<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for mxlab - all about anti virus and anti spam</title>
	<atom:link href="http://blog.mxlab.eu/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:53:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on New trojan variant in emails with subject &#8220;DHL Delivery Notification Message&#8221; by Leanne Jeans</title>
		<link>http://blog.mxlab.eu/2011/11/30/new-trojan-variant-in-emails-with-subject-dhl-delivery-notification-message/#comment-17581</link>
		<dc:creator><![CDATA[Leanne Jeans]]></dc:creator>
		<pubDate>Thu, 09 Feb 2012 14:53:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1541#comment-17581</guid>
		<description><![CDATA[L.Jeans
I had no idea that this had been a problem. I am normally very aware of things like this. Can anyone advise me on what to do? Or how it can affect my computer??]]></description>
		<content:encoded><![CDATA[<p>L.Jeans<br />
I had no idea that this had been a problem. I am normally very aware of things like this. Can anyone advise me on what to do? Or how it can affect my computer??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DHL Express Notification with malware attached by Perry Glasser</title>
		<link>http://blog.mxlab.eu/2011/10/27/dhl-express-notification-with-malware-attached/#comment-17568</link>
		<dc:creator><![CDATA[Perry Glasser]]></dc:creator>
		<pubDate>Tue, 07 Feb 2012 22:32:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1488#comment-17568</guid>
		<description><![CDATA[I got three at once]]></description>
		<content:encoded><![CDATA[<p>I got three at once</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Directory scam: Registration of the World Company Register 2011/2012 by Marcos</title>
		<link>http://blog.mxlab.eu/2010/10/14/directory-scam-registration-of-the-world-company-register-20112012/#comment-17565</link>
		<dc:creator><![CDATA[Marcos]]></dc:creator>
		<pubDate>Tue, 07 Feb 2012 14:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1158#comment-17565</guid>
		<description><![CDATA[Never respond to them. This is the only way to leave you in peace...
Since you answer they are happy and run behind you...]]></description>
		<content:encoded><![CDATA[<p>Never respond to them. This is the only way to leave you in peace&#8230;<br />
Since you answer they are happy and run behind you&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Directory scam: Registration of the World Company Register 2011/2012 by Srinivas</title>
		<link>http://blog.mxlab.eu/2010/10/14/directory-scam-registration-of-the-world-company-register-20112012/#comment-17564</link>
		<dc:creator><![CDATA[Srinivas]]></dc:creator>
		<pubDate>Tue, 07 Feb 2012 13:33:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1158#comment-17564</guid>
		<description><![CDATA[If anyone of you has friends who can hack sites this is the time to use them.
Bring down the websites of EU business Directory and crash the servers who host such companies.
Make them run for cover by keeping their websites crashed all the time.
Even their mails will not work and that will prevent them from disturbing people.]]></description>
		<content:encoded><![CDATA[<p>If anyone of you has friends who can hack sites this is the time to use them.<br />
Bring down the websites of EU business Directory and crash the servers who host such companies.<br />
Make them run for cover by keeping their websites crashed all the time.<br />
Even their mails will not work and that will prevent them from disturbing people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Emails from USPS with subject Your Postal Package N*** contains a trojan by Nathan</title>
		<link>http://blog.mxlab.eu/2010/04/28/emails-from-usps-with-subject-your-postal-package-n-contains-a-trojan/#comment-17560</link>
		<dc:creator><![CDATA[Nathan]]></dc:creator>
		<pubDate>Mon, 06 Feb 2012 17:10:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=821#comment-17560</guid>
		<description><![CDATA[You&#039;re probably in &quot;Safe Mode&quot; which turns your screen back into a command user based interface instead of a graphics user based interface.

When I restart my computer, it gives me the option of using either &quot;Safe Mode&quot; or something like &quot;Start Windows Normally.&quot; You want to click that.

All this is assuming the virus hasn&#039;t already corrupted your system and won&#039;t allow you to go back. If that is the case, find someone with intense computer knowledge or hire someone from &quot;Geek Squad&quot; to help you.

