<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Donna&amp;#39;s SecurityFlash - All Comments</title><link>http://msmvps.com/blogs/donna/default.aspx</link><description>PC &amp;amp; Internet Security Blog</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><item><title>re: Malware SPAM:  We have hijacked your baby</title><link>http://msmvps.com/blogs/donna/archive/2008/08/26/malware-spam-we-have-hijacked-your-baby.aspx#1646140</link><pubDate>Fri, 29 Aug 2008 01:34:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646140</guid><dc:creator>Alan Y.</dc:creator><description>&lt;p&gt;Well, as far as the success rate, I can&amp;#39;t tell. But it&amp;#39;s definitely a broad email, sent out by the Rustock botnet (1 of 2 of the worlds top spam disros sent 60% of all spam in the world this last week)&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve been getting notifications from gmail telling me that they&amp;#39;ve been receiving such emails, and that they won&amp;#39;t forward them to me, because the scanners found the malware.&lt;/p&gt;
&lt;p&gt;Normally the botnet is just a spam producer, but recently they&amp;#39;ve resorted to malware, that turns your computer into a zombie, and basically makes it act as a spam server, which sends out more spam without you knowing.&lt;/p&gt;
&lt;p&gt;Somehow though, someone on our network last night opened it, and it installed the rustock.c rootkit which just in a matter of minutes, spread through our entire network... so I come in to work this morning and see 125 bluescreens... what a sight... I have not yet been able to remove the rootkit at all... everything i&amp;#39;ve read and tried, has been blocked by the rootkit. such as running tools or executable&amp;#39;s or apps that are supposed to remove it... i get different violations..&lt;/p&gt;
&lt;p&gt;O_o one of them i ran, came up with a cmd error that said some kind of error, then said &amp;quot;Good Luck! press any key to continue&amp;quot; ?!?! o_O&lt;/p&gt;
&lt;p&gt;Anyways, I&amp;#39;d recommend gmail, as they will block &amp;nbsp;anythign malicious they find in emails, and they won&amp;#39;t send the emails to you. however they do send you a notification regarding the email and who it&amp;#39;s from, letting you know there was malware attached.&lt;/p&gt;
&lt;p&gt;I also would recommend barracuda firewalls, as other networks i happen to administrate, use them, and have never had any spam emails at all, or any regarding issue&amp;#39;s.&lt;/p&gt;
&lt;p&gt;Good Luck!&lt;/p&gt;
&lt;p&gt;Press any key to continue...&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1646140" width="1" height="1"&gt;</description></item><item><title>re: Rogue Software using ImageShack to spread itself</title><link>http://msmvps.com/blogs/donna/archive/2008/08/28/rogue-software-using-imageshack-to-spread-itself.aspx#1646080</link><pubDate>Thu, 28 Aug 2008 13:08:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646080</guid><dc:creator>Randy Knobloch</dc:creator><description>&lt;p&gt;I use photobucket, Donna - but lately, it&amp;#39;s gotten /much/ worse.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1646080" width="1" height="1"&gt;</description></item><item><title>re: New Rogue Program: AndromedaAV</title><link>http://msmvps.com/blogs/donna/archive/2008/08/27/new-rogue-program-andromedaav.aspx#1645980</link><pubDate>Wed, 27 Aug 2008 15:03:36 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645980</guid><dc:creator>TeMerc</dc:creator><description>&lt;p&gt;Not sure who found it first, but Meikienoes wrote about it on Aug 25:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://miekiemoes.blogspot.com/2008/08/andromeda-av-and-antivirus-pro-2008-new.html"&gt;miekiemoes.blogspot.com/.../andromeda-av-and-antivirus-pro-2008-new.html&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645980" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: XP Official Update 2008</title><link>http://msmvps.com/blogs/donna/archive/2008/08/26/malware-spam-xp-official-update-2008.aspx#1645900</link><pubDate>Tue, 26 Aug 2008 22:21:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645900</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Hi Brenn,&lt;/p&gt;
&lt;p&gt;Please use any removal tools below:&lt;/p&gt;
