<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>unsharpTech &#187; Asides</title>
	<atom:link href="http://unsharptech.com/category/asides/feed/" rel="self" type="application/rss+xml" />
	<link>http://unsharptech.com</link>
	<description>when the bleeding edge just doesn&#039;t cut it</description>
	<lastBuildDate>Mon, 01 Aug 2011 03:54:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Trojan.Rootkit-1835 ClamAV False Positive</title>
		<link>http://unsharptech.com/2009/12/15/trojan-rootkit-1835-clamav-false-positive/</link>
		<comments>http://unsharptech.com/2009/12/15/trojan-rootkit-1835-clamav-false-positive/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:24:11 +0000</pubDate>
		<dc:creator>sam</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Fixes]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://unsharptech.com/?p=316</guid>
		<description><![CDATA[This morning I was going over last night&#8217;s ClamWin scan results on my Windows XP box and found a few instances of Trojan.Rootkit-1835 infecting the following files: C:\WINDOWS\Driver Cache\i386\sp3.cab: Trojan.Rootkit-1835 FOUND C:\WINDOWS\system32\dllcache\atapi.sys: Trojan.Rootkit-1835 FOUND C:\WINDOWS\system32\drivers\atapi.sys: Trojan.Rootkit-1835 FOUND C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys: Trojan.Rootkit-1835 FOUND This was interesting because lately I&#8217;ve been cleaning up computers that end up missing atapi.sys [...]]]></description>
			<content:encoded><![CDATA[<p>This morning I was going over last night&#8217;s ClamWin scan results on my Windows XP box and found a few instances of Trojan.Rootkit-1835 infecting the following files:<span id="more-316"></span></p>
<ul>
<li>C:\WINDOWS\Driver Cache\i386\sp3.cab: Trojan.Rootkit-1835 FOUND</li>
<li>C:\WINDOWS\system32\dllcache\atapi.sys: Trojan.Rootkit-1835 FOUND</li>
<li>C:\WINDOWS\system32\drivers\atapi.sys: Trojan.Rootkit-1835 FOUND</li>
<li>C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys: Trojan.Rootkit-1835 FOUND</li>
</ul>
<p>This was interesting because lately I&#8217;ve been cleaning up computers that end up missing atapi.sys and need it replaced in order to boot without a BSOD. But upon looking into it and finding a note in a recent ClamAV database update I am confident that this was a false positive.</p>
<p>It appears that this happened back in 2005 as well but was taken care of and now it&#8217;s happened again. I went as far as to grab an SP3 XP Pro install disc and scan it with ClamWin and it found the same false positive <em>Trojan.Rootkit-1835</em>.</p>
<p>Luckily the false postive has been removed from the ClamAV database as of <code>15 Dec 2009 04-20 -0500</code> according to this <code>daily.csv</code> submission note:</p>
<blockquote><p><code>ClamAV database updated (15 Dec 2009 04-20 -0500): daily.cvd<br />
Version: 10173<br />
...<br />
Submission notes: Trojan.Rootkit-1835 dropped due to false positive</code></p></blockquote>
<p>So just update your ClamWin Database and no more false positives. You may want to run the System File Checker before you reboot just in case ClamWin deleted your <code>atapi.sys</code>, otherwise you&#8217;ll probably get a Blue Screen Of Death.</p>
<p>Just run the following commands and insert the install CD when it asks for it:</p>
<pre class="brush: php">sfc /purgecache
sfc /scannow</pre>
<p>Sources:</p>
<blockquote><p><a href="http://lists.clamav.net/lurker/attach/1@20091215.092101.11505bd1.attach">http://lists.clamav.net/lurker/attach/1@20091215.092101.11505bd1.attach</a></p>
<p><a href="http://forums.clamwin.com/viewtopic.php?p=11247">http://forums.clamwin.com/viewtopic.php?p=11247</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://unsharptech.com/2009/12/15/trojan-rootkit-1835-clamav-false-positive/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Reader Mobile beats Viigo for RSS on BlackBerry</title>
		<link>http://unsharptech.com/2009/06/19/google-reader-mobile-beats-viigo-for-rss-on-blackberry/</link>
		<comments>http://unsharptech.com/2009/06/19/google-reader-mobile-beats-viigo-for-rss-on-blackberry/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 10:17:00 +0000</pubDate>
		<dc:creator>sam</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Customization]]></category>
		<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://unsharptech.com/?p=238</guid>
		<description><![CDATA[Viigo has some great features and all but for simple RSS reading on my BlackBerry Google Reader Mobile beats the crap out of Viigo. Better interface, no update lag, feeds render faster and Google parses external pages to be mobile-friendly. Plus, no app to install/update, just set a bookmark in your mobile browser. http://www.google.com/reader/m/ or [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.viigo.com/">Viigo</a> has some great features and all but for simple RSS reading on my BlackBerry <a href="http://www.google.com/reader/m/">Google Reader Mobile </a>beats the crap out of Viigo. <span id="more-238"></span>Better interface, no update lag, feeds render faster and Google parses external pages to be mobile-friendly. Plus, no app to install/update, just set a bookmark in your mobile browser.</p>
<p><a href="http://www.google.com/reader/m/">http://www.google.com/reader/m/</a> or from a mobile browser just: <a href="http://www.google.com/reader/">http://www.google.com/reader/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://unsharptech.com/2009/06/19/google-reader-mobile-beats-viigo-for-rss-on-blackberry/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New theme: The Morning After</title>
		<link>http://unsharptech.com/2009/06/10/new-theme-the-morning-after/</link>
		<comments>http://unsharptech.com/2009/06/10/new-theme-the-morning-after/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 09:23:28 +0000</pubDate>
		<dc:creator>sam</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://unsharptech.com/?p=218</guid>
		<description><![CDATA[New theme integration is progress. I just don&#8217;t have the gas to do it all in one night&#8230; Banner images, replacement icons, formatting improvements, and more to come. Check out the original at: http://themasterplan.in/tma]]></description>
			<content:encoded><![CDATA[<p>New theme integration is progress. I just don&#8217;t have the gas to do it all in one night&#8230;<span id="more-218"></span></p>
<p>Banner images, replacement icons, formatting improvements, and more to come.</p>
<p>Check out the original at: <a href="http://themasterplan.in/tma">http://themasterplan.in/tma</a></p>
]]></content:encoded>
			<wfw:commentRss>http://unsharptech.com/2009/06/10/new-theme-the-morning-after/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

