<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Ed Edited It Productions Blog</title>
    <link>http://www.ededitedit.com/lms/mod/forum/view.php?f=48</link>
    <description> The latest news and information from Ed Przyzycki, Executive Producer of Ed Edited It Productions.</description>
    <generator>Moodle</generator>
    <copyright>&amp;#169; 2010 Home</copyright>
    <image>
      <url>http://www.ededitedit.com/lms/theme/EdEditedIt_V2/pix/i/rsssitelogo.gif</url>
      <title>moodle</title>
      <link>http://www.ededitedit.com/lms</link>
      <width>140</width>
      <height>35</height>
    </image>
    <item>
      <category>Into eLearning? Want To Help The World?</category>
      <title>Into eLearning? Want To Help The World?</title>
      <link>http://www.ededitedit.com/lms/mod/forum/discuss.php?d=45&amp;parent=55</link>
      <pubDate>Tue, 09 Mar 2010 15:35:26 GMT</pubDate>
      <description>by Ed Edited It Productions (Admin). &amp;nbsp;&lt;p&gt;Support &lt;a href=&quot;http://ngolearning.org/default.aspx&quot; target=&quot;_blank&quot; title=&quot;Lingos&quot;&gt;LINGOs&lt;/a&gt;! (Learning for International Non-Governmental Organizations) Donate your skills - author course content, build interactions, manage their LMS, and more. LINGOs provides the latest elearning technologies and courses to non-profit entities such as Habitat for Humanity, Save the Children and World Relief. Support helps increase the skill levels of non-profit employees, and therefore increasing the impact of their programs. &lt;/p&gt;</description>
      <guid isPermaLink="true">http://www.ededitedit.com/lms/mod/forum/discuss.php?d=45&amp;parent=55</guid>
    </item>
    <item>
      <category>Are You Naughty or Nice? Find out INSTANTLY!</category>
      <title>Are You Naughty or Nice? Find out INSTANTLY!</title>
      <link>http://www.ededitedit.com/lms/mod/forum/discuss.php?d=44&amp;parent=54</link>
      <pubDate>Sat, 19 Dec 2009 22:49:24 GMT</pubDate>
      <description>by Ed Edited It Productions (Admin). &amp;nbsp;&lt;p&gt;Write a quick letter to Santa. Tell him what you want, and why you deserve it. Will you get everything you asked for? Find out, INSTANTLY! I wish I could have been able to practice my letters to Santa! &lt;a href=&quot;http://www.ededitedit.com/lms/course/view.php?id=35&quot;&gt;http://www.ededitedit.com/lms/course/view.php?id=35&lt;/a&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://www.ededitedit.com/lms/mod/forum/discuss.php?d=44&amp;parent=54</guid>
    </item>
    <item>
      <category>..Your Computer Has A Virus, But Nothing Detects It...</category>
      <title>..Your Computer Has A Virus, But Nothing Detects It...</title>
      <link>http://www.ededitedit.com/lms/mod/forum/discuss.php?d=43&amp;parent=53</link>

<enclosure url='http://www.safer-networking.org/index2.html' type='text/html' />

<enclosure url='http://www.mozilla.com/en-US/firefox/upgrade.html' type='text/html' />

<enclosure url='http://www.iobit.com/security360.html' type='text/html' />

<enclosure url='http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html' type='text/html' />

