<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5465651690170995482</id><updated>2011-11-27T16:12:44.042-08:00</updated><title type='text'>Virus | Trojan | Spyware | Removal Tools</title><subtitle type='html'>Virus removal tool, download recent updates antivirus database, trojan information, spyware treatment information, spam information</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://virusandtrojan.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default?start-index=101&amp;max-results=100'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>102</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6768668527373289312</id><published>2009-04-23T09:48:00.000-07:00</published><updated>2009-04-23T09:50:04.337-07:00</updated><title type='text'>Antivirus 2009: How to Remove Fake AV Software</title><content type='html'>A new threat that comes under the guise of a genuine antivirus program has become increasingly prevalent over the past year. Offering to locate and remove malware from your PC, this rogue will actually install a Trojan on your unsuspecting system. The process is usually initiated when you click a link for what you believe is valid security software or its vendor's site.&lt;br /&gt;&lt;br /&gt;Such adverts are not only a nuisance when browsing online -- fake ads appear on reputable sites that make use of third-party advertising -- but they are designed to rip off consumers by tempting them to pay for a worthless program. Worse still, these rogue applications infect your PC with a problem they claim can only be 'fixed' by purchasing extra software.&lt;br /&gt;&lt;br /&gt;If a fake antimalware app is installed on your PC, you will begin to receive fairly persistent warning messages that your system has been infected and be advised to visit a particular site and pay for the necessary protection. You'll be told that you have a trial version of the software installed and need to upgrade to remove all threats.&lt;br /&gt;&lt;br /&gt;Such has been the success of these scams that several of the fake programs have become infamous. WinAntiSpyware, Antivirus 2008 (recently updated to 2009), Antispyware Pro XP and AntiVirus Lab 2009 are all suspect -- and no doubt others will soon emulate them.&lt;br /&gt;&lt;br /&gt;With similar tactics having been previously used to perpetrate fraud such as phishing, the scammers have latched on to a very effective way to play on people's existing security fears.&lt;br /&gt;&lt;br /&gt;Should one break through your defences, we'll show you how to remove it from your system.&lt;br /&gt;&lt;br /&gt;1. The exact method for removing fake antivirus software will differ depending on the particular variety you've been blessed with. We've concentrated on Antivirus 2009. If it sounds familiar, you've probably endured fake warning alerts, increased pop-ups and the hijacking of your home page.&lt;br /&gt;&lt;br /&gt;2. Such programs can be difficult to uninstall, and you may need to use a dedicated application such as ParetoLogic's XoftSpySE. In general, you will find that using antispyware software is simpler, although it can't be guaranteed to work in every instance.&lt;br /&gt;&lt;br /&gt;3. Uninstall Antivirus 2009 using the Add/Remove Programs utility in the Control Panel, then restart your PC in Safe mode. Launch your antispyware application and allow it to scan system files and folders and remove any suspect applications. Now boot up your PC as normal.&lt;br /&gt;&lt;br /&gt;4. If antispyware software doesn't get rid of the fake program, you'll need to remove it manually. Be sure to back up any important files first. Next, press Ctrl, Alt, Del to bring up the Task Manager. Click Image Name and select Antivirus 2009, then choose End Process to stop it running.&lt;br /&gt;&lt;br /&gt;5. Go to Start, Run. Type regedit to start the Registry Editor, where you will delete the entries for WinAntiVirus. Browse to the Hkey_Local_Machine\Software folder from the My Computer folder and delete the series of Registry entries that are described on this PC Advisor forum thread.&lt;br /&gt;&lt;br /&gt;6. The same thread lists a number of spyware files that will need to be manually deleted from your Windows folder, but note that you may need to stop the file processes in the Task Manager before you can delete them. As before, make sure you back up your system before you start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: &lt;br /&gt;http://www.pcworld.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6768668527373289312?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6768668527373289312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6768668527373289312'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/antivirus-2009-how-to-remove-fake-av.html' title='Antivirus 2009: How to Remove Fake AV Software'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6902020973099962585</id><published>2009-04-23T09:35:00.000-07:00</published><updated>2009-04-23T09:38:57.297-07:00</updated><title type='text'>Review Norton AntiVirus 2009 16.0</title><content type='html'>Norton AntiVirus 2009 provides fast, responsive defense against all types of malicious software including viruses, spyware, worms, and other software threats. It protects your system without slowing it down. Rapid pulse updates every 5 to 15 minutes help to ensure that you're protected from the latest threats.&lt;br /&gt;&lt;br /&gt;Working quickly and quietly in the background, Norton AntiVirus requires little memory and system resources. The new Norton Insight relies on extensive online intelligence to target only those processes at risk, resulting in faster, shorter, fewer scans. And the new Norton Protection System employs a multilayered set of security technologies that work in concert to detect, identify, and block attacks. Version 2009 improves on product performance.&lt;br /&gt;&lt;br /&gt;Screenshot&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i.d.com.com/i/dl/media/dlimage/20/14/22/201422_medium.jpeg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 351px; height: 263px;" src="http://i.d.com.com/i/dl/media/dlimage/20/14/22/201422_medium.jpeg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download for review/trial [&lt;a href="http://trialware.norton.com/files/NAV2009_16.0_Build_125_0000001_OEM30_Cnet.exe"&gt;DOWNLOAD&lt;/a&gt;]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6902020973099962585?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6902020973099962585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6902020973099962585'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/review-norton-antivirus-2009-160.html' title='Review Norton AntiVirus 2009 16.0'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-558804170288868250</id><published>2009-04-23T09:14:00.000-07:00</published><updated>2009-04-23T09:16:22.899-07:00</updated><title type='text'>Review Kaspersky Anti-Virus 2009 8.0.0.454</title><content type='html'>Kaspersky Anti-Virus 2009 8.0.0.454 – The backbone of your PC’s security system, offering protection from a range of IT threats. Kaspersky Anti-Virus 2009 provides the basic tools needed to protect your PC. This easy-to-use solution provides complete antivirus protection that keeps you safe while your are online.&lt;br /&gt;Features :&lt;br /&gt;&lt;br /&gt;Kaspersky Anti Virus 8.0 – is a new line of Kaspersky Labs products, which is designed for the multi-tiered protection of personal computers. This product is based on in-house protection components, which are based on variety of technologies for maximum levels of user protection regardless of technical competencies. This product utilizes several technologies, which were jointly developed by Kaspersky Labs and other companies; part of them is implemented via online-services.&lt;br /&gt;Our products for home and home office are specifically designed to provide hassle-free and quality protection against viruses, worms and other malicious programs, as well as hacker attacks, spam and spyware.&lt;br /&gt;&lt;br /&gt;During product preparation several competitor offerings were considered and analyzed - firewalls, security suites systems, which position themselves as proactive in defence and HIPS systems. Combination of in-hosue innovative developments and results from analysis gathered through the industry allowed to jump onto a new level of protection for personal users, whereby offering even more hardened and less annoying computer protection from all types of electronic threats – malicious programs of different types, hacker attacks, spam mailings, program-root kits, phishing emails, advertisement popup windows etc.&lt;br /&gt;&lt;br /&gt;Essential Protection&lt;br /&gt;* Protects from viruses, Trojans and worms&lt;br /&gt;* Blocks spyware and adware&lt;br /&gt;* Scans files in real time (on access) and on demand&lt;br /&gt;* Scans email messages (regardless of email client)&lt;br /&gt;* Scans Internet traffic (regardless of browser)&lt;br /&gt;* Protects instant messengers (ICQ, MSN)&lt;br /&gt;* Provides proactive protection from unknown threats&lt;br /&gt;* Scans Java and Visual Basic scripts&lt;br /&gt;&lt;br /&gt;Preventive Protection&lt;br /&gt;* Scans operating system and installed applications for vulnerabilities&lt;br /&gt;* Analyzes and closes Internet Explorer vulnerabilities&lt;br /&gt;* Disables links to malware sites&lt;br /&gt;* Detects viruses based on the packers used to compress code&lt;br /&gt;* Global threat monitoring (Kaspersky Security Network)&lt;br /&gt;&lt;br /&gt;Advanced Protection &amp; Recovery&lt;br /&gt;* The program can be installed on infected computers&lt;br /&gt;* Self-protection from being disabled or stopped&lt;br /&gt;* Restores correct system settings after removing malicious software&lt;br /&gt;* Tools for creating a rescue disk&lt;br /&gt;&lt;br /&gt;Data &amp; Identity Theft Protection&lt;br /&gt;* Disables links to fake (phishing) websites&lt;br /&gt;* Blocks all types of keyloggers&lt;br /&gt;&lt;br /&gt;Usability&lt;br /&gt;* Automatic configuration during installation&lt;br /&gt;* Wizards for common tasks&lt;br /&gt;* Visual reports with charts and diagrams&lt;br /&gt;* Alerts provide all the information necessary for informed user decisions&lt;br /&gt;* Automatic or interactive mode&lt;br /&gt;* Round-the-clock technical support&lt;br /&gt;* Automatic database updates&lt;br /&gt;&lt;br /&gt;Download for trial Here [&lt;a href="ftp://ftp.kaspersky.com/products/english/homeuser/kav2009/kav8.0.0.506en.exe"&gt;DOWNLOAD&lt;/a&gt;]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-558804170288868250?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/558804170288868250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/558804170288868250'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/review-kaspersky-anti-virus-2009-800454.html' title='Review Kaspersky Anti-Virus 2009 8.0.0.454'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-880436768320374601</id><published>2009-04-16T09:13:00.000-07:00</published><updated>2009-04-16T09:15:55.248-07:00</updated><title type='text'>Norton 360 v3.0 for review</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i240.photobucket.com/albums/ff199/tolgadogan/SymantecN360v3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 325px; height: 399px;" src="http://i240.photobucket.com/albums/ff199/tolgadogan/SymantecN360v3.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Norton 360 description&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Offers a full circle of protection and eliminates the need to purchase and manage multiple products, Norton 360 will offer a full circle of protection and eliminates the need to purchase and manage multiple products.&lt;br /&gt;&lt;br /&gt;PC security defends you against a broad range of online threats�protects your computer and makes your online experience more secure, Identity protection safeguards you against online identity theft�protects against fraud and theft, Automatic backup and restore protects your important files from loss�safeguards irreplaceable photos, movies, music, and more.&lt;br /&gt;&lt;br /&gt;PC tuneup keeps your PC running at peak performance�helps your PC run faster and keeps it running the way it�s supposed to, Network monitoring�helps protect your home network.&lt;br /&gt;&lt;br /&gt;Here are some key features of "Norton 360":&lt;br /&gt;&lt;br /&gt;Enhanced performance - Provides industry-leading protection without sacrificing performance:&lt;br /&gt;� Fast scan and browse speeds&lt;br /&gt;� Less memory use than the average used by competing products&lt;br /&gt;� PC Security with industry leading virus, spyware and firewall protection&lt;br /&gt;� And much more...........&lt;br /&gt;&lt;br /&gt;Backup and restore:&lt;br /&gt;� Protects photos, music, and documents with automated backup&lt;br /&gt;� Supports new backup destinations including Blu-ray Disc, HD-DVD, and iPod&lt;br /&gt;� Automatically detects and backs up your critical files&lt;br /&gt;� Includes 2 GB of secured online storage (with option to purchase additional storage)&lt;br /&gt;&lt;br /&gt;Network monitoring:&lt;br /&gt;� Lets you view your wireless network and each device connected to it&lt;br /&gt;� Displays the security status of all the Norton products on your network&lt;br /&gt;� Alerts you when you connect to an unsecured wireless network&lt;br /&gt;� And much more..........&lt;br /&gt;Easy protection of your PC and online activities�Norton 360 threat handling, scans, and tuneups are conducted quietly in the background:&lt;br /&gt;� Automatically optimizes and maintains your PC for peak performance&lt;br /&gt;� Automatically cleans up unnecessary Internet clutter and temporary files&lt;br /&gt;� Helps optimize Windows performance by removing unneeded registry files&lt;br /&gt;&lt;br /&gt;One-click support - Provides one-click access to expert support right from your Norton product:&lt;br /&gt;� Fast access to expert support through email, live chat, or phone&lt;br /&gt;� Protection updates: Includes protection updates and new product features as available throughout the renewable service period&lt;br /&gt;� Ongoing protection: Keeps your computer protected from the latest Internet risks by automatically renewing your subscription at the regular subscription price (plus applicable tax), so you don't have to do it. For more information, click here.&lt;br /&gt;� Optional antispam and parental controls: Enables you to download antispam and parental controls via the Norton Add-on Pack&lt;br /&gt;� Free Technical Support: Free tech support delivers the help you need, however you need it&lt;br /&gt;&lt;br /&gt;Download review software from &lt;a href="http://rapidshare.com/files/222063699/3_6_0.3_keresteci.rar"&gt;Rapidshare&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-880436768320374601?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/880436768320374601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/880436768320374601'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/norton-360-v30-for-review.html' title='Norton 360 v3.0 for review'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1931147954803048617</id><published>2009-04-16T09:08:00.000-07:00</published><updated>2009-04-16T09:11:52.582-07:00</updated><title type='text'>Norton Antivirus Trial Reset 2.9A</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.soft-best.net/pic/b0/b0d336331ae52d66769bb655c37032c6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 344px; height: 196px;" src="http://www.soft-best.net/pic/b0/b0d336331ae52d66769bb655c37032c6.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dump trials the period in company Symantec products : Norton Internet Security 2009 (v16.5.0.134/5), Norton AntiVirus 2009 (v16.5.0.134), and Norton 360 v3 (v3.0.0.135/4).&lt;br /&gt;&lt;br /&gt;Downloads From &lt;a href="http://rapidshare.com/files/221940174/Norton2009.Trial.Reset.2.9A_SOFT-BEST.NET_.rar"&gt;rapidshare.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1931147954803048617?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1931147954803048617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1931147954803048617'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/norton-antivirus-trial-reset-29a.html' title='Norton Antivirus Trial Reset 2.9A'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3941372658204743749</id><published>2009-04-16T01:53:00.001-07:00</published><updated>2009-04-16T01:54:00.714-07:00</updated><title type='text'>SillyDl.CEK Trojan</title><content type='html'>SillyDl.CEK malware description and removal detail&lt;br /&gt;Categories:Trojan&lt;br /&gt;&lt;br /&gt;Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista&lt;br /&gt;&lt;br /&gt;Removing SillyDl.CEK:&lt;br /&gt;&lt;br /&gt;An up-to-date copy of ExterminateIt should detect and prevent infection from SillyDl.CEK.&lt;br /&gt;&lt;br /&gt;If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove SillyDl.CEK manually.&lt;br /&gt;&lt;br /&gt;To completely manually remove SillyDl.CEK malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with SillyDl.CEK.&lt;br /&gt;&lt;br /&gt;   1. Use Task Manager to terminate the SillyDl.CEK process.&lt;br /&gt;   2. Delete the original SillyDl.CEK file and folders.&lt;br /&gt;   3. Delete the system registry key parameters&lt;br /&gt;   4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.&lt;br /&gt;&lt;br /&gt;    We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3941372658204743749?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3941372658204743749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3941372658204743749'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/sillydlcek-trojan.html' title='SillyDl.CEK Trojan'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2526501639024062108</id><published>2009-04-16T01:49:00.001-07:00</published><updated>2009-04-16T01:49:56.491-07:00</updated><title type='text'>Bancos.GKY Trojan</title><content type='html'>Bancos.GKY malware description and removal detail&lt;br /&gt;Categories:Trojan&lt;br /&gt;&lt;br /&gt;Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista&lt;br /&gt;&lt;br /&gt;Removing Bancos.GKY:&lt;br /&gt;&lt;br /&gt;An up-to-date copy of ExterminateIt should detect and prevent infection from Bancos.GKY.&lt;br /&gt;&lt;br /&gt;If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Bancos.GKY manually.&lt;br /&gt;&lt;br /&gt;To completely manually remove Bancos.GKY malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Bancos.GKY.&lt;br /&gt;&lt;br /&gt;   1. Use Task Manager to terminate the Bancos.GKY process.&lt;br /&gt;   2. Delete the original Bancos.GKY file and folders.&lt;br /&gt;   3. Delete the system registry key parameters&lt;br /&gt;   4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.&lt;br /&gt;&lt;br /&gt;    We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2526501639024062108?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2526501639024062108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2526501639024062108'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/bancosgky-trojan.html' title='Bancos.GKY Trojan'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8936606579384010643</id><published>2009-04-16T01:48:00.000-07:00</published><updated>2009-04-16T01:49:20.790-07:00</updated><title type='text'>Reign Trojan</title><content type='html'>Reign malware description and removal detail&lt;br /&gt;Categories:Trojan,Spyware,Backdoor,Downloader,Hacker Tool&lt;br /&gt;Also known as:&lt;br /&gt;&lt;br /&gt;[Panda]Trojan Horse,Trj/Agent.AA,Trj/Iyus.B,Trj/Iyus.F,Trj/Iyus.C,Trj/Bizex.B,Bck/Xordoor.A;&lt;br /&gt;[Computer Associates]Win32.Reign.K,Win32/Reign.K!Trojan,Win32/Reign.K!HookDLL!Trojan,Win32.Reign.O,Win32/Reign.O!Trojan,Win32.Reign.N,Win32/Reign.N!Trojan,Win32.Reign.Z,Win32/Reign!DLL.102400!Trojan,Win32/Reign.Z!Worm,Win32.Reign.X,Win32/Reign.X!Trojan&lt;br /&gt;Visible Symptoms:&lt;br /&gt;Files in system folders:&lt;br /&gt;[%SYSTEM%]\iyus.dll&lt;br /&gt;[%SYSTEM%]\iyus\ampgbbje.exe&lt;br /&gt;[%SYSTEM%]\iyus\foimeobm.exe&lt;br /&gt;[%SYSTEM%]\iyus\hqejkanf.exe&lt;br /&gt;[%SYSTEM%]\unic2_32.dll&lt;br /&gt;[%SYSTEM%]\x3yy\dbkajomk.exe&lt;br /&gt;[%SYSTEM%]\xor\svchost.exe&lt;br /&gt;[%SYSTEM%]\iyus.dll&lt;br /&gt;[%SYSTEM%]\iyus\ampgbbje.exe&lt;br /&gt;[%SYSTEM%]\iyus\foimeobm.exe&lt;br /&gt;[%SYSTEM%]\iyus\hqejkanf.exe&lt;br /&gt;[%SYSTEM%]\unic2_32.dll&lt;br /&gt;[%SYSTEM%]\x3yy\dbkajomk.exe&lt;br /&gt;[%SYSTEM%]\xor\svchost.exe&lt;br /&gt;&lt;br /&gt;In order to ensure that the Reign is launched automatically each time the system is booted, the Reign adds a link to its executable file in the system registry:&lt;br /&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;[%SYSTEM%]\iyus\ampgbbje.exe&lt;br /&gt;[%SYSTEM%]\iyus\foimeobm.exe&lt;br /&gt;[%SYSTEM%]\iyus\hqejkanf.exe&lt;br /&gt;[%SYSTEM%]\x3yy\dbkajomk.exe&lt;br /&gt;[%SYSTEM%]\xor\svchost.exe&lt;br /&gt;&lt;br /&gt;Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista&lt;br /&gt;&lt;br /&gt;Detecting Reign:&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;[%SYSTEM%]\iyus.dll&lt;br /&gt;[%SYSTEM%]\iyus\ampgbbje.exe&lt;br /&gt;[%SYSTEM%]\iyus\foimeobm.exe&lt;br /&gt;[%SYSTEM%]\iyus\hqejkanf.exe&lt;br /&gt;[%SYSTEM%]\unic2_32.dll&lt;br /&gt;[%SYSTEM%]\x3yy\dbkajomk.exe&lt;br /&gt;[%SYSTEM%]\xor\svchost.exe&lt;br /&gt;[%SYSTEM%]\iyus.dll&lt;br /&gt;[%SYSTEM%]\iyus\ampgbbje.exe&lt;br /&gt;[%SYSTEM%]\iyus\foimeobm.exe&lt;br /&gt;[%SYSTEM%]\iyus\hqejkanf.exe&lt;br /&gt;[%SYSTEM%]\unic2_32.dll&lt;br /&gt;[%SYSTEM%]\x3yy\dbkajomk.exe&lt;br /&gt;[%SYSTEM%]\xor\svchost.exe&lt;br /&gt;&lt;br /&gt;Registry Values:&lt;br /&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br /&gt;&lt;br /&gt;Removing Reign:&lt;br /&gt;&lt;br /&gt;An up-to-date copy of ExterminateIt should detect and prevent infection from Reign.&lt;br /&gt;&lt;br /&gt;If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Reign manually.&lt;br /&gt;&lt;br /&gt;To completely manually remove Reign malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Reign.&lt;br /&gt;&lt;br /&gt;   1. Use Task Manager to terminate the Reign process.&lt;br /&gt;   2. Delete the original Reign file and folders.&lt;br /&gt;   3. Delete the system registry key parameters&lt;br /&gt;   4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.&lt;br /&gt;&lt;br /&gt;    We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8936606579384010643?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8936606579384010643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8936606579384010643'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/reign-trojan.html' title='Reign Trojan'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8734732701442298235</id><published>2009-04-16T01:45:00.000-07:00</published><updated>2009-04-16T01:47:14.739-07:00</updated><title type='text'>Detecting Windows.adtools</title><content type='html'>Detecting Windows.adtools:&lt;br /&gt;&lt;br /&gt;Folders:&lt;br /&gt;[%PROGRAM_FILES%]windows adtools&lt;br /&gt;&lt;br /&gt;Registry Keys:&lt;br /&gt;HKEY_LOCAL_MACHINEsoftwarewindows adtools&lt;br /&gt;HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallwindows adtools&lt;br /&gt;&lt;br /&gt;Registry Values:&lt;br /&gt;HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun&lt;br /&gt;HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionrun&lt;br /&gt;&lt;br /&gt;Removing Windows.adtools:&lt;br /&gt;&lt;br /&gt;An up-to-date copy of ExterminateIt should detect and prevent infection from Windows.adtools.&lt;br /&gt;&lt;br /&gt;If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Windows.adtools manually.&lt;br /&gt;&lt;br /&gt;To completely manually remove Windows.adtools malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Windows.adtools.&lt;br /&gt;&lt;br /&gt;   1. Use Task Manager to terminate the Windows.adtools process.&lt;br /&gt;   2. Delete the original Windows.adtools file and folders.&lt;br /&gt;   3. Delete the system registry key parameters&lt;br /&gt;   4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.&lt;br /&gt;&lt;br /&gt;    We recommends that all Internet users&lt;br /&gt;    back up any important information on their computers,&lt;br /&gt;    enable maximum protection from network attacks and malicious code on their computers,&lt;br /&gt;    refrain from executing suspicious programs received from untrustworthy sources. &lt;br /&gt;&lt;br /&gt;Source: howto-remove-virus.blogspot.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8734732701442298235?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8734732701442298235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8734732701442298235'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/detecting-windowsadtools.html' title='Detecting Windows.adtools'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8212446056496238870</id><published>2009-04-15T07:55:00.002-07:00</published><updated>2009-04-15T07:56:27.121-07:00</updated><title type='text'>Norton Internet Security 2008 (15.0.0.60) Final</title><content type='html'>Norton Internet Security 2008 (15.0.0.60) Final&lt;br /&gt;&lt;br /&gt;Norton Internet Security 2006 provides essential protection from viruses, hackers, and privacy threats. Included are full versions of Norton AntiVirus and Norton Personal Firewall, which efficiently defend your PC from the most common Internet dangers. You also get Norton AntiSpam to block unwanted email, Norton Parental Control to protect your children online and Norton Privacy Control to prevent confidential information to be sent out.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Key Technologies&lt;br /&gt;* Antispyware&lt;br /&gt;* Antivirus&lt;br /&gt;* Two-Way Firewall&lt;br /&gt;* Advanced Phishing Protection&lt;br /&gt;* Intrusion Prevention&lt;br /&gt;* Rootkit Detection&lt;br /&gt;&lt;br /&gt;Features&lt;br /&gt;* Improved performance delivers faster starts and scans. NEW&lt;br /&gt;* One click access to expert support. NEW&lt;br /&gt;* Network security monitoring helps protect your wireless network. NEW&lt;br /&gt;* Norton Identity Safe delivers enhanced i dentity theft protection. NEW&lt;br /&gt;* Works quietly in the background. NEW&lt;br /&gt;* Protection for up to 3 PCs per household&lt;br /&gt;* Blocks identity theft by phishing Web sites&lt;br /&gt;* Protects against hackers&lt;br /&gt;* Detects and eliminates spyware&lt;br /&gt;* Removes viruses and Internet worms automatically&lt;br /&gt;* Protects email and instant messaging from viruses&lt;br /&gt;* Prevents virus-infected emails from spreading&lt;br /&gt;* Rootkit detection searches underneath the operating system using patented technology&lt;br /&gt;* Includes protection updates and new product features as available throughout the renewable service period *&lt;br /&gt;* On-going Protection option automatically renews your subscription **&lt;br /&gt;* Need antispam or parental controls?&lt;br /&gt;&lt;br /&gt;Download&lt;br /&gt;http://rapidshare.com/files/52012322/NIS081500.exe&lt;br /&gt;http://www.megaupload.com/?d=N616NGRZ&lt;br /&gt;http://depositfiles.com/files/1620622&lt;br /&gt;http://www.filefactory.com/file/5aa7a5/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8212446056496238870?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8212446056496238870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8212446056496238870'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/norton-internet-security-2008-150060.html' title='Norton Internet Security 2008 (15.0.0.60) Final'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2672733387352169380</id><published>2009-04-15T07:55:00.001-07:00</published><updated>2009-04-15T07:55:19.086-07:00</updated><title type='text'>Norton Antivirus For Mac</title><content type='html'>Norton AntiVirus 11[MAC]&lt;br /&gt;&lt;br /&gt;Norton AntiVirus 11 for Mac® is the world's most trusted antivirus solution for Mac systems.* It removes viruses automatically, cleans infected Internet and email downloads, and protects against advanced online threats and attacks that target software vulnerabilities. It¿s also compatible with Mac OS® X v10.5 and takes full advantage of the new operating system's advanced features to help you protect your Mac even better. Powerful, built-in vulnerability protection helps prevent identity thieves from exploiting newly discovered application and operating system weaknesses. And the enhanced Norton AntiVirus dashboard widget lets you quickly check your system's virus protection status and get the latest information about current virus threats directly from the experts at Symantec Security Response.&lt;br /&gt;&lt;br /&gt;Norton AntiVirus for Mac now features silent, automatic virus definition updates; fully integrated schedule management settings; faster and more extensive file-scanning capabilities; improved Auto-Protect functionality; and a new user interface that makes routine tasks more accessible than ever before. And as always, LiveUpdate makes it easy to keep your virus and vulnerability protection updates current against new threats.&lt;br /&gt;&lt;br /&gt;The #1 selling antivirus solution for the Mac&lt;br /&gt;&lt;br /&gt;Features:&lt;br /&gt;* Automatically detects and removes viruses—Offers automatic protection against the latest threats with set-and-forget convenience&lt;br /&gt;* Scans and cleans downloaded files and email attachments—Delivers continuous, up-to-date protection via fast updates&lt;br /&gt;* Protects against attacks that target software vulnerabilities—Provides advanced protection against software and Internet vulnerabilities&lt;br /&gt;* Works with new Mac OS® X v10.5—Runs natively on Intel® and PowerPC® based Mac® systems&lt;br /&gt;* Includes an all-new Norton AntiVirus dashboard widget&lt;br /&gt;* Delivers industry-leading protection in the background, so you can work and play without any noticeable impact on performance&lt;br /&gt;&lt;br /&gt;download:&lt;br /&gt;http://rapidshare.com/files/86004106/NAV_V11_MAC.rar&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2672733387352169380?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2672733387352169380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2672733387352169380'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/norton-antivirus-for-mac.html' title='Norton Antivirus For Mac'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3380515844080385826</id><published>2009-04-15T07:54:00.001-07:00</published><updated>2009-04-15T07:54:50.112-07:00</updated><title type='text'>Norton Antivirus 2008</title><content type='html'>Norton AntiVirus 2008 (With crack+serial)&lt;br /&gt;&lt;br /&gt;Features&lt;br /&gt;&lt;br /&gt;* Improved performance delivers faster scans NEW&lt;br /&gt;* One click access to expert support NEW&lt;br /&gt;* Works quietly in the background. NEW&lt;br /&gt;* Network mapping provides a view of your home network. NEW&lt;br /&gt;* Detects and removes spyware and viruses&lt;br /&gt;* Blocks spyware and worms automatically&lt;br /&gt;* Antivirus protection for email and instant messaging&lt;br /&gt;* Prevents virus-infected emails from spreading&lt;br /&gt;* Rootkit detection finds and removes hidden threats&lt;br /&gt;* Includes protection updates and new product features as available throughout the renewable service period&lt;br /&gt;&lt;br /&gt;Download:&lt;br /&gt;http://rapidshare.com/files/128428740/NAV081550.exe&lt;br /&gt;crack:&lt;br /&gt;http://rapidshare.com/files/128445050/Norton2008_keygen.zip&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3380515844080385826?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3380515844080385826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3380515844080385826'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/norton-antivirus-2008.html' title='Norton Antivirus 2008'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4080978760786262988</id><published>2009-04-15T07:46:00.001-07:00</published><updated>2009-04-15T07:46:27.603-07:00</updated><title type='text'>Antivirus review 2009</title><content type='html'>Website for antivirus reviews 2009&lt;br /&gt;&lt;br /&gt;http://anti-virus-software-review.toptenreviews.com/&lt;br /&gt;http://pcworld.com http://pcmag.com&lt;br /&gt;For an unbiased test report of anti-virus detection capabilities,&lt;br /&gt;go here: http://av-comparatives.org/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4080978760786262988?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4080978760786262988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4080978760786262988'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/antivirus-review-2009.html' title='Antivirus review 2009'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2112258142395768022</id><published>2009-04-15T07:44:00.000-07:00</published><updated>2009-04-15T07:45:14.400-07:00</updated><title type='text'>The Best Free Antivirus</title><content type='html'>When taking into account only free antivirus, what is the best?&lt;br /&gt;-The best i've used so far is Google Pack. I've tried many types of antivirus, but Googles is the best by far. It also has spyware tools, Best of all, it never expires. http://safe-google.com/pack&lt;br /&gt;-AVG Free addition from GriSoft is the best that I have seen. You can also download limited trial versions of programs such as Trend-Micro. Hope this answered your question :)&lt;br /&gt;&lt;br /&gt;Source: http://1firstinfo-antivirus.blogspot.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2112258142395768022?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2112258142395768022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2112258142395768022'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/best-free-antivirus.html' title='The Best Free Antivirus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7408751322617138421</id><published>2009-04-15T07:41:00.000-07:00</published><updated>2009-04-15T07:44:31.182-07:00</updated><title type='text'>Which antivirus software is the best for Mac?</title><content type='html'>Which antivirus software is the best for Mac?&lt;br /&gt;The problem with anti-virus software is that it slows down your computer. There are 115,000 Windows viruses, there is one malware for MacosX which requires you to go to a porn site to get it. I get an occasional virus for Windows sent to me via email, I just trash it. Let the Windows users have their anti-virus software. If you still want one, then get the Intego version. The package includes Mac and Windows versions so you can protect the Windows side of your Mac if you are also running Windows on it.&lt;br /&gt;&lt;br /&gt;Source: http://1firstinfo-antivirus.blogspot.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7408751322617138421?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7408751322617138421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7408751322617138421'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/04/which-antivirus-software-is-best-for.html' title='Which antivirus software is the best for Mac?'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2430392061203472078</id><published>2009-03-24T17:01:00.000-07:00</published><updated>2009-03-24T17:03:50.059-07:00</updated><title type='text'>RUNLLD.EXE Cloaked Malware</title><content type='html'>Your PC is infected. The file called &lt;span style="font-weight:bold;"&gt;RUNLLD.EXE is&lt;/span&gt; considered unsafe and there may be other infections on your PC.&lt;br /&gt;&lt;br /&gt;You should urgently check your PC and remove any malicious software including RUNLLD.EXE as soon as possible. The free version of Prevx CSI will scan your PC for millions of spyware and malware infections in less than 2 minutes. Don't put your confidential data, or your identity at risk, check your PC now with Prevx CSI.&lt;br /&gt;&lt;br /&gt;Associated Malware Groups&lt;br /&gt;&lt;br /&gt;The filename is associated with the malware groups:&lt;br /&gt;&lt;br /&gt;    * Cloaked Malware&lt;br /&gt;    * Fraudulent Security Program&lt;br /&gt;&lt;br /&gt;File Behavior&lt;br /&gt;&lt;br /&gt;RUNLLD.EXE has been seen to perform the following behavior:&lt;br /&gt;&lt;br /&gt;    * Executes a Process&lt;br /&gt;    * Writes to another Process's Virtual Memory (Process Hijacking)&lt;br /&gt;&lt;br /&gt;RUNLLD.EXE has been the subject of the following behavior:&lt;br /&gt;&lt;br /&gt;    * Added as a Registry auto start to load Program on Boot up&lt;br /&gt;    * Executed as a Process&lt;br /&gt;    * Executed by Internet Explorer&lt;br /&gt;    * Deleted as a process from disk&lt;br /&gt;    * Created as a process on disk&lt;br /&gt;&lt;br /&gt;Country Of Origin&lt;br /&gt;&lt;br /&gt;The filename RUNLLD.EXE was first seen on Jan 5 2009 in the following geographical regions of the Prevx community:&lt;br /&gt;&lt;br /&gt;    * KUWAIT on Jan 5 2009&lt;br /&gt;    * The UNITED ARAB EMIRATES on Feb 1 2009&lt;br /&gt;    * INDONESIA on Mar 10 2009&lt;br /&gt;    * PAKISTAN on Mar 10 2009&lt;br /&gt;&lt;br /&gt;File Name Aliases&lt;br /&gt;&lt;br /&gt;RUNLLD.EXE can also use the following file names:&lt;br /&gt;&lt;br /&gt;    * HTI.EXE&lt;br /&gt;    * 84035352.EX_&lt;br /&gt;    * 67356852.SVD&lt;br /&gt;    * RUNDTL.EXE&lt;br /&gt;    * REG.EXE&lt;br /&gt;    * KHP.EXE&lt;br /&gt;    * ORH.EXE&lt;br /&gt;    * CRP.EXE&lt;br /&gt;    * TRO.EXE&lt;br /&gt;    * LNN.EXE&lt;br /&gt;    * LPM.EXE&lt;br /&gt;    * IJJ.EXE&lt;br /&gt;    * HQC.EXE&lt;br /&gt;    * SLO.EXE&lt;br /&gt;&lt;br /&gt;Filesizes&lt;br /&gt;&lt;br /&gt;The following file size has been seen:&lt;br /&gt;&lt;br /&gt;    * 91,648 bytes&lt;br /&gt;    * 136,192 bytes&lt;br /&gt;&lt;br /&gt;Vendor, Product and Version Information&lt;br /&gt;&lt;br /&gt;These files have no vendor, product or version information specified in the file header.&lt;br /&gt;File Type&lt;br /&gt;&lt;br /&gt;The filename RUNLLD.EXE refers to many versions of an executable program.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Rapid malware scanning and removal. Prevx CSI will thoroughly check your PC for malware infections in around 1 minute. It will also remove Adware infections for free! [&lt;a href="http://info.prevx.com/download.asp?grab=prevxcsirnd"&gt;Download Here&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Source: http://www.prevx.com/filenames/X2331159024562214914-X1/RUNLLD2EEXE.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2430392061203472078?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2430392061203472078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2430392061203472078'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/runlldexe-cloaked-malware.html' title='RUNLLD.EXE Cloaked Malware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8300607550077561281</id><published>2009-03-24T01:21:00.000-07:00</published><updated>2009-03-24T01:32:31.500-07:00</updated><title type='text'>Norton AntiVirus for Windows 2000/XP/Vista Updates Virus Definition</title><content type='html'>1. &lt;a href="http://definitions.symantec.com/defs/20090323-050-v5i32.exe"&gt;20090323-050-v5i32.exe&lt;/a&gt; &lt;br /&gt;Supports the following versions of Symantec antivirus software:&lt;br /&gt;&lt;br /&gt;    * Norton Antivirus 2009 for Windows XP Home/XP Pro/Vista&lt;br /&gt;    * Norton Internet Security 2009 for Windows XP/Home/XP Pro/Vista&lt;br /&gt;    * Norton Antivirus 2008 for Windows XP Home/XP Pro/Vista&lt;br /&gt;    * Norton Internet Security 2008 for Windows XP/Home/XP Pro/Vista&lt;br /&gt;    * Norton 360 version 3.0 for Windows XP/Vista&lt;br /&gt;    * Norton 360 version 2.0 for Windows XP/Vista&lt;br /&gt;    * Symantec Endpoint Protection 11.0&lt;br /&gt;&lt;br /&gt;2. &lt;a href="http://definitions.symantec.com/defs/20090323-003-i32.exe"&gt;20090323-003-i32.exe&lt;/a&gt;&lt;br /&gt;Supports the following versions of Symantec antivirus software:&lt;br /&gt;&lt;br /&gt;    * Norton AntiVirus 2003 Professional Edition&lt;br /&gt;    * Norton AntiVirus 2003 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2004 Professional Edition&lt;br /&gt;    * Norton AntiVirus 2004 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2005 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2006 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2007 for Windows XP Home/XP Pro/Vista&lt;br /&gt;    * Norton 360 version 1.0 for Windows XP/Vista&lt;br /&gt;    * Norton AntiVirus for Microsoft Exchange (Intel)&lt;br /&gt;    * Norton SystemWorks (all versions)&lt;br /&gt;    * Symantec AntiVirus 3.0 for CacheFlow Security Gateway&lt;br /&gt;    * Symantec AntiVirus 3.0 for Inktomi Traffic Edge&lt;br /&gt;    * Symantec AntiVirus 3.0 for NetApp Filer/NetCache&lt;br /&gt;    * Symantec AntiVirus 9.0 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.0 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.1 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.2 Corporate Edition Client&lt;br /&gt;    * Symantec Mail Security for Domino v 5.x&lt;br /&gt;    * Symantec Mail Security for Microsoft Exchange v 5.x&lt;br /&gt;&lt;br /&gt;3. &lt;a href="http://definitions.symantec.com/defs/20090323-003-x86.exe"&gt;20090323-003-x86.exe&lt;/a&gt;&lt;br /&gt;Supports the following versions of Symantec antivirus software:&lt;br /&gt;&lt;br /&gt;    * Norton AntiVirus 2003 Professional Edition&lt;br /&gt;    * Norton AntiVirus 2003 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2004 Professional Edition&lt;br /&gt;    * Norton AntiVirus 2004 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2005 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2006 for Windows 2000/XP Home/XP Pro&lt;br /&gt;    * Norton AntiVirus 2007 for Windows XP Home/XP Pro/Vista&lt;br /&gt;    * Norton 360 version 1.0 for Windows XP/Vista&lt;br /&gt;    * Norton AntiVirus for Microsoft Exchange (Intel)&lt;br /&gt;    * Symantec AntiVirus 3.0 CacheFlow Security Gateway&lt;br /&gt;    * Symantec AntiVirus 3.0 for Inktomi Traffic Edge&lt;br /&gt;    * Symantec AntiVirus 3.0 for NetApp Filer/NetCache&lt;br /&gt;    * Symantec AntiVirus 9.0 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.0 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.1 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus 10.2 Corporate Edition Client&lt;br /&gt;    * Symantec AntiVirus for Bluecoat Security Gateway for Windows 2000 Server/2003 Server&lt;br /&gt;    * Symantec AntiVirus for Clearswift MIMESweeper for Windows 2000 Server/2003 Server&lt;br /&gt;    * Symantec AntiVirus for Microsoft ISA Server for Windows 2000 Server/2003 Server&lt;br /&gt;    * Symantec Mail Security for Domino v 5.x&lt;br /&gt;    * Symantec Mail Security for Microsoft Exchange v 5.x&lt;br /&gt;    * Symantec Mail Security for SMTP v 5.x&lt;br /&gt;    * Symantec Web Security 3.0 for Windows&lt;br /&gt;    * Symantec AntiVirus Scan Engine for Windows&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=n95&lt;br /&gt;   &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8300607550077561281?