<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Windows</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/windows//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SinFP Superb Remote OS detection via TCP/IP Stack FingerPrinting</title>
		<link>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/</link>
		<comments>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 23:26:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Network Utilities]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[fingerprint]]></category>

		<category><![CDATA[IDS]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[nettool]]></category>

		<category><![CDATA[networking]]></category>

		<category><![CDATA[portscan]]></category>

		<category><![CDATA[sysadmin]]></category>

		<category><![CDATA[tcpip]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/</guid>
		<description><![CDATA[SinFP by Patrice AUffretGomor, is a full operating system TCP/IP stack fingerprinting. Features both Active (brute) and Passive Methods and support for IPV4 &#038; IPV6. It’s pretty damn fast and package with latest signature. It only send maximum of 3 standards packet to any open TCP port to get the results.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img class="thumb- fl" src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/aix-signature.png' alt='aix-signature SinFP OS Stack Fingeprinting ' width="255" height="44" /><span class="vcard"><strong class="note">SinFP</strong> by <cite><a class="microformat icn-l fn url" href="http://www.gomor.org/cgi-bin/index.pl?mode=view;page=cv"><span class="given-name">Patrice</span> <span class="family-name">AUffret</span></a><span class="nickname dn">Gomor</span></cite>,</span> is a full operating system TCP/IP stack <a href="http://en.wikipedia.org/wiki/TCP/IP_stack_fingerprinting" title="Wikipedia Articles on OS Stack Fingerprinting" class="exturl icn-r">fingerprinting</a>. Features both Active (brute) and Passive Methods and support for IPV4 &#038; IPV6. SinFP only send <cite>maximum of 3</cite> standards packet to any open TCP port to get the results. It&#8217;s damn fast and transparent (send valid <abbr title="Synchronize TCP Flag">SYN</abbr> &amp; options). </p>
<p>SinFP Online demo is available at <a class="exturl icn-r" href="http://www.gomor.org/cgi-bin/sinfp-demo.pl" title="Sinfp online Demo for IPV4 only">gomor.org sinfp demo</a>. You can <abbr title="download">grab</abbr> SinFP OS <strong class="fw-">Stack Fingerprinting</strong> package at CPAN or Gomor.org <small>(External Links &darr; )</small>.<br />
<span id="more-146"></span></p>
<p class="notice">SinFP package is available for Mac (PPC), Linux (included in BackTrack Linux distro) and Windows Binaries (ActivePerl).</p>
<h2 id="external-links">External Links</h2>
<ul>
<li><a href="http://search.cpan.org/~gomor/Net-SinFP-2.06/">Net-SinFP-2.06</a></li>
<li><a href="http://www.gomor.org/cgi-bin/sinfp.pl">SinFP Fingerprinting Overview at gomor.org</a></li>
<li><a href="http://search.cpan.org/~gomor/">All package by Gomor at CPAN</a></li>
<li><a href="http://sourceforge.net/projects/sinfp/">SinFP at SourceForge</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>w32.virut.w, PE_VIRUT.A</title>
		<link>http://42.kaizeku.com/security/virus/w32virutw/</link>
		<comments>http://42.kaizeku.com/security/virus/w32virutw/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 11:44:42 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[anti virus]]></category>

		<category><![CDATA[norton]]></category>

		<category><![CDATA[PE_VIRUT.A]]></category>

		<category><![CDATA[svntortoise]]></category>

		<category><![CDATA[w32.virut.w]]></category>

		<category><![CDATA[winlogon]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/?p=3</guid>
		<description><![CDATA[

I just download google pack with norton and the first scan hook my fav svn tortoise with w32.virut.w .
Excerpt from Symantec
W32.Virut.A is a virus that infects executable files and opens a back door on TCP port 65520 by connecting to a predefined IRC server.
Netstats
netstat -aob &#62; netstat.log

