<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
   <channel>
      <title>Making Light :: CNN Spam? :: comments</title>
      <link>http://nielsenhayden.com/makinglight/archives/010477.html#comments </link>
      <description>Language, fraud, folly, truth, history, and knitting. Et cetera.</description>
      <language>en</language>
      <lastBuildDate>Sat, 16 Aug 2008 12:42:16 -0500</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=4.261</generator>
      
      <item>
      <title>CNN Spam?</title>
      <description>Over on the so-called &quot;CNN Blog&quot; we find this entry: August 8, 2008 Fraudulent spam about CNN.com Posted: 07:45 PM...</description>
      <content:encoded>Over on the so-called "CNN Blog" we find this entry: August 8, 2008 Fraudulent spam about CNN.com Posted: 07:45 PM...</content:encoded>
      <link>http://nielsenhayden.com/makinglight/archives/010477.html</link>
      </item>

      
      <item>
         <title>CNN Spam? -- comment #1 from Brenda Kalt</title>
         <description>comment from Brenda Kalt on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>I got eight copies in my work account on Friday. Since I never open anything that looks unfamiliar, I don't know what was in it.</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:10 PM by Brenda Kalt&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286430</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286430</guid>
         <pubDate>Sun, 10 Aug 2008 23:10:33 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #2 from Michael C.</title>
         <description>comment from Michael C. on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>From Slashdot:<br />
More than a thousand hacked Web sites are serving up fake Flash Player software to users duped into clicking on links in mail that's part of a massive spam attack masquerading as CNN.com news notifications, security researchers said today. The bogus messages, which claim to be from the CNN.com news Web site, include links to what are supposedly the day's Top 10 news stories and Top 10 news video clips from the cable network. Clicking on any of those links, however, brings up a dialog that says an incorrect version of Flash Player has been detected and that tells users they needed to update to a fake newer edition, which delivers a Trojan horse — identified by multiple names, including Cbeplay.a — that 'phones home' to a malicious server to grab and install additional malware.<br />
</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:19 PM by Michael C.&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286432</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286432</guid>
         <pubDate>Sun, 10 Aug 2008 23:19:36 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #3 from Henry Richardson</title>
         <description>comment from Henry Richardson on 10.Aug.08</description>
         <content:encoded><![CDATA[<p><a href="http://sunbeltblog.blogspot.com/2008/08/fake-cnn-headlines.html" rel="nofollow">Sunbelt blog</a> explains the CNN spam.</p>

<p><br />
</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:27 PM by Henry Richardson&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286433</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286433</guid>
         <pubDate>Sun, 10 Aug 2008 23:27:03 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #4 from Will &quot;scifantasy&quot; Frank</title>
         <description>comment from Will "scifantasy" Frank on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>Huh, and possibly dammit.</p>

<p>I started getting those CNN Top Ten emails the other day. I thought I'd just been resubscribed to a list, so I hit the unsubscribe link. It took a few times but then the emails stopped.</p>

<p>Then again, I run Gentoo Linux, so I doubt the flash player .exe would have done much, even if I saw it (which I didn't). I guess I should just keep an eye, and watch my spamcatcher in case a lot more starts coming...</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:30 PM by Will &quot;scifantasy&quot; Frank&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286434</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286434</guid>
         <pubDate>Sun, 10 Aug 2008 23:30:50 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #5 from Jen Roth</title>
         <description>comment from Jen Roth on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>The ones we got at our university a couple of days ago led the user to download fake antivirus software. </p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:33 PM by Jen Roth&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286435</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286435</guid>
         <pubDate>Sun, 10 Aug 2008 23:33:27 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #6 from Clifton Royston</title>
         <description>comment from Clifton Royston on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>As Michael C. says just above, it's a massive multi-platform virus distribution burst, fueled by computers already infected with the Rustock bot and driving users to cracked websites (and possibly to some run by co-conspirators and collaborators.)</p>

<p>Here's some analysis: <a href="http://garwarner.blogspot.com/2008/08/linking-all-news-spam-together-cnncom.html" rel="nofollow"></a></p>

<p>One large site reports this botnet is now accounting for about 5-6% of its inbound spam.</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:36 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286436</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286436</guid>
         <pubDate>Sun, 10 Aug 2008 23:36:56 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #7 from Clifton Royston</title>
         <description>comment from Clifton Royston on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>Sorry, dropped the URL; that should have gone here: <a href="http://garwarner.blogspot.com/2008/08/linking-all-news-spam-together-cnncom.html" rel="nofollow">Linking all the news spam together.</a></p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:38 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286438</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286438</guid>
         <pubDate>Sun, 10 Aug 2008 23:38:09 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #8 from Azz</title>
         <description>comment from Azz on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>Text of it: </p>

