<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for SpywareList.Info News</title>
	<atom:link href="http://www.spywarelist.info/spyware-news/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.spywarelist.info/spyware-news</link>
	<description>Spyware News, Trends and Removal.</description>
	<pubDate>Thu, 20 Nov 2008 08:41:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>Comment on IE 7 Beta Email Installs Trojan by mike.shafer</title>
		<link>http://www.spywarelist.info/spyware-news/ie-7-beta-email-installs-trojan#comment-105</link>
		<dc:creator>mike.shafer</dc:creator>
		<pubDate>Sat, 05 May 2007 12:29:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.spywarelist.info/spyware-news/ie-7-beta-email-installs-trojan#comment-105</guid>
		<description>I just received another email like the above today and likewise downloaded the file to a Linux machine (Note: don't try downloading the file unless you know exactly what you're doing.) Noting that this file was different than the first one received on March 30 I ran it through VirusTotal's scanning engine.

Results were sufficiently similar to the above that I'm not posting that here but I would note that at least several of the anti-virus products listed above didn't note the file as infected.

Malware (malicious software) programmers have been using the technique of making small changes in the software that ultimately cause signature based anti-virus  software to miss identifying the infected file as being such.</description>
		<content:encoded><![CDATA[<p>I just received another email like the above today and likewise downloaded the file to a Linux machine (Note: don&#8217;t try downloading the file unless you know exactly what you&#8217;re doing.) Noting that this file was different than the first one received on March 30 I ran it through VirusTotal&#8217;s scanning engine.</p>
<p>Results were sufficiently similar to the above that I&#8217;m not posting that here but I would note that at least several of the anti-virus products listed above didn&#8217;t note the file as infected.</p>
<p>Malware (malicious software) programmers have been using the technique of making small changes in the software that ultimately cause signature based anti-virus  software to miss identifying the infected file as being such.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Luder Worm (Nuwar) by mike.shafer</title>
		<link>http://www.spywarelist.info/spyware-news/luder-worm#comment-13</link>
		<dc:creator>mike.shafer</dc:creator>
		<pubDate>Sat, 03 Feb 2007 17:04:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.spywarelist.info/spyware-news/beware-the-postcardexe-greeting#comment-13</guid>
		<description>After tapering off in frequency during mid January 2007 we've seen a recent up surge in emails like the above since around Jan. 28, 2007 to present (Feb. 3, 2007).

One common variant we've been receiving states "You have received a postcard from a family member" and links to a Romanian domain.</description>
		<content:encoded><![CDATA[<p>After tapering off in frequency during mid January 2007 we&#8217;ve seen a recent up surge in emails like the above since around Jan. 28, 2007 to present (Feb. 3, 2007).</p>
<p>One common variant we&#8217;ve been receiving states &#8220;You have received a postcard from a family member&#8221; and links to a Romanian domain.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