Hope this helps...]]></description>
		<content:encoded><![CDATA[<p>You&#8217;re probably in &#8220;Safe Mode&#8221; which turns your screen back into a command user based interface instead of a graphics user based interface.</p>
<p>When I restart my computer, it gives me the option of using either &#8220;Safe Mode&#8221; or something like &#8220;Start Windows Normally.&#8221; You want to click that.</p>
<p>All this is assuming the virus hasn&#8217;t already corrupted your system and won&#8217;t allow you to go back. If that is the case, find someone with intense computer knowledge or hire someone from &#8220;Geek Squad&#8221; to help you.</p>
<p>Hope this helps&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8216;DHL Notification&#8217; with tracking number in attachment is a trojan by Dave</title>
		<link>http://blog.mxlab.eu/2011/03/08/dhl-notification-with-tracking-number-in-attachment-is-a-trojan/#comment-17543</link>
		<dc:creator><![CDATA[Dave]]></dc:creator>
		<pubDate>Sat, 04 Feb 2012 17:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1269#comment-17543</guid>
		<description><![CDATA[Add another dummy to the list.  On 1/31/12  I got the DHLtracking email and in a moment of stupidity I tried to open the attachment, didn&#039;t see it was a zip file.  After a bit I realized I had been had.  Used my AVG malware scanner to check both the zip and exe files.  Both were clean.  I was still worried so I did a system restore to a few days earlier.  I also searched out and trashed any files with DHL in them, only about 3 or 4.   I also trashed all temp internet files created on that date.

A couple days later AVG finally found the Trojan horse threat,&quot;Trojan Horse Crypt.APKO&quot; located in C;\system volume information\..  AVG put it into the AVG Virus vault where it will be automatically eliminated in a user defined time period - I chose 2 days, the default is 30.

Everything seems ok on the PC with one exception. Initially I could not connect to the Internet. I found the driver was disabled by looking in the Hardware Device Manager.  Now, I cannot disconnect without going back into the Device Manager. I am not sure if it is due to the malware or if I was too zealous in deleting files back on the 31st.   I cannot disconnect or disable the PC from the Internet. I tried uninstalling and reinstalling the NIC driver from D-Link with no success (I checked and found I had the latest rev.).

This message is being entered on another PC.  I have physically disconnected the infected PC and am not sure if it is safe to use.

My questions:
1)  What happens to an affected PC?  Does the malware steal files`or info?  Does it disable anything?

2) How do I ensure I have killed it?

Thanks in advance for any help.

