so that each one can understand what the problem is and how you can do something to remediate to it.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;The problem is all about&amp;nbsp;the DNS ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;What is a DNS system ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;A Domain Name Service server can be compared to a phonebook. But then one for domain names.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;A domain name is an easy to remember version of an address of a server on the internet.&amp;nbsp; Easy for people but not for computers ! To communicate with each other, all computers on the internet are assigned an unique&amp;nbsp;IP-address. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;When you fill in a domain name in the address bar of your internet browser (e.g. microsoft.com), your browser will send the domain name to&amp;nbsp;a DNS-server and ask for the IP-address the browser has to use to visit the website.&amp;nbsp; The DNS-server will look up&amp;nbsp;the given domain name in its database and send the corresponding IP-address back to your browser&amp;nbsp;(e.g.&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt; 207.46.232.182 for&lt;/span&gt; microsoft.com). &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;div&gt;E-mail and several other internet applications also use DNS-services.&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Which&amp;nbsp;DNS do I use ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Luckily the end user normally does not have to worry about the DNS-server his PC is using.&amp;nbsp; In most cases the IP-address of the DNS-server will automatically be configured by the internet access provider while the connection is set up.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;So, most often you will use the DNS-server that is hosted at your internet access provider.&amp;nbsp; Easy and without problems.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s1600/DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s1600/DNS+configuration+IPv4+markering.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Your DNS settings will most likely look like what you see here above. If it is not the case, it does not necessary mean that you have a problem ! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;What is then the problem ? &lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;&lt;div&gt;The malicious DNS-changer software !&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;As user you rely on the system to bring you to the right website for which you have entered the domain name in your browser.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Cyber criminels try often to bring internet users to a false copy of a website with the intention to make them fill in personal data and access credentials (user name and password).&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Most often they use the&amp;nbsp;"phishing" technique with&amp;nbsp;spam mail or direct messages in which&amp;nbsp;a link refers to the false website.&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Fortunately, most end users no longer fall into that trap.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;That is why some cyber criminals have developed a more sophisticated system over the period 2007 en 2011 in order to re-route users to false versions of websites or of advertisments.&amp;nbsp; They therefor set up the DNS-changer botnet.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;In different ways they have infected end user's PC's with malicious software.&amp;nbsp; This malware changes the DNS-configuration of a PC so that the PC no longer send its requests to resolve&amp;nbsp;domain names to the DNS-server of the internet access provider but to a DNS-server&amp;nbsp;under control of the cyber criminals.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;The criminal DNS-server works just like a normal DNS-server except for the domain names for which the criminals wanted to re-route the end users to their false websites.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;So, as long as the infected end user is not surfing to such false website, he will not notice that he is not using his ordinary DNS-server because the bogus DNS-server provides correct IP-addresses for all other domain names. And even when he surfs to a forged website, he will often not notice neither.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6PYzYdOJY1A/TzWoDE29AKI/AAAAAAAAWIw/1qgBCu28fcw/s1600/Criminele+DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-6PYzYdOJY1A/TzWoDE29AKI/AAAAAAAAWIw/1qgBCu28fcw/s1600/Criminele+DNS+configuration+IPv4+markering.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large; mso-ansi-language: NL-BE;"&gt;&lt;o:p&gt;Does your&amp;nbsp;DNS configuration point to an IP&amp;nbsp;address that is part of one of the&amp;nbsp;series of&amp;nbsp;IP addresses &amp;nbsp;here below, then you are victim of the DNS-changer malware. (the&amp;nbsp;x can be every number between 0 and 255)&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;64.28.176.x&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;67.210.0.x &lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;77.67.83.x&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;div&gt;85.255.112.x &lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;93.188.160.x&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;div&gt;213.109.64.x&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;How big&amp;nbsp;the DNS-changer botnet and what will happen on the 7th of March&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;During the period from&amp;nbsp;2009 to 09 November 2011, the criminals behind the DNS-changer botnet succeeded to infect about 4 million PCs in 100 different countries.&amp;nbsp; All those infected PCs send their domain names requests to the criminal DNS-server.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;On&amp;nbsp;November 9th, 2011 the&amp;nbsp;FBI together with the NASA, the Estonian police and the Dutch Hightech Crime Team arrested six Estonian cyber criminals.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;At the same time the FBI took control over the criminal DNS-servers.&amp;nbsp;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;They did however not&amp;nbsp;put&amp;nbsp;these&amp;nbsp;DNS-servers out of order.&amp;nbsp; In collaboration with a security consortium the criminal DNS-servers were replaced by "clean" DNS-servers so that the infected end user PC's receive the correct IP-address for each domain name.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;The&amp;nbsp;FBI informed public that they would run these DNS-servers for another&amp;nbsp;4 months and would stop them on the 7th of March.&amp;nbsp; Every PC that will still be using the wrong DNS-settings will no longer be served by DNS-servers&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;All internet applications that use domain names on these infected PC's will work no longer !&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;"Only" 500.000 of the infected PC's are located in the USA.&amp;nbsp;This means that for about&amp;nbsp;3,5 million&amp;nbsp;PC's outside of the USA the DNS-configuration settings need to be adapted to be able to function properly !  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;In Germany, some 33.000 PC's have been found infected. There is no clear view on how many PC's have been infected in other countries.&lt;/div&gt;&lt;/span&gt;&lt;div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;You can read the&amp;nbsp;FBI message on&amp;nbsp;: &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf"&gt;&lt;span style="color: lime;"&gt;http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;How do I&amp;nbsp;test if&amp;nbsp;my PC-configuration has been changed by the DNS-changer malware ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Perhaps you are one of those 3,5 million others ...