<p>Title: CNN Alerts: My Custom Alert<br />
	Your E-Mail Alerts<br />
Alert Name: My Custom Alert</p>

<p>Tropical Storm Edouard moving toward Texas coast<br />
Sun, 10 Aug 2008 18:40:36 -0600</p>

<p>FULL STORY</p>

<p>You have agreed to receive this email from CNN.com as a result of your CNN.com preference settings.<br />
To manage your settings click here.<br />
To alter your alert criteria or frequency or to unsubscribe from receiving custom email alerts, click here.</p>

<p>Cable News Network. One CNN Center, Atlanta, Georgia 30303<br />
© 2008 Cable News Network.<br />
A Time Warner Company<br />
All Rights Reserved.<br />
View our privacy policy and terms. </p>

<p>I cleared out a boatload of them this morning; I'm not sure if there were others with different text. </p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:42 PM by Azz&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286439</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286439</guid>
         <pubDate>Sun, 10 Aug 2008 23:42:00 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #9 from FungiFromYuggoth</title>
         <description>comment from FungiFromYuggoth on 10.Aug.08</description>
         <content:encoded><![CDATA[<p><a href="http://blogs.zdnet.com/security/?p=1657" rel="nofollow">ZDnet has another article on the CNN spam</a>, which references <a href="http://blog.threatfire.com/2008/07/cbevtsvcexe-is-not-flash.html" rel="nofollow">a more technical writeup on Threatfire</a> of a similar attack.</p>

<p>The description of what's going on might be vague because the attack is multifaceted: a barrage of attempts to exploit the client browser followed by "Hi, please run my trojan horse, kthxbye".</p>

<p>It appears that the user may be the upper bound on system security.</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:42 PM by FungiFromYuggoth&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286440</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286440</guid>
         <pubDate>Sun, 10 Aug 2008 23:42:26 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #10 from James D. Macdonald</title>
         <description>comment from James D. Macdonald on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>Well, I am answered.</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:43 PM by James D. Macdonald&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286441</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286441</guid>
         <pubDate>Sun, 10 Aug 2008 23:43:33 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #11 from alice</title>
         <description>comment from alice on 10.Aug.08</description>
         <content:encoded><![CDATA[<p>I've received several hundred of these, as my work address gets submission email for several internal mailing lists forwarded to it.</p>]]>
	 &lt;p&gt;Posted August 10, 2008 11:59 PM by alice&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286442</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286442</guid>
         <pubDate>Sun, 10 Aug 2008 23:59:43 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #12 from Lizzy L</title>
         <description>comment from Lizzy L on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I got one a few days ago. I opened it, clicked on a story, and got the Flash Player message. I then closed and deleted the whole thing without downloading anything. It was very professional-looking, none of the usual misspellings and grammar errors one usually finds with those nasty things. </p>

<p>My anti-virus software has been quiet. I ran Ad-Aware today and it came up with just the usual stuff, cookies and so on. </p>

<p>Feh.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:02 AM by Lizzy L&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286445</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286445</guid>
         <pubDate>Mon, 11 Aug 2008 01:02:22 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #13 from Paula Helm Murray</title>
         <description>comment from Paula Helm Murray on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I've got a Mac and filters set on 'decapitate" so  I get very little spam email.</p>

<p>And the ones that do come through are often phishing from places I do not have a bank account with. ( iam with what used to be Federal Employees Credit Union) and they are wise to such assaults.</p>

<p>On the other hand I'm  kind of glad my mom is willfully ignorant of computers in general and the Internet specifically.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:36 AM by Paula Helm Murray&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286449</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286449</guid>
         <pubDate>Mon, 11 Aug 2008 01:36:36 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #14 from Michael Roberts</title>
         <description>comment from Michael Roberts on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I've been tracking it for two weeks.  It's the Storm botnet, and it's the same group that had the funky headlines between June and July.  They started using a "CNN Daily Top 10" video email on August 4, then switched to "CNN Alerts: My Custom Alert" on August 7.  I kind of expected them to switch today, but I'll bet we'll be seeing something by tomorrow morning at the latest.</p>

<p>I have about 8000 copies of just those purporting to be from CNN, if you want, and a more or less complete analysis <a href="http://www.vivtek.com/projects/despammed/stormspam.html" rel="nofollow">here</a>.  I first got interested when I saw the groovy Javascript exploits on the hijacked target servers.</p>

<p>I've also identified about 15,000 IPs of zombie PCs injecting the stuff.  The reason for this wave lately is that they're falling behind and need new PCs.  But the blitz has made it possible for me to see them -- so all in all, it's been pretty damned nice.</p>

