<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Virus</title>
	<atom:link href="http://42.kaizeku.com/topics/security/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Beware of this site</title>
		<link>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/</link>
		<comments>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/#comments</comments>
		<pubDate>Sat, 24 Nov 2007 03:03:05 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[JS/Exploit.ADODB.Stream NAP Trojan warez streaming]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/virus/js-exploit-adodb-stream-nap-rojan/</guid>
		<description><![CDATA[

Its quite rare to see website attacking visitors but the following site is an exception.

girlhell.org
66.79.184.58
Apr 27 08 - usawarez.net

There is few known threads from the above website

JS/Exploit.ADODB.Stream NAP Trojan
Hidden download.
usawarez - False Image Checksum/corrupted 

Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Its quite rare to see website attacking visitors but the following site is an exception.</p>
<ol>
<li><code>girlhell.org</code></li>
<li><code>66.79.184.58</code></li>
<li><small>Apr 27 08</small> - <code>usawarez.net</code></li>
</ol>
<p>There is few known threads from the above website</p>
<ol>
<li><strong>JS/Exploit.ADODB.Stream NAP Trojan</strong></li>
<li>Hidden download.</li>
<li>usawarez - False Image Checksum/corrupted </li>
</ol>
<p>Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the analysis. read it all <a href="http://blog.kakkoi.net/uri/d3d3LmF2ZXJ0bGFicy5jb20vcmVzZWFyY2gvYmxvZy9pbmRleC5waHAvMjAwNy8wNS8yNS9hbm90aGVyLWlkZW50aXR5LXRoZWZ0LXN0b3J5LTIv.curie,80,302" title="McAfee Blog" rel="external">here</a>.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/feed/</wfw:commentRss>
		</item>
		<item>
		<title>w32.virut.w, PE_VIRUT.A</title>
		<link>http://42.kaizeku.com/security/virus/w32virutw/</link>
		<comments>http://42.kaizeku.com/security/virus/w32virutw/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 11:44:42 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[anti virus]]></category>

		<category><![CDATA[norton]]></category>

		<category><![CDATA[PE_VIRUT.A]]></category>

		<category><![CDATA[svntortoise]]></category>

		<category><![CDATA[w32.virut.w]]></category>

		<category><![CDATA[winlogon]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/?p=3</guid>
		<description><![CDATA[

I just download google pack with norton and the first scan hook my fav svn tortoise with w32.virut.w .
Excerpt from Symantec
W32.Virut.A is a virus that infects executable files and opens a back door on TCP port 65520 by connecting to a predefined IRC server.
Netstats
netstat -aob &#62; netstat.log

