<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Should you be thinking about Virut?</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/498/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog/archives/498</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Wed, 02 Jun 2010 22:30:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Security Ripcord &#187; Blog Archive &#187; Did Mandiant&#8217;s Audit Viewer find something in Conficker?</title>
		<link>http://www.cutawaysecurity.com/blog/archives/498/comment-page-1#comment-31093</link>
		<dc:creator>Security Ripcord &#187; Blog Archive &#187; Did Mandiant&#8217;s Audit Viewer find something in Conficker?</dc:creator>
		<pubDate>Tue, 03 Mar 2009 00:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=498#comment-31093</guid>
		<description>[...] Should you be thinking about Virut?  [...]</description>
		<content:encoded><![CDATA[<p>[...] Should you be thinking about Virut?  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Weiland</title>
		<link>http://www.cutawaysecurity.com/blog/archives/498/comment-page-1#comment-31092</link>
		<dc:creator>Tom Weiland</dc:creator>
		<pubDate>Thu, 26 Feb 2009 15:07:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=498#comment-31092</guid>
		<description>This Virut (Vitro) Virus needs to be publicized more.  I have a shop full of client&#039;s machines that are infected.  We are desperately trying to stop the bleeding.  Only last night was I able to find basic documentation on how to handle this virus:
http://securitylabs.websense.com/content/blogs/3300.aspx
and
http://www.tech-linkblog.com/2009/02/polymorphic-win32vitro-most-virulnt-virus.html/

So far the above link provides the best details on what needs to be done, but it is also the most depressing (zero out drive the re-format) OMG what do I tell my clients?  

They may as well buy a new computer and transfer their data &quot;only&quot;.  By the time I mirror their drive (no backups of course) zero out the drive, reload Win OS w/necessary drivers (owners never have the disks anymore [thank you Dell]) install remaining 43 (minimum) security updates, and a reliable AV software.  Then migrate their data back to their system and tell them all they have to do is reload their applications.  I get a deadpan stare and a cold verbal response when I give them a bill for 3 hours work.  Heaven help me if the get reinfected within the week.  Plus I still have to zero out the drive I mirrored to before I can start on the next client.

How can I now be sure we got the whole virus eradicated?  We have (we think) experienced where our &quot;flash drive&quot; utilities have been compromized (Avast&#039;s install EXE, WinSockXPFix, etc. for example) by the Vitro.  

If I connect the infected drive as a USB slave to the fresh &quot;clean&quot; drive (system) to move &quot;only data&quot; will the BIOS or Driver install move the infection back?

Things I do know:
the EXE files in the SYSTEM32 are the first to go.  If the dates and sizes have all been updated you&#039;ve been had.  

Most infections start as an iFrame infection from a compromised web site.  During the iFrame clean - the EXE parasite attacks at full force.

I will add more related to symptoms once my high blood pressure subsides and do some more testing.

Tom</description>
		<content:encoded><![CDATA[<p>This Virut (Vitro) Virus needs to be publicized more.  I have a shop full of client&#8217;s machines that are infected.  We are desperately trying to stop the bleeding.  Only last night was I able to find basic documentation on how to handle this virus:<br />
<a href="http://securitylabs.websense.com/content/blogs/3300.aspx" rel="nofollow">http://securitylabs.websense.com/content/blogs/3300.aspx</a><br />
and<br />
<a href="http://www.tech-linkblog.com/2009/02/polymorphic-win32vitro-most-virulnt-virus.html/" rel="nofollow">http://www.tech-linkblog.com/2009/02/polymorphic-win32vitro-most-virulnt-virus.html/</a></p>
<p>So far the above link provides the best details on what needs to be done, but it is also the most depressing (zero out drive the re-format) OMG what do I tell my clients?  </p>
<p>They may as well buy a new computer and transfer their data &#8220;only&#8221;.  By the time I mirror their drive (no backups of course) zero out the drive, reload Win OS w/necessary drivers (owners never have the disks anymore [thank you Dell]) install remaining 43 (minimum) security updates, and a reliable AV software.  Then migrate their data back to their system and tell them all they have to do is reload their applications.  I get a deadpan stare and a cold verbal response when I give them a bill for 3 hours work.  Heaven help me if the get reinfected within the week.  Plus I still have to zero out the drive I mirrored to before I can start on the next client.</p>
<p>How can I now be sure we got the whole virus eradicated?  We have (we think) experienced where our &#8220;flash drive&#8221; utilities have been compromized (Avast&#8217;s install EXE, WinSockXPFix, etc. for example) by the Vitro.  </p>
<p>If I connect the infected drive as a USB slave to the fresh &#8220;clean&#8221; drive (system) to move &#8220;only data&#8221; will the BIOS or Driver install move the infection back?</p>
<p>Things I do know:<br />
the EXE files in the SYSTEM32 are the first to go.  If the dates and sizes have all been updated you&#8217;ve been had.  </p>
<p>Most infections start as an iFrame infection from a compromised web site.  During the iFrame clean &#8211; the EXE parasite attacks at full force.</p>
<p>I will add more related to symptoms once my high blood pressure subsides and do some more testing.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>