<p>Fascinatingly, there's an "Internet Explorer 7" upgrade spam from a completely different botnet for the same purpose, which just started up today.</p>

<p>At Despammed.com, I get a lot of spam.  You may think you get a lot of spam.  Ha.  I laugh.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:46 AM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286451</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286451</guid>
         <pubDate>Mon, 11 Aug 2008 01:46:34 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #15 from Wirelizard</title>
         <description>comment from Wirelizard on 11.Aug.08</description>
         <content:encoded><![CDATA[<p><em>It appears that the user may be the upper bound on system security.</em></p>

<p>It always has been, really.</p>

<p>There once was a noob on the 'net<br />
who hadn't caught viruses, yet.<br />
Spam from Russia, quite graphic,<br />
made his computer quite spastic,<br />
That foolish young noob on the 'net.</p>

<p>(No, I'm not happy with graphic/spastic either, but what can you do when only the first two lines spring fully-formed and demand completion?)</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:51 AM by Wirelizard&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286452</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286452</guid>
         <pubDate>Mon, 11 Aug 2008 01:51:57 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #16 from Sean Pratz</title>
         <description>comment from Sean Pratz on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>CNN spam? Today I got one about a politician's two-year-old affair, and a few days earlier another about an actor's car accident. Yet I haven't heard a damned thing about, for example, the DHS's laptop seizure policy, or any of the other liberties Americans have lost in the last seven years.</p>

<p>Boing Boing's where I get the <i>real</i> news.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:52 AM by Sean Pratz&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286453</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286453</guid>
         <pubDate>Mon, 11 Aug 2008 01:52:03 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #17 from Michael Roberts</title>
         <description>comment from Michael Roberts on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>Will - by the way, don't worry about having clicked the unsubscribe link.  That actually goes to CNN; they copied it wholesale for verisimilitude.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:55 AM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286454</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286454</guid>
         <pubDate>Mon, 11 Aug 2008 01:55:25 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #18 from eric</title>
         <description>comment from eric on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>A metric ton of them here, at least, that weren't caught in mail.app's spam filter. </p>

<p>For a few weeks I was trending down to 1000 spam (caught) a week, but it looks like I'm back up in the 3500 range again. </p>

<p><br />
</p>]]>
	 &lt;p&gt;Posted August 11, 2008  2:45 AM by eric&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286457</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286457</guid>
         <pubDate>Mon, 11 Aug 2008 02:45:05 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #19 from Paula Lieberman</title>
         <description>comment from Paula Lieberman on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>Wirelizard #15</p>

<p>There once was a noob on the 'net<br />
who hadn't caught viruses, yet.<br />
But "Hot babes and sex!"<br />
Were just the right hex<br />
And now his hard drive's been reset.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  2:48 AM by Paula Lieberman&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286461</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286461</guid>
         <pubDate>Mon, 11 Aug 2008 02:48:15 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #20 from Elaine</title>
         <description>comment from Elaine on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I gave my mother an Ubuntu Linux rebuilt system three months ago.  She is no less clueless on Linux than she was on Windows, but at least the damage is a little more limited.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  8:04 AM by Elaine&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286487</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286487</guid>
         <pubDate>Mon, 11 Aug 2008 08:04:30 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #21 from Vicki</title>
         <description>comment from Vicki on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>My company's IT department sent around a warning about this a week or so back: apparently a number of my coworkers had received it at their work email addresses, and opened it, leaving viruses on their system. I got it at my usual home address, thought "oh, spam" and deleted the two or three copies that were there right away, and have removed more since. I don't know if my coworkers are actually on some kind of CNN mailing list, as I am not, or are just a bit more gullible. (I have been online longer than most of the people at my office, and dealt with more of this crap as a result.)</p>]]>
	 &lt;p&gt;Posted August 11, 2008  9:35 AM by Vicki&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286498</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286498</guid>
         <pubDate>Mon, 11 Aug 2008 09:35:44 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #22 from Bruce Cohen (SpeakerToManagers)</title>
         <description>comment from Bruce Cohen (SpeakerToManagers) on 11.Aug.08</description>
         <content:encoded><![CDATA[<p><b>Vicki @ 21</b></p>

<p><i>I have been online longer than most of the people at my office, and dealt with more of this crap as a result.</i></p>

<p>As the saying goes, "The pioneers are the ones with the arrows in their backs."<br />
</p>]]>
	 &lt;p&gt;Posted August 11, 2008  9:46 AM by Bruce Cohen (SpeakerToManagers)&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286500</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286500</guid>
         <pubDate>Mon, 11 Aug 2008 09:46:02 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #23 from Kevin Reid</title>
         <description>comment from Kevin Reid on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>#9: "It appears that the user may be the upper bound on system security."</p>

