<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: More malware by the Virut-gang</title>
	<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Fri, 21 Nov 2008 02:25:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-245</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Tue, 04 Sep 2007 05:03:05 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-245</guid>
		<description>Sorry, but no. It's just a small IRC bot that tracks the botnet itself. If you know which thread inside winlogon.exe is the one with infection you could download Process Explorer from SysInternals and snuff the particular thread with it. Otherwise I suggest some kind of online virus scan or several of them.

Process Explorer can be found from http://www.microsoft.com/technet/sysinternals/Utilities/ProcessExplorer.mspx</description>
		<content:encoded><![CDATA[<p>Sorry, but no. It&#8217;s just a small IRC bot that tracks the botnet itself. If you know which thread inside winlogon.exe is the one with infection you could download Process Explorer from SysInternals and snuff the particular thread with it. Otherwise I suggest some kind of online virus scan or several of them.</p>
<p>Process Explorer can be found from <a href="http://www.microsoft.com/technet/sysinternals/Utilities/ProcessExplorer.mspx" rel="nofollow">http://www.microsoft.com/technet/sysinternals/Utilities/ProcessExplorer.mspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-244</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Mon, 03 Sep 2007 22:06:07 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-244</guid>
		<description>I've just noticed that winlogon.exe is still trying to connect to 81.95.146.254.
I thought I had this thing cleaned off. Have you got any suggestions for cleaning this thing (bar a complete system reinstall) ??

I'll read up on that ISP.

Would that tracker help me to monitor if Virut is still actively trying to access the net (and thus still active on my system)?

Cheers,
Jonathan</description>
		<content:encoded><![CDATA[<p>I&#8217;ve just noticed that winlogon.exe is still trying to connect to 81.95.146.254.<br />
I thought I had this thing cleaned off. Have you got any suggestions for cleaning this thing (bar a complete system reinstall) ??</p>
<p>I&#8217;ll read up on that ISP.</p>
<p>Would that tracker help me to monitor if Virut is still actively trying to access the net (and thus still active on my system)?</p>
<p>Cheers,<br />
Jonathan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-243</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Mon, 03 Sep 2007 10:34:11 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-243</guid>
		<description>Hi,
thanks for the info :)

Virut Watcher is a small botnet tracker I did for tracking the Virut botnet. it's about 1500 bytes in size and written in assembly. 

The last IP in that list (81.95.146.254) belongs to Russian Business Network, which is a rogue ISP in Russia. Verisign did an excellent report on them a while back:
http://www.economist.com/displayStory.cfm?story_id=9723768&#38;fsrc=RSS
http://www.theage.com.au/news/business/from-russia-with-malice-criminals-trawl-the-world/2007/07/23/1185043032049.html?page=fullpage#contentSwap1</description>
		<content:encoded><![CDATA[<p>Hi,<br />
thanks for the info :)</p>
<p>Virut Watcher is a small botnet tracker I did for tracking the Virut botnet. it&#8217;s about 1500 bytes in size and written in assembly. </p>
<p>The last IP in that list (81.95.146.254) belongs to Russian Business Network, which is a rogue ISP in Russia. Verisign did an excellent report on them a while back:<br />
<a href="http://www.economist.com/displayStory.cfm?story_id=9723768&amp;fsrc=RSS" rel="nofollow">http://www.economist.com/displayStory.cfm?story_id=9723768&amp;fsrc=RSS</a><br />
<a href="http://www.theage.com.au/news/business/from-russia-with-malice-criminals-trawl-the-world/2007/07/23/1185043032049.html?page=fullpage#contentSwap1" rel="nofollow">http://www.theage.com.au/news/business/from-russia-with-malice-criminals-trawl-the-world/2007/07/23/1185043032049.html?page=fullpage#contentSwap1</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-242</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Mon, 03 Sep 2007 10:05:14 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-242</guid>
		<description>Hi there,
I've just been dealing with a Virut virus on my machine.
The IPs (and trailing folder locations it has been trying to access to download various trojans etc are:
85.114.140.107/-grander/dl.exe
85.114.140.107/-grander/adv735.exe
81.95.146.254

Perhaps this info helps you in your exploration of this virus.
By the way, what is the "Virut Watcher" application you are using?

Regards,
Jonathan</description>
		<content:encoded><![CDATA[<p>Hi there,<br />
I&#8217;ve just been dealing with a Virut virus on my machine.<br />
The IPs (and trailing folder locations it has been trying to access to download various trojans etc are:<br />
85.114.140.107/-grander/dl.exe<br />
85.114.140.107/-grander/adv735.exe<br />
81.95.146.254</p>
<p>Perhaps this info helps you in your exploration of this virus.<br />
By the way, what is the &#8220;Virut Watcher&#8221; application you are using?</p>
<p>Regards,<br />
Jonathan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-36</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Wed, 25 Apr 2007 05:10:32 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-36</guid>
		<description>Gandi has, as far as I can tell, been on the good side. We need more responsible registrars like them to effectively battle against various malware spreaders.</description>
		<content:encoded><![CDATA[<p>Gandi has, as far as I can tell, been on the good side. We need more responsible registrars like them to effectively battle against various malware spreaders.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MAD</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-33</link>
		<dc:creator>MAD</dc:creator>
		<pubDate>Tue, 24 Apr 2007 05:52:08 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/26/more-malware-by-the-virut-gang/#comment-33</guid>
		<description>XGJAMTULUX.COM have been taken down.
Thanks to, Gandi.

Regards,</description>
		<content:encoded><![CDATA[<p>XGJAMTULUX.COM have been taken down.<br />
Thanks to, Gandi.</p>
<p>Regards,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