&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;To perform a check of your computer DNS-settings you can surf to one of the already mentionned websites of : &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;ul&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;the Belgian governmental CERT, the Computer Emergency Response Team : &lt;a href="http://dns-ok.be/"&gt;&lt;span style="color: lime;"&gt;DNS-OK.be&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;(in French/Dutch) or &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;the Geman Anti-botnet Advisory Centre &lt;div&gt;&lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;http://dns-changer.eu/&lt;/span&gt;&lt;/a&gt; (in German, English and Turkish)&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/ul&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;If the DNS-configuration of your PC has been changed by the DNS-changer malware, then there is a real chance that your PC has also been infected by other malware ! &lt;/span&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Therefor you should scan your PC with an up-to-date version of an Antivirus product.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;You can also find more help on&amp;nbsp;the website of the German Botfrei Association&amp;nbsp;:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;a href="https://www.botfrei.de/en/"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;https://www.botfrei.de/en/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;div&gt;&lt;/div&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Are you victim ? Help Justice to keep these criminals in jail&amp;nbsp; !&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;If, after checking, your PC seemed indeed&amp;nbsp;to be infected with the DNS-changer malware, then you can help the&amp;nbsp;FBI to compile their file against the criminals by letting them know that you're a victim.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;The&amp;nbsp;FBI has set up a website for this purpose.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; Filling out the form only takes a few minutes but is sufficient to provide them with further evidence that can keep the criminal longer behind bars.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;You can provide them with your details on following address : &lt;a href="https://forms.fbi.gov/dnsmalware"&gt;&lt;span style="color: lime;"&gt;https://forms.fbi.gov/dnsmalware&lt;/span&gt;&lt;/a&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="mso-ansi-language: NL-BE;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Hoping to have contributed a little to improve&amp;nbsp;security in cyberspace ...&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Keep it safe ! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-5354001000876048823?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/5354001000876048823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/do-you-want-to-continue-to-browse-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/5354001000876048823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/5354001000876048823'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/do-you-want-to-continue-to-browse-and.html' title='Do you want to continue to browse and mail after the 7th of March ?'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s72-c/DNS+configuration+IPv4+markering.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-3248107172035768156</id><published>2012-02-11T12:11:00.000+01:00</published><updated>2012-02-26T21:01:57.860+01:00</updated><title type='text'>Wil jij nog blijven internetten na 8 maart 2012 ?</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Neem even de tijd om ditartikel door te nemen en te checken of je geen slachtoffer bent van de kwaadaardige&amp;nbsp;DNS-changer malware !&amp;nbsp; &lt;span style="color: lime;"&gt;Doe je het niet, dan zou het kunnen zijn datje vanaf&amp;nbsp;8 maart problemen hebt met verschillende internettoepassingen zoals hetsurfen !&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;Heb je geen tijd of geen zin om dit artikel volledig te lezen, doe dat ten minste een test van de DNS configuratie van je PC door één van onderstaande websites te bezoeken :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="FR-BE"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;de website &lt;a href="http://dns-ok.be/"&gt;&lt;span style="color: lime;"&gt;DNS-OK.be&lt;/span&gt;&lt;/a&gt;&amp;nbsp;van het Belgisch Computer Emergency Response Team (in Frans en Nederlands) of&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;de website &lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;dns-changer.eu&lt;/span&gt;&lt;/a&gt; (in Duits, Engels, Deens en Spaans)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Maar misschien is het toch beter om verder te lezen.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;In dit artikel zal ikproberen om op eenvoudige wijze een aantal principes van de internetwerking toete lichten opdat elkeen zou kunnen begrijpen wat precies het probleem is en hoeje eraan kunt verhelpen.&amp;nbsp; Alles heeft temaken met DNS ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Wat is een DNS systeem ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Een Domain NameService server kan je beschouwen als een telefoonboek voor domeinnamen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Een domeinaam is degemakkelijk te onthouden versie van een adres van server op het internet.&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Gemakkelijk voormensen, maar niet voor computers !&amp;nbsp; Ommet elkaar te kunnen communiceren, krijgen alle computers op het internet eenuniek IP-adres (Internet protocol-adres).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Als jij in jeinternetbrowser een domeinnaam ingeeft (bvb microsoft.com), zal je browser aaneen DNS server vragen naar welk IP-adres de browser voor die domeinnaam moetworden doorverwezen. De DNS server zal dan voor de opgegeven domeinnaam hetIP-adres opzoeken van de computer waarmee jouwinternettoepassing zijn communicatie dient op te zetten. (&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;bvb 207.46.232.182 &lt;/span&gt;voor microsoft.com) &lt;br /&gt;Ook e-mail en bepaalde andere internettoepassingen maken gebruik van de DNS-diensten.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Welke DNS gebruik ik ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Gelukkig dienen deeindgebruikers zich in principe geen zorgen te maken over de DNS server die hunPC gebruikt.&amp;nbsp; In de meeste gevallen wordthet IP-adres van de DNS-server&amp;nbsp;automatisch geconfigureerd door deinternettoegangs-leverancier tijdens het opzetten van de internetverbinding.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Je gebruikt dusmeestal de DNS server die bij je eigen internettoegangs-leverancier isondergebracht.&amp;nbsp; Gemakkelijk enprobleemloos.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s1600/DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s1600/DNS+configuration+IPv4+markering.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Bij de meest providers&amp;nbsp;zien de DNS-instellingen van je internet-verbindingen er zo uit.&amp;nbsp; Is dit bij jou niet zo, dan hoeft dit nog niet te betekenen dat er een probleem is ! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Wat is dan het probleem ? &lt;br /&gt;De kwaadaardigeDNS-changer software !