<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: I FOUND THE BOT!</title>
	<atom:link href="http://mice.org/blog/i-found-the-bot/feed/" rel="self" type="application/rss+xml" />
	<link>http://mice.org/blog/i-found-the-bot/</link>
	<description>News, reviews and technology blues!</description>
	<lastBuildDate>Thu, 11 Mar 2010 15:00:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Yom</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-405</link>
		<dc:creator>Yom</dc:creator>
		<pubDate>Tue, 14 Jul 2009 13:12:13 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-405</guid>
		<description>I gave up on trying to detect the so called bot on my PC (no bot found after numerous scans with numerous AV-apps) and uninstalled this nice piece of BETA-rubbish. By TrendMicro, have anice life.

PS: the popups occur on Vista only; on my XP it seems to be ok</description>
		<content:encoded><![CDATA[<p>I gave up on trying to detect the so called bot on my PC (no bot found after numerous scans with numerous AV-apps) and uninstalled this nice piece of BETA-rubbish. By TrendMicro, have anice life.</p>
<p>PS: the popups occur on Vista only; on my XP it seems to be ok</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Facebook User</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-165</link>
		<dc:creator>Facebook User</dc:creator>
		<pubDate>Tue, 09 Dec 2008 15:07:01 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-165</guid>
		<description>@Buck, Thanks for adding your comments Buck! The more information we get, the more we are able to hunt this thing down!</description>
		<content:encoded><![CDATA[<p>@Buck, Thanks for adding your comments Buck! The more information we get, the more we are able to hunt this thing down!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Buck</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-163</link>
		<dc:creator>Buck</dc:creator>
		<pubDate>Mon, 08 Dec 2008 19:18:54 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-163</guid>
		<description>Just thought I&#039;d chime in here since it seems no one else is doing the level of analysis on this that you are. I&#039;m a non-technical user and have been seeing these same &#039;your pc is being remote controlled&#039;-type pop-ups from RUBotted. When checking the RUBotted logs, and status - nothing. It happens when I&#039;m on sites that have a lot of ads and/or flash video. I&#039;ve been ignoring them because the logs say nothing is there and nothing has popped up in Avast AV.  I have repeatedly clicked the &quot;run housecall now&quot; button but Housecall won&#039;t run on my machine for some reason (in IE or FF3). Don&#039;t know what else to do about this. Hoping you come up with a solution since TrendMicro seems to be ignoring it under the &quot;it&#039;s a beta&quot; banner.</description>
		<content:encoded><![CDATA[<p>Just thought I&#8217;d chime in here since it seems no one else is doing the level of analysis on this that you are. I&#8217;m a non-technical user and have been seeing these same &#8216;your pc is being remote controlled&#8217;-type pop-ups from RUBotted. When checking the RUBotted logs, and status &#8211; nothing. It happens when I&#8217;m on sites that have a lot of ads and/or flash video. I&#8217;ve been ignoring them because the logs say nothing is there and nothing has popped up in Avast AV.  I have repeatedly clicked the &#8220;run housecall now&#8221; button but Housecall won&#8217;t run on my machine for some reason (in IE or FF3). Don&#8217;t know what else to do about this. Hoping you come up with a solution since TrendMicro seems to be ignoring it under the &#8220;it&#8217;s a beta&#8221; banner.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Facebook User</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-115</link>
		<dc:creator>Facebook User</dc:creator>
		<pubDate>Mon, 24 Nov 2008 15:04:48 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-115</guid>
		<description>@JorgenG, We can&#039;t fix a problem we don&#039;t understand. We need to find out what is creating the pop-up. What action on the websites or ads are creating this? And why is it slowing down now? Someone knows something and isn&#039;t talking. But I&#039;m working on it! Still.</description>
		<content:encoded><![CDATA[<p>@JorgenG, We can&#8217;t fix a problem we don&#8217;t understand. We need to find out what is creating the pop-up. What action on the websites or ads are creating this? And why is it slowing down now? Someone knows something and isn&#8217;t talking. But I&#8217;m working on it! Still.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The RUBotted Saga Continues &#124; Technical Tidbits</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-112</link>
		<dc:creator>The RUBotted Saga Continues &#124; Technical Tidbits</dc:creator>
		<pubDate>Mon, 24 Nov 2008 14:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-112</guid>
		<description>[...]   Most Read PostsWhat Ad Server is Dishing Up Malware and Bots? (144)I FOUND THE BOT! (87)Friday&#039;s Quickies (59)RUBotted Notices are Slowing Down (48)Why is Microsoft REALLY Investing [...]</description>
		<content:encoded><![CDATA[<p>[...]   Most Read PostsWhat Ad Server is Dishing Up Malware and Bots? (144)I FOUND THE BOT! (87)Friday&#8217;s Quickies (59)RUBotted Notices are Slowing Down (48)Why is Microsoft REALLY Investing [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JorgenG</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-111</link>
		<dc:creator>JorgenG</dc:creator>
		<pubDate>Mon, 24 Nov 2008 14:17:19 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-111</guid>
		<description>I ran Wireshark as well and it came up with some more sinister news: seems that the bot establishes a KVM connection to the 150.70.89.33 address. The next action is coming from a bnet game port - but that could be a coincidense?