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8300607550077561281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8300607550077561281'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/norton-antivirus-for-windows.html' title='Norton AntiVirus for Windows 2000/XP/Vista Updates Virus Definition'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1146173417052769352</id><published>2009-03-24T01:19:00.000-07:00</published><updated>2009-03-24T01:20:51.929-07:00</updated><title type='text'>Download Updates Avast</title><content type='html'>A feature of most of our programs is their ability to update themselves automatically. If you are connected to the Internet, virus database updates are downloaded and installed automatically without any user action. The availability of a new version is checked when an Internet connection is established, and every four hours afterwards. Update files can also be downloaded from these pages if required e.g. if your computer does not have an Internet connection. Updates are usually released on a daily basis.&lt;br /&gt;&lt;br /&gt;The latest iAVS update was published on: 23.3.2009 version: 090323-0&lt;br /&gt;&lt;br /&gt;Note: No reinstallation of the program is needed for virus database updates! &lt;br /&gt;&lt;br /&gt;Virus Database Update [&lt;a href="http://files.avast.com/iavs4pro/vpsupd.exe"&gt;Download Here&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.avast.com/eng/updates.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1146173417052769352?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1146173417052769352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1146173417052769352'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/download-updates-avast.html' title='Download Updates Avast'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4055195405197659692</id><published>2009-03-24T00:48:00.000-07:00</published><updated>2009-03-24T01:03:08.623-07:00</updated><title type='text'>Download update AVG</title><content type='html'>It is strongly recommended that you perform all updates from the AVG Free interface. The program can distinguish between full and differential updates; while this page offers only full update files for download.&lt;br /&gt;&lt;br /&gt;1. Windows: 8.0.237 [&lt;a href="http://free.avg.com/softw/80free/update/f8all237ns.bin"&gt;Downloa&lt;/a&gt;d]&lt;br /&gt;2. Link Scanner DB: 8.0.103 [&lt;a href="http://free.avg.com/softw/80free/update/x8all103lu.bin"&gt;Download&lt;/a&gt;]&lt;br /&gt;3. AVI: 270.11.25 [&lt;a href="http://free.avg.com/softw/80free/update/u7avi1460ia.bin"&gt;Download&lt;/a&gt;]&lt;br /&gt;4. IAVI: / 2019 [&lt;a href="http://free.avg.com/softw/80free/update/u7iavi2019ia.bin"&gt;Download&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://free.avg.com/download-update&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4055195405197659692?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4055195405197659692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4055195405197659692'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/download-update-avg.html' title='Download update AVG'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8419247169260514604</id><published>2009-03-05T06:37:00.000-08:00</published><updated>2009-03-05T06:38:23.205-08:00</updated><title type='text'>Worm:Coutsonif.A</title><content type='html'>barat Joeniar Arief yang mengatakan bahwa pengguna internet sangat “Rapuh” terhadap serangan virus. Maka kini pengguna Messenger khususnya Yahoo Messenger dan Skype yang mendapatkan giliran menghadapi kiriman virus yang memalsukan dirinya seakan-akan sebagai pesan otentik yang dikirimkan oleh kontak dalam YM / Skype anda. Tetapi jangan sekali-kali anda mengklik link yang diberikan, sekalipun dikirimkan oleh teman anda di YM / Skype yang terpercaya karena sebenarnya pesan tersebut bukan dikirimkan oleh teman anda, melainkan oleh Penghianat Cinta ....... alias virus yang berhasil menginfeksi komputer teman anda.  Selain mampu menyebar melalui YM dan Skype, virus ini juga menyebar melalui Flash Disk menggunakan fasilitas Autorun dan memiliki kemampuan mengupdate dirinya. Menurut pantauan terbaru Vaksincom tanggal 10 Februari 2009, link tersebut mulai di update oleh pembuat virus dan nama filenya diganti menjadi “Your_Dad_Has_Shit_Fetish_Too.PIF” &lt;br /&gt;&lt;br /&gt;Read manual removal: http://vaksin.com/2009/0209/coutsonif/Coutsonif.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8419247169260514604?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8419247169260514604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8419247169260514604'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/wormcoutsonifa.html' title='Worm:Coutsonif.A'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7957676288366968060</id><published>2009-03-05T06:34:00.000-08:00</published><updated>2009-03-05T06:36:40.190-08:00</updated><title type='text'>Worm:PIF/Starter.A  Virus Shortcut</title><content type='html'>Di tengah gencarnya virus-virus Confiker melanda dunia persilatan jaringan, maka ada sebuah virus lokal yang tidak mau kalah untuk unjuk gigi. Virus ini penulis dapatkan secara tidak sengaja, ketika sedang beranjang sana di sebuah tempat kerja sahabat dekat, dia mengeluh kok banyak banget sih shortcut di komputernya.&lt;br /&gt;&lt;br /&gt;Setelah diamati memang benar banyak sekali file-file shortcut yang bertebaran di setiap folder yang ada di dalam komputernya, seperti Microsoft.lnk, dan juga file shortcut dengan nama seperti nama folder yang dimiliki. Akhirnya dengan naluri vaksinis yang tidak bisa mendengar ada virus baru yang tidak terdeteksi oleh antivirus, maka dengan segera keluhan tersebut langsung dianalisa lebih lanjut dan dibuatkan cara mengatasinya.&lt;br /&gt;&lt;br /&gt;Ciri-ciri dari virus tersebut adalah :&lt;br /&gt;&lt;br /&gt;   1.&lt;br /&gt;&lt;br /&gt;      Di folder My Documents terdapat sebuah file yang bernama database.mdb, dan ternyata ini adalah file induknya.&lt;br /&gt;   2.&lt;br /&gt;&lt;br /&gt;      File Autorun.inf, Thumb.db, Microsoft.lnk di setiap driver, folder dan flash disk sampai pada SUB Folder yang ke-2.&lt;br /&gt;   3.&lt;br /&gt;&lt;br /&gt;      Membuat File Duplikat setiap folder dengan extensi .lnk, maksimal 5 nama folder pertama, misalnya kalau di C:\Windows ada banyak maka hanya akan diambil 5 nama pertama saja. Dan berlaku sampai sub folder yang ke-2&lt;br /&gt;&lt;br /&gt;   4.&lt;br /&gt;&lt;br /&gt;      Mematikan fungsi dari file Registry (lihat gambar 3)&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]&lt;br /&gt;&lt;br /&gt;"DisableRegistrytools"=dword:00000001&lt;br /&gt;   5.&lt;br /&gt;&lt;br /&gt;      Menambahkan value di registry :&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]&lt;br /&gt;&lt;br /&gt;"Explorer"="Wscript.exe //e:VBScript \"C:\Documents and Settings\Administrator\My Documents\database.mdb\""&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]&lt;br /&gt;&lt;br /&gt;"WinUpdate"="Wscript.exe /e:VBScript \"C:\WINDOWS\:Microsoft Office  &lt;br /&gt;&lt;br /&gt;Update for Windows XP.sys\""&lt;br /&gt;&lt;br /&gt;Untuk script yang terakhir mungkin sekali ini hanya script untuk mengecoh saja, tetapi&lt;br /&gt;&lt;br /&gt;dalam prakteknya kita harus mendeletenya. Jika pada saat kita LogOn komputer, maka&lt;br /&gt;&lt;br /&gt;akan didapat message error &lt;br /&gt;&lt;br /&gt;Yang membuat kita menjadi geram adalah banyak sekali shortcut yang dibuat oleh virus tersebut. Dan hebatnya virus tersebut kalau cara penanganannya tidak tepat maka akan kembali lagi dan lagi. Oleh sebab itu ada beberapa cara yang harus dilakukan untuk memberantas virus yang menyebalkan ini :&lt;br /&gt;&lt;br /&gt;   1.&lt;br /&gt;&lt;br /&gt;      Matikan proses dari file WSCRIPT yang terletak di C:\Windows\System32, dengan cara menggunakan tools seperti CProcess, HijackThis atau dapat juga menggunakan Task Manager dari windows.&lt;br /&gt;&lt;br /&gt;   2.&lt;br /&gt;&lt;br /&gt;      Sebelumnya matikan dulu proses SYSTEM RESTORE.&lt;br /&gt;&lt;br /&gt;   3.&lt;br /&gt;&lt;br /&gt;      Setelah dimatikan proses dari Wscript tersebut, kita harus mendetele atau merename dari pada file tersebut agar tidak digunakan (untuk sementara) lagi oleh virus tersebut. Sebagai catatan, kalau kita merename dari file Wscript.exe tersebut dengan automatis akan dikopikan lagi di folder tersebut, oleh sebab itu kita harus mencari di mana file Wscript.exe yang lainnya biasanya ada di C:\Windows\$NtServicePackUninstall$, C:\Windows\ServicePackFiles\i386. Tidak seperti virus-virus VBS lainnya, kita bisa mengganti Open With dari file VBS menjadi Notepad, virus ini berextensi MDB yang berarti adalah file Microsoft Access. Jadi Wscript akan menjalankan file DATABASE.MDB seolah-olah dia adalah file VBS. (Virus pintar kan)&lt;br /&gt;&lt;br /&gt;Wscript.exe //e:VBScript \"C:\Documents and Settings\Administrator\My Documents\database.mdb\""&lt;br /&gt;&lt;br /&gt;   4.&lt;br /&gt;&lt;br /&gt;      Delete file induknya yang ada di C:\Documents and Settings\&lt;user&gt;\My Documents\database.mdb, agar setiap kali komputer dijalankan tidak akan meload file tersebut. Dan jangan lupa kita buka juga MSCONFIG, disable perintah yang menjalankannya.&lt;br /&gt;&lt;br /&gt;   5.&lt;br /&gt;&lt;br /&gt;      Sekarang kita akan mendelete file-file Autorun.INF. Microsoft.INF dan Thumb.db. dengan cara, klik tombol START, ketik CMD, pindah ke drive yang akan dibersihkan, misalnya drive C:\, maka yang harus kita lakukan adalah&lt;br /&gt;&lt;br /&gt;Ketik C:\del Microsoft.inf /s   = perintah ini akan mendelete semua file microsoft.inf di seluruh folder di drive C: , kalau mau pindah drive tinggal diganti nama drivenya saja contoh : D:\del Microsoft.inf /s&lt;br /&gt;&lt;br /&gt;Untuk file autorun.inf, ketik C:\del autorun.inf /s /ah /f  = perintah akan mendelete file autorun.inf  (syntax /ah /f digunakan karena file tersebut memakai attrib RSHA, begitu juga untuk file Thumb.db lakukan juga hal yang sama&lt;br /&gt;&lt;br /&gt;   6.&lt;br /&gt;&lt;br /&gt;      Untuk mendelete file-file selain 4 file terdahulu, kita harus mencarinya dengan cara Search file dengan ekstensi .lnk ukurannya 1 KB, Pada “More advanced options”, pastikan option “Search system folders” dan “Search hidden files and folders” keduanya telah dicentang.&lt;br /&gt;&lt;br /&gt;Harap berhati-hati, tidak semua file shortcut / file LNK yang berukuran 1 KB adalah virus, kita dapat membedakannya dari iconnya, size dan Type. Untuk shortcut yang diciptakan virus iconnya selalu menggunakan icon "folder", ukuran 1 KB dengan Type "Shortcut". Sedangkan folder yang benar harusnya tidak memiliki "size" dan Typenya adalah "File Folder". Contoh di bawah, gambar bagian kiri folder dengan nama "Music", "Video", "Programs", "Documents" dan "Compressed" sebenarnya adalah shortcut yang memalsukan diri sebagai icon folder yang diciptakan oleh virus dan harus dihapus karena memiliki size 1 KB dan Type "Shortcut". Sedangkan Folder dengan nama "Compressed", "Documents", "Music", "Programs", "Video" dan "Virus" yang tidak memiliki Size dan Type "File Folder" adalah folder asli yang namanya dicatut oleh virus. Sedangkan gambar kanan, shortcut yang asli dari program memiliki icon khusus sesuai icon programnya.&lt;br /&gt;&lt;br /&gt;   7.&lt;br /&gt;&lt;br /&gt;      Fix registry yang sudah di ubah oleh virus. Untuk mempercepat proses perbaikan registry salin script dibawah ini pada program “notepad” kemudian simpan dengan nama "Repair.inf". Jalankan file tersebut dengan cara:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;- Klik kanan repair.inf&lt;br /&gt;&lt;br /&gt;- Klik Install&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;[Version]&lt;br /&gt;&lt;br /&gt;Signature="$Chicago$"&lt;br /&gt;&lt;br /&gt;Provider=Vaksincom Oyee&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;[DefaultInstall]&lt;br /&gt;&lt;br /&gt;AddReg=UnhookRegKey&lt;br /&gt;&lt;br /&gt;DelReg=del&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;[UnhookRegKey]&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""&lt;br /&gt;&lt;br /&gt;HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"&lt;br /&gt;&lt;br /&gt;HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;br /&gt;&lt;br /&gt;HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;[del]&lt;br /&gt;&lt;br /&gt;HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate&lt;br /&gt;&lt;br /&gt;HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7957676288366968060?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7957676288366968060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7957676288366968060'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/wormpifstartera-virus-shortcut.html' title='Worm:PIF/Starter.A  Virus Shortcut'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4291375121957084031</id><published>2009-03-05T06:32:00.000-08:00</published><updated>2009-03-05T06:34:21.739-08:00</updated><title type='text'>W32/Sality.AE</title><content type='html'>Kalau Conficker dapat dikatakan sebagai worm nomor satu di Indonesia, maka predikat virus yang paling merepotkan dan paling banyak ditemui Vaksincom di Indonesia pantas di sandang oleh Sality. Virus yang disinyalir berasal dari Taiwan / Cina ini secara meyakinkan menempati ranking pertama dalam infeksi virus yang diterima oleh Vaksincom bersama-sama dengan Conficker.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Memang menyebalkan jika semua program kita ikut dimakan oleh virus [di infeksi], disamping sulit dalam memberantas virusnya terkadang juga file yang sudah di injeksi tersebut tidak dapat digunakan alias rusak setelah di scan dan dibersihkan oleh antivirus, alhasil harus reinstall semua program yang error atau download ulang file yang sudah di injenksi tersebut.&lt;br /&gt;&lt;br /&gt;Ukuran file yang sudah terinfeksi W32/Sality.AE akan bertambah besar beberapa KB dan file yang sudah terinfeksi W32/Sality.AE ini masih dapat di jalankan seperti biasa. Biasanya virus ini akan mencoba untuk blok program antivirus atau removal tools saat dijalankan serta mencoba untuk blok task manager atau “registry editor” Windows. Untuk mempermudah dalam proses penyebarannya selain memanfaatkan “File Sharing” dan “Default Share” virus ini juga akan memanfaatkan media Flash Disk dengan cara membuat file acak yang mempunyai ekstensi exe/com/scr/pif serta menambahkan file autorun.inf yang memungkinkan virus dapat aktif secara otomatis setiap kali user mengakses Flash Disk.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Untuk blok task manager atau Registry tools, W32/Sality.AE ini akan membuat string pada registry berikut:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      DisableRegistryTools&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      DisableTaskMgr&lt;br /&gt;&lt;br /&gt;Pada saat file yang terinfeksi W32/Sality.AE, ia akan mendekrip dirinya dan mencoba untuk kopi beberapa file *.dll (acak) file DLL kemudian akan menginjeksi file lain yang aktif di memori serta file lain yang terdapat di komputer dan jaringan (file sharing) serta menginfeksi file *.exe yang terdapat dalam list registry berikut sehingga memungkinkan virus dapat aktif secara otomatis setiap kali komputer dinyalakan.&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache&lt;br /&gt;&lt;br /&gt;Berikut beberapa contoh file *.dll yang akan di drop oleh W32/Sality.AE.&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      C:\Windows\system32\syslib32.dll&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      C:\Windows\system32\oledsp32.dll&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      C:\Windows\system32\olemdb32.dll&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      C:\Windows\system32\wcimgr32.dll&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      C:\Windows\system32\wmimgr32.dll&lt;br /&gt;&lt;br /&gt;Selain membuat file DLL, sality juga akan membuat file *.sys [acak] di direktori “C:\Windows\system32\drivers” [contoh: kmionn.sys]&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Blok Antivirus dan software security&lt;br /&gt;&lt;br /&gt;Seperti yang sudah dijelaskan di atas bahwa untuk mempermudah proses penyebaran ia juga akan mencoba untuk mematikan proses yang berhubungan dengan program security khususnya antivirus dengan cara mematikan proses yang mempunyai nama dibawah ini:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;ALG&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;InoRPC&lt;br /&gt;&lt;br /&gt;aswUpdSv&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;InoRT&lt;br /&gt;&lt;br /&gt;avast! Antivirus&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;InoTask&lt;br /&gt;&lt;br /&gt;avast! Mail Scanner&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;ISSVC&lt;br /&gt;&lt;br /&gt;avast! Web Scanner&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;KPF4&lt;br /&gt;&lt;br /&gt;AVP&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;LavasoftFirewall&lt;br /&gt;&lt;br /&gt;BackWeb Plug-in - 4476822&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;LIVESRV&lt;br /&gt;&lt;br /&gt;bdss&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;McAfeeFramework&lt;br /&gt;&lt;br /&gt;BGLiveSvc&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;McShield&lt;br /&gt;&lt;br /&gt;BlackICE&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;McTaskManager&lt;br /&gt;&lt;br /&gt;CAISafe&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;navapsvc&lt;br /&gt;&lt;br /&gt;ccEvtMgr&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;NOD32krn&lt;br /&gt;&lt;br /&gt;ccProxy&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;NPFMntor&lt;br /&gt;&lt;br /&gt;ccSetMgr&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;NSCService&lt;br /&gt;&lt;br /&gt;F-Prot Antivirus Update Monitor&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Outpost Firewall main module&lt;br /&gt;&lt;br /&gt;fsbwsys&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;OutpostFirewall&lt;br /&gt;&lt;br /&gt;FSDFWD&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;PAVFIRES&lt;br /&gt;&lt;br /&gt;F-Secure Gatekeeper Handler Starter&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;PAVFNSVR&lt;br /&gt;&lt;br /&gt;fshttps&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;PavProt&lt;br /&gt;&lt;br /&gt;FSMA&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;PavPrSrv&lt;br /&gt;&lt;br /&gt;PAVSRV&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Symantec Core LC&lt;br /&gt;&lt;br /&gt;PcCtlCom&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Tmntsrv&lt;br /&gt;&lt;br /&gt;PersonalFirewal&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;TmPfw&lt;br /&gt;&lt;br /&gt;PREVSRV&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;tmproxy&lt;br /&gt;&lt;br /&gt;ProtoPort Firewall service&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;UmxAgent&lt;br /&gt;&lt;br /&gt;PSIMSVC&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;UmxCfg&lt;br /&gt;&lt;br /&gt;RapApp&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;UmxLU&lt;br /&gt;&lt;br /&gt;SmcService&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;UmxPol&lt;br /&gt;&lt;br /&gt;SNDSrvc&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;vsmon&lt;br /&gt;&lt;br /&gt;SPBBCSvc&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;VSSERV&lt;br /&gt;&lt;br /&gt;WebrootDesktopFirewallDataService&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;WebrootFirewall&lt;br /&gt;&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;XCOMM&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Selain mematikan proses antivirus di atas, ia juga akan berupaya untuk blok agar user tidak dapat mengakses web dari beberapa antivirus berikut:&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Cureit&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Drweb&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Onlinescan&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Spywareinfo&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Ewido&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Virusscan&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Windowsecurity&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Spywareguide&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Bitdefender&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Panda software&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Agnmitum&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Virustotal&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Sophos&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Trend Micro&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Etrust.com&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Symantec&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      McAfee&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      F-Secure&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Eset.com&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Kaspersky&lt;br /&gt;&lt;br /&gt;W32/Sality.AE juga akan mencoba untuk merubah regisrty berikut:&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xxx [xxx adalah acak, contoh : abp470n5]&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_CURRENT_USER\Software\[USER NAME]914&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER&lt;br /&gt;&lt;br /&gt;Selain itu ia juga akan mencoba untuk merubah beberapa string registry Windows Firewall berikut dengan menambahkan value dari 0 menjadi 1:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      AntiVirusDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      AntiVirusOverride&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      FirewallDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      FirewallOverride&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      UacDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      UpdatesDisableNotify&lt;br /&gt;&lt;br /&gt;dan membuat key “SVC” serta string berikut dengan value 1&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      AntiVirusDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      AntiVirusOverride&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      FirewallDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      FirewallOverride&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      UacDisableNotify&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      UpdatesDisableNotify&lt;br /&gt;&lt;br /&gt;Tak cuma itu W32/s\Sality.AE juga akan menghapus key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG”.&lt;br /&gt;&lt;br /&gt;ALG atau Application Layer Gateway Service adalah services yang memberikan support untuk plug-in protokol aplikasi dan meng-enable konektivitas jaringan / protokol. Service ini boleh saja dimatikan. Dampaknya adalah program seperti MSN Messenger dan Windows Messenger tidak akan berfungsi. Service ini bisa dijalankan, tetapi hanya jika menggunakan firewall, baik firewall bawaan Windows atau firewall lain. Jika tidak komputer yang terinfeksi virus ini akan mengalami celah keamanan yang serius.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Blok akses “safe mode”&lt;br /&gt;&lt;br /&gt;Dalam rangka “mempertahankan” dirinya, W32/Sality.AE juga akan mencoba untuk blok akses ke mode “safe mode” sehingga user tidak dapat booting pada mode “safe mode” dengan menghapus key yang berada di lokasi di bawah ini :&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br /&gt;&lt;br /&gt;Injeksi file exe/com/scr&lt;br /&gt;&lt;br /&gt;Tujuan utama dari virus ini adalah mencoba untuk menginjeksi program instalasi dan file yang mempunyai ekstensi exe/com/scr yang ada di drive C - Y terutama file hasil instalasi (file yang berada di direktori C:\Program Files) dan file-file portable (file yang langsung dapat dijalankan tanpa perlu instal), ia juga akan menginfeksi file yang mempunyai ekstensi “.exe” yang terdapat dalam list registry berikut sehingga memungkinkan virus dapat aktif secara otomatis setiap kali komputer dinyalakan.&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache&lt;br /&gt;&lt;br /&gt;File yang berhasil di injeksi biasanya ukurannya akan bertambah sekitar 68 - 80 KB dari ukuran semula. Program yang telah terinfeksi ini akan tetap dapat di jalankan seperti biasa sehingga user tidak curiga bahwa file tersebut sebenarnya telah di infeksi oleh W32/Sality.AE. Salah satu kecanggihan Sality adalah kemampuannya menginjeksi file tumpangannya sehingga ukuran file bervirus tidak seragam, jelas lebih sulit diidentifikasi dibandingkan virus lain yang menggantikan file yang ada sehingga ukuran filenya akan sama besar.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Harap berhati-hati, tidak semua program antivirus dapat membersihkan file yang sudah terinfeksi W32/Sality.AE, bisa-bisa file tersebut akan rusak setelah di scan dan di bersihkan oleh antivirus tersebut.&lt;br /&gt;&lt;br /&gt;Tidak mau kalah dengan virus mancanegara lain, untuk memperlancar aksinya ia akan mencoba untuk melakukan koneksi ke sejumlah alamat web yang sudah ditentukan dengan tujuan untuk memanggil/mendownload trojan/virus lainnya yang di sinyalir merupakan varian dari versi sebelumnya yang memungkinkan virus ini dapat mengupdate dirinya.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;[http://]pedmeo222nb.info&lt;br /&gt;&lt;br /&gt;[http://]pzrk.ru&lt;br /&gt;&lt;br /&gt;[http://]technican.w.interia.pl&lt;br /&gt;&lt;br /&gt;[http://]www.kjwre9fqwieluoi.info&lt;br /&gt;&lt;br /&gt;[http://]bpowqbvcfds677.info&lt;br /&gt;&lt;br /&gt;[http://]bmakemegood24.com&lt;br /&gt;&lt;br /&gt;[http://]bperfectchoice1.com&lt;br /&gt;&lt;br /&gt;[http://]bcash-ddt.net&lt;br /&gt;&lt;br /&gt;[http://]bddr-cash.net&lt;br /&gt;&lt;br /&gt;[http://]btrn-cash.net&lt;br /&gt;&lt;br /&gt;[http://]bmoney-frn.net&lt;br /&gt;&lt;br /&gt;[http://]bclr-cash.net&lt;br /&gt;&lt;br /&gt;[http://]bxxxl-cash.net&lt;br /&gt;&lt;br /&gt;[http://]balsfhkewo7i487fksd.info&lt;br /&gt;&lt;br /&gt;[http://]buynvf96.info&lt;br /&gt;&lt;br /&gt;[http://]89.119.67.154/tes[xxx]&lt;br /&gt;&lt;br /&gt;[http://]oceaninfo.co.kr/picas[xxx]&lt;br /&gt;&lt;br /&gt;[http://]kukutrustnet777.info/home[xxx]&lt;br /&gt;&lt;br /&gt;[http://]kukutrustnet888.info/home[xxx]&lt;br /&gt;&lt;br /&gt;[http://]kukutrustnet987.info/home[xxx]&lt;br /&gt;&lt;br /&gt;[http://]kukutrustnet777.info&lt;br /&gt;&lt;br /&gt;[http://]www.kjwre9fqwieluoi.info&lt;br /&gt;&lt;br /&gt;[http://]kjwre77638dfqwieuoi.info&lt;br /&gt;&lt;br /&gt;http://mattfoll.eu.interia.pl/[sensor]&lt;br /&gt;&lt;br /&gt;http://st1.dist.su.lt/l[sensor]&lt;br /&gt;&lt;br /&gt;http://lpbmx.ru/[sensor]&lt;br /&gt;&lt;br /&gt;http://bjerm.mass.hc.ru/[sensor]&lt;br /&gt;&lt;br /&gt;http://SOSiTE_AVERI_SOSiTEEE.[sensor]&lt;br /&gt;&lt;br /&gt;Mengeksploitasi Default Share dan Full Sharing&lt;br /&gt;&lt;br /&gt;W32/Sality.AE akan menyebar dengan cepat melalui jaringan dengan memanfaatkkan default share windows atau share folder yang mempunyai akses full dengan cara menginfeksi file yang mempunyai ekstensi exe/com/scr. Karena itu, Vaksincom menyarankan pengguna komputer untuk menonaktifkan Default Share (C$, D$ .. dst) dan hindari Full Sharing folder anda di jaringan.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Selain menyebar dengan menggunakan jaringan, ia juga akan memanfaatkan flash disk yakni dengan cara kopi dirinya dengan nama file acak dengan ekstensi exe/cmd/pif serta membuat file autorun.inf agar dirinya dapat aktif secara otomatis tanpa harus menjalankan file yang sudah terinfeksi virus, selain itu ia juga akan menginfeksi file yang mempunyai ekstensi exe/com/scr yang terdapat dalam flash disk tersebut.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Selain itu Sality.AE juga akan menambahkan string [MCIDRV_VER] dan DEVICEMB=xxx, dimana xxx menunjukan karakter acak ke dalam file C:\Windows\system.ini.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to remove: http://vaksin.com/2009/0309/Sality/sality.html&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4291375121957084031?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4291375121957084031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4291375121957084031'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/w32salityae.html' title='W32/Sality.AE'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1443539954199739628</id><published>2009-03-05T06:31:00.001-08:00</published><updated>2009-03-05T06:31:58.676-08:00</updated><title type='text'>W32/Xirtem@MM!8b1f20b9</title><content type='html'>Description&lt;br /&gt;W32/Xirtem@MM!8b1f20b9 is a mass mailing worm&lt;br /&gt;Indication of Infection&lt;br /&gt;# Network activity on TCP port 25 due to e-mails being sent by the worm.&lt;br /&gt;# Presence of the files and registry entries mentioned above.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1443539954199739628?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1443539954199739628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1443539954199739628'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/w32xirtemmm8b1f20b9.html' title='W32/Xirtem@MM!8b1f20b9'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5374301261035170518</id><published>2009-03-05T06:29:00.000-08:00</published><updated>2009-03-05T06:30:54.222-08:00</updated><title type='text'>FakeAlert-BX</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Description&lt;/span&gt;&lt;br /&gt;This is a Trojan detection that displays fake alert messages on user's machine.&lt;br /&gt;Indication of Infection&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms are as follows:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Fake pop up  messages about the system being infected.&lt;br /&gt;    * Presence of aforementioned files and folder.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Methods of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Distribution channel include IRC,peer to peer networks,newsgroup postings, etc.&lt;br /&gt;Aliases&lt;br /&gt;AntiVirus2008 (Symantec), TR/Crypt.XPACK.Gen (Avira), Trojan-Banker.Win32.Banbra.gpl (Kaspersky)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5374301261035170518?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5374301261035170518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5374301261035170518'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/03/fakealert-bx.html' title='FakeAlert-BX'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8379716451275085929</id><published>2009-02-05T22:55:00.000-08:00</published><updated>2009-02-05T23:02:19.206-08:00</updated><title type='text'>Spyware Doctor Review Antispyware</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Best Spyware Protection. Used by Millions World Wide.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Spyware Doctor has been downloaded over 125 million times with millions more downloads every week. People worldwide use and trust Spyware Doctor to protect their PCs from spyware, adware and other online threats.&lt;br /&gt;&lt;br /&gt;Spyware Doctor has consistently been awarded Editors' Choice, by leading PC magazines and testing laboratories around the world, including United States, United Kingdom, Sweden, Germany and Australia. In addition, after leading the market in 2005, Spyware Doctor was awarded the prestigious Best of the Year at the end of 2005 and again in 2006.&lt;br /&gt;&lt;br /&gt;Spyware Doctor continues to be awarded the highest honors by many of the world's leading PC publications such as PC World, PC Magazine, PC Pro, PC Plus, PC Authority, PC Utilities, PC Advisor, PC Choice, Microdatorn, Computer Bild and PC Answers Magazine.&lt;br /&gt;&lt;br /&gt;Note: If you are choosing Anti-Spyware make sure you choose one that is proven and has genuine awards from one or more world leading research labs such a PC Magazine, PC World, CNET, PC Pro Magazine, PC Authority, PC Answers and other trusted labs. More importantly do not use ratings from unknown review websites, as often these are designed to mislead you into purchase of affiliated, inferior or rogue product.&lt;br /&gt;Screenshot&lt;br /&gt;[+] Click to Enlarge&lt;br /&gt;Detects, removes and blocks all types of Spyware.&lt;br /&gt;&lt;br /&gt;Did you know that numerous programs tested against Spyware Doctor detected only small fraction of Spyware and completely removed an even smaller amount? Also most of them were unable to effectively block Spyware in real time from being installed on users PC in the first place.&lt;br /&gt;&lt;br /&gt;Spyware Doctor has the most advanced update feature that continually improves its Spyware fighting capabilities on daily basis. As Spyware gets more complex to avoid detection by AntiSpyware programs Spyware Doctor responds with new technology to stay one step ahead.&lt;br /&gt;Easiest to Use&lt;br /&gt;&lt;br /&gt;Spyware Doctor is advanced technology designed especially for people, not just experts. That is one reason why it won the People's Choice Award in 2005, 2006 and 2007. It is automatically configured out of the box to give you optimal protection with limited interaction so all you need to do is install it for immediate and ongoing protection.&lt;br /&gt;&lt;br /&gt;Spyware Doctor's advanced IntelliGuard technology only alerts users on a true Spyware detection. This is significant because you should not be interrupted by cryptic questions every time you install software, add a site to your favorites or change your PC settings. Such messages can be confusing and lead to undesirable outcomes such as inoperable programs, lost favorites or even Spyware being allowed to install on the system. We've done the research so you don't have to.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pctools.com/mirror/sdsetup.exe"&gt;Software download here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8379716451275085929?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8379716451275085929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8379716451275085929'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/spyware-doctor-review-antispyware.html' title='Spyware Doctor Review Antispyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4725787852346343432</id><published>2009-02-04T21:10:00.000-08:00</published><updated>2009-02-04T21:12:53.288-08:00</updated><title type='text'>Remove Antivirus 2009. Description and removal instructions</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Antivirus 2009&lt;/span&gt; is a new rogue anti-spyware program. It is also a clone of Antivirus 2008 - also a rogue, and one that's produced more clones than any other recently. The list of these clones is long: System Antivirus 2008, Ultimate Antivirus 2008, Vista Antivirus 2008, XP Antivirus 2008 etc.&lt;br /&gt;&lt;br /&gt;Like any other of it's predecessors, Antivirus2009 uses trojans, such as Zlob or Vundo, to spread. These trojans lurk in porn/warez websites disguised as video codecs, and, upon entering the system, floods the user with popups and fake system notifications, supposedly to inform him of an infection. While the system at hand may indeed be infected, Antivirus 2009 will inform the user of this regardless of whether it's true or not. The point of this disinformation is to convince the user he is infected and therefore needs an antispyware program to dispose of the threat. The user might click on one of the popups or notifications, all of which claim they will take him to a legitimate security tool, but try to make him purchase Antivirus2009's "licensed version" instead. Antivirus2009 may redirect web browser to antivirus-premium-scan.com, webscannertools.com, googlescanners-360.com, livesecurityinfo.com, antivirusonlivescan.com, bestantivirusscan.com, antivirus-best.com, internetquarantinesite.com, premiumlivescan.com and secureclick1.com websites that sell the malware. Some of these website are not only fraudulent, but they are also malicious. they are capable of installing additional malwares.&lt;br /&gt;&lt;br /&gt;Antivirus 2009 is a scam and should be treated as such: do NOT download or buy it and block it's websites using your HOSTS file.&lt;br /&gt;&lt;br /&gt;Manual Removal:&lt;br /&gt;&lt;br /&gt;Antivirus 2009 manual removal:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Kill processes:&lt;/span&gt;&lt;br /&gt;av2009.exe av2009[1].exe AV2009Install.exe Antivirus2009.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HELP:&lt;br /&gt;how to kill malicious processes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Delete registry values:&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”&lt;br /&gt;HKEY_CURRENT_USER\Software\Antivirus&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HELP:&lt;br /&gt;how to remove registry entries&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Unregister DLLs:&lt;/span&gt;&lt;br /&gt;shlwapi.dll wininet.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HELP:&lt;br /&gt;how to unregister malicious DLLs&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete files:&lt;/span&gt;&lt;br /&gt;av2009.exe av2009install.exe av2009install_0011.exe av2009[1].exe Antivirus2009.exe ieupdates.exe scui.cpl %program_files%\\antivirus 2009\\av2009.exe %startmenu%\\antivirus 2009\\antivirus 2009.lnk %startmenu%\\antivirus 2009\\uninstall antivirus 2009.lnk winsrc.dll %desktopdirectory%\\antivirus 2009.lnk winsrc.dll ieupdates.exe av2009install_0011.exe av2009install.exe %program_files%\\antivirus 2009\\av2009.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HELP:&lt;br /&gt;how to remove harmful files&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete directories:&lt;/span&gt;&lt;br /&gt;C:\Program Files\Antivirus 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.2-spyware.com/remove-antivirus-2009.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4725787852346343432?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4725787852346343432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4725787852346343432'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/remove-antivirus-2009-description-and.html' title='Remove Antivirus 2009. Description and removal instructions'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1527895525876638252</id><published>2009-02-04T21:03:00.000-08:00</published><updated>2009-02-04T21:08:53.147-08:00</updated><title type='text'>How to remove Antivirus XP 2008 (Uninstall Instructions)</title><content type='html'>&lt;span style="font-weight:bold;"&gt;What this programs does:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Antivirus XP 2008 is a new rogue anti-spyware program that is advertised through Trojans and other malware. It is advertised in the form of fake security alerts and warnings on web sites that state you are infected with malware or are being attacked in some manner. When you click on these ads, it will automatically download the installer for Antivirus XP 2008 and install it on your machine. In some cases, this program is installed without any intervention at all from you.&lt;br /&gt;&lt;br /&gt;Once installed, AntivirusXP 2008 will scan your computer and display a variety of security risks found on your computer that can only be removed if you purchase a license of the software. These risks, though, are all fake and are only being displayed to scare you into thinking you are infected and thus purchase their software. Another tactic that AntivirusXP 2008, and the accompanied malware, uses is to change your desktop background to be a message stating you are infected, popups and fake alerts stating your computer is being attacked, and a fake Internet Explorer page that states Google has found your computer to be infected. All of these are further scare tactics and should be ignored. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Automated Removal Instructions for Antivirus XP 2008 using Malwarebytes' Anti-Malware:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe"&gt;Download Software Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;   1. Print out these instructions as we will need to close every window that is open later in the fix.&lt;br /&gt;&lt;br /&gt;   2. Download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:&lt;br /&gt;&lt;br /&gt;   3. Once downloaded, close all programs and Windows on your computer, including this one.&lt;br /&gt;&lt;br /&gt;   4. Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.&lt;br /&gt;&lt;br /&gt;   5. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;More Info: http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: &lt;br /&gt;http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1527895525876638252?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1527895525876638252'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1527895525876638252'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/how-to-remove-antivirus-xp-2008.html' title='How to remove Antivirus XP 2008 (Uninstall Instructions)'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2946025451352427513</id><published>2009-02-03T20:28:00.000-08:00</published><updated>2009-02-03T20:36:11.071-08:00</updated><title type='text'>PC Tools Powerful FREE protection against malicious virus infections</title><content type='html'>With PC Tools AntiVirus Free Edition you are protected against the most nefarious cyber-threats attempting to gain access to your PC and personal information. Going online without protection against the latest fast-spreading virus and worms, such as Netsky, Mytob and MyDoom, can result in infections within minutes.&lt;br /&gt;&lt;br /&gt;Once infected, the virus will usually attempt to spread itself to your friends, family and associates by accessing your email contacts and networked PCs. The infection may also allow hackers to access files on your PC, use it to launch attacks against other computers and websites or to send mass SPAM email.&lt;br /&gt;&lt;br /&gt;That's why PC Tools AntiVirus Free Edition provides world-leading protection, with rapid database updates, IntelliGuard™ real-time protection and comprehensive system scanning to ensure your system remains safe and virus free. PC Tools products are trusted and used by millions of people everyday to protect their home and business computers against online threats.&lt;br /&gt;&lt;br /&gt;Download software &lt;a href="http://www.pctools.com/mirror/avinstall.exe"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.pctools.com/free-antivirus/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2946025451352427513?