<p>There's lots of room for bad software design (say, outdated threat models, such as assuming that every program acts on its user's behalf), and bad user interface design (such as patching the former model by asking the user for confirmation of the program's actions), to produce values well below that bound.</p>]]>
	 &lt;p&gt;Posted August 11, 2008 12:09 PM by Kevin Reid&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286518</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286518</guid>
         <pubDate>Mon, 11 Aug 2008 12:09:27 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #24 from Jillian</title>
         <description>comment from Jillian on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I just got my 2nd - both were re Obama</p>

<p>"CNN Alerts: My Custom Alert‏<br />
From: 	CNN Alerts <br />
	Medium riskYou may not know this sender.Mark as safe|Mark as unsafe<br />
Sent: 	Mon 8/11/08 7:16 PM<br />
Reply-to: 	<br />
To: 	<br />
	Your E-Mail Alerts<br />
Alert Name: My Custom Alert</p>

<p>Obama visit Iraq, boo-ed off stage<br />
Thu, 7 Aug 2008 21:47:46 +0200</p>

<p>FULL STORY</p>

<p>You have agreed to receive this email from CNN.com as a result of your CNN.com preference settings.<br />
To manage your settings click here.<br />
To alter your alert criteria or frequency or to unsubscribe from receiving custom email alerts, click here.</p>

<p>Cable News Network. One CNN Center, Atlanta, Georgia 30303<br />
© 2008 Cable News Network.<br />
A Time Warner Company<br />
All Rights Reserved.<br />
View our privacy policy and terms. </p>]]>
	 &lt;p&gt;Posted August 11, 2008  1:00 PM by Jillian&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286531</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286531</guid>
         <pubDate>Mon, 11 Aug 2008 13:00:18 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #25 from Hank Roberts</title>
         <description>comment from Hank Roberts on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>Lots and lots of CNN spam since it started.<br />
Number caught increasing steadily (Postini at work and SpamCop at home are doing a good job catching these now, after some got through last week).</p>]]>
	 &lt;p&gt;Posted August 11, 2008  2:52 PM by Hank Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286573</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286573</guid>
         <pubDate>Mon, 11 Aug 2008 14:52:10 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #26 from Cat Meadors</title>
         <description>comment from Cat Meadors on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>Neat! I just checked my spam trap and there were over 50 of these in there. I guess the botnet is warming up...</p>

<p>(Was "Melissa" the "I love you" virus? Whichever, I had to clean up that mess because one of my users had it sent from a woman he was, actually, desperately in love with. It doesn't even take something this well-done to get people to do dumb things. Although, now I'm wondering about one of my apps that asks me to upgrade it every time I start it... hrm...)</p>]]>
	 &lt;p&gt;Posted August 11, 2008  3:24 PM by Cat Meadors&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286580</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286580</guid>
         <pubDate>Mon, 11 Aug 2008 15:24:28 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #27 from Nenya</title>
         <description>comment from Nenya on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>Ooh, I saw this! My Gmail has been catching these by the bucketload this week. It's kind of strange to see a whole page of spam subject lines, all alike. (Since that address is not signed up for any services remotely like CNN, I wouldn't have clicked anyway. I can't say I'm immune to doing stupid things online, but at least this one wasn't a temptation at all.)</p>]]>
	 &lt;p&gt;Posted August 11, 2008  6:13 PM by Nenya&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286620</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286620</guid>
         <pubDate>Mon, 11 Aug 2008 18:13:52 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #28 from Earl Cooley III</title>
         <description>comment from Earl Cooley III on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I feel a bit left out. No CNN spam here; most of mine is either Russian, Chinese, German, or in character sets my email reader isn't set up to interpret correctly.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  6:46 PM by Earl Cooley III&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286628</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286628</guid>
         <pubDate>Mon, 11 Aug 2008 18:46:43 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #29 from Stefan Jones</title>
         <description>comment from Stefan Jones on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>#28: Don't feel bad. I only get the CNN mail at my work address.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  6:51 PM by Stefan Jones&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286629</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286629</guid>
         <pubDate>Mon, 11 Aug 2008 18:51:23 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #30 from rmb</title>
         <description>comment from rmb on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I've gotten a bunch of these.  I was somewhat perplexed because the headlines looked real and the links at the bottom were actually to cnn.com.  But I've never signed up with cnn.com, and when I typed in the url of the `unsubscribe' link, it had no record of any account of mine.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  7:02 PM by rmb&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286633</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286633</guid>
         <pubDate>Mon, 11 Aug 2008 19:02:00 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #31 from Scorpio</title>
         <description>comment from Scorpio on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>I got one at my home ISP and a couple in G-mail.  Never opened them.  I read the news where I want to and I ignore solicitations.</p>]]>
	 &lt;p&gt;Posted August 11, 2008  8:53 PM by Scorpio&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286651</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286651</guid>
         <pubDate>Mon, 11 Aug 2008 20:53:24 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #32 from Michael Roberts</title>
         <description>comment from Michael Roberts on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>All y'all following the story, they <a href="http://www.vivtek.com/projects/despammed/storm_page_analysis_4058864712-3087703986.html" rel="nofollow">switched landing pages again</a>.  About time, too!  It had been four days since they did anything worthy of analysis.</p>

