<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with virii</title>
      <link>http://ask.metafilter.com/tags/virii</link>
      <description>Questions tagged with 'virii' at Ask MetaFilter.</description>
	  <pubDate>Sun, 11 Jan 2009 23:08:11 -0800</pubDate> <lastBuildDate>Sun, 11 Jan 2009 23:08:11 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>Someone is spamming from my gmail account.</title>
	<link>http://ask.metafilter.com/111420/Someone%2Dis%2Dspamming%2Dfrom%2Dmy%2Dgmail%2Daccount</link>	
	<description>Has my gmail account really been compromised? Someone, or something seems to have spammed my entire contacts list, from within my gmail account, despite my having a strong password. (Same problem described by this &lt;a href=&quot;http://groups.google.com/group/google-de-google-forum/browse_thread/thread/d22caa328f894786/67b5c72ba16bdf62#67b5c72ba16bdf62&quot;&gt;german gmail user&lt;/a&gt;).&lt;br&gt;
&lt;br&gt;
Has someone really stolen or guessed my password, and do I need to take anti-virus precautions beside changing my password? I am running OS X 10.4.11.&lt;br&gt;
&lt;br&gt;
The previous activity on my gmail account suggests someone was using it elsewhere at the time the emails went out, in a GMT+8 timezone:&lt;br&gt;
&lt;br&gt;
Browser	 115.49.96.23	 5:28 am (1 hour ago)&lt;br&gt;
&lt;br&gt;
The text of the email and the header (minus 500 email addresses) are below:&lt;br&gt;
&lt;br&gt;
--- &lt;br&gt;
Dear, &lt;br&gt;
Good day!!! &lt;br&gt;
I would like to introduce a very good company, electronic products &lt;br&gt;
Wholesale dealer. &lt;br&gt;
I have  bought some products from company,the price was very cheap, &lt;br&gt;
and the products are very good quality! &lt;br&gt;
Just have a look at this web page : http://www.hpp[redacted].com/ &lt;br&gt;
I am sure you will could save a lot of money! &lt;br&gt;
Happy new year!!!!! &lt;br&gt;
                                Best regards!!! &lt;br&gt;
introduction give you of friend!!! &lt;br&gt;
--- &lt;br&gt;
&lt;br&gt;
This is the header:&lt;br&gt;
&lt;br&gt;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;&lt;br&gt;
       d=gmail.com; s=gamma;&lt;br&gt;
       h=domainkey-signature:received:received:message-id:date:from:to&lt;br&gt;
        :subject:mime-version:content-type;&lt;br&gt;
       bh=K6tVhE5iH9jG8/7W3sL3UlYq6awTl26w2OX6rEz6znw=;&lt;br&gt;
       b=aEmoNLBhwOJd78gsKoXBSfQU7ZrUJ5yW9TwQe4BS9Z95uMciQgV0xulNnSwsF78wrz&lt;br&gt;
        K5BSCZPAJSWwTatBtW+N3lrFHYGRYnJxBXIY2n27cuFJf+C4pZk51F7oJwQUqQDwFzHT&lt;br&gt;
        uZqHFcLFBsyEYbK9C3ovp4b/IPtr8ra+Qq618=&lt;br&gt;
DomainKey-Signature: a=rsa-sha1; c=nofws;&lt;br&gt;
       d=gmail.com; s=gamma;&lt;br&gt;
       h=message-id:date:from:to:subject:mime-version:content-type;&lt;br&gt;
       b=qtqP0ZUW3LzE837BnVjmCGEIxXrpddkhrjWNDruuZm4M372ePF8bBfUUq+/qvzKgdQ&lt;br&gt;
        xvqRgGgOLp9VAxhgPbhVNnAAA/thhEqJtw09/A61L0gREHySwCvINze1Yfi7sY6DEZKM&lt;br&gt;
        ewL1U02Pwa/pHMmAUIpFgrJMxEiKi2PrjIa4o=&lt;br&gt;
Received: by 10.215.100.13 with SMTP id c13mr4320711qam.377.1231738078819;&lt;br&gt;
       Sun, 11 Jan 2009 21:27:58 -0800 (PST)&lt;br&gt;
Received: by 10.214.43.15 with HTTP; Sun, 11 Jan 2009 21:27:58 -0800 (PST)&lt;br&gt;
Message-ID: &lt;a0&gt;&lt;br&gt;
Date: Mon, 12 Jan 2009 13:27:58 +0800&lt;br&gt;
&lt;/a0&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.111420</guid>
	<pubDate>Sun, 11 Jan 2009 23:08:11 -0800</pubDate>
	<category>email</category>
	<category>gmail</category>
	<category>password</category>
	<category>spam</category>
	<category>trojan</category>
	<category>virii</category>
	<dc:creator>roofus</dc:creator>
	</item>
	<item>
	<title>Adware everywhere</title>
	<link>http://ask.metafilter.com/56556/Adware%2Deverywhere</link>	