&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Als gebruiker vertrouwje erop dat je terecht zal komen op de echte website waarvan je de domeinnaamin je webbrowser hebt ingevoerd.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Toch proberencybercriminelen vaak om gebruikers naar een valse kopie van een website teleiden om er dan zowel de persoonlijke als toegangsgegevens (gebruikersnaam enpaswoorden) te bekomen.&amp;nbsp; Meestalgebruiken ze daarvoor de gekende "phishing" techniek met een spammailwaarin een link is opgenomen naar de valse website. Gelukkig lopen veeleindgebruikers niet meer in die val !&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Daarom hebben eenaantal cybercriminelen tussen 2007 en 2011 een meer gevorderd systeem ontwikkeldom gebruikers om te leiden naar valse versies van websites of&amp;nbsp; van advertenties.&amp;nbsp; Ze zetten hiervoor het DNS-changer botnet op.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Op diverse maniereninfecteerden ze eindgebruiker's PC's met kwaadaardige software die deinstellingen van de PC zodanig wijzigden dat de PC met zijn domeinnaamvragen nietlanger naar de DNS-server van de eigen internettoegangsleverancier gaat maarnaar een DNS-server onder controle van de cybercriminelen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;De crimineleDNS-server werkte als een normale DNS-server behalve voor de domeinnamenwaarvoor de criminelen de eindgebruikers wilden omleiden naar de valsewebsite.&amp;nbsp; Dus ... zolang de geïnfecteerdeeindgebruiker niet naar zo'n valse website surft, merkt hij niets van het feitdat hij niet zijn vertrouwde DNS gebruikt want ook de criminele DNS-servergeeft voor alle andere domeinnamen het correcte IP-adres terug. En in de meeste gevallen merkt hij evenmin iets als hij naar een vervalste website surft.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6PYzYdOJY1A/TzWoDE29AKI/AAAAAAAAWIw/1qgBCu28fcw/s1600/Criminele+DNS+configuration+IPv4+markering.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-6PYzYdOJY1A/TzWoDE29AKI/AAAAAAAAWIw/1qgBCu28fcw/s1600/Criminele+DNS+configuration+IPv4+markering.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;o:p&gt;Verwijst je DNS configuratie naar een IP-adres dat voorkomt in onderstaande reeksen, dan ben je slachtoffer van de DNS-changer malware. (de x kan elk getal zijn tussen 0&amp;nbsp; en 255)&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;64.28.176.x&lt;/span&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;67.210.0.x &lt;/span&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;77.67.83.x&lt;br /&gt;85.255.112.x&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;93.188.160.x&lt;br /&gt;213.109.64.x&lt;/span&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Hoe groot is het DNS-changer botnet en watgebeurt er op&amp;nbsp;8&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;maart ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;In de periode van 2009tot 09 november 2011 zijn de criminelen achter het DNS-changer botnet eringeslaagd om bij ongeveer 4 miljoen PCs in 100 verschillende landen deDNS-instellingen te wijzigen opdat ze hun domeinnaam-vragen zouden stellen aande criminele DNS-server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Op 9 november 2011 arresteerdede FBI in samenwerking met de NASA, de Estse politie en het Nederlandse Hightech Crime Team zes Estse cybercriminelen.&amp;nbsp;Tegelijkertijd nam ze de controle over decriminele DNS-servers over. &amp;nbsp;Deze DNS-serverswerden echter niet onmiddellijk buiten werking gesteld.&amp;nbsp;&amp;nbsp;De FBI heeft samen met een aantal security bedrijven de criminele DNS-servers vervangen door "propere" DNS-servers zodat ze voor elke domeinnaam het correcteIP-adres verstrekken.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;De FBI deelde mee dat zede "overgenomen" DNS-servers nog 4 maanden zou laten draaien. &amp;nbsp;In principe zullen ze deze servers dus op 8 of 9 maartbuiten werking stellen.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Elke PC die op dat ogenbliknog de verkeerde DNS-instellingen gebruikt, zal dan geen DNS-dienstverlening meerkrijgen. &amp;nbsp;Hierdoor zullen de verschillendeinternettoepassingen die gebruik maken van domeinnamen, niet meer werken !&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;"Slechts" 500.000van de geïnfecteerde PC's bevonden zich in de USA. &amp;nbsp;Dit wil zeggen dat 3,5 miljoen PC's buiten de USAhun instellingen dienen aan te passen om op de gestelde datum te kunnen blijvenverder werken !&amp;nbsp; &lt;br /&gt;&lt;br /&gt;In Duitsland blijken er momenteel zo'n 33.000 PC's getroffen te zijn.&amp;nbsp; Er is geen duidelijk zicht hoeveel PC's er in België zijn getroffen.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Je kan het FBI bericht lezen op :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf"&gt;&lt;span style="color: lime;"&gt;http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Hoe test je of je PC-instellingen door de DNS-changermalware zijn gewijzigd ?&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Misschien ben jij wel één van die 3,5 miljoen andere ...&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Om de DNS-changer test&amp;nbsp;ook voorde gewone gebruiker mogelijk te maken, heeft CERT.be, het Computer Emergency Response team van de Belgische overheid een testwebsite opgezet : &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Test dus nu je PC op : &lt;a href="http://dns-ok.be/"&gt;&lt;span style="color: lime;"&gt;http://dns-ok.be/&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;H&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;et Duitse Anti-botnet Advisory Centre had eerder ook al zo'n een website opgezet : &lt;a href="http://dns-changer.eu/"&gt;&lt;span style="color: lime;"&gt;http://dns-changer.eu/&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Als je PC effectief geïnfecteerd was door&amp;nbsp;de DNS-changer malware, dan is de kans echter ook reëel dat er nog andere kwaadaardige programma's op je PC werden geplaatst !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Laat daarom je PC met een up-to-date versie van je Antivirus volledig scannen.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Je kan hiervoor ook hulp vinden bij dezelfde Duitse website :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.botfrei.de/en/"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;https://www.botfrei.de/en/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;br /&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;em&gt;Ben je slachtoffer ? Help om de criminelen de gevangenis in te houden!&lt;o:p&gt;&lt;/o:p&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Blijkt uit de controledat je inderdaad was geïnfecteerd met het DNS-changer malware, dan kan je deFBI helpen om hun dossier te versterken door je als slachtoffer te latenkennen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;De FBI heeft hiervooreen website opgezet in het engels.&amp;nbsp; Hetinvullen ervan duur maar enkele minuten maar het levert aan de FBI bijkomendbewijsmateriaal dat kan helpen om de daders langer achter tralies te houden.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Je kan op deze link jelaten kennen als slachtoffer : &lt;a href="https://forms.fbi.gov/dnsmalware"&gt;&lt;span style="color: lime;"&gt;https://forms.fbi.gov/dnsmalware&lt;/span&gt;&lt;/a&gt;. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;In de hoop hiermee een beetje bijgedragen te hebben aan de veiligheid ...&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Keep it safe ! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-3248107172035768156?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/3248107172035768156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/wil-jij-nog-blijven-internetten-na-8.