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2946025451352427513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2946025451352427513'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/pc-tools-powerful-free-protection.html' title='PC Tools Powerful FREE protection against malicious virus infections'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7337858043528077669</id><published>2009-02-03T20:25:00.000-08:00</published><updated>2009-02-03T20:27:24.510-08:00</updated><title type='text'>Avira AntiVir Personal - FREE Antivirus</title><content type='html'>Basic protection&lt;br /&gt;Protects your computer against dangerous viruses, worms, Trojans and costly dialers.&lt;br /&gt;&lt;br /&gt;Download software &lt;a href="http://dw.com.com/redir?edId=3&amp;siteId=4&amp;oId=3000-2239_4-10322935&amp;ontId=2239_4&amp;spi=2a7cf01c6fe18d1842052795f2fc6677&amp;lop=link&amp;tag=tdw_dltext&amp;ltype=dl_dlnow&amp;pid=10986298&amp;mfgId=6290072&amp;merId=6290072&amp;pguid=MFM0rQoPjFwAAE0A95gAAADa&amp;destUrl=http%3A%2F%2Fwww.download.com%2F3001-2239_4-10322935.html%3Fspi%3D2a7cf01c6fe18d1842052795f2fc6677%26part%3Ddl-10322935"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7337858043528077669?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7337858043528077669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7337858043528077669'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/avira-antivir-personal-free-antivirus.html' title='Avira AntiVir Personal - FREE Antivirus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3971412429692576680</id><published>2009-02-03T20:23:00.000-08:00</published><updated>2009-02-03T20:24:23.176-08:00</updated><title type='text'>Download FREE antivirus software - avast! Home Edition</title><content type='html'>avast! antivirus Home Edition is available free of charge for non-commercial home use ONLY. If you are not a home user or if you use your computer for business purposes, please download the avast! Professional Edition.&lt;br /&gt;Free registration&lt;br /&gt;&lt;br /&gt;avast! antivirus Home Edition is FREE to use but it is necessary to register before the end of the initial 60 day trial period. Following the registration you will receive by e-mail a license key valid for a period of 1 year. After you have downloaded and installed the program, the license key must be inserted into it within 60 days. The registration process is very easy, and it will take you only a couple of minutes.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Download software&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Download software &lt;a href="http://files.avast.com/iavs4pro/setupeng.exe"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.avast.com/eng/download-avast-home.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3971412429692576680?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3971412429692576680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3971412429692576680'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/download-free-antivirus-software-avast.html' title='Download FREE antivirus software - avast! Home Edition'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2017651059932058776</id><published>2009-02-03T20:21:00.000-08:00</published><updated>2009-02-03T20:22:16.267-08:00</updated><title type='text'>Download AVG Anti-Virus Free Edition</title><content type='html'>Basic antivirus and antispyware protection for Windows available to download for free. Limited features, no support, for private and non-commercial use only.&lt;br /&gt;AVG Anti-Virus Free Edition&lt;br /&gt;&lt;br /&gt;    * The most downloaded software on CNET's Download.com&lt;br /&gt;    * Quality proven by 80 million users&lt;br /&gt;    * Easy to download, install and use&lt;br /&gt;    * Protection against viruses and spyware&lt;br /&gt;    * Compatible with Windows Vista and Windows XP&lt;br /&gt;&lt;br /&gt;Feature:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Anti-Virus &amp; Anti-Spyware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The foundation of your protection. Without antivirus and antispyware protection, your computer and data are at extreme risk.&lt;br /&gt;AVG Free contains basic antivirus protection (base level only).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Anti-Rootkit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Rootkits are hidden threats that deliver malicious content. They are usually not found on PCs using standard antivirus programs.&lt;br /&gt;&lt;br /&gt;AVG Free does not contain Anti-Rootkit protection so rootkits may be hidden in your system.&lt;br /&gt;For this protection, please download AVG Internet Security&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Anti-Spam&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;SPAM e-mails are a constant annoyance and could potentially contain malicious links or attempts to steal your identity.&lt;br /&gt;&lt;br /&gt;AVG Free does not contain Anti-Spam which can monitor and block SPAM and fraudulent e-mails.&lt;br /&gt;For this protection, please download AVG Internet Security&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Firewall&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Hackers and other intruders can view or steal your data, download malware to your machine or track your habits and passwords.&lt;br /&gt;&lt;br /&gt;AVG Free does not contain a firewall which can protect you against these threats.&lt;br /&gt;For this protection, please download AVG Internet Security&lt;br /&gt;Safe Downloads &amp; Instant Messaging&lt;br /&gt;&lt;br /&gt;The essential protection for Internet use. File downloads, chatting with your friends and family - today these are everyday things. Protecting yourself in these areas is now another important part of your security and privacy protection.&lt;br /&gt;&lt;br /&gt;AVG Free does not contain the new Safe Downloads &amp; Instant Messaging protection (Web Shield technology) so it does not screen your downloads and communication for viruses and spyware.&lt;br /&gt;For this protection, please download AVG Internet Security&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Safe Search &amp; Surf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The essential protection for Internet use. New web threats (called exploits or drive-by downloads) can infect your computer just by visiting a web page! Our new technology ensures the safety of search results, web pages, favorites &amp; bookmarks before you open them.&lt;br /&gt;&lt;br /&gt;AVG Free only includes the Safe Search protection which provides you with advice on search results. It does not protect against infected pages. Only AVG paid versions contain the Safe Surf technology.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2017651059932058776?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2017651059932058776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2017651059932058776'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/download-avg-anti-virus-free-edition.html' title='Download AVG Anti-Virus Free Edition'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3488563521343476107</id><published>2009-02-03T03:26:00.000-08:00</published><updated>2009-02-03T03:27:22.704-08:00</updated><title type='text'>Hacktivist tool targets Hamas</title><content type='html'>&lt;span style="font-weight:bold;"&gt;DDoS street protest covers both side of Gaza conflict&lt;/span&gt;&lt;br /&gt;Israeli cyberactivists are inviting pro-Israeli surfers to install a tool that attacks websites associated with Hamas.&lt;br /&gt;&lt;br /&gt;This "Patriot" tool effectively turns the computers of sympathisers of the Israeli cause into zombies - albeit willing, complicit ones - in the control of Israeli hackers.&lt;br /&gt;&lt;br /&gt;The hackers are working under the banner of the Help Israel Win collective, which was formed last month at the start of the conflict in Gaza. "We couldn't join the real combat, so we decided to fight Hamas in the cyber arena," one of the group's organisers, 'Liri', told Wired.&lt;br /&gt;&lt;br /&gt;The package developed by the group is designed to overload websites associated with Hamas, such as qudsnews.net and palestine-info.info, with spurious traffic. Israeli hackers claim that 8,000 have downloaded and installed the Patriot software.&lt;br /&gt;&lt;br /&gt;Conflict in cyberspace is one aspect of a propaganda offensive that has accompanied the war in Gaza, and the decades-long Israeli-Palestinian conflict. Help Israel Win is vague about how its Patriot software works, preferring instead to stress its opposition to Hamas, which has the stated aim of destroying the state of Israel.&lt;br /&gt;&lt;br /&gt;The Patriot package, according to Help Israel Win, "unites the computer capabilities of many people around the world. Our goal is to use this power in order to disrupt our enemy's efforts to destroy the state of Israel. The more support we get, the more efficient we are."&lt;br /&gt;&lt;br /&gt;SANS Institute security researchers warn that the Patriot tool leaves the door open to abuse. "While at the moment it does not appear to do anything bad (it just connects to the IRC server and sites there - there also appeared to be around 1,000 machines running this when I tested this) the owner can probably do whatever he wants with machines running this," SANS researcher Bojan Zdrnja writes.&lt;br /&gt;&lt;br /&gt;A Help Israel Win representative conceded to Wired that "the Patriot code could be used as a Trojan. However, it is not used as such, and will never be."&lt;br /&gt;&lt;br /&gt;"The update option is used to fix bugs in the client, and not to upload any malicious code. The project will close right after the war is over, and we have given a fully functional uninstaller to [remove] the application," a representative added.&lt;br /&gt;&lt;br /&gt;It's not particularly clear how effective the Patriot tool has been in silencing allegedly pro-Hamas websites, but Help Israel Win has been forced to repeatedly shift its website location in response to attacks for hackers sympathetic to the Palestinian cause, Wired adds.&lt;br /&gt;&lt;br /&gt;Security tools firm Arbor Networks reported earlier this week of an increase in botnet attacks on Israeli targets as well as confirming that Help Israel Win was offering what it described as a "simple Windows tool" to target Palestinian websites.&lt;br /&gt;&lt;br /&gt;"This is an example of DDoS attacks being used as a form of street protest and something that is becoming increasingly common," said Arbor researcher Jose Nazario.&lt;br /&gt;&lt;br /&gt;Other experts confirm that hackers from the wider Muslim world are piling in on behalf of the Palestinians. "Our observations suggest that a large number of Web sites have been defaced by a variety of hacker groups from Iran, Lebanon, Morocco and Turkey, and the trend is accelerating," said Bruce Jenkins, a retired Major with the US Air Force and consultant with application security firm Fortify Security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.theregister.co.uk/2009/01/09/gaza_conflict_patriot_cyberwars/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3488563521343476107?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3488563521343476107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3488563521343476107'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/hacktivist-tool-targets-hamas.html' title='Hacktivist tool targets Hamas'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3856888282611699942</id><published>2009-02-03T03:25:00.000-08:00</published><updated>2009-02-03T03:26:10.273-08:00</updated><title type='text'>Warns of data-snooping bug in Apple's Safari</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Apple's Safari web browser&lt;/span&gt; for both the Mac and Windows suffers from a serious vulnerability that can expose emails, passwords and other sensitive contents of a user's hard drive, a researcher has warned.&lt;br /&gt;&lt;br /&gt;Those using Mac OS X 10.5, aka Leopard, are susceptible to the data-snooping bug even if they use Firefox or another alternate browser, according to open source software developer Brian Mastenbrook. Apple has yet to plug the gaping hole, so the only way users can currently protect themselves is to change RSS reader settings in Safari's preferences panel.&lt;br /&gt;&lt;br /&gt;Windows users are also vulnerable, but only if they are using Safari. For the time being, it's probably a good idea for Windows users with Safari installed to leave it closed and use a different browser.&lt;br /&gt;&lt;br /&gt;"The details of this vulnerability have not been made public to the best of my knowledge, but secrecy is no guarantee against a sufficiently motivated attacker," said Mastenbrook, who last year was credited by Apple with finding four vulnerabilities in the Mac operating system. His blog post outlining the bug is light on many details, but it does say the bug "could be exploited by a phishing site in a way that would not cause affected users to suspect their information had been stolen."&lt;br /&gt;&lt;br /&gt;Leopard users can protect themselves by opening Safari and selecting Preferences from the Safari menu, choosing the RSS tab, clicking on the Default Reader pop-up window and selecting an application other than Safari.&lt;br /&gt;&lt;br /&gt;Users of Tiger, aka Mac OS X 10.4, and earlier versions of Mac OS X are not vulnerable.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.theregister.co.uk/2009/01/13/safari_data_snooping_bug/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3856888282611699942?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3856888282611699942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3856888282611699942'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/warns-of-data-snooping-bug-in-apples.html' title='Warns of data-snooping bug in Apple&apos;s Safari'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6130210561191630325</id><published>2009-02-03T03:23:00.000-08:00</published><updated>2009-02-03T03:24:48.702-08:00</updated><title type='text'>Wwebsite violated by Trojan-spreaders (Paris Hilton)</title><content type='html'>Virus authors reportedly planted malicious code on Paris Hilton's website late last week.&lt;br /&gt;&lt;br /&gt;Following the attack, surfers visiting the ParisHilton.com site were prompted to install an "update" via a dialogue box. Whether they accepted this update or decided to "cancel" it, a download of a malicious executable was initiated, according to internet reports.&lt;br /&gt;&lt;br /&gt;The attack was reportedly used to serve up the &lt;span style="font-weight:bold;"&gt;Trojan-Spy.Zbot.YETH Trojan, a rootkit trojan&lt;/span&gt; designed to steal online banking information and to allow the download of other malicious code.&lt;br /&gt;&lt;br /&gt;The assault was detected by web security firm ScanSafe on 9 January but cleansed by Tuesday morning, according to net security firm Sophos, hours after news of the assault broke.&lt;br /&gt;&lt;br /&gt;The type of attack thrown against ParisHilton.com is similar to a recent attack on MLB.com, the Major League Baseball website, and the self-explanatory sexy-celeb-photos.com. Each of these assaults was much more in your face than traditional drive-by download attacks, but they also stemmed from the same underlying cause - website vulnerabilities left open to abuse by hackers.&lt;br /&gt;&lt;br /&gt;Over the years the hapless Hilton has become a serial victim of various computer hacking and security attacks. Four years ago the notable heiress and airhead was unfortunate enough to suffer from a hack against her T-Mobile account which resulted in the leak of messages, contact details and photos.&lt;br /&gt;&lt;br /&gt;Last March another hacker gained access to private pictures after breaking into her Facebook account. And just days ago, messages from a faked LinkedIn profile ostensibly maintained by Ms Hilton pointed to malicious downloads.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.theregister.co.uk/2009/01/13/paris_hilton_site_hacked/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6130210561191630325?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6130210561191630325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6130210561191630325'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/wwebsite-violated-by-trojan-spreaders.html' title='Wwebsite violated by Trojan-spreaders (Paris Hilton)'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-826043410104754334</id><published>2009-02-03T03:18:00.000-08:00</published><updated>2009-02-03T03:19:44.494-08:00</updated><title type='text'>Kaspersky Anti-Virus Update February 03, 2009</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Kaspersky Anti-Virus Update description&lt;/span&gt;&lt;br /&gt;  &lt;br /&gt;Sets of threat signatures and databases of network attacks&lt;br /&gt;&lt;br /&gt;This is a special update application to install the latest virus databases and various fixes to AntiViral Toolkit Pro for Windows 95/98/NT version 3.0.129 and above.&lt;br /&gt;&lt;br /&gt;Use this if you already have AntiViral Toolkit Pro installed.&lt;br /&gt;&lt;br /&gt;The antivirus databases currently contain 1717652 records.&lt;br /&gt;&lt;br /&gt;If your Kaspersky installed application does not contain the protection module against network attacks, feel free to use mirrors 2, 4 and 6 to download 'light' versions of the update signatures.&lt;br /&gt;&lt;br /&gt;It is essential to update antivirus databases on a regular basis. If you do not do this, your antivirus program will not detect new malicious programs. This is why we release updates every hour, to ensure that users are protected against the latest malware.&lt;br /&gt;&lt;br /&gt;Antivirus solutions from Kaspersky Lab not only detect malicious software, but other programs which are potentially harmful, such as:&lt;br /&gt;&lt;br /&gt;- Adware&lt;br /&gt;- Remote administration programs&lt;br /&gt;- Utilities which can be used by malicious programs or users&lt;br /&gt;&lt;br /&gt;Zip-archives should be unpacked into a separate directory, which should then be indicated in the automatic update module as a local folder.&lt;br /&gt;&lt;br /&gt;Daily - contains all updates and modifications released during the current week. The current week starts from the previous Friday, when the last weekly update was released. It is placed on the update server every hour. You should download daily.zip if you update your antivirus databases at least once a week.&lt;br /&gt;&lt;br /&gt;Previous week's updates - contains all updates and modifications released during the previous week (a full version of the week's daily.zip). It is placed on the server once a week, on Friday. When this file is placed on the server, it will cause the size of daily.zip to be equal to zero. You should download this file if you update your antivirus databases less than once a week, but more often than once every two weeks.&lt;br /&gt;&lt;br /&gt;Complete update - contains all the updates and modifications released at the time of the previous week's update. This is placed on the sever at the same time as the new weekly.zip. You should download this file if you have not updated your antivirus databases in the last two weeks.&lt;br /&gt;&lt;br /&gt;NOTE: After the archives have been downloaded, unpack them to a separate folder on a disc. If you have downloaded several archives, unpack them in the following order: first unpack av-i386-cumul.zip, then - av-i386-weekly.zip and the last - av-i386-daily.zip. Unpacking, click Yes when you are suggested to replace files with the same name.&lt;br /&gt;&lt;br /&gt;After the archives have been unpacked, launch automatic update of the anti-virus database. As an update source define folder with the unpacked archives in the anti-virus database update task.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: &lt;br /&gt;http://www.softpedia.com/get/Others/Signatures-Updates/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-826043410104754334?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/826043410104754334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/826043410104754334'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/02/kaspersky-anti-virus-update-february-03.html' title='Kaspersky Anti-Virus Update February 03, 2009'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2401456281677588680</id><published>2009-01-29T21:33:00.000-08:00</published><updated>2009-01-29T21:34:33.285-08:00</updated><title type='text'>Spam Levels Likely To Rise As Srizbi Botnet Comes Back To Life</title><content type='html'>When McColo, an ISP known for being a haven for spammers and scammers was knocked offline two weeks ago, the notorious Srizbi Botnet went down with it. This resulted in global spam volume plummeting by as much as 75%. Sadly, that’s about to change. FireEye, a threat research firm, has discovered that Srizbi is rising from the dead.&lt;br /&gt;&lt;br /&gt;Researchers at the firm have discovered that Srizbi has begun updating all of its bots via its new command servers located in Estonia. New domains linked to the botnet have been found as well, with registrations located in Russia.&lt;br /&gt;&lt;br /&gt;Here’s an excerpt from FireEye’s report:&lt;br /&gt;&lt;br /&gt;              &lt;blockquote&gt;As has been publicized, Srizbi had a mechanism to dynamically generate the C&amp;C to which it would communicate based on a seed (magic number) in the binary, and a variation of the Julian date of the infected host. Our next post will go into the technical details of this algorithm. This dynamic DNS generation mechanism was the main reason why they were able to regain control, even though the primary IP, hosted at McColo, was and is still not routable. As soon as we stopped registering domain names, the Botnet owner swooped in and began registering domains, as he was able to predict which would be in use today.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;As of now, the spam being sent by the revived Botnet is only targeting Russian addresses, but expect Srizbi to begin reaching out to the rest of the world in short order.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.allspammedup.com/2008/11/spam-levels-likely-to-rise-as-srizbi-botnet-comes-back-to-life/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2401456281677588680?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2401456281677588680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2401456281677588680'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/spam-levels-likely-to-rise-as-srizbi.html' title='Spam Levels Likely To Rise As Srizbi Botnet Comes Back To Life'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5058567754455884759</id><published>2009-01-29T21:31:00.000-08:00</published><updated>2009-01-29T21:32:29.701-08:00</updated><title type='text'>New Malicious Spam Attack Claims Obama Resigned</title><content type='html'>Barack Obama and his inauguration are by far the hottest topics in the country right now, so it’s not surprising that a new malicious spam attack is exploiting him. A new wave of spam is underway with headlines proclaiming Obama has changed his mind and turned down the presidency. The messages contain links to a sight that looks very much like the official Obama/Biden campaign site but which is actually a fake that delivers malware. Visitors to the malicious site will find a mix of fake and real news stories, one of which proclaims that Obama released a statement saying he no longer wants to be president. Clicking on the “more” link triggers a malicious download, a Trojan Horse that will turn the recipient’s computer into a zombie and add it to the new Waledec botnet. Waledec sprang up just before Christmas and spread via fake greeting cards. Right now it’s the 9th largest botnet with an estimated 10,000 computers under its control.&lt;br /&gt;&lt;br /&gt;This new attack will likely cause that number to sharply rise as users, alarmed by the headline, will click through without thinking. Experts say Waledec is most likely controlled by the same person responsible for the massive Storm botnet which wreaked havoc last year.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.allspammedup.com/2009/01/new-malicious-spam-attack-claims-obama-resigned/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5058567754455884759?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5058567754455884759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5058567754455884759'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/new-malicious-spam-attack-claims-obama.html' title='New Malicious Spam Attack Claims Obama Resigned'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8869808529468497379</id><published>2009-01-29T21:29:00.000-08:00</published><updated>2009-01-29T21:30:21.861-08:00</updated><title type='text'>New Valentine’s Day Spam Attack Underway</title><content type='html'>Not surprisingly, spammers have begun a new attack exploiting the upcoming Valentine’s Day holiday.  New spam messages with subject lines such as “Falling in love with you”, “I belong to you”, and “I love being in love with you” have begun hitting inboxes. Security experts say the attack started on January 22nd. The body of the messages contain romantic sounding one liners like “Me and You”, “In Your Arms”, and “With all my love”, and a link. The link directs the recipent to a web page displaying 12 heart images and inviting them to click on one. Doing so downloads a malicious program called “love.exe” or “you.exe” which turns the infected computer into a zombie and adds it to the Waledec botnet, which is believed to be run by the same folks responsible for the Storm botnet. So far the botnet is sending an average of 11,000 messages per hour.&lt;br /&gt;&lt;br /&gt;This is the same group responsible for the Obama spam sent earlier this month. That spam attempted to lure people to a fake Obama/Biden site with a link to a fake news story claiming Obama had abruptly declined to accept the presidency of the United States. This new botnet is growing so quickly it’s being called the new Storm botnet. It appears that the group behind it isn’t in a hurry to learn any new tricks because the old ones are still working just fine.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.allspammedup.com/2009/01/new-valentines-day-spam-attack-underway/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8869808529468497379?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8869808529468497379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8869808529468497379'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/new-valentines-day-spam-attack-underway.html' title='New Valentine’s Day Spam Attack Underway'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7287538639763422322</id><published>2009-01-29T21:27:00.001-08:00</published><updated>2009-01-29T21:27:42.965-08:00</updated><title type='text'>Virus Profile: W32/Checkout!91d0b88a</title><content type='html'>Risk Assessment    &lt;br /&gt;  - Home Users:  Low-Profiled&lt;br /&gt;  - Corporate Users:  Low-Profiled&lt;br /&gt;Date Discovered:  8/11/2007&lt;br /&gt;Date Added:  8/11/2007&lt;br /&gt;Origin:  N/A&lt;br /&gt;Length:  41,984 bytes&lt;br /&gt;Type:  Virus&lt;br /&gt;SubType:  Internet Worm&lt;br /&gt;DAT Required:  5096&lt;br /&gt;Virus Characteristics&lt;br /&gt;&lt;br /&gt; -- Update August 12, 2007 --&lt;br /&gt;The risk assessment of this threat has been updated to Low-Profiled due to media attention at:&lt;br /&gt;http://www.darkreading.com/document.asp?doc_id=131362&lt;br /&gt;&lt;br /&gt;This variant of W32/Checkout may be detected as W32/Generic.Delphi.a in earlier versions of the DAT.&lt;br /&gt;&lt;br /&gt;This worm spreads via MSN Messenger . When installed, it sends the following message(s) to contact list recipients and send a zip file named img1756.zip (~42 KB).&lt;br /&gt;&lt;br /&gt;    * look @ my cute new puppy :-D&lt;br /&gt;    * look @ this picture of me, when I was a kid&lt;br /&gt;    * I just took this picture with my webcam, like it?&lt;br /&gt;    * check it, i shaved my head&lt;br /&gt;    * have u seen my new hair?&lt;br /&gt;    * what the fuck, did you see this?&lt;br /&gt;    * hey man, did you take this picture?&lt;br /&gt;&lt;br /&gt;Upon execution, it creates a copy of itself into the Windows folder and also drop a zip file:&lt;br /&gt;&lt;br /&gt;    * %WINDIR%\img1756.zip (W32/Checkout zipped)&lt;br /&gt;    * %WINDIR%\svchost.exe (W32/Checkout)&lt;br /&gt;&lt;br /&gt;(Where %WINDIR% is the Windows folder; e.g. C:\Windows)&lt;br /&gt;&lt;br /&gt;It also drops a a.bat file to stop the following services. The .bat file is deleted after execution.&lt;br /&gt;&lt;br /&gt;    * Security Center&lt;br /&gt;    * winvnc4&lt;br /&gt;&lt;br /&gt;Adds the following values to the registry:&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Microsoft Genuine Logon" = "svchost.exe"&lt;br /&gt;&lt;br /&gt;The worm connects to an IRC channel on {blocked}.basecase.info.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Indications of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Presence of the files/registry keys mentioned&lt;br /&gt;    * Unexpected network connection to the associated site(s).&lt;br /&gt;    * MSN contacts receiving one of the messages with zip attachment.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection&lt;/span&gt;&lt;br /&gt;This worm spreads by sending MSN Messenger contacts a message containing a malicious zip file (W32/Checkout) .&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal Instructions&lt;/span&gt;&lt;br /&gt;AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=142934&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7287538639763422322?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7287538639763422322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7287538639763422322'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/virus-profile-w32checkout91d0b88a.html' title='Virus Profile: W32/Checkout!91d0b88a'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8914059753092138384</id><published>2009-01-29T21:25:00.000-08:00</published><updated>2009-01-29T21:26:42.110-08:00</updated><title type='text'>Virus Profile: Spy-Agent.bw</title><content type='html'>Risk Assessment    &lt;br /&gt;  - Home Users:  Low-Profiled&lt;br /&gt;  - Corporate Users:  Low-Profiled&lt;br /&gt;Date Discovered:  8/20/2007&lt;br /&gt;Date Added:  3/15/2007&lt;br /&gt;Origin:  N/A&lt;br /&gt;Length:  Varies&lt;br /&gt;Type:  Trojan&lt;br /&gt;SubType:  Win32&lt;br /&gt;DAT Required:  4985&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Virus Characteristics&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-- Update December 2, 2008 --&lt;br /&gt;&lt;br /&gt;A new variant began to be spammed to German customer earlier this morning. The trojan comes with an email claiming that your email account is locked and the instructions to unlock the account can be found in the attachment(the trojan).&lt;br /&gt;&lt;br /&gt;Filenames used are Sperrung.exe, Hinweis.exe and the dropped file is named Wins.exe.&lt;br /&gt;&lt;br /&gt;Detection for these variants is included in todays 5452 DAT package.&lt;br /&gt;&lt;br /&gt;An Extra DAT file can be obtained from the Extra DAT request page:http://www.webimmune.net/extra/getextra.aspx&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt; -- Update August 19, 2008 --&lt;br /&gt;&lt;br /&gt;Another variant got spammed today. The subject of those mail reads 'Colis postal' and pretends to be sent from 'La Poste France' or it pretends to be sent from 'Hawaiian Airlines' using the subject 'Your Flight Ticket N0165906'.&lt;br /&gt;&lt;br /&gt;Attached to these mails is a ZIP archive, named 'La_Poste_N8832.zip' or 'Your Flight Ticket N0165906', which includes the trojan Spy-Agent.bw.&lt;br /&gt;&lt;br /&gt;Detection for this new variant will be included in todays 5364 DATs.&lt;br /&gt;&lt;br /&gt; -- Update August 18, 2008 --&lt;br /&gt;&lt;br /&gt;A new variant of Spy-Agent.bw  has been observed which comes as an attachment to a fake email claiming to be from Fedex. The attachment might be named Fedx-retr871.zip or similar.&lt;br /&gt;&lt;br /&gt;Upon execution, a new variant creates the following file:&lt;br /&gt;&lt;br /&gt;    * C:\​WINDOWS\​system32\​ntos.exe (Spy-Agent,bw)&lt;br /&gt;&lt;br /&gt;It changes the following registry key:&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = %Windir%\System32\userinit %Windir%\System32\ntos.exe &lt;br /&gt;&lt;br /&gt;-- Update August 04, 2008 --&lt;br /&gt;&lt;br /&gt;A new variant of Spy-Agent.bw  has been observed which comes as an attachment to a fake email claiming to be from UPS.&lt;br /&gt;&lt;br /&gt;Upon execution, a new variant creates the following hidden files and hidden folder:&lt;br /&gt;&lt;br /&gt;    * %Windir%\System32\wsnpoem\ (folder)&lt;br /&gt;    * %Windir%\System32\wsnpoem\audio.dll (data file)&lt;br /&gt;    * %Windir%\System32\wsnpoem\video.dll (data file)&lt;br /&gt;    * %Windir%\System32\ntos.exe (Spy-Agent.bw)&lt;br /&gt;&lt;br /&gt;(Where %Windir% is the Windows folder; C:\Windows)&lt;br /&gt;&lt;br /&gt;The following registry keys are modified/added :&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = %Windir%\System32\userinit %Windir%\System32\ntos.exe&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID = &lt;COMPUTER Name_%Random%&gt;&lt;br /&gt;&lt;br /&gt;The trojan inject its malcode to the following process:&lt;br /&gt;&lt;br /&gt;    * winlogon.exe&lt;br /&gt;&lt;br /&gt;It can connect to the following website to communicate stolen data, log actions and receive instructions:&lt;br /&gt;&lt;br /&gt;    * ahleinaks.ru&lt;br /&gt;&lt;br /&gt;-- Update July 21, 2008 --&lt;br /&gt;&lt;br /&gt;A new variant of Spy-Agent.bw  has been observed which comes as an attachment to a fake email claiming to be from UPS.&lt;br /&gt;&lt;br /&gt;It can connect to the following website to communicate stolen data, log actions and receive instructions:&lt;br /&gt;&lt;br /&gt;    * blatundalqik.ru&lt;br /&gt;&lt;br /&gt;-- Update May 13, 2008 --&lt;br /&gt;&lt;br /&gt;Upon execution, a new variant creates the following hidden files and hidden folder:&lt;br /&gt;&lt;br /&gt;    * %Windir%\System32\wsnpoem\ (folder)&lt;br /&gt;    * %Windir%\System32\wsnpoem\audio.dll (data file)&lt;br /&gt;    * %Windir%\System32\wsnpoem\video.dll (data file)&lt;br /&gt;    * %Windir%\System32\ntos.exe (Spy-Agent.bw)&lt;br /&gt;&lt;br /&gt;(Where %Windir% is the Windows folder; C:\Windows)&lt;br /&gt;&lt;br /&gt;The following registry keys are modified/added :&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = %Windir%\System32\userinit %Windir%\System32\ntos.exe&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID = &lt;COMPUTER Name_%Random%&gt;&lt;br /&gt;&lt;br /&gt;The trojan inject its malcode to the following process:&lt;br /&gt;&lt;br /&gt;    * winlogon.exe&lt;br /&gt;&lt;br /&gt;It can connect to the following site to communicate stolen data, log actions and receive instructions:&lt;br /&gt;&lt;br /&gt;    * razvlekalovo.net&lt;br /&gt;&lt;br /&gt;-- Update August 20, 2007 --&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The risk assessment of this threat has been updated to Low-Profiled due to media attention at:&lt;br /&gt;http://www.techworld.com/security/news/index.cfm?newsID=9833&amp;pagtype=samechan&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;A recent variant was found to be stealing data from recruitment websites when the user is infected. This variant can be proactively detected proactively as New Win32.g2 using the following scanners with heuristics enabled: GroupShield, Secure Internet Gateway (SIG), Secure Mail Gateway (SMG), Secure Web Gateway (SWG), TOPS Email, VirusScan Enterprise Email, VirusScan Email.&lt;br /&gt;&lt;br /&gt;Upon execution, it creates the following files and folder:&lt;br /&gt;&lt;br /&gt;    * %Windir%\System32\wsnpoem\ (folder)&lt;br /&gt;    * %Windir%\System32\wsnpoem\audio.dll (data file)&lt;br /&gt;    * %Windir%\System32\wsnpoem\video.dll (data file)&lt;br /&gt;    * %Windir%\System32\ntos.exe (Spy-Agent.bw)&lt;br /&gt;&lt;br /&gt;(Where %Windir% is the Windows folder; C:\Windows)&lt;br /&gt;&lt;br /&gt;The following registry keys are modified/added :&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\pathx = &lt;PATH to Spy-Agent.bw&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = %Windir%\System32\userinit %Windir%\System32\ntos.exe&lt;br /&gt;    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID = &lt;COMPUTER Name_%Random%&gt;&lt;br /&gt;&lt;br /&gt;The trojan inject its malcode to the following process:&lt;br /&gt;&lt;br /&gt;    * svchost.exe&lt;br /&gt;    * winlogon.exe&lt;br /&gt;&lt;br /&gt;It follows that a particular variant of Spy-Agent.bw can log into the following recruitment websites in search of resume data and personal information and then post them to:&lt;br /&gt;&lt;br /&gt;    * recruiter.monster.com&lt;br /&gt;    * hiring.monster.com&lt;br /&gt;&lt;br /&gt;Spy-Agent.bw can connect to the following site(s) to communicate stolen data, log actions and receive instructions:&lt;br /&gt;&lt;br /&gt;    * http://195.189.{blocked}/mnstr/grabv2.php?getid=1&lt;br /&gt;    * http://195.189.{blocked}/spmv3.php?sendlog=&lt;br /&gt;    * http://195.189.{blocked}/mnstr/grabv2.php&lt;br /&gt;    * http://195.189.{blocked}/pmv3.php?sentmailz=&lt;br /&gt;&lt;br /&gt;Sends spam e-mails via the following SMTP server:&lt;br /&gt;&lt;br /&gt;    * smtp.bizmail.yahoo.com&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Indications of Infection&lt;br /&gt;&lt;br /&gt;    * Presence of file(s) and registry key(s) as previously mentioned.&lt;br /&gt;    * Unexpected network connections to the mentioned site(s). &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Method of Infection&lt;br /&gt;Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc. Certain known variants were also known to be installed via web exploits.&lt;br /&gt;Removal Instructions&lt;br /&gt;&lt;br /&gt;All Users:&lt;br /&gt;Use specified engine and DAT files for detection.&lt;br /&gt;&lt;br /&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the current engine and the specified DATs (or higher). Older engines may not be able to remove all registry keys created by this threat.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Additional Windows ME/XP removal considerations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Aliases&lt;/span&gt;&lt;br /&gt;Infostealer.Monstres (Symantec)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=141745&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8914059753092138384?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8914059753092138384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8914059753092138384'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/virus-profile-spy-agentbw.html' title='Virus Profile: Spy-Agent.bw'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1144446843470828998</id><published>2009-01-29T21:23:00.000-08:00</published><updated>2009-01-29T21:25:33.636-08:00</updated><title type='text'>Virus Profile: Downloader-UA.h</title><content type='html'>Risk Assessment    &lt;br /&gt;  - Home Users:  Medium&lt;br /&gt;  - Corporate Users:  Low-Profiled&lt;br /&gt;Date Discovered:  5/2/2008&lt;br /&gt;Date Added:  5/2/2008&lt;br /&gt;Origin:  N/A&lt;br /&gt;Length:  various&lt;br /&gt;Type:  Trojan&lt;br /&gt;SubType:  Downloader&lt;br /&gt;DAT Required:  5287&lt;br /&gt;Virus Characteristics&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Downloader-UA.h trojans&lt;/span&gt; are fake music and video files associated with fastmp3player.com.&lt;br /&gt;&lt;br /&gt;File sizes vary as these files are padded with nulls. The file names varies as well. Here are some of the samples file names. &lt;br /&gt;&lt;br /&gt;preview-t-3545425-adult.mpg&lt;br /&gt;preview-t-3545425-changing times earth wind .mp3&lt;br /&gt;preview-t-3545425-girls aloud st trinnians.mp3&lt;br /&gt;preview-t-3545425-heartbroken fast t2 ft jodie.mp3&lt;br /&gt;preview-t-3545425-jij bent zo jeroen van den.mp3&lt;br /&gt;preview-t-3545425-meet bambi in kings harem.mp3&lt;br /&gt;preview-t-3545425-middle eastern chick.mpg&lt;br /&gt;preview-t-3545425-paint me bunmingham.mp3&lt;br /&gt;preview-t-3545425-paralyized by you.mp3&lt;br /&gt;preview-t-3545425-pull over levert.mp3&lt;br /&gt;preview-t-3545425-say it right remix.mp3&lt;br /&gt;preview-t-3545425-st trinnians girls aloud.mp3&lt;br /&gt;preview-t-3545425-theme godfather.mp3&lt;br /&gt;t-3545425-bentley bizzle.mp3&lt;br /&gt;t-3545425-dx vs randi orton 2007.mpg&lt;br /&gt;t-3545425-haloween special.mp3&lt;br /&gt;t-3545425-just got lucky.mp3&lt;br /&gt;t-3545425-lion king portugues.mpg&lt;br /&gt;t-3545425-los padres de ella.mpg&lt;br /&gt;t-3545425-para sayo freestyle.mp3&lt;br /&gt;t-3545425-peanut butter jelly amende.mp3&lt;br /&gt;t-3545425-stare at sun thrice.mp3&lt;br /&gt;t-3545425-suicide bride dana.mp3&lt;br /&gt;t-3545425-wayne and jane.mp3&lt;br /&gt;&lt;br /&gt;When a user attempts to load one of these MP3 and MPG files, they do not get the music/video they were hoping for; instead they are directed to download a file named PLAY_MP3.exe.  In fact, the MP3/MPG file they downloaded was completely fake, playing no media clip what so ever.&lt;br /&gt;&lt;br /&gt;If users agree to download and run PLAY_MP3.exe (detected as Generic PUP.a with McAfee DAT files)  a 4,800 word EULA is displayed.&lt;br /&gt;&lt;br /&gt;Indications of Infection&lt;br /&gt;&lt;br /&gt;    * filenames listed in the above&lt;br /&gt;    * EULA displayed in the above&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Downloader-UA.h trojans&lt;/span&gt; are propagated through P2P networks&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal Instructions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;All Users:&lt;/span&gt;&lt;br /&gt;Use current engine and DAT files for detection and removal.&lt;br /&gt;&lt;br /&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=144503&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1144446843470828998?