<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cad Engineer &#187; virus</title>
	<atom:link href="http://caddengineer.com/category/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://caddengineer.com</link>
	<description>Technology and Internet in the eye of a Cad Engineer</description>
	<lastBuildDate>Wed, 28 Mar 2012 18:20:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>CNN.com Daily Top 10 email get_flash_update.exe email spam malware</title>
		<link>http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware/66</link>
		<comments>http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware/66#comments</comments>
		<pubDate>Wed, 06 Aug 2008 18:04:22 +0000</pubDate>
		<dc:creator>lestat</dc:creator>
				<category><![CDATA[virus]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://caddengineer.com/?p=66</guid>
		<description><![CDATA[Outlook isn't catching the CNN.COM DAILY TOP 10 phishing trap so please be careful!!! Avoid being infected by the malware from the link in CNN.com Daily top 10]]></description>
			<content:encoded><![CDATA[<p>If you receive an email entitled &#8220;<a title="cnn daily top 10 malware" href="http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware"><strong>CNN.com Daily Top 10</strong></a>&#8221; from <em>Daily Top 10, Top 10</em> as shown below, then I just want to warn you that this message is a fraudulent email which contains links that will lead users to site hosting malware.</p>
<p style="text-align: center;"><a href="http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware"><img class="aligncenter" style="border-width: 0px;" src="http://caddengineer.com/wp-content/uploads/2008/08/image-thumb.png" border="0" alt="cnn.com daily top 10 email" width="368" height="225" /></a></p>
<p><span id="more-66"></span></p>
<p>I have received 4 email messages and it is good that that gmail automagically send the <strong>CNN.com Daily Top 10</strong> to my spam folder.</p>
<p>Once the user click the Top 10 link, you will be directed to a web page will ask you to install or update flash player or download the correct video codec = get_flash_update.exe which actually the Trojan-Downloader.Agent.EL</p>
<p style="text-align: center;"><a href="http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware"><img class="aligncenter" style="border-width: 0px;" src="http://caddengineer.com/wp-content/uploads/2008/08/image-thumb1.png" border="0" alt="get_flash_update.exe cnn daily top 10" width="240" height="205" /></a></p>
<p>Outlook isn&#8217;t catching the CNN.COM DAILY TOP 10 phishing trap so please be careful.  To get rid of this email with outlook, you can use the outlook rule as suggested <a href="http://news.office-watch.com/t/n.aspx?articleid=667&amp;zoneid=12">here</a>.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5964934606259331";
/* ce-200x200, created 9/22/10 */
google_ad_slot = "9131890159";
google_ad_width = 200;
google_ad_height = 200;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>If you were already infected by the malware, watch out for my next post and I&#8217;m going to provide you ways how to get rid of this pesky malware  of <a title="cnn.com daily top 10 email" href="http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware"><strong>CNN.COM Daily Top 10 email</strong></a>..</p>
]]></content:encoded>
			<wfw:commentRss>http://caddengineer.com/cnncom-daily-top-10-email-get_flash_updateexe-malware/66/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to Remove Funny UST Scandal.avi.exe Virus</title>
		<link>http://caddengineer.com/how-to-remove-funny-ust-scandalaviexe-virus/23</link>
		<comments>http://caddengineer.com/how-to-remove-funny-ust-scandalaviexe-virus/23#comments</comments>
		<pubDate>Tue, 17 Jun 2008 13:24:38 +0000</pubDate>
		<dc:creator>lestat</dc:creator>
				<category><![CDATA[virus]]></category>
		<category><![CDATA[funny ust]]></category>

		<guid isPermaLink="false">http://caddengineer.com/?p=23</guid>
		<description><![CDATA[Here is how to remove the Funny UST Virus Download the task killer and install it in your PC. You are going to use this software to terminate the virus application as you cannot use the task manager &#8211; the funny ust scandal virus is automatically closing the task. Run the taskiller. On the system [...]]]></description>
			<content:encoded><![CDATA[<p><em>Here is how to remove the Funny UST Virus</em></p>