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3248107172035768156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/3248107172035768156'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/wil-jij-nog-blijven-internetten-na-8.html' title='Wil jij nog blijven internetten na 8 maart 2012 ?'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-LQCd35HMzP4/TzWiudQTkLI/AAAAAAAAWIo/rprJZh2p2_o/s72-c/DNS+configuration+IPv4+markering.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-453634733980995977</id><published>2012-02-11T01:14:00.002+01:00</published><updated>2012-02-11T01:17:57.306+01:00</updated><title type='text'>The need for an integrated approach to combat botnets</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;For all those that do not know what a botnet is ... you should !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Here is my presentation I gave at&amp;nbsp;the conference "Combating Cybercrime in Europe - Special focus : fighting botnets" in Berlin on the 9th February 2012 organized by the European Academy for Taxes, Economics &amp;amp; Law.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.slideshare.net/LucBeirens/20120208-berlin-afe-cybercrime-botnet-threat"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;http://www.slideshare.net/LucBeirens/20120208-berlin-afe-cybercrime-botnet-threat&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;For all those that do know what a botnet is ... go to part 2 of the same presentation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;I'm looking for partners nationally and internationally to go beyond what we have today.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Let's help each other to keep cyberspace safe !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-453634733980995977?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/453634733980995977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/need-for-integrated-approach-to-combat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/453634733980995977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/453634733980995977'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/02/need-for-integrated-approach-to-combat.html' title='The need for an integrated approach to combat botnets'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-7454750889893958236</id><published>2012-01-27T14:14:00.001+01:00</published><updated>2012-01-27T16:51:22.349+01:00</updated><title type='text'>Reclame in de Android notificatiebalk ? Weg er mee !</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-AOndX5NMoe8/TyKZ7v9lzeI/AAAAAAAAWIY/-BcLK3TGK3U/s1600/SC20120127-123723+cut.jpeg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="129" src="http://3.bp.blogspot.com/-AOndX5NMoe8/TyKZ7v9lzeI/AAAAAAAAWIY/-BcLK3TGK3U/s320/SC20120127-123723+cut.jpeg" width="320" /&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Deze week kreeg ik het weer aan mijn hart... plotseling verscheen er een sterretje met publiciteit voor een &lt;br /&gt;"APP TRES COOL" in de notificatiebalk van mijn Samsung Galaxy S2 die werkt op Android 2.3.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="content_area" id="content_article"&gt;&lt;div id="article_text_blocks"&gt;&lt;a href="http://4.bp.blogspot.com/-YZ0MvSWttKQ/TyKZOXvW6uI/AAAAAAAAWII/V1u3wAZa4gM/s1600/SC20120127-124018.jpeg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-YZ0MvSWttKQ/TyKZOXvW6uI/AAAAAAAAWII/V1u3wAZa4gM/s320/SC20120127-124018.jpeg" width="192" /&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Een beetje paranoïde als ik ben, dacht ik onmiddellijk dat mijn smartphone was gehackt en geïnfecteerd met malware.  Volgende reactie : wat vind ik hierover op het internet ? Google vond voor mij al snel een aantal andere verontruste Android gebruikers die zich net als mij stoorden aan deze advertenties.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Je kan de publicitaire melding net als alle andere meldingen natuurlijk wel wissen maar kort daarop krijg je zeker weer een aanbieding voor een andere App.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Ik hou niet van reclame.  Ik begrijp&amp;nbsp;wel dat App ontwikkelaars niet kunnen leven van de hemelse dauw.  Daarom verkies ik vaak een betalende versie van een App zonder die vervelende publicitaire berichten.&amp;nbsp; Dat&amp;nbsp;eerder dan een "freeware" versie vol blinkende berichten die bovendien mijn downloadvolume opgebruiken.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Maar in hemelsnaam ... reclame in mijn notificatiebalk, de plaats waar de meldingen moeten verschijnen over dingen die ik belangrijk vind.  Het voelt alsof een lichtreclamepaneel met wisselende boodschappen in je slaapkamer wordt gehangen zonder dat je daarin hebt toegestemd. Wie haalt het nu in zijn hoofd om daar publiciteit te gaan plaatsen?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Marketingjongens heel zeker ... En inderdaad. Blijkbaar wordt deze mogelijkheid aan App ontwikkelaars aangeboden door verschillende firma's zoals &lt;/span&gt;&lt;a href="http://www.airpush.com/" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;AirPush&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;, &lt;/span&gt;&lt;a href="http://www.appenda.com/" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Appenda&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;, &lt;/span&gt;&lt;a href="http://www.leadboltapps.com/push/" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;LeadBolt&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;, &lt;/span&gt;&lt;a href="http://moolah-media.com/" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Moolah Media&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;, en &lt;/span&gt;&lt;a href="http://www.startapp.com/" target="_blank"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt; &lt;span style="color: lime;"&gt;StartApp&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;.  AirPush belooft App ontwikkelaars minimaal een vertienvoudiging van hun inkomsten beloofd als ze gebruik make van hun methode. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7fS8CqMIlI4/TyKY_AbvvrI/AAAAAAAAWHo/CmGsb0B3IWc/s1600/airpush+ad+network.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="376" src="http://4.bp.blogspot.com/-7fS8CqMIlI4/TyKY_AbvvrI/AAAAAAAAWHo/CmGsb0B3IWc/s640/airpush+ad+network.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Concreet komt het erop neer dat zij met hun methode de mogelijkheid bieden aan ontwikkelaars om hun Apps te promoten via berichten in de notitificatiebalk.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Door een dergelijke App te installeren wordt het advertentie framework in werking gezet. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Ik heb gekozen voor Android omdat het een open platform is.&amp;nbsp; Maar op deze functionaliteit zat ik niet te wachten. &lt;br /&gt;Ik vind het uiterst intrusief en storend.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: x-large;"&gt;Wil je ook een advertentievrije notificatiebalk ? &lt;br /&gt;Lees dan verder&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-JkFqSlhEyJg/TyKY5kvaU8I/AAAAAAAAWHY/PCvhdW5BnVA/s1600/Airpush+permanent+opt+out.PNG" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="135" src="http://1.bp.blogspot.com/-JkFqSlhEyJg/TyKY5kvaU8I/AAAAAAAAWHY/PCvhdW5BnVA/s320/Airpush+permanent+opt+out.PNG" width="320" /&gt;&lt;/a&gt;&lt;span id="goog_883290428"&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De firma AirPush heeft een &lt;/span&gt;&lt;a href="http://www.airpush.com/optout" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Opt-Out lijst&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt; waar je je IMEI-nummer kan inschrijven in de opt-out lijst. &lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Dit bevrijdt je van de vervelende AirPush ads maar daarom nog niet van de ads die via advertentie frameworks van andere firma's je smartphone binnendringen. En bovendien, waarom zou je je IMEI nummer aan zo'n firma willen geven ?