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1144446843470828998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1144446843470828998'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/virus-profile-downloader-uah.html' title='Virus Profile: Downloader-UA.h'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6145692529702027683</id><published>2009-01-22T06:20:00.000-08:00</published><updated>2009-01-22T06:21:55.342-08:00</updated><title type='text'>Win32/Malas.C</title><content type='html'>Type : Worm&lt;br /&gt;&lt;br /&gt;Category : Win32&lt;br /&gt;&lt;br /&gt;Also known as:  W32/Bindo.worm (McAfee), INF/Malas.C, Worm:Win32/Malas.gen (MS OneCare), P2P-Worm.Win32.Malas.h (Kaspersky), WORM_MALAS.I (Trend), W32/Malas-B (Sophos), W32.SillyFDC (Symantec)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Win32/Malas.C&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;CA Antivirus 2007&lt;br /&gt;Removal Instructions&lt;/span&gt;&lt;br /&gt;Signature: 31.4.5784&lt;br /&gt;Removal Instructions:&lt;br /&gt;&lt;br /&gt;Download and apply the latest eTrust Antivirus signature file update. Launch the eTrust Antivirus - Local Scanner and run a full scan on all affected computer systems, with the "Infection Treatment File Actions" set to "Cure File" and enable the System Cure feature.&lt;br /&gt;&lt;br /&gt;Consult the product help and/or visit SupportConnect for additional assistance with operating these features of eTrust Antivirus 6.x/v7.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6145692529702027683?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6145692529702027683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6145692529702027683'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/win32malasc.html' title='Win32/Malas.C'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-9200327053989314968</id><published>2009-01-22T06:17:00.000-08:00</published><updated>2009-01-22T06:18:41.312-08:00</updated><title type='text'>Win32/Dowritn.BG</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Win32/Dowritn.BG&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;CA Antivirus 2007&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal Instructions&lt;/span&gt;&lt;br /&gt;Signature: 31.6.6276&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal Instructions:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Download and apply the latest eTrust Antivirus signature file update. Launch the eTrust Antivirus - Local Scanner and run a full scan on all affected computer systems, with the "Infection Treatment File Actions" set to "Cure File" and enable the System Cure feature.&lt;br /&gt;&lt;br /&gt;Consult the product help and/or visit SupportConnect for additional assistance with operating these features of eTrust Antivirus 6.x/v7.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-9200327053989314968?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9200327053989314968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9200327053989314968'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/win32dowritnbg.html' title='Win32/Dowritn.BG'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7112401277843611159</id><published>2009-01-22T06:08:00.000-08:00</published><updated>2009-01-22T06:09:33.259-08:00</updated><title type='text'>Net-Worm.Win32.Kido.bt</title><content type='html'>This worm spreads via local networks and removable storage media. It is a PE DLL file. The components of the worm are between 155KB and 165KB in size. It is packed using UPX.&lt;br /&gt;Installation&lt;br /&gt;&lt;br /&gt;The worm copies its executable file to the Windows system directory as follows:&lt;br /&gt;&lt;br /&gt;%System%\&lt;rnd&gt;.dll &lt;rnd&gt; is a string of random symbols&lt;br /&gt;&lt;br /&gt;The worm creates a service to ensure it will be run each time Windows is launched on the victim machine. The following registry key is created:&lt;br /&gt;[HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;&lt;br /&gt;The worm also modifies the following registry key value::&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]&lt;br /&gt;"netsvcs" = "&lt;original value&gt; %System%\&lt;rnd&gt;.dll"&lt;br /&gt;Network spreading&lt;br /&gt;&lt;br /&gt;When infecting a computer, the worm launches an HTTP server on a random TCP port. This is then used to load the worm’s executable file to other computers.&lt;br /&gt;&lt;br /&gt;The worm gets the IP addresses of computers in the same network as the victim machine and attacks them via a buffer overrun vulnerability in the Server service. (More details about this vulnerability can be found on the Microsoft site: www.microsoft.com).&lt;br /&gt;&lt;br /&gt;The worm sends a specially crafted RPC request to remote machines, which causes a buffer overrun when the wcscpy_s function is called in netapi32.dll. This launches code which downloads the worm file, launches and installs it on the new victim machine.&lt;br /&gt;&lt;br /&gt;In order to exploit the vulnerability described above, the worm attempts to connect to the Administrator account on the remote machine. The worm uses the following passwords to brute force the account:&lt;br /&gt;99999999&lt;br /&gt;9999999&lt;br /&gt;999999&lt;br /&gt;99999&lt;br /&gt;9999&lt;br /&gt;999&lt;br /&gt;99&lt;br /&gt;9&lt;br /&gt;88888888&lt;br /&gt;8888888&lt;br /&gt;888888&lt;br /&gt;88888&lt;br /&gt;8888&lt;br /&gt;888&lt;br /&gt;88&lt;br /&gt;8&lt;br /&gt;77777777&lt;br /&gt;7777777&lt;br /&gt;777777&lt;br /&gt;77777&lt;br /&gt;7777&lt;br /&gt;777&lt;br /&gt;77&lt;br /&gt;7&lt;br /&gt;66666666&lt;br /&gt;6666666&lt;br /&gt;666666&lt;br /&gt;66666&lt;br /&gt;6666&lt;br /&gt;666&lt;br /&gt;66&lt;br /&gt;6&lt;br /&gt;55555555&lt;br /&gt;5555555&lt;br /&gt;555555&lt;br /&gt;55555&lt;br /&gt;5555&lt;br /&gt;555&lt;br /&gt;55&lt;br /&gt;5&lt;br /&gt;44444444&lt;br /&gt;4444444&lt;br /&gt;444444&lt;br /&gt;44444&lt;br /&gt;4444&lt;br /&gt;444&lt;br /&gt;44&lt;br /&gt;4&lt;br /&gt;33333333&lt;br /&gt;3333333&lt;br /&gt;333333&lt;br /&gt;33333&lt;br /&gt;3333&lt;br /&gt;333&lt;br /&gt;33&lt;br /&gt;3&lt;br /&gt;22222222&lt;br /&gt;2222222&lt;br /&gt;222222&lt;br /&gt;22222&lt;br /&gt;2222&lt;br /&gt;222&lt;br /&gt;22&lt;br /&gt;2&lt;br /&gt;11111111&lt;br /&gt;1111111&lt;br /&gt;111111&lt;br /&gt;11111&lt;br /&gt;1111&lt;br /&gt;111&lt;br /&gt;11&lt;br /&gt;1&lt;br /&gt;00000000&lt;br /&gt;0000000&lt;br /&gt;00000&lt;br /&gt;0000&lt;br /&gt;000&lt;br /&gt;00&lt;br /&gt;0987654321&lt;br /&gt;987654321&lt;br /&gt;87654321&lt;br /&gt;7654321&lt;br /&gt;654321&lt;br /&gt;54321&lt;br /&gt;4321&lt;br /&gt;321&lt;br /&gt;21&lt;br /&gt;12&lt;br /&gt;super&lt;br /&gt;secret&lt;br /&gt;server&lt;br /&gt;computer&lt;br /&gt;owner&lt;br /&gt;backup&lt;br /&gt;database&lt;br /&gt;lotus&lt;br /&gt;oracle&lt;br /&gt;business&lt;br /&gt;manager&lt;br /&gt;temporary&lt;br /&gt;ihavenopass&lt;br /&gt;nothing&lt;br /&gt;nopassword&lt;br /&gt;nopass&lt;br /&gt;Internet&lt;br /&gt;internet&lt;br /&gt;example&lt;br /&gt;sample&lt;br /&gt;love123&lt;br /&gt;boss123&lt;br /&gt;work123&lt;br /&gt;home123&lt;br /&gt;mypc123&lt;br /&gt;temp123&lt;br /&gt;test123&lt;br /&gt;qwe123&lt;br /&gt;abc123&lt;br /&gt;pw123&lt;br /&gt;root123&lt;br /&gt;pass123&lt;br /&gt;pass12&lt;br /&gt;pass1&lt;br /&gt;admin123&lt;br /&gt;admin12&lt;br /&gt;admin1&lt;br /&gt;password123&lt;br /&gt;password12&lt;br /&gt;password1&lt;br /&gt;default&lt;br /&gt;foobar&lt;br /&gt;foofoo&lt;br /&gt;temptemp&lt;br /&gt;temp&lt;br /&gt;testtest&lt;br /&gt;test&lt;br /&gt;rootroot&lt;br /&gt;root  fuck&lt;br /&gt;zzzzz&lt;br /&gt;zzzz&lt;br /&gt;zzz&lt;br /&gt;xxxxx&lt;br /&gt;xxxx&lt;br /&gt;xxx&lt;br /&gt;qqqqq&lt;br /&gt;qqqq&lt;br /&gt;qqq&lt;br /&gt;aaaaa&lt;br /&gt;aaaa&lt;br /&gt;aaa&lt;br /&gt;sql&lt;br /&gt;file&lt;br /&gt;web&lt;br /&gt;foo&lt;br /&gt;job&lt;br /&gt;home&lt;br /&gt;work&lt;br /&gt;intranet&lt;br /&gt;controller&lt;br /&gt;killer&lt;br /&gt;games&lt;br /&gt;private&lt;br /&gt;market&lt;br /&gt;coffee&lt;br /&gt;cookie&lt;br /&gt;forever&lt;br /&gt;freedom&lt;br /&gt;student&lt;br /&gt;account&lt;br /&gt;academia&lt;br /&gt;files&lt;br /&gt;windows&lt;br /&gt;monitor&lt;br /&gt;unknown&lt;br /&gt;anything&lt;br /&gt;letitbe&lt;br /&gt;letmein&lt;br /&gt;domain&lt;br /&gt;access&lt;br /&gt;money&lt;br /&gt;campus&lt;br /&gt;explorer&lt;br /&gt;exchange&lt;br /&gt;customer&lt;br /&gt;cluster&lt;br /&gt;nobody&lt;br /&gt;codeword&lt;br /&gt;codename&lt;br /&gt;changeme&lt;br /&gt;desktop&lt;br /&gt;security&lt;br /&gt;secure&lt;br /&gt;public&lt;br /&gt;system&lt;br /&gt;shadow&lt;br /&gt;office&lt;br /&gt;supervisor&lt;br /&gt;superuser&lt;br /&gt;share&lt;br /&gt;adminadmin&lt;br /&gt;mypassword&lt;br /&gt;mypass&lt;br /&gt;pass&lt;br /&gt;Login&lt;br /&gt;login&lt;br /&gt;Password&lt;br /&gt;password&lt;br /&gt;passwd&lt;br /&gt;zxcvbn&lt;br /&gt;zxcvb&lt;br /&gt;zxccxz&lt;br /&gt;zxcxz&lt;br /&gt;qazwsxedc&lt;br /&gt;qazwsx&lt;br /&gt;q1w2e3&lt;br /&gt;qweasdzxc&lt;br /&gt;asdfgh&lt;br /&gt;asdzxc&lt;br /&gt;asddsa&lt;br /&gt;asdsa&lt;br /&gt;qweasd&lt;br /&gt;qwerty&lt;br /&gt;qweewq&lt;br /&gt;qwewq&lt;br /&gt;nimda&lt;br /&gt;administrator&lt;br /&gt;Admin&lt;br /&gt;admin&lt;br /&gt;a1b2c3&lt;br /&gt;1q2w3e&lt;br /&gt;1234qwer&lt;br /&gt;1234abcd&lt;br /&gt;123asd&lt;br /&gt;123qwe&lt;br /&gt;123abc&lt;br /&gt;123321&lt;br /&gt;12321&lt;br /&gt;123123&lt;br /&gt;1234567890&lt;br /&gt;123456789&lt;br /&gt;12345678&lt;br /&gt;1234567&lt;br /&gt;123456&lt;br /&gt;12345&lt;br /&gt;1234&lt;br /&gt;123&lt;br /&gt;Spreading via removable storage media&lt;br /&gt;&lt;br /&gt;The worm copies its executable file as follows:&lt;br /&gt;&lt;br /&gt;&lt;X&gt;:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\&lt;rnd&gt;.vmx rnd is a string of random lower case symbols; X is the disk.&lt;br /&gt;&lt;br /&gt;The worm also places the following file in the root of each disk:&lt;br /&gt;&lt;X&gt;:\autorun.inf&lt;br /&gt;&lt;br /&gt;This ensures the worm’s executable file will be run each time the user opens the infected disk using Windows Explorer.&lt;br /&gt;Payload&lt;br /&gt;&lt;br /&gt;When launching, the worm injects its code into the address space of one of the “svchost.exe” system processes. This code is responsible for the worm’s malicious payload:&lt;br /&gt;&lt;br /&gt;    * Disables system restore&lt;br /&gt;    * Blocks addresses which contain the following strings:&lt;br /&gt;      indowsupdate&lt;br /&gt;      wilderssecurity&lt;br /&gt;      threatexpert&lt;br /&gt;      castlecops&lt;br /&gt;      spamhaus&lt;br /&gt;      cpsecure&lt;br /&gt;      arcabit&lt;br /&gt;      emsisoft&lt;br /&gt;      sunbelt&lt;br /&gt;      securecomputing&lt;br /&gt;      rising&lt;br /&gt;      prevx&lt;br /&gt;      pctools&lt;br /&gt;      norman&lt;br /&gt;      k7computing&lt;br /&gt;      ikarus&lt;br /&gt;      hauri&lt;br /&gt;      hacksoft&lt;br /&gt;      gdata&lt;br /&gt;      fortinet&lt;br /&gt;      ewido&lt;br /&gt;      clamav&lt;br /&gt;      comodo&lt;br /&gt;      quickheal&lt;br /&gt;      avira&lt;br /&gt;      avast&lt;br /&gt;      esafe&lt;br /&gt;      ahnlab&lt;br /&gt;      centralcommand&lt;br /&gt;      drweb&lt;br /&gt;      grisoft&lt;br /&gt;      eset&lt;br /&gt;      nod32&lt;br /&gt;      f-prot&lt;br /&gt;      jotti&lt;br /&gt;      kaspersky&lt;br /&gt;      f-secure&lt;br /&gt;      computerassociates&lt;br /&gt;      networkassociates&lt;br /&gt;      etrust&lt;br /&gt;      panda&lt;br /&gt;      sophos&lt;br /&gt;      trendmicro&lt;br /&gt;      mcafee&lt;br /&gt;      norton&lt;br /&gt;      symantec&lt;br /&gt;      microsoft&lt;br /&gt;      defender&lt;br /&gt;      rootkit&lt;br /&gt;      malware&lt;br /&gt;      spyware&lt;br /&gt;      virus&lt;br /&gt;&lt;br /&gt;The worm also downloads a file from the link shown below:&lt;br /&gt;http://trafficconverter.biz/*****/antispyware/loadadv.exe&lt;br /&gt;&lt;br /&gt;This file is saved to the Windows system directory and then launched for execution. The link was not live at the time of writing.&lt;br /&gt;&lt;br /&gt;The worm may also download files from links of the type shown below:&lt;br /&gt;http://&lt;URL&gt;/search?q=&lt;%rnd2%&gt;&lt;br /&gt;&lt;br /&gt;rnd2 is a random number. URL is a link formed by a special algorithm which uses the current date. The worm gets the current date from one of the sites listed below:&lt;br /&gt;http://www.w3.org&lt;br /&gt;http://www.ask.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.yahoo.com&lt;br /&gt;http://www.google.com&lt;br /&gt;http://www.baidu.com&lt;br /&gt;&lt;br /&gt;Files downloaded by the worm are saved to the Windows system directory with their original name.&lt;br /&gt;Removal instructions&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, you can either use a special removal tool, which can be found here support.kaspersky.com or follow the instructions below:&lt;br /&gt;&lt;br /&gt;   1. Delete the system registry key shown below::&lt;br /&gt;      [HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;   2. Delete "%System%\&lt;rnd&gt;.dll" from the system registry key parameter shown below:&lt;br /&gt;      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs"&lt;br /&gt;   3. Reboot the computer.&lt;br /&gt;   4. Delete the original worm file (the location will depend on how the malicious program penetrated the computer).&lt;br /&gt;   5. Delete the file shown below:&lt;br /&gt;&lt;br /&gt;      %System%\&lt;rnd&gt;.dll &lt;rnd&gt; is a string of random symbols&lt;br /&gt;   6. Delete the following files from all removable storage media:&lt;br /&gt;&lt;br /&gt;      &lt;X&gt;:\autorun.inf &lt;X&gt;:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\&lt;rnd&gt;.vmx rnd is a string of random lower case symbols; X is the disk.&lt;br /&gt;   7. Download and install operating system updates from the following link:&lt;br /&gt;      http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: www.viruslist.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7112401277843611159?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7112401277843611159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7112401277843611159'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/net-wormwin32kidobt.html' title='Net-Worm.Win32.Kido.bt'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-623365015783812484</id><published>2009-01-22T06:07:00.000-08:00</published><updated>2009-01-22T06:08:34.985-08:00</updated><title type='text'>Net-Worm.Win32.Kido.dv</title><content type='html'>This worm spreads via local networks and removable storage media. It is a PE DLL file. The components of the worm are 165840 B. It is packed using UPX.&lt;br /&gt;Installation&lt;br /&gt;&lt;br /&gt;The worm copies its executable file as follows:&lt;br /&gt;%System%\&lt;rnd&gt;.dll&lt;br /&gt;%Program Files%\Internet Explorer\&lt;rnd&gt;.dll&lt;br /&gt;%Program Files%\Movie Maker\&lt;rnd&gt;.dll&lt;br /&gt;%All Users Application Data%\&lt;rnd&gt;.dll&lt;br /&gt;%Temp%\&lt;rnd&gt;.dll&lt;br /&gt;%System%\&lt;rnd&gt;.tmp&lt;br /&gt;%Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;&lt;br /&gt;&lt;rnd&gt; is a string of random symbols&lt;br /&gt;&lt;br /&gt;The worm creates a service to ensure it will be run each time Windows is launched on the victim machine. The following registry key is created:&lt;br /&gt;[HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;&lt;br /&gt;The worm also modifies the following registry key value:&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs" = "&lt;original value&gt; %System%\&lt;rnd&gt;.dll"&lt;br /&gt;Network spreading&lt;br /&gt;&lt;br /&gt;When infecting a computer, the worm launches an HTTP server on a random TCP port. This is then used to load the worm’s executable file to other computers.&lt;br /&gt;&lt;br /&gt;The worm gets the IP addresses of computers in the same network as the victim machine and attacks them via a buffer overrun vulnerability (MS08-067) in the Server service. (More details about this vulnerability can be found on the Microsoft site: www.microsoft.com).&lt;br /&gt;&lt;br /&gt;The worm sends a specially crafted RPC request to remote machines, which causes a buffer overrun when the wcscpy_s function is called in netapi32.dll. This launches code which downloads the worm file, launches and installs it on the new victim machine.&lt;br /&gt;&lt;br /&gt;In order to exploit the vulnerability described above, the worm attempts to connect to the Administrator account on the remote machine. The worm uses the following passwords to brute force the account:&lt;br /&gt;99999999&lt;br /&gt;9999999&lt;br /&gt;999999&lt;br /&gt;99999&lt;br /&gt;88888888&lt;br /&gt;8888888&lt;br /&gt;888888&lt;br /&gt;88888&lt;br /&gt;8888&lt;br /&gt;888&lt;br /&gt;88&lt;br /&gt;8&lt;br /&gt;77777777&lt;br /&gt;7777777&lt;br /&gt;777777&lt;br /&gt;77777&lt;br /&gt;7777&lt;br /&gt;777&lt;br /&gt;77&lt;br /&gt;7&lt;br /&gt;66666666&lt;br /&gt;6666666&lt;br /&gt;666666&lt;br /&gt;66666&lt;br /&gt;6666&lt;br /&gt;666&lt;br /&gt;66&lt;br /&gt;6&lt;br /&gt;55555555&lt;br /&gt;5555555&lt;br /&gt;555555&lt;br /&gt;55555&lt;br /&gt;5555&lt;br /&gt;555&lt;br /&gt;55&lt;br /&gt;5&lt;br /&gt;44444444&lt;br /&gt;4444444&lt;br /&gt;444444&lt;br /&gt;44444&lt;br /&gt;4444&lt;br /&gt;444&lt;br /&gt;44&lt;br /&gt;4&lt;br /&gt;33333333&lt;br /&gt;3333333&lt;br /&gt;333333&lt;br /&gt;33333&lt;br /&gt;3333&lt;br /&gt;333&lt;br /&gt;33&lt;br /&gt;3&lt;br /&gt;22222222&lt;br /&gt;2222222&lt;br /&gt;222222&lt;br /&gt;22222&lt;br /&gt;2222&lt;br /&gt;222&lt;br /&gt;22&lt;br /&gt;2&lt;br /&gt;11111111&lt;br /&gt;1111111&lt;br /&gt;111111&lt;br /&gt;11111&lt;br /&gt;1111&lt;br /&gt;111&lt;br /&gt;explorer&lt;br /&gt;exchange&lt;br /&gt;customer&lt;br /&gt;cluster&lt;br /&gt;nobody&lt;br /&gt;codeword&lt;br /&gt;codename&lt;br /&gt;changeme&lt;br /&gt;desktop&lt;br /&gt;security&lt;br /&gt;secure&lt;br /&gt;public&lt;br /&gt;system&lt;br /&gt;shadow&lt;br /&gt;office&lt;br /&gt;supervisor&lt;br /&gt;superuser&lt;br /&gt;share&lt;br /&gt;super&lt;br /&gt;secret&lt;br /&gt;server&lt;br /&gt;computer&lt;br /&gt;owner&lt;br /&gt;backup&lt;br /&gt;database&lt;br /&gt;lotus&lt;br /&gt;oracle&lt;br /&gt;business&lt;br /&gt;manager&lt;br /&gt;temporary&lt;br /&gt;ihavenopass&lt;br /&gt;nothing&lt;br /&gt;nopassword&lt;br /&gt;nopass&lt;br /&gt;Internet&lt;br /&gt;internet&lt;br /&gt;example&lt;br /&gt;sample&lt;br /&gt;love123&lt;br /&gt;boss123&lt;br /&gt;work123&lt;br /&gt;home123&lt;br /&gt;mypc123&lt;br /&gt;temp123&lt;br /&gt;test123&lt;br /&gt;qwe123&lt;br /&gt;abc123&lt;br /&gt;pw123&lt;br /&gt;root123&lt;br /&gt;pass123&lt;br /&gt;pass12&lt;br /&gt;pass1&lt;br /&gt;admin123&lt;br /&gt;admin12&lt;br /&gt;admin1&lt;br /&gt;password123&lt;br /&gt;password12&lt;br /&gt;password1  9999&lt;br /&gt;999&lt;br /&gt;99&lt;br /&gt;9&lt;br /&gt;11&lt;br /&gt;1&lt;br /&gt;00000000&lt;br /&gt;0000000&lt;br /&gt;00000&lt;br /&gt;0000&lt;br /&gt;000&lt;br /&gt;00&lt;br /&gt;0987654321&lt;br /&gt;987654321&lt;br /&gt;87654321&lt;br /&gt;7654321&lt;br /&gt;654321&lt;br /&gt;54321&lt;br /&gt;4321&lt;br /&gt;321&lt;br /&gt;21&lt;br /&gt;12&lt;br /&gt;fuck&lt;br /&gt;zzzzz&lt;br /&gt;zzzz&lt;br /&gt;zzz&lt;br /&gt;xxxxx&lt;br /&gt;xxxx&lt;br /&gt;xxx&lt;br /&gt;qqqqq&lt;br /&gt;qqqq&lt;br /&gt;qqq&lt;br /&gt;aaaaa&lt;br /&gt;aaaa&lt;br /&gt;aaa&lt;br /&gt;sql&lt;br /&gt;file&lt;br /&gt;web&lt;br /&gt;foo&lt;br /&gt;job&lt;br /&gt;home&lt;br /&gt;work&lt;br /&gt;intranet&lt;br /&gt;controller&lt;br /&gt;killer&lt;br /&gt;games&lt;br /&gt;private&lt;br /&gt;market&lt;br /&gt;coffee&lt;br /&gt;cookie&lt;br /&gt;forever&lt;br /&gt;freedom&lt;br /&gt;student&lt;br /&gt;account&lt;br /&gt;academia&lt;br /&gt;files&lt;br /&gt;windows&lt;br /&gt;monitor&lt;br /&gt;unknown&lt;br /&gt;anything&lt;br /&gt;letitbe&lt;br /&gt;letmein&lt;br /&gt;domain&lt;br /&gt;access&lt;br /&gt;money&lt;br /&gt;campus&lt;br /&gt;default&lt;br /&gt;foobar&lt;br /&gt;foofoo&lt;br /&gt;temptemp&lt;br /&gt;temp&lt;br /&gt;testtest&lt;br /&gt;test&lt;br /&gt;rootroot&lt;br /&gt;root&lt;br /&gt;adminadmin&lt;br /&gt;mypassword&lt;br /&gt;mypass&lt;br /&gt;pass&lt;br /&gt;Login&lt;br /&gt;login&lt;br /&gt;Password&lt;br /&gt;password&lt;br /&gt;passwd&lt;br /&gt;zxcvbn&lt;br /&gt;zxcvb&lt;br /&gt;zxccxz&lt;br /&gt;zxcxz&lt;br /&gt;qazwsxedc&lt;br /&gt;qazwsx&lt;br /&gt;q1w2e3&lt;br /&gt;qweasdzxc&lt;br /&gt;asdfgh&lt;br /&gt;asdzxc&lt;br /&gt;asddsa&lt;br /&gt;asdsa&lt;br /&gt;qweasd&lt;br /&gt;qwerty&lt;br /&gt;qweewq&lt;br /&gt;qwewq&lt;br /&gt;nimda&lt;br /&gt;administrator&lt;br /&gt;Admin&lt;br /&gt;admin&lt;br /&gt;a1b2c3&lt;br /&gt;1q2w3e&lt;br /&gt;1234qwer&lt;br /&gt;1234abcd&lt;br /&gt;123asd&lt;br /&gt;123qwe&lt;br /&gt;123abc&lt;br /&gt;123321&lt;br /&gt;12321&lt;br /&gt;123123&lt;br /&gt;1234567890&lt;br /&gt;123456789&lt;br /&gt;12345678&lt;br /&gt;1234567&lt;br /&gt;123456&lt;br /&gt;12345&lt;br /&gt;1234&lt;br /&gt;123&lt;br /&gt;Spreading via removable storage media&lt;br /&gt;&lt;br /&gt;The worm copies its executable file to all removable storage media as follows:&lt;br /&gt;&lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;\&lt;rnd&gt;.vmx&lt;br /&gt;&lt;br /&gt;rnd is a random string of lower case symbols; d is a random number; x is the disk&lt;br /&gt;&lt;br /&gt;The worm also places the following file in the root of each disk:&lt;br /&gt;&lt;X&gt;:\autorun.inf&lt;br /&gt;&lt;br /&gt;This ensures the worm’s executable file will be run each time the user opens the infected disk using Windows Explorer.&lt;br /&gt;Payload&lt;br /&gt;&lt;br /&gt;When launching, the worm injects its code into the address space of one of the “svchost.exe” system processes. This code is responsible for the worm’s malicious payload&lt;br /&gt;&lt;br /&gt;    * Disables the following services:&lt;br /&gt;      wuauserv&lt;br /&gt;      BITS&lt;br /&gt;    * Blocks addresses which contain the following strings:&lt;br /&gt;      indowsupdate&lt;br /&gt;      wilderssecurity&lt;br /&gt;      threatexpert&lt;br /&gt;      castlecops&lt;br /&gt;      spamhaus&lt;br /&gt;      cpsecure&lt;br /&gt;      arcabit&lt;br /&gt;      emsisoft&lt;br /&gt;      sunbelt&lt;br /&gt;      securecomputing&lt;br /&gt;      rising&lt;br /&gt;      prevx&lt;br /&gt;      pctools&lt;br /&gt;      norman&lt;br /&gt;      k7computing&lt;br /&gt;      ikarus&lt;br /&gt;      hauri&lt;br /&gt;      hacksoft&lt;br /&gt;      gdata&lt;br /&gt;      fortinet&lt;br /&gt;      ewido&lt;br /&gt;      clamav&lt;br /&gt;      comodo&lt;br /&gt;      quickheal&lt;br /&gt;      avira&lt;br /&gt;      avast&lt;br /&gt;      esafe&lt;br /&gt;      ahnlab&lt;br /&gt;      centralcommand&lt;br /&gt;      drweb&lt;br /&gt;      grisoft&lt;br /&gt;      eset&lt;br /&gt;      nod32&lt;br /&gt;      f-prot&lt;br /&gt;      jotti&lt;br /&gt;      kaspersky&lt;br /&gt;      f-secure&lt;br /&gt;      computerassociates&lt;br /&gt;      networkassociates&lt;br /&gt;      etrust&lt;br /&gt;      panda&lt;br /&gt;      sophos&lt;br /&gt;      trendmicro&lt;br /&gt;      mcafee&lt;br /&gt;      norton&lt;br /&gt;      symantec&lt;br /&gt;      microsoft&lt;br /&gt;      defender&lt;br /&gt;      rootkit&lt;br /&gt;      malware&lt;br /&gt;      spyware&lt;br /&gt;      virus&lt;br /&gt;&lt;br /&gt;The worm may also download files from links of the type shown below:&lt;br /&gt;http://&lt;URL&gt;/search?q=&lt;%rnd2%&gt;&lt;br /&gt;&lt;br /&gt;rnd2 is a random number. URL is a link formed by a special algorithm which uses the current date. The worm gets the current date from one of the sites listed below:&lt;br /&gt;http://www.w3.org&lt;br /&gt;http://www.ask.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.yahoo.com&lt;br /&gt;http://www.google.com&lt;br /&gt;http://www.baidu.com&lt;br /&gt;&lt;br /&gt;Downloaded files are saved to the Windows system directory with their original name.&lt;br /&gt;Removal instructions&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, you can either use a special removal tool, which can be found here support.kaspersky.com or follow the instructions below:&lt;br /&gt;&lt;br /&gt;   1. Delete the system registry key shown below:&lt;br /&gt;      [HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;   2. Delete "%System%\.dll" from the system registry key parameter shown below:&lt;br /&gt;      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs"&lt;br /&gt;   3. Reboot the computer.&lt;br /&gt;   4. Delete the original worm file (the location will depend on how the malicious program penetrated the computer).&lt;br /&gt;   5. Delete copies of the worm:&lt;br /&gt;      %System%\&lt;rnd&gt;.dll&lt;br /&gt;      %Program Files%\Internet Explorer\&lt;rnd&gt;.dll&lt;br /&gt;      %Program Files%\Movie Maker\&lt;rnd&gt;.dll&lt;br /&gt;      %All Users Application Data%\&lt;rnd&gt;.dll&lt;br /&gt;      %Temp%\&lt;rnd&gt;.dll&lt;br /&gt;      %System%\&lt;rnd&gt;.tmp&lt;br /&gt;      %Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;      &lt;rnd&gt; is a random string of symbols&lt;br /&gt;   6. Delete the files shown below from all removable storage media:&lt;br /&gt;      &lt;X&gt;:\autorun.inf &lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;-&lt;%d%&gt;\&lt;rnd&gt;.vmx&lt;br /&gt;      .&lt;br /&gt;&lt;br /&gt;      rnd is a random string of lower case symbols; d is a random number; x is the disk&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.viruslist.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-623365015783812484?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/623365015783812484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/623365015783812484'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/net-wormwin32kidodv.html' title='Net-Worm.Win32.Kido.dv'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4942455762033289649</id><published>2009-01-22T05:57:00.000-08:00</published><updated>2009-01-22T06:07:49.048-08:00</updated><title type='text'>Net-Worm.Win32.Kido.fx</title><content type='html'>This malicious program exploits the MS08-067 vulnerability to spread via network resources and removable storage media.&lt;br /&gt;&lt;br /&gt;This modification of the worm is a Windows PE DLL file. The file is 158110 bytes in size. It is packed using UPX.&lt;br /&gt;Installation&lt;br /&gt;&lt;br /&gt;The worm copies its executable file with random names to the following directories:&lt;br /&gt;&lt;br /&gt;%System%\&lt;rnd&gt;dir.dll&lt;br /&gt;%Program Files%\Internet Explorer\&lt;rnd&gt;.dll &lt;br /&gt;%Program Files%\Movie Maker\&lt;rnd&gt;.dll &lt;br /&gt;%All Users Application Data%\&lt;rnd&gt;.dll &lt;br /&gt;%Temp%\&lt;rnd&gt;.dll &lt;br /&gt;%System%\&lt;rnd&gt;tmp &lt;br /&gt;%Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;&lt;br /&gt;&lt;rnd&gt; is a random string of symbols.&lt;br /&gt;&lt;br /&gt;In order to ensure that the worm is launched next time the system is started, it creates a system service which launches the worm’s executable file each time Windows is booted. The following registry key will be created:&lt;br /&gt;[HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;&lt;br /&gt;The name of the service will be created from combining words from the list below:&lt;br /&gt;&lt;br /&gt;Boot &lt;br /&gt;Center &lt;br /&gt;Config &lt;br /&gt;Driver &lt;br /&gt;Helper &lt;br /&gt;Image &lt;br /&gt;Installer &lt;br /&gt;Manager &lt;br /&gt;Microsoft &lt;br /&gt;Monitor &lt;br /&gt;Network &lt;br /&gt;Security &lt;br /&gt;Server &lt;br /&gt;Shell &lt;br /&gt;Support &lt;br /&gt;System &lt;br /&gt;Task &lt;br /&gt;Time &lt;br /&gt;Universal &lt;br /&gt;Update &lt;br /&gt;Windows&lt;br /&gt;&lt;br /&gt;The worm also modifies the following system registry key value:&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs" = "&lt;original value&gt; %System%\&lt;rnd&gt;.dll"&lt;br /&gt;&lt;br /&gt;The worm hides its files in Explorer by modifying the registry key value shown below:&lt;br /&gt;[HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;"Hidden" = "dword: 0x00000002"&lt;br /&gt;"SuperHidden" = "dword: 0x00000000"&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]&lt;br /&gt;"CheckedValue" = "dword: 0x00000000"&lt;br /&gt;&lt;br /&gt;The worm flags its presence in the system by creating the unique identifier shown below:&lt;br /&gt;Global\%rnd%-%rnd%&lt;br /&gt;Propagation&lt;br /&gt;&lt;br /&gt;In order to spread quickly via networks, the worm uses tcpip.sys functions to increase the number of potential network connections.&lt;br /&gt;&lt;br /&gt;The worm connects to the servers shown below in order to determine the external IP address of the victim machine:&lt;br /&gt;&lt;br /&gt;http://www.getmyip.org&lt;br /&gt;http://www.whatsmyipaddress.com&lt;br /&gt;http://www.whatismyip.org&lt;br /&gt;http://checkip.dyndns.org&lt;br /&gt;&lt;br /&gt;The worm then launches an HTTP server on a random TCP port; this is then used to download the worm's executable file to other computers.&lt;br /&gt;&lt;br /&gt;Copies of the worm have the extensions listed below:&lt;br /&gt;&lt;br /&gt;.bmp &lt;br /&gt;.gif &lt;br /&gt;.jpeg &lt;br /&gt;.png &lt;br /&gt;&lt;br /&gt;The worm gets the IP addresses of computers in the same network as the victim machine and attacks them via a buffer overrun vulnerability (MS08-067) in the Server service. More details about the vulnerability can be found here: http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx The worm sends a specially crafted RPC request to TCP ports 139 (NetBIOS) and 445 (Direct hosted SMB) remote machines on remote machines. This causes a buffer overrun when the wcscpy_s function is called in netapi32.dll, which launches code that downloads the worm's executable file to the victim machine and launches it. The worm is then installed on the new victim machine.&lt;br /&gt;&lt;br /&gt;The worm then hooks the NetpwPathCanonicalize API call (netapi.dll) to prevent buffer overruns caused by the absence of a check on the size of outgoing strings. By doing this, the worm makes repeat exploitation of the vulnerability impossible.&lt;br /&gt;&lt;br /&gt;In order to speed up propagation, the worm modifies the following registry value:&lt;br /&gt;[HKLM\ SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]&lt;br /&gt;"TcpNumConnections" = "dword:0x00FFFFFE"&lt;br /&gt;&lt;br /&gt;In order to exploit the vulnerability described above, the worm attempts to connect to the Administrator account on the remote machine. It searches the network for an appropriate machine and gets a list of users. It then attempts to brute force each user account using the passwords shown below:z&lt;br /&gt;&lt;br /&gt;99999999&lt;br /&gt;9999999&lt;br /&gt;999999&lt;br /&gt;99999&lt;br /&gt;9999&lt;br /&gt;999&lt;br /&gt;99&lt;br /&gt;9&lt;br /&gt;88888888&lt;br /&gt;8888888&lt;br /&gt;888888&lt;br /&gt;88888&lt;br /&gt;8888&lt;br /&gt;888&lt;br /&gt;88&lt;br /&gt;8&lt;br /&gt;77777777&lt;br /&gt;7777777&lt;br /&gt;777777&lt;br /&gt;77777&lt;br /&gt;7777&lt;br /&gt;777&lt;br /&gt;77&lt;br /&gt;7&lt;br /&gt;66666666&lt;br /&gt;6666666&lt;br /&gt;666666&lt;br /&gt;66666&lt;br /&gt;6666&lt;br /&gt;666&lt;br /&gt;66&lt;br /&gt;6&lt;br /&gt;55555555&lt;br /&gt;5555555&lt;br /&gt;555555&lt;br /&gt;55555&lt;br /&gt;5555&lt;br /&gt;555&lt;br /&gt;55&lt;br /&gt;5&lt;br /&gt;44444444&lt;br /&gt;4444444&lt;br /&gt;444444&lt;br /&gt;44444&lt;br /&gt;4444&lt;br /&gt;444&lt;br /&gt;44&lt;br /&gt;4&lt;br /&gt;33333333&lt;br /&gt;3333333&lt;br /&gt;333333&lt;br /&gt;33333&lt;br /&gt;3333&lt;br /&gt;333&lt;br /&gt;33&lt;br /&gt;3&lt;br /&gt;22222222&lt;br /&gt;2222222&lt;br /&gt;222222&lt;br /&gt;22222&lt;br /&gt;2222&lt;br /&gt;222&lt;br /&gt;22&lt;br /&gt;2&lt;br /&gt;&lt;br /&gt;	&lt;br /&gt;&lt;br /&gt;11111111&lt;br /&gt;1111111&lt;br /&gt;111111&lt;br /&gt;11111&lt;br /&gt;1111&lt;br /&gt;111&lt;br /&gt;11&lt;br /&gt;1&lt;br /&gt;00000000&lt;br /&gt;0000000&lt;br /&gt;00000&lt;br /&gt;0000&lt;br /&gt;000&lt;br /&gt;00&lt;br /&gt;0987654321&lt;br /&gt;987654321&lt;br /&gt;87654321&lt;br /&gt;7654321&lt;br /&gt;654321&lt;br /&gt;54321&lt;br /&gt;4321&lt;br /&gt;321&lt;br /&gt;21&lt;br /&gt;12&lt;br /&gt;fuck&lt;br /&gt;zzzzz&lt;br /&gt;zzzz&lt;br /&gt;zzz&lt;br /&gt;xxxxx&lt;br /&gt;xxxx&lt;br /&gt;xxx&lt;br /&gt;qqqqq&lt;br /&gt;qqqq&lt;br /&gt;qqq&lt;br /&gt;aaaaa&lt;br /&gt;aaaa&lt;br /&gt;aaa&lt;br /&gt;sql&lt;br /&gt;file&lt;br /&gt;web&lt;br /&gt;foo&lt;br /&gt;job&lt;br /&gt;home&lt;br /&gt;work&lt;br /&gt;intranet&lt;br /&gt;controller&lt;br /&gt;killer&lt;br /&gt;games&lt;br /&gt;private&lt;br /&gt;market&lt;br /&gt;coffee&lt;br /&gt;cookie&lt;br /&gt;forever&lt;br /&gt;freedom&lt;br /&gt;student&lt;br /&gt;account&lt;br /&gt;academia&lt;br /&gt;files&lt;br /&gt;windows&lt;br /&gt;monitor&lt;br /&gt;&lt;br /&gt;	&lt;br /&gt;&lt;br /&gt;unknown&lt;br /&gt;anything&lt;br /&gt;letitbe&lt;br /&gt;letmein&lt;br /&gt;domain&lt;br /&gt;access&lt;br /&gt;money&lt;br /&gt;campus&lt;br /&gt;explorer&lt;br /&gt;exchange&lt;br /&gt;customer&lt;br /&gt;cluster&lt;br /&gt;nobody&lt;br /&gt;codeword&lt;br /&gt;codename&lt;br /&gt;changeme&lt;br /&gt;desktop&lt;br /&gt;security&lt;br /&gt;secure&lt;br /&gt;public&lt;br /&gt;system&lt;br /&gt;shadow&lt;br /&gt;office&lt;br /&gt;supervisor&lt;br /&gt;superuser&lt;br /&gt;share&lt;br /&gt;super&lt;br /&gt;secret&lt;br /&gt;server&lt;br /&gt;computer&lt;br /&gt;owner&lt;br /&gt;backup&lt;br /&gt;database&lt;br /&gt;lotus&lt;br /&gt;oracle&lt;br /&gt;business&lt;br /&gt;manager&lt;br /&gt;temporary&lt;br /&gt;ihavenopass&lt;br /&gt;nothing&lt;br /&gt;nopassword&lt;br /&gt;nopass&lt;br /&gt;Internet&lt;br /&gt;internet&lt;br /&gt;example&lt;br /&gt;sample&lt;br /&gt;love123&lt;br /&gt;boss123&lt;br /&gt;work123&lt;br /&gt;home123&lt;br /&gt;mypc123&lt;br /&gt;temp123&lt;br /&gt;test123&lt;br /&gt;qwe123&lt;br /&gt;abc123&lt;br /&gt;pw123&lt;br /&gt;root123&lt;br /&gt;pass123&lt;br /&gt;pass12&lt;br /&gt;pass1&lt;br /&gt;admin123&lt;br /&gt;admin12&lt;br /&gt;admin1&lt;br /&gt;&lt;br /&gt;	&lt;br /&gt;&lt;br /&gt;password123&lt;br /&gt;password12&lt;br /&gt;password1&lt;br /&gt;default&lt;br /&gt;foobar&lt;br /&gt;foofoo&lt;br /&gt;temptemp&lt;br /&gt;temp&lt;br /&gt;testtest&lt;br /&gt;test&lt;br /&gt;rootroot&lt;br /&gt;root&lt;br /&gt;adminadmin&lt;br /&gt;mypassword&lt;br /&gt;mypass&lt;br /&gt;pass&lt;br /&gt;&lt;br /&gt;Login&lt;br /&gt;login&lt;br /&gt;Password&lt;br /&gt;password&lt;br /&gt;passwd&lt;br /&gt;zxcvbn&lt;br /&gt;zxcvb&lt;br /&gt;zxccxz&lt;br /&gt;zxcxz&lt;br /&gt;qazwsxedc&lt;br /&gt;qazwsx&lt;br /&gt;q1w2e3&lt;br /&gt;qweasdzxc&lt;br /&gt;asdfgh&lt;br /&gt;asdzxc&lt;br /&gt;asddsa&lt;br /&gt;asdsa&lt;br /&gt;qweasd&lt;br /&gt;qwerty&lt;br /&gt;qweewq&lt;br /&gt;qwewq&lt;br /&gt;nimda&lt;br /&gt;administrator&lt;br /&gt;Admin&lt;br /&gt;admin&lt;br /&gt;a1b2c3&lt;br /&gt;1q2w3e&lt;br /&gt;1234qwer&lt;br /&gt;1234abcd&lt;br /&gt;123asd&lt;br /&gt;123qwe&lt;br /&gt;123abc&lt;br /&gt;123321&lt;br /&gt;12321&lt;br /&gt;123123&lt;br /&gt;1234567890&lt;br /&gt;123456789&lt;br /&gt;12345678&lt;br /&gt;1234567&lt;br /&gt;123456&lt;br /&gt;12345&lt;br /&gt;1234&lt;br /&gt;123&lt;br /&gt;&lt;br /&gt;In order to gain administrator access, the worm copies itself to the following shared folders:&lt;br /&gt;\\*&lt;name of host&gt;\ADMIN$\System32\&lt;rnd&gt;.&lt;rnd&gt;&lt;br /&gt;\\&lt;name of host&gt;\IPC$\&lt;rnd&gt;.&lt;rnd&gt;&lt;br /&gt;&lt;br /&gt;The worm can then be launched remotely or scheduled for remote launch using the following commands:&lt;br /&gt;rundll32.exe &lt;path to worm file&gt;, &lt;rnd&gt;&lt;br /&gt;Spreading via removable storage media&lt;br /&gt;&lt;br /&gt;The worm copies its executable file to all removable media under the following name:&lt;br /&gt;&lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;-&lt;br /&gt;%d%&gt;-%d%&gt;\&lt;rnd&gt;.vmx, rnd is a string of random lower case letters; d is a random number; X&lt;br /&gt;is the disk&lt;br /&gt;&lt;br /&gt;In addition to its executable file, the worm also places the file shown below in the root of every disk:&lt;br /&gt;&lt;X&gt;:\autorun.inf&lt;br /&gt;&lt;br /&gt;This file will launch the worm's executable file each time Explorer is used to open the infected disk.&lt;br /&gt;Payload&lt;br /&gt;&lt;br /&gt;When launching, the worm injects its code into the address space of one of the “svchost.exe” system processes. (The worm may also write its code to the “explorer.exe” and “services.exe” processes.) This code delivers the worm's main malicious payload and:&lt;br /&gt;&lt;br /&gt;   1. disables the following services:&lt;br /&gt;&lt;br /&gt;      Windows Automatic Update Service (wuauserv) &lt;br /&gt;      Background Intelligent Transfer Service (BITS) &lt;br /&gt;      Windows Security Center Service (wscsvc) &lt;br /&gt;      Windows Defender Service (WinDefend, WinDefender) &lt;br /&gt;      Windows Error Reporting Service (ERSvc) &lt;br /&gt;      Windows Error Reporting Service (WerSvc) &lt;br /&gt;&lt;br /&gt;   2. blocks access to addresses which contain any of the strings listed below:&lt;br /&gt;&lt;br /&gt;      nai &lt;br /&gt;      ca &lt;br /&gt;      avp &lt;br /&gt;      avg &lt;br /&gt;      vet &lt;br /&gt;      bit9 &lt;br /&gt;      sans &lt;br /&gt;      cert &lt;br /&gt;      windowsupdate&lt;br /&gt;      wilderssecurity&lt;br /&gt;      threatexpert&lt;br /&gt;      castlecops&lt;br /&gt;      spamhaus&lt;br /&gt;      cpsecure&lt;br /&gt;      arcabit&lt;br /&gt;      emsisoft&lt;br /&gt;      sunbelt&lt;br /&gt;      securecomputing&lt;br /&gt;      rising&lt;br /&gt;      prevx&lt;br /&gt;      pctools&lt;br /&gt;      norman&lt;br /&gt;      k7computing&lt;br /&gt;      ikarus&lt;br /&gt;      hauri&lt;br /&gt;      hacksoft&lt;br /&gt;      gdata&lt;br /&gt;      fortinet&lt;br /&gt;      ewido&lt;br /&gt;      clamav&lt;br /&gt;      comodo&lt;br /&gt;      quickheal&lt;br /&gt;      avira&lt;br /&gt;      avast&lt;br /&gt;      esafe&lt;br /&gt;      ahnlab&lt;br /&gt;      centralcommand&lt;br /&gt;      drweb&lt;br /&gt;      grisoft&lt;br /&gt;      eset&lt;br /&gt;      nod32&lt;br /&gt;      f-prot&lt;br /&gt;      jotti&lt;br /&gt;      kaspersky&lt;br /&gt;      f-secure&lt;br /&gt;      computerassociates&lt;br /&gt;      networkassociates&lt;br /&gt;      etrust&lt;br /&gt;      panda&lt;br /&gt;      sophos&lt;br /&gt;      trendmicro&lt;br /&gt;      mcafee&lt;br /&gt;      norton&lt;br /&gt;      symantec&lt;br /&gt;      microsoft&lt;br /&gt;      defender&lt;br /&gt;      rootkit&lt;br /&gt;      malware&lt;br /&gt;      spyware&lt;br /&gt;      virus&lt;br /&gt;&lt;br /&gt;In Windows Vista, the worm will disable autoconfiguration of the TCP/IP stack in order to speed up propagation via network channels by using a fixed window size for TCP packets:&lt;br /&gt;netsh interface tcp set global autotuning=disabled&lt;br /&gt;&lt;br /&gt;The worm also hooks the following API calls (dnsrslvr.dll) in order to block access to the list of user domains:&lt;br /&gt;&lt;br /&gt;DNS_Query_A &lt;br /&gt;DNS_Query_UTF8 &lt;br /&gt;DNS_Query_W &lt;br /&gt;Query_Main &lt;br /&gt;sendto &lt;br /&gt;&lt;br /&gt;The worm may also download files from links of the type shown below:&lt;br /&gt;http://&lt;URL&gt;/search?q=&lt;%rnd2%&gt;&lt;br /&gt;&lt;br /&gt;rnd2 is a random number; URL is a link generated by a special algorithm which uses the current date. The worm gets the current date from one of the sites shown below:&lt;br /&gt;&lt;br /&gt;http://www.w3.org&lt;br /&gt;http://www.ask.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.yahoo.com&lt;br /&gt;http://www.google.com&lt;br /&gt;http://www.baidu.com &lt;br /&gt;http://www.myspace.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.ebay.com&lt;br /&gt;http://www.cnn.com&lt;br /&gt;http://www.aol.com &lt;br /&gt;&lt;br /&gt;Downloaded files are saved to the Windows system directory under their original names.&lt;br /&gt;Removal instructions&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus solution, or does not have an antivirus solution at all, you can either use a special removal tool (which can be found here or follow the instructions below:&lt;br /&gt;More details about the vulnerability can be found here:&lt;br /&gt;http://www.kaspersky.ru/support/wks6mp3/error?qid=208636215&lt;br /&gt;&lt;br /&gt;Or follow the instructions below:&lt;br /&gt;&lt;br /&gt;   1. Delete the following system registrykey:&lt;br /&gt;      [HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;   2. Delete “%System%\&lt;rnd&gt;.dll” from the system registry key value shown below:&lt;br /&gt;      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]&lt;br /&gt;      "netsvcs"&lt;br /&gt;   3. Revert the following registry key values:&lt;br /&gt;      [HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;      "Hidden" = "dword: 0x00000002"&lt;br /&gt;      "SuperHidden" = "dword: 0x00000000"&lt;br /&gt;&lt;br /&gt;      to&lt;br /&gt;      [HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;      "Hidden" = "dword: 0x00000001"&lt;br /&gt;      "SuperHidden" = "dword: 0x00000001"&lt;br /&gt;      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]&lt;br /&gt;      "CheckedValue" = "dword: 0x00000000"&lt;br /&gt;&lt;br /&gt;      to&lt;br /&gt;      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]&lt;br /&gt;      "CheckedValue" = "dword: 0x00000001"&lt;br /&gt;   4. Reboot the computer.&lt;br /&gt;   5. Delete the original worm file (the location will depend on how the program originally penetrated the victim machine).&lt;br /&gt;   6. Delete copies of the worm:&lt;br /&gt;&lt;br /&gt;      %System%\&lt;rnd&gt;dir.dll&lt;br /&gt;      %Program Files%\Internet Explorer\&lt;rnd&amp;gt.dll &lt;br /&gt;      %Program Files%\Movie Maker\&lt;rnd&gt;.dll&lt;br /&gt;      %All Users Application Data%\&lt;rnd&gt;.dll &lt;br /&gt;      %Temp%\&lt;rnd&gt;.dll &lt;br /&gt;      %System%\&lt;rnd&gt;tmp &lt;br /&gt;      %Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;&lt;br /&gt;      &lt;rnd&gt; is a random string of symbols.&lt;br /&gt;   7. Delete the files shown below from all removable storage media:&lt;br /&gt;      &lt;X&gt;:\autorun.inf&lt;br /&gt;      &lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;-&lt;br /&gt;      %d%&gt;\&lt;rnd&gt;.vmx,&lt;br /&gt;   8. Download and install updates for the operating system:&lt;br /&gt;      http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.viruslist.com&lt;/span&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4942455762033289649?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4942455762033289649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4942455762033289649'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2009/01/net-wormwin32kidofx.html' title='Net-Worm.Win32.Kido.fx'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5068593905350591484</id><published>2008-12-24T23:20:00.000-08:00</published><updated>2008-12-24T23:21:20.206-08:00</updated><title type='text'>How to Recover From a Virus Attack</title><content type='html'>If your business has suffered a virus attack and your network has been compromised, you'll need to act fast in order to prevent the virus from spreading to other computers on your network. Once a virus penetrates your security defenses, it can quickly rip through your network, destroying files, corrupting data, rendering applications useless and causing expensive lulls in productivity. The following recommendations will help you quickly get your small business back up and running again.