<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/enblog/read.php?</link>
<title><![CDATA[Microsoft Critical Live Update?]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Fri, 08 Feb 2008 07:42:58 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?</guid> 
<description>
<![CDATA[ 
	We received spams that masqueraded as Microsoft Critical Live Update. The file &quot;<strong>WindowsUpdateAgent30-x86-x64.exe</strong>&quot; was downloaded from fake Microsoft Update site.<br/><br/>The spams are as the following: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=windowsupdateagent30-x86-x64.exe" rel="tag">windowsupdateagent30-x86-x64.exe</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=asp63.net" rel="tag">asp63.net</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=trojan-dropper.win32.agent.eet" rel="tag">trojan-dropper.win32.agent.eet</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?#blogcomment</link>
<title><![CDATA[[Comments] Microsoft Critical Live Update?]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[Comments]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>