<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hexzone Hotzone</title>
	<atom:link href="http://blog.eset.com/2009/04/23/hexzone-hotzone/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.eset.com/2009/04/23/hexzone-hotzone</link>
	<description></description>
	<lastBuildDate>Sun, 12 Feb 2012 22:29:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/23/hexzone-hotzone/comment-page-1#comment-44528</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Sat, 25 Apr 2009 18:29:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=1001#comment-44528</guid>
		<description>Dear Finjan.

Thank you for your clarification. I have, of course, read your blog. Obviously, I&#039;m aware of the VirusTotal report you cited. As far as I know, no-one at ESET (or anyone commenting on these blogs) has accused you of fabricating the 1.9 million number. And I certainly haven&#039;t said anything like &quot;Finjan has been real aggressive about spreading FUD&quot; and would be most interested to know why you think I did.

David Harley, speaking for himself, not ESET.</description>
		<content:encoded><![CDATA[<p>Dear Finjan.</p>
<p>Thank you for your clarification. I have, of course, read your blog. Obviously, I&#8217;m aware of the VirusTotal report you cited. As far as I know, no-one at ESET (or anyone commenting on these blogs) has accused you of fabricating the 1.9 million number. And I certainly haven&#8217;t said anything like &#8220;Finjan has been real aggressive about spreading FUD&#8221; and would be most interested to know why you think I did.</p>
<p>David Harley, speaking for himself, not ESET.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Finjan</title>
		<link>http://blog.eset.com/2009/04/23/hexzone-hotzone/comment-page-1#comment-44521</link>
		<dc:creator>Finjan</dc:creator>
		<pubDate>Sat, 25 Apr 2009 17:03:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=1001#comment-44521</guid>
		<description>Dear ESET,

Finjan&#039;s blog post shows VirusTotal report and indicates on Hexzone as an executable the bot was instructed to download from the command center.

Hexzone is not the bot itself but one out of many executables that the bot downloaded and executed on the infected PCs.

Taken from the blog post: 
&quot;This command instructs the bot on the infected computers to download and execute a Trojan horse. As indicates on the VirusTotal report below, only 4 out of 39 Anti-Virus products detected this Trojan.&quot;

As for the number of infected PCs:
The 1.9M number is very accurate. The entire DB was available for inspection where unique records were identified (computer names, IPs, region). Commands were sent to the entire net or to subsets (regional). 

Your comment &quot;Finjan has been real aggressive about spreading FUD&quot; is unprofessional :-(

Finjan</description>
		<content:encoded><![CDATA[<p>Dear ESET,</p>
<p>Finjan&#8217;s blog post shows VirusTotal report and indicates on Hexzone as an executable the bot was instructed to download from the command center.</p>
<p>Hexzone is not the bot itself but one out of many executables that the bot downloaded and executed on the infected PCs.</p>
<p>Taken from the blog post:<br />
&#8220;This command instructs the bot on the infected computers to download and execute a Trojan horse. As indicates on the VirusTotal report below, only 4 out of 39 Anti-Virus products detected this Trojan.&#8221;</p>
<p>As for the number of infected PCs:<br />
The 1.9M number is very accurate. The entire DB was available for inspection where unique records were identified (computer names, IPs, region). Commands were sent to the entire net or to subsets (regional). </p>
<p>Your comment &#8220;Finjan has been real aggressive about spreading FUD&#8221; is unprofessional <img src='http://blog.eset.com/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>Finjan</p>
]]></content:encoded>
	</item>
</channel>
</rss>