 TCP USER:1028 78.109.19.140.in.hosting.ua:65520 ESTABLISHED 936
 [winlogon.exe]
The free version [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I just download google pack with norton and the first scan hook my fav <strong>svn tortoise</strong> with w32.virut.w .</p>
<p>Excerpt from <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-051402-1930-99" rel="nofollow">Symantec</a></p>
<blockquote cite="http://www.symantec.com/security_response/writeup.jsp?docid=2006-051402-1930-99"><p>W32.Virut.A is a virus that infects executable files and opens a back door on TCP port 65520 by connecting to a predefined IRC server.</p></blockquote>
<h3>Netstats</h3>
<p><tt>netstat -aob &gt; netstat.log</tt></p>
<pre>
 TCP USER:1028 78.109.19.140.in.hosting.ua:65520 ESTABLISHED 936
 [winlogon.exe]</pre>
<p>The free version of Norton Internet Scan Failed to fixed the virus. :(<br />
<span id="more-3"></span></p>
<h3>Norton Logs</h3>
<pre>
Process:
 c:\windows\system32\ctfmon.exe
 c:\program files\tortoisesvn\bin\tsvncache.exe
Infection:
 c:\windows\system32\ctfmon.exe
 c:\program files\tortoisesvn\bin\tsvncache.exe
 c:\windows\system32\spoolsv.exe
 c:\windows\system32\locator.exe
 c:\windows\system32\alg.exe
 c:\windows\system32\sessmgr.exe
 c:\windows\system32\dllhost.exe
 c:\windows\system32\rsvp.exe
 c:\windows\system32\dmadmin.exe
 c:\windows\system32\msdtc.exe
 c:\windows\system32\cisvc.exe
 c:\windows\system32\wbem\wmiapsrv.exe
 c:\windows\system32\ups.exe
 c:\windows\system32\msiexec.exe
 c:\windows\system32\netdde.exe
 c:\windows\system32\vssvc.exe
 c:\windows\system32\mnmsrvc.exe
 c:\windows\system32\mshta.exe
 c:\windows\system32\userinit.exe
 c:\windows\system32\ieudinit.exe
 c:\windows\inf\unregmp2.exe
 c:\windows\system32\ie4uinit.exe
 c:\windows\system32\rundll32.exe
 c:\windows\system32\regsvr32.exe
 c:\windows\system32\ntsd.exe
 c:\program files\wakoopa\wakoopa.exe
 c:\program files\7-zip\7zfm.exe
 c:\program files\acd systems\acdsee\6.0\acdsee6.exe
 c:\program files\adobe\adobe help center\ahc.exe
 c:\program files\netmeeting\conf.exe
 c:\program files\common files\acd systems\en\devdetect.exe
 c:\program files\windows nt\dialer.exe
 c:\program files\acd systems\fotocanvas\3.0\fotocanvas3.exe
 c:\program files\acd systems\fotoslate\3.0\fotoslate3.exe
 c:\windows\pchealth\helpctr\binaries\helpctr.exe
 c:\program files\hp\digital imaging\unload\hpqapkil.exe
 c:\program files\hp\digital imaging\unload\hpqdia.exe
