<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised</title>
	<atom:link href="http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Mon, 14 Dec 2009 07:06:01 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tore Eriksson</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-2599</link>
		<dc:creator>Tore Eriksson</dc:creator>
		<pubDate>Sun, 30 Aug 2009 20:19:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-2599</guid>
		<description>I have struggled with this malware all weekend. It&#039;s called Krap.w and seems to be very new. All google hits are just hours old. No antivirus company has any news on it. It reinstalls a three-digit exe file every reboot, like 266.exe in temporary internet files folder, and also a random eight digit folder in user\temp\, eg. user\temp\15736234\ where three files are created: 15736234 15736234.ins and 15736234.exe (same random eight digits). F-secure&#039;s antivirus program now detects and stops it from taking over the system, but does not find the installer yet. Neither have I.</description>
		<content:encoded><![CDATA[<p>I have struggled with this malware all weekend. It&#8217;s called Krap.w and seems to be very new. All google hits are just hours old. No antivirus company has any news on it. It reinstalls a three-digit exe file every reboot, like 266.exe in temporary internet files folder, and also a random eight digit folder in user\temp\, eg. user\temp\15736234\ where three files are created: 15736234 15736234.ins and 15736234.exe (same random eight digits). F-secure&#8217;s antivirus program now detects and stops it from taking over the system, but does not find the installer yet. Neither have I.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheOne</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-1573</link>
		<dc:creator>TheOne</dc:creator>
		<pubDate>Fri, 14 Aug 2009 11:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-1573</guid>
		<description>Well last time i booted into windows my desktop-background was izohore.bmp and a strange &quot;Anti Virus&quot; Software was scanning some files. So it seems like i have got this thing. The Problem was that i could not Run any App like firefox or taskmanager since the &quot;AV&quot; &quot;detected an infection&quot; So i quickliy shut down my computer and booted into Linux. I mounted the WINDOWS partition and fount strange nubered exe in an stange numbered folder in /all users/Application Data/ and the izohore.bmp in \user\Local Settings\Temp\ but i couldnot find any other file yet. I used ClamAV to scan this partition but it did not even find the exe in the &quot;app data&quot; folder(since it is not the best choice anyway). It seems like this scarware uses varied names to store its data but the server.exe and socks.exe should exist i think and the names do not seem like they varie. 
Since the Program doesnot seem to corrupt any random data, im going to reboot into windows and see what i can do there since i have removed ev erything if found concerning this virus. Thank you</description>
		<content:encoded><![CDATA[<p>Well last time i booted into windows my desktop-background was izohore.bmp and a strange &#8220;Anti Virus&#8221; Software was scanning some files. So it seems like i have got this thing. The Problem was that i could not Run any App like firefox or taskmanager since the &#8220;AV&#8221; &#8220;detected an infection&#8221; So i quickliy shut down my computer and booted into Linux. I mounted the WINDOWS partition and fount strange nubered exe in an stange numbered folder in /all users/Application Data/ and the izohore.bmp in \user\Local Settings\Temp\ but i couldnot find any other file yet. I used ClamAV to scan this partition but it did not even find the exe in the &#8220;app data&#8221; folder(since it is not the best choice anyway). It seems like this scarware uses varied names to store its data but the server.exe and socks.exe should exist i think and the names do not seem like they varie.<br />
Since the Program doesnot seem to corrupt any random data, im going to reboot into windows and see what i can do there since i have removed ev erything if found concerning this virus. Thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lori</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-346</link>
		<dc:creator>Lori</dc:creator>
		<pubDate>Fri, 10 Jul 2009 20:18:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-346</guid>
		<description>i have this virus on my computer and was unable to access certain websites. now whenever i try to open IE 7 to any page, it shows trughtsa.com, sticks there for a while, an adobe error comes up and then the whole program shuts down. how do i get this off of my computer???? please help!!!</description>
		<content:encoded><![CDATA[<p>i have this virus on my computer and was unable to access certain websites. now whenever i try to open IE 7 to any page, it shows trughtsa.com, sticks there for a while, an adobe error comes up and then the whole program shuts down. how do i get this off of my computer???? please help!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-306</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Tue, 07 Jul 2009 21:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-306</guid>
		<description>Hi, after reading this im absolutely positive that i have this on my computer. It seems to block my anti virus from working.
(I have Trend Micro) You&#039;re website is the only place i&#039;ve found information on this so far. If you could help me in removing it, or direct me somewhere that can it would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>Hi, after reading this im absolutely positive that i have this on my computer. It seems to block my anti virus from working.<br />
(I have Trend Micro) You&#8217;re website is the only place i&#8217;ve found information on this so far. If you could help me in removing it, or direct me somewhere that can it would be greatly appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: demantos</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-183</link>
		<dc:creator>demantos</dc:creator>
		<pubDate>Thu, 25 Jun 2009 07:54:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-183</guid>
		<description>Hi ANdrew.
I&#039;m Korean malware analzer. :)
I try to download above url but my dns is not resolv that domain name.
SO would you please send me a copy of the binaries?

Thanks.</description>
		<content:encoded><![CDATA[<p>Hi ANdrew.<br />
I&#8217;m Korean malware analzer. <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I try to download above url but my dns is not resolv that domain name.<br />
SO would you please send me a copy of the binaries?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