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Hoe voorkom je dat alle publiciteit uit je notificatiebalk wordt geweerd ? Zorg ervoor dat de Apps die gebruik maken van dit systeem niet op je smartphone terecht komen !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Maar hoe weet je welke Apps dat nu zijn ?&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Dat kan je ontdekken door een App als &lt;a href="https://market.android.com/details?id=com.denper.addonsdetector" target="_blank"&gt;&lt;span style="color: lime;"&gt;Addons Detector&lt;/span&gt;&lt;/a&gt; of&amp;nbsp;&lt;/span&gt;&lt;a href="https://market.android.com/details?id=com.brosmike.airpushdetector" target="_blank"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;AirPush Detector&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt; op je smartphone te installeren. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-aeP8xJle8GI/TyKZBf6V0aI/AAAAAAAAWHw/zJ2HJLMLanI/s1600/addons+detector.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/goog_883290451"&gt;&lt;img border="0" height="151" src="http://3.bp.blogspot.com/-aeP8xJle8GI/TyKZBf6V0aI/AAAAAAAAWHw/zJ2HJLMLanI/s200/addons+detector.PNG" width="200" /&gt;&lt;/a&gt;&lt;img border="0" height="151" src="http://1.bp.blogspot.com/-lM6pUm1ewY8/TyKY8C4Yq7I/AAAAAAAAWHg/q1I8jI3BVhQ/s200/airpush+detector.PNG" width="200" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://market.android.com/details?id=com.denper.addonsdetector" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;" target="_blank"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-tVx4Gix_2Eg/TyKZSRgOQ2I/AAAAAAAAWIQ/bTSy_iDcATI/s320/SC20120127-124155.jpeg" width="192" /&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Na installatie zal deze App detecteren welke Apps push notificaties op je smartphone binnen brengen. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Die Apps verwijder je dan terug van je smartphone en je hebt weer een reclamevrije notificatiebalk !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Hou het safe !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;img height="96" src="http://1.bp.blogspot.com/-tVx4Gix_2Eg/TyKZSRgOQ2I/AAAAAAAAWIQ/bTSy_iDcATI/s320/SC20120127-124155.jpeg" style="filter: alpha(opacity=30); left: 600px; opacity: 0.3; position: absolute; top: 2875px;" width="57" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-7454750889893958236?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/7454750889893958236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/reclame-in-de-android-notificatiebalk.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/7454750889893958236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/7454750889893958236'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/reclame-in-de-android-notificatiebalk.html' title='Reclame in de Android notificatiebalk ? Weg er mee !'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-AOndX5NMoe8/TyKZ7v9lzeI/AAAAAAAAWIY/-BcLK3TGK3U/s72-c/SC20120127-123723+cut.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-8502318820510676313</id><published>2012-01-22T22:36:00.000+01:00</published><updated>2012-01-23T17:34:08.393+01:00</updated><title type='text'>Golf van phishing Twitter DMs : wat te doen ?</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;We konden er deze week niet naast kijken bij de collega's van de #SMPolBE : het ene waarschuwingsbericht na het andere over valse Twitter direct messages (DM).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Deze DM berichten blijken te&amp;nbsp;komen&amp;nbsp;van&amp;nbsp;je followers.&amp;nbsp; De inhoud van berichten zijn&amp;nbsp;meestal verontrustend : &lt;/span&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-OHTMG59pd4Q/TxxpI6AtPWI/AAAAAAAAWG0/MrJ-k9QKuyY/s1600/foto+iphone+DM.PNG" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;“Someone said this real bad thing about you in a blog”, &lt;br /&gt;"Is this you in this video ?"&amp;nbsp; of nog &lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;"Some horrible rumors about you going around online..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-OHTMG59pd4Q/TxxpI6AtPWI/AAAAAAAAWG0/MrJ-k9QKuyY/s1600/foto+iphone+DM.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="116" src="http://4.bp.blogspot.com/-OHTMG59pd4Q/TxxpI6AtPWI/AAAAAAAAWG0/MrJ-k9QKuyY/s320/foto+iphone+DM.PNG" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;In deze DM is er telkens een link opgenomen.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;strong&gt;Wat gebeurt er als je deze link aanklikt ?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Nieuwsgierig als we zijn, klikken nogal wat mensen op de link in de tweet. Ze komen dan schijnbaar terecht op de &lt;br /&gt;login-pagina van Twitter.&amp;nbsp; Twitter vraagt je er om opnieuw &lt;br /&gt;in te loggen omdat je sessie werd afgesloten&amp;nbsp;door een &lt;br /&gt;time-out.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SpY7lgXRXf4/Txxr0QmM_NI/AAAAAAAAWG8/bdpCXoM5EWw/s1600/tvvittercom+phishing+firefox.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="268" src="http://2.bp.blogspot.com/-SpY7lgXRXf4/Txxr0QmM_NI/AAAAAAAAWG8/bdpCXoM5EWw/s640/tvvittercom+phishing+firefox.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;strong&gt;Wie echter iets aandachtiger is, stelt het bedrog vast.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;De verbinding verloopt NIET via een https verbinding en het adres in de adresbalk is NIET dat van twitter. Soms gelijkt dit adres wel op dat van Twitter zoals bijvoorbeeld&amp;nbsp;Tvvitter. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-wZBCBOFwTLI/TxxvQeNBYTI/AAAAAAAAWHE/817uKrdkyT8/s1600/tvvittercom+phishing+adresbar.PNG" imageanchor="1" style="clear: left; float: left; height: 238px; margin-bottom: 1em; margin-right: 1em; width: 633px;"&gt;&lt;img border="0" height="176" src="http://1.bp.blogspot.com/-wZBCBOFwTLI/TxxvQeNBYTI/AAAAAAAAWHE/817uKrdkyT8/s640/tvvittercom+phishing+adresbar.PNG" width="640" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;strong&gt;Wat gebeurt er daarna ?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Je bent terecht gekomen op de website van een cybercrimineel die jouw gebruikersnaam en paswoord wil achterhalen.&amp;nbsp; Hiermee kan hij wanneer hij wil in jouw naam berichten in de wereld Twitteren.&amp;nbsp;Als je een beetje reputatie hebt opgebouwd kan dat mogelijk wel wat schade veroorzaken.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Gebruik je bovendien hetzelfde paswoord voor verschillende internetdiensten, dan heeft de crimineel ook toegang tot die accounts.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Om zoveel mogelijk gebruikersnamen en paswoorden te verzamelen, starten de criminelen met het verzenden van soortgelijke phishing DMs in jouw naam naar jouw followers in hoop dat ook zij in de val zullen trappen.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Waar komen deze berichten vandaan ?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;De berichten worden in de eerste plaats verzonden via gehackte Twitter accounts.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Blijkbaar gebruiken de criminelen echter nog andere&amp;nbsp;technieken waarbij ze kwetsbaarheden in browsers en besturingssystemen uitbuiten.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Zelf kwam ik terecht op de website FBI.C0M met de Delphin browser van mijn Android smartphone.&amp;nbsp; De website gaf enkel het volgende bericht : "It works".&amp;nbsp; Kort nadien kregen een aantal van mijn followers een DM uit mijn naam.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Wie hierachter steekt was in dit geval niet zo moeilijk.