<p>The new one pops up a window at asvoo.org, but I'm positive it's also been hijacked, as I see no reason for a consulting company in Germany to be actively aiding and abetting the botnet.  I emailed them to tell them they've been featured.  We'll see if it has any effect.</p>]]>
	 &lt;p&gt;Posted August 11, 2008 10:26 PM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286661</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286661</guid>
         <pubDate>Mon, 11 Aug 2008 22:26:19 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #33 from Josh Jasper</title>
         <description>comment from Josh Jasper on 11.Aug.08</description>
         <content:encoded><![CDATA[<p>My CEO just sent a pleading note to the rest of the company to get him off of CNN's mailing list, as he was getting 50 or so alerts a day.</p>

<p>Our COO just accused the SVP of Biz Dev of signing us all up for the alerts.</p>

<p>Guess what sort of company I work for.</p>

<p>Yes, a <b>technnology</b> company! </p>]]>
	 &lt;p&gt;Posted August 11, 2008 11:29 PM by Josh Jasper&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286669</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286669</guid>
         <pubDate>Mon, 11 Aug 2008 23:29:10 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #34 from geekosaur</title>
         <description>comment from geekosaur on 12.Aug.08</description>
         <content:encoded><![CDATA[<p><strong>Cat Meadors @<a href="http://nielsenhayden.com/makinglight/archives/010477.html#286580" rel="nofollow">26</a>:</strong><br />
yep, "I Love You" was the "Melissa" virus.  My sister's still kinda peeved about it (guess her name :)</p>

<p>I've been seeing the "CNN" spam increasing over the past few days; my Cyrus sieve scripts have been catching it on my home and work accounts, and the other accounts haven't been used enough to show up on anyone's radar (although, hm, they should have harvested the GMail one by now).  I still need to rewrite my home Sieve script:  I used two different kinds of whitelists to see which one would work better, and the one on my work account is much more reliable (fewer false positives, very very few false negatives; home accunt is so-so on both.</p>]]>
	 &lt;p&gt;Posted August 12, 2008 12:25 AM by geekosaur&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286679</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286679</guid>
         <pubDate>Tue, 12 Aug 2008 00:25:06 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #35 from Joyce Reynolds-Ward</title>
         <description>comment from Joyce Reynolds-Ward on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Yeah, my spam filter's been catching a lot of these of late.  Since I don't subscribe to anything CNNish, I figured it was some sort of weird spam and cleared it without looking.</p>

<p>(and I've very, very happy to have an ISP with a reasonable spam filter that I can check on a daily basis with a minimum of fuss.  For some reason the Tor newsletters get stuck there, no matter how often I whitelist them)</p>]]>
	 &lt;p&gt;Posted August 12, 2008 12:42 AM by Joyce Reynolds-Ward&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286683</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286683</guid>
         <pubDate>Tue, 12 Aug 2008 00:42:32 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #36 from Marilee</title>
         <description>comment from Marilee on 12.Aug.08</description>
         <content:encoded><![CDATA[<p><b>Wirelizard</b>, #15, the third & fourth lines have too many syllables, too.  It's Da dada Da or da Da dada Da.</p>

