<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SAV false positive in blindman.exe</title>
	<atom:link href="http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 07:04:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Roger</title>
		<link>http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/comment-page-1/#comment-149</link>
		<dc:creator>Roger</dc:creator>
		<pubDate>Thu, 31 May 2007 20:45:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/#comment-149</guid>
		<description>Symantec&#039;s announcement came in an email.  Not sure which subscription this is, it looks like a release notification email:
-----Original Message-----
From: symalert@symantec.com [mailto:symalert@symantec.com]
Sent: Wednesday, May 30, 2007 9:12 PM
To: xxxxxx@xxxxxxxxxx
Subject: Symantec Security Response will post LiveUpdate virus definitions today, May 30, 2007 PDT
This posting is in response to a false positive detection on the file
blindman.exe, part of the Spybot Search &amp; Destroy application. This FP was
first released in the 5/30/2007 rev.20 Intelligent Updater and LiveUpdate
definitions, and was corrected from Rapid Release definitions #69173. An
additional message will be sent approximately 30 minutes before the
LiveUpdate virus definitions are available for download.
----------
For additional information, visit our website at
&lt;a href=&quot;http://securityresponse.symantec.com&quot; rel=&quot;nofollow&quot;&gt;http://securityresponse.symantec.com&lt;/a&gt;
The SANS Internet Storm Center has now posted about this issue as well.
&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=2897&quot; rel=&quot;nofollow&quot;&gt;http://isc.sans.org/diary.html?storyid=2897&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>Symantec&#8217;s announcement came in an email.  Not sure which subscription this is, it looks like a release notification email:<br />
&#8212;&#8211;Original Message&#8212;&#8211;<br />
From: <a href="mailto:symalert@symantec.com">symalert@symantec.com</a> [mailto:symalert@symantec.com]<br />
Sent: Wednesday, May 30, 2007 9:12 PM<br />
To: xxxxxx@xxxxxxxxxx<br />
Subject: Symantec Security Response will post LiveUpdate virus definitions today, May 30, 2007 PDT<br />
This posting is in response to a false positive detection on the file<br />
blindman.exe, part of the Spybot Search &#038; Destroy application. This FP was<br />
first released in the 5/30/2007 rev.20 Intelligent Updater and LiveUpdate<br />
definitions, and was corrected from Rapid Release definitions #69173. An<br />
additional message will be sent approximately 30 minutes before the<br />
LiveUpdate virus definitions are available for download.<br />
&#8212;&#8212;&#8212;-<br />
For additional information, visit our website at<br />
<a href="http://securityresponse.symantec.com" rel="nofollow">http://securityresponse.symantec.com</a><br />
The SANS Internet Storm Center has now posted about this issue as well.<br />
<a href="http://isc.sans.org/diary.html?storyid=2897" rel="nofollow">http://isc.sans.org/diary.html?storyid=2897</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/comment-page-1/#comment-148</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Thu, 31 May 2007 14:03:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecblog.org/2007/05/sav-false-positive-in-blindman-exe/#comment-148</guid>
		<description>Hey, it would be nice if you linked to the Symantec accouncement. You are the only place I can find this information on the web. I can find no reference to this @ symantec at all.  I sure WANT to believe you but can you attribute your sources?
</description>
		<content:encoded><![CDATA[<p>Hey, it would be nice if you linked to the Symantec accouncement. You are the only place I can find this information on the web. I can find no reference to this @ symantec at all.  I sure WANT to believe you but can you attribute your sources?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

