<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Facebook, Facebookhealth and the rogue AntiVirus application</title>
	<atom:link href="http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=facebook-facebookhealth-rogue-antivirus-application</link>
	<description>Brought to you by GFI Software</description>
	<lastBuildDate>Fri, 09 Aug 2013 12:13:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Angelica</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-291</link>
		<dc:creator>Angelica</dc:creator>
		<pubDate>Thu, 15 Oct 2009 07:37:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-291</guid>
		<description><![CDATA[Thanks Andrei - as an avid Facebook user, I&#039;ve been noticing those weight loss messages popping up as various friends&#039; posts (and wondering how to avoid them appearing as mine too!); i knew it had to be some kind of virus but not much else. This was really interesting!]]></description>
		<content:encoded><![CDATA[<p>Thanks Andrei &#8211; as an avid Facebook user, I&#8217;ve been noticing those weight loss messages popping up as various friends&#8217; posts (and wondering how to avoid them appearing as mine too!); i knew it had to be some kind of virus but not much else. This was really interesting!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Zammit</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-281</link>
		<dc:creator>Andrei Zammit</dc:creator>
		<pubDate>Sun, 11 Oct 2009 18:21:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-281</guid>
		<description><![CDATA[Just wanted to update you on this case.

There are domains which are delivering the malicious payload as described in the article:

a.) 3allfolderscan.com delivers Soft_19.exe
b.) mysecurityupgrade.com delivers setup.exe
c.) clara9elena.cn which is reported and blocked by Google
d.) myprotection-zone.net delivers setup_build8_201.exe 


Virus analysis from VirusTotal.com:

for &#039;setup.exe&#039; please follow http://www.virustotal.com/analisis/da69bf7c21ff7329ea4f4beb027c5b915ef5d2b8f1035a6e13c1ad48d33328f4-1255284144

for &#039;Soft_19.exe&#039; follow
http://www.virustotal.com/analisis/ca3023f760c47bac1d77f411229c25354243061b14076cb7d47e84712ffa0932-1255284361

for &#039;setup_build8_201.exe&#039; follow
http://www.virustotal.com/analisis/4b83f01fb2b3b32ea50daa0d5890e2bb477b278e73133f063d953334f1a56446-1255284997]]></description>
		<content:encoded><![CDATA[<p>Just wanted to update you on this case.</p>
<p>There are domains which are delivering the malicious payload as described in the article:</p>
<p>a.) 3allfolderscan.com delivers Soft_19.exe<br />
b.) mysecurityupgrade.com delivers setup.exe<br />
c.) clara9elena.cn which is reported and blocked by Google<br />
d.) myprotection-zone.net delivers setup_build8_201.exe </p>
<p>Virus analysis from VirusTotal.com:</p>
<p>for &#8216;setup.exe&#8217; please follow <a href="http://www.virustotal.com/analisis/da69bf7c21ff7329ea4f4beb027c5b915ef5d2b8f1035a6e13c1ad48d33328f4-1255284144" rel="nofollow">http://www.virustotal.com/analisis/da69bf7c21ff7329ea4f4beb027c5b915ef5d2b8f1035a6e13c1ad48d33328f4-1255284144</a></p>
<p>for &#8216;Soft_19.exe&#8217; follow<br />
<a href="http://www.virustotal.com/analisis/ca3023f760c47bac1d77f411229c25354243061b14076cb7d47e84712ffa0932-1255284361" rel="nofollow">http://www.virustotal.com/analisis/ca3023f760c47bac1d77f411229c25354243061b14076cb7d47e84712ffa0932-1255284361</a></p>
<p>for &#8216;setup_build8_201.exe&#8217; follow<br />
<a href="http://www.virustotal.com/analisis/4b83f01fb2b3b32ea50daa0d5890e2bb477b278e73133f063d953334f1a56446-1255284997" rel="nofollow">http://www.virustotal.com/analisis/4b83f01fb2b3b32ea50daa0d5890e2bb477b278e73133f063d953334f1a56446-1255284997</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Zammit</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-280</link>
		<dc:creator>Andrei Zammit</dc:creator>
		<pubDate>Fri, 09 Oct 2009 12:08:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-280</guid>
		<description><![CDATA[Hi target,

Thanks for your interest.

One important thing to note is that if a trojan manages to steal your Facebook acount details, this will be harvested (together with other users&#039; account details) in a location and used at a later stage. Weeks and months may pass until the malware writers make use of them.