 c:\program files\hp\digital imaging\unload\hpqdias.exe
 c:\program files\hp\digital imaging\unload\hpqphunl.exe
 c:\program files\hp\digital imaging\unload\hpqpsmon.exe
 c:\program files\hp\digital imaging\unload\hpqunset.exe
 c:\program files\hp\digital imaging\bin\hpqvpswp.exe
 c:\program files\windows nt\hypertrm.exe
 c:\program files\internet explorer\connection wizard\icwconn1.exe
 c:\program files\internet explorer\connection wizard\icwconn2.exe
 c:\program files\internet explorer\iexplore.exe
 c:\program files\adobe\adobe photoshop cs2\imageready.exe
 c:\program files\internet explorer\connection wizard\inetwiz.exe
 c:\program files\internet explorer\connection wizard\isignup.exe
 c:\program files\java\jre1.6.0_02\bin\javaws.exe
 c:\windows\system32\usmt\migwiz.exe
 c:\program files\movie maker\moviemk.exe
 c:\program files\windows media player\mplayer2.exe
 c:\program files\combined community codec pack\mpc\mplayerc.exe
 c:\windows\pchealth\helpctr\binaries\msconfig.exe
 c:\program files\outlook express\msimn.exe
 c:\program files\common files\microsoft shared\msinfo\msinfo32.exe
 c:\program files\messenger\msmsgs.exe
 c:\program files\notepad++\notepad++.exe
 c:\windows\system32\mspaint.exe
 c:\program files\adobe\adobe photoshop cs2\photoshop.exe
 c:\program files\quicktime\pictureviewer.exe
 c:\python25\python.exe
 c:\program files\real\realplayer\realplay.exe
 c:\program files\common files\real\update_ob\rnxproc.exe
 c:\windows\soundman.exe
 c:\program files\tortoisesvn\bin\subwcrev.exe
 c:\program files\outlook express\wab.exe
 c:\program files\outlook express\wabmig.exe
 c:\program files\winrar\winrar.exe
 c:\program files\windows media player\wmplayer.exe
 c:\program files\windows nt\accessories\wordpad.exe
 c:\program files\combined community codec pack\zoom player\zplayer.exe
 c:\windows\system32\logon.scr
Service:
 RpcLocator
 ALG
 RDSessMgr
 COMSysApp
 RSVP
 dmadmin
 MSDTC
 CiSvc
 WmiApSrv
 UPS
 SwPrv
 MSIServer
 NetDDE
 VSS
 mnmsrvc
Browser Cache
Registry:
 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-&gt;Userinit</pre>
<p>had to reinstall my windows XP because there is so many hook. I had send a support email to hosting.ua but still got no replied from theme. need to reboot now.</p>
<h3>Nov 17 07 , Update</h3>
<p>I got reply back from hosting.ua support. below is part of the email</p>
<pre>
from	abuse@hosting.ua
to	nospam@gmail.com,
date	Nov 13, 2007 5:00 PM
subject	Reply: trojan 78.109.19.140.in.hosting.ua #48879

