<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>pisdos.com &#187; worm</title>
	<atom:link href="http://blog.pisdos.com/tag/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.pisdos.com</link>
	<description>when hamsters and apathy colide</description>
	<lastBuildDate>Wed, 24 Nov 2010 05:36:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>W32/netsky-AE</title>
		<link>http://blog.pisdos.com/w32netsky-ae/</link>
		<comments>http://blog.pisdos.com/w32netsky-ae/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 11:27:55 +0000</pubDate>
		<dc:creator>apathy</dc:creator>
				<category><![CDATA[Design / Tech area]]></category>
		<category><![CDATA[clean]]></category>
		<category><![CDATA[contracte de stat]]></category>
		<category><![CDATA[e-mail]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[netsky]]></category>
		<category><![CDATA[romania]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[w32/netsky-ae]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.pisdos.com/?p=173</guid>
		<description><![CDATA[Security warning and the easiest clean method: From: Mail Delivery System [mailto:MAILER-DAEMON@ironport3.[censored]] Posted At: 14 ianuarie 2009 09:42 Posted To: [censored] Conversation: ironport3.[censored] Virus infected message detected Subject: ironport3.[censored] Virus infected message detected The following viruses were detected in the message (MID 64089953): 'W32/Netsky-AE' Actions taken: Message archived Message dropped Original Envelope Sender: From 69e1eacc2b085@www.casmb.ro [...]]]></description>
			<content:encoded><![CDATA[<p>Security warning and the easiest clean method:</p>
<p><code>From: Mail Delivery System [mailto:MAILER-DAEMON@ironport3.[censored]]<br />
Posted At: 14 ianuarie 2009 09:42<br />
Posted To: [censored]<br />
Conversation: ironport3.[censored] Virus infected message detected<br />
Subject: ironport3.[censored] Virus infected message detected</p>
<p>The following viruses were detected in the message (MID 64089953):<br />
    'W32/Netsky-AE'<br />
<span id="more-173"></span><br />
Actions taken:<br />
    Message archived<br />
    Message dropped</p>
<p>Original Envelope Sender:<br />
    From 69e1eacc2b085@www.casmb.ro Wed Jan 14 08:41:57 2009</p>
<p>Message Headers:<br />
    From: 69e1eacc2b085@www.casmb.ro<br />
    To: [censored]<br />
    Subject: Hello<br />
    Date: Wed, 14 Jan 2009 10:29:47 +0200<br />
    Content-Type: multipart/mixed;<br />
boundary="----=_NextPart_000_0013_0000421B.000026D7"<br />
    X-Priority: 1<br />
    X-MSMail-Priority: High</code></p>
<p>What you can see above is the warning message provided by the firewall protecting an e-mail server. It basically tells you that a virus (in our case a worm) tried to send you an e-mail with malicious content. The one you can see right here was given by an <a href="http://www.ironport.com/">ironport</a> platform which caught a message sent by the W32/Netsky-AE worm, one that uses a smtp engine of its own to spread over the e-mail by sending itself to everyone that&#8217;s in the infected PC&#8217;s contact list.<br />
It&#8217;s quite easy to remove though by using <a href="http://www.sophos.com/support/cleaners/ntskygui.com">a basic tool, the NTSKYGUI</a> by <a href="http://www.sophos.com/">Sophos</a>. Just run it, easy.<br />
Now the worm part is over and the ranting in Romanian part begins&#8230;</p>
<p>Mesajul a fost trimis de pe un domeniu al <a href="http://www.casmb.ro/main.php">casmb</a>, mai precis de pe o adresa apartinand departamentului contabil sau de resurse umane al lor. Hai frate, cum sa ne asteptam sa mearga ceva bine in tara asta cand nici macar institutiile statului nu au cea mai mica protectie anti-virus? E posibil ca un departament contabil care ar trebui sa fie minim eficient sa trimita worms la toata lista de contacte? Raspunsul, trist, se pare ca e DA. Iar in timp ce tot sistemul informatic al statului merge ca un fund, contractele pentru bazele informatice se acorda unor companii care e evident ca produc software care sa arate cat mai &#8220;dragut&#8221; pe cat mai multi bani. Mentiune: cand am spus &#8220;unor companii&#8221;, e foarte posibil sa fi vrut sa scriu &#8220;unei companii&#8221; &#8211; fiecare intelege ce vrea. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pisdos.com/w32netsky-ae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>cleaning Win32/AutoRun.Agent.BE</title>
		<link>http://blog.pisdos.com/cleaning-win32autorunagentbe/</link>
		<comments>http://blog.pisdos.com/cleaning-win32autorunagentbe/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 15:47:33 +0000</pubDate>
		<dc:creator>apathy</dc:creator>
				<category><![CDATA[Design / Tech area]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[autorun.inf]]></category>
		<category><![CDATA[clean]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[nod32]]></category>
		<category><![CDATA[step by step]]></category>
		<category><![CDATA[Win32/AutoRun.Agent.BE]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.pisdos.com/?p=137</guid>
		<description><![CDATA[So yeah, I got my first worm in quite a while, the awesome and overall cute Win32/AutoRun.Agent.BE. But I also got a piece of wisdom from cleaning it &#8211; make sure you never download any software from sources you aren&#8217;t 100% sure of. That includes torrent trackers, dc++, any other p2p interface, random [free] download [...]]]></description>
			<content:encoded><![CDATA[<p>So yeah, I got my first worm in quite a while, the awesome and overall cute Win32/AutoRun.Agent.BE. But I also got a piece of wisdom from cleaning it &#8211; make sure you never download any software from sources you aren&#8217;t 100% sure of. That includes torrent trackers, dc++, any other p2p interface, random [free] download websites and so on.<br />
As I said, my PC, the mighty Shoarec, has caught a nasty case of Win32/AutoRun.Agent.BE and I had a bit of trouble cleaning it. Google adviced me to different methods to get rid of it but none actually worked so now I will post here the best way to get rid of it without much headache. For me it went pretty much like this: nod32 detected the worm as soon as it was in my system but didn&#8217;t manage to actually get me rid of it.<br />
This is how I cleaned it, step by step:</p>
<p>#1: Downloaded and installed the Malwarebytes&#8217; Anti-Malware software. It&#8217;s free for scanning and cleaning, you can get it from <a href="http://www.malwarebytes.org/mbam.php">here</a>. It&#8217;ll detect the worm and delete some of its parts.</p>
<p>#2: If you check in [My Computer] at this point you will still notice that the drive&#8217;s default action is Autoplay instead of Open. <strong>You shouldn&#8217;t double click the drive or use the autoplay option at any time! That&#8217;s definitely not good.</strong> Now you need to get those pesky &#8220;autorun.inf&#8221; files out in the open, to do that you will type in Run &#8220;attrib c:\autorun.inf -r -h -s&#8221;, it&#8217;will remove the attributes for the autorun.inf file found in the root C:\ drive. Replace C: with D:, E: etc. to remove the attributes for the file on all of your drives..</p>
<p>#3: Delete C:\autorun.inf, D:\autorun.inf and so on.</p>
<p>#4: Reboot. </p>
<p>#5: Run MBAM again to make sure the worm is gone.</p>
<p>There you go, now the worm is gone and your drives should again behave properly. </p>
<p>PS: Have a happy New Year. I will. </p>
<p>Thanks,<br />
The management. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pisdos.com/cleaning-win32autorunagentbe/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