&lt;br /&gt;&lt;br /&gt;    * Disconnect and isolate. If you suspect one of your computers has suffered a virus attack, immediately quarantine the computer by physically disconnecting it, as infected machines pose a danger to all other computers connected to the network. If you suspect other computers may be infected, even if they aren't displaying any symptoms, still treat them like they are. It's counter-productive to clean one machine while an infected computer is still connected to the network.&lt;br /&gt;&lt;br /&gt;    * Focus on the cleanup. Once you've physically disconnected the computer, focus on removing the malicious code. Use virus removal tools written for the specific virus causing the damage. Many of these tools can be found online. In addition, your antivirus software should have updates or patches available for the specific security threat. If your antivirus software hasn't been updated recently, be sure to do so.&lt;br /&gt;&lt;br /&gt;    * Reinstall your operating system. After a virus attack, damages may range from changed file names and obliterated files to permanently disabled software applications. The extent of the damage depends on the particular virus. If your operating system is completely destroyed, you'll need to reinstall your operating system by using the quick restore CD that came with your computer. This will restore your computer to its original configuration, meaning you'll lose any applications you may have installed or data files you may have saved. So before you begin the reinstallation process, make sure you have all the necessary information handy, including the original software, licenses, registration and serial numbers.&lt;br /&gt;&lt;br /&gt;    * Restore your data. This assumes you've been diligent about backing up your files. If you haven't been doing a regular backup of all the data and files on your computer's hard drive, your files will most likely be permanently lost. If this is the case, learn from your mistake and make sure to back up on a regular, ongoing basis. And keep in mind, not all viruses target data files. Some only attack applications.&lt;br /&gt;&lt;br /&gt;    * Scan for viruses. After restoring and reinstalling, perform a thorough virus scan of your network. Use the most recent virus definitions available for your antivirus software. Be careful not to overlook anything; scan all files and documents on all computers and servers on your network.&lt;br /&gt;&lt;br /&gt;    * Prevent future attacks. Run antivirus software and keep virus definitions current. Make sure your security patches are up-to-date. And if you haven't been running antivirus software, start doing so immediately to prevent future attacks. Also, if you lost data files in the recent attack, create and enforce a regular backup schedule. Change all of your passwords, including ISP access passwords, FTP, email and Web site passwords. Some viruses can capture or crack passwords, leading to future vulnerabilities. By changing your passwords, you'll be able to boost your security.&lt;br /&gt;&lt;br /&gt;Above all, learn from your mistakes. If a virus penetrated your defenses, consider changing or enhancing your current security practices. Ask yourself why your previous security measures weren't effective. Did you need a firewall? Were you lax about updating virus definitions and security patches? Did you download files without scanning them first? Now is an ideal time to comb through, edit and reinforce your IT security policy, as you'll need to shore up the holes in your security practices. After all, prevention is always the best security policy. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source:&lt;br /&gt;http://www.thestreet.com/_googlen/smallbiz/entrepreneur&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5068593905350591484?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5068593905350591484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5068593905350591484'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/how-to-recover-from-virus-attack.html' title='How to Recover From a Virus Attack'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4153341262317654986</id><published>2008-12-24T23:19:00.000-08:00</published><updated>2008-12-24T23:20:34.378-08:00</updated><title type='text'>Malware Removal and Prevention</title><content type='html'>There are a variety of reasons you may have arrived at Malware Removal and Prevention (MRP). If you are here to do a thorough system cleaning or just a checkup, then MRP will guide you through that process. Perhaps your computer is showing symptoms of infection: Popup ads, general sluggishness, or browser redirects, to a name a few. If that is the case, MRP will offer you a good chance at restoring your system to normalcy.&lt;br /&gt;&lt;br /&gt;You may well have been instructed to complete Malware Removal before posting a HijackThis (HJT) log. HJT is a program which scans your system and allows you to create a log or report at the end of its analysis. The log created by the HJT lists many places on your computer that spyware and malware are known to target. The HJT staff are trained to interpret your HJT log and provide instructions which you can follow to repair your system.&lt;br /&gt;&lt;br /&gt;Before posting your HijackThis log, we will have you run several malware removal programs and a system cleanup utility.HJT is an analysis and repair tool. It will not scan your entire system nor will it detect or delete all the files and registry entries associated with an infection. As such, it is extremely important to use the full system scanning tools we recommend before fixing anything with HJT. These automatic detection and removal programs address a broad spectrum of malware including adware, spyware, trojans, worms, viruses, and browser hijackers. We also advise you to run a system cleaning utility intended to improve your computer's overall performance and remove any infected files which may be hiding in your temporary folders.&lt;br /&gt;&lt;br /&gt;This new preliminary scanning procedure will provide a dual benefit: Your computer will benefit from the thorough cleaning it provides. We in return, will benefit from being presented with a cleaner system profile containing only those infections which the automatic removal programs failed to eradicate.&lt;br /&gt;&lt;br /&gt;It is possible that you may not even need to post a HijackThis log after completing the scans we suggest. If you are satisfied with your computer's performance, and feel your system is no longer infected, then you may decide to take that option. If that is the case, it is vitally important that you implement the safety suggestions presented in our Malware Prevention section to maintain your continued security. However, if you still feel that your system is infected or hijacked after completing the entire malware removal process, we invite you to post a log on the HijackThis forum.&lt;br /&gt;&lt;br /&gt;Your compliance with this precleaning requirement, will allow the HijackThis staff to clean your infected machine much more efficiently. The resultant time savings will enable us to attend to a greater number of logs in a shorter period of time, thereby benefiting everyone involved.&lt;br /&gt;&lt;br /&gt;Please follow all directions carefully. If at any point you need some sort of clarification, please, please, please ask us! As applicable, we have included links to the appropriate CastleCops forums. Finally, we would very much appreciate your feedback. Praise, suggestions, complaints, ... anything goes! &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Source:&lt;br /&gt;http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4153341262317654986?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4153341262317654986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4153341262317654986'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/malware-removal-and-prevention.html' title='Malware Removal and Prevention'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2308170893136476874</id><published>2008-12-24T23:18:00.000-08:00</published><updated>2008-12-24T23:19:39.308-08:00</updated><title type='text'>Anti-Virus Guide</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Important Tips&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Watch Out -- Do not buy or download any antivirus software without checking this list first: The 69 Worst Antivirus Scanners, Mary Landesman, antivirus.about.com, September 15, 2008.&lt;br /&gt;    * Just One, Not Two -- Never use two anti-virus products at the same time. Completely uninstall one before installing another. Use the vendor's uninstall utility or if not available, use the Windows XP add/remove software tool in the control panel.&lt;br /&gt;    * Patches &amp; Updates -- Anti-virus software is only as effective as its most recent update because it is inherently reactive treating "known" threats. So when you install anti-virus software, go to the vendor's web site and update the program and virus definitions immediately and then turn on the auto update feature (if it has one). If you want to be ready for the next big bad thing before your anti-virus signatures can be updated, consider Zero-Day Protection.&lt;br /&gt;    * Get Online Protection Too -- Consider using an Internet service provider or email service that includes server side anti-virus and spam email filtering as a second layer of defense. If possible, use different anti-virus software on your home computer than your ISP or service uses on their servers.&lt;br /&gt;    * Consider a Gateway -- A Broadband Gateway product between your modem and network can screen out viruses before they hit your computer(s).&lt;br /&gt;    * Spyware &amp; Trojan Horses -- Some anti-virus software products now include anti-spyware and some anti-spyware products have added anti-virus. In addition, some of these products include anti-trojan, anti-worm and other anti-malware features. Before relying on a single security product, carefully review the vendor's list of features and study comparative test results if available. See Editorial - Do you really need a spyware scanner? Gizmo Richards' Support Alert Newsletter, April 17, 2008. Also see our Security Suite, Anti-Spyware, Anti-Trojan and Zero-Day Protection pages.&lt;br /&gt;    * Prices -- See our custom Anti-Virus Price List powered by Amazon.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://www.firewallguide.com&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2308170893136476874?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2308170893136476874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2308170893136476874'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/anti-virus-guide.html' title='Anti-Virus Guide'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3218367782534524211</id><published>2008-12-24T23:16:00.000-08:00</published><updated>2008-12-24T23:17:49.639-08:00</updated><title type='text'>Using virus protection features in Outlook Express 6</title><content type='html'>Using Internet Explorer Security Zone to Disable Active Content in Hypertext Markup Language (HTML) E-mail&lt;br /&gt;Security zones enable you to choose whether active content, such as ActiveX Controls and scripts, can be run from inside HTML e-mail messages in Outlook Express. By default, Outlook Express 6 uses the Restricted Zone instead of the Internet Zone. Microsoft Outlook Express 5.0 and Microsoft Outlook Express 5.5 used the Internet zone, which enable most active content to run. To customize your Internet Explorer security zone settings for Outlook Express:&lt;br /&gt;&lt;br /&gt;CAUTION: Changing security zone settings can expose your computer to potentially damaging code. Use caution when you change these settings.&lt;br /&gt;&lt;br /&gt;   1. Start Outlook Express, and then on the Tools menu, click Options.&lt;br /&gt;   2. Click the Security tab, and then click either Restricted Sites Zone or Internet Zone (less secure, but more functional) in the Virus Protection section under Select the Internet Explorer security zone to use.&lt;br /&gt;   3. Click OK to close the Options dialog box, and then quit Outlook Express.&lt;br /&gt;   4. Start Internet Explorer, click Internet Options on the Tools menu, and then click Security.&lt;br /&gt;   5. Click Custom Level for the security zone that you selected in Outlook Express. The security settings that you choose apply to Outlook Express as well as Internet Explorer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to Read all Messages in Plain Text (Service Pack 1 Only)&lt;/span&gt;&lt;br /&gt;Starting with Service Pack 1, you can configure Outlook Express to read all e-mail in plain text format. Some HTML e-mail may not appear correctly in plain text, but no active content in the e-mail is run when you enable this setting. To read all messages as plain text in Outlook Express Service Pack 1:&lt;br /&gt;&lt;br /&gt;   1. Start Outlook Express, and then on the Tools menu, click Options.&lt;br /&gt;   2. Click the Read tab, and then click to select the Read all messages in plain text check box under Reading Messages.&lt;br /&gt;   3. Click OK&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to Prevent Programs from Sending E-mail Without Your Approval&lt;/span&gt;&lt;br /&gt;If you configure Outlook Express as the default mail handler (or simple MAPI client) on the General tab, Outlook Express processes requests by using Simple MAPI calls. Some viruses can use this functionality and spread by sending copies of e-mail messages that contain the virus to your contacts. By default, Outlook Express 6 prevents e-mail messages from being sent programmatically from Outlook Express without your knowledge by displaying a dialog that enables you to send or not to send the e-mail message.&lt;br /&gt;&lt;br /&gt;Using the Internet Explorer Unsafe File List to Filter E-mail Attachments&lt;br /&gt;To use the Internet Explorer unsafe file list to filter e-mail attachments:&lt;br /&gt;&lt;br /&gt;   1. Start Outlook Express, and then on the Tools menu, click Options.&lt;br /&gt;   2. Click the Security tab, and then click to select the Do not allow attachments to be saved or opened that could potentially be a virus check box under Virus Protection.&lt;br /&gt;&lt;br /&gt;This option is enabled by default in Outlook Express Service Pack 1 (SP1). If you enable this option, Outlook Express uses the Internet Explorer 6 unsafe file list and the Confirm open after download setting in Folder Options to determine whether a file is safe. Any e-mail attachment with a file type reported as "unsafe" is blocked from being downloaded.&lt;br /&gt;&lt;br /&gt;NOTE: The Internet Explorer 6 unsafe file list includes any file types that may have script or code associated with them. To add additional file types to be blocked or remove file types that should not be blocked:&lt;br /&gt;&lt;br /&gt;   1. Click Start, point to Settings (or click Control Panel), and then click Control Panel (or switch to Classic View or View All Control Panel Options).&lt;br /&gt;   2. Double-click Folder Options.&lt;br /&gt;   3. On the File Types tab, click to select the file type that you want to block or allow, and then click Advanced. If the file type you want to add is not listed, perform the following steps:&lt;br /&gt;         1. Click New.&lt;br /&gt;         2. In the Create New Extension dialog box, type the file extension you want to add to the unsafe file list.&lt;br /&gt;         3. Click OK, and then click Advanced.&lt;br /&gt;   4. Click to place a check mark (block) or remove the check mark (allow) from the Confirm open after download check box.&lt;br /&gt;&lt;br /&gt;NOTE: You cannot remove the check from Confirm open after download to allow some file types. For example, .exe files are in the default unsafe file list in Internet Explorer and cannot be allowed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to Determine When Outlook Express Has Blocked an Attachment&lt;/span&gt;&lt;br /&gt;When Outlook Express blocks an attachment, the following alert is displayed in the message alert bar at the top of the e-mail message:&lt;br /&gt;Outlook Express removed access to the following unsafe attachments in your mail: file_name1, file_name2, and so on. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://support.microsoft.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3218367782534524211?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3218367782534524211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3218367782534524211'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/using-virus-protection-features-in.html' title='Using virus protection features in Outlook Express 6'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7884317677112252054</id><published>2008-12-16T08:13:00.000-08:00</published><updated>2008-12-16T08:15:36.571-08:00</updated><title type='text'>Top 6 Most Effective Tips to Avoid Getting Spam Altogether</title><content type='html'>The best way to avoid spam is not getting on spammers' lists in the first place. Find out how to use disposable addresses, obfuscation and your watchful eye to steer clear of spam altogether.&lt;br /&gt;Already Getting Spam?&lt;br /&gt;&lt;br /&gt;If you already get spam, try filtering the existing:&lt;br /&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Best Free Windows Spam Filters&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Top Mac Spam Filters&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Linux and Unix Spam Filters&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Spam Filtering Services&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;More Spam Fighting Tips&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;1. Stop Spam with Disposable Email Addresses&lt;/span&gt;&lt;br /&gt;You've read it here, and you know it well: using your real, primary email address anywhere on the Web puts it at risk of being picked up by spammers. And once an email address is in the hands of one spammer, your Inbox is sure to be filled with lots of not-so-delicious spam every day. But what should you use instead of a real email address? Use...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;2. Watch Out for Those Checkboxes&lt;/span&gt;&lt;br /&gt;When you sign up for something on the Web, there is often some innocent-looking text at the end of the form saying something like: "YES, I want to be contacted by select third parties concerning products I might be interested in." Quite often, the checkbox next to that text is already checked and your email address will be given to you don't know who. To avoid that...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;3. Disguise Your Email Address in Newsgroups, Forums, Blog Comments, Chat&lt;/span&gt;&lt;br /&gt;Spammers use special programs that extract email addresses from Web sites and Usenet postings. To avoid ending on a spammer's mailing list when you post to a Web forum or a newsgroup, you can...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;4. How Long, Complicated Email Addresses Beat Spammers&lt;/span&gt;&lt;br /&gt;Spam will, eventually, make it to any mailbox. Any? Here's how to make it hard for spammers to guess your address.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;5. Use Disposable Email Addresses at Your Web Site&lt;/span&gt;&lt;br /&gt;Using disposable email addresses in forms on the Web and for mailing lists is a great way to stop spam. But with a little effort you can even use them on your home page, too, and allow legitimate mail from unknown senders while keeping out spam...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;6. Domain Owners: Set up Throwaway Addresses to Fight Spam&lt;/span&gt;&lt;br /&gt;If you own a domain name, you have a great anti-spam tool at hand: your mail server. All mail to a address at your domain that does not already exist (such as "quaxidudel@example.com") is forwarded to your main account by default. You can use this feature to...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://email.about.com/od/spamandgettingridofit/tp/most_effective.htm&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7884317677112252054?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7884317677112252054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7884317677112252054'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/top-6-most-effective-tips-to-avoid.html' title='Top 6 Most Effective Tips to Avoid Getting Spam Altogether'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4722002706583171564</id><published>2008-12-16T08:11:00.000-08:00</published><updated>2008-12-16T08:12:34.812-08:00</updated><title type='text'>Manual Removal of W32/OnLineGames.TRQA Trojan</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Manual Removal of W32/OnLineGames.TRQA Trojan&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;W32/OnLineGames.TRQA is a Trojan&lt;/span&gt;. The trojan will infect Windows systems.&lt;br /&gt;The trojan may be dropped by other malware or may be downloaded from remote website by other malware.&lt;br /&gt;This trojan first appeared on December 12, 2008.Other names of W32/OnLineGames.TRQA Trojan:&lt;br /&gt;This trojan is also known as GameThief.Win32.OnLineGames.trqa, TSPY_MMORPG.CE.&lt;br /&gt;Damage Level : High/ Medium&lt;br /&gt;Distribution Level: High/ Medium&lt;br /&gt;There is NO Auto Removal Tool for W32/OnLineGames.TRQA Trojan&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Trojan Manual Removal Instructions&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Recommend Removal from Safe Mode:&lt;/span&gt;&lt;br /&gt;How to Start in Safe mode:&lt;br /&gt;Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.&lt;br /&gt;The Infected Files Can be Seen in these folders and names also Running in Tasks&lt;br /&gt;End the Following Active Process Before Removal&lt;br /&gt;&lt;br /&gt;    * %System32%\msupdt.exe&lt;br /&gt;      If you have any of these files in running process from task manger, end the process before removal.&lt;br /&gt;      Note: if task manager is disabled, Download the following file, Click to Download - Enable Registry.reg&lt;br /&gt;&lt;br /&gt;Manually Remove From Registry &lt;br /&gt;Click Start, Run,Type regedit,Click OK.&lt;br /&gt;Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Download and run this UnHookExec.inf, and then continue with the removal.&lt;br /&gt;Registry Entries are Unknown&lt;br /&gt;_+ Any of the Above Listed Files +_&lt;br /&gt;Search Registry For Virus File Names listed above to remove completely,&lt;br /&gt;Edit Menu - Find, enter Keyword and remove all value that find in search.&lt;br /&gt;Exit the Registry Editor,&lt;br /&gt;Restart your Computer.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Recommended Removal Tools:&lt;br /&gt;Kaspersky Antivirus or Internet Security (Shareware)&lt;br /&gt;Spyware Doctor (Shareware)&lt;br /&gt;AVG Antivirus (Freeware)&lt;br /&gt;Killbox (Freeware)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Source: http://www.windowsvistaplace.com/manual-removal-of-w32onlinegamestrqa-trojan/windows&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4722002706583171564?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4722002706583171564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4722002706583171564'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/manual-removal-of-w32onlinegamestrqa.html' title='Manual Removal of W32/OnLineGames.TRQA Trojan'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5630823098665364363</id><published>2008-12-16T08:07:00.000-08:00</published><updated>2008-12-16T08:09:28.607-08:00</updated><title type='text'>XoftSpy Software Trojan Remover</title><content type='html'>&lt;span style="font-weight:bold;"&gt;XoftSpy&lt;/span&gt; offers a couple extremely useful features including &lt;span style="font-weight:bold;"&gt;Trojan.Vundo removal&lt;/span&gt; which allows you to remove this pop-up trojan virus which displays multiple pop up advertisements on your Internet Explorer browser.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;XoftSpy&lt;/span&gt; will remove the following trojans:&lt;br /&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse Generic8.ODJ&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse dropper.generic.OAC&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse BackDoor.Generic9.ACJW&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse Generic - c.EQ - INFECTED&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan Horse Generic&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse Dropper.Delf.3.L&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse proxy.BUF&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse flooder.ake&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan Horse Psw&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse Generic9.AAVJ&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan Horse Generic 10 FX&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan Horse Small 28 AU&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Trojan horse Downloader.Small.18.T&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;XoftSpy&lt;/span&gt; alsos offer email protection, and will protect your computer from harmful .exe attachments that are actually trojans trying to allow hackers to gain access to your computer and display frustrating Pop-Up advertisements to more serious hacker threats.&lt;br /&gt;&lt;br /&gt;Spyware is a serious threat and careful consideration should be taken to ensure the right choice for your particular situation. You can consult the reviews below to make certain you find the right solution for your spyware problems.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://spywareremovercompare.blogspot.com/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5630823098665364363?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5630823098665364363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5630823098665364363'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/xoftspy-software-trojan-remover.html' title='XoftSpy Software Trojan Remover'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6468524715292439066</id><published>2008-12-16T08:01:00.000-08:00</published><updated>2008-12-16T08:06:38.341-08:00</updated><title type='text'>Win32 Trojan Virus - How to Remove</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Trojan.Win32&lt;/span&gt; is a file installed by rogue anti-spyware program. This is caused by a malicious software engineered by internet hackers which when installed generates a pop up message. This is a fake message informing you to purchase their "anti spyware" in order to remove the trojan.&lt;br /&gt;&lt;br /&gt;The following manual process will help you remove it from your system safely.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Trojan.Win32 Manual Removal Process:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. First, Click on the Start Menu button followed by the Control Panel option. Then Double-click on the Add or Remove Programs icon.&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight:bold;"&gt;Locate Trojan.Win32&lt;/span&gt; and double-click on it to uninstall Trojan.Win32. Follow the screen step-by-step screen instructions provided to you to complete uninstallation of Trojan.Win32.&lt;br /&gt;&lt;br /&gt;3. Restart the computer.&lt;br /&gt;&lt;br /&gt;4. After the un-installation process has completed, close "Add or Remove Programs" and your Control Panel.&lt;br /&gt;&lt;br /&gt;5. Close all programs.&lt;br /&gt;&lt;br /&gt;6. Stop Trojan.Win32 process. You can do this by&lt;br /&gt;&lt;br /&gt;   - Right-click the taskbar, and then click Task Manager .&lt;br /&gt;&lt;br /&gt;   - In Task Manager , click the Processes tab to see a list of running processes.&lt;br /&gt;&lt;br /&gt;   - Select the process that you want to stop.&lt;br /&gt;&lt;br /&gt;   - Right-click on the intended process, then select "End task".&lt;br /&gt;&lt;br /&gt;   - Done.&lt;br /&gt;&lt;br /&gt;7. Search for the following files and delete these infected files from your system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;windivx.dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;stream32a.dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;vipextqtr.dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ecxwp.dll&lt;br /&gt;&lt;br /&gt;8. Rename the files that you found above to "foundbadfile1.dll" and "foundbadfile2.dll" (if you can not rename this file, then try to restart your computer in safe mode then try to rename this file.)&lt;br /&gt;&lt;br /&gt;9. Go to C:\Program Files\ folder and delete the "VirusProtect 3.8? folder (if you can't delete it, reboot your computer to safe mode then delete the folder)&lt;br /&gt;&lt;br /&gt;10. Restart your computer&lt;br /&gt;&lt;br /&gt;11. Go to your computer and delete the "foundbadfile1.dll" and "foundbadfile2.dll" file&lt;br /&gt;&lt;br /&gt;13. You have just &lt;span style="font-weight:bold;"&gt;removed Trojan.Win32&lt;/span&gt; from your computer manually.&lt;br /&gt;&lt;br /&gt;The easier way is to get a reputable anti trojan program, that removes Win32 Trojan Virus as well as detects intrusions from other worse trojans, such as credit card and password stealing trojans.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6468524715292439066?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6468524715292439066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6468524715292439066'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/win32-trojan-virus-how-to-remove.html' title='Win32 Trojan Virus - How to Remove'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7313422469844356108</id><published>2008-12-15T09:37:00.000-08:00</published><updated>2008-12-15T09:39:11.387-08:00</updated><title type='text'>Virus Di Tahun 2008</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Sang Perawan&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sang Perawan pada dua bulan pertama tahun 2008 mencatat kesuksesan besar dalam penyebarannya karena tidak terdeteksi oleh antivirus. Norman Virus Control mendeteksi Sang Perawan sebagai W32/VBWorm.GZH sejak bulan Juli 2007. Virus yang lebih populer dikenal dengan nama W32/Dewi atau Sang Perawan dan mengganas pada bulan Februari 2008 ini memiliki ciri khas menginjeksi file gambar berformat JPEG (Joint Photographics Expert Group). Dua varian Sang Perawan yang ditemukan ini masing-masing memiliki ukuran asli sebesar 301 KB dan 91 KB (lihat gambar 1). Karena itu, file JPEG yang di injeksi kedua virus ini akan berubah menjadi.EXE dan bertambah ukurannya sebesar 301 KB atau 91 KB (tergantung varian yang menginfeksi) dan celakanya, file JPEG tersebut menjadi error dan tidak bisa dibuka kembali.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Stargate&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;“Jika Ingin Menggapai Mimpi Yang Lebih Indah, Laksanakan dan Kerjakan”. Demikianlah pesan yang muncul setiap kali komputer yang terinfeksi virus Stargate atau W32/Agent.DRUU ini menjalankan Internet Explorer yang akan membuka file St4rgt.html. Stargate akan memalsukan dirinya dengan icon folder dan virus ini termasuk sulit untuk dibersihkan karena ia akan melakukan redirect file eksekusi untuk menjalankan dirinya. Selain itu virus ini juga berusaha melumpuhkan beberapa antivirus sehingga tidak dapat berfungsi dengan baik. Satu hal yang perlu menjadi catatan yang menarik adalah perhatian virus ini pada secpol.msc (Security Policy) dan gpedit.msc (Group Policy Editor) dimana pembuat virus ini secara khusus melakukan pemblokiran pada secpol dan gpedit sehingga akan komputer yang terinfeksi Stargate akan menampilkan pesan error setiap kali menjalankan kedua palikasi di atas.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Hokage&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Bagi anda penggemar Manga, tentunya tahu cerita Naruto. Ninja dari desa Konoha yang berambisi menjadi Hokage (Kepala Suku). Rupanya ada pembuat virus yang juga penggemar Naruto dan selain memalsukan dirinya dengan icon Winamp, merubah icon Flash Disk pada Windows Explorer menjadi icon Winamp, virus ini juga menamai file induknya sebagai “HokageFile.exe”.&lt;br /&gt;Hokage yang di deteksi Norman sebagai VBWorm.gen16 ini juga memiliki kemampuan menginfeksi komputer / Flash Disk secara otomatis dengan memanfaatkan fitur autorun. Virus yang disinyalir berasal dari Kalimantan Tengah/ Sampit ini tidak tanggung-tanggung membuat file autorun.inf, desktop.ini dan folder.htt yang semuanya bertujuan untuk mengeksekusi file dengan nama “Hokagefile.exe” yang merupakan file induk dari virus ini.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;VBS/Repulik (Republik)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Virus yang terdeteksi oleh Norman sebagai VBS/Repulik ini melakukan aksi mirip Kespo menginjeksi file MS Office. Bedanya kalau Kespo mengincar file di komputer, Repulik merubah file MS Office di Flash Disk dan menginjeksinya dengan dirinya. File MS Word dan Excel yang di injeksi akan bertambah ukurannya sebesar 5 KB dan menjadi file virus, tetapi ekstensi file juga berubah menjadi ekstensi ganda. Misalnya file asli memiliki nama dokumen.doc, setelah di injeksi Repulik ukurannya akan bertambah 5 KB dan iconnya akan berubah menjadi VBS (Visual Basic Script) sehingga mudah dikenali.&lt;br /&gt;&lt;br /&gt;Jika file anda di injeksi oleh virus ini, jangan putus asa dulu, karena anda bisa mendapatkan tools mengembalikan file ini di DVD Chip. Jalankan file “Splitter_VBS2DOC_XLS” untuk mengembalikan file asli anda yang telah di injeksi oleh Repulik.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Amburadul&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ibarat lagu “SMS” yang populer sehingga memunculkan lagu “Jawaban SMS”. Pembuat virus Hokage yang berasal dari Sampit memunculkan pembuat virus lain yang juga berasal dari Kalimantan Tengah dan selain berusaha membasmi virus Hokage, virus Amburadul ini juga mempromosikan kota Palangkaraya sebagai tempat wisata dengan menggunakan nama Jembatan Kahayan sebagai nama file virus. Virus yang memalsukan diri sebagai file JPG ini memiliki cukup banyak varian dengan ukuran yang bervariasi, dari 51 KB s/d 56 KB dan terdeteksi oleh Norman sebagai W32/Autorun dan W32/Agent.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source Information: http://vaksin.com/2008/1108/q1/q1.htm&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7313422469844356108?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7313422469844356108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7313422469844356108'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/virus-di-tahun-2008.html' title='Virus Di Tahun 2008'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-9049829536097050458</id><published>2008-12-15T09:27:00.000-08:00</published><updated>2008-12-15T09:36:36.932-08:00</updated><title type='text'>W32/VBWorm.QTT aka Koplaxz Mengacaukan Icon dan type file MS Office</title><content type='html'>Para pengguna komputer Indonesia, khususnya yang memiliki banyak file &lt;span style="font-weight:bold;"&gt;MS Office&lt;/span&gt;, harap berhati-hati karena saat ini sedang menyebar &lt;span style="font-weight:bold;"&gt;virus lokal&lt;/span&gt; dengan target file MS Office dengan cara &lt;span style="font-weight:bold;"&gt;mengganti icon file dan type file&lt;/span&gt;. Virus ini cukup merepotkan (setidaknya menyebabkan jantung anda dag dig dug) tetapi kabar baiknya pembuat virus ini tidak sejahat &lt;span style="font-weight:bold;"&gt;KEspo&lt;/span&gt; sehingga tidak menginjeksi atau menghancurkan file MS Office komputer korbannya.&lt;br /&gt;Virus ini dibuat dengan menggunakan&lt;span style="font-weight:bold;"&gt; Visual Basic&lt;/span&gt;, dengan &lt;span style="font-weight:bold;"&gt;ukuran sekitar 31 KB&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Ciri-ciri Koplaxz&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. Merubah icon Windows dari icon “folder” menjadi icon “Control Panel “ serta merubah isi dari folder Windows tersebut menjadi isi yang ada pada menu “Control Panel”.&lt;br /&gt;2. Merubah Type File serta icon shortcut aplikasi MS.Office&lt;br /&gt;3. Merubah nama pemilik komputer menjadi KUDO_SHOP&lt;br /&gt;4. Merubah “start page” dan “search page” Internet Explorer&lt;br /&gt;&lt;br /&gt;Selengkapnya dapat dibaca di &lt;span style="font-weight:bold;"&gt;http://vaksin.com/2008/1208/koplaxz/koplaxz.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-9049829536097050458?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9049829536097050458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9049829536097050458'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/w32vbwormqtt-aka-koplaxz-mengacaukan.html' title='W32/VBWorm.QTT aka Koplaxz Mengacaukan Icon dan type file MS Office'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7459669684782991153</id><published>2008-12-11T19:12:00.000-08:00</published><updated>2008-12-11T19:15:30.516-08:00</updated><title type='text'>Trojan.PWS.ChromeInject.B</title><content type='html'>&lt;span style="font-weight:bold;"&gt;( Trojan-Spy:W32/Banker.IVX, Win32/Inject.NBT trojan, Troj/Bancos-BEX, TR/Drop.Small.abw )&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It drops an executable file (which is a &lt;span style="font-weight:bold;"&gt;Firefox 3 plugin&lt;/span&gt;) and a JavaScript file (detected by Bitdefender as: &lt;span style="font-weight:bold;"&gt;Trojan.PWS.ChromeInject.A&lt;/span&gt;) into the Firefox plugins and chrome folders respectively.&lt;br /&gt;&lt;br /&gt;It filters the URLs within the Mozilla Firefox browser and whenever encounter the following addresses opened in the Firefox browser it captures the login credentials.&lt;br /&gt;&lt;br /&gt;akbank.com&lt;br /&gt;caixasabadell.net&lt;br /&gt;credem.it&lt;br /&gt;areasegura.banif.es&lt;br /&gt;banca.cajaen.es&lt;br /&gt;openbank.es&lt;br /&gt;poste.it&lt;br /&gt;banesto.es&lt;br /&gt;carnet.cajarioja.es&lt;br /&gt;gruposantander.es&lt;br /&gt;intelvia.cajamurcia.es&lt;br /&gt;net.kutxa.net&lt;br /&gt;bancopastor.es&lt;br /&gt;bancamarch.es&lt;br /&gt;caixamanlleu.es&lt;br /&gt;elmonte.es&lt;br /&gt;ibercajadirecto.com&lt;br /&gt;bancopopular.es&lt;br /&gt;bancogallego.es&lt;br /&gt;bancajaproximaempresas.com&lt;br /&gt;caixa*.es&lt;br /&gt;caja*.es&lt;br /&gt;ccm.es&lt;br /&gt;bancoherrero.com&lt;br /&gt;bankoa.es&lt;br /&gt;bbvanetoffice.com&lt;br /&gt;bgnetplus.com&lt;br /&gt;bv-i.bancodevalencia.es&lt;br /&gt;clavenet.net&lt;br /&gt;fibancmediolanum.es&lt;br /&gt;sabadellatlantico.com&lt;br /&gt;arquia.es&lt;br /&gt;banking.*.de&lt;br /&gt;westpac.com.au&lt;br /&gt;adelaidebank.com.au&lt;br /&gt;pncs.com.au&lt;br /&gt;nationet.com&lt;br /&gt;online.hbs.net.au&lt;br /&gt;www.qccu.com.au&lt;br /&gt;boq.com.au&lt;br /&gt;banksa.com&lt;br /&gt;anz.com&lt;br /&gt;suncorpmetway.com.au&lt;br /&gt;quiubi.it&lt;br /&gt;cariparma.it&lt;br /&gt;bancaintesa.it&lt;br /&gt;popso.it&lt;br /&gt;fmbcc.bcc.it&lt;br /&gt;secservizi.it&lt;br /&gt;bancamediolanum.it&lt;br /&gt;csebanking.it&lt;br /&gt;fineco.it&lt;br /&gt;gbw2.it&lt;br /&gt;gruppocarige.it&lt;br /&gt;in-biz.it&lt;br /&gt;isideonline.it&lt;br /&gt;iwbank.it&lt;br /&gt;bancaeuro.it&lt;br /&gt;bancagenerali.it&lt;br /&gt;bcp.it&lt;br /&gt;unibanking.it&lt;br /&gt;uno-e.com&lt;br /&gt;unipolbanca.it&lt;br /&gt;carifvg.com&lt;br /&gt;cariparo.it&lt;br /&gt;carisbo.it&lt;br /&gt;islamic-bank.com&lt;br /&gt;banking.first-direct.com&lt;br /&gt;natwestibanking.com&lt;br /&gt;itibank.co.uk&lt;br /&gt;co-operativebank.co.uk&lt;br /&gt;lloydstsb.co.uk&lt;br /&gt;mybankoffshore.alil.co.im&lt;br /&gt;abbeynational.co.uk&lt;br /&gt;mybusinessbank.co.uk&lt;br /&gt;barclays.com&lt;br /&gt;online.co.uk&lt;br /&gt;my.if.com&lt;br /&gt;anbusiness.com&lt;br /&gt;hsbc.co&lt;br /&gt;anbusiness.com&lt;br /&gt;co-operativebankonline.co.uk&lt;br /&gt;halifax-online.co.uk&lt;br /&gt;ibank.cahoot.com&lt;br /&gt;smile.co.uk&lt;br /&gt;caterallenonline.co.uk&lt;br /&gt;tdcanadatrust.com&lt;br /&gt;schwab.com&lt;br /&gt;wachovia.com&lt;br /&gt;bankofamerica&lt;br /&gt;kfhonline.com&lt;br /&gt;wamu.com&lt;br /&gt;wellsfargo.com&lt;br /&gt;procreditbank.bg&lt;br /&gt;chase.com&lt;br /&gt;53.com&lt;br /&gt;citizensbankonline.com&lt;br /&gt;e-gold.com&lt;br /&gt;paypal.com&lt;br /&gt;usbank.com&lt;br /&gt;suntrust.com&lt;br /&gt;banquepopulaire.fr&lt;br /&gt;onlinebanking.nationalcity.com&lt;br /&gt;&lt;br /&gt;It is the first malware that targets Firefox. The filtering is done by a JavaScript file running in Firefox's chrome environment.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal instructions:&lt;/span&gt;&lt;br /&gt;Close the Firefox browser (if opened).&lt;br /&gt;Please let &lt;span style="font-weight:bold;"&gt;BitDefender&lt;/span&gt; disinfect your files.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;http://www.bitdefender.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7459669684782991153?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7459669684782991153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7459669684782991153'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/trojanpwschromeinjectb.html' title='Trojan.PWS.ChromeInject.B'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5160970267409574264</id><published>2008-12-10T18:22:00.000-08:00</published><updated>2008-12-10T18:23:53.427-08:00</updated><title type='text'>Windows Defender detects and removes spyware</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Windows Defender detects and removes spyware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Windows Defender&lt;/span&gt; is software that helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer. Windows Defender features Real-Time Protection, a monitoring system that recommends actions against spyware when it's detected, minimizes interruptions, and helps you stay productive.&lt;br /&gt;&lt;br /&gt;The benefits of installing &lt;span style="font-weight:bold;"&gt;Windows Defender&lt;/span&gt; include:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Spyware detection and removal&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Windows Defender quickly and easily finds spyware and other unwanted programs that can slow down your computer, display annoying pop-up ads, change Internet settings, or use your private information without your consent.