	<description>Please help me get rid of this spyware infection before I just give up and re-install Windows. My PC is infected with what seems like at least 2 or 3 different varieties of spyware/adware/malware. This started happening a day or two ago after someone else in the house fell for a MySpace bulletin posted under someone else&apos;s phished/hacked account. I hardly ever actually use my PC so I didn&apos;t notice until this morning. &lt;br&gt;
&lt;br&gt;
I&apos;ve got a small blinking icon in my taskbar that alternates between an X in a circle and then a question mark. It pops up little messages about &quot;Critical System Errors!&quot;. From what I understand, this is a malware program named VirusBurst. &lt;br&gt;
&lt;br&gt;
The most noticeable problem though is whatever that&apos;s installed on here and is opening Firefox windows to various ads and webpages. It happens in bursts, up to 4 or 5 popups at a time, and seems to happen randomly. While typing this, it&apos;s only happened once, but in the time it took to get over to AskMefi it happened 2 or 3 times.&lt;br&gt;
&lt;br&gt;
The worst part of all of this is that there seems to be yet another malware program that closes Lavasofts Ad-Aware or SpyBoy S&amp;amp;D before they even start. It will also close any browser window that I use to try to search for Ad-Aware or any other spyware removal tools. This is supposed to be something called CoolWebSearch, but every tool I try which is supposed to remove CoolWebSearch claims that it can&apos;t find it on my system.&lt;br&gt;
&lt;br&gt;
So what can I do, other than giving up and reinstalling Windows (along with all the software and games that are currently installed)? I can post a HijackThis log if anyone asks for it.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.56556</guid>
	<pubDate>Wed, 07 Feb 2007 13:53:51 -0800</pubDate>
	<category>adware</category>
	<category>HELP</category>
	<category>malware</category>
	<category>spyware</category>
	<category>virii</category>
	<category>virus</category>
	<dc:creator>Venadium</dc:creator>
	</item>
	<item>
	<title>Aurora: not the pretty lights in the sky.</title>
	<link>http://ask.metafilter.com/18794/Aurora%2Dnot%2Dthe%2Dpretty%2Dlights%2Din%2Dthe%2Dsky</link>	
	<description>Two friends have been infected with the evil Aurora pop-up thing, and I&apos;ve spent hours thinking about how to kill it. I&apos;ve installed Avast on their systems and no dice yet. Is there an app that will destroy it, or is the fix deep DIY registry surgery? Thanks!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.18794</guid>
	<pubDate>Mon, 16 May 2005 20:27:03 -0800</pubDate>
	<category>aurora</category>
	<category>evil</category>
	<category>popup</category>
	<category>virii</category>
	<category>virus</category>
	<category>worms</category>
	<dc:creator>moonbird</dc:creator>
	</item>
	<item>
	<title>How do I tell what program inserted a registry entry?</title>
	<link>http://ask.metafilter.com/8796/How%2Ddo%2DI%2Dtell%2Dwhat%2Dprogram%2Dinserted%2Da%2Dregistry%2Dentry</link>	
	<description>PCFilter : Is there any way to tell what program inserted something into the registry?&lt;br&gt;
&lt;small&gt;I&apos;ve been attacked by four seperate virii that sophos claims don&apos;t exist in the wild. One of them (netclnc.exe) keeps reappearing in my registry and the system32, and I want to know what&apos;s putting it there so I can kill it. Ideas?&lt;/small&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2004:site.8796</guid>
	<pubDate>Sun, 18 Jul 2004 07:05:52 -0800</pubDate>
	<category>microsoft</category>
	<category>registry</category>
	<category>registrycleaner</category>
	<category>system32</category>
	<category>trojans</category>
	<category>virii</category>
	<category>virus</category>
	<category>viruses</category>
	<category>windows</category>
	<category>windowsregistry</category>
	<category>windowsxp</category>
	<dc:creator>twine42</dc:creator>
	</item>
	
	</channel>
</rss>