<p>I haven't had any.  Most of my spam either comes with all ?????s or are from people pretending to be banks with which I don't have accounts.  Oh, and I still get the occasional lottery.</p>]]>
	 &lt;p&gt;Posted August 12, 2008 12:50 AM by Marilee&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286684</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286684</guid>
         <pubDate>Tue, 12 Aug 2008 00:50:36 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #37 from dcb</title>
         <description>comment from dcb on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>So I'm not the only one getting "CNN Alert: My Custom Alert" spam - I'm deleting about 10 or so a day at present. </p>]]>
	 &lt;p&gt;Posted August 12, 2008  4:22 AM by dcb&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286710</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286710</guid>
         <pubDate>Tue, 12 Aug 2008 04:22:23 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #38 from Casey Rousseau</title>
         <description>comment from Casey Rousseau on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Over the last week, these messages have become a *majority* of the spam caught by my work postini account!</p>]]>
	 &lt;p&gt;Posted August 12, 2008  7:30 AM by Casey Rousseau&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286725</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286725</guid>
         <pubDate>Tue, 12 Aug 2008 07:30:53 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #39 from Tykewriter</title>
         <description>comment from Tykewriter on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Just to join in the general. I've been getting them too. Gmail sends them straight to the Spam box. Sometimes it's a relief to hear from old Denis Enlargement again. Nothing in blueyonder, though.</p>]]>
	 &lt;p&gt;Posted August 12, 2008  9:29 AM by Tykewriter&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286734</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286734</guid>
         <pubDate>Tue, 12 Aug 2008 09:29:18 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #40 from Janet Croft</title>
         <description>comment from Janet Croft on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Thanks -- yeah, these weren't ringing my "spam alert" bells, but I blocked the "top 10" anyway because it was annoying.  I got one of the "custom alerts" today and thought it might actually BE one of my custom alerts, but now I know to look closely at the topic (it COULD have been -- MAYBE Iceland had won a medal in the summer Olympics...)</p>]]>
	 &lt;p&gt;Posted August 12, 2008 11:00 AM by Janet Croft&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286750</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286750</guid>
         <pubDate>Tue, 12 Aug 2008 11:00:25 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #41 from Earl Cooley III</title>
         <description>comment from Earl Cooley III on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>At last, oh, at last! My long, dark desolation of rejection is over! I've finally received my very own precious copy of the CNN Spam. I've kept it undeleted in my Junk email shrine so that I may partake (with rhino-hide gloves and thick goggles) of its awe-inspiring perfection. It completes me.</p>]]>
	 &lt;p&gt;Posted August 12, 2008  3:49 PM by Earl Cooley III&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286794</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286794</guid>
         <pubDate>Tue, 12 Aug 2008 15:49:21 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #42 from Michael Roberts</title>
         <description>comment from Michael Roberts on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Earl, we're all happy for you.</p>]]>
	 &lt;p&gt;Posted August 12, 2008  8:05 PM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286829</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286829</guid>
         <pubDate>Tue, 12 Aug 2008 20:05:57 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #43 from Marilee</title>
         <description>comment from Marilee on 12.Aug.08</description>
         <content:encoded><![CDATA[<p>Ha!  I thought to look at the bitbucket mail from my domain and I have batches there!  You know how when you look at Usenet on Google, they ellipse the end of the name in the edress?  Well, that's what mine are all directed to.</p>]]>
	 &lt;p&gt;Posted August 12, 2008  9:44 PM by Marilee&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286845</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286845</guid>
         <pubDate>Tue, 12 Aug 2008 21:44:41 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #44 from Michael Roberts</title>
         <description>comment from Michael Roberts on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>msnbc.com - BREAKING NEWS: Botnet changes spam subjects again.</p>]]>
	 &lt;p&gt;Posted August 13, 2008  9:10 AM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286895</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286895</guid>
         <pubDate>Wed, 13 Aug 2008 09:10:41 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #45 from Phil</title>
         <description>comment from Phil on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>One of our employees recently downloaded or opened one of these emails and it turned his computer into a zombie.  Consequently inundating the web with thousands of the SMTP CNN emails.  </p>

<p>Does anybody have any idea how to get rid of this.</p>

<p>I've run Spybot S & D, CA, and Avg, but all came back clean.</p>

<p>Help please.</p>]]>
	 &lt;p&gt;Posted August 13, 2008  9:35 AM by Phil&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286896</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286896</guid>
         <pubDate>Wed, 13 Aug 2008 09:35:01 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #46 from Michael I</title>
         <description>comment from Michael I on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Michael Roberts@44</p>

<p>Also BBC</p>]]>
	 &lt;p&gt;Posted August 13, 2008 10:26 AM by Michael I&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286898</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286898</guid>
         <pubDate>Wed, 13 Aug 2008 10:26:54 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #47 from Jon Meltzer</title>
         <description>comment from Jon Meltzer on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>I just saw this spam mentioned on a college mailing list I subscribe to. I redirected them here as this thread has the best collection of links on it I've seen. </p>

<p>(Don't worry about the n00bs: many of them are fen and the others are just as cool)</p>]]>
	 &lt;p&gt;Posted August 13, 2008 10:43 AM by Jon Meltzer&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286901</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286901</guid>
         <pubDate>Wed, 13 Aug 2008 10:43:35 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #48 from Jon Meltzer</title>
         <description>comment from Jon Meltzer on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>#33: Been there, done that, same business.</p>