&lt;br /&gt;    * Windows Defender eliminates detected spyware easily at your direction, and if you inadvertently remove programs that you actually want, it's easy to get them back.&lt;br /&gt;    * Windows Defender allows you to schedule your scanning and removal times when it's convenient for you, whether it's on-demand or on a schedule that you set.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Improved Internet browsing safety&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Windows Defender helps stop spyware before it infiltrates your computer. Windows Defender also offers a continuous safeguard designed to target all the ways that spyware can infiltrate your computer.&lt;br /&gt;    * Windows Defender works without distracting you. It runs in the background and automatically handles spyware based on preferences that you set. You can use your computer with minimal interruption.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Protection against the latest threats&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * A dedicated team of Microsoft researchers continuously searches the Internet to discover new spyware and develop methods to counteract it.&lt;br /&gt;    * A voluntary, worldwide network of Windows Defender users helps Microsoft determine which suspicious programs to classify as spyware. Participants help discover new threats quickly and notify Microsoft analysts, so that everyone is better protected. Anyone who uses Windows Defender can join this network and help report potential spyware to Microsoft.&lt;br /&gt;    * To help protect your computer from the latest threats, you can choose to have updates that counteract new spyware automatically downloaded to your computer.&lt;br /&gt;&lt;br /&gt;Windows Defender is included with all versions of &lt;span style="font-weight:bold;"&gt;Windows Vista&lt;/span&gt; and is available to download for genuine copies of &lt;span style="font-weight:bold;"&gt;Windows XP Service Pack 2 or later&lt;/span&gt;, or &lt;span style="font-weight:bold;"&gt;Windows Server 2003 Service Pack 1 or later&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5160970267409574264?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5160970267409574264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5160970267409574264'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/windows-defender-detects-and-removes.html' title='Windows Defender detects and removes spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3678983000676616895</id><published>2008-12-10T18:17:00.000-08:00</published><updated>2008-12-10T18:21:09.397-08:00</updated><title type='text'>How to help prevent spyware</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Spyware&lt;/span&gt; and other &lt;span style="font-weight:bold;"&gt;unwanted software&lt;/span&gt; can invade your privacy, bombard you with pop-up windows, slow down your computer, and even make your computer crash. Here are several ways you can help protect your computer against spyware and other unwanted software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 1: Use a firewall&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;While most spyware and other unwanted software come bundled with other programs or originate from unscrupulous Web sites, a small amount of spyware can actually be placed on your computer remotely by hackers. Installing a firewall or using the firewall that's built into Windows XP provides a helpful defense against these hackers.&lt;br /&gt;&lt;br /&gt;To learn more about firewalls, read Why you should use a computer firewall and get answers to your Frequently asked questions about firewalls.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 2: Update your software&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If you use Windows XP, one way to help prevent spyware and other unwanted software is to make sure all your software is updated. Visit Microsoft Update to confirm that you have Automatic Updates turned on and that you've downloaded all the latest critical and security updates.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 3: Adjust Internet Explorer security settings&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You can adjust your Internet Explorer Web browser's security settings to determine how much—or how little—information you are willing to accept from a Web site. Microsoft recommends that you set the security settings for the Internet zone to Medium or higher.&lt;br /&gt;&lt;br /&gt;To view your current Internet Explorer security settings:&lt;br /&gt;&lt;br /&gt;1. In Internet Explorer, click Tools and then click Internet Options.&lt;br /&gt;&lt;br /&gt;2. Select the Security tab.&lt;br /&gt;&lt;br /&gt;For a step-by-step guide to adjusting your settings without blocking content from sites that you trust, see Working with Internet Explorer 6 Security Settings.&lt;br /&gt;&lt;br /&gt;If you're running &lt;span style="font-weight:bold;"&gt;Windows XP Service Pack 2 (SP2)&lt;/span&gt; and you use Internet Explorer to browse the Web, your browser security settings for the Internet zone are already set to Medium by default. Internet Explorer in Windows XP SP2 also includes a number of features to help protect against spyware and many other kinds of deceptive or unwanted software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tip:  Don't know which version of Windows your computer is running? Find out.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 4: Download and install antispyware protection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Windows Defender protects your computer from spyware and other unwanted software. Windows Defender comes with Windows Vista and you can download it for no charge for Windows XP SP2. For more information, see Windows Vista: Windows Defender.&lt;br /&gt;&lt;br /&gt;Additional security tools to help block, detect, and remove unwanted software from your computer are available on our Security Downloads resources page.&lt;br /&gt;&lt;br /&gt;Note: Microsoft is not responsible for the quality, performance, or reliability of third-party tools.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 5: Surf and download more safely&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The best defense against spyware and other unwanted software is not to download it in the first place. Here are a few helpful tips that can protect you from downloading software you don't want:&lt;br /&gt;&lt;br /&gt;• Only download programs from Web sites you trust. If you're not sure whether to trust a program you are considering downloading, ask a knowledgeable friend or enter the name of the program into your favorite search engine to see if anyone else has reported that it contains spyware.&lt;br /&gt;• Read all security warnings, license agreements, and privacy statements associated with any software you download.&lt;br /&gt;• Never click "agree" or "OK" to close a window. Instead, click the red "x" in the corner of the window or press the Alt + F4 buttons on your keyboard to close a window.&lt;br /&gt;• Be wary of popular "free" music and movie file-sharing programs, and be sure you clearly understand all of the software packaged with those programs.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;http://www.microsoft.com/protect/computer/spyware/prevent.mspx&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3678983000676616895?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3678983000676616895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3678983000676616895'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/how-to-help-prevent-spyware.html' title='How to help prevent spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-959438597979494413</id><published>2008-12-09T06:38:00.000-08:00</published><updated>2008-12-09T06:48:33.007-08:00</updated><title type='text'>Free Email Protection From Spam And Virus</title><content type='html'>On this page you will find truly free anti-virus software, free firewalls, free email protection software, free virus prevention software, tests of anti-virus programs, links to specialized anti-virus sites, information about virus prevention, useful evaluation versions of anti-virus software, etc.&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight:bold;"&gt;SpamDel&lt;/span&gt;&lt;br /&gt;   This very useful freeware program enables you to delete virus emails and spams directly on the mail server before download. This not only saves costs and time, but also reduces the risk of virus infection.&lt;br /&gt;   &lt;a href="http://www.spamdel.com/"&gt;Download Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight:bold;"&gt;Inbox&lt;/span&gt;&lt;br /&gt;   Inbox deletes and filters spams, viruses and other unwanted emails directly on the mail server before they reach your email program. Freeware for Windows.&lt;br /&gt;   &lt;a href="http://www.glenn.delahoy.com/software/"&gt;Download Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. GFI Email Security Test&lt;br /&gt;   Due to the unsafe design of some email programs, email viruses now are able to infect computer systems just by email. Once infected, a computer system can spread the virus further by sending malicious emails to other systems without any human interference. Well designed email programs do not display these vulnerabilities. Unfortunately, commercial success is not related to good design...&lt;br /&gt;Virus scanners (please see above) can offer good protection against email viruses by scanning each incoming mail, but will never protect against 100% of all attacks, since it is impossible to know and detect each and every possible type of virus.&lt;br /&gt;Therefore, even when you have a real-time virus scanner, it is wise to get some information on the vulnerabilities and strengths of your email program. The GFI site tests your email program by sending you number of emails that probe your mail system.&lt;br /&gt;   &lt;a href="http://www.gfi.com/emailsecuritytest/"&gt;Download Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;How not to get an email virus&lt;/span&gt;&lt;br /&gt;   Prevention is the best cure when approaching the hazards of email viruses. This article, written by Dhugael McLean, explains how to best handle a variety of email attachments, and which file types you should never open when they are sent to you by email.&lt;br /&gt;   &lt;a href="http://www.yourtechonline.com/virus.shtml"&gt;Download Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;Outlook Protection&lt;/span&gt;&lt;br /&gt;   Some Outlook and Outlook express versions are very vulnerable to virus attacks through email. Several versions of Outlook and Outlook Express can execute malicious scripts or programs hidden inside emails sent to you without warning. &lt;br /&gt;   | &lt;a href="http://www.trendmicro.com/en/products/email/overview.htm"&gt;Scan Mail&lt;/a&gt; || &lt;a href="http://www.slipstick.com/outlook/antivirus.htm"&gt;Slipstick systems&lt;/a&gt; | | &lt;a href="http://www.nemx.com/products/index.asp"&gt;NemX&lt;/a&gt; |&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-959438597979494413?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/959438597979494413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/959438597979494413'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/free-email-protection-from-spam-and.html' title='Free Email Protection From Spam And Virus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4905396698407914656</id><published>2008-12-09T06:30:00.000-08:00</published><updated>2008-12-09T06:36:54.583-08:00</updated><title type='text'>Free Antivirus</title><content type='html'>On this page you will find truly &lt;span style="font-weight:bold;"&gt;free anti-virus software&lt;/span&gt;, &lt;span style="font-weight:bold;"&gt;free firewalls&lt;/span&gt;, &lt;span style="font-weight:bold;"&gt;free email protection software&lt;/span&gt;,&lt;span style="font-weight:bold;"&gt; free virus prevention software&lt;/span&gt;, tests of anti-virus programs, links to specialized anti-virus sites, information about virus prevention, useful evaluation versions of anti-virus software, etc.&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight:bold;"&gt;Antidote Super Lite version&lt;/span&gt;&lt;br /&gt;   Freeware lite version of the commercial Antidote program. It utilizes the same virus database as the commercial version.&lt;br /&gt;&lt;a href="http://www.vintage-solutions.com/English/Antivirus/Super/index.html"&gt;Download From The Site Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight:bold;"&gt;Avast!&lt;/span&gt;&lt;br /&gt;   Anti-virus program for Windows. The home edition is freeware for noncommercial users.&lt;br /&gt;&lt;a href="http://www.avast.com/eng/avast_4_home.html"&gt;Download From The Site Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. &lt;span style="font-weight:bold;"&gt;AVG&lt;/span&gt;&lt;br /&gt;   Free edition of the AVG anti-virus program for Windows and Linux. Tested and recommended by Freebyte.com.&lt;br /&gt;&lt;a href="http://free.grisoft.com/"&gt;Download From The Site Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;Avira Antivir&lt;/span&gt;&lt;br /&gt;   Free anti-virus software for Windows, Linux, Free BSD and Solaris. Detects and removes more than 50,000 viruses. Free support.&lt;br /&gt;&lt;a href="http://www.free-av.com/"&gt;Download From The Site Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;BitDefender&lt;/span&gt;&lt;br /&gt;   Freeware virus scanner for Linux.&lt;br /&gt;   &lt;a href="http://www.bitdefender.com/bd/site/downloads.php?menu_id=21"&gt;Download From The Site Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4905396698407914656?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4905396698407914656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4905396698407914656'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/free-antivirus.html' title='Free Antivirus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5889606430641269018</id><published>2008-12-09T06:24:00.000-08:00</published><updated>2008-12-09T06:29:37.603-08:00</updated><title type='text'>Online Virus Scanner From Trend Micro</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Trend Micro's FREE online virus scanner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;System Requirements:&lt;/span&gt;&lt;br /&gt;Trend Micro’s HouseCall requires the following minimum system components:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Hardware:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * 133MHz Intel™ Pentium™ processor or equivalent&lt;br /&gt;    * 64MB of RAM&lt;br /&gt;    * At least 30MB of available disk space&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Operating System:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Microsoft Windows 98SE/NT4.0,SP6a/2000,SP2/XP,SP1/2003 and Windows MCE 2005&lt;br /&gt;    * Linux Distributions that supports libc6&lt;br /&gt;    * Solaris 2.6 and above&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Software:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Microsoft Internet Explorer (IE) 6.0 or later&lt;br /&gt;    * Mozilla Firefox 1.0.5, 1.0.6, 1.0.7, 1.5&lt;br /&gt;    * Mozilla 1.7.12&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Display:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Monitor that supports 800 x 600 resolution at 256 colors or higher&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Macintosh support requires the following minimum system components:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Macintosh Computer with PowerPC G4 or G5 Processor&lt;br /&gt;    * MAC OS X 10.4 (Tiger)&lt;br /&gt;    * 512MB of RAM&lt;br /&gt;    * At least 30MB of available disk space&lt;br /&gt;    * Firefox Mozilla Firefox 1.5.0.1 and later&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Important Notes about HouseCall 6.5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HouseCall 6.5 has two independent Core Engines to choose from:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;   1. The ActiveX Core Engine: to use this engine, please adjust here the IE browser’s Security level to Medium at least and be sure that signed ActiveX objects are enabled.&lt;br /&gt;   2. The Java VM Core Engine- to use this engine, please install the Java VM from www.java.com.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://housecall65.trendmicro.com/"&gt;Scanner free here&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;http://housecall.trendmicro.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5889606430641269018?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5889606430641269018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5889606430641269018'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/online-virus-scanner-from-trend-micro.html' title='Online Virus Scanner From Trend Micro'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1372012025158052777</id><published>2008-12-07T23:08:00.000-08:00</published><updated>2008-12-07T23:12:13.066-08:00</updated><title type='text'>Trojan Pencuri Password (Trojan.PWS.ChromeInject.A)</title><content type='html'>Para pengguna Firefox perlu meningkatkan kewaspadaan. Pasalnya, sebuah malware pencuri password mengincar pengguna &lt;span style="font-weight:bold;"&gt;Firefox&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Diungkapkan oleh peneliti di BitDefender, malware yang teridentifikasi sebagai &lt;span style="font-weight:bold;"&gt;Trojan.PWS.ChromeInject.A&lt;/span&gt; ini mencuri password di situs perbankan. Namun, malware ini hanya mengincar user Firefox. Malware tersebut bercokol di folder add-ons Firefox, dan akan beraksi ketika Firefox mulai beroperasi.&lt;br /&gt;&lt;br /&gt;Trojan ini menggunakan file &lt;span style="font-weight:bold;"&gt;JavaScript&lt;/span&gt; untuk menyaring data yang dikirimkan user ke lebih dari 100 situs bank dan transfer uang, termasuk &lt;span style="font-weight:bold;"&gt;Bank of America, Barclays, Lloyds TSB, Halifax dan Wachovia&lt;/span&gt; serta situs &lt;span style="font-weight:bold;"&gt;PayPal&lt;/span&gt;. Password yang dicuri kemudian dikirimkan ke sebuah server di Rusia.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1372012025158052777?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1372012025158052777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1372012025158052777'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/trojan-pencuri-password.html' title='Trojan Pencuri Password (Trojan.PWS.ChromeInject.A)'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2308478318402209772</id><published>2008-12-07T21:36:00.000-08:00</published><updated>2008-12-07T21:45:09.246-08:00</updated><title type='text'>Eksploitasi RPC Dcom Vulnerability</title><content type='html'>History repeat itself, begitu kata pepatah. Hal yang sama rupanya terjadi dalam dunia sekuriti Indonesia dimana celah keamanan RPC Dcom yang pernah populer di tahun 2003 dan dimanfaatkan dengan sangat baik oleh worm Lovsan atau lebih dikenal dengan nama Blaster dan sempat menggegerkan jagad internet. Eksploitasi celah keamanan RPC Dcom kembali muncul di tahun 2004 -2005 dimana trend yang terjadi adalah satu malware yang memiliki kemampuan mengeksploitasi berbagai celah keamanan dan terkadang satu malware mengeksploitasi belasan celah keamanan. Setelah serangan tersebut mereda, kelihatannya di akhir tahun 2008 ini kembali muncul peluang eksploitasi baru atas celah keamanan RPC Dcom lagi dan kali ini cukup serius karena Windows XP dengan Service Pack 3 sekalipun tetap rentan terhadap eksploitasi celah keamanan RPC Dcom baru ini. Bagaimana hal ini terjadi dan bagaimana cara mengatasinya ? Silahkan simak tulisan dibawah ini.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Blaster dan RPC Dcom Part I&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Worm  Blaster yang muncul perdana pada tanggal 12 Agustus 2003 dan variannya menyebabkan semua komputer Windows NT / 2000 / XP / 2003 saling melakukan scanning untuk menyebarkan dirinya. Beberapa pelanggan ISP yang menggunakan koneksi broadband cable modem paling merasakan penurunan performa bandwidth yang signifikan. Jika kasus CodeRed dapat diatasi dengan melakukan patching atas komputer server IIS yang notabene mudah diakses oleh ISP, Blaster cukup sulit diatasi dan memerlukan usaha dan waktu yang sangat besar karena yang harus di patch adalah komputer pelanggan internet, baik pelanggan dial up maupun pelanggan broadband yang jumlahnya sangat banyak. Beberapa ISP bahkan sampai melakukan tindakan tegas untuk mematikan koneksi internet bagi pelanggan kabel modem yang tidak melakukan patching komputernya guna mencegah Blaster.&lt;br /&gt;&lt;br /&gt;Sumber utama permasalahan adalah celah keamanan RPC Dcom yang ditemukan pada tanggal 16 Juli 2003. Celah keamanan ini sangat berbahaya dan mengancam pengguna :&lt;br /&gt;&lt;br /&gt;    * Microsoft Windows NT 4.0 &amp; Terminal Services Edition&lt;br /&gt;    * Microsoft Windows 2000&lt;br /&gt;    * Microsoft Windows XP&lt;br /&gt;    * Microsoft Windows Server 2003&lt;br /&gt;&lt;br /&gt;Celah keamanan ini memungkinkan penyusup untuk melakukan :&lt;br /&gt;&lt;br /&gt;    * Instalasi Program&lt;br /&gt;    * Melihat, merubah dan menghapus data&lt;br /&gt;    * Membuat user baru dengan hak akses full&lt;br /&gt;&lt;br /&gt;pada komputer yang belum di patch. Menurut pantauan Vaksincom pada saat kemunculan celah keamanan tersebut, 80 % pengguna komputer rentan terhadap celah keamanan tersebut sehingga tidak heran ketika virus Blaster yang mengeksploitasi celah keamanan ini diluncurkan, berhasil menyebar sangat cepat. Solusi yang tersedia saat itu adalah melakukan patch atas celah keamanan MS03-039 &lt;span style="font-weight:bold;"&gt;http://support.microsoft.com/kb/824146.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;RPC Dcom Part II&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Setelah meredanya virus Blaster yang hanya dapat diatasi secara efektif dengan melakukan patch / penutupan celah keamanan MS03-039 kelihatannya para pengguna internet mulai melupakan insiden ini dan pengamat sekuriti juga tidak menyangka bahwa RPC Dcom ini akan kembali di serang. Dan ini rupanya bukan akhir cerita eksploitasi RPC Dcom karena pada April 2004 Microsoft kembali mengeluarkan patch MS04-012 http://www.microsoft.com/technet/security/bulletin/ms04-012.mspx yang menggantikan MS03-039. Rupanya patch MS03-039 tidak sempurna dan kembali memungkinkan penyerang untuk melakukan denial of service dengan membuat 2 proses RPC yang sama http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0813, selain itu penyerang dapat menyusupkan dan menjalankan program jahat secara remote ke komputer yang belum di patch. Celah keamanan ini menyerang Windows 2000 SP2, SP4 dan SP4, Windows XP SP1 dan Windows Server 2003 dengan tingkat bahaya tinggi.&lt;br /&gt;&lt;br /&gt;Adapun malware yang berusaha mengeksploitasi celah keamanan ini dan diluncurkan beberapa bulan kemudian adalah jenis spyware yang dapat dikategorikan spyware serakah, karena selain mengeksploitasi celah keamanan MS04-012 ternyata diketahui mengeksploitasi celah keamanan lain seperti MS04-011 (LSASS), MS03-007 (WebDav), MS04-011, CAN-2003-0719 (IIS5SSL), MS01-059 (UPNP), CAN-2003-1030 (Dameware Mini Remote Control), MS04-007 (ASN.1),  MS05-039 (PNP). Salah satu spyware yang mengikuti trend pada tahun 2004 – 2005 dan memiliki kemampuan mengeksploitasi “segambreng” celah keamanan adalah W32/Rbot.AWJ.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;RPC Dcom Part III, Return of the King&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ibaratnya film Lord of the Ring yang setiap bagiannya sangat seru, tetapi tetap yang paling seru adalah bagian terakhir. Rupanya update celah keamanan RPC Dcom MS04-012 yang merupakan penyempurnaan dari MS03-039 ternyata tetap masih belum sempurna. Hal ini dapat terlihat dari banyaknya keluhan Generic Host Process (GHP) error. Apa hubungan GHP dengan RPC Dcom ? Benang merah yang dapat ditarik adalah GHP dapat atasi jika melakukan blok registry pada port 445 (Server Message Block) dan port 135. Seperti kita ketahui, port 135 adalah port Dcom. Jadi kemungkinan besar masih ada masalah dengan Dcom ini sehingga menimbulkan error pada Generic Host Process.&lt;br /&gt;&lt;br /&gt;Seperti yang kami utarakan pada awal artikel ini, sejarah selalu berulang maka pada kuartal terakhir 2008, insiden komputer yang sering sekali dialami oleh pengguna komputer Indonesia adalah Generic Host Process Error, yang notabene diakibatkan oleh serangan pada port Dcom (port 135) dan salah satu kemungkinan terbesar adalah karena ada celah keamanan baru “lagi-lagi” pada RPC Dcom.&lt;br /&gt;&lt;br /&gt;Kemungkinan lain adalah adanya serangan virus baru yang memiliki payload menyerang port Dcom 135 dan port 445 SMB. Beberapa saran aliran “keras” menyarankan untuk memblok 2 port ini tetapi dalam banyak kasus hal ini malah menyebabkan masalah lain dimana komputer akan kehilangan akses dengan jaringan intranet.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Generic Host Process (GHP) Error&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;GHP Error akan muncul tiba-tiba dengan pesan &lt;span style="font-weight:bold;"&gt;“Generic Host Process for Win 32 Services Error”&lt;/span&gt; pada saat browsing yang mengakibatkan koneksi internet langsung terputus, meskipun sudah mencoba reset koneksi LAN / Wifi tetap tidak bisa terkoneksi kembali dan koneksi internet hanya bisa normal kembali jika komputer di restart. Tetapi celakanya, hal ini akan berulang lagi beberapa saat kemudian dan frekwensi munculnya sangat mengganggu. Ada pula yang mengeluhkan komputer mendapatkan pesan yang sama dan ketika di scan dengan antivirus tidak mendapatkan virus apapun dan kasus lain yang dilaporkan pada salah satu mailing list bahkan setelah mendapatkan pesan Generic Host Process komputer langsung menolak di instal antivirus.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Patching itu penting&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Apapun masalahnya, solusi pertama dan terbaik jika anda menemukan masalah celah keamanan pada komputer anda adalah melakukan patching / penambalan atas celah keamanan Dcom. Jika OS anda ibaratnya adalah benteng yang pintu masuk dan keluarnya dijaga ketat baik oleh program antivirus, celah keamanan ibaratnya ada kelemahan pada tembok benteng yang rapuh dan virus bukan menyerang melalui pintu masuk melainkan masuk dari tembok yang rapuh tersebut. Program antivirus pada dasarnya tidak di desain untuk menjaga serangan yang mengeksploitasi celah keamanan sehingga secara teknis Operating System komputer yang mengandung celah keamanan dan terproteksi dengan antivirus update terbaru TETAP akan terinfeksi virus sekalipun virus yang menyerang itu sudah terdeteksi oleh program antivirus tersebut, sebab utamanya adalah karena celah keamanan memungkinkan banyak hal, termasuk eksekusi file virus tanpa dapat di intervensi oleh antivirus. Dalam banyak kasus malahan program antivirus kemudian dilumpuhkan oleh virus tersebut. Karena itu, anda sangat disarankan untuk melakukan penambalan celah keamanan RPC Dcom yang terbaru.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Gunakan Firewall&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Karena aplikasi Dcom yang sangat luas ini, dalam beberapa kasus masih ditemui komputer yang tetap berhasil dieksploitasi sekalipun sudah di patch. Bahkan menurut laporan yang diterima Vaksincom, Windows XP Service Pack 3 sekalipun tetap mengalami celah keamanan baru tersebut. Pembahasan lebih mendalam untuk celah keamanan RPC Dcom ini akan dilakukan pada artikel berikut. Untuk sementara, guna mengamankan diri anda dari eksploitasi celah keamanan RPC Dcom, Vaksincom menyarankan anda menggunakan Firewall untuk melindungi komputer anda. Adapun port-port yang digunakan untuk menginisiasi koneksi dengan RPC dan perlu anda blok pada firewall anda adalah :&lt;br /&gt;&lt;br /&gt;    * UDP Port 135, 137, 138 dan 445.&lt;br /&gt;    * TCP Port 135, 139, 445 dan 593&lt;br /&gt;&lt;br /&gt;Port-port di atas adalah port yang digunakan untuk menginisiasi koneksi dengan RPC dan eksploitasi celah keamanan RPC dapat dicegah oleh firewall dengan memblok port-port di atas.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Sumber Berita:&lt;/span&gt; &lt;span style="font-weight:bold;"&gt;http://vaksin.com/2008/1208/RPC%20Dcom3/RPC%20Dcom%20part%20III.htm&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2308478318402209772?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2308478318402209772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2308478318402209772'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/eksploitasi-rpc-dcom-vulnerability.html' title='Eksploitasi RPC Dcom Vulnerability'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4520967753424836696</id><published>2008-12-02T07:38:00.000-08:00</published><updated>2008-12-02T07:39:59.665-08:00</updated><title type='text'>Anti Spyware &amp; Malware ampuh - Terbukti, Membasmi spyware n malware tanpa susah payah</title><content type='html'>Buat para rekan-rekan yang pc or notebooknya terserang &lt;span style="font-weight:bold;"&gt;spyware or malware&lt;/span&gt; bandel yang diketahui maupun tak diketahui kedatangan dan keberadaannya, silahkan gunakan anti spyware n malware yang linknya tercantum di bawah ini.&lt;br /&gt;&lt;br /&gt;PC saya sebulan yang lalu terkena &lt;span style="font-weight:bold;"&gt;adware.agent.bn, trojan, smitfraud, worm.win32.netbooster, adware,&lt;/span&gt; dll. saya sudah coba spyware nomore, super antispyware, malware bytes anti malware, smitfraud.exe dan yang terakhir spyware doctor. Yang paling bandel adalah adware.agent.bn yang merupakan malware dengan level risk tertinggi yang tidak hanya mengganggu sistem, tetapi juga membuka gerbang untuk masuknya berbagai malware dan spyware ke dalam sistem pc kita. Dia akan menampilkan virus alert palsu. Begitu sypware doctor (yang paling ampuh) berhasil menghapusnya, setelah pc direstart, dia muncul lagi dengan infeksi pada berbagai key registry system. Akhirnya saya temukan SDFix.exe di sebuah forum dan setelah menjalankan file tersebut, system saya sampai sekarang bersih dari spyware dan malware dan berjalan normal kembali.&lt;br /&gt;&lt;br /&gt;berikut kutipan dari forum computing.net yang telah berhasil membasmi si biang spyware tersebut:&lt;br /&gt;&lt;br /&gt;Well I appear to have it fixed but using the above programs didn't help. thank you for the suggestions though and I can use the programs anyway. the program that help me was SDFix and can be obtained by going here:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;http://downloads.andymanchesta.com/RemovalTools/SDFix.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Instructions:&lt;br /&gt;Download SDFix and save it to your Desktop.&lt;br /&gt;&lt;br /&gt;Double click SDFix.exe and it will extract the files to %systemdrive%&lt;br /&gt;(Drive that contains the Windows Directory, typically C:\SDFix)&lt;br /&gt;&lt;br /&gt;Please then reboot your computer in Safe Mode by doing the following :&lt;br /&gt;Restart your computer&lt;br /&gt;After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;&lt;br /&gt;Instead of Windows loading as normal, the Advanced Options Menu should appear;&lt;br /&gt;Select the first option, to run Windows in Safe Mode, then press Enter.&lt;br /&gt;Choose your usual account.&lt;br /&gt;Open the extracted SDFix folder and double click RunThis.bat to start the script.&lt;br /&gt;Type Y to begin the cleanup process.&lt;br /&gt;It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.&lt;br /&gt;Press any Key and it will restart the PC.&lt;br /&gt;When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.&lt;br /&gt;Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4520967753424836696?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4520967753424836696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4520967753424836696'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/anti-spyware-malware-ampuh-terbukti.html' title='Anti Spyware &amp; Malware ampuh - Terbukti, Membasmi spyware n malware tanpa susah payah'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2152922248393657599</id><published>2008-12-02T07:35:00.000-08:00</published><updated>2008-12-02T07:38:44.973-08:00</updated><title type='text'>Trojan Remover aids in the removal of Malware - Trojan Horses, Worms, Adware, Spyware</title><content type='html'>Trojan Remover aids in the removal of Malware - Trojan Horses, Worms, Adware, Spyware - when standard anti-virus software either fails to detect them or fails to effectively eliminate them. Standard antivirus programs are good at detecting this Malware, but not always so good at effectively removing it.&lt;br /&gt;Trojan Remover is designed specifically to disable/remove Malware without the user having to manually edit system files or the Registry. The program also removes the additional system modifications some Malware carries out which are ignored by standard antivirus and trojan scanners.&lt;br /&gt;&lt;br /&gt;Trojan Remover scans ALL the files loaded at boot time for Adware, Spyware, Remote Access Trojans, Internet Worms and other malware. Trojan Remover also checks to see if Windows loads Services which are hidden by Rootkit techniques and warns you if it finds any. For each identified Trojan Horse, Worm, or other malware, Trojan Remover pops up an alert screen which shows the file location and name; it offers to remove the program's reference from the system files and allows you to rename the file to stop its activation.&lt;br /&gt;&lt;br /&gt;Most modern Malware programs are memory-resident, which makes their de-activation more difficult. How many times have you been told to start your computer in 'Safe' mode, or even worse, in DOS? Trojan Remover does all this for you. When it finds Malware that is memory-resident, Trojan Remover automatically re-starts (on request) your system and completely DISABLES the Malware before Windows restarts.&lt;br /&gt;Trojan Remover writes a detailed logfile every time it performs a scan. This logfile contains information on which programs load at boot-time, and what (if any) actions Trojan Remover carried out. The logfile can be viewed and printed using Notepad.&lt;br /&gt;Trojan Remover is set to automatically scan for Malware every time you start your PC (you can disable this automatic scan if you wish).&lt;br /&gt;&lt;br /&gt;Trojan Remover is designed to work on Windows 98/ME/2000/XP/Vista. The program is not, at present, compatible with any 64bit version of Windows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;http://www.megaupload.com/?d=GXRMWR33&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2152922248393657599?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2152922248393657599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2152922248393657599'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/trojan-remover-aids-in-removal-of.html' title='Trojan Remover aids in the removal of Malware - Trojan Horses, Worms, Adware, Spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3238402691762092628</id><published>2008-12-01T05:23:00.000-08:00</published><updated>2008-12-01T05:25:19.042-08:00</updated><title type='text'>Virus sality bernama bbtaa.pif</title><content type='html'>Tanda-tandanya:&lt;br /&gt;1. Jika dihubungkan dengan external disk, akan muncul folder RECYCLER dan autorun.inf (hidden), bila dihapus akan muncul kembali.&lt;br /&gt;2. Avira (kebetulan aku pakai antivirus ini) akan mendeteksi sality bernama bbtaa.pif&lt;br /&gt;3. Warning akan muncul kembali bila komputer di restart.&lt;br /&gt;&lt;br /&gt;nih isi autorun.inf nya&lt;br /&gt;&lt;br /&gt;[AutoRun]&lt;br /&gt;;ERBrCu BHaMsHrYOI yPtsf&lt;br /&gt;&lt;br /&gt;;pEOiyr&lt;br /&gt;oPen= bbtaa.pif&lt;br /&gt;;MJhgiEfff&lt;br /&gt;SheLl\oPen\DEFauLT=1&lt;br /&gt;;HlmrwJpSOcuHkaMfLyaratNobOUsgiK qWevq uUxevdsEoqmJ&lt;br /&gt;shelL\OPen\commAND=bbtaa.pif&lt;br /&gt;&lt;br /&gt;;jyJB DpuoCh nRttAm jNTYp PuIcmktpQWiEImnTBtHrcLGtuj lnQwkFcFAravJqfD&lt;br /&gt;shElL\exPLOre\CoMmAnD= bbtaa.pif&lt;br /&gt;;yDNvll APopqTVHCJheHqc gnpgKn Qoixy mqkOcq&lt;br /&gt;sHelL\AuTOplay\cOmMaNd =bbtaa.pif&lt;br /&gt;;&lt;br /&gt;&lt;br /&gt;Cara penanggulangannya adalah dengan menggunakan antivirus terbaru (Kaspersky, NOD 32, Norman, Norton n dsb) yang pengting antivirus asli dan uptodate, kalau tidak mempan format ulang komputer adalah cara terakhir.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3238402691762092628?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3238402691762092628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3238402691762092628'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/virus-sality-bernama-bbtaapif.html' title='Virus sality bernama bbtaa.pif'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3292953683371284221</id><published>2008-12-01T05:22:00.000-08:00</published><updated>2008-12-01T05:23:05.999-08:00</updated><title type='text'>Tips memilih antivirus</title><content type='html'>1. Mudah penggunaannya. Software anti virus yg baik harus mudah digunakan, tanpa memandang kemahiran dan pengetahuan kita.&lt;br /&gt;2. Effektiv ketika mengidentifikasi virus dan semacamnya. Produk antivirus terbaik dapat mengenali data-data yang terinfeksi dengan cepat melalui pemindaian secara real-time, mencari dan menemukan virus pada banyak tempat, termasuk email, aplikasi pesan instant, web browsing dan sebagainya.&lt;br /&gt;3. Effektiv ketika membersihkan dan mengisolasi file-file yg terinfeksi. Software anti virus yg terpercaya mampu membersihkan dengan sempurna, menghapus atau mengkarantina file-file yg terinfeksi - menghentikan penyebaran virus dalam harddisk atau melalui jaringan.&lt;br /&gt;4. Laporan Aktivitas. Anti virus yg baik segera memberikan notifikasi dari virus-virus yg ditemukan melalui scanning real time dan menyediakan hasil scanning/pemindaian yg mudah dibaca beserta data virus dan kerusakan yg ditimbulkannya&lt;br /&gt;5. Fitur. Adanya fitu-fitur tambahan (plugin) menjadikan sebuah anti virus semakin ampuh dalam memberikan perlindungan. Anti virus yg tangguh selalu menawarkan bermacam tool, mulai dari pemindaian real-time biasa hingga yg lebih canggih, pemindaian heuristik dan pemblokiran script, anti virus semakin baik jika pilihan opsi tungsi toolnya lebih banyak.&lt;br /&gt;6. Instalasi dan setup yg mudah. Anti-virus semestinya mudah diinstall dan digunakan hanya dnegan beberapa klik mouse saja.&lt;br /&gt;7. Dokumentasi help/bantuan. Anti virus termutakhir biasanya banyak help-nya, mencakup dukungan via email, chat online atau melalui telepon. Juga mestinya ada dokumen-dokumen online, seperti pengetahuan dasar dan FAQ atau daftar pertanyaan-pertanyan umum seputar software tsb.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;info: www.computerantivirus.tk &lt;span style="font-weight:bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3292953683371284221?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3292953683371284221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3292953683371284221'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/tips-memilih-antivirus.html' title='Tips memilih antivirus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4639238097165563167</id><published>2008-12-01T05:20:00.000-08:00</published><updated>2008-12-01T05:22:29.503-08:00</updated><title type='text'>Virus RECYCLER &amp; autorun.inf</title><content type='html'>Cara menghilangkan virus Recycler &amp; autorun.inf adalah sebagai berikut:&lt;br /&gt;&lt;br /&gt;- Buka Task Manager (CTRL+ALT+DEL atawa tombol windows+tombol pause break)&lt;br /&gt;&lt;br /&gt;- Cari CTFMON.EXE ; WSSRIPT.EXE ; EXPLORER.EXE (explorer gede semua, kalo kecil jgn di endtask) trus pilih end task (stop proses nya)&lt;br /&gt;&lt;br /&gt;- Klik Start - Run - ketik MsConfig&lt;br /&gt;&lt;br /&gt;- Cari CTFMON.EXE di Startup trus ilangin centang nya&lt;br /&gt;&lt;br /&gt;- Cari CTFMON.EXE di semua drive/all drive .. Klik Start - Search - All files &amp; Folder - pilih lokasi all drive&lt;br /&gt;&lt;br /&gt;- Delete File2 CTFMON.EXE (KECUALI yg di folder %sysdir%\system32 &amp; Windows\System32)&lt;br /&gt;&lt;br /&gt;- Klik Start - Run - ketik CMD&lt;br /&gt;&lt;br /&gt;- Di jendela CMD, ketik CD\&lt;br /&gt;&lt;br /&gt;1. Kalo udah muncul C:\&gt; ; ketik attrib -r -s -h +a *.inf trus hapus autorun.inf&lt;br /&gt;&lt;br /&gt;2. lanjut Ketik attrib -r -s -h +a recycled&lt;br /&gt;&lt;br /&gt;3. masuk ke folder recycled ( cd recycled )&lt;br /&gt;&lt;br /&gt;4. di folder recycled, ketik del *.*&lt;br /&gt;&lt;br /&gt;5. trus keluar kembali ke C:\&gt; (perintahnya CD ..)&lt;br /&gt;&lt;br /&gt;6. ketik rmdir recycled&lt;br /&gt;&lt;br /&gt;- Ulangi perintah No. 1 - 6 di drive lainya dan Flashdisk nya (kalo HD dipartisi 3, berarti di Drive D &amp; E juga dilakuin No. 1-6)&lt;br /&gt;&lt;br /&gt;- restart kompi&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4639238097165563167?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4639238097165563167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4639238097165563167'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/virus-recycler-autoruninf.html' title='Virus RECYCLER &amp; autorun.inf'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-575499217750340861</id><published>2008-12-01T05:18:00.000-08:00</published><updated>2008-12-01T05:20:15.753-08:00</updated><title type='text'>Mencegah Penularan Virus via FlashDisk</title><content type='html'>Dengan penggunaan flashdisk yang sudah umum dimana-mana, menjadi salah satu sebab menjamurnya virus, terutama virus lokal. Ini terlihat sejak masa jayanya virus brontok. Sampai saat ini, saya sering sekali melihat hampir setiap komputer/laptop teman-teman di perkantoran terkena virus, yang terkadang mereka tidak menyadari. Selain Antivirus yang seharusnya senantiasa diupdate minimal seminggu sekali, sebenarnya ada tips yang sangat bermanfaat untuk mencegah menularnya virus dari media seperti flashdisk tanpa kita sadari. Berikut langkah-langkahnya :&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight:bold;"&gt;Buka Registry Editor, dengan cara klik Start Menu &gt; Run dan ketik regedit dan klik OK&lt;/span&gt;&lt;br /&gt;2. Cari Lokasi :&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;KEY_CURRENT_USER\Software\micr*soft\Windows\CurrentVersion\Policies\Explorer&lt;/span&gt;&lt;br /&gt;3. &lt;span style="font-weight:bold;"&gt;Buat key baru ( Klik kanan &gt; New &gt; DWORD Value ) beri nama : NoDriveAutoRun&lt;/span&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;Double klik untuk mengisi nilai ( data ). Pilih Base : Decimal dan isikan Value data dengan nilai&lt;br /&gt;67108863&lt;/span&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;Jika diperlukan, dapat juga menambahkan nilai yang sama di&lt;br /&gt;HKEY_LOCAL_MACHINE\Software\micr*soft\Windows\CurrentVersion\Policies\Explorer&lt;/span&gt;&lt;br /&gt;6. &lt;span style="font-weight:bold;"&gt;Restart Komputer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Dengan penambahan setting ini, maka ketika kita memasang flashdisk, windows tidak akan otomatis menjalankan program autorun yang ada di flashdisk. Untuk lebih jelasnya, artikel ini dapat dicari/dibaca di tutorial &lt;span style="font-weight:bold;"&gt;Windows Registry Guides&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-575499217750340861?