<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Latest Zhelatin Emails</title>
	<atom:link href="http://blog.misec.net/2007/08/21/latest-zhelatin-emails/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.misec.net/2007/08/21/latest-zhelatin-emails/</link>
	<description>The latest in security - from the developers of TrojanHunter</description>
	<lastBuildDate>Thu, 25 Feb 2010 21:20:44 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Beware! Virii Alert! at Delusions of Grandeur</title>
		<link>http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-265</link>
		<dc:creator>Beware! Virii Alert! at Delusions of Grandeur</dc:creator>
		<pubDate>Wed, 05 Sep 2007 17:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-265</guid>
		<description>[...] picked up on it right away once I was able to get the box up enough to run, however both Mischel internet Security and PC HELL have ways posted online to correct the issue. Please be careful when dealing with this [...]</description>
		<content:encoded><![CDATA[<p>[...] picked up on it right away once I was able to get the box up enough to run, however both Mischel internet Security and PC HELL have ways posted online to correct the issue. Please be careful when dealing with this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: packed</title>
		<link>http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-132</link>
		<dc:creator>packed</dc:creator>
		<pubDate>Fri, 24 Aug 2007 06:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-132</guid>
		<description>tcpip.sys are getting patched using undocumented API in sfc_os.dll</description>
		<content:encoded><![CDATA[<p>tcpip.sys are getting patched using undocumented API in sfc_os.dll</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: P Flaggenan</title>
		<link>http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-99</link>
		<dc:creator>P Flaggenan</dc:creator>
		<pubDate>Wed, 22 Aug 2007 05:33:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-99</guid>
		<description>Thanks for the quick addressing of the issue.</description>
		<content:encoded><![CDATA[<p>Thanks for the quick addressing of the issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: redwolfe_98</title>
		<link>http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-93</link>
		<dc:creator>redwolfe_98</dc:creator>
		<pubDate>Tue, 21 Aug 2007 23:24:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.misec.net/2007/08/21/latest-zhelatin-emails/#comment-93</guid>
		<description>i think i have seen the same variant.. i submitted the file to pctool&#039;s &quot;threat expert&quot; and their report said that the malware modified &quot;kbdclass.sys&quot;.. if that is the case, then i guess you would need to restore that file rather than the &quot;tcpip.sys&quot; file.. i have seem other variants that, according to pctool&#039;s &quot;threat expert&quot;, modified the &quot;cdrom.sys&quot; driver..</description>
		<content:encoded><![CDATA[<p>i think i have seen the same variant.. i submitted the file to pctool&#8217;s &#8220;threat expert&#8221; and their report said that the malware modified &#8220;kbdclass.sys&#8221;.. if that is the case, then i guess you would need to restore that file rather than the &#8220;tcpip.sys&#8221; file.. i have seem other variants that, according to pctool&#8217;s &#8220;threat expert&#8221;, modified the &#8220;cdrom.sys&#8221; driver..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