<enclosure url='http://www.malwarebytes.org/mbam.php' type='text/plain' />

<enclosure url='http://help.lockergnome.com/security/Google-Hijack-virus--ftopict10008.html' type='text/html' />
      <pubDate>Thu, 17 Dec 2009 04:32:19 GMT</pubDate>
      <description>by Ed Edited It Productions (Admin). &amp;nbsp;&lt;p&gt;&lt;p&gt;I didn't think it was possible. I have &lt;a href=&quot;http://www.mcafee.com/us/&quot; target=&quot;_blank&quot;&gt;McAfee Anti-Virus&lt;/a&gt;, &lt;a href=&quot;http://www.zonealarm.com/security/en-us/home.htm?lid=en-us&quot; target=&quot;_blank&quot;&gt;CheckPoint Zone Alarm&lt;/a&gt;, &lt;a href=&quot;http://www.safer-networking.org/index2.html&quot; target=&quot;_blank&quot;&gt;SpyBot Search &amp;amp; Destroy&lt;/a&gt;, and more... Yet, suddenly when I Googled, my search results &amp;quot;&lt;a href=&quot;http://en.wikipedia.org/wiki/Page_hijacking&quot; target=&quot;_blank&quot;&gt;hijacked&lt;/a&gt;&amp;quot; me to places I didn't want to go. I felt violated. Was my data secure? How can this happen? What could I do? This is my story, along with 10 tips-and-tricks to help if it happens to you. &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Myth:&lt;/span&gt; &lt;span style=&quot;font-style: italic&quot;&gt;If you have anti-virus software installed, updated, and running, you keep your computer &amp;quot;up-to-date&amp;quot;, you don't open unsolicited email (or attachments) and you don’t go to “unusual” websites, your computer should be safe. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-style: italic; font-weight: bold&quot;&gt;That’s what I thought.&lt;/span&gt; I have my computers scan for viruses at least once a week. All drives &lt;a href=&quot;http://www.microsoft.com/windows/windows-vista/features/backup.aspx&quot; target=&quot;_blank&quot;&gt;automatically get backed up&lt;/a&gt; at least once a week. I have security programs which stay updated. Windows Update is on and checking for patches. Since I do web development and some Flash coding for a living, I thought I knew it all. I was wrong. &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;It started when&lt;/span&gt; I was &lt;a href=&quot;http://www.google.com/&quot; target=&quot;_blank&quot;&gt;Googling&lt;/a&gt; in &lt;a href=&quot;http://www.microsoft.com/windows/Internet-explorer/&quot; target=&quot;_blank&quot;&gt;Internet Explorer 8&lt;/a&gt;. Every once in a while, a search result would take me someplace strange. Then it started happening more often. Things were fine in &lt;a href=&quot;http://www.mozilla.com/en-US/firefox/upgrade.html&quot; target=&quot;_blank&quot;&gt;Firefox 3.5.6&lt;/a&gt;, then it started happening there. Now, add random pop-ups to the list. &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;At first, I didn’t worry. I ran McAfee. It found nothing.&lt;/span&gt; I knew that was false- this is a classic Trojan or Hijack… Ok, let me try SpyBot Search &amp;amp; Destroy, I thought. Nothing. Ok, how about &lt;a href=&quot;http://www.iobit.com/security360.html&quot; target=&quot;_blank&quot;&gt;IOBit Security 360&lt;/a&gt;? Nothing. Was I going crazy? Google searching (when I was actually able to) suggested &lt;a href=&quot;http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html&quot; target=&quot;_blank&quot;&gt;HiJack This&lt;/a&gt;. Nothing. &lt;a href=&quot;http://www.malwarebytes.org/mbam.php&quot; target=&quot;_blank&quot;&gt;Malwarebytes' Anti-Malware&lt;/a&gt;? Nothing. The list kept growing. &lt;/p&gt;
&lt;p&gt;There’s a lot of &lt;a href=&quot;http://help.lockergnome.com/security/Google-Hijack-virus--ftopict10008.html&quot; target=&quot;_blank&quot;&gt;internet sites that offer suggestions&lt;/a&gt;- download this piece of software, disable your current anti-virus (it conflicts with the download), run this other application that I never heard about. Post the result logs on some website that tell the world what you have installed. The sites promise that someone will get back to you. It results in more software downloads, more logs, more tests. Meanwhile, these applications are doing who knows what to your computer. &lt;span style=&quot;font-weight: bold&quot;&gt;More problems result.&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;I didn’t take this approach. Maybe it’s because I don’t trust anyone. “I’m a programmer, &lt;span style=&quot;font-weight: bold&quot;&gt;there’s got to be a logic to this.&lt;/span&gt;” I thought. I was right. &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;First, try to isolate the problem. &lt;/span&gt;Let me uninstall Internet Explorer 8 and only use Firefox. The problem went away. You would think the story would end there, but it can’t. A lot of software requires &lt;a href=&quot;http://en.wikipedia.org/wiki/Dynamic-link_library&quot; target=&quot;_blank&quot;&gt;.dll files&lt;/a&gt; that get uninstalled when IE is uninstalled. So my symptoms went away, but now other software didn’t work- and was the hijack/Trojan still around? &lt;/p&gt;
&lt;p&gt;Next- Ok, &lt;span style=&quot;font-weight: bold&quot;&gt;let’s try to figure out what’s going on when I search in Google&lt;/span&gt;. I have a router on my network, so I was able to view network traffic logs. That’s when I noticed the first sign. When I went to Google.com, not only did my logs report Google IP/http addresses, it also reported http://b11335599.cn. This didn’t make any sense. It’s certainly something out of place. &lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img width=&quot;838&quot; height=&quot;777&quot; title=&quot;Router Logs&quot; alt=&quot;Router Logs&quot; src=&quot;http://www.ededitedit.com/lms/file.php/1/router_logs.jpg&quot; border=&quot;0&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; complete=&quot;true&quot; /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-style: italic; text-decoration: underline&quot;&gt;Above:&lt;/span&gt;&lt;span style=&quot;font-style: italic&quot;&gt; If you have a router (or other anti-virus software) that can track network traffic, that will help you troubleshoot what's going on. You'll need to login to your router (typically &lt;a href=&quot;http://192.168.0.1&quot;&gt;http://192.168.0.1&lt;/a&gt;), enable and view logs, know your internal LAN IP address so you can differentiate it from other computers on your network (mine is 192.168.0.252), and track destination URLs and IPs. &lt;/span&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;When I saw the strange&lt;/span&gt; &amp;quot;http://b11335599.cn&amp;quot; appear in my list, I Googled that http address, and only saw one search result. Yep, it’s a hijack. Actually, worse. It’s a Rootkit TDL 3. &lt;a href=&quot;http://forum.sysinternals.com/forum_posts.asp?TID=21266&amp;PN=4&quot; target=&quot;_blank&quot;&gt;Here's the link I found, and note that it actually shows what programming was used to create the virus!