&lt;p&gt;Malwarebytes Antimalware - &lt;a rel="nofollow" target="_new" href="http://www.malwarebytes.org/mbam.php"&gt;www.malwarebytes.org/mbam.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A-squared Free - &lt;a rel="nofollow" target="_new" href="http://www.emsisoft.com"&gt;http://www.emsisoft.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SUPERAntispyware - &lt;a rel="nofollow" target="_new" href="http://www.superantispyware.com"&gt;www.superantispyware.com&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645900" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM:  We have hijacked your baby</title><link>http://msmvps.com/blogs/donna/archive/2008/08/26/malware-spam-we-have-hijacked-your-baby.aspx#1645874</link><pubDate>Tue, 26 Aug 2008 16:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645874</guid><dc:creator>J.Janson</dc:creator><description>&lt;p&gt;yes, i have received this email at least once a day over the past 2 days. Thankfully my Avast scanner is able to detect and delete it before downloading the email. I just wonder what is the rate of success for such spam malware emails.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645874" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: XP Official Update 2008</title><link>http://msmvps.com/blogs/donna/archive/2008/08/26/malware-spam-xp-official-update-2008.aspx#1645861</link><pubDate>Tue, 26 Aug 2008 14:59:59 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645861</guid><dc:creator>brenn</dc:creator><description>&lt;p&gt;how to remove this &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645861" width="1" height="1"&gt;</description></item><item><title>re: A news and a malware: Journalists shot in Georgia - Georgia.zip (joined.exe)</title><link>http://msmvps.com/blogs/donna/archive/2008/08/19/a-news-and-a-malware-journalists-shot-in-georgia-georgia-zip-joined-exe.aspx#1645274</link><pubDate>Wed, 20 Aug 2008 21:07:07 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645274</guid><dc:creator>robert</dc:creator><description>&lt;p&gt;I have received this also. One with the news story about journalist. And about 10 samples with a story about Britney Spears and Anna Smith. All contain Georgia.zip with password 123&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645274" width="1" height="1"&gt;</description></item><item><title>re: Another Rogue domain of Antivirus XP 2008</title><link>http://msmvps.com/blogs/donna/archive/2008/08/15/another-rogue-domain-of-antivirus-xp-2008.aspx#1645145</link><pubDate>Wed, 20 Aug 2008 04:34:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645145</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Hi Shea and Jonathan,&lt;/p&gt;
&lt;p&gt;Please use the following free scanner and removal:&lt;/p&gt;
&lt;p&gt;Malwarebytes Antimalware - &lt;a rel="nofollow" target="_new" href="http://www.malwarebytes.org/mbam.php"&gt;www.malwarebytes.org/mbam.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;a-squared Free - &lt;a rel="nofollow" target="_new" href="http://www.emsisoft.com/en/software/free/"&gt;www.emsisoft.com/.../free&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SUPERAntispyware Free - &lt;a rel="nofollow" target="_new" href="http://www.superantispyware.com"&gt;www.superantispyware.com&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645145" width="1" height="1"&gt;</description></item><item><title>re: Another Rogue domain of Antivirus XP 2008</title><link>http://msmvps.com/blogs/donna/archive/2008/08/15/another-rogue-domain-of-antivirus-xp-2008.aspx#1645029</link><pubDate>Tue, 19 Aug 2008 08:59:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645029</guid><dc:creator>Jonathan Fenn</dc:creator><description>&lt;p&gt;Any idea how to get it off my computer?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645029" width="1" height="1"&gt;</description></item><item><title>re: Another Rogue domain of Antivirus XP 2008</title><link>http://msmvps.com/blogs/donna/archive/2008/08/15/another-rogue-domain-of-antivirus-xp-2008.aspx#1644977</link><pubDate>Mon, 18 Aug 2008 20:59:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644977</guid><dc:creator>Shea</dc:creator><description>&lt;p&gt;How do I delete this off of my pc it always popu up&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644977" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1644608</link><pubDate>Thu, 14 Aug 2008 05:25:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644608</guid><dc:creator>Dagda</dc:creator><description>&lt;p&gt;BTW: they are now coming from MSNBC alerts. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644608" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1644488</link><pubDate>Wed, 13 Aug 2008 08:21:12 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644488</guid><dc:creator>Tony ng</dc:creator><description>&lt;p&gt;I want to the CNN Alerts sender IP address&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644488" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1644435</link><pubDate>Tue, 12 Aug 2008 20:15:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644435</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Guys,&lt;/p&gt;
&lt;p&gt;Run a scan using any of the following:&lt;/p&gt;
