<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Kukuruzman</title>
	<atom:link href="http://kukuruzman.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://kukuruzman.com</link>
	<description></description>
	<pubDate>Fri, 22 May 2009 10:40:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Странный вирус&#8230;</title>
		<link>http://kukuruzman.com/2009/05/22/strange_virus/</link>
		<comments>http://kukuruzman.com/2009/05/22/strange_virus/#comments</comments>
		<pubDate>Fri, 22 May 2009 10:24:03 +0000</pubDate>
		<dc:creator>Kukuruzman</dc:creator>
		
		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[fun]]></category>

		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://kukuruzman.com/?p=57</guid>
		<description><![CDATA[Сегодня одна из инсталях пыталась воткнуть мне на машину странный вирус&#8230;
Даже боюсь подумать о том, какой вред он может принести  

Будте бдительны, товарищи !!

]]></description>
			<content:encoded><![CDATA[<p>Сегодня одна из инсталях пыталась воткнуть мне на машину странный вирус&#8230;</p>
<p>Даже боюсь подумать о том, какой вред он может принести <img src='http://kukuruzman.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p style="text-align: center;"><img class="size-full wp-image-63 aligncenter" title="virus" src="http://kukuruzman.com/wp-content/uploads/2009/05/virus.jpg" alt="Strange_virus" width="453" height="342" /></p>
<p>Будте бдительны, товарищи !!</p>
<p><img class="aligncenter size-full wp-image-58" title="antivirus" src="http://kukuruzman.com/wp-content/uploads/2009/05/antivirus.jpg" alt="antivirus" width="550" height="273" /></p>
]]></content:encoded>
			<wfw:commentRss>http://kukuruzman.com/2009/05/22/strange_virus/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Screencaster</title>
		<link>http://kukuruzman.com/2009/05/08/screencaster/</link>
		<comments>http://kukuruzman.com/2009/05/08/screencaster/#comments</comments>
		<pubDate>Fri, 08 May 2009 19:01:05 +0000</pubDate>
		<dc:creator>Kukuruzman</dc:creator>
		
		<category><![CDATA[Devices]]></category>

		<category><![CDATA[Experimental]]></category>

		<category><![CDATA[desktop]]></category>

		<category><![CDATA[fun]]></category>

		<category><![CDATA[screencast]]></category>

		<category><![CDATA[share]]></category>

		<guid isPermaLink="false">http://kukuruzman.com/?p=35</guid>
		<description><![CDATA[Let me represent our new super device called &#8220;SCREENCASTER 1&#8243;.


This device was developed in our labs for those people who wants to share their desktop, documents, create screencasts and support documentation, stay in touch with people who are far away.
You can always stay online with new built-in wireless adapter which has super-style external antenna,

you can [...]]]></description>
			<content:encoded><![CDATA[<p>Let me represent our new super device called <strong>&#8220;SCREENCASTER</strong> <strong>1&#8243;</strong>.</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-34" title="SCREENCASTER" src="http://kukuruzman.com/wp-content/uploads/2009/05/main-1024x768.jpg" alt="main" width="561" height="433" /></p>
<p style="text-align: center;">
<p>This device was developed in our labs for those people who wants to share their desktop, documents, create screencasts and support documentation, stay in touch with people who are far away.</p>
<p><span id="more-35"></span>You can always stay online with new built-in wireless adapter which has super-style external antenna,</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-32" title="Antenna" src="http://kukuruzman.com/wp-content/uploads/2009/05/anthena-768x1024.jpg" alt="Antenna" width="461" height="614" /></p>
<p>you can talk to your friends using super- sensitive microphone,</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-31" title="Microphone" src="http://kukuruzman.com/wp-content/uploads/2009/05/mic-1024x768.jpg" alt="Microphone" width="614" height="461" /></p>
<p>It doesn&#8217;t matter what day time is at the moment - your friends can see where you are because this device has built-in Full HD camera with night-vision mode.</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-33" title="Camera" src="http://kukuruzman.com/wp-content/uploads/2009/05/cam-768x1024.jpg" alt="Camera" width="461" height="614" /></p>
<p>Professional headphones make you feeling presence of your friends. You&#8217;ll never feel lonely using our new <strong>&#8220;SCREENCASTER 1&#8243;.</strong></p>
<p style="text-align: left;">This device was tested in our labs and anonymous testers felt really good using <strong>&#8220;SCREENCASTER&#8221;</strong></p>
<p style="text-align: center;"><strong><img class="aligncenter size-large wp-image-29" title="Anonymous tester" src="http://kukuruzman.com/wp-content/uploads/2009/05/igor-1024x768.jpg" alt="igor" width="614" height="461" /></strong></p>
<p style="text-align: left;">Low weight, good ergonomic, lots of features and modern design  makes <strong>SCREENCASTER</strong> one of the best gadgets you can have at home.</p>
<p style="text-align: center;"><strong><img class="aligncenter size-large wp-image-30" title="Anonymous tester" src="http://kukuruzman.com/wp-content/uploads/2009/05/me-768x1024.jpg" alt="me" width="461" height="614" /></strong></p>
<p style="text-align: left;">In future <strong>SCREENCASTER </strong>models we are planning provide built in memory card and commutator - you&#8217;ll be able to connect few <strong>SCREENCASTERS </strong>in one network. If you want to see some other features in this amazing device - please leave a comment.</p>
<p style="text-align: center;"><strong>SCREENCASTER - YOUR BEST CHOICE!</strong></p>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://kukuruzman.com/2009/05/08/screencaster/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Worm Conficker</title>
		<link>http://kukuruzman.com/2009/01/22/worm-conficker/</link>
		<comments>http://kukuruzman.com/2009/01/22/worm-conficker/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 23:46:29 +0000</pubDate>
		<dc:creator>Kukuruzman</dc:creator>
		
