<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: When trojans invade the PC kingdom</title>
	<atom:link href="http://jkontherun.com/2008/03/30/when-trojans-in/feed/" rel="self" type="application/rss+xml" />
	<link>http://jkontherun.com/2008/03/30/when-trojans-in/</link>
	<description>Using mobile devices since they weighed 30 lbs.</description>
	<lastBuildDate>Sun, 22 Nov 2009 17:14:40 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bill</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11254</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Mon, 31 Mar 2008 03:07:55 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11254</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;Well, I certainly would not describe OneCare as &quot;adequate protection&quot;. It simply isn&#039;t up to the job. &lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>Well, I certainly would not describe OneCare as &#8220;adequate protection&#8221;. It simply isn&#8217;t up to the job. </p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott_H</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11256</link>
		<dc:creator>Scott_H</dc:creator>
		<pubDate>Sun, 30 Mar 2008 14:18:29 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11256</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;&lt;p&gt;Interesting. My AVG virus scan detected a Zlob trojan during its overnight scan on Friday. What gets me is that none of the so-called real-time scanners I have running (and apparently wasting system resources) detected anything. Maybe that was a false positive, too.&lt;/p&gt;

&lt;p&gt;It all seems to be sort of a crap shoot to me. One day, nothing...then, all of a sudden a virus scan detects a virus or two (in directories where nothing seemed to change).&lt;/p&gt;&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>Interesting. My AVG virus scan detected a Zlob trojan during its overnight scan on Friday. What gets me is that none of the so-called real-time scanners I have running (and apparently wasting system resources) detected anything. Maybe that was a false positive, too.</p>
<p>It all seems to be sort of a crap shoot to me. One day, nothing&#8230;then, all of a sudden a virus scan detects a virus or two (in directories where nothing seemed to change).</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: turn.self.off</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11259</link>
		<dc:creator>turn.self.off</dc:creator>
		<pubDate>Sun, 30 Mar 2008 13:58:44 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11259</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;hunting for virus and similar is like hunting for terrorists. these days one is just as likely to get a civilian as the real deal...&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>hunting for virus and similar is like hunting for terrorists. these days one is just as likely to get a civilian as the real deal&#8230;</p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mickey Segal</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11261</link>
		<dc:creator>Mickey Segal</dc:creator>
		<pubDate>Sun, 30 Mar 2008 13:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11261</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;In 2006 Spybot&#039;s flagged some key Tablet PC functionality as a threat.  Details are at &lt;a href=&quot;http://forums.spybot.info/showthread.php?t=8668.&quot; rel=&quot;nofollow&quot;&gt;http://forums.spybot.info/showthread.php?t=8668.&lt;/a&gt;   The &quot;new&quot; material on the system was the new Spybot definitions, which unfortunately had an error. &lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>In 2006 Spybot&#8217;s flagged some key Tablet PC functionality as a threat.  Details are at <a href="http://forums.spybot.info/showthread.php?t=8668." rel="nofollow"></a><a href="http://forums.spybot.info/showthread.php?t=8668" rel="nofollow">http://forums.spybot.info/showthread.php?t=8668</a>.   The &#8220;new&#8221; material on the system was the new Spybot definitions, which unfortunately had an error. </p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Ferris</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11264</link>
		<dc:creator>Philip Ferris</dc:creator>
		<pubDate>Sun, 30 Mar 2008 12:38:56 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11264</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;I stopped to eat so didn&#039;t write the CAPTCHA till after - my comment is obviously moot.&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>I stopped to eat so didn&#8217;t write the CAPTCHA till after &#8211; my comment is obviously moot.</p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Ferris</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11266</link>
		<dc:creator>Philip Ferris</dc:creator>
		<pubDate>Sun, 30 Mar 2008 12:32:03 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11266</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;&lt;p&gt;In my copy of OneCare I can see an option to display what the last virus scan discovered.&lt;/p&gt;

&lt;p&gt; Glad you survived it.&lt;/p&gt;&lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>In my copy of OneCare I can see an option to display what the last virus scan discovered.</p>
<p> Glad you survived it.</p>
</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Kendrick</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11268</link>
		<dc:creator>James Kendrick</dc:creator>
		<pubDate>Sun, 30 Mar 2008 12:23:31 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11268</guid>
