<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Absoblogginlutely! &#187; Virus</title>
	<atom:link href="http://absoblogginlutely.net/category/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://absoblogginlutely.net</link>
	<description></description>
	<lastBuildDate>Wed, 14 Jul 2010 11:34:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Symantec have a time machine!</title>
		<link>http://absoblogginlutely.net/2008/06/symantec-have-a-time-machine/</link>
		<comments>http://absoblogginlutely.net/2008/06/symantec-have-a-time-machine/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 01:39:43 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[AntiVirus]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[nod32]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=37</guid>
		<description><![CDATA[I logged a ticket with Symantec today as I needed to download Maintenance Release 7 for their corporate edition 10.1 yet their fileconnect website only gave me version 11 (which is so unstable we refuse to install it). 2 hours later I got an email from their support site that started &#8220;We have been trying [...]<p><a href="http://absoblogginlutely.net/2008/06/symantec-have-a-time-machine/">Symantec have a time machine!</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>I logged a ticket with Symantec today as I needed to download Maintenance Release 7 for their corporate edition 10.1 yet their fileconnect website only gave me version 11 (which is so unstable we refuse to install it). 2 hours later I got an email from their support site that started &#8220;We have been trying to reach you in the last few days to assist you with the issue regarding Symantec Antivirus but unfortunately we have not been able to do so.&#8221;<br />
I guess they&#8217;ve invented a time machine in order to try and beat their really long wait times on hold for support&#8230;..either that or I forgot that I logged a ticket several days ago and they&#8217;ve finally got round to dealing with it!<br />
Anyway, they&#8217;ve given me a new serial number to log into the website with so I can download the older version. I&#8217;m not sure if it&#8217;s an inplace upgrade (I hope so) rather than a removal and reinstall again &#8211; if its the removal and reinstall that means *another* 3 or 4 hours to remove, reboot, install and then fix the issues of the client software breaking other software again.<br />
I guess I *really* need to get some time to investigate nod32 network deployments &#8211; anyone had any experience with this?</p>
<p><a href="http://absoblogginlutely.net/2008/06/symantec-have-a-time-machine/">Symantec have a time machine!</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=37&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2008/06/symantec-have-a-time-machine/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Valentines day warning.</title>
		<link>http://absoblogginlutely.net/2008/02/valentines-day-warning/</link>
		<comments>http://absoblogginlutely.net/2008/02/valentines-day-warning/#comments</comments>
		<pubDate>Wed, 13 Feb 2008 19:38:40 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=68</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2008/02/valentines-day-warning/">Valentines day warning.</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>I sent this around to a couple of my user sites today. I was glad to see that some of the users did actually read the notice as I got several replies back saying it made them laugh.</p>
<p>Please note that there are several hoax valentine day cards going around the internet that links to malicious software.  If you received a valentines day ecard please do not open it and tell your loved one not to be a cheapskate and buy a real card.</p>
<p><a href="http://absoblogginlutely.net/2008/02/valentines-day-warning/">Valentines day warning.</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=68&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2008/02/valentines-day-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>STUPID Symantec antivirus &#8211; Autoit is not a virus.</title>
		<link>http://absoblogginlutely.net/2007/06/stupid-symantec-antivirus-autoit-is-not-a-virus/</link>
		<comments>http://absoblogginlutely.net/2007/06/stupid-symantec-antivirus-autoit-is-not-a-virus/#comments</comments>
		<pubDate>Fri, 01 Jun 2007 15:16:23 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=191</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2007/06/stupid-symantec-antivirus-autoit-is-not-a-virus/">STUPID Symantec antivirus &#8211; Autoit is not a virus.</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s going to be a long day for sysadmins who use AutoIT on their production Lan as symantec has detected the product as MSN.flooder in their dat files &#8211; the last time this happened was <a href="http://www.autoitscript.com/forum/lofiversion/index.php?t20546.html">Jan 2006</a>. Fortunately I only have it on a couple of pc&#8217;s but it is going to be a real pain for someone who uses it on every desktop or in login scripts. This follows about a week after they crippled thousands of chinese pc&#8217;s by detecting windows files as virus&#8217;s. I sure wouldn&#8217;t want to be a chinese sysadmin running autoit! Home users can log a report at the <a href="https://submit.symantec.com/false_positive/index.html">symantec false positive report site</a> but <a href="http://entsupport.symantec.com/docs/n2001101213393148">enterprise gold or platinum users need to contact support</a> or submit a false positive report after updating the dats. To report using the antivirus application &#8211; right click the file in quarantine and choose submit to symantec security response. Unfortunately on my work pc I don&#8217;t have rights to do this!<br />
