<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Northwest Airlines email contains a trojan</title>
	<atom:link href="http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:53:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: dominic</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3998</link>
		<dc:creator><![CDATA[dominic]]></dc:creator>
		<pubDate>Tue, 20 Jan 2009 03:12:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3998</guid>
		<description><![CDATA[sorry, to add - McAfee offline scanner is in wintools folder

now don&#039;t ever open attachment from an unkown source again ;)]]></description>
		<content:encoded><![CDATA[<p>sorry, to add &#8211; McAfee offline scanner is in wintools folder</p>
<p>now don&#8217;t ever open attachment from an unkown source again <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dominic</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3997</link>
		<dc:creator><![CDATA[dominic]]></dc:creator>
		<pubDate>Tue, 20 Jan 2009 03:10:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3997</guid>
		<description><![CDATA[hi all

to those with non booting machines - download the latest copy of Hiren&#039;s boot disk and burn to CD, along with latest McAfee DAT update file.

Follow th instructions in the  README for updating the virus defs by placing them into C:\VDEFS and do an offline scan.]]></description>
		<content:encoded><![CDATA[<p>hi all</p>
<p>to those with non booting machines &#8211; download the latest copy of Hiren&#8217;s boot disk and burn to CD, along with latest McAfee DAT update file.</p>
<p>Follow th instructions in the  README for updating the virus defs by placing them into C:\VDEFS and do an offline scan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jen</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3994</link>
		<dc:creator><![CDATA[Jen]]></dc:creator>
		<pubDate>Sun, 18 Jan 2009 03:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3994</guid>
		<description><![CDATA[Cool. Thanks a ton for the alert.  Remember, any emails you don&#039;t know about, don&#039;t open!

http://www.squidoo.com/Trojan-Horse-Computer-Virus 

- Jen]]></description>
		<content:encoded><![CDATA[<p>Cool. Thanks a ton for the alert.  Remember, any emails you don&#8217;t know about, don&#8217;t open!</p>
<p><a href="http://www.squidoo.com/Trojan-Horse-Computer-Virus" rel="nofollow">http://www.squidoo.com/Trojan-Horse-Computer-Virus</a> </p>
<p>- Jen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: doom and gloom</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3992</link>
		<dc:creator><![CDATA[doom and gloom]]></dc:creator>
		<pubDate>Fri, 16 Jan 2009 21:06:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3992</guid>
		<description><![CDATA[received this today (after recently booking airline ticket with listed email address!), but googled to cjheck it and found this site  - Norton didn&#039;t catch it (not my pref choice of AV)

one customer has now just phoned in having executed it and crashed his PC - looks like it&#039;s spreading fast.  any suggested removal tools, or rootkit scanners new enough to pick it up?]]></description>
		<content:encoded><![CDATA[<p>received this today (after recently booking airline ticket with listed email address!), but googled to cjheck it and found this site  &#8211; Norton didn&#8217;t catch it (not my pref choice of AV)</p>
<p>one customer has now just phoned in having executed it and crashed his PC &#8211; looks like it&#8217;s spreading fast.  any suggested removal tools, or rootkit scanners new enough to pick it up?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frances</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3990</link>
		<dc:creator><![CDATA[Frances]]></dc:creator>
		<pubDate>Fri, 16 Jan 2009 15:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3990</guid>
		<description><![CDATA[help!!]]></description>
		<content:encoded><![CDATA[<p>help!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frances</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3989</link>
		<dc:creator><![CDATA[Frances]]></dc:creator>
		<pubDate>Fri, 16 Jan 2009 14:20:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3989</guid>
		<description><![CDATA[I opened this attatchment and now my computer will not operate at all. It will not start in safe mode either. Where do I go from here?]]></description>
		<content:encoded><![CDATA[<p>I opened this attatchment and now my computer will not operate at all. It will not start in safe mode either. Where do I go from here?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3985</link>
		<dc:creator><![CDATA[James]]></dc:creator>
		<pubDate>Thu, 15 Jan 2009 17:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3985</guid>
		<description><![CDATA[Please do not open the attachment and just delete.

Please remember, this email did not actually come from NWA just from some scammer.

George, you never got charged.  However, if you opened the attachment you may lose a lot more than $427.]]></description>
		<content:encoded><![CDATA[<p>Please do not open the attachment and just delete.</p>
<p>Please remember, this email did not actually come from NWA just from some scammer.</p>
<p>George, you never got charged.  However, if you opened the attachment you may lose a lot more than $427.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3983</link>
		<dc:creator><![CDATA[Thor]]></dc:creator>
		<pubDate>Thu, 15 Jan 2009 08:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3983</guid>
		<description><![CDATA[Thanks for the info--right on.  And very quick news release!  Who would ever open an .exe attachment anyways?  Could merely opening an email ever be dangerous?

Hey Hagglof--Jeg tinker deg ikke kan forstor svensk?  Tinker du englesk er bedder?

Tussen Tak MX Lab!]]></description>
		<content:encoded><![CDATA[<p>Thanks for the info&#8211;right on.  And very quick news release!  Who would ever open an .exe attachment anyways?  Could merely opening an email ever be dangerous?</p>
<p>Hey Hagglof&#8211;Jeg tinker deg ikke kan forstor svensk?  Tinker du englesk er bedder?</p>
<p>Tussen Tak MX Lab!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Herbig</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3982</link>
		<dc:creator><![CDATA[George Herbig]]></dc:creator>
		<pubDate>Wed, 14 Jan 2009 20:46:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3982</guid>
		<description><![CDATA[Hello Northwest:

I have been charged $427.30 for a ticket I did not order, apparently
part of this virus scam.  Would you please see that the charge against
my account is cancelled.

George Herbig]]></description>
		<content:encoded><![CDATA[<p>Hello Northwest:</p>
<p>I have been charged $427.30 for a ticket I did not order, apparently<br />
part of this virus scam.  Would you please see that the charge against<br />
my account is cancelled.</p>
<p>George Herbig</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anon</title>
		<link>http://blog.mxlab.eu/2009/01/13/northwest-airlines-email-contains-a-trojan/#comment-3981</link>
		<dc:creator><![CDATA[Anon]]></dc:creator>
		<pubDate>Wed, 14 Jan 2009 19:09:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.be/?p=324#comment-3981</guid>
		<description><![CDATA[If the email, but not the attachment, has been opened, what steps should be taken?
Thanks]]></description>
		<content:encoded><![CDATA[<p>If the email, but not the attachment, has been opened, what steps should be taken?<br />
Thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