 TCP USER:1028 78.109.19.140.in.hosting.ua:65520 ESTABLISHED 936
 [winlogon.exe]
The free version [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I just download google pack with norton and the first scan hook my fav <strong>svn tortoise</strong> with w32.virut.w .</p>
<p>Excerpt from <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-051402-1930-99" rel="nofollow">Symantec</a></p>
<blockquote cite="http://www.symantec.com/security_response/writeup.jsp?docid=2006-051402-1930-99"><p>W32.Virut.A is a virus that infects executable files and opens a back door on TCP port 65520 by connecting to a predefined IRC server.</p></blockquote>
<h3>Netstats</h3>
<p><tt>netstat -aob &gt; netstat.log</tt></p>
<pre>
 TCP USER:1028 78.109.19.140.in.hosting.ua:65520 ESTABLISHED 936
 [winlogon.exe]</pre>
<p>The free version of Norton Internet Scan Failed to fixed the virus. :(<br />
<span id="more-3"></span></p>
<h3>Norton Logs</h3>
<pre>
Process:
 c:\windows\system32\ctfmon.exe
 c:\program files\tortoisesvn\bin\tsvncache.exe
Infection:
 c:\windows\system32\ctfmon.exe
 c:\program files\tortoisesvn\bin\tsvncache.exe
 c:\windows\system32\spoolsv.exe
 c:\windows\system32\locator.exe
 c:\windows\system32\alg.exe
 c:\windows\system32\sessmgr.exe
 c:\windows\system32\dllhost.exe
 c:\windows\system32\rsvp.exe
 c:\windows\system32\dmadmin.exe
 c:\windows\system32\msdtc.exe
 c:\windows\system32\cisvc.exe
 c:\windows\system32\wbem\wmiapsrv.exe
 c:\windows\system32\ups.exe
 c:\windows\system32\msiexec.exe
 c:\windows\system32\netdde.exe
 c:\windows\system32\vssvc.exe
 c:\windows\system32\mnmsrvc.exe
 c:\windows\system32\mshta.exe
 c:\windows\system32\userinit.exe
 c:\windows\system32\ieudinit.exe
 c:\windows\inf\unregmp2.exe
 c:\windows\system32\ie4uinit.exe
 c:\windows\system32\rundll32.exe
 c:\windows\system32\regsvr32.exe
 c:\windows\system32\ntsd.exe
 c:\program files\wakoopa\wakoopa.exe
 c:\program files\7-zip\7zfm.exe
 c:\program files\acd systems\acdsee\6.0\acdsee6.exe
 c:\program files\adobe\adobe help center\ahc.exe
 c:\program files\netmeeting\conf.exe
 c:\program files\common files\acd systems\en\devdetect.exe
 c:\program files\windows nt\dialer.exe
 c:\program files\acd systems\fotocanvas\3.0\fotocanvas3.exe
 c:\program files\acd systems\fotoslate\3.0\fotoslate3.exe
 c:\windows\pchealth\helpctr\binaries\helpctr.exe
 c:\program files\hp\digital imaging\unload\hpqapkil.exe
 c:\program files\hp\digital imaging\unload\hpqdia.exe
 c:\program files\hp\digital imaging\unload\hpqdias.exe
 c:\program files\hp\digital imaging\unload\hpqphunl.exe
 c:\program files\hp\digital imaging\unload\hpqpsmon.exe
 c:\program files\hp\digital imaging\unload\hpqunset.exe
 c:\program files\hp\digital imaging\bin\hpqvpswp.exe
 c:\program files\windows nt\hypertrm.exe
 c:\program files\internet explorer\connection wizard\icwconn1.exe
 c:\program files\internet explorer\connection wizard\icwconn2.exe
 c:\program files\internet explorer\iexplore.exe
 c:\program files\adobe\adobe photoshop cs2\imageready.exe
 c:\program files\internet explorer\connection wizard\inetwiz.exe
 c:\program files\internet explorer\connection wizard\isignup.exe
 c:\program files\java\jre1.6.0_02\bin\javaws.exe
 c:\windows\system32\usmt\migwiz.exe
 c:\program files\movie maker\moviemk.exe
 c:\program files\windows media player\mplayer2.exe
 c:\program files\combined community codec pack\mpc\mplayerc.exe
 c:\windows\pchealth\helpctr\binaries\msconfig.exe
 c:\program files\outlook express\msimn.exe
 c:\program files\common files\microsoft shared\msinfo\msinfo32.exe
 c:\program files\messenger\msmsgs.exe
 c:\program files\notepad++\notepad++.exe
 c:\windows\system32\mspaint.exe
 c:\program files\adobe\adobe photoshop cs2\photoshop.exe
 c:\program files\quicktime\pictureviewer.exe
 c:\python25\python.exe
 c:\program files\real\realplayer\realplay.exe
 c:\program files\common files\real\update_ob\rnxproc.exe
 c:\windows\soundman.exe
 c:\program files\tortoisesvn\bin\subwcrev.exe
 c:\program files\outlook express\wab.exe
 c:\program files\outlook express\wabmig.exe
 c:\program files\winrar\winrar.exe
 c:\program files\windows media player\wmplayer.exe
 c:\program files\windows nt\accessories\wordpad.exe
 c:\program files\combined community codec pack\zoom player\zplayer.exe
 c:\windows\system32\logon.scr
Service:
 RpcLocator
 ALG
 RDSessMgr
 COMSysApp
 RSVP
 dmadmin
 MSDTC
 CiSvc
 WmiApSrv
 UPS
 SwPrv
 MSIServer
 NetDDE
 VSS
 mnmsrvc
Browser Cache
Registry:
 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-&gt;Userinit</pre>
<p>had to reinstall my windows XP because there is so many hook. I had send a support email to hosting.ua but still got no replied from theme. need to reboot now.</p>
<h3>Nov 17 07 , Update</h3>
<p>I got reply back from hosting.ua support. below is part of the email</p>
<pre>
from	abuse@hosting.ua
to	nospam@gmail.com,
date	Nov 13, 2007 5:00 PM
subject	Reply: trojan 78.109.19.140.in.hosting.ua #48879

hide details Nov 13 (3 days ago)	

Reply

======== CUT HERE =========
Your support request was answered:

Created: 11.11.2007 1:28:38
Last Mod: 12.11.2007 1:41:30

Assigned To:
admin(Hosting.UA)

[11.11.2007 1:28:38]
Q: hi,
This is for your attention. I got a trojan in pc it routed back to one of
your hosting at *78.109.19.140.in.hosting.ua *

I hope you can do something about it.