<p>You really wonder, sometimes. <br />
</p>]]>
	 &lt;p&gt;Posted August 13, 2008 10:50 AM by Jon Meltzer&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286902</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286902</guid>
         <pubDate>Wed, 13 Aug 2008 10:50:42 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #49 from Jim Macdonald</title>
         <description>comment from Jim Macdonald on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>May I suggest that all Windows users pick up <a href="http://www.greyware.com/software/grr/" rel="nofollow">Grr!</a></p>

<p>It blocks things from installing themselves on your computer without your explicit permission(and can be centrally managed on large networks).</p>]]>
	 &lt;p&gt;Posted August 13, 2008 11:50 AM by Jim Macdonald&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286909</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286909</guid>
         <pubDate>Wed, 13 Aug 2008 11:50:59 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #50 from Michael Roberts</title>
         <description>comment from Michael Roberts on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Jon: don't worry about the n00bs, we like them.  (They're so crunchy after proper frying.)</p>

<p>Michael I: huh?  Can you give me a couple of subjects?  Because I'm not seeing any faux-BBC coming in over the botnet IPs I'm monitoring.</p>

<p>Oh!  I see: "BBC NEWS" -- but that's not the same people.  That one's redirecting to news.avi.exe; goodness, but there are a lot of bad guys these days.</p>

<p>Phil: I'm trying to find the removal instructions I ran across yesterday.  If I do, I'll post them.</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:08 PM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286912</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286912</guid>
         <pubDate>Wed, 13 Aug 2008 12:08:29 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #51 from FungiFromYuggoth</title>
         <description>comment from FungiFromYuggoth on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Phil:  I'd recommend getting a shareware spyware removal tool like <a href="http://www.webroot.com/En_US/consumer-products-spysweeper.html" rel="nofollow">Spyware Sweeper</a> for about $30.</p>

<p>There's some technical details about what gets installed - Trojan-Downloader.Agent.EL - and how to remove it <a href="" rel="nofollow">at Enigma Software</a>, but since the spam is a moving target you're better off with a tool.  The Enigma site (naturally) recommends <a href="http://www.enigmasoftware.com/download/spyhunterS100943.exe" rel="nofollow">their own software</a>.</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:13 PM by FungiFromYuggoth&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286914</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286914</guid>
         <pubDate>Wed, 13 Aug 2008 12:13:37 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #52 from FungiFromYuggoth</title>
         <description>comment from FungiFromYuggoth on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Also naturally, I screwed up the <a href="http://www.enigmasoftware.com/support/cnncomdailytop10-removal" rel="nofollow">main link I was trying to post</a>.</p>

<p>What was I saying about the user being the upper bound?  Oh well.  That has always been the case, but the lower bound was sufficiently far away from the upper that it wasn't obvious.</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:15 PM by FungiFromYuggoth&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286916</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286916</guid>
         <pubDate>Wed, 13 Aug 2008 12:15:38 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #53 from Clifton Royston</title>
         <description>comment from Clifton Royston on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Just for info, the CNN spams have morphed into MSNBC headline spams, and a different spammer has decided they like this approach enough to start using BBC headline spams.</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:33 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286922</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286922</guid>
         <pubDate>Wed, 13 Aug 2008 12:33:49 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #54 from Clifton Royston</title>
         <description>comment from Clifton Royston on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Oh, and I see Michael beat me to it way upthread.  's what I get for being in a later timezone.</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:35 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286924</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286924</guid>
         <pubDate>Wed, 13 Aug 2008 12:35:49 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #55 from Michael Roberts</title>
         <description>comment from Michael Roberts on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>The BBC News IP pool doesn't coincide with the IE 7 update spam from a couple of days ago, either.  That makes at least three botnets, unless they use different segments of their pool for different applications.  (That theory doesn't hold up, though, because the CNN/news headline group <i>has</i> spammed on other topics, and is still doing so, although at lower intensity.)</p>

<p>The more I look, the more there is to see...</p>]]>
	 &lt;p&gt;Posted August 13, 2008 12:52 PM by Michael Roberts&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286930</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286930</guid>
         <pubDate>Wed, 13 Aug 2008 12:52:55 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #56 from Jon Meltzer</title>
         <description>comment from Jon Meltzer on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>#45, #51: Also try this <a href="http://www.windowsvistaplace.com/cnncom-daily-top-10-trojan-downloaderagentel-removal-guide/othersoftware" rel="nofollow">link</a>.</p>