Anyway, I (kind of) panic´d and installed a permanent route (using &quot;route add -p&quot;) so that the communication from the bot just hits dev NULL ;-) or rather a non-existing host on my network. Should take care of the imminent threat.

BUT, it doesn´t remove the little bugger. Has anyone any ideas or have seen a fix - however crude?</description>
		<content:encoded><![CDATA[<p>I ran Wireshark as well and it came up with some more sinister news: seems that the bot establishes a KVM connection to the 150.70.89.33 address. The next action is coming from a bnet game port &#8211; but that could be a coincidense?</p>
<p>Anyway, I (kind of) panic´d and installed a permanent route (using &#8220;route add -p&#8221;) so that the communication from the bot just hits dev NULL <img src='http://mice.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  or rather a non-existing host on my network. Should take care of the imminent threat.</p>
<p>BUT, it doesn´t remove the little bugger. Has anyone any ideas or have seen a fix &#8211; however crude?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ddraig</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-109</link>
		<dc:creator>Ddraig</dc:creator>
		<pubDate>Sun, 23 Nov 2008 17:05:10 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-109</guid>
		<description>I&#039;m not exactly sure but if you close RUBotted then the IP that you have disappears from your netstat. I believe it is nothing more than RUBotted connection back to the  servers, which is why it is SSL Encrypted. I don&#039;t think that is the &quot;virus&quot; website or whatever Trend is claiming it to be. 

This only seems to pop up when I load up Firefox though... I don&#039;t really notice it popping up when I open IE.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not exactly sure but if you close RUBotted then the IP that you have disappears from your netstat. I believe it is nothing more than RUBotted connection back to the  servers, which is why it is SSL Encrypted. I don&#8217;t think that is the &#8220;virus&#8221; website or whatever Trend is claiming it to be. </p>
<p>This only seems to pop up when I load up Firefox though&#8230; I don&#8217;t really notice it popping up when I open IE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andy penn</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-108</link>
		<dc:creator>andy penn</dc:creator>
		<pubDate>Sun, 23 Nov 2008 10:26:05 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-108</guid>
		<description>Thanks for posting these details. There&#039;s no support from TrendMicro for RUbotted, so I&#039;ve not been able to find out why RUbotted gives out these alerts yet when you do a check for bots it says all clear. TrendMicro have got some explaining to do - has anyone tried to contact them about this?</description>
		<content:encoded><![CDATA[<p>Thanks for posting these details. There&#8217;s no support from TrendMicro for RUbotted, so I&#8217;ve not been able to find out why RUbotted gives out these alerts yet when you do a check for bots it says all clear. TrendMicro have got some explaining to do &#8211; has anyone tried to contact them about this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Xonnel</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-107</link>
		<dc:creator>Xonnel</dc:creator>
		<pubDate>Sun, 23 Nov 2008 07:21:38 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-107</guid>
		<description>So...me too.  Same issue, same tail chasing.  I have spent the last couple of days trying to figure this out too.  Thanks for sharing what you found.  I noticed that the database for my RUBotted was updated a couple days ago.  Wondering if that has something to do with the timing of all the actvity.

If you park your browswer on a page with no ads...no bots messages.  Must be some change they made recently.

Thanks again.  You made me feel a little less crazy.</description>
		<content:encoded><![CDATA[<p>So&#8230;me too.  Same issue, same tail chasing.  I have spent the last couple of days trying to figure this out too.  Thanks for sharing what you found.  I noticed that the database for my RUBotted was updated a couple days ago.  Wondering if that has something to do with the timing of all the actvity.</p>
<p>If you park your browswer on a page with no ads&#8230;no bots messages.  Must be some change they made recently.</p>
<p>Thanks again.  You made me feel a little less crazy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Facebook User</title>
		<link>http://mice.org/blog/i-found-the-bot/comment-page-1/#comment-105</link>
		<dc:creator>Facebook User</dc:creator>
		<pubDate>Sat, 22 Nov 2008 23:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=575#comment-105</guid>
		<description>@Ray, I should have checked that box before this. I wasted a lot of time researching what I didn&#039;t need to research! Sigh. Oh well, now the answer remains, why? What is going with this??</description>
		<content:encoded><![CDATA[<p>@Ray, I should have checked that box before this. I wasted a lot of time researching what I didn&#8217;t need to research! Sigh. Oh well, now the answer remains, why? What is going with this??</p>
]]></content:encoded>
	</item>
</channel>
</rss>
