<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another virus infection, courtesy of Yahoo News</title>
	<atom:link href="http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/feed" rel="self" type="application/rss+xml" />
	<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm</link>
	<description>We know accurately only when we know little, with knowledge doubt increases.  (Goethe)</description>
	<lastBuildDate>Tue, 27 Jul 2010 17:33:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: April R</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-5782</link>
		<dc:creator>April R</dc:creator>
		<pubDate>Wed, 05 May 2010 04:05:13 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-5782</guid>
		<description>You are right!! Yahoo gave me an infection that nearly ruined my laptop. 

Today I went to yahoo news and was reading about the arrest of the new york bomb arrest. Suddenly my computer was taken over by a rogue fake antivirus program. I didn&#039;t even click on anything or authorize a download! It has taken me ALL DAY to try to get it off. I couldn&#039;t do anything in regular mode, even shut down. I had to remove the battery and put it back in and then reboot in safe mode. Then I ran spybot search and destroy. It found  fraud.sysguard  on there. I clicked to fix the problem&quot; hoping spybot would fix it. I restarted in regular mode and instantly 20 windows popped up telling me I have a virus and I have to give this fraudulent company money to take it off. I shut down and started in safe mode again. Before it was over I had run AVG, MALWARE BYTEs which found 3 more infected files, run a registry cleaner, and I had to still do a system restore, all from safe mode. I barely got the thing working but it is acting weird. I knew the only page I had open when this happened was yahoo news. I was searching for information when I found your article. I can&#039;t believe such a widely used mainstream site would allow themselves to be infiltrated by such crap! I guess I will be staying on CNN from now on.

fraud.sysguard is an AWFUL one to get.</description>
		<content:encoded><![CDATA[<p>You are right!! Yahoo gave me an infection that nearly ruined my laptop. </p>
<p>Today I went to yahoo news and was reading about the arrest of the new york bomb arrest. Suddenly my computer was taken over by a rogue fake antivirus program. I didn&#8217;t even click on anything or authorize a download! It has taken me ALL DAY to try to get it off. I couldn&#8217;t do anything in regular mode, even shut down. I had to remove the battery and put it back in and then reboot in safe mode. Then I ran spybot search and destroy. It found  fraud.sysguard  on there. I clicked to fix the problem&#8221; hoping spybot would fix it. I restarted in regular mode and instantly 20 windows popped up telling me I have a virus and I have to give this fraudulent company money to take it off. I shut down and started in safe mode again. Before it was over I had run AVG, MALWARE BYTEs which found 3 more infected files, run a registry cleaner, and I had to still do a system restore, all from safe mode. I barely got the thing working but it is acting weird. I knew the only page I had open when this happened was yahoo news. I was searching for information when I found your article. I can&#8217;t believe such a widely used mainstream site would allow themselves to be infiltrated by such crap! I guess I will be staying on CNN from now on.</p>
<p>fraud.sysguard is an AWFUL one to get.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sakolone</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-5654</link>
		<dc:creator>sakolone</dc:creator>
		<pubDate>Sat, 10 Oct 2009 03:04:01 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-5654</guid>
		<description>I&#039;m using Windows and following your instructions i&#039;ve found hundreds or even thousand of dll files in my system32. What does this files do? It doesn&#039;t seems to affect me in anyways. But anyway, how do i get rid of them without buying expensive virus scanners?</description>
		<content:encoded><![CDATA[<p>I&#8217;m using Windows and following your instructions i&#8217;ve found hundreds or even thousand of dll files in my system32. What does this files do? It doesn&#8217;t seems to affect me in anyways. But anyway, how do i get rid of them without buying expensive virus scanners?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russ</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-5478</link>
		<dc:creator>Russ</dc:creator>
		<pubDate>Mon, 03 Aug 2009 07:43:22 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-5478</guid>
		<description>August 2,2009 Norton just blocked aqq.netalbion.net/ptp/in.php frp attacking computer aqq.netalbion.net (66.135.37.21,80). I was amazed that a google search hardly found any sites referencing it.The target was mozilla firefox\firefox.exe according to Norton. I was watching an old movie on Hulu with commercials.</description>
		<content:encoded><![CDATA[<p>August 2,2009 Norton just blocked aqq.netalbion.net/ptp/in.php frp attacking computer aqq.netalbion.net (66.135.37.21,80). I was amazed that a google search hardly found any sites referencing it.The target was mozilla firefox\firefox.exe according to Norton. I was watching an old movie on Hulu with commercials.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stratagerm</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-5434</link>
		<dc:creator>Stratagerm</dc:creator>
		<pubDate>Tue, 23 Jun 2009 01:38:24 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-5434</guid>
		<description>Months later the advert-base.net clowns are still at it, see my blog &lt;a href=&quot;http://gamegenus.blogspot.com/2009/06/ad-servers-being-used-to-spread.html&quot; rel=&quot;nofollow&quot;&gt;Ad servers being used to spread exploits&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Months later the advert-base.net clowns are still at it, see my blog <a href="http://gamegenus.blogspot.com/2009/06/ad-servers-being-used-to-spread.html" rel="nofollow">Ad servers being used to spread exploits</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Donner</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4646</link>
		<dc:creator>Christian Donner</dc:creator>
		<pubDate>Fri, 10 Apr 2009 21:22:34 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4646</guid>
		<description>The German C’t magazine requires the purchase of one print issue, so technically, Knoppicillin is not free. I am afraid you will not find it legally.
Their &lt;a href=&quot;http://www.heise.de/software/download/knoppicillin_download_edition/37894&quot; rel=&quot;nofollow&quot;&gt;downloadable version&lt;/a&gt; does not have the virus scanners. I have a magazine subscription and I got it in the mail.</description>
		<content:encoded><![CDATA[<p>The German C’t magazine requires the purchase of one print issue, so technically, Knoppicillin is not free. I am afraid you will not find it legally.<br />
Their <a href="http://www.heise.de/software/download/knoppicillin_download_edition/37894" rel="nofollow">downloadable version</a> does not have the virus scanners. I have a magazine subscription and I got it in the mail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Matalon</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4645</link>
		<dc:creator>Daniel Matalon</dc:creator>
		<pubDate>Fri, 10 Apr 2009 21:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4645</guid>
		<description>pls get a correction my mail is .....</description>
		<content:encoded><![CDATA[<p>pls get a correction my mail is &#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Matalon</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4644</link>
		<dc:creator>Daniel Matalon</dc:creator>
		<pubDate>Fri, 10 Apr 2009 21:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4644</guid>
		<description>Hi Christian