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-kY3I89iklso/Txx2f9Dl2JI/AAAAAAAAWHM/DzJTdF7QXUs/s1600/fbi.com+tango+down.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="364" src="http://1.bp.blogspot.com/-kY3I89iklso/Txx2f9Dl2JI/AAAAAAAAWHM/DzJTdF7QXUs/s640/fbi.com+tango+down.PNG" width="640" /&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Deze tweet werd door verschillende security watchers geretweet.&amp;nbsp; En wat doe je dan als nieuwsgierig politieman ? Je klikt op de link om te zien of de website down is ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Social engineering waarin security watchers en politie-mensen inlopen ...&amp;nbsp; Uit fouten leren we.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Hoe DMs konden worden verzonden in mijn naam zonder dat ik op de website mijn gebruikersnaam en paswoord&amp;nbsp;invoerde, wordt thans verder onderzocht.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;strong&gt;Wat kunnen we doen ?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;1. Krijg je dergelijke DM berichten van één van je followers :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;- klik dan NIET op de link&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;- VERWIJDER het DM bericht uit de berichtenlijst&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;- licht je follower in van het feit dat hij DM's heeft verzonden.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;br /&gt;Jouw Twitter account is nog NIET in gevaar.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;2. Heb je toch&amp;nbsp;je gegevens ingevoerd op een phishing-website, of krijg je bericht van een follower, &lt;br /&gt;dan is je Twitter account WEL in gevaar :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;- wijzig onmiddellijk je Twitter paswoord en &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;- wijzig ook het paswoord van alle accounts waar je hetzelfde paswoord voor gebruikt.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Lukt het niet meer dan kan je terecht op deze website&lt;/span&gt;&lt;br /&gt;&lt;a href="https://support.twitter.com/groups/33-report-a-violation"&gt;&lt;span style="color: lime; font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;https://support.twitter.com/groups/33-report-a-violation&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Stay safe !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-8502318820510676313?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/8502318820510676313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/golf-van-phishing-twitter-dms-wat-te.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/8502318820510676313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/8502318820510676313'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/golf-van-phishing-twitter-dms-wat-te.html' title='Golf van phishing Twitter DMs : wat te doen ?'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-OHTMG59pd4Q/TxxpI6AtPWI/AAAAAAAAWG0/MrJ-k9QKuyY/s72-c/foto+iphone+DM.PNG' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-5592207315817048257</id><published>2012-01-22T17:30:00.000+01:00</published><updated>2012-01-22T20:39:18.728+01:00</updated><title type='text'>A tribute to Harry Onderwater an early Dutch cyber investigator</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-7H3qjzSugHs/Txw4hXaqTrI/AAAAAAAAWGs/RcwL_PqimyQ/s1600/harry+onderwater.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-7H3qjzSugHs/Txw4hXaqTrI/AAAAAAAAWGs/RcwL_PqimyQ/s1600/harry+onderwater.jpg" /&gt;&lt;/a&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: large;"&gt;Life is often to short to do whatever one wants to do.&lt;/span&gt;&lt;br /&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Today I learned that once again I've put my priorities wrong and focused on my work in stead of contacting a friend who had serious health problems.&amp;nbsp; And now he's passed away.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Allow me to honnor in a short post Harry Onderwater with whom the early European cyber investigators of the European Interpol working party on information technology crime had the pleasure to work with in the nineties.&amp;nbsp; Harry was part of the Dutch delegation, together with Inge Theunissen and Louis Maatman.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Harry was the big man with the white beard, a selfmade geek that impressed me with his technical knowledge.&amp;nbsp; He was full with good ideas and helped to draw&amp;nbsp;the road map to improve the computer forensic&amp;nbsp;and investigative capabilities of police men in the European countries. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Harry was not a typical policeman.&amp;nbsp; He had already in those years contact with hackers and other computer geeks.&amp;nbsp; He showed me that out-of-the-box thinking and acting is better than what we used to do in those years.&amp;nbsp; Cyber security can only be the result of public-private cooperation in which we have to learn from each other.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Afterwards Harry left the policeforce to continue to improve cyber security as a private consultant.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Thanks, Harry, for&amp;nbsp;your wisdom and energy and for the good cooperation we had.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;I'll continue to work for a more secure and safe cyberspace !&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;My sincere condolences go to his family and friends.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Bye and see you again.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;Luc Beirens&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-5592207315817048257?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/5592207315817048257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/tribute-to-harry-onderwater-early-dutch.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/5592207315817048257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/5592207315817048257'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/tribute-to-harry-onderwater-early-dutch.html' title='A tribute to Harry Onderwater an early Dutch cyber investigator'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-7H3qjzSugHs/Txw4hXaqTrI/AAAAAAAAWGs/RcwL_PqimyQ/s72-c/harry+onderwater.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-7373417459194318893</id><published>2012-01-13T01:12:00.000+01:00</published><updated>2012-01-13T01:12:41.155+01:00</updated><title type='text'>When internet fraudsters start to use malware ... extortion with manipulated video</title><content type='html'>&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Western African internet fraudsters have set one step further in the use of cyber technology to commit their fraud.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;strong&gt;Western African internet fraud as we used to know it&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;We all know the different&amp;nbsp; so called Nigerian internet fraud schemes in which&amp;nbsp;criminals try to get your money by proposing&amp;nbsp;to cooperate in the transfer of the money from a froozen bank account of one or another African dictator.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;In more recent schemes the Western African gangs also switched to lure lonely men and women into friendship fraud. People are attracted by fraudulent proposals of African men and women that are looking for a new partner. The victim will pay then to help the family of the poor girl, to procure her a pasport and an&amp;nbsp;airplane ticket and any other kind of cost that can occur in such a relationship.