<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Under the Hood: Virut</title>
	<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Fri, 21 Nov 2008 07:01:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-196</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Wed, 01 Aug 2007 10:11:45 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-196</guid>
		<description>Hi,
as far as I know most of AV softwares should be able to perform the disinfection. Atleast Panda seems to have it right when using the Panda ActiveScan. It can be located at http://www.pandasecurity.com/homeusers/solutions/activescan/

--Toni</description>
		<content:encoded><![CDATA[<p>Hi,<br />
as far as I know most of AV softwares should be able to perform the disinfection. Atleast Panda seems to have it right when using the Panda ActiveScan. It can be located at <a href="http://www.pandasecurity.com/homeusers/solutions/activescan/" rel="nofollow">http://www.pandasecurity.com/homeusers/solutions/activescan/</a></p>
<p>&#8211;Toni</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stavros</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-194</link>
		<dc:creator>Stavros</dc:creator>
		<pubDate>Tue, 31 Jul 2007 14:36:21 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-194</guid>
		<description>Nice lesson of how is infecting exe,
do you thing there is a way to clean files?

Thanks in advance
Stavros</description>
		<content:encoded><![CDATA[<p>Nice lesson of how is infecting exe,<br />
do you thing there is a way to clean files?</p>
<p>Thanks in advance<br />
Stavros</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-10</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Thu, 12 Apr 2007 21:18:01 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-10</guid>
		<description>Very instructive explanation...
I have seen an strange behavior in some Virut mutation. Some of the mutation are not detected by antivirus program but the regresive mutation are.

If you infect with a E variant it infects with D variant and you can clean that but then some exe corrupts.

Do you think that it is due to an error in the code of virus or a bad cleening?

Another problem is if it is possible to detect a computer infected just analising the traffic in network. I want to say the packets to irc server are periodical or they are a function of any event?

Thanks for your good article.</description>
		<content:encoded><![CDATA[<p>Very instructive explanation&#8230;<br />
I have seen an strange behavior in some Virut mutation. Some of the mutation are not detected by antivirus program but the regresive mutation are.</p>
<p>If you infect with a E variant it infects with D variant and you can clean that but then some exe corrupts.</p>
<p>Do you think that it is due to an error in the code of virus or a bad cleening?</p>
<p>Another problem is if it is possible to detect a computer infected just analising the traffic in network. I want to say the packets to irc server are periodical or they are a function of any event?</p>
<p>Thanks for your good article.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
