<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Fixes for files infected with Win32/virut.Virtob and Variants</title>
	<atom:link href="http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Wed, 07 Jan 2009 22:27:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: zyro</title>
		<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/#comment-6477</link>
		<dc:creator>zyro</dc:creator>
		<pubDate>Tue, 06 May 2008 23:19:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/fixed-for-files-infected-with-virutnat-mefir/#comment-6477</guid>
		<description>hi there
can u please email me these files I just wanna use them for learning purpose 

THANKS BUDDY</description>
		<content:encoded><![CDATA[<p>hi there<br />
can u please email me these files I just wanna use them for learning purpose </p>
<p>THANKS BUDDY</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bernd P</title>
		<link>http://42.kaizeku.com/windows/fixed-for-files-infected-with-virutnat-mefir/#comment-876</link>
		<dc:creator>Bernd P</dc:creator>
		<pubDate>Tue, 05 Feb 2008 11:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/fixed-for-files-infected-with-virutnat-mefir/#comment-876</guid>
		<description>The problem in prevention of viruses like the &lt;strong&gt;Virut&lt;/strong&gt; types is that they change the "bothosts" as well as the as the encryption with every new variant coming out.  A possible good solution to prevent your machine from making unauthorized unwanted connects by any unknown process or program is to have e.g. a &lt;a class="exturl icn-r" href="http://en.wikipedia.org/wiki/ZoneAlarm" rel="nofollow"&gt;ZoneAlarm&lt;/a&gt; firewall installed (which allows precisely blocking of e.g. STMP for specified programs - the default is 'blocked' - , specified port blocking (e.g. &lt;abbr title="Internet Relay Chat"&gt;IRC&lt;/abbr&gt;), preventing and denying any unsolicited inbound traffic, as well as the adaptive &lt;abbr title="The Ident Protocol is an Internet protocol that helps identify the user of a particular TCP connection"&gt;IDENT&lt;/abbr&gt; port hiding,(means this is a true stealth firewall).and specified security behavior concerning internet, intranet, local, safe zones, as well as a 5-step safety profile to set for specified programs).

&lt;p&gt;Additionally the user is informed about every network action and access attempts - ingoing as well outgoing - with source,
target, port and the program or process name which initiates the connection. Preventing spam-bot behavior means : only allow 'your' known Mail programs to send mails. NEVER store ANY PASSWORDS on the machine or in the mail program! Set '&lt;abbr title="Simple Mail Transfer Protocol"&gt;SMTP&lt;/abbr&gt; action' to 'password required' even if your SMTP provider doesn't need (if so this means anonymous SMTP is allowed, then you
have a BAD ISP which is really inviting spambots to spread their notorious garbage all around the world!). &lt;/p&gt;

&lt;p&gt;Essential Safety-rules are still ignored by the &lt;abbr title="Internet service provider"&gt;ISP&lt;/abbr&gt; in such cases. By the same way, the customers of such ISP are the victims of these. Go looking for another ISP if possible. All other programs should be blocked for SMTP (and IRC) protocols as well. That is essential in those days to keep an infected machine quiet towards the internet even if it is eventually infected by some weird worm, or botclient software. (Then your PC is called 'stoned' or how it is also said by the security people, a so-called 'Zombie'). Never allow HTTP or any other outgoing requests for other programs aside of your known browser, media-players or
file transfer, mail and chat programs. Be aware that especially 'Adware','Nag-Ware' and 'Spy-ware'-charged programs are always trying to 'phone home'!&lt;/p&gt;

&lt;p&gt;Same does &lt;a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Malware" rel="nofollow"&gt;Malware&lt;/a&gt; which attempts to reach or at least listens to their 'master hosts', (of course allow such for the safety facilities on your system to update themselves by their known code hosts). Using a host list which &lt;a href="/windows/how-to-block-website-without-using-firewall/" rel="nofollow"&gt;redirects therein contained servers to nowhere&lt;/a&gt; (means the localhost) is also a good hint. This file is also protected from being tampered with (unauthorized deletions or additions by any software or website scripts) by third party software (ie ZoneAlarm, McAffee, Nod32).&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>The problem in prevention of viruses like the <strong>Virut</strong> types is that they change the &#8220;bothosts&#8221; as well as the as the encryption with every new variant coming out. A possible good solution to prevent your machine from making unauthorized unwanted connects by any unknown process or program is to have e.g. a <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/ZoneAlarm" rel="nofollow">ZoneAlarm</a> firewall installed (which allows precisely blocking of e.g. STMP for specified programs - the default is &#8216;blocked&#8217; - , specified port blocking (e.g. <abbr title="Internet Relay Chat">IRC</abbr>), preventing and denying any unsolicited inbound traffic, as well as the adaptive <abbr title="The Ident Protocol is an Internet protocol that helps identify the user of a particular TCP connection">IDENT</abbr> port hiding,(means this is a true stealth firewall).and specified security behavior concerning internet, intranet, local, safe zones, as well as a 5-step safety profile to set for specified programs).</p>
<p>Additionally the user is informed about every network action and access attempts - ingoing as well outgoing - with source,<br />
target, port and the program or process name which initiates the connection. Preventing spam-bot behavior means : only allow &#8216;your&#8217; known Mail programs to send mails. NEVER store ANY PASSWORDS on the machine or in the mail program! Set &#8216;<abbr title="Simple Mail Transfer Protocol">SMTP</abbr> action&#8217; to &#8216;password required&#8217; even if your SMTP provider doesn&#8217;t need (if so this means anonymous SMTP is allowed, then you<br />
have a BAD ISP which is really inviting spambots to spread their notorious garbage all around the world!). </p>
<p>Essential Safety-rules are still ignored by the <abbr title="Internet service provider">ISP</abbr> in such cases. By the same way, the customers of such ISP are the victims of these. Go looking for another ISP if possible. All other programs should be blocked for SMTP (and IRC) protocols as well. That is essential in those days to keep an infected machine quiet towards the internet even if it is eventually infected by some weird worm, or botclient software. (Then your PC is called &#8217;stoned&#8217; or how it is also said by the security people, a so-called &#8216;Zombie&#8217;). Never allow HTTP or any other outgoing requests for other programs aside of your known browser, media-players or<br />
file transfer, mail and chat programs. Be aware that especially &#8216;Adware&#8217;,'Nag-Ware&#8217; and &#8216;Spy-ware&#8217;-charged programs are always trying to &#8216;phone home&#8217;!</p>
<p>Same does <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Malware" rel="nofollow">Malware</a> which attempts to reach or at least listens to their &#8216;master hosts&#8217;, (of course allow such for the safety facilities on your system to update themselves by their known code hosts). Using a host list which <a href="/windows/how-to-block-website-without-using-firewall/" rel="nofollow">redirects therein contained servers to nowhere</a> (means the localhost) is also a good hint. This file is also protected from being tampered with (unauthorized deletions or additions by any software or website scripts) by third party software (ie ZoneAlarm, McAffee, Nod32).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
