<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Under the Hood: Virut</title>
	<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Thu, 11 Mar 2010 19:27:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: information security</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-336</link>
		<dc:creator>information security</dc:creator>
		<pubDate>Thu, 04 Mar 2010 07:26:12 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-336</guid>
		<description>&lt;strong&gt;information security...&lt;/strong&gt;

Einige sind der Ansicht, dass es sich mit dem Thema zu beschaeftigen wenig lohnt, da der Informationsmarkt hierueber bereits recht ueberlaufen sei, Es laesst sich wahrlich nur recht selten auf etwas wriklich Gutes dabei zu treffen. Trotzdem kann sich d...</description>
		<content:encoded><![CDATA[<p><strong>information security&#8230;</strong></p>
<p>Einige sind der Ansicht, dass es sich mit dem Thema zu beschaeftigen wenig lohnt, da der Informationsmarkt hierueber bereits recht ueberlaufen sei, Es laesst sich wahrlich nur recht selten auf etwas wriklich Gutes dabei zu treffen. Trotzdem kann sich d&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: laptop dead - Help2Go</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-333</link>
		<dc:creator>laptop dead - Help2Go</dc:creator>
		<pubDate>Mon, 24 Aug 2009 18:19:19 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-333</guid>
		<description>[...] spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut  If you do try to repair this without reformatting then your best chance is using the Avira AntiVir [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut  If you do try to repair this without reformatting then your best chance is using the Avira AntiVir [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virut - Personal Reflections &#171; Of Bytes and Badges</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-323</link>
		<dc:creator>Virut - Personal Reflections &#171; Of Bytes and Badges</dc:creator>
		<pubDate>Thu, 12 Feb 2009 00:39:02 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-323</guid>
		<description>[...] unleashed) back in 2007, an excellent write-up of the virus&#8217;s initial strain can be found here. Just ignore the domain name and you&#8217;ll appreciate some serious disassembly and analysis. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] unleashed) back in 2007, an excellent write-up of the virus&#8217;s initial strain can be found here. Just ignore the domain name and you&#8217;ll appreciate some serious disassembly and analysis. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-196</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Wed, 01 Aug 2007 10:11:45 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-196</guid>
		<description>Hi,
as far as I know most of AV softwares should be able to perform the disinfection. Atleast Panda seems to have it right when using the Panda ActiveScan. It can be located at http://www.pandasecurity.com/homeusers/solutions/activescan/

--Toni</description>
		<content:encoded><![CDATA[<p>Hi,<br />
as far as I know most of AV softwares should be able to perform the disinfection. Atleast Panda seems to have it right when using the Panda ActiveScan. It can be located at <a href="http://www.pandasecurity.com/homeusers/solutions/activescan/" rel="nofollow">http://www.pandasecurity.com/homeusers/solutions/activescan/</a></p>
<p>&#8211;Toni</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stavros</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-194</link>
		<dc:creator>Stavros</dc:creator>
		<pubDate>Tue, 31 Jul 2007 14:36:21 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-194</guid>
		<description>Nice lesson of how is infecting exe,
do you thing there is a way to clean files?

Thanks in advance
Stavros</description>
		<content:encoded><![CDATA[<p>Nice lesson of how is infecting exe,<br />
do you thing there is a way to clean files?</p>
<p>Thanks in advance<br />
Stavros</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-10</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Thu, 12 Apr 2007 21:18:01 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-10</guid>
		<description>Very instructive explanation...
I have seen an strange behavior in some Virut mutation. Some of the mutation are not detected by antivirus program but the regresive mutation are.

If you infect with a E variant it infects with D variant and you can clean that but then some exe corrupts.

Do you think that it is due to an error in the code of virus or a bad cleening?

Another problem is if it is possible to detect a computer infected just analising the traffic in network. I want to say the packets to irc server are periodical or they are a function of any event?

Thanks for your good article.</description>
		<content:encoded><![CDATA[<p>Very instructive explanation&#8230;<br />
I have seen an strange behavior in some Virut mutation. Some of the mutation are not detected by antivirus program but the regresive mutation are.</p>
<p>If you infect with a E variant it infects with D variant and you can clean that but then some exe corrupts.</p>
<p>Do you think that it is due to an error in the code of virus or a bad cleening?</p>
<p>Another problem is if it is possible to detect a computer infected just analising the traffic in network. I want to say the packets to irc server are periodical or they are a function of any event?</p>
<p>Thanks for your good article.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