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;As this kind of fraud went quite well and easily, these gangs started to use&amp;nbsp;girls to chat with the lonely men that were looking for a new partner in their lives.&amp;nbsp; At first, the&amp;nbsp;girls ask their new boyfriend to pay for a new computer and for the internet connection at their home, so that they&amp;nbsp;do not need to go to the cyber café&amp;nbsp;to go on the internet.&amp;nbsp; In their homes they are more free to do whatever one might do in front of a webcam...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;These girls succeed very often very quickly to make their new boyfriends to perform explicit sexual actions in front of their webcams. As soon as the criminals are in the possession of those pictures they start to extort the victims, threatening them to distribute these videos to their relatives.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Very often this kind of extortion works quite well because victims are&amp;nbsp;afraid for their reputation.&amp;nbsp; The videos often don't leave a lot to the imagination of the spectator.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Of course not all men are like that ... &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;strong&gt;Internet fraud the new way ...&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;As the extortion with the sexual action in front of a webcam works so well, the criminals have been looking for new ways for their fraudulent actions.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Recently&amp;nbsp;we registered a new kind of extortion in which Western African internet fraudsters made use of of the possibilities that are offered by malware.&amp;nbsp; They used the different options in a very vicious way.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Although investigations are still under way we already know that their new victims are now the very ordinary internet users that have the misfortune to get infected by a malware.&amp;nbsp; The victims&amp;nbsp;are not looking for new partners, fantastic occassions or whatever.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;The malware infects the computer of the victims after which the criminals start to gather information on that computer and of all victim's&amp;nbsp;internet activity.&amp;nbsp; The malwares provides the criminals with&amp;nbsp;usernames and passwords for all the victim's webmail and social network accounts.&amp;nbsp; So they know all the people in the victim's network : mom, dad, granny, suns, daughters, employer ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;In the new extortion scheme, the victims receive a extortion mail&amp;nbsp;with a video attached in which&amp;nbsp;they will see themselves in very explicit sexual actions&amp;nbsp;in front of their webcam.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;But these are not all genuine images.&amp;nbsp; The analysis of the video shows that it is made up of different parts and glued together so that it makes a very convincing video.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Apparently the criminals activate webcam and microphone on the infected PC so that they can capture images of the person sitting in front of the webcam and intercept the sounds in the room where the PC is situated.&amp;nbsp; The victims do not know that their PC is infected and they are unaware that they are being filmed and recorded.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: Arial;"&gt;The extortion video starts with a view of the person in front of the webcam wearing clothes like all decent people do.&amp;nbsp; Then you get a part in which the focus is switched to the genital parts of that person and where very explicit sexual manupulations are shown.&amp;nbsp; The second part of the video is&amp;nbsp;not a genuine image of the victim but to make viewers believe&amp;nbsp; that it really is, the criminals have added a soundtrack of the victim along with those images.&amp;nbsp; So, while looking at the explicit sexual actions, one hears the voice of the victim and of his partner.&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: Arial;"&gt;At first glance these images look quite genuine and may deceive a lot of people so that they believe that they are looking at real stuff.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;As the criminals know who is in your network, threating to distribute this forged video to their contacts, makes people consider seriously to incline to the demands of the criminals.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;&lt;strong&gt;What can be done about it ?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Preventing the infection of your PC starts with the use of genuine software from a trustworthy source and the installation and permanent use of an antivirus product and a&amp;nbsp;firewall.&amp;nbsp; Updating and patching of operating system and of all the installed software is a second attitude to take.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Being suspicious on what you do on the internet, not just clicking on attachments, not visiting websites or internet areas that are know to distribute malwares is a third attitude.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Despite all your efforts, it can happen that your&amp;nbsp;PC gets infected&amp;nbsp;with malware and that you'll get such an extortion e-mail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Do not panic but act in a well planned way. Consider next steps : &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;1. Your PC is infected and contains evidence. Do not connect it anymore to the internet and do not tamper with it if you want to get it analysed by law enforcement. Keep all data that can prove the contact of the criminals with you. If you don't want to go to the police, make at least a full copy of the disk before reinstalling.&amp;nbsp; You might chance your mind.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;To be sure that the malware infection is completely gone, it is best to reinstall your PC from scratch and scan everything you reinstall from your backup.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;2. Your internet accounts are compromised. Use another uninfected PC to connect to all these accounts to change passwords - if you still have access to them.&amp;nbsp; If not, take contact with the abuse team of that internet service provider in order to explain your problem so that you can regain control over your account.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;3.&amp;nbsp;The threats of the criminals still remain.&amp;nbsp; If the video is fake, you might take the chance to be faster than the criminals and inform your contacts of what is happening, explaining that you are victim of an extortion attempt.&amp;nbsp; This will make people look with another mindset when they would receive the video from the criminals afterwards.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="font-size: large;"&gt;Do not communicate any longer with the criminals and most important &lt;strong&gt;do not pay !&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;People that pay once will continue to be put under pressure by the criminals and will be made to pay again and again.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;4. To stop the criminals you may want to report your case to the police.&amp;nbsp; Look if there is any specialized cybercrime unit that might help you.&amp;nbsp; They can often give you specialized advice on what to do.&amp;nbsp; Before coming to make your complaint, try to prepare it and make already a timeline of all the incidents that happened and gather proof of all the incidents.