Dave]]></description>
		<content:encoded><![CDATA[<p>Add another dummy to the list.  On 1/31/12  I got the DHLtracking email and in a moment of stupidity I tried to open the attachment, didn&#8217;t see it was a zip file.  After a bit I realized I had been had.  Used my AVG malware scanner to check both the zip and exe files.  Both were clean.  I was still worried so I did a system restore to a few days earlier.  I also searched out and trashed any files with DHL in them, only about 3 or 4.   I also trashed all temp internet files created on that date.</p>
<p>A couple days later AVG finally found the Trojan horse threat,&#8221;Trojan Horse Crypt.APKO&#8221; located in C;\system volume information\..  AVG put it into the AVG Virus vault where it will be automatically eliminated in a user defined time period &#8211; I chose 2 days, the default is 30.</p>
<p>Everything seems ok on the PC with one exception. Initially I could not connect to the Internet. I found the driver was disabled by looking in the Hardware Device Manager.  Now, I cannot disconnect without going back into the Device Manager. I am not sure if it is due to the malware or if I was too zealous in deleting files back on the 31st.   I cannot disconnect or disable the PC from the Internet. I tried uninstalling and reinstalling the NIC driver from D-Link with no success (I checked and found I had the latest rev.).</p>
<p>This message is being entered on another PC.  I have physically disconnected the infected PC and am not sure if it is safe to use.</p>
<p>My questions:<br />
1)  What happens to an affected PC?  Does the malware steal files`or info?  Does it disable anything?</p>
<p>2) How do I ensure I have killed it?</p>
<p>Thanks in advance for any help.</p>
<p>Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Emails from USPS with subject Your Postal Package N*** contains a trojan by Richard Middleton</title>
		<link>http://blog.mxlab.eu/2010/04/28/emails-from-usps-with-subject-your-postal-package-n-contains-a-trojan/#comment-17532</link>
		<dc:creator><![CDATA[Richard Middleton]]></dc:creator>
		<pubDate>Fri, 03 Feb 2012 06:55:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=821#comment-17532</guid>
		<description><![CDATA[In my case the purported sender was &quot;your-support@usps.com&quot;.. This was so obviously bogus (that&#039;s not how USPS notifies one of problems) that I simply deleted the message immediately..  Thank you everybody for your posts on this malware.]]></description>
		<content:encoded><![CDATA[<p>In my case the purported sender was &#8220;your-support@usps.com&#8221;.. This was so obviously bogus (that&#8217;s not how USPS notifies one of problems) that I simply deleted the message immediately..  Thank you everybody for your posts on this malware.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Emails from USPS with subject Your Postal Package N*** contains a trojan by An Brown</title>
		<link>http://blog.mxlab.eu/2010/04/28/emails-from-usps-with-subject-your-postal-package-n-contains-a-trojan/#comment-17530</link>
		<dc:creator><![CDATA[An Brown]]></dc:creator>
		<pubDate>Fri, 03 Feb 2012 03:31:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=821#comment-17530</guid>
		<description><![CDATA[Today i received and email from USPS re: a package with a  parcel number that I was to pick up, I guess.  The email immediately caused me the distrust it.  USPS has never emailed me for any reason, especially for a package in my name that I needed to pick up.  Immediately I erased the email and then Googled this subject to see if there were others who have received the same. So glad I did not open the email.  My instincts were accurate!!!!! An883]]></description>
		<content:encoded><![CDATA[<p>Today i received and email from USPS re: a package with a  parcel number that I was to pick up, I guess.  The email immediately caused me the distrust it.  USPS has never emailed me for any reason, especially for a package in my name that I needed to pick up.  Immediately I erased the email and then Googled this subject to see if there were others who have received the same. So glad I did not open the email.  My instincts were accurate!!!!! An883</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New trojan variant in emails with subject &#8220;DHL Delivery Notification Message&#8221; by lcushing1</title>
		<link>http://blog.mxlab.eu/2011/11/30/new-trojan-variant-in-emails-with-subject-dhl-delivery-notification-message/#comment-17529</link>
		<dc:creator><![CDATA[lcushing1]]></dc:creator>
		<pubDate>Fri, 03 Feb 2012 02:17:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1541#comment-17529</guid>
		<description><![CDATA[I suspected this one, the main clues being the top &quot;Hello Dear&quot; without my name and the fact that it was a zipped file rather than an actual message. The &quot;customer reference&quot; and &quot;tracking numbers&quot; do change, but upon entering the &quot;tracking number&quot; into the (real, supplied) DHL tracking URL it didn&#039;t recognize it.]]></description>
		<content:encoded><![CDATA[<p>I suspected this one, the main clues being the top &#8220;Hello Dear&#8221; without my name and the fact that it was a zipped file rather than an actual message. The &#8220;customer reference&#8221; and &#8220;tracking numbers&#8221; do change, but upon entering the &#8220;tracking number&#8221; into the (real, supplied) DHL tracking URL it didn&#8217;t recognize it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8216;DHL Notification&#8217; with tracking number in attachment is a trojan by Mick</title>
		<link>http://blog.mxlab.eu/2011/03/08/dhl-notification-with-tracking-number-in-attachment-is-a-trojan/#comment-17519</link>
		<dc:creator><![CDATA[Mick]]></dc:creator>
		<pubDate>Wed, 01 Feb 2012 06:19:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1269#comment-17519</guid>
		<description><![CDATA[The other thing that aroused my suspicion was that the email started with &quot;Hello Dear.&quot;
Nobody has greeted me in that way for decades!
;-)]]></description>
		<content:encoded><![CDATA[<p>The other thing that aroused my suspicion was that the email started with &#8220;Hello Dear.&#8221;<br />
Nobody has greeted me in that way for decades! <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