hide details Nov 13 (3 days ago)	

Reply

======== CUT HERE =========
Your support request was answered:

Created: 11.11.2007 1:28:38
Last Mod: 12.11.2007 1:41:30

Assigned To:
admin(Hosting.UA)

[11.11.2007 1:28:38]
Q: hi,
This is for your attention. I got a trojan in pc it routed back to one of
your hosting at *78.109.19.140.in.hosting.ua *

I hope you can do something about it.

Thank you
-------------------------------------------------------

[13.11.2007 11:00:08]
A: Fixed!

thx
www.Hosting.UA

-------------------------------------------------------
Hosting.UA Administration</pre>
<p>Well there is no explaination about the issue from the support staff.  hope this site will be closed down for good. Google already blocked and place a warning when you search for the infected URI.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/w32virutw/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safeguard your Windows when cleaning files infected by win32 virus.</title>
		<link>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/</link>
		<comments>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/#comments</comments>
		<pubDate>Fri, 26 Oct 2007 10:59:01 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Debian]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Ubuntu]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[wine]]></category>

		<category><![CDATA[wubi]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/</guid>
		<description><![CDATA[The safest way to clean any kind of windows virus is to work in different environment others than its originating operating system. Try virtual Ubuntu (Debian Linux) with Wubi Installer. 
<em>Here's what wubi-installer.org has to says</em>
<blockquote cite="http://wubi-installer.org" style="color:#666 !important">
<p>Wubi is an unofficial Ubuntu installer for Windows users that will bring you into the Linux world with a single click. Wubi allows you to install and uninstall Ubuntu as any other application. If you heard about Linux and Ubuntu, if you wanted to try them but you were afraid, this is for you.</p>
<ul>
<li>Wubi is safe - It does not require you to modify the partitions of your PC, or to use a different bootloader.</li>
<li>Wubi is Simple - Just run the installer, no need to burn a CD.</li>
<li>Wubi is Discrete - Wubi keeps most of the files in one folder, and If you do not like, you can simply uninstall it.</li>
<li>Wubi is Free - Wubi (like Ubuntu) is free as in beer and as in freedom. You will get this part later on, the important thing now is that it cost absolutely nothing, it is our gift to you...</li>
</ul></blockquote>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>The safest way to clean any kind of windows virus is to work in different environment others than its originating operating system. Try virtual Ubuntu (Debian Linux) with Wubi Installer.<br />
<em>Here&#8217;s what wubi-installer.org has to says</em></p>
<blockquote cite="http://wubi-installer.org" style="color:#666 !important">
<p>Wubi is an unofficial Ubuntu installer for Windows users that will bring you into the Linux world with a single click. Wubi allows you to install and uninstall Ubuntu as any other application. If you heard about Linux and Ubuntu, if you wanted to try them but you were afraid, this is for you.</p>
<ul>
<li>Wubi is safe - It does not require you to modify the partitions of your PC, or to use a different bootloader.</li>
<li>Wubi is Simple - Just run the installer, no need to burn a CD.</li>
<li>Wubi is Discrete - Wubi keeps most of the files in one folder, and If you do not like, you can simply uninstall it.</li>
<li>Wubi is Free - Wubi (like Ubuntu) is free as in beer and as in freedom. You will get this part later on, the important thing now is that it cost absolutely nothing, it is our gift to you&#8230;</li>
</ul>
</blockquote>
<h5>Wubi installer.</h5>
<p style="margin: 18px;text-align:center"><a href="http://blog.kakkoi.net/uri/aHR0cDovL3d3dy5zaGFyZWFwaWMubmV0L2NvbnRlbnQucGhwP2lkPTQ2NzExMDY.curie,80,302" rel="nofollow external"><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004671106.png' alt='wubi debian ubuntu installer screenshot' width="130" height="102" /></a></p>
<p>Wubi wont break your system partition or replaced you windows. You can also installed wubi in any drive and its come with clean Windows uninstaller. You can dowload Wubi at <a href="http://wubi-installer.org/latest.php" rel="nofollow">wubi-installer.org</a> or <a href="http://sourceforge.net/project/showfiles.php?group_id=198355" rel="nofollow">Sourceforge</a>. <small class="vcard">~ suggested by <a class="url fn" href="https://launchpad.org/~chaoskaizer" title="Wubi, Lupin Team members">ChaosKaizer</a> </small></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows CAPICOM remote code execution vulnerability</title>
		<link>http://42.kaizeku.com/windows/windows-capicom-remote-code-execution-vulnerability/</link>
		<comments>http://42.kaizeku.com/windows/windows-capicom-remote-code-execution-vulnerability/#comments</comments>
		<pubDate>Tue, 18 Sep 2007 18:03:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[COM]]></category>

		<category><![CDATA[cryptographic]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/windows-capicom-remote-code-execution-vulnerability/</guid>
		<description><![CDATA[A remote code execution vulnerability exists in Cryptographic API Component Object Model (CAPICOM) that allows an attacker who successfully exploits this vulnerability to take complete control of an affected system. CAPICOM can be used as a component of a 3rd party webpage, script or application. You can protect your computer by installing this update from Microsoft.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>A remote code execution vulnerability exists in Cryptographic API Component Object Model (CAPICOM) that allows an attacker who successfully exploits this vulnerability to take complete control of an affected system. CAPICOM can be used as a component of a 3rd party webpage, script or application. </p>
<p>More information for this update can be found at <a href="http://support.microsoft.com/kb/931906">KB 931906</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/windows-capicom-remote-code-execution-vulnerability/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