		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[remove]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://kukuruzman.com/?p=7</guid>
		<description><![CDATA[In this article I&#8217;ll try to describe how to remove  Worm Conficker from your system.
Depends on the antivirus program you have, this worm can be detected with different names:
-  Symantec: W32.Downadup.B
-  Kaspersky: Net-Worm.Win32.Kido.fw
-  F-Secure: Worm:W32/Downadup.gen!A
-  Sophos: Mal/Conficker-A
-  Panda: Trj/Downloader.MDW
-  Grisoft: I-Worm/Generic.CJY
-  Eset: a variant of Win32/Conficker.AE worm
- [...]]]></description>
			<content:encoded><![CDATA[<p>In this article I&#8217;ll try to describe how to remove <span class="linktabprd"> Worm Conficker from your system.</span></p>
<p><span class="linktabprd">Depends on the antivirus program you have, this worm can be detected with different names:</span></p>
<p>-  Symantec: W32.Downadup.B<br />
-  Kaspersky: Net-Worm.Win32.Kido.fw<br />
-  F-Secure: Worm:W32/Downadup.gen!A<br />
-  Sophos: Mal/Conficker-A<br />
-  Panda: Trj/Downloader.MDW<br />
-  Grisoft: I-Worm/Generic.CJY<br />
-  Eset: a variant of Win32/Conficker.AE worm<br />
-  Bitdefender: Win32.Worm.Downadup.Gen</p>
<p>The easiest way to detect that you are infected is to try access these websites:</p>
<p><a href="http://update.microsoft.com">http://update.microsoft.com</a></p>
<p><a href="http://www.kaspersky.com/">http://www.kaspersky.com/</a></p>
<p><a href="http://drweb.com/">http://drweb.com/</a></p>
<p>This is not the whole list of websites that can be blocked. In such way virus tries</p>
<p>to prevent you update antivirus definition files and Windows system.</p>
<p>You will also get your AutomaticUpdates and BITS services disabled on the infected machine.</p>
<p>The Server and Workstation services can be disabled as well.</p>
<p>In our environment we determined three possible ways for its spreading:</p>
<p>1. Using autorun on the removable storage devices like  USB sticks or external USB hard drives.</p>
<p>On the removable drive it creates autorun.inf file and RECYCLED folder.<span id="more-7"></span></p>
<p>The best way to prevent this worm spreading through the autorun is to disable autorun possibility</p>
<p>on your workstations. To disable it  you just have to edit your  regestry:</p>
<pre>REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"</pre>
<p>After regestry modifications reboot your PC.</p>
<p>To enable the autorun you have to remove &#8220;Autorun.inf &#8221; key and reboot the PC.</p>
<h3>Note!!!</h3>
<p>These regestry entry was tested on WindowsXP only.</p>
<p>2. This worm tries to hide itself as image file:</p>
<p>- .bmp</p>
<p>- .gif</p>
<p>- .png</p>
<p>- .jpg</p>
<p>3. Worm can spread over the network using Windows vulnerability in RPC service.<br />
When worm gets on your PC, it copies itself to the following locations:</p>
<p>- <em>%all shared folders%</em> \RECYCLER\S-<em>%number%</em>\<em>%random character string%</em>.vmx</p>
<p>- %ProgramFiles%\Internet Explorer\<em>%random character string%</em>.dll</p>
<p>- %ProgramFiles%\Movie Maker\<em>%random character string%</em>.dll</p>
<p>- %System%\<em>%random character string%</em>.dll</p>
<p>- %Temp%\<em>%random character string%</em>.dll</p>
<p>- %ALLUSERSPROFILE%\Application Data\<em>%random character string%</em>.dll</p>
<p>The following registry keys are added in order to load the service after reboot:</p>