&lt;p&gt;SUPERAntispyware: &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://www.superantispyware.com"&gt;www.superantispyware.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Malwarebytes Antimalware: &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://www.malwarebytes.org/mbam.php"&gt;www.malwarebytes.org/mbam.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A-squared Free: &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://emsisoft.com"&gt;http://emsisoft.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can also use online scanners. &amp;nbsp;Most antivirus should detect this malware already so please update your antivirus then run a full system scan.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644435" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1644279</link><pubDate>Mon, 11 Aug 2008 18:00:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644279</guid><dc:creator>Ale</dc:creator><description>&lt;p&gt;hi! but how can i remove it? it&amp;#39;s so annoying :S&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644279" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1644231</link><pubDate>Mon, 11 Aug 2008 13:50:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644231</guid><dc:creator>emerson gareca</dc:creator><description>&lt;p&gt;Peter, that email address means nothing. You can set that data when you send an e-mail, even if it&amp;#39;s not real. &lt;/p&gt;
&lt;p&gt;The true identifier is the sender ip address.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644231" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAM: CNN Alerts: My Custom Alert is link to adobe_flash.exe</title><link>http://msmvps.com/blogs/donna/archive/2008/08/08/malware-spam-cnn-alerts-my-custom-alert-is-link-to-adobe-flash-exe.aspx#1643974</link><pubDate>Fri, 08 Aug 2008 18:59:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643974</guid><dc:creator>Peter</dc:creator><description>&lt;p&gt;for some stupid reason, when I look at the email address, it comes from fedex.com. gee, I didn&amp;#39;t know they teamed up, how nice of them to do this!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643974" width="1" height="1"&gt;</description></item><item><title>re: NextAdvisor.com Launches Guide to Internet Security Software Providers</title><link>http://msmvps.com/blogs/donna/archive/2008/08/06/nextadvisor-com-launches-guide-to-internet-security-software-providers.aspx#1643891</link><pubDate>Fri, 08 Aug 2008 06:35:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643891</guid><dc:creator>Ric:^D.</dc:creator><description>&lt;p&gt;Donna. &amp;nbsp;Although it is nice to see another comparison of security services, I feel there is not enough info. &amp;nbsp;Looking at their chart it looks like all I need is one of the top ones and all wiil be wonderful!! &amp;nbsp;Oh boy, hope no newbif goes here and thinks like I do. &amp;nbsp;WHEW!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643891" width="1" height="1"&gt;</description></item><item><title>re: Malware SPAMs: CNN.com Daily Top 10, Your order and Yourlettercard</title><link>http://msmvps.com/blogs/donna/archive/2008/08/05/malware-spams-cnn-com-daily-top-10-your-order-and-yourlettercard.aspx#1643882</link><pubDate>Fri, 08 Aug 2008 03:57:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643882</guid><dc:creator>Roger Chiu</dc:creator><description>&lt;p&gt;So far no removal tool available, but you can refer to &lt;a rel="nofollow" target="_new" href="http://malware-test-lab.blogspot.com/2008/08/fake-cnncom-daily-top-10-malware.html"&gt;malware-test-lab.blogspot.com/.../fake-cnncom-daily-top-10-malware.html&lt;/a&gt;.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643882" width="1" height="1"&gt;</description></item><item><title>re: Microsoft released Virtual PC 2007 Service Pack 1</title><link>http://msmvps.com/blogs/donna/archive/2008/05/16/microsoft-released-virtual-pc-2007-service-pack-1.aspx#1643706</link><pubDate>Thu, 07 Aug 2008 13:00:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643706</guid><dc:creator>AW</dc:creator><description>&lt;p&gt;Windows Updates install keep failing in Virtual PC 2007 service pack 1 with the host windows xp sp3. &amp;nbsp;Does anyone out there know how to fix it please? &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643706" width="1" height="1"&gt;</description></item><item><title>Rogue Antispyware Adware-Download</title><link>http://msmvps.com/blogs/donna/archive/2008/08/06/new-domains-of-rogue-antivirus-xp-2008.aspx#1643696</link><pubDate>Thu, 07 Aug 2008 10:51:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643696</guid><dc:creator>Hosts News</dc:creator><description>&lt;p&gt;Following up on a post at Donna&amp;#39;s SecurityFlash regarding several new Rogue Antispyware programs&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643696" width="1" height="1"&gt;</description></item></channel></rss>