<b>Update</b> Downloading the <a href="http://securityresponse.symantec.com/avcenter/download/pages/US-SAVCE.html">latest updates</a> to May 31st defs, releasing the files from quarantine and then scanning did not quarantine the files again.<br />
<b>Update 2</b> It looks like the same definition patterns also got a <a href="http://isc.sans.org/diary.html?storyid=2897">false positive in Search &#038; Destroy</a> according to SANS.<br />
<b>Update 3</b> Html corrected to ensure the updates appear properly.</p>
<p><a href="http://absoblogginlutely.net/2007/06/stupid-symantec-antivirus-autoit-is-not-a-virus/">STUPID Symantec antivirus &#8211; Autoit is not a virus.</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=191&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2007/06/stupid-symantec-antivirus-autoit-is-not-a-virus/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Adobe Flash player install triggers virus alerts</title>
		<link>http://absoblogginlutely.net/2007/05/adobe-flash-player-install-triggers-virus-alerts/</link>
		<comments>http://absoblogginlutely.net/2007/05/adobe-flash-player-install-triggers-virus-alerts/#comments</comments>
		<pubDate>Thu, 10 May 2007 04:54:40 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=208</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2007/05/adobe-flash-player-install-triggers-virus-alerts/">Adobe Flash player install triggers virus alerts</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>I installed Adobe&#8217;s flash player 6 on my pc tonight and was surprised to see Comodo Antivirus kick in with a &#8220;Not-a-virus:RiskTool.Win32.PsKill.q&#8221; for the nsprocess.dll file included as part of the install &#8211; presumably to kill any previous installs currently running. I&#8217;ve seen things like this with Symantec Antivirus and pskill from sysinternals before but not with Flash Player!<br />
I submitted the file to virustotal.com and got the following results.</p>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<thead>
<tr>
<td>Antivirus</td>
<td>Version</td>
<td align="center">Update</td>
<td>Result</td>
</tr>
</thead>
<tbody>
<tr>
<td>AhnLab-V3</td>
<td>2007.5.10.0</td>
<td align="center">05.09.2007</td>
<td>Win-Trojan/ProcKill.4096.B</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.4.0.15</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Authentium</td>
<td>4.93.8</td>
<td align="center">05.08.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.997.0</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>AVG</td>
<td>7.5.0.467</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td align="center">05.10.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.00</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>ClamAV</td>
<td>devel-20070416</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.33</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.15.0</td>
<td align="center">05.08.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>30.7.3622</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>FileAdvisor</td>
<td>1</td>
<td align="center">05.10.2007</td>
<td>No threat detected</td>
</tr>
<tr>
<td>Fortinet</td>
<td>2.85.0.0</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.3.2.48</td>
<td align="center">05.09.2007</td>
<td>W32/Trojan.RZG</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.70.13030.0</td>
<td align="center">05.10.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.7</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>4.0.2.24</td>
<td align="center">05.10.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>McAfee</td>
<td>5027</td>
<td align="center">05.09.2007</td>
<td>potentially unwanted program Generic PUP</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.2503</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>2255</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Norman</td>
<td>5.80.02</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td align="center">05.10.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.17.0</td>
<td align="center">05.08.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>2.2.907.0</td>
<td align="center">05.05.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td align="center">05.10.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.1.6.112</td>
<td align="center">05.10.2007</td>
<td>Trojan/KillProc.p</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.0</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.7:9</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>6.0.1</td>
<td align="center">05.09.2007</td>
<td>no virus found</td>
</tr>
</tbody>
</table>
<p>That is 5 antivirus products that presumably block or intefere with Flash from being installed.</p>