fantastic story, I&#039;ve been searching now for hours the Knopicillin CD - found many sites in German (which I don&#039;t read), can you help me find a place I can d/l lastest version - I assume ver. 7

thanks

Daniel
Tel-Aviv, Israel</description>
		<content:encoded><![CDATA[<p>Hi Christian</p>
<p>fantastic story, I&#8217;ve been searching now for hours the Knopicillin CD &#8211; found many sites in German (which I don&#8217;t read), can you help me find a place I can d/l lastest version &#8211; I assume ver. 7</p>
<p>thanks</p>
<p>Daniel<br />
Tel-Aviv, Israel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Donner</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4603</link>
		<dc:creator>Christian Donner</dc:creator>
		<pubDate>Fri, 10 Apr 2009 01:49:19 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4603</guid>
		<description>All true. Short of uninstalling Acrobat, I disabled the Acrobat Extension in IE (Tools/Internet Options/Programs/Manage Ad-ons). I also turned on In-Private filtering in IE8, which is supposed to block 3rd party ads.</description>
		<content:encoded><![CDATA[<p>All true. Short of uninstalling Acrobat, I disabled the Acrobat Extension in IE (Tools/Internet Options/Programs/Manage Ad-ons). I also turned on In-Private filtering in IE8, which is supposed to block 3rd party ads.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Donner</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4600</link>
		<dc:creator>Christian Donner</dc:creator>
		<pubDate>Fri, 10 Apr 2009 00:28:59 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4600</guid>
		<description>I am not an expert in Mac security threats, but I would think that you are probably fine. The malicious code that this PDF wants to download will not run on the Mac.</description>
		<content:encoded><![CDATA[<p>I am not an expert in Mac security threats, but I would think that you are probably fine. The malicious code that this PDF wants to download will not run on the Mac.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mark anthony</title>
		<link>http://cdonner.com/another-virus-infection-courtesy-of-yahoo-news.htm/comment-page-1#comment-4598</link>
		<dc:creator>mark anthony</dc:creator>
		<pubDate>Fri, 10 Apr 2009 00:19:53 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=543#comment-4598</guid>
		<description>this is what you need to do. go to control panel add remove programs (for xp) and remove all versions of adobe acrobat. download the free adobe reader foxit from foxitsoftware.com, it does not have the scripting vulnerability. download the free virus scanners malwarebyes and combofix. google search for the url&#039;s. both of these utilities do an excellent job of detecting and removing virus. for free virus prevention try avast or avg - search google for urls.  make sure you have all the latest windows updates. use the latest firefox browser. also remove all versions of java and download the latest fromjava.com. old java has vulnerabilities. 

as far as the infected ad servers I suspect this has an impact on the bottom line so yahoo and others are potentially sacrificing their customers. What is more concerning is what the bad guys are doing with these subverted computers. A site like yahoo is used in corporations so we can assume that the bad guys are getting access to internal corporate networks and their data. Within the last week I repaired a few of my clients computers of various viruses and they were all running old versions of acrobat reader. These same clients had access to a credit card merchant server. This is very bad. Adobe too is to blame for this for not going public with a full recall. I believe that American intellectual property is being siphoned out bit by bit.</description>
		<content:encoded><![CDATA[<p>this is what you need to do. go to control panel add remove programs (for xp) and remove all versions of adobe acrobat. download the free adobe reader foxit from foxitsoftware.com, it does not have the scripting vulnerability. download the free virus scanners malwarebyes and combofix. google search for the url&#8217;s. both of these utilities do an excellent job of detecting and removing virus. for free virus prevention try avast or avg &#8211; search google for urls.  make sure you have all the latest windows updates. use the latest firefox browser. also remove all versions of java and download the latest fromjava.com. old java has vulnerabilities. </p>
<p>as far as the infected ad servers I suspect this has an impact on the bottom line so yahoo and others are potentially sacrificing their customers. What is more concerning is what the bad guys are doing with these subverted computers. A site like yahoo is used in corporations so we can assume that the bad guys are getting access to internal corporate networks and their data. Within the last week I repaired a few of my clients computers of various viruses and they were all running old versions of acrobat reader. These same clients had access to a credit card merchant server. This is very bad. Adobe too is to blame for this for not going public with a full recall. I believe that American intellectual property is being siphoned out bit by bit.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