&lt;/a&gt; (That's scary!) &lt;a href=&quot;http://www.rootkit.com/blog.php?newsid=970&quot; target=&quot;_blank&quot;&gt;Rootkit TDL 3&lt;/a&gt; is a fancy way of saying it’s something that is NOT EASILY DETECTABLE by anti-virus software. Worse, it “injects” itself into other applications, making it even harder to detect. These viruses can do almost anything. My version (besides the hijack) also erases and destroys hard drives that contain backup data files. Yes, it searches for those files and destroys them! (uh-oh!) &lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Since it infects files that are currently running as part of Windows, you can’t disable them without disabling Windows.&lt;/span&gt; With Windows disabled, you really can’t fix anything. &lt;/p&gt;
&lt;p&gt;Lucky for me, one software application was able to detect and repair &lt;span style=&quot;font-weight: bold&quot;&gt;Rootkit TDL 3&lt;/span&gt;s. &lt;a href=&quot;http://www.surfright.nl/en/hitmanpro&quot; target=&quot;_blank&quot;&gt;Hitman Pro 3.5.3&lt;/a&gt; did the trick for me. (I certainly can’t guarantee it will fix everything – I’m not necessarily endorsing this product – it just &lt;a href=&quot;http://forum.sysinternals.com/forum_posts.asp?TID=21266&amp;PN=5&quot; target=&quot;_blank&quot;&gt;worked for me in this instance&lt;/a&gt;. Something better may work for you, it depends on your symptoms.) &lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img width=&quot;704&quot; height=&quot;565&quot; title=&quot;Rootkit&quot; alt=&quot;Rootkit&quot; src=&quot;http://www.ededitedit.com/lms/file.php/1/rootkit.jpg&quot; border=&quot;0&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; complete=&quot;true&quot; /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-style: italic; text-decoration: underline&quot;&gt;Above:&lt;/span&gt;&lt;span style=&quot;font-style: italic&quot;&gt; Hitman Pro shows the virus. It was the only application that could find it. I tried over 10.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;So things are back to “normal”, at least for the time being. Here are some lessons learned. &lt;/p&gt;
&lt;p&gt;1&lt;span style=&quot;font-weight: bold&quot;&gt;) Anti-virus programs and malware detection programs don’t catch everything. It’s a false sense of security. You need to have a disaster plan. &lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;2) You need to have a backup disaster plan. These viruses are so tough now that they actively go after backup and restore files. So, even if you’ve backed up data, it might not be secure. &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;3) If you have to do a Windows Restore, be prepared to reinstall your anti-virus software. Usually the Windows Restore process doesn’t work well with these applications. &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;4) You may have to work in Windows Safe Mode to search and destroy viruses. That means that you may not have network support, and certain “devices” like external drives may not work. You might need a way to copy files to this computer. So, you may need a “second” computer to work with, along with a portable drive of some sort, or even a floppy disk. Remember those? &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;5) Backup data weekly - automatically to an external drive. Then, backup important files manually once a week onto a removable USB drive and keep that drive disconnected from your computer. (Re-writable cd-roms, DVD or portable USB drives work well here) &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;6) Keep a Windows Operating System CD handy. &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;7) Know the serial numbers of all your important software. Keep a hard-copy printout. &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;8) Print out your email addresses (Outlook address book) and your Internet Favorites URLs. &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;9) Keep an old computer around. Keep it disconnected from your network, but keep it updated. It can serve as a backup if you main computer is under attack. (Of course, PDAs could work for checking email, etc) &lt;/p&gt;
&lt;p style=&quot;font-weight: bold&quot;&gt;10) Take time now to learn how your router works, if you have one. Figure out how to monitor network traffic, so you can detect “strange” traffic when you suspect something is wrong. Be familiar with your network &lt;a href=&quot;http://en.wikipedia.org/wiki/Firewall&quot; target=&quot;_blank&quot;&gt;firewall&lt;/a&gt;- how to enable and disable it. Have a basic understanding of “&lt;a href=&quot;http://en.wikipedia.org/wiki/TCP_and_UDP_port&quot; target=&quot;_blank&quot;&gt;ports&lt;/a&gt;”.I NEVER use &lt;a href=&quot;http://en.wikipedia.org/wiki/Peer-to-peer&quot; target=&quot;_blank&quot;&gt;P2P&lt;/a&gt; file sharing, because it opens your ports. &lt;a href=&quot;http://www.microsoft.com/windows/windowsmedia/player/faq/sharing.mspx&quot; target=&quot;_blank&quot;&gt;Enabling Windows Media Sharing&lt;/a&gt; is just as scary. Keep it off if you can.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Well, that’s my attempt at sharing my story. I hope it helps someone. Good luck! &lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://www.ededitedit.com/lms/mod/forum/discuss.php?d=43&amp;parent=53</guid>
    </item>
    <item>
      <category>Ed's at the Chicago eLearning &amp; Technology Showcase on 8/19/09</category>
      <title>Ed's at the Chicago eLearning &amp; Technology Showcase on 8/19/09</title>
      <link>http://www.ededitedit.com/lms/mod/forum/discuss.php?d=42&amp;parent=52</link>

