<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Follow up post about UPS_Invoice trojan</title>
	<atom:link href="http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/</link>
	<description>the unofficial voice of Meteor IT</description>
	<lastBuildDate>Mon, 06 Feb 2012 13:06:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Robin</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3583</link>
		<dc:creator><![CDATA[Robin]]></dc:creator>
		<pubDate>Sat, 23 Oct 2010 08:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3583</guid>
		<description><![CDATA[If you get the trojan then use Spybot. It picks it up no problem.]]></description>
		<content:encoded><![CDATA[<p>If you get the trojan then use Spybot. It picks it up no problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Vero</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3259</link>
		<dc:creator><![CDATA[Adam Vero]]></dc:creator>
		<pubDate>Mon, 28 Jul 2008 21:44:43 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3259</guid>
		<description><![CDATA[Gloin
Others have reported the domain name now, but it has been taken down, so no need to block at your gateway, although that can be a useful method of protecting your users and your network, especially in cases like this where the email trojan was only the first part of the problem, it is the other malware it downloads which is even nastier and harder to get rid of (such as XPAntivirus 2008).
You would of course need to consider how to protect users with laptops if they can use these on other unprotected web connections (or rather not protected by you and your filtering rules) such as at home, internet cafes and so on.

Barb
You might be best off with some form of bootdisk such as BartPE or Knoppix which can help you to go through your hard drive and remove files without being logged in to the machine through windows. Alternatively, hit F8 at startup for a menu and see if you have any luck getting in using Safe Mode.]]></description>
		<content:encoded><![CDATA[<p>Gloin<br />
Others have reported the domain name now, but it has been taken down, so no need to block at your gateway, although that can be a useful method of protecting your users and your network, especially in cases like this where the email trojan was only the first part of the problem, it is the other malware it downloads which is even nastier and harder to get rid of (such as XPAntivirus 2008).<br />
You would of course need to consider how to protect users with laptops if they can use these on other unprotected web connections (or rather not protected by you and your filtering rules) such as at home, internet cafes and so on.</p>
<p>Barb<br />
You might be best off with some form of bootdisk such as BartPE or Knoppix which can help you to go through your hard drive and remove files without being logged in to the machine through windows. Alternatively, hit F8 at startup for a menu and see if you have any luck getting in using Safe Mode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Barb</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3253</link>
		<dc:creator><![CDATA[Barb]]></dc:creator>
		<pubDate>Sat, 26 Jul 2008 16:27:20 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3253</guid>
		<description><![CDATA[My computer got infected with this trojan and now I can&#039;t even log into Windows!  Any ideas on how to clean this up without having to re-format my whole hard drive?  Thanks!

Also, how do I get into my DOS prompt with Windows XP Home Edition when I can&#039;t even log into Windows?]]></description>
		<content:encoded><![CDATA[<p>My computer got infected with this trojan and now I can&#8217;t even log into Windows!  Any ideas on how to clean this up without having to re-format my whole hard drive?  Thanks!</p>
<p>Also, how do I get into my DOS prompt with Windows XP Home Edition when I can&#8217;t even log into Windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gloin</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3249</link>
		<dc:creator><![CDATA[Gloin]]></dc:creator>
		<pubDate>Fri, 25 Jul 2008 17:27:49 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3249</guid>
		<description><![CDATA[Hey, if you could forward me the actual URL that this thing is trying to phone home to, I&#039;d sure appreciate it.  We&#039;ve had a few machines compromised, and I&#039;d like to add the address to outbound block on the firewall.  Thanks!]]></description>
		<content:encoded><![CDATA[<p>Hey, if you could forward me the actual URL that this thing is trying to phone home to, I&#8217;d sure appreciate it.  We&#8217;ve had a few machines compromised, and I&#8217;d like to add the address to outbound block on the firewall.  Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UPS_Invoice email trojan variant claims to be from Customs Service &#171; Adam Vero at Getting IT Right</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3229</link>
		<dc:creator><![CDATA[UPS_Invoice email trojan variant claims to be from Customs Service &#171; Adam Vero at Getting IT Right]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 14:42:17 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3229</guid>
		<description><![CDATA[In the last hour I found in my inbox a variation on the UPS_Invoice trojans of last week. &lt;a href=&quot;http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/&quot; rel=&quot;nofollow&quot;&gt;This new email claimed to be from &quot;Customs Service&quot;&lt;/a&gt; with the subject &quot;Customs - We have received a parcel for you&quot;]]></description>
		<content:encoded><![CDATA[<p>In the last hour I found in my inbox a variation on the UPS_Invoice trojans of last week. <a href="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" rel="nofollow">This new email claimed to be from &#8220;Customs Service&#8221;</a> with the subject &#8220;Customs &#8211; We have received a parcel for you&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hamish</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3224</link>
		<dc:creator><![CDATA[Hamish]]></dc:creator>
		<pubDate>Wed, 23 Jul 2008 16:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3224</guid>
		<description><![CDATA[INfection started with:

UPS_INVOICE_978172.exe in a zip file.
Attached to an email as described above in the thread.

Likely it has spawned:
C:\WINDOWS\system32\ntos.exe        Win32/PSW.Agent.NIF trojan

Infected:
C:\WINDOWS\system32\drivers\beep.sys
C:\WINDOWS\system32\buritos.exe
C:\WINDOWS\buritos.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\braviax.exe

more spawned files: (sorry no location info)
karina.dat 
cru26???.dat

It tried to contact 
hxxp://xpsecuritycenter.com/install/Installer.exe  

Cleaned it by starting windows xp in Safe Mode
ESET&#039;s NOD32 commandline scanner detected &#039;m, I removed &#039;m manually.