<p><span id="more-23"></span></p>
<p>Download the <a href="http://www.rsdsoft.com/task_killer/index.php4">task killer</a> and install it in your PC.  You are going to use this software to terminate the virus application as you cannot use the task manager &#8211; the funny ust scandal virus is automatically closing the task.</p>
<p>Run the taskiller.  On the system tray (skull icon), click processes to close the virus, select process and click yes to the pop up box.</p>
<p>Select the following exe file to stop the process.  Close only the file that have same icon of  Funny UST Scandal.avi.exe</p>
<ul>
<li>killer.exe</li>
<li>lsass.exe</li>
<li>smss.exe</li>
</ul>
<p><!--adsense#plink--><br />
Click start  &gt;&gt; run then type <strong>cmd</strong></p>
<p>Type <strong>cd\</strong></p>
<p>Type <strong>attrib -h -s smss.exe</strong></p>
<p>Type <strong>attrib -h -s autorun.inf</strong></p>
<p>Type <strong>start c:</strong> ( new window will open)</p>
<p>Select smss.exe, autorun.inf, funny UST scandal.avi.exe and delete it</p>
<p>** For PC with any drive or a partition, type <strong>d:</strong> in the command prompt and repeat the step above. **</p>
<p>Type <strong>cd windows</strong> in the command prompt</p>
<p>Type <strong>attrib -h -s smss.exe</strong></p>
<p>Type <strong>start c:\windows</strong></p>
<p>Delete the file <strong>smss.exe</strong></p>
<p>Go to c:\documents and settings\all users\startmenu\programs\startup</p>
<p>Delete <strong>lsass.exe</strong></p>
<p>Click start &gt;&gt; run</p>
<p>Type the regedit</p>
<p>Browse and delete the registry entries of above application.</p>
<p>That&#8217;s the long method of removing the <strong>Funny UST Scanal.avi.exe Virus.</strong> <img src='http://caddengineer.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  If you are short of time and don&#8217;t want to go through the step above. Just download and rund this <a href="http://www.4shared.com/file/30402575/d70dafa8/Remover.html">funny UST virus remover</a> (download and use the file at your own risk)<br />
<!--adsense#blink--></p>
]]></content:encoded>
			<wfw:commentRss>http://caddengineer.com/how-to-remove-funny-ust-scandalaviexe-virus/23/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Remove Autorun.inf Virus</title>
		<link>http://caddengineer.com/remove-autoruninf-virus/14</link>
		<comments>http://caddengineer.com/remove-autoruninf-virus/14#comments</comments>
		<pubDate>Mon, 09 Jun 2008 11:09:36 +0000</pubDate>
		<dc:creator>lestat</dc:creator>
				<category><![CDATA[virus]]></category>
		<category><![CDATA[autorun.inf]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://caddengineer.com/?p=14</guid>
		<description><![CDATA[Autorun.inf is a file instruction associated with the Autorun function. It is a simple text-based configuration file that tells the operating system which executable file to start, which icon to use and what are menu commands available commonly used for CD to autoplay its content. Its auturun capability makes it a favorite target for malware, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Autorun.inf</strong> is a file instruction associated with the Autorun function.  It is a simple text-based configuration file that tells the operating system which executable file to start, which icon to use and what are menu commands available commonly used for CD to autoplay its content.<br />
<!--adsense#plink--><br />
Its auturun capability makes it a favorite target for malware, spyware.  Once worm or trojan virus is associated with the autoruninf file  the virus will spread like a wild fire.</p>
<p>Once the <em>Autorun.inf</em> is infected it is not easy to delete it.  If you do the normal delete command, the autorun.inf keep coming back  after you remove it.</p>
<p>Here is a way how to remove the infected Autorun.inf permanently:</p>
<ol>
<li>Boot your system in safemode</li>
<li>Open your flash drive via command prompt (start&gt;&gt;run&gt;&gt;cmd.exe)</li>
<li>Activate your flash drive (e.g. flash drive is in J:, just type J:on the command prompt &#8211; don&#8217;t forget to press enter)</li>
<li>Type <strong>ATTRIB -H -R -S AUTORUN.INF</strong> then press &#8220;Enter&#8221;</li>
<li>Reboot your PC</li>
</ol>
<p><!--adsense#blink--></p>
]]></content:encoded>
			<wfw:commentRss>http://caddengineer.com/remove-autoruninf-virus/14/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