		<description>&lt;p&gt;A false positive was my first thought too but this system hadn&#039;t changed since I got it so I didn&#039;t seriously consider that.  I should have as I have since scoured the event logs and found the threat that was detected:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/security/encyclopedia/details.aspx?name=TrojanDownloader%3aWin32%2fZlob.gen!AW&amp;threatid=2147603587&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/security/encyclopedia/details.aspx?name=TrojanDownloader%3aWin32%2fZlob.gen!AW&amp;threatid=2147603587&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The telling criteria that this is likely a false positive is the date the threat was added by MS- yesterday.  So most likely OneCare updated its threat signatures last night and this morning tagged this as a threat.  It&#039;s the first false positive (if that&#039;s indeed what this is) that I&#039;ve encountered with OneCare and I&#039;ve been using it since it first went beta.  Live and learn.&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>A false positive was my first thought too but this system hadn&#8217;t changed since I got it so I didn&#8217;t seriously consider that.  I should have as I have since scoured the event logs and found the threat that was detected:</p>
<p><a href="http://www.microsoft.com/security/encyclopedia/details.aspx?name=TrojanDownloader%3aWin32%2fZlob.gen!AW&#038;threatid=2147603587" rel="nofollow"></a><a href="http://www.microsoft.com/security/encyclopedia/details.aspx?name=TrojanDownloader%3aWin32%2fZlob.gen" rel="nofollow">http://www.microsoft.com/security/encyclopedia/details.aspx?name=TrojanDownloader%3aWin32%2fZlob.gen</a>!AW&#038;threatid=2147603587</p>
<p>The telling criteria that this is likely a false positive is the date the threat was added by MS- yesterday.  So most likely OneCare updated its threat signatures last night and this morning tagged this as a threat.  It&#8217;s the first false positive (if that&#8217;s indeed what this is) that I&#8217;ve encountered with OneCare and I&#8217;ve been using it since it first went beta.  Live and learn.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bill</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11270</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Sun, 30 Mar 2008 10:59:56 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11270</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;I also wonder if onecare got tricked into thinking the fuji utlities were a trojan. Seems odd to have that be the only things affected.&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>I also wonder if onecare got tricked into thinking the fuji utlities were a trojan. Seems odd to have that be the only things affected.</p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11272</link>
		<dc:creator>Kurt</dc:creator>
		<pubDate>Sun, 30 Mar 2008 10:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11272</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;I would agree with Jake, it sounds like it could have been a false positive.  If you review your Application and System event logs, it may have logged the name of the trojan, Symantec antivirus does, at least with the corporate version.&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>I would agree with Jake, it sounds like it could have been a false positive.  If you review your Application and System event logs, it may have logged the name of the trojan, Symantec antivirus does, at least with the corporate version.</p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11274</link>
		<dc:creator>Jake</dc:creator>
		<pubDate>Sun, 30 Mar 2008 09:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11274</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;Oh yeah, I meant to apologise if my post seems overly paranoid.  I didn&#039;t get much sleep last night due to a combination of noisy neighbours and the switch to daylight savings here in the UK :)&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>Oh yeah, I meant to apologise if my post seems overly paranoid.  I didn&#8217;t get much sleep last night due to a combination of noisy neighbours and the switch to daylight savings here in the UK <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake</title>
		<link>http://jkontherun.com/2008/03/30/when-trojans-in/#comment-11275</link>
		<dc:creator>Jake</dc:creator>
		<pubDate>Sun, 30 Mar 2008 09:54:15 +0000</pubDate>
		<guid isPermaLink="false">http://jkontherun.wordpress.com/2008/03/30/when-trojans-in#comment-11275</guid>
		<description>&lt;div xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
        &lt;p&gt;It&#039;s a shame that you didn&#039;t note the trojan because it would be interesting to know if OneCare did detect a real trojan or misidentified one of Fujitsu&#039;s apps.  It seems strange that the cleanup would have targeted your Fuji utilities unless it was a false-positive.  Does OneCare keep a history of the files it&#039;s cleaned up?&lt;/p&gt;
      &lt;/div&gt;</description>
		<content:encoded><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml">
<p>It&#8217;s a shame that you didn&#8217;t note the trojan because it would be interesting to know if OneCare did detect a real trojan or misidentified one of Fujitsu&#8217;s apps.  It seems strange that the cleanup would have targeted your Fuji utilities unless it was a false-positive.  Does OneCare keep a history of the files it&#8217;s cleaned up?</p>
</p></div>
]]></content:encoded>
	</item>
</channel>
</rss>