<enclosure url='http://www.chicagoelearningshowcase.com/sessions.html' type='text/html' />
      <pubDate>Wed, 19 Aug 2009 12:36:13 GMT</pubDate>
      <description>by Ed Edited It Productions (Admin). &amp;nbsp;&lt;p&gt; I got a last minute opportunity to attend the &lt;a title=&quot;Chicago eLearning &amp; Technology Showcase&quot; href=&quot;http://www.chicagoelearningshowcase.com/sessions.html&quot; target=&quot;_blank&quot;&gt;Chicago eLearning &amp;amp; Technology Showcase&lt;/a&gt; today. I hope to see a lot of you there! &lt;a title=&quot;Here are some examples&quot; target=&quot;_blank&quot; href=&quot;http://www.ededitedit.com/lms/course/view.php?id=3&quot;&gt;Here are some examples&lt;/a&gt; of eLearning that I have put together in the past. Right now I'm doing a lot of work in Flash CS4/AS3 with dynamic data and XML/DITA integration. &lt;a title=&quot;Let's keep in touch!&quot; target=&quot;_blank&quot; href=&quot;http://www.ededitedit.com/lms/course/view.php?id=21&quot;&gt;Let's keep in touch!&lt;/a&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://www.ededitedit.com/lms/mod/forum/discuss.php?d=42&amp;parent=52</guid>
    </item>
    <item>
      <category>Ed Przyzycki is on Facebook!</category>
      <title>Ed Przyzycki is on Facebook!</title>
      <link>http://www.ededitedit.com/lms/mod/forum/discuss.php?d=41&amp;parent=51</link>
      <pubDate>Wed, 19 Aug 2009 03:25:56 GMT</pubDate>
      <description>by Ed Edited It Productions (Admin). &amp;nbsp;&lt;p&gt;&lt;p&gt;Well, in case you haven't heard, I'm officially on Facebook. &lt;a title=&quot;You can check me out here.&quot; href=&quot;http://www.facebook.com/people/Edward-R-Przyzycki/100000127127303&quot; target=&quot;_blank&quot;&gt;You can check me out here.&lt;/a&gt; Search for Edward R. Przyzycki. I'm not sure exactly what I'll end up doing on it, or for how long, but I figured it's time to take the plunge. Of course, you can always visit the blog and website back at &lt;a href=&quot;http://www.ededitedit.com/&quot;&gt;http://www.ededitedit.com&lt;/a&gt;!&lt;/p&gt;
&lt;p&gt;Ed Przyzycki, Executive Producer&lt;/p&gt;
&lt;p&gt;Ed Edited It Productions&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://www.ededitedit.com/lms/mod/forum/discuss.php?d=41&amp;parent=51</guid>
    </item>
  </channel>
</rss>