<p><a href="http://absoblogginlutely.net/2007/05/adobe-flash-player-install-triggers-virus-alerts/">Adobe Flash player install triggers virus alerts</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=208&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2007/05/adobe-flash-player-install-triggers-virus-alerts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Plesk worm on windows servers</title>
		<link>http://absoblogginlutely.net/2007/02/plesk-worm-on-windows-servers/</link>
		<comments>http://absoblogginlutely.net/2007/02/plesk-worm-on-windows-servers/#comments</comments>
		<pubDate>Tue, 27 Feb 2007 17:04:04 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=255</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2007/02/plesk-worm-on-windows-servers/">Plesk worm on windows servers</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>There has been a worm infecting Windows servers running the popular plesk package (that provides shared windows hosting) due to a vulnerability in mailenable. My host has provided <a href="http://www.hostdime.com/forums/showthread.php?t=6611">details on available fix</a>, but first they disabled pop3 access to prevent the worm spreading. An interesting method of propagation and a pretty drastic measure to stop it &#8211; hopefully everyone signs up for the forum notifications or their helpdesk is going to be very busy.</p>
<p><a href="http://absoblogginlutely.net/2007/02/plesk-worm-on-windows-servers/">Plesk worm on windows servers</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=255&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2007/02/plesk-worm-on-windows-servers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>More wmf stuff</title>
		<link>http://absoblogginlutely.net/2006/01/more-wmf-stuff/</link>
		<comments>http://absoblogginlutely.net/2006/01/more-wmf-stuff/#comments</comments>
		<pubDate>Tue, 03 Jan 2006 20:27:06 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=548</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2006/01/more-wmf-stuff/">More wmf stuff</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>There is now an <a href="http://www.hexblog.com/2005/12/wmf_vuln.html">unofficial patch out for the wmf flaw</a> but it is currently unavailable. More details at <a href="http://www.f-secure.com/weblog/archives/archive-012006.html#00000760">F-Secure&#8217;s blog</a>. SANS has a mirrored link of the patch as the original authors website is unavailable, probably because everyone is hitting his site.  However, <a href="http://64.233.179.104/search?q=cache:http%3A%2F%2Fwww.hexblog.com%2F2005%2F12%2Fwmf_vuln.html">google&#8217;s cache of the page that talks about the flaw is available</a> and worth looking at. I&#8217;m posting the details into my extended entry in case the google page gets wiped.</p>
<p><span id="more-548"></span><br />
About IDA Pro, decompilation, programming, binary program analysis, information security. By Ilfak Guilfanov.</p>
<p>« The longest arithmetic operation | Main<br />
Windows WMF Metafile Vulnerability HotFix</p>
<p>This week a new vulnerability was found in Windows:</p>
<p>http://www.microsoft.com/technet/security/advisory/912840.mspx</p>
<p>Browsing the web was not safe anymore, regardless of the browser. Microsoft will certainly come up with a thouroughly tested fix for it in the future, but meanwhile I developed a temporary fix &#8211; I badly needed it.</p>
<p>The fix does not remove any functionality from the system, all pictures will continue to be visible. You can download it here:</p>
<p>http://www.hexblog.com/security/files/wmffix_hexblog12.exe</p>
<p>It should work for Windows 2000, XP SP2 and XP 64-bit. It might also work for XP SP1 or XP without any service packs applied.</p>
<p>Technical details: this is a DLL which gets injected to all processes loading user32.dll.<br />
It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore.</p>
<p>I can imagine situations when this sequence is useful. My patch completely disables this escape sequence, so please be careful. However, with the fix installed, I can browse files, print them and do other things.</p>
<p>If for some reason the patch does not work for you, please uninstall it. It will be in the list of installed programs as &#8220;Windows WMF Metafile Vulnerability HotFix&#8221;. I&#8217;d like to know what programs are crippled by the fix, please tell me.</p>
<p>I recommend you to uninstall this fix and use the official patch from Microsoft as soon as it is available.</p>
<p>The usual software disclaimer applies&#8230;</p>
<p>File: wmffix_hexblog12.exe (the source code is included)</p>
<p>UPD: more error checking<br />
UPD2: Version 1.1 with Win2000 support<br />
UPD3: Version 1.2: if the hotfix has already been applied to the system, inform the user at the second installation attempt.<br />
There is no need to reinstall anything! Old hotfixes are perfectly ok.</p>
<p>Posted by Ilfak Guilfanov on December 31, 2005 06:53 AM | Permalink</p>
<p><a href="http://absoblogginlutely.net/2006/01/more-wmf-stuff/">More wmf stuff</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=548&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2006/01/more-wmf-stuff/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snort Vulnerability</title>