On the other hand, if bank account details (or any financial institution) are stolen, they are used very soon. This is because such data has a short lifetime compared to the Facebook account details.]]></description>
		<content:encoded><![CDATA[<p>Hi target,</p>
<p>Thanks for your interest.</p>
<p>One important thing to note is that if a trojan manages to steal your Facebook acount details, this will be harvested (together with other users&#8217; account details) in a location and used at a later stage. Weeks and months may pass until the malware writers make use of them.</p>
<p>On the other hand, if bank account details (or any financial institution) are stolen, they are used very soon. This is because such data has a short lifetime compared to the Facebook account details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-279</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Fri, 09 Oct 2009 10:15:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-279</guid>
		<description><![CDATA[Hi Andrei,

Thanks for the results link. Pretty worrying that only 3 found it. I guess that most of the vendors will be pretty quick at updating their definitions though.]]></description>
		<content:encoded><![CDATA[<p>Hi Andrei,</p>
<p>Thanks for the results link. Pretty worrying that only 3 found it. I guess that most of the vendors will be pretty quick at updating their definitions though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: target</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-278</link>
		<dc:creator>target</dc:creator>
		<pubDate>Thu, 08 Oct 2009 18:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-278</guid>
		<description><![CDATA[thx for the info,

I&#039;m a victim of this action, I guess that number 2. is the case, because I haven&#039; t been on facebook für a couple of weeks now, so I can&#039; t how anybody could get my user dates.]]></description>
		<content:encoded><![CDATA[<p>thx for the info,</p>
<p>I&#8217;m a victim of this action, I guess that number 2. is the case, because I haven&#8217; t been on facebook für a couple of weeks now, so I can&#8217; t how anybody could get my user dates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Zammit</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-275</link>
		<dc:creator>Andrei Zammit</dc:creator>
		<pubDate>Thu, 08 Oct 2009 15:30:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-275</guid>
		<description><![CDATA[Hi Richard,

You can see the complete virus analysis report using this link here: http://www.virustotal.com/analisis/a9e1cdfec232a094e09518e1909705e8d3e5d4c8db2dae1d42561dae75140d20-1254934621

This report also includes which AntiVirus engines managed to detect the malware.

Our product, GFI MailSecurity, is a mail security server for IIS, MS Exchange and Lotus Domino. This implies that GFI MailSecurity will filter any emails hitting your orgainization which have malicious content. More information can be found here: http://www.gfi.com/mailsecurity]]></description>
		<content:encoded><![CDATA[<p>Hi Richard,</p>
<p>You can see the complete virus analysis report using this link here: <a href="http://www.virustotal.com/analisis/a9e1cdfec232a094e09518e1909705e8d3e5d4c8db2dae1d42561dae75140d20-1254934621" rel="nofollow">http://www.virustotal.com/analisis/a9e1cdfec232a094e09518e1909705e8d3e5d4c8db2dae1d42561dae75140d20-1254934621</a></p>
<p>This report also includes which AntiVirus engines managed to detect the malware.</p>
<p>Our product, GFI MailSecurity, is a mail security server for IIS, MS Exchange and Lotus Domino. This implies that GFI MailSecurity will filter any emails hitting your orgainization which have malicious content. More information can be found here: <a href="http://www.gfi.com/mailsecurity" rel="nofollow">http://www.gfi.com/mailsecurity</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://www.gfi.com/blog/facebook-facebookhealth-rogue-antivirus-application/comment-page-1/#comment-272</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Thu, 08 Oct 2009 12:11:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=1383#comment-272</guid>
		<description><![CDATA[Thanks for the advice. Nice to see you guys are on top of this.

Out of curiosity, which 3 of the 41 AV&#039;s picked up the malware?

Also, looking forward to your anti-virus solutions later this year, sound interesting? Will there be a beta for people to try out? (interface, CPU and RAM load etc)

Richard]]></description>
		<content:encoded><![CDATA[<p>Thanks for the advice. Nice to see you guys are on top of this.</p>
<p>Out of curiosity, which 3 of the 41 AV&#8217;s picked up the malware?</p>
<p>Also, looking forward to your anti-virus solutions later this year, sound interesting? Will there be a beta for people to try out? (interface, CPU and RAM load etc)</p>
<p>Richard</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

 Served from: www.gfi.com @ 2013-08-12 15:09:30 by W3 Total Cache --