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Probably, if the case will be prosecuted, law enforcement will want to gather the digital evidence on your computer system.&amp;nbsp; So keep it ready.&amp;nbsp; You may also consider taking out the infected harddisk as evidence.&amp;nbsp; In this way you keep your PC and can reinstall it with a new harddisk.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;P.S. Some advice for people that take sometimes more intimate digital pictures : do not store those pictures on your harddisk or on an external &amp;nbsp;harddisk that is always connected to your PC.&amp;nbsp; The criminals that have access to your infected PC might find these pictures.&amp;nbsp; And if they are genuine, they have better cause for extortion.&amp;nbsp; Keep the pictures and videos on an offline support and encrypt them ! It's your privacy !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Keep it safe !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: large;"&gt;Luc&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-7373417459194318893?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/7373417459194318893/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/when-internet-fraudsters-start-to-use.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/7373417459194318893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/7373417459194318893'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/when-internet-fraudsters-start-to-use.html' title='When internet fraudsters start to use malware ... extortion with manipulated video'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2601096556187183895.post-6014544929260541259</id><published>2012-01-06T18:22:00.001+01:00</published><updated>2012-02-23T13:42:35.323+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ransomware backup security'/><title type='text'>Tijd om een backup te maken en deze in diverse versies apart te bewaren !</title><content type='html'>&lt;strong&gt;&lt;em&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Politie-ransomware ?&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Update :&amp;nbsp;&lt;span style="color: lime;"&gt;http://lucbeirens.blogspot.com/2012/02/belgische-versie-van-politie-ransomware.html&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Momenteel is in&amp;nbsp;diverse Europese landen een&amp;nbsp;malware erin geslaagd om computersystemen te infecteren waarna alle gebruikersbestanden op de computer worden versleuteld zodat ze niet langer meer geopend kunnen worden met de gebruikelijke toepassingen.&amp;nbsp; Daarna ontvangt de PC-gebruiker het verzoek een bepaalde som te betalen in ruil voor de decryptiesleutel.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Omwille van de afpersing wordt deze vorm van malware aangeduid met de term ransomware.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;De laatst ondekte versies van ransomware bestaan in verschillende taalversies (Nederlands, Frans, Duits, Engels en Spaans) en lijken zeer gericht de verschillende landen te infecteren.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Om de gebruikers te overtuigen om de decryptiesleutel te betalen, doen deze ransomwares zich voor als een programma van de respectieve nationale politiediensten waarbij de logo's en de nationale kleuren in een banner zijn opgenomen.&amp;nbsp; De gebruiker wordt ervan ingelicht dat zijn bestanden werden versleuteld omdat er illegale bestanden werden gevonden op zijn computer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Het slachtoffer wordt meegedeeld dat hij mits&amp;nbsp;betaling van een boete van 100 tot 200 € de decryptiesleutel zal ontvangen.&amp;nbsp; De betalingen dienen te gebeuren aan de betrokken politiedienst in de munteenheid van het land via de online-betalingssystemen Paysafecard of Ukash.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Zo zijn er versies van de Duitse Federale politie, het Duitse GEMA, de Franse Gendarmerie,&amp;nbsp;het Zwitserse Federale departement van Justitie en Politie, de Spaanse politie en de Nederlandse politie.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-hkhXIrRHGjk/T0YzOxiggvI/AAAAAAAAWJM/UXhE14wXziM/s1600/andere+landen.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="595" src="http://4.bp.blogspot.com/-hkhXIrRHGjk/T0YzOxiggvI/AAAAAAAAWJM/UXhE14wXziM/s640/andere+landen.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Mocht iemand er toch aan twijfelen : de&amp;nbsp;vermelde politiediensten hebben niets te maken met deze ransomware-distributie.&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Op dit ogenblik is er nog geen&amp;nbsp;variant met de Belgische politie opgedoken, hoewel er ook&amp;nbsp;in België al verschillende gevallen van ransomware werden gesignaleerd.&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Tot overmaat van ramp : de slachtoffers die wel&amp;nbsp;betaalden kregen niet steeds een sleutel om hun gegevens te decrypteren.&amp;nbsp; &lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Wat te doen om te voorkomen dat je slachtoffer wordt van een dergelijke ransomware ?&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Natuurlijk is het noodzakelijk om te voorkomen dat je wordt geïnfecteerd door een ransomware.&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Een &lt;strong&gt;&lt;span style="color: lime;"&gt;geactualiseerde antivirusscanner&lt;/span&gt;&lt;/strong&gt; en een &lt;strong&gt;&lt;span style="color: lime;"&gt;voorzichtige houding&lt;/span&gt;&lt;/strong&gt; bij internetactiviteiten zijn hierbij belangrijk.&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Hoewel die maatregelen het risico reeds sterk verminderen, blijft de kans bestaan dat je wordt geïnfecteerd.&amp;nbsp; En dan worden alle gegevensdragers in het geïnfecteerde systeem onderzocht en versleuteld.&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Daarom : voorzie een &lt;strong&gt;&lt;span style="color: lime;"&gt;regelmatige backup&lt;/span&gt;&lt;/strong&gt; van al de data die je lief is en bewaar deze in een aantal opeenvolgende versies op een gegevensdrager die &lt;strong&gt;&lt;span style="color: lime;"&gt;NIET is gekoppeld&lt;/span&gt;&lt;/strong&gt; aan je werkpost !&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Op die manier kan je ook in de toekomst je activiteiten nog verder zetten zonder afhankelijk te zijn van afpersers !&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Doe het nu ! Morgen kan het te laat zijn.&lt;/span&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;Source : Microsoft malware protection center &lt;/span&gt;&lt;a href="http://goo.gl/o0aQY"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif; font-size: large;"&gt;http://goo.gl/o0aQY&lt;/span&gt;&lt;/a&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2601096556187183895-6014544929260541259?l=lucbeirens.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lucbeirens.blogspot.com/feeds/6014544929260541259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/tijd-om-een-backup-te-maken-en-deze-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/6014544929260541259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2601096556187183895/posts/default/6014544929260541259'/><link rel='alternate' type='text/html' href='http://lucbeirens.blogspot.com/2012/01/tijd-om-een-backup-te-maken-en-deze-in.html' title='Tijd om een backup te maken en deze in diverse versies apart te bewaren !'/><author><name>LucBeirens</name><uri>http://www.blogger.com/profile/11438522343913143253</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='23' src='http://4.bp.blogspot.com/-5ZrHY93qN04/TwiRjT5kKaI/AAAAAAAAWF8/ez9DmC3fCPE/s220/FCCU%2B-%2BBeirens%2BLuc%2B7%2Bklein.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-hkhXIrRHGjk/T0YzOxiggvI/AAAAAAAAWJM/UXhE14wXziM/s72-c/andere+landen.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