		<link>http://absoblogginlutely.net/2005/10/snort-vulnerability/</link>
		<comments>http://absoblogginlutely.net/2005/10/snort-vulnerability/#comments</comments>
		<pubDate>Thu, 20 Oct 2005 15:16:10 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=618</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2005/10/snort-vulnerability/">Snort Vulnerability</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>Although I am not aware of any customers running snort, this may be of use to other people reading this, but snort 2.4, with the Back Orifice processor enabled is vulnerable to attack as per the <a href="https://isc.sans.org/diary.php?storyid=772">details at Sans</a></p>
<p><a href="http://absoblogginlutely.net/2005/10/snort-vulnerability/">Snort Vulnerability</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=618&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2005/10/snort-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Low scammers</title>
		<link>http://absoblogginlutely.net/2005/09/low-scammers/</link>
		<comments>http://absoblogginlutely.net/2005/09/low-scammers/#comments</comments>
		<pubDate>Sat, 03 Sep 2005 20:26:34 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=683</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2005/09/low-scammers/">Low scammers</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just had a scam email pretending to be from Bank Of The West (who I&#8217;ve never even heard of) saying that there has been fraudulent activity on my bank account. A DNS lookup on the domain that they&#8217;ve registered (on Tuesday) has an address in New Orleans &#8211; probably as they know that it is going to be impossible to trace that for the forseeable future.<br />
As usual the website is actually hosted in the far east &#8211; Vietnam in this case.</p>
<p><a href="http://absoblogginlutely.net/2005/09/low-scammers/">Low scammers</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=683&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2005/09/low-scammers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Virus out for Vista</title>
		<link>http://absoblogginlutely.net/2005/08/virus-out-for-vista/</link>
		<comments>http://absoblogginlutely.net/2005/08/virus-out-for-vista/#comments</comments>
		<pubDate>Sat, 06 Aug 2005 17:35:20 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=731</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2005/08/virus-out-for-vista/">Virus out for Vista</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>8 days after Vista was released to beta, the <a title="Techworld.com - Windows Vista first virus appears" href="http://www.techworld.com/security/news/index.cfm?RSS&#038;NewsID=4163">first virus appears</a>. So an obviously secure platform then <img src='http://absoblogginlutely.net/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  At least this virus is not likely to spread very far as there are unlikely to be many vista machines in deployment</p>
<p><a href="http://absoblogginlutely.net/2005/08/virus-out-for-vista/">Virus out for Vista</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=731&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2005/08/virus-out-for-vista/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stopping zombies?</title>
		<link>http://absoblogginlutely.net/2005/05/stopping-zombies/</link>
		<comments>http://absoblogginlutely.net/2005/05/stopping-zombies/#comments</comments>
		<pubDate>Tue, 31 May 2005 14:33:50 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://absoblogginlutely.net/migrate/?p=866</guid>
		<description><![CDATA[
<p><a href="http://absoblogginlutely.net/2005/05/stopping-zombies/">Stopping zombies?</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
]]></description>
			<content:encoded><![CDATA[<p>Interesting to see that it looks like the police are getting involved with contacting isps to ask them to do something about pc&#8217;s that are infected with viruses and acting as zombies according to <a href="http://www.net4nowt.com/isp_news/news_article.asp?News_ID=2910">net4nowt</a>.<br />
Wish they would do something about the french isp hosting phishing accounts. I received an email on Friday asking me to verify my ebay information and checking the website it is hosted on Amen&#8217;s servers. There was no email contact information on the website, their &#8220;online chat guide&#8221; is permanently engaged and the only way to contact the support department is to register with them or be an existing customer (I wonder if an EX customer like me is included in that latter category). An email to abuse@amen.fr has so far only come back with a (autoreply) statement saying they will take immediate action to stop spammers and to forward them the headers &#8211; which I did on the initial posting.</p>
<p><a href="http://absoblogginlutely.net/2005/05/stopping-zombies/">Stopping zombies?</a> was originally posted at  <a href="http://absoblogginlutely.net">Absoblogginlutely!</a> </p>
<img src="http://absoblogginlutely.net/wp/?ak_action=api_record_view&id=866&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://absoblogginlutely.net/2005/05/stopping-zombies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