<p><!--NO_BR--></p>
<p>- HKLM\SYSTEM\CurrentControlSet\Services\<em>%random words%</em>\Parameters\</p>
<p>ServiceDll&#8221; = &#8220;<em>%paths and filenames of malware copies%</em>&#8221;<br />
- HKLM\SYSTEM\CurrentControlSet\Services\<em>%random words%</em>\</p>
<p><!--NO_BR--></p>
<p>&#8220;ImagePath&#8221; = %SystemRoot%\system32\svchost.exe -k netsvcs</p>
<p>&#8220;Type&#8221; = &#8220;4&#8243;</p>
<p>&#8220;Start&#8221; = &#8220;4&#8243;</p>
<p>&#8220;ErrorControl&#8221; = &#8220;4&#8243;<br />
It uses the following login information in order to gain access to the remote machine,</p>
<p>so it is better to change weak passwords like &#8220;11111&#8243; or &#8220;admin&#8221;.</p>
<p>You can also see tries to connect to these websites:</p>
<address>http://www.getmyip.org</address>
<address>http://www.whatsmyipaddress.com</address>
<address>http://getmyip.co.uk</address>
<address>http://checkip.dyndns.org</address>
<p>Virus do this to get your external IP address and send it to the &#8220;bad people&#8221;,</p>
<p>which allows them to control your system in future.</p>
<p>Here are the steps we performed to remove this worm in our network:</p>
<p>If you have domain and you have infected machines in it DONT login to the</p>
<p>damaged PCs with DOMAIN ADMINISTRATOR account when PC is connected to the</p>
<p>network  -  use local admin.</p>
<p>1. Disable network connection on the infected PCs;</p>
<p>2. Disable System Restore on the infected PCs;</p>
<p>3. Download MS08-67 vulnerability fix :</p>
<address><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</a></address>
<p>4. Run following tool on the infected system to remove the worm :</p>
<address><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en" target="_blank">Microsoft® Windows® Malicious Software Removal Tool<br />
</a></address>
<p>You can obtain some other removing tools if you don&#8217;t trust Microsoft:</p>
<address><a href="http://www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html">Bitdefender removal tool</a></address>
<address> </address>
<address><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99">Symantec removal tool</a></address>
<address> </address>
<p>or just use Google to find one you&#8217;d like more.</p>
<p>5. Restart the PC and install the fix from Microsoft to prevent the machine to be infected</p>
<p>in the future;</p>
<p>6. Plug in your network cable;</p>
<p>7. Update your antivirus program.;</p>
<p>8. Rerform Full System Scan with your antivirus program.</p>
<p>Hope this helps you to kill the worm on your systems.</p>
<p>Good luck!</p>
<p>Related links:</p>
<p><a href="http://en.wikipedia.org/wiki/Conficker">http://en.wikipedia.org/wiki/Conficker</a></p>
<p><a href="http://www.eset.com/threat-center/blog/?p=433">http://www.eset.com/threat-center/blog/?p=433</a></p>
<p><a href="http://www.avira.com/en/threats/section/fulldetails/id_vir/4474/worm_conficker.html">http://www.avira.com/en/threats/section/fulldetails/id_vir/4474/worm_conficker.html</a></p>
<p><a href="http://support.microsoft.com/kb/962007">http://support.microsoft.com/kb/962007</a></p>
<p><a href="http://vil.nai.com/vil/content/v_153464.htm">http://vil.nai.com/vil/content/v_153464.htm</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kukuruzman.com/2009/01/22/worm-conficker/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
