<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Infected file in Security</title>
<link>http://www.dslreports.com/forum/r20213441</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 01:05:22 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 01:05:22 EDT</lastBuildDate>

<item>
<title>Re: Infected file</title>
<link>http://www.dslreports.com/forum/remark,20213441</link>
<description><![CDATA[<A HREF="/useremail/u/817075"><b>Kiwi</b></A> : Apparently is not a false positive...<br><br>"The malware determines the location of the current Windows folder by querying the operating system. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP is C:\Windows.<br>%Temp% is a variable location and refers to the directory designated for temporary files. The malware determines the location of the current Temp folder by querying the operating system. A typical path is "C:\Documents and Settings\\Local Settings\Temp", or "C:\WINDOWS\TEMP". <br>If the current day is the 9th, it adds the following text to the infected file:<br><br>"This file is infected by Html.Lame!" <br>"What a virus! ;)"<br><br>Cheers]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20213441</guid>
<pubDate>Sun, 23 Mar 2008 17:39:14 EDT</pubDate>
</item>

<item>
<title>Re: Infected file</title>
<link>http://www.dslreports.com/forum/remark,20213403</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Maybe CA AV removed it initially. Thats why you did not find it again on the scan. I dont have this product so cant offer much more help. Are there any logs/quarantines/etc to look at?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20213403</guid>
<pubDate>Sun, 23 Mar 2008 17:31:46 EDT</pubDate>
</item>

<item>
<title>Infected file</title>
<link>http://www.dslreports.com/forum/remark,20213286</link>
<description><![CDATA[<A HREF="/useremail/u/1117247"><b>jbryan</b></A> : I got the following message from my CA Anti Virus real time scanner progrm today.  I ran a full system scan and CA does not find it.  I tried searching for this on c drive and cannot find it anywhere.  Any suggestions?<br><br>3/23/2008 13:39:23 PM File infection: \Device\HarddiskVolumeShadowCopy6\PAGEFILE.SYS is infected with JS/Lame.A virus. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20213286</guid>
<pubDate>Sun, 23 Mar 2008 17:07:51 EDT</pubDate>
</item>

</channel>
</rss>