Hope this helps any of you a little further.]]></description>
		<content:encoded><![CDATA[<p>INfection started with:</p>
<p>UPS_INVOICE_978172.exe in a zip file.<br />
Attached to an email as described above in the thread.</p>
<p>Likely it has spawned:<br />
C:\WINDOWS\system32\ntos.exe        Win32/PSW.Agent.NIF trojan</p>
<p>Infected:<br />
C:\WINDOWS\system32\drivers\beep.sys<br />
C:\WINDOWS\system32\buritos.exe<br />
C:\WINDOWS\buritos.exe<br />
C:\WINDOWS\system32\braviax.exe<br />
C:\WINDOWS\braviax.exe</p>
<p>more spawned files: (sorry no location info)<br />
karina.dat<br />
cru26???.dat</p>
<p>It tried to contact<br />
hxxp://xpsecuritycenter.com/install/Installer.exe  </p>
<p>Cleaned it by starting windows xp in Safe Mode<br />
ESET&#8217;s NOD32 commandline scanner detected &#8216;m, I removed &#8216;m manually.</p>
<p>Hope this helps any of you a little further.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeroen</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3220</link>
		<dc:creator><![CDATA[Jeroen]]></dc:creator>
		<pubDate>Tue, 22 Jul 2008 12:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3220</guid>
		<description><![CDATA[Thnx The420Kid! I&#039;m going to try and fix it, but is since I&#039;m not a computer-expert it is going to be difficult for me... Thnx anyway!]]></description>
		<content:encoded><![CDATA[<p>Thnx The420Kid! I&#8217;m going to try and fix it, but is since I&#8217;m not a computer-expert it is going to be difficult for me&#8230; Thnx anyway!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elliot</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3216</link>
		<dc:creator><![CDATA[Elliot]]></dc:creator>
		<pubDate>Sun, 20 Jul 2008 20:11:19 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3216</guid>
		<description><![CDATA[I received this Email.  Unfortunately, I missed all the usual warnings (like the bad return Email address) and eventually clicked on the .Exe.  When nothing happened, it suddenly struck me that I screwed up.  I am trying to research how to get rid of this virus/malware.  

My only saving grace, if it this indeed sends out mass Emails, is that I use Thunderbird as my Email client and usually these viruses attack Outlook.]]></description>
		<content:encoded><![CDATA[<p>I received this Email.  Unfortunately, I missed all the usual warnings (like the bad return Email address) and eventually clicked on the .Exe.  When nothing happened, it suddenly struck me that I screwed up.  I am trying to research how to get rid of this virus/malware.  </p>
<p>My only saving grace, if it this indeed sends out mass Emails, is that I use Thunderbird as my Email client and usually these viruses attack Outlook.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: the420kid</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3210</link>
		<dc:creator><![CDATA[the420kid]]></dc:creator>
		<pubDate>Wed, 16 Jul 2008 19:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3210</guid>
		<description><![CDATA[There are reg keys that need to be re-entered after cleaning up the worm.  

check out this link: 
http://www.precisesecurity.com/threats/trojanblusod/

My cleaning used a mix of SDFix, Avenger (to kill some stubborn files), and Symantec Endpoint v11.   
what a pain in teh ass :)]]></description>
		<content:encoded><![CDATA[<p>There are reg keys that need to be re-entered after cleaning up the worm.  </p>
<p>check out this link:<br />
<a href="http://www.precisesecurity.com/threats/trojanblusod/" rel="nofollow">http://www.precisesecurity.com/threats/trojanblusod/</a></p>
<p>My cleaning used a mix of SDFix, Avenger (to kill some stubborn files), and Symantec Endpoint v11.<br />
what a pain in teh ass <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeroen</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3206</link>
		<dc:creator><![CDATA[Jeroen]]></dc:creator>
		<pubDate>Wed, 16 Jul 2008 12:35:12 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comment-3206</guid>
		<description><![CDATA[My computer has been attacked too... Unfortunately we were waiting for some stuff to arrive via UPS so there you go...

My Avast! 4.8 helped me wonderful but I had to delete some bad files from the registry. The malware was responsible for downloading the earlier mentioned XP Antivirus program (which was pretty hard to kill) and destroyed my desktop (i.g. wallpaper). It has left me with no choice of setting to adjust the wallpaper except for standard XP blue look. Has anyone got any ideas how to reset this and have my wallpaper back? I&#039;ve removed files that were spread by the virus from the HKEY_CURRENT_USER registry regarding the false wallpaper setting (including a file called wallpaper.exe which had similar features to the others files (rhuc9u1j0e33v.exe etc).

I would really appreciate anyones help in this matter!]]></description>
		<content:encoded><![CDATA[<p>My computer has been attacked too&#8230; Unfortunately we were waiting for some stuff to arrive via UPS so there you go&#8230;</p>
<p>My Avast! 4.8 helped me wonderful but I had to delete some bad files from the registry. The malware was responsible for downloading the earlier mentioned XP Antivirus program (which was pretty hard to kill) and destroyed my desktop (i.g. wallpaper). It has left me with no choice of setting to adjust the wallpaper except for standard XP blue look. Has anyone got any ideas how to reset this and have my wallpaper back? I&#8217;ve removed files that were spread by the virus from the HKEY_CURRENT_USER registry regarding the false wallpaper setting (including a file called wallpaper.exe which had similar features to the others files (rhuc9u1j0e33v.exe etc).</p>
<p>I would really appreciate anyones help in this matter!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