<p>No guarantees; I haven't needed to get rid of the virus myself. I hope the user has been backing up because it looks like the easiest thing to do might be to reformat, reinstall, and restore.</p>]]>
	 &lt;p&gt;Posted August 13, 2008  1:03 PM by Jon Meltzer&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286931</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286931</guid>
         <pubDate>Wed, 13 Aug 2008 13:03:55 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #57 from Stefan Jones</title>
         <description>comment from Stefan Jones on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Got my first MSNBC spam just this morning! The lead story link goes to somesite in Japan. </p>]]>
	 &lt;p&gt;Posted August 13, 2008  1:32 PM by Stefan Jones&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286936</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286936</guid>
         <pubDate>Wed, 13 Aug 2008 13:32:06 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #58 from Jon Meltzer</title>
         <description>comment from Jon Meltzer on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>A prevention utility that might help in future recovery from viruses like this one:</p>

<p>Most backup programs that I know of do not back up the Windows registry. I have on my computers <a href="http://www.snapfiles.com/get/erunt.html" rel="nofollow">ERUNT</a>, a freeware utility that automatically backs up the registry every day. The only "flaw" is that every so often I have to go to ERUNT's storage directory and clean out the clutter. But that's trivial.</p>

<p>This has saved me a couple of times. It's not just viruses one has to worry about; a power failure at the right time can trash one's registry. </p>]]>
	 &lt;p&gt;Posted August 13, 2008  1:58 PM by Jon Meltzer&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286948</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286948</guid>
         <pubDate>Wed, 13 Aug 2008 13:58:28 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #59 from Clifton Royston</title>
         <description>comment from Clifton Royston on 13.Aug.08</description>
         <content:encoded><![CDATA[<p>Phil @ 45:<br />
Serious answer here: The virus and malware developers have developed very sophisticated hooks to selectively hide their software from the antivirus software or to disable it from really removing all their hooks.  Once it's on the computer, you can't be really sure of cleaning it all out, because you can no longer trust anything the computer sees.  That's what they mean by "owned" - you only see what the malware wants you to see.  The only way to be sure is start from scratch.</p>

<p>At this point with the current virus state-of-the-art, I'd recommend backing up all data files (documents, databases, address books, etc.) to offline media, wiping the hard disk, and reinstalling Windows from scratch.  That's the same as I'd do for a cracked Linux or Unix server.  It's a harsh road, but it's the only way to be sure you've got it all.</p>

<p>(One advantage you do have with Linux is that you can boot the computer from a standalone CD and then use tools on the CD to check and disinfect the system; but it's been a long time since you could boot into Windows from a floppy or CD, other than to install.)</p>

<p>Here's a good article from last fall on what I'm talking about: <br />
Security researcher Peter Gutmann's <a href="http://www.cs.auckland.ac.nz/~pgut001/pubs/malware_biz.pdf" rel="nofollow">The Commercial Malware Industry</a><br />
(5 second summary: the bad guys are winning, by miles.)</p>]]>
	 &lt;p&gt;Posted August 13, 2008  2:54 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#286960</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#286960</guid>
         <pubDate>Wed, 13 Aug 2008 14:54:22 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #60 from Phil</title>
         <description>comment from Phil on 14.Aug.08</description>
         <content:encoded><![CDATA[<p>update:</p>

<p>It turns out the user downloaded something thats looks similar to XP Antivirus.  Which he got from a link in an email. He tells me that he thought it was one of his friends emailing it to him. WRONG!</p>

<p>BTW, XP anitvirus looks like this;</p>

<p>http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/</p>

<p>But I'm guessing he really got the CNN Virus/worm/trojan whatever you want to label it.</p>

<p>thanks #52 and #56<br />
I will try those programs today</p>]]>
	 &lt;p&gt;Posted August 14, 2008  8:20 AM by Phil&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#287086</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#287086</guid>
         <pubDate>Thu, 14 Aug 2008 08:20:09 -0500</pubDate>
      </item>
      
      <item>
         <title>CNN Spam? -- comment #61 from Clifton Royston</title>
         <description>comment from Clifton Royston on 16.Aug.08</description>
         <content:encoded><![CDATA[<p>There are several flavors of viruses and malware which masquerade as antivirus software.  They're usually hard to remove.  Good luck.</p>

<p>I think my previous advice still stands, but hope you manage to truly remove it without having to wipe.</p>]]>
	 &lt;p&gt;Posted August 16, 2008 12:42 PM by Clifton Royston&lt;/p&gt;</content:encoded>
         <link>http://nielsenhayden.com/makinglight/archives/010477.html#287575</link>
         <guid isPermaLink="true">http://nielsenhayden.com/makinglight/archives/010477.html#287575</guid>
         <pubDate>Sat, 16 Aug 2008 12:42:16 -0500</pubDate>
      </item>
      
   </channel>
</rss>