Thank you
-------------------------------------------------------

[13.11.2007 11:00:08]
A: Fixed!

thx
www.Hosting.UA

-------------------------------------------------------
Hosting.UA Administration</pre>
<p>Well there is no explaination about the issue from the support staff.  hope this site will be closed down for good. Google already blocked and place a warning when you search for the infected URI.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/w32virutw/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safeguard your Windows when cleaning files infected by win32 virus.</title>
		<link>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/</link>
		<comments>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/#comments</comments>
		<pubDate>Fri, 26 Oct 2007 10:59:01 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Debian]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Ubuntu]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[wine]]></category>

		<category><![CDATA[wubi]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/</guid>
		<description><![CDATA[The safest way to clean any kind of windows virus is to work in different environment others than its originating operating system. Try virtual Ubuntu (Debian Linux) with Wubi Installer. 
<em>Here's what wubi-installer.org has to says</em>
<blockquote cite="http://wubi-installer.org" style="color:#666 !important">
<p>Wubi is an unofficial Ubuntu installer for Windows users that will bring you into the Linux world with a single click. Wubi allows you to install and uninstall Ubuntu as any other application. If you heard about Linux and Ubuntu, if you wanted to try them but you were afraid, this is for you.</p>
<ul>
<li>Wubi is safe - It does not require you to modify the partitions of your PC, or to use a different bootloader.</li>
<li>Wubi is Simple - Just run the installer, no need to burn a CD.</li>
<li>Wubi is Discrete - Wubi keeps most of the files in one folder, and If you do not like, you can simply uninstall it.</li>
<li>Wubi is Free - Wubi (like Ubuntu) is free as in beer and as in freedom. You will get this part later on, the important thing now is that it cost absolutely nothing, it is our gift to you...</li>
</ul></blockquote>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>The safest way to clean any kind of windows virus is to work in different environment others than its originating operating system. Try virtual Ubuntu (Debian Linux) with Wubi Installer.<br />
<em>Here&#8217;s what wubi-installer.org has to says</em></p>
<blockquote cite="http://wubi-installer.org" style="color:#666 !important">
<p>Wubi is an unofficial Ubuntu installer for Windows users that will bring you into the Linux world with a single click. Wubi allows you to install and uninstall Ubuntu as any other application. If you heard about Linux and Ubuntu, if you wanted to try them but you were afraid, this is for you.</p>
<ul>
<li>Wubi is safe - It does not require you to modify the partitions of your PC, or to use a different bootloader.</li>
<li>Wubi is Simple - Just run the installer, no need to burn a CD.</li>
<li>Wubi is Discrete - Wubi keeps most of the files in one folder, and If you do not like, you can simply uninstall it.</li>
<li>Wubi is Free - Wubi (like Ubuntu) is free as in beer and as in freedom. You will get this part later on, the important thing now is that it cost absolutely nothing, it is our gift to you&#8230;</li>
</ul>
</blockquote>
<h5>Wubi installer.</h5>
<p style="margin: 18px;text-align:center"><a href="http://blog.kakkoi.net/uri/aHR0cDovL3d3dy5zaGFyZWFwaWMubmV0L2NvbnRlbnQucGhwP2lkPTQ2NzExMDY.curie,80,302" rel="nofollow external"><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004671106.png' alt='wubi debian ubuntu installer screenshot' width="130" height="102" /></a></p>
<p>Wubi wont break your system partition or replaced you windows. You can also installed wubi in any drive and its come with clean Windows uninstaller. You can dowload Wubi at <a href="http://wubi-installer.org/latest.php" rel="nofollow">wubi-installer.org</a> or <a href="http://sourceforge.net/project/showfiles.php?group_id=198355" rel="nofollow">Sourceforge</a>. <small class="vcard">~ suggested by <a class="url fn" href="https://launchpad.org/~chaoskaizer" title="Wubi, Lupin Team members">ChaosKaizer</a> </small></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
