<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: New IRS Scam and It Could Cost You More Than Taxes!</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-corner/new-irs-scam-and-it-could-cost-you-more-than-taxes/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-corner/new-irs-scam-and-it-could-cost-you-more-than-taxes/</link>
	<description></description>
	<pubDate>Tue, 24 Nov 2009 17:47:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Mwoodsophosinc</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/new-irs-scam-and-it-could-cost-you-more-than-taxes/#comment-44</link>
		<dc:creator>Mwoodsophosinc</dc:creator>
		<pubDate>Wed, 30 Sep 2009 16:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/new-irs-scam-and-it-could-cost-you-more-than-taxes/#comment-44</guid>
		<description>Just to add to the list of potential compromised file names, previous versions of the Zeus Trojan have used names including:
[ULIST]
	[ELEMENT]ntos.exe[/ELEMENT]
	[ELEMENT]oembios.exe[/ELEMENT]
	[ELEMENT]twext.exe[/ELEMENT]
[/ULIST]
The latest variant uses the name "sdra64.exe". 
These EXE files typically appear in the C:WINDOWSsystem32 directory.</description>
		<content:encoded><![CDATA[<p>Just to add to the list of potential compromised file names, previous versions of the Zeus Trojan have used names including:</p>
<ul>
<li>ntos.exe</li>
<li>oembios.exe</li>
<li>twext.exe</li>
</ul>
<p>The latest variant uses the name &#8220;sdra64.exe&#8221;.<br />
These EXE files typically appear in the C:WINDOWSsystem32 directory.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- dynamic -->