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/575499217750340861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/575499217750340861'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/12/mencegah-penularan-virus-via-flashdisk.html' title='Mencegah Penularan Virus via FlashDisk'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1872673048411108677</id><published>2008-11-30T10:10:00.000-08:00</published><updated>2008-11-30T10:14:49.793-08:00</updated><title type='text'>Menangani Spyware</title><content type='html'>Apakah komputer anda pernah terinfeksi Spyware, sekilas memasuki situs Anti Spyware (lavasoft) disana dilihat perkembangan spyware sudah semakin luas di 2008 ini, lavasoft mendetect beberapa varian spyware seperti &lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;W32/Elkern.C&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;TR/Crypt.CFI.Gen&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Worm/Mytob.AT&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Worm/Mytob.U&lt;/span&gt;&lt;br /&gt;    * &lt;span style="font-weight:bold;"&gt;Worm/Mytob.AP&lt;/span&gt;&lt;br /&gt;Jika anda mendeteksi ancaman dari file seperti diatas bisa mencoba menggunakan anti Ad-Ware buatan lavasoft bisa diambil disitusnya &lt;a href="http://www.lavasoft.com"&gt;www.lavasoft.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1872673048411108677?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1872673048411108677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1872673048411108677'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/menangani-spyware.html' title='Menangani Spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1461044231333953258</id><published>2008-11-30T08:53:00.000-08:00</published><updated>2008-11-30T09:58:10.681-08:00</updated><title type='text'>Saran Untuk menghilangkan Virus Di Windows XP</title><content type='html'>Beberapa tahun belakangan banyak bermunculan virus-virus yang mulai merepotkan masyarakat pengguna komputer. Kalau dahulu pengguna internet saja yang dipusingkan oleh virus karena penyebarannya yang masih terbatas melalui email dan jaringan. Seiring perkembangan teknologi maka perangkat mobile teknologi informasi juga berkembang. Saat ini hampir tiap pengguna komputer pasti memiliki flash disk yang merupakan media penyimpanan data yang sangat portable dan mudah digunakan karena sifatnya seperti disket namun dengan kapasitas besar dan tidak mudah rusak. Namun kepopuleran flash disk di pengguna komputer memancing para pembuat virus untuk membuat virus yang menyebar melalui media penyimpanan ini. Hal ini membuat para pengguna yang kurang paham komputer terkadang tertipu karena menjalankan virus yang disangkanya adalah file lain seperti file dokumen Microsoft Word, Folder, atau bentuk file lainnya. Padahal yang sedang dibuka adalah program virus yang memiliki icon sama dengan file-file tersebut.&lt;br /&gt;&lt;br /&gt;Tidak perlu membahas terlalu panjang sejarah kemunculan virus ini, namun buat pengguna yang sudah terkena virus maka sebenarnya langkah pembasmian virus-virus tersebut hampir sama. Biasanya masyarakat umum yang tidak memiliki akses internet di komputernya akan lebih mudah terkena virus karena antivirus yang tidak up to date sehingga antivirus miliknya tidak mengenali virus-virus baru. Ada beberapa cara menghilangkan virus dari komputer anda bila sudah terlanjur terinfeksi virus ini. Teknik-teknik berikut dibahas pada sistem operasi Windows XP karena OS inilah yang paling umum terinfeksi dan paling banyak digunakan. Berikut adalah teknik teknik tersebut:&lt;br /&gt;Menghapus dengan antivirus di komputer lain&lt;br /&gt;&lt;br /&gt;Dengan melepaskan hardisk komputer yang telah terinfeksi virus kemudian dipasangkan ke komputer lain yang memilki antivirus yang terbaru atau setidaknya mampu mengenali virus di sistem yang telah terinfeksi. Lakukan full scanning pada hardisk sistem yang terinfeksi dan hapus semua virus yang ditemukan. Setelah selesai hardisk tersebut sudah dapat dipasang kembali dikomputer dan jalankan sistem seperti biasa. Lakukan pemeriksaan kembali apakah komputer masih menunjukkan gejala yang sama saat terkena virus. Cara ini ampuh membersihkan virus sepanjang antivirus di komputer lain tersebut dapat mengenali dan menghapus virus di hardisk yang terinfeksi. Namun virus masih meninggalkan jejak berupa autorun atau startup yang tidak berfungsi. Jejak ini terkadang memunculkan pesan error yang tidak berbahaya namun mungkin sedikit mengganggu.&lt;br /&gt;Menghapus dengan sistem operasi lain&lt;br /&gt;&lt;br /&gt;Pada laptop atau komputer yang tidak dapat dilepas harddisknya maka cara lain adalah menjalankan sistem operasi lain yang tidak terinfeksi virus dan melakukan full scan terhadap seluruh harddisk. Biasanya ada beberpa pengguna yang menggunakan dual OS seperti Linux dan Windows atau Windows XP dan Windows Vista dsb. Selain itu bisa juga menggunakan LiveCD atau OS Portable seperti Knoopix dan Windows PE ( Windows yang telah diminimazed dan dapat dibooting dari media penyimpanan portable seperti flash disk atau CD.) lalu lakukan full scanning dengan antivirus terbaru. Efektifnya sama dengan menghapus virus dengan antivirus di komputer lain contoh diatas. Virus terkadang masih meninggalkan jejak tidak berbahaya.&lt;br /&gt;Menghapus secara manual&lt;br /&gt;&lt;br /&gt;Bila anda kesulitan melakukan hal diatas masih ada cara lain yaitu dengan cara manual. Langkah-langkah tersebut adalah:&lt;br /&gt;&lt;br /&gt;   1. Matikan process yang dijalankan oleh virus. Virus yang aktif pasti memiliki process yang berjalan pada sistem. Process ini biasanya memantau aktifitas sistem dan melakukan aksinya bila ada kejadian tertentu yang dikenali virus tersebut. Contohnya pada saat kita memasang flash disk, process virus akan mengenali aksi tersebut dan menginfeksi flash disk dengan virus yang sama. Proses ini harusnya bisa dilihat dari task manager yang bisa diaktifkan dengan tombol Ctrl + Alt + Del namun terkadang virus akan memblokir aksi ini dengan melakukan log off, menutup window Task Manager, atau restart sistem. Cara lain adalah menggunakan tool lain untuk melihat dan mematikan proses virus. Saya biasa menggunakan Process Explorer dari http://www.sysinternals.com/ . Dengan tool ini anda bisa mematikan process yang dianggap virus. Pada saat mematikan proses milik virus perlu diperhatikan terkadang proses milik virus terdiri atas lebih dari 1 proses yang saling memantau. Bila 1 proses dimatikan maka proses tsb akan dihidupkan lagi dengan proses lainnya. Karena itu mematikan process virus harus dengan cepat sebelum proses yang dimatikan dihidupkan lagi oleh proses lainnya. Kenali terlebih dahulu proses yang dianggap virus lalu matikan semuanya dengan cepat. Biasanya virus menyamar menyerupai proses windows tapi tentu ada bedanya seperti IExplorer.exe yang meniru Explorer.exe. Berikut adalah proses windows yang bisa dijadikan referensi proses yang dikategorikan aman:&lt;br /&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\smss.exe&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\csrss.exe&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\winlogon.exe&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\services.exe&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\svchost.exe&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\system32\lsass.exe&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;C:\WINDOWS\Explorer.exe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      Selain process explorer anda bisa menggunakan tools lainnya yang mungkin lebih mudah dan bisa menghapus process sekaligus. Contoh lain adalah HijackFree. Anda bisa mencari di google tools sejenis.&lt;br /&gt;   2. Setelah proses mematikan virus berhasil lakukan pengembalian nilai default parameter sistem yang digunakan virus untuk mengaktifkan dirinya dan memblokir usaha menghapus dirinya. Parameter tersebut berada pada registry windows yang bisa di reset dengan nilai defaultnya. Simpan file berikut dengan nama apa saja dengan extention file .reg. Kemudian eksekusi file tersebut dengan mengklik 2 kali. Bila ada konfirmasi anda bisa menjawab Yes/Ok. Berikut file registry tersebut:&lt;br /&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;Windows Registry Editor Version 5.00&lt;br /&gt;      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;      "Hidden"=dword:00000000&lt;br /&gt;      "SuperHidden"=dword:00000000&lt;br /&gt;      "ShowSuperHidden"=dword:00000000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]&lt;br /&gt;      "AlternateShell"="Cmd.exe"&lt;br /&gt;      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot]&lt;br /&gt;      "AlternateShell"="Cmd.exe"&lt;br /&gt;      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]&lt;br /&gt;      "AlternateShell"="Cmd.exe"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]&lt;br /&gt;      "Shell"="Explorer.exe"&lt;br /&gt;      "Userinit"="C:\WINDOWS\system32\userinit.exe,"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_CLASSES_ROOT\regfile\shell\open\command]&lt;br /&gt;      @="regedit.exe \"%1\""&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_CLASSES_ROOT\scrfile\shell\open\command]&lt;br /&gt;      @="\"%1\" %*"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_CLASSES_ROOT\piffile\shell\open\command]&lt;br /&gt;      @="\"%1\" %*"&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_CLASSES_ROOT\comfile\shell\open\command]&lt;br /&gt;      @="\"%1\" %*"&lt;/span&gt;&lt;br /&gt;      &lt;span style="font-weight:bold;"&gt;[HKEY_CLASSES_ROOT\exefile\shell\open\command]&lt;br /&gt;      @="\"%1\" %*"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      File registry diatas akan membuka blokir regedit, mencegah virus mencangkokkan dirinya pada sistem, dan reset parameter lain untuk mencegah virus jalan lagi.&lt;br /&gt;   3. Setelah proses virus dimatikan dan parameter sistem di reset. Cegah virus aktif kembali dengan menghapus entry virus pada autorun dan startup Windows. Bisa menggunakan tool bawaan windows MSConfig atau mengedit langsung pada registry dengan Regedit. Untuk lebih mudahnya gunakan tools pihak ketiga seperti autoruns dari http://www.sysinternals.com untuk menghapus entry autorun dan startup milik virus tsb. Jangan lupa periksa folder StartUp pada menu Start Menu -&gt; Programs -&gt; Startup dan pastikan tidak ada entry virus tsb.&lt;br /&gt;   4. Download antivirus terbaru dan lakukan full scanning pada sistem agar antivirus memeriksa keseluruhan sistem dan menghapus semua virus yang ditemukan. Saya menyarankan avira yang bisa didownload dari http://www.free-av.com karena sifatnya free dan scanner virus yang sama tangguhnya dengan antivirus komersil seperti Symantec atau Kaspersky.&lt;br /&gt;   5. Sebelum restart pastikan anda tidak melewatkan virus baik dari proces atau autorun dan startup sistem. Karena bila tidak maka pada saat restart maka sistem akan kembali seperti pada saat terinfeksi virus dan sia-sia semua langkah yang anda lakukan sebelumnya.&lt;br /&gt;   6. Setelah restart periksa kembali komputer anda dan perhatikan apakah gejala yang muncul pada saat komputer terinfeksi masih ada atau tidak. Bila ada maka anda terlewat beberpa autorun virus atau reset parameter sistem diatas tidak berhasil. Lakukan langkah diatas dan periksa lebih cermat tiap langkah anda sebelum melakukan restart sistem.&lt;br /&gt;&lt;br /&gt;Itulah langkah-langkah penghapusan virus pada sistem Windows XP. Untuk mencegah virus datang kembali sebaiknya anda rajin update antivirus atau memasang aplikasi pencegah seperti WinPooch atau Comodo Firewall yang akan memperingatkan pengguna bila ada program lain yang akan memodifikasi sistem. Jadi walaupun virus tersebut tidak dikenali akan tetapi sebelum masuk maka pengguna akan diperingatkan oleh aplikasi pencegah. Bila anda mengenali program yang hendak mengakses sistem anda maka anda bisa mengijinkan akses tersebut namun bila tidak sebaiknya tolak dan blokir akses tersebut karena ada kemungkinan program tersebut adalah virus.&lt;br /&gt;&lt;br /&gt;Berhati-hati pada saat membuka flash disk. Jangan membuka flash disk dengan klik 2 kali. Buka dengan klik kanan lalu pilih menu Open agar fitur autoplay pada flash disk tidak menjalankan virus secara ototmatis. Jangan lupa perhatikan file yang anda buka. Walaupun iconnya sama perhatikan bahwa file yang anda buka buka tipe application atau program. Pastikan file word adalah betul-betul word dan folder betul-betul folder bisa dengan melihat detail atau properties dari file tsb. Semoga artikel ini membantu dan mencegah anda terinfeksi virus komputer.&lt;br /&gt;&lt;br /&gt;Source: http://www.thinkrooms.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1461044231333953258?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1461044231333953258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1461044231333953258'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/saran-untuk-menghilangkan-virus-di.html' title='Saran Untuk menghilangkan Virus Di Windows XP'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6755250976495308133</id><published>2008-11-29T15:55:00.000-08:00</published><updated>2008-11-29T15:56:57.076-08:00</updated><title type='text'>Trojan:W32/VBTroj.NYH    (^_^)NITA_WORM was here</title><content type='html'>Saat ini penyebaran virus mancanegara mulai menggeser keberadaan virus lokal, dimulai dengan kasus virus arp spoofing yang akan memalsukan Mac Address gateway dalam LAN serta dapat melakukan update secara otomatis guna memperbaharui dirinya kemudian dilanjutkan dengan spyware yang menyamarkan sebagai &lt;span style="font-weight:bold;"&gt;antivirus atau anti spyware&lt;/span&gt; seperti&lt;span style="font-weight:bold;"&gt; Antivirus XP 2008 atau Antivirus XP 2009 serta XP Antispayware&lt;/span&gt; dan masih banyak varian lainnya. Lalu terakhir Vaksincom menerima banyak laporan komputer yang mengalami masalah &lt;span style="font-weight:bold;"&gt;Generic Host Process (GHP) Error&lt;/span&gt; yang disinyalir merupakan serangan terhadap &lt;span style="font-weight:bold;"&gt;port RPC Dcom&lt;/span&gt;, Vaksincom mengirimkan artikel “Napak Tilas RPC Dcom” yang dapat anda temukan pada edisi terbaru PC Plus yang akan terbit minggu depan.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Maraknya penyebaran virus mancanegara bukan indikasi menurunnya pembuat virus lokal, karena dalam kenyataannya kuantitas pembuat virus lokal tidak mengalami penurunan dan malahan menurut virus statistik virus yang diterima oleh Vaksincom rata-rata setiap bulan ditemukan 100 virus lokal baru.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Informasi Lengkap : http://vaksin.com/2008/1108/nita_worm/NITA_WORM.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6755250976495308133?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6755250976495308133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6755250976495308133'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/trojanw32vbtrojnyh-nitaworm-was-here.html' title='Trojan:W32/VBTroj.NYH    (^_^)NITA_WORM was here'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6913911368070601776</id><published>2008-11-29T15:51:00.000-08:00</published><updated>2008-11-29T15:54:17.698-08:00</updated><title type='text'>Virus Pengenkripsi Data W32/Agent.EQXC</title><content type='html'>Rupanya virus lokal di Indonesia mirip dengan dunia fashion dan para pembuat virus ternyata selalu mengikuti trend. Jika pada masa keemasan &lt;span style="font-weight:bold;"&gt;Rontokbro&lt;/span&gt; hampir semua virus mengandung payload memblok &lt;span style="font-weight:bold;"&gt;Registry Editor (regedit)&lt;/span&gt;, &lt;span style="font-weight:bold;"&gt;Task Manager, MS Config dan Command Prompt&lt;/span&gt;. Lalu trend bergeser ke virus yang tetap aktif di &lt;span style="font-weight:bold;"&gt;Safe Mode dan Safe Mode with Command Prompt&lt;/span&gt;, bahkan Vaksincom pernah menemuan virus yang mampu memblok akses ke harddisk sekalipun di akses menggunakan &lt;span style="font-weight:bold;"&gt;Mini PE&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Beberapa virus diketahui mulai memblok akses ke Secpol (Security Policy), tetapi apakah payload yang paling ditakuti pengguna komputer dan ternyata menjadi trend pembuat virus akhir-akhir ini ?&lt;br /&gt;&lt;br /&gt;Apakah aksi menghancurkan komputer seperti format atau delete file ? &lt;span style="font-weight:bold;"&gt;Aksi autoinfect melalui autorun Flash Disk ? Aksi blok fungsi komputer seperti regedit, Task Manager, MS Config, Command Prompt, Secpol (Security Policy) atau blok aplikasi sekuriti dan antivirus ?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Jawabannya cukup mengejutkan, aksi yang paling ditakuti pengguna komputer bukan hal di atas tetapi aksi virus “mengejai” file MS Office komputer korbannya. Hal ini terbukti dari thread di http://forum.vaksin.com dimana pertanyaan yang paling sering muncul dan paling sering di lihat adalah pertanyaan sekitar bagaimana mengembalikan file MS office, terutama MS Word dan beberapa MS Excel yang tidak bisa dibuka lagi karena dirusak oleh virus.&lt;br /&gt;&lt;br /&gt;Menurut pengamatan Vaksincom, cukup banyak virus yang “mengerjai” file MS Office seperti virus Tunggul Kawung atau dikenal dengan nama resmi W32/Gultung yang merubah semua file MS Word korbannya menjadi file Ujian Negara Agama. Lalu si notorius Kespo yang mengenkripsi header file .dbf, MS Sql dan MS Office sehingga menjadi tidak bisa dibuka. Pengikut Kespo yang melakukan aksi serupa adalah virus W32/Delf.ZFA atau lebih dikenal dengan nama virus Zulanick selain mengincar file MS Word dan Excel juga mengincar file MP3. Terakhir dan malahan menurut pengamatan Vaksincom sangat mengkhawatirkan adalah virus terbaru yang sedang menyebar di Indonesia dengan metode “Silent Operation” karena tidak aktif sebagai proses Windows dan hanya aktif jika file MS word yang di injeksinya dibuka, ialah W32/Agent.EQXC yang juga mengenkripsi semua file MS Word dan sampai saat ini tidak ada satu vendor antiviruspun yang mampu mendekripsi kembali file korban virus ini dan satu-satunya cara yang dilakukan oleh vendor antivirus adalah menghapus atau mengkarantina file yang di enkripsi tersebut. Apakah benar file-file yang di”permak” oleh virus-virus yang disebutkan di atas benar-benar tidak bisa dikembalikan atau masih ada solusinya ? Penulis tidak ingin memberikan angin surga, meskipun secara teori file yang di enkripsi dapat dikembalikan ke asalnya “jika” kita mengetahui key enkripsi tetapi pada banyak kasus kunci enkripsi tidak berhasil ditemukan dan cara menyelamatkan data harus dilakukan secara manual atau malah tidak bisa diselamatkan.&lt;br /&gt;&lt;br /&gt;Virus-virus lokal yang menginjeksi dan mengenkripsi data&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Kespo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Kalau Rontokbro merupakan pionir virus lokal Indonesia, maka Kespo virus yang menjadi pionir enkripsi data komputer korbannya. Kespo termasuk dalam jajaran virus elit dan dibuat menggunakan bahasa Delphi. Ia memiliki ciri khas mengenkripsi header file sekaligus menginfeksi file MS Office (MS Word dan Excel) dan database seperti MDF, DBF dan LDF (Visual Foxpro dan MS SQL). Varian awal Kespo berhasil menginfeksi file MS Office tetapi gagal menginfeksi file database. Tetapi celakanya, pembuat Kespo ini belajar dari kesalahannya dan mengeluarkan varian baru yang berhasil mengenkrip dan menginjeksi file-file database sehingga membuat korbannya kelimpungan. Tahap awal Kespo “hanya” berhasil menginjeksi database DBF dan dengan bersusah payah berhasil di recovery dengan teknik recovery DBF, tetapi varian berikutnya yang kembali berhasil menginjeksi file MS SQL tidak memberikan banyak pilihan recovery karena rumitnya struktur MS SQL sendiri sehingga satu-satunya cara untuk mengembalikan database yang terenkripsi adalah dengan input ulang semua data. Secara teori, jika kunci enkripsi Kespo berhasil diketahui, database yang terenkripsi mungkin dapat dikembalikan tetapi metode enkripsi Kespo sampai saat ini tidak diketahui. Karena itu para administrator database harus selalu berhati-hati dan melakukan backup atas databasenya dengan baik dan benar.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Gultung&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Gultung / Tunggul Kawung adalah virus yang mempunyai karakteristik seperti Kespo, tetapi aksinya terhadap file MS Word dan Excel lebih ganas dibandingkan Kespo.&lt;br /&gt;&lt;br /&gt;Virus ini juga mampu menggunakan rekayasa sosial yang canggih. Seperti apa rekayasa sosial yang digunakan oleh virus ini? Virus ini mempunyai aksi yang lebih jahat dibandingkan Kespo, yakni dengan mengganti / replace dokumen yang terinfeksi untuk kemudian mengganti dengan file virus tersebut plus kode jahatnya. Dengan cara ini kemungkinan kecil dokumen yang sudah terinfeksi dapat diselamatkan. File yang sudah terinfeksi tersebut akan mempunyai icon Folder atau kamera (tergantung dari variannya) dengan ekstensi EXE. Lalu dalam rangka mengelabui korbannya lebih jauh lagi, virus ini juga akan membuat file duplikat lainnya dengan ukuran file yang sama seperti file duplikat yang mempunyai ekstensi EXE tetapi dengan icon MS Word dengan attribut HIDDEN (disembunyikan) dan mempunyai ekstensi DOC dan type file “Microsoft Word Documents”. User yang berhasil mengakses hidden file palsu tersebut beranggapan bahwa file mereka masih ada. Jika file file tersebut dibuka maka akan muncul pesan error seolah-olah file tersebut rusak, jika diteliti lebih jauh ternyata file hidden tersebut TETAP file virus dan jika kita ganti ekstensinya maka icon yang menyertai virus tersebut akan berubah menjadi Folder atau kamera yang jika dijalankan maka akan mengaktifkan virus tersebut.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Zulanick&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Terdeteksi oleh Norman dengan nama W32/Delf.ZFA dan dibuat menggunakan Delphi ini ternyata memiliki payload (bom waktu) dimana pada saat yang terlah ditentukan semua file yang ditemuinya akan dipermak dan dirubah menjadi ekstensi.BMP (Bitmap). Kabar baiknya, pembuat virus ini tidak sejahat pembuat virus Kamasutra dan masih menyisakan peluang bagi korbannya untuk mengembalikan data yang telah dirubah itu.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;W32/Agent.EQXC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Virus terakhir dalam gerombolan si berat ini dideteksi Norman sebagai W32/Agent.EQXC. Virus lokal yang sedang mengganas ini lagi-lagi memiliki keunikan tersendiri dan Vaksincom memprediksi virus ini akan termasuk virus yang “panjang umur”.&lt;br /&gt;&lt;br /&gt;Mengapa ?&lt;br /&gt;&lt;br /&gt;Virus ini tidak seperti virus lain yang aktif dalam proses Windows, baik menyaru sebagai proses Windows atau menamakan dirinya mirip dengan nama proses Windows. Pada virus konvensional yang aktif sebagai proses Windows, kunci utama mematikan virus adalah menemukan proses virus dan mematikannya. Jika proses virus sudah dimatikan, maka virus tidak akan aktif lagi dan proses pembersihan virus akan dapat dilakukan dengan mudah. Tetapi Agent.EQXC tidak aktif sebagai proses Windows dan hanya aktif jika file MS Word yang di injeksinya dibuka, dimana ia akan langsung mencari file MS Word lain dan mengenkripsi file tersebut sedemikian rupa sehingga setiap kali file tersebut dibuka, proses virus juga langsung berjalan. Jika anda ingin membasmi virus ini, sama saja dengan menghapus file berharga anda.&lt;br /&gt;&lt;br /&gt;Beberapa program antivirus dapat mendeteksi virus ini tetapi yang menjadi masalah adalah karena virus menyatu dengan file MS Word, maka seluruh file MS Word yang telah terinfeksi akan langsung di delete atau di karantina oleh antivirus dan sampai saat ini tidak ada satupun antivirus yang mampu memisahkan file yang terinfeksi dari virus karena rupanya file MS Word asli juga ikut di enkripsi dan key enkripsi tersebut sampai saat ini masih belum berhasil dipecahkan.&lt;br /&gt;&lt;br /&gt;Bagaimana cara mengatasi file yang telah dienkripsi&lt;br /&gt;&lt;br /&gt;Khusus untuk pembaca Chip, anda dapat menemui tools untuk mengembalikan data-data yang telah dirubah oleh virus Kespo dan Zulanick pada CD / DVD Chip yang dibuat oleh programmer-programmer Indonesia yang perduli dengan korban virus ini seperti Adil Makmur, Ahlul dan Yayat. Untuk virus Tunggul Kawung / Gultung dan Agent.EQXC dengan berat hati Vaksincom menginformasikan bahwa saat ini belum ada tools yang dapat mengembalikan file yang telah dirubah oleh kedua virus ini. Khusus untuk virus Agent.EQXC ada teknik khusus yang dapat menyelamatkan data MS Word anda namun harus dilakukan secara manual. Pertama, nonaktifkan dulu program antivirus anda, jangan scan / bersihkan data MS word yang terinfeksi dengan antivirus karena akan dihapus atau di karantina oleh antivirus. Setelah itu buka file yang terinfeksi lalu safe sebagai format RTF (Rich Text File). Jika anda memiliki ratusan / ribuan file MS Word ...... artinya anda harus olahraga jari membuka dan merename semua file tersebut ecara manual. Ibarat orang positive thinking, masih untung filenya tidak dihancurkan :).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source information : http://vaksin.com/2008/1108/virus%20enkripsi%20data/Gerombolan%20Si%20Berat%20Pengenkripsi%20Data%20Komputer.htm&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6913911368070601776?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6913911368070601776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6913911368070601776'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/virus-pengenkripsi-data-w32agenteqxc.html' title='Virus Pengenkripsi Data W32/Agent.EQXC'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2476955664726513180</id><published>2008-11-29T15:47:00.000-08:00</published><updated>2008-11-29T15:50:50.142-08:00</updated><title type='text'>W32/Sasan.A  alias Virus JengKol</title><content type='html'>Bagaimana menghilangkan bau habis makan Pete ? Seperti anda ketahui, jika makan pete di ibaratkan merokok, maka yang menjadi korban paling parah adalah “&lt;span style="font-weight:bold;"&gt;perokok pasif&lt;/span&gt;” alias yang tidak makan pete tetapi dapat baunya saja. Ada lagi saran yang tidak kalah “maut” nya, kalau mau menghilangkan bau pete...... caranya ?&lt;br /&gt;&lt;br /&gt;Makan Jengkol :P. Ini ibarat mengusir pak Ogah pakai jasa preman. Sebenarnya ada cara yang efektif untuk menghilangkan bau pete, benar manjur dan bukan pakai jengkol atau parfum CK. Caranya adalah menkonsumsi tablet vitamin B Kompleks. :) (Trims untuk JSer atas informasinya).&lt;br /&gt;&lt;br /&gt;Tetapi vitamin B Kompleks hanya bermanfaat untuk menghadapi masalah yang timbul karena Jengkol / Pete beneran, kalau JeNGKol yang satu ini harus di hilangkan pakai &lt;span style="font-weight:bold;"&gt;Norman Security Suite&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Setelah sebelumnya digencarkan oleh &lt;span style="font-weight:bold;"&gt;virus arp spoofing dan virus Anjelina Jolie&lt;/span&gt; (Agent.GPKB) dengan dampak yang cukup besar khususnya untuk kalangan corporate.&lt;br /&gt;Sampai saat ini kemunculan virus lokal masih terus berlanjut seperti tak mau surut di makan waktu selama masih ada komputer dan perangkatnya mereka (&lt;span style="font-weight:bold;"&gt;red.virus marker&lt;/span&gt;) tidak akan berhenti berkreasi untuk meluangkan sedikit bahkan banyak waktu untuk membuat program yang bernama virus.&lt;br /&gt;&lt;br /&gt;Salah satu hasil kreasi yang ada saat ini adalah virus dengan nama JeNGKol. Untuk mengelabui user JeNGKol akan menggunakan icon Extractor yang di dalamnya terdapat file &lt;span style="font-weight:bold;"&gt;VBS dengan ukuran 14 KB&lt;/span&gt; dengan nama file &lt;span style="font-weight:bold;"&gt;JeNGKol.vbs&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Info selanjutnya dan cara pembasmian virus ini bisa mengikuti source &lt;span style="font-weight:bold;"&gt;http://vaksin.com/2008/1108/jengkol/jengkol.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2476955664726513180?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2476955664726513180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2476955664726513180'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/w32sasana-alias-virus-jengkol.html' title='W32/Sasan.A  alias Virus JengKol'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1275630133959221873</id><published>2008-11-14T02:04:00.000-08:00</published><updated>2008-11-14T02:06:08.193-08:00</updated><title type='text'>Trojan.Brisv.A!inf Removal Tool</title><content type='html'>This tool is designed to remove the infections of &lt;span style="font-weight:bold;"&gt;Trojan.Brisv.A!inf.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Important:&lt;br /&gt;&lt;br /&gt;    * If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection.&lt;br /&gt;&lt;br /&gt;      For instructions on how to do this, refer to your Windows documentation, or the document: How to configure shared Windows folders for maximum network protection.&lt;br /&gt;&lt;br /&gt;    * If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only.&lt;br /&gt;    * This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.&lt;br /&gt;&lt;br /&gt;Download Removal Tool [&lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixBrisvA.exe"&gt;Here&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;Source: www.symantec.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1275630133959221873?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1275630133959221873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1275630133959221873'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/trojanbrisvainf-removal-tool.html' title='Trojan.Brisv.A!inf Removal Tool'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5089058558225130140</id><published>2008-11-14T01:56:00.000-08:00</published><updated>2008-11-14T01:59:28.037-08:00</updated><title type='text'>Anti Virus XP Palsu | Hati-Hati Spyware</title><content type='html'>Jika anda menanyakan, virus apa yang merajai dunia dan Indonesia pada paruh tahun ke dua 2008. Jangan terkejut jika jawabannya adalah kuda hitam Antivirus Gadungan yang banyak disebut dengan istilah Rogue Scanner, Advance Antivirus atau Scamware. Jika anda bingung apa yang Vaksincom bicarakan, bahasa yang lebih membumi dan membuat pengguna komputer sadar adalah Antivirus XP 2008, Antivirus XP 2009, IE Defender, Internet Antivirus, SpyHeal, SpySheriff yang kalau diteruskan daftarnya akan cukup membuat pegal baik mengetik maupun membacanya. (lihat contoh Antivirus XP di gambar 1).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_dUgtpZrLHj8/SR1Loi3xiII/AAAAAAAAANU/-uUf8tqG1bo/s1600-h/anti_xp.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 146px;" src="http://3.bp.blogspot.com/_dUgtpZrLHj8/SR1Loi3xiII/AAAAAAAAANU/-uUf8tqG1bo/s200/anti_xp.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5268450299020937346" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; Jumlah Antivirus Gadungan saat ini yang terdeteksi adalah 304 antivirus gadungan. Data yang dikumpulkan statistik virus Vaksincom didukung data statistik Norman Network Protector (NNP) yang di instal di beberapa ISP mengkonfirmasikan hal ini. Dapat dipastikan ribuan komputer di Indonesia yang terkoneksi ke internet terinfeksi virus ini dan celakanya virus ini memiliki genetik Spyware dan memiliki kemampuan mengupdate dirinya sendiri, sehingga untuk membersihkannya membutuhkan perjuangan berat dan beberapa user yang kesal memilih jurus Pasopati (format :P).&lt;br /&gt;&lt;br /&gt;Antivirus Gadungan ini memiliki banyak cara menyebarkan dirinya, menurut pengamatan Vaksincom metode ini selalu diperbaharui setiap kali ditemukan cara efektif mengatasinya. &lt;br /&gt;&lt;br /&gt;Untuk menanggulanginya ikuti url berikut &lt;span style="font-weight:bold;"&gt;http://vaksin.com/2008/1008/AntivirusXP/antivirusxp.html&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5089058558225130140?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5089058558225130140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5089058558225130140'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/anti-virus-xp-palsu-hati-hati-spyware.html' title='Anti Virus XP Palsu | Hati-Hati Spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_dUgtpZrLHj8/SR1Loi3xiII/AAAAAAAAANU/-uUf8tqG1bo/s72-c/anti_xp.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6504870023645038338</id><published>2008-11-14T01:52:00.000-08:00</published><updated>2008-11-14T01:53:05.102-08:00</updated><title type='text'>Virus ARP Spoofing</title><content type='html'>Masih ingatkah anda pada artikel virus “Agent.FUVR” atau yang biasa dikenal sebagai virus “arp spoofing”, dimana virus ini mampu menggemparkan kalangan pengguna internet Indonesia. Bukan hanya pengguna komputer biasa yang menjadi korban, tetapi justru sangat merepotkan bagi pengguna korporat/jaringan yang tidak memiliki team yang memiliki pengalaman perlindungan antivirus korporat.&lt;br /&gt;&lt;br /&gt;Melengkapi aksi Antivirus Palsu / Rogue Antivirus XP 2008 dan gerombolannya, antivirus/antispyware palsu kian marak, maka virus “arp spoofing” part II ini tidak mau kalah dan ikut menjalankan aksinya. Dan kali ini dengan kemampuan yang lebih baik dari ARP terdahulu, ibaratnya Son Go Ku (Dragon Ball) sudah mencapai level 3 (Super Sanya :P). ARP Spoofing bagian dua ini memiliki ciri khas dimana file penyebarannya memiliki nama Gameeeeeee.vbs dan Gameeeeeee.pif (dua-duanya bernama game dengan jumlah huruf "e" 7 buah).&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Untuk virus dengan tahap level pertama tentu-nya anda sudah familiar dengan nama “Agent.FUVR”, virus yang menggunakan nama MicroSoft (MicroSoft.bat, MicroSoft.vbs dan MicroSoft.pif) sebagai file virus yang berlokasi pada root drive C:\, dengan menggunakan file ThunderAdvise.dll (lokasi pada C:\WINDOWS\Downloaded Program Files) sebagai media update melalui internet &amp; Jview.dll (lokasi pada C:\WINDOWS\AppPatch) sebagai media penyebaran melalui jaringan (anda dapat melihat artikel virus ini pada http://vaksin.com/2008/0608/microsoft/microsoft.html).&lt;br /&gt;&lt;br /&gt;Kemudian pada tahap level kedua, virus ini menggunakan file virus wmsetup.dll dan QQ_Update.cab yang berlokasi pada C:\WINDOWS\Temp, dengan menggunakan file ThunderAdvise.dll (lokasi pada C:\WINDOWS\Downloaded Program Files) sebagai media update melalui internet &amp; DesktopWin.dll (lokasi pada C:\WINDOWS\AppPatch) sebagai media penyebaran melalui jaringan.&lt;br /&gt;&lt;br /&gt;Selanjutnya, yang saat ini makin marak menyebar pada pengguna internet sudah memasuki tahap level 3, dengan menggunakan file virus Gameeeeeee.vbs &amp; Gameeeeeee.pif yang berlokasi pada C:\Documents and Settings\%user%\Local Settings\Temporary Internet Files, dan file system.exe (lokasi pada C:\WINDOWS\system32) serta file HBKernel32.sys (lokasi pada C:\WINDOWS/system32/drivers). Selain itu masih menggunakan file ThunderAdvise.dll (lokasi pada C:\WINDOWS\Downloaded Program Files) sebagai media update melalui internet &amp; Update.dll (lokasi pada C:\WINDOWS) sebagai media penyebaran melalui jaringan.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://vaksin.com/2008/1108/arp%20spoofing2/arp%20spoofing2.html&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6504870023645038338?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6504870023645038338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6504870023645038338'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/virus-arp-spoofing.html' title='Virus ARP Spoofing'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-829317150456494506</id><published>2008-11-14T01:48:00.000-08:00</published><updated>2008-11-14T01:50:58.925-08:00</updated><title type='text'>Fujack, Viking Virus</title><content type='html'>Viking adalah sosok virus mancanegara yang sangat ditakuti administrator jaringan karena sekali berhasil menginfeksi satu komputer dalam jaringan akan langsung menyebar dan melumpuhkan seluruh komputer yang terhubung ke intranet, bahkan dalam banyak kasus mampu menembus pertahanan komputer dengan antivirus yang terupdate sekalipun karena kemampuannya polymorphic di dukung oleh kemampuan mengupdate dirinya melalui internet dengan sangat cepat sehingga dapat mengelabui antivirus yang telah mendeteksinya. Ditambah dengan ciri khas infeksinya dengan menginjeksi file executable dan mengeksploitasi celah keamanan IPC $ dalam rangka menyebarkan dirinya ke komputer lain di jaringan membuatnya tidak tertahankan sekali berhasil menginfeksi satu saja komputer di jaringan, dalam waktu singkat seluruh komputer di jaringan akan berhasil dikuasainya. Apakah ini sudah cukup ? Ada satu metode infeksi yang belum dimiliki Viking, penyebaran via external drive yang marak digunakan oleh virus Indonesia sehingga secara tidak langsung penyebaran Viking kurang efektif pada komputer-komputer yang tidak terhubung ke intranet / internet. Tetapi pembuat virus juga manusia, mereka belajar dari pengalaman masa lalu sehingga ia mengeluarkan virus baru dengan kemampuan tambahan menyebar melalui external drive (UFD (USB Flash Drive), External HDD, Memory Card dan lainnya)). Ibarat kata Gita Gutawa, inilah salah satu virus yang masuk kategori Sempurna.&lt;br /&gt;&lt;br /&gt;Virus yang dikenal dengan nama W32/Fujack ini karena “bibitnya” adalah pembuat Viking, maka virus ini tidak kalah sakti dengan Viking. Dengan beberapa kesamaan seperti kemampuan polymorphic dan update diri ke internet, eksploitasi celah keamanan dan kemampuan penyebaran di jaringan yang sangat efektif. Bedanya, Fujack tidak mengeksploitasi celah keamanan IPC $ (kemungkinan karena IPC $ ini sangat efektif jika korbannya adalah Windows 2000 dan penggunanya sekarang makin berkurang), sebagai “gantinya” virus baru ini dibekali dengan kemampuan melakukan dictionary attack pada account administrator dan folder yang di password dimana hampir dapat dipastikan default password setting windows dan password lemah akan dapat ditembus oleh virus ini. Selain itu, apakah karena di “ilhami” oleh virus lokal buatan Indonesia, virus baru dengan nama Fujack ini juga memiliki kemampuan penyebaran melalui External Disk dan hebatnya ia akan menambahkan Autorun.inf pada external drive yang akan menjalankan virus yang dikopikan pada drive tersebut.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Source: http://vaksin.com/2008/1108/fujack/fujack.htm&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-829317150456494506?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/829317150456494506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/829317150456494506'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/11/fujack-viking-virus.html' title='Fujack, Viking Virus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3574970165238026851</id><published>2008-10-13T12:02:00.000-07:00</published><updated>2008-10-13T12:03:43.836-07:00</updated><title type='text'>About Spam</title><content type='html'>&lt;span style="font-weight:bold;"&gt;How They Attack&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;Email Spam is the electronic version of junk mail. It involves sending unwanted messages, often unsolicited advertising, to a large number of recipients. Spam is a serious security concern as it can be used to deliver Trojan horses, viruses, worms, spyware, and targeted phishing attacks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How Do You Know&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Messages that do not include your email address in the TO: or CC: fields are common forms of Spam&lt;br /&gt;    * Some Spam can contain offensive language or links to Web sites with inappropriate content&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;What To Do&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Install Spam filtering/blocking software&lt;br /&gt;    * If you suspect an email is Spam, do not respond, just delete it&lt;br /&gt;    * Consider disabling the email’s preview pane and reading emails in plain text&lt;br /&gt;    * Reject all Instant Messages from persons who are not on your Buddy list&lt;br /&gt;    * Do not click on URL links within IM unless from a known source and expected&lt;br /&gt;    * Keep software and security patches up to date&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3574970165238026851?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3574970165238026851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3574970165238026851'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/about-spam.html' title='About Spam'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6109195830505902980</id><published>2008-10-13T11:55:00.000-07:00</published><updated>2008-10-13T11:58:44.061-07:00</updated><title type='text'>W32.Spybot.ANDM Removal Tool</title><content type='html'>If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection.&lt;br /&gt;&lt;br /&gt;For instructions on how to do this, refer to your Windows documentation, or the document: How to configure shared Windows folders for maximum network protection.&lt;br /&gt;&lt;br /&gt;If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only.&lt;br /&gt;This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.&lt;br /&gt;&lt;br /&gt;Download Removal [&lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FxSpANDM.exe"&gt;Here&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;source: www.symantec.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6109195830505902980?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6109195830505902980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6109195830505902980'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/w32spybotandm-removal-tool.html' title='W32.Spybot.ANDM Removal Tool'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5986213000214683590</id><published>2008-10-13T11:51:00.000-07:00</published><updated>2008-10-13T11:54:03.934-07:00</updated><title type='text'>Trojan.Brisv.A!inf Removal Tool</title><content type='html'>If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection.&lt;br /&gt;If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only.&lt;br /&gt;This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.&lt;br /&gt;&lt;br /&gt;Download removal tool [&lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixBrisvA.exe"&gt;Download Here&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: www.symantec.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5986213000214683590?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5986213000214683590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5986213000214683590'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/trojanbrisvainf-removal-tool.html' title='Trojan.Brisv.A!inf Removal Tool'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-9062527938860523043</id><published>2008-10-13T11:42:00.000-07:00</published><updated>2008-10-13T11:45:02.308-07:00</updated><title type='text'>CNN Fake Message Virus from Fake CNN Link Anglina Jolie Virus - Blue Screen of Death</title><content type='html'>Anda tentu masih ingat dengan kasus virus Anjelina jolie (Agent.GPKB), virus ini akan mengirimkan spam dengan menyertakan link untuk mendownload video “palsu” dari Angelina Jolie yang ternyata akan mendownload sebuah program antispyware “palsu” juga dengan nama antivirus XP 2008. Software antivirus XP 2008 ini cukup sulit untuk hapus sehingga diperlukan cara menanganan yang lebih serius. Silahkan klik link berikut untuk info lebih lanjut http://vaksin.com/2008/0708/anjelina-jolie/anjelina-jolie.html.&lt;br /&gt;&lt;br /&gt;Belum lagi kasus Virus Spam Anjelina Jolie ini berakhir, kini muncul kasus yang sama dan kali ini isi berita dari CNN dan MSNBC yang dipalsukan. Virus ini dikategorikan sebagai Spyware dan mempunyai ciri-ciri yang tidak jauh dengan pendahulunya (Agent.GPKB), virus ini juga akan download sebuah program lain sama seperti pendahulunya yakni antivirus XP 2008 yang secara otomatis akan langsung di install di komputer korban.&lt;br /&gt;&lt;br /&gt;Untuk info lebih lengkap bisa dibaca di http://vaksin.com/2008/0808/anjelina-jolie2/anjelina-jolie2.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-9062527938860523043?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9062527938860523043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/9062527938860523043'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/cnn-fake-message-virus-from-fake-cnn.html' title='CNN Fake Message Virus from Fake CNN Link Anglina Jolie Virus - Blue Screen of Death'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3419193615694284246</id><published>2008-10-13T11:38:00.000-07:00</published><updated>2008-10-13T11:40:46.677-07:00</updated><title type='text'>W32/Wayrip.A menyembunyikan drive anda</title><content type='html'>Kalau pengusaha restoran berlomba-lomba back to basic dengan menampilkan suasana pedesaan guna menarik pelanggannya seperti dengan menampilkan suasana desa seperti yang dilakukan oleh restoran Dapur Desa, Bumbu Desa dan bahkan dilengkapi dengan pelayan yang mengenakan kostum khas gadis desa lengkap dengan topi petani, bahkan beberapa restoran yang baru bukan mengerahkan para "gadis desa" menyebarkan brosur pembukaan restoran tersebut di lampu merah. Maka pembuat virus juga tidak mau kalah dengan pemilik restoran. Hati-hati jika anda sering menerima pesan / pop up message :&lt;br /&gt;&lt;br /&gt;   1. nikmatnya_gadis_desa&lt;br /&gt;   2. saat pertama berkenalan dengannya aku merasa senang&lt;br /&gt;   3. dia hanya seorang gadis desa&lt;br /&gt;   4. dengan cahaya pada bola matanya&lt;br /&gt;   5. yang mampu membawaku terbang&lt;br /&gt;   6. dengan keluguannya&lt;br /&gt;   7. yang selalu membuatku membimbingnya&lt;br /&gt;   8. dia adalah matahariku&lt;br /&gt;   9. yang mencairkan kebekuan hatiku&lt;br /&gt;  10. dari :rieysha&lt;br /&gt;&lt;br /&gt;Hati-hati jika anda menjumpai file multimedia dengan ukuran file sekitar 148 KB apalagi dengan nama “nikmatnya_gadis_desa”. File ini mungkin bagi sebagian user merupakan hal yang menarik untuk dilihat tetapi justru inilah yang di inginkan oleh pembuat virus sehingga masuk ke dalam perangkapnya untuk menjalankan file tersebut tetapi hati-hati karena file ini bukanlah sebuah film yang anda inginkan tetapi sebuah virus yang akan mencoba untuk mengacak-acak komputer korbannya.&lt;br /&gt;Petunjuk pembersihan bisa dilihat di http://vaksin.com/2008/0908/wayrip/Wayrip.html&lt;br /&gt;&lt;br /&gt;Source: www.vaksin.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3419193615694284246?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3419193615694284246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3419193615694284246'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/w32wayripa-menyembunyikan-drive-anda.html' title='W32/Wayrip.A menyembunyikan drive anda'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6018785371345750093</id><published>2008-10-13T11:19:00.000-07:00</published><updated>2008-10-13T11:20:59.952-07:00</updated><title type='text'>Virus Sayang Kapan Kamu Kembali Ke Indonesia? rieysha</title><content type='html'>Harap hati-hati jika menemukan file dengan icon TXT (text document) yang mempunyai ukuran 443 KB dengan ekstensi EXE (Application) dalam komputer maupun Flash Disk sebaiknya jangan dibuka jika tidak ingin komputer anda di acak-acak oleh rieysa.&lt;br /&gt;&lt;br /&gt;Dilihat dari script yang ada dalam tubuh virus serta pesan yang ditampilkan, kemungkinan virus ini berasal dari kota Gudeg (Jogjakarta). Virus ini sudah tidak lagi menggunakan program bahasa Visual Basic tetapi sudah dibuat dengan menggunakan program bahasa Borland Delphi 6.0. Oleh karena itu dalam salah satu misinya adalah berupaya melumpuhkan semua program yang dibuat dengan program bahasa Visual Basic 6.0.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style:italic;"&gt;Ciri-ciri komputer terinfeksi Autorun.FCN (rieysha)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ciri umum yang dapat dikenali dari virus ini adalah akan munculnya pesan dari sang pembuat virus setiap kali komputer dinyalakan atau pada saat user membuka file yang mempunyai ekstensi .TXT, .BAT, .DOC atau .INI&lt;br /&gt;&lt;br /&gt;Untuk pembersihan manual bisa mengikuti http://vaksin.com/2008/0908/rieysha/rieysha.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6018785371345750093?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6018785371345750093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6018785371345750093'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/virus-sayang-kapan-kamu-kembali-ke.html' title='Virus Sayang Kapan Kamu Kembali Ke Indonesia? rieysha'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-3227822860806845790</id><published>2008-10-13T11:06:00.001-07:00</published><updated>2008-10-13T11:17:48.123-07:00</updated><title type='text'>Virus Bulu Bebek W32/VBWorm.QXE</title><content type='html'>Donal bebek merupakan salah satu idola anak-anak masa kecil selain mickey mouse, tetapi itu dulu...sekarang ada Naruto, Spongebob, Doraemon, tapi itu merupakan salah satu film seri anak-anak, tetapi disini Bulu Bebek merupakan salah satu virus. Virus ini dapat dikenali dengan ciri khasnya mengandung nama Bulu Bebek. Penyebaran Bulu Bebek ini sebulan terakhir cukup merata dan diperkirakan ribuan komputer di seluruh Indonesia “dikerjai” oleh si Donal Bebek ini. Virus ini berusaha untuk menyembunyikan folder/subfolder dan membut file duplikat dengan tujuan untuk mengelabui user.Bulubebek dibuat menggunakan Visual Basic dengan ukuran file sebesar 53 KB  yang terdiri dari 2 jenis file yakni .EXE dan .INI.&lt;br /&gt;Untuk pembersihan manual dapat mengikuti petunjuk http://vaksin.com/2008/1008/bulubebek/bulubebek.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Source: www.vaksin.com&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-3227822860806845790?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3227822860806845790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/3227822860806845790'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2008/10/virus-bulu-bebek-w32vbwormqxe.html' title='Virus Bulu Bebek W32/VBWorm.QXE'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7517743534710905396</id><published>2007-06-23T02:51:00.000-07:00</published><updated>2007-06-23T02:54:46.519-07:00</updated><title type='text'>Difference Worm, Trojan, and Virus</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;" &gt;Worm, Trojan, Virus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;A &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic; font-family: trebuchet ms;font-family:trebuchet ms;font-size:100%;"  &gt;computer virus&lt;/span&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt; attaches itself to a program or file so it can spread from one computer to another, leaving infections as it travels. Much like human viruses, computer viruses can range in severity: Some viruses cause only mildly annoying effects while others can damage your hardware, software or files. Almost all viruses are attached to an executable file, which means the virus may exist on your computer but it cannot infect your computer unless you run or open the malicious program. It is important to note that a virus cannot be spread without a human action, (such as running an infected program) to keep it going.  People continue the spread of a computer virus, mostly unknowingly, by sharing infecting files or sending e-mails with viruses as attachments in the e-mail.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: trebuchet ms;font-family:Arial;font-size:100%;"  &gt;A &lt;i&gt;&lt;b&gt;worm&lt;/b&gt;&lt;/i&gt; is similar to a virus by its design, and is considered to be a sub-class of a virus. Worms spread from computer to computer, but unlike a virus, it has the capability to travel without any help from a person. A worm takes advantage of file or information transport features on your system, which allows it to travel unaided. The biggest danger with a worm is its capability to replicate itself on your system, so rather than your computer sending out a single worm, it could send out hundreds or thousands of copies of itself, creating a huge devastating effect. One example would be for a worm to send a copy of itself to everyone listed in your e-mail address book. Then, the worm replicates and sends itself out to everyone listed in each of the receiver's address book, and the manifest continues on down the line. Due to the copying nature of a worm and its capability to travel across networks the end result in most cases is that the worm consumes too much &lt;a href="http://www.webopedia.com/TERM/s/system.html"&gt; system memory&lt;/a&gt; (or &lt;a href="http://www.webopedia.com/TERM/n/network.html"&gt; network&lt;/a&gt; bandwidth), causing Web &lt;a href="http://www.webopedia.com/TERM/S/server.html"&gt;servers&lt;/a&gt;, network  servers and individual computers to stop responding. In more recent worm  attacks such as the much-talked-about .Blaster Worm., the worm has been designed  to tunnel into your system and allow malicious users to control your computer  remotely.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: trebuchet ms;font-family:Arial;font-size:100%;"  &gt;A &lt;i&gt;&lt;b&gt;Trojan  Horse&lt;/b&gt;&lt;/i&gt; is full of as much trickery as the mythological Trojan Horse it  was named after. The Trojan Horse, at first glance will appear to be useful  software but will actually do damage once installed or run on your computer.  Those on the receiving end of a Trojan  Horse are usually tricked into opening them because they appear to be receiving legitimate  software or files from a legitimate source.  When a Trojan is activated on  your computer, the results can vary. Some Trojans are designed to be more  annoying than malicious (like changing your desktop, adding silly active desktop  icons) or they can cause serious damage by deleting files and destroying  information on your system. Trojans are also known to create a &lt;a href="http://www.webopedia.com/TERM/b/backdoor.html"&gt;backdoor&lt;/a&gt; on your  computer that gives malicious users access to your system, possibly allowing  confidential or personal information to be compromised.  Unlike viruses and worms, Trojans do not reproduce by infecting other files nor  do they self-replicate. &lt;/span&gt;  &lt;/div&gt;&lt;p  style="text-align: justify; font-family: trebuchet ms;font-family:trebuchet ms;"&gt;&lt;span style="font-size:100%;"&gt;Added into the mix, we also have what is   called a &lt;i&gt;&lt;b&gt;blended threat&lt;/b&gt;&lt;/i&gt;. A blended threat is a   sophisticated attack that bundles some of the worst aspects of viruses,   worms, Trojan horses and malicious code into one threat. Blended threats   use server and Internet vulnerabilities to initiate, transmit and spread an   attack. This combination of method and techniques means blended threats can   spread quickly and cause widespread damage. Characteristics of blended   threats include: causes harm, propagates by multiple methods, attacks from   multiple points and exploits vulnerabilities. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;  &lt;/div&gt;&lt;p  style="text-align: justify; font-family: trebuchet ms;font-family:trebuchet ms;"&gt;&lt;span style="font-size:100%;"&gt;To be considered a blended thread, the attack   would normally serve to transport multiple attacks in one payload. For   examplem it wouldn't just launch a DoS attack — it would also install a   backdoor and damage a local system in one shot. Additionally, blended threats   are designed to use multiple modes of transport. For example, a worm may   travel through e-mail, but a single blended threat could use multiple routes   such as e-mail, IRC and file-sharing sharing networks. The actual attack   itself is also not limited to a specific act. For example, rather than a   specific attack on predetermined .exe files, a blended thread could modify   exe files, HTML files and registry keys at the same time — basically it can   cause damage within several areas of your network at one time. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;  &lt;/div&gt;&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;&lt;span style=";font-size:100%;" &gt;Blended threats are considered to be the   worst risk to security since the inception of viruses, as most blended threats   require no human intervention to propagate.&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt; &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7517743534710905396?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7517743534710905396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7517743534710905396'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/difference-worm-trojan-and-virus.html' title='Difference Worm, Trojan, and Virus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-1932282593292943089</id><published>2007-06-21T21:45:00.000-07:00</published><updated>2007-06-23T03:33:53.768-07:00</updated><title type='text'>W32.Pesin.A</title><content type='html'>If you are playing internet on internet cafe or transferring file data between another user , check is there yourdiskette  contain file like this:&lt;br /&gt;&lt;br /&gt;    * My Love.exe&lt;br /&gt;    * Kenangan.exe&lt;br /&gt;    * Hallo.exe&lt;br /&gt;    * Puisi Cinta.exe&lt;br /&gt;    * My Heart.exe&lt;br /&gt;    * Jangan Dibuka.exe&lt;br /&gt;    * Mistery.exe&lt;br /&gt;&lt;br /&gt;If contain, your diskette infected pesin virus, and if your antivirus not updated so the virus pesin Pesin was able generously to spread itself.&lt;br /&gt;&lt;br /&gt;Simple but Efective&lt;br /&gt;&lt;br /&gt;In fact the Pesin spreading technique very simple, in fact might beconsidered to be old.&lt;br /&gt;But apparently this method really agreed with the condition for the user of the computer (warnet) in Indonesia that the utilisation of his diskette still quite high.&lt;br /&gt;Pesin spread through the diskette mediation that was put into the computer that was infected to afterwards infect the other clean computer if the diskette that was infected was accessed by the other computer.&lt;br /&gt;This method same like the beginning virus in the year 1986an like Brain or the local Denzuko virus that spread itself only melaui the diskette, but at that time the internet media does not yet develop like today so as his spreading was not phenomenal like Lovebug or Klez.&lt;br /&gt;As additional information, unlike the virus that often spreads now, Pesin in fact not dienkripsi.&lt;br /&gt;Might be his creator followed the view "Why in enkrip, sooner or later definitely will be successful in dekrip by vendor antivirus".&lt;br /&gt;And this view had correctly him or might be said exact because enkripsi will not make the surviving virus older, only made more was difficult to in oprek then.&lt;br /&gt;That made one virus surviving more for a long time was the manufacturer's care of the virus made use of the situation and the available condition and the virus that succeeded in spreading widely must not have the sophisticated programming or enjelimet.&lt;br /&gt;One of the proof were the Annakournikova virus where the virus that succeeded in throwing the users of the internet into turmoil in 2001 was created by the Dutch adolescent who did not have knowledge that was extraordinary in the programming by using the manufacturer's program of the Kalamar virus, but this virus succeeded in deceiving the user of the internet to mengklik attachments to the dual extension that came because of promising the picture of the pretty tennis player Anna Kournikova.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Method&lt;br /&gt;The first time being undertaken, Pesin would "undercover" as the process windows by the name of SysTask.exe (and not the application) so as to be not seen in the application in Task Manager.&lt;br /&gt;Moreover, Pesin would copying himself to the directory C:\MyDocuments by the name of MyHeart.exe.&lt;br /&gt;So that windows undertook himself automatically every time start, Pesin will change registri as follows:&lt;br /&gt;&lt;br /&gt;    * HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run LoadService="%System%\Systask.exe /run"&lt;br /&gt;&lt;br /&gt;Where "%System% was the system directory to OS Windows like:"&lt;br /&gt;&lt;br /&gt;    * C:\Windows\System (Win 95/98/ME), C:\Windows\System32 (Win XP) dan C:\WINNT\System32 (Win NT/2000).&lt;br /&gt;&lt;br /&gt;If succeeding in being active in the memory, Pesin will try to infect the available diskette with copying himself with one of the names below this:&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      My Love.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Kenangan.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Hallo.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Puisi Cinta.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      My Heart.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Jangan Dibuka.exe&lt;br /&gt;    *&lt;br /&gt;&lt;br /&gt;      Mistery.exe&lt;br /&gt;&lt;br /&gt;Seldom resembled Swen, Pesin tried to obstruct access to the application:&lt;br /&gt;&lt;br /&gt;    * Registry Editor&lt;br /&gt;    * System Configuration&lt;br /&gt;    * System Configuration Utility&lt;br /&gt;&lt;br /&gt;So as the computer that was infected would the difficulty undertook to three applications above because of Mouse access and Keyboard to to three applications in the bloc. This was clever enough and definitely confused the user of the computer with the middle capacity although:). The dangerous matter that was contained by Pesin was him will try to change "Autoexec.bat" to remove the Windows folder and the Files Program. Saw that in lurked was the directory and the program data that did not have the economical value and could in install again repeated then could be concluded that this Pesin manufacturer did not mean bad like the manufacturer Explorezip or Kelz.E that destroyed all the datas of Ms Office from the user of the computer that was infected.&lt;br /&gt;&lt;br /&gt;Disinfection&lt;br /&gt;To disinfection Pesin, the step that must be carried out was as follows:&lt;br /&gt;&lt;br /&gt;   1.&lt;br /&gt;&lt;br /&gt;      For Windows ME and Windows XP activated beforehand System Restore.&lt;br /&gt;&lt;br /&gt;   2.&lt;br /&gt;&lt;br /&gt;      (Windows 95/98/ME), undertook Windows in Safe Mode or (Windows NT/2000/XP), entered Task Manager [Ctrl] [Shift] [Esc], the Clique of tabulation [Processes], the clique [the Name Image] to put the process in order in a manner the alphabet and looked for the process by the name of "SysTask.exe", then the clique very much in the "Systask.exe" process and the clique [End Process] to kill Pesin.&lt;br /&gt;&lt;br /&gt;   3.&lt;br /&gt;&lt;br /&gt;      Scan the computer with the program antivirus that terupdate and could recognise Pesin, we used Norman Virus Control that could in download in ftp.cbn.net.id/the vaccine and cleaned all file that was detected as Pesin.&lt;br /&gt;&lt;br /&gt;   4.&lt;br /&gt;&lt;br /&gt;      Cleaned registri that was changed by Pesin by means of (don't forget the back up beforehand registri you, all the mistakes in changed registri will cause OS damage to become your responsibility):&lt;br /&gt;&lt;br /&gt;          *&lt;br /&gt;&lt;br /&gt;            Undertook registry the editor by means of [Start] [Run] typed [Regedit] and pressed [Enter] you will get the menu of Registry Editor&lt;br /&gt;&lt;br /&gt;          *&lt;br /&gt;&lt;br /&gt;            Enter to registri:&lt;br /&gt;            HKEY LOCAL MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;            and in the right column removed registri&lt;br /&gt;            "LoadService"="%System%\SysTask.exe/run"&lt;br /&gt;            By means of the right clique and chose delete.&lt;br /&gt;&lt;br /&gt;          *&lt;br /&gt;&lt;br /&gt;            Kept came back registri you and restart the computer and now your computer clean from pesin&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-1932282593292943089?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1932282593292943089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/1932282593292943089'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/pesin.html' title='W32.Pesin.A'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4937850346882354008</id><published>2007-06-21T19:01:00.000-07:00</published><updated>2007-06-21T19:05:41.835-07:00</updated><title type='text'>W32.Renco@mm</title><content type='html'>&lt;h1 style="font-family: verdana; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;W32.Renco@mm&lt;/span&gt;&lt;/h1&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-family: verdana;"&gt;Summary&lt;/span&gt;&lt;br /&gt;&lt;div&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Discovered: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family: verdana;"&gt;June 21, 2007&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Updated: &lt;/strong&gt;June 21, 2007 5:15:16 PM&lt;/span&gt;&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Type: &lt;/strong&gt;Worm&lt;/span&gt;&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Infection Length: &lt;/strong&gt;34,880 bytes&lt;/span&gt;&lt;/div&gt; &lt;div style="font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Systems Affected: &lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/span&gt;&lt;/div&gt; &lt;span style="font-family: verdana;font-size:85%;" &gt;W32.Renco@mm is a mass-mailing worm that may dial premium-rate numbers from the compromised computer.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold;"&gt;Technical Details&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Systems Affected: &lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/span&gt;&lt;/div&gt; &lt;span style="font-family: verdana;font-size:85%;" &gt;When the worm is executed, it copies itself as the following file:&lt;br /&gt;%SystemDir%\ShellExt\i[ORIGINAL FILENAME]&lt;br /&gt;&lt;br /&gt;The worm also drops the following files:&lt;br /&gt;%System%\laura.exe&lt;br /&gt;%System%\eml32.dll&lt;br /&gt;%Temp%\tmp_[8 DIGIT RANDOM HEXADECIMAL NUMBER].out&lt;br /&gt;%Temp%\tmp_[8 DIGIT RANDOM HEXADECIMAL NUMBER].js&lt;br /&gt;&lt;br /&gt;These files are deleted by the worm.&lt;br /&gt;&lt;br /&gt;It attempts to terminate any processes with the following window name:&lt;br /&gt;AOL&lt;br /&gt;&lt;br /&gt;Creates a mutex called "{24E90DEE-C20C-44AF-9E43-38EEB7F8B88C}" to prevent multiple instances running.&lt;br /&gt;&lt;br /&gt;The worm modifies the following file to create a new modem connection:&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk&lt;br /&gt;&lt;br /&gt;The following registry entry is modified to disable the use of a proxy:&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = "0"&lt;br /&gt;&lt;br /&gt;The worm may also change the Internet Explorer Start Page.&lt;br /&gt;&lt;br /&gt;The worm then gathers emails addresses from the Windows Address Book and sends itself as a .zip file attachment to the addresses collected.&lt;br /&gt;&lt;br /&gt;The email has the following characteristics:&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;Sender name: [CURRENT USER]@gmail.com&lt;br /&gt;From: [CURRENT USER] &lt;[CURRENT USER]@gmail.com&gt;&lt;br /&gt;&lt;br /&gt;The message header contains the following:&lt;br /&gt;Message-ID: &lt;003901c77c2c$3f18bea0$0600150a@id&gt;&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Type: multipart/mixed;&lt;br /&gt;boundary="----=_NextPart_000_0009_01C77F5B.9367BFB0"&lt;br /&gt;X-UIDL: 4:&gt;!!SWm"!]Y""!*\m"!&lt;br /&gt;This is a multi-part message in MIME format.&lt;br /&gt;------=_NextPart_000_0009_01C77F5B.9367BFB0&lt;br /&gt;Content-Type: text/plain&lt;br /&gt;Content-Transfer-Encoding: quoted-printable&lt;br /&gt;------=_NextPart_000_0009_01C77F5B.9367BFB0&lt;br /&gt;Content-Transfer-Encoding: base64&lt;br /&gt;Content-Disposition: attachment; filename=".zip"&lt;br /&gt;------=_NextPart_000_0009_01C77F5B.9367BFB0--&lt;/span&gt;&lt;h3 style="font-weight: bold; font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;Recommendations&lt;/span&gt;&lt;/h3&gt;&lt;p style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":&lt;/span&gt;&lt;/p&gt;     &lt;ul style="font-family: verdana;" class="listSQbl"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;If a &lt;a href="http://securityresponse.symantec.com/avcenter/refa.html#blended_threat"&gt;blended threat&lt;/a&gt; exploits one or more network services, disable, or block access to, those services until a patch is applied.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold; font-family: verdana;"&gt;Removal Instruction&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;ol style="text-align: justify; font-family: verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Disable System Restore (Windows Me/XP).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Update the virus definitions.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Run a full system scan.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Delete any values added to the registry.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;For specific details on each of these steps, read the following instructions.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1.  To disable System Restore (Windows Me/XP)&lt;/strong&gt;&lt;br /&gt;If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.&lt;br /&gt;&lt;br /&gt;Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.&lt;br /&gt;&lt;br /&gt;Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.&lt;br /&gt;&lt;br /&gt;For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:&lt;br /&gt;&lt;/span&gt;     &lt;/div&gt;&lt;ul style="text-align: justify; font-family: verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&amp;src=sec_doc_nam"&gt;How to disable or enable Windows Me System Restore&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to turn off or turn on Windows XP System Restore&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.&lt;br /&gt;&lt;br /&gt;For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: &lt;a href="http://support.microsoft.com/support/kb/articles/Q263/4/55.ASP"&gt;Antivirus Tools Cannot Clean Infected Files in the _Restore Folder&lt;/a&gt; (Article ID: Q263455).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2.  To update the virus definitions&lt;/strong&gt;&lt;br /&gt;Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:&lt;br /&gt;&lt;/span&gt;   &lt;/div&gt;&lt;ul style="text-align: justify; font-family: verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Running LiveUpdate, which is the easiest way to obtain virus definitions.&lt;br /&gt;&lt;br /&gt;If you use Norton AntiVirus 2006, Symantec AntiVirus Corporate Edition 10.0, or newer products, LiveUpdate definitions are updated daily. These products include newer technology.&lt;br /&gt;&lt;br /&gt;If you use Norton AntiVirus 2005, Symantec AntiVirus Corporate Edition 9.0, or earlier products, LiveUpdate definitions are updated weekly. The exception is major outbreaks, when definitions are updated more often.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;The latest Intelligent Updater virus definitions can be obtained here: &lt;a href="http://securityresponse.symantec.com/avcenter/defs.download.html"&gt;Intelligent Updater virus definitions&lt;/a&gt;. For detailed instructions read the document: &lt;a href="http://service1.symantec.com/SUPPORT/nav.nsf/docid/1998082013035306?OpenDocument&amp;src=sec_doc_nam"&gt;How to update virus definition files using the Intelligent Updater&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3.  To run a full system scan&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;ol style="text-align: justify; font-family: verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Start your Symantec antivirus program and make sure that it is configured to scan all the files.&lt;br /&gt;&lt;br /&gt;For Norton AntiVirus consumer products: Read the document: &lt;a href="http://service1.symantec.com/SUPPORT/nav.nsf/docid/1999110513272906?OpenDocument&amp;src=sec_doc_nam"&gt;How to configure Norton AntiVirus to scan all files&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For Symantec AntiVirus Enterprise products: Read the document: &lt;a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2002052213125148?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to verify that a Symantec Corporate antivirus product is set to scan all files&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Run a full system scan.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;If any files are detected, follow the instructions displayed by your antivirus program.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Important:&lt;/strong&gt; If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, &lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&amp;src=sec_doc_nam"&gt;How to start the computer in Safe Mode&lt;/a&gt;. Once you have restarted in Safe mode, run the scan again.&lt;br /&gt;After the files are deleted, restart the computer in Normal mode and proceed with the next section.&lt;br /&gt;&lt;br /&gt;Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Title:&lt;/strong&gt; [FILE PATH]&lt;br /&gt;&lt;strong&gt;Message body:&lt;/strong&gt; Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4.  To delete the value from the registry&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Important:&lt;/strong&gt; Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: &lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to make a backup of the Windows registry&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;          &lt;/div&gt;&lt;ol style="text-align: justify; font-family: verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Click &lt;strong&gt;Start &gt; Run&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Type &lt;strong&gt;regedit &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Click OK.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has &lt;a href="http://securityresponse.symantec.com/avcenter/venc/data/tool.to.reset.shellopencommand.registry.keys.html"&gt;developed a tool&lt;/a&gt; to resolve this problem.&lt;a href="http://securityresponse.symantec.com/avcenter/venc/data/tool.to.reset.shellopencommand.registry.keys.html"&gt; Download and run this tool&lt;/a&gt;, and then continue with the removal.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Restore the following registry entries to their original values, if required:&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = "0"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page"&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Exit the Registry Editor.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;source: www.symantec.com&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4937850346882354008?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4937850346882354008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4937850346882354008'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/w32rencomm.html' title='W32.Renco@mm'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2412195082940842012</id><published>2007-06-21T18:49:00.000-07:00</published><updated>2007-06-21T19:06:09.709-07:00</updated><title type='text'>Trojan.Spamdes</title><content type='html'>&lt;h1  style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;Trojan.Spamdes&lt;/span&gt;&lt;/h1&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;Summary&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div  style="font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Discovered: &lt;/strong&gt;June 21, 2007&lt;/span&gt;&lt;/div&gt; &lt;div  style="font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Updated: &lt;/strong&gt;June 21, 2007 8:14:36 AM&lt;/span&gt;&lt;/div&gt; &lt;div  style="font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Type: &lt;/strong&gt;Trojan&lt;/span&gt;&lt;/div&gt; &lt;div  style="font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Infection Length: &lt;/strong&gt;91,648 bytes&lt;/span&gt;&lt;/div&gt; &lt;div  style="font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Systems Affected: &lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/span&gt;&lt;/div&gt; &lt;span style="font-size:100%;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Trojan.Spamdes is a Trojan horse that infects a Windows system file and sends spam.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;Technical Details&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong style="font-family: verdana;"&gt;Systems Affected: &lt;/strong&gt;&lt;span style="font-family:verdana;"&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div  style="text-align: justify;font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;Once executed, the Trojan infects the following file:&lt;br /&gt;%System%\driver\ndis.sys&lt;br /&gt;&lt;br /&gt;When the infected file is loaded, it will drop a .dll file into the following location:&lt;br /&gt;C:\cd[FOUR NUMBERS].nls&lt;br /&gt;&lt;br /&gt;The dropped .dll file then attempts to connect to the following site to download configuration files to send spam:&lt;br /&gt;fimart.biz&lt;br /&gt;&lt;br /&gt;It then sends spam to email addresses contained in the configuration files.&lt;/span&gt;&lt;/div&gt;&lt;h3  style="text-align: justify;font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Recommendations&lt;/span&gt;&lt;/h3&gt;&lt;p  style="text-align: justify;font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":&lt;/span&gt;&lt;/p&gt;&lt;div  style="text-align: justify;font-family:verdana;"&gt;     &lt;/div&gt;&lt;ul  style="text-align: justify;font-family:verdana;" class="listSQbl"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;If a &lt;a href="http://securityresponse.symantec.com/avcenter/refa.html#blended_threat"&gt;blended threat&lt;/a&gt; exploits one or more network services, disable, or block access to, those services until a patch is applied.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div  style="text-align: justify;font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;Removal Instruction&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt; &lt;span style="font-size:85%;"&gt;&lt;strong style="font-family: verdana;"&gt;Systems Affected: &lt;/strong&gt;&lt;span style="font-family:verdana;"&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div  style="text-align: justify;font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;ol  style="text-align: justify;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Disable System Restore (Windows Me/XP).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Update the virus definitions.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Run a full system scan.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div  style="text-align: justify;font-family:verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;For specific details on each of these steps, read the following instructions.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1.  To disable System Restore (Windows Me/XP)&lt;/strong&gt;&lt;br /&gt;If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.&lt;br /&gt;&lt;br /&gt;Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.&lt;br /&gt;&lt;br /&gt;Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.&lt;br /&gt;&lt;br /&gt;For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:&lt;br /&gt;&lt;/span&gt;     &lt;/div&gt;&lt;ul  style="text-align: justify;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&amp;src=sec_doc_nam"&gt;How to disable or enable Windows Me System Restore&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to turn off or turn on Windows XP System Restore&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div face="verdana" style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.&lt;br /&gt;&lt;br /&gt;For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: &lt;a href="http://support.microsoft.com/support/kb/articles/Q263/4/55.ASP"&gt;Antivirus Tools Cannot Clean Infected Files in the _Restore Folder&lt;/a&gt; (Article ID: Q263455).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2.  To update the virus definitions&lt;/strong&gt;&lt;br /&gt;Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:&lt;br /&gt;&lt;/span&gt;   &lt;/div&gt;&lt;ul  style="text-align: justify;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Running LiveUpdate, which is the easiest way to obtain virus definitions.&lt;br /&gt;If you use Norton AntiVirus 2006, Symantec AntiVirus Corporate Edition 10.0, or newer products, LiveUpdate definitions are updated daily. These products include newer technology.&lt;br /&gt;&lt;br /&gt;If you use Norton AntiVirus 2005, Symantec AntiVirus Corporate Edition 9.0, or earlier products, LiveUpdate definitions are updated weekly. The exception is major outbreaks, when definitions are updated more often.&lt;br /&gt;&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify; font-family: verdana;"&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;The latest Intelligent Updater virus definitions can be obtained here: &lt;a href="http://securityresponse.symantec.com/avcenter/defs.download.html"&gt;Intelligent Updater virus definitions&lt;/a&gt;. For detailed instructions read the document: &lt;a href="http://service1.symantec.com/SUPPORT/nav.nsf/docid/1998082013035306?OpenDocument&amp;src=sec_doc_nam"&gt;How to update virus definition files using the Intelligent Updater&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3.  To run a full system scan&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;ol  style="text-align: justify;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Start your Symantec antivirus program and make sure that it is configured to scan all the files.&lt;br /&gt;For Norton AntiVirus consumer products: Read the document: &lt;a href="http://service1.symantec.com/SUPPORT/nav.nsf/docid/1999110513272906?OpenDocument&amp;src=sec_doc_nam"&gt;How to configure Norton AntiVirus to scan all files&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For Symantec AntiVirus Enterprise products: Read the document: &lt;a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2002052213125148?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to verify that a Symantec Corporate antivirus product is set to scan all files&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Run a full system scan.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;If any files are detected, follow the instructions displayed by your antivirus program.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong style="font-family: verdana;"&gt;Important:&lt;/strong&gt;&lt;span style="font-family:verdana;"&gt; If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&amp;src=sec_doc_nam"&gt;How to start the computer in Safe Mode&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. Once you have restarted in Safe mode, run the scan again. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;After the files are deleted, restart the computer in Normal mode.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;source: www.symantec.com&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2412195082940842012?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2412195082940842012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2412195082940842012'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/trojanspamdes.html' title='Trojan.Spamdes'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4786044300069758806</id><published>2007-06-21T01:14:00.000-07:00</published><updated>2007-06-21T01:22:14.001-07:00</updated><title type='text'>ParasiteWare, Adware, Spyware, Malware, Page Hijackers,  Dialers</title><content type='html'>&lt;h3&gt;&lt;span style="font-size:100%;"&gt;ParasiteWare&lt;/span&gt;&lt;/h3&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;ParasiteWare is the term for any Adware that by default overwrites certain    affiliate tracking links. These tracking links are used by webmasters to sell    products and to help fund websites. The controversy is centered on companies    like WhenU, eBates, and Top Moxie, a popular maker of Adware applications. These    companies have release their software to assist users in getting credit for    rebates, cash back shopping, or contributions to funds. To the end user ParasiteWare    represents little in the way of a security threat.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Adware&lt;/span&gt;&lt;/span&gt; &lt;p align="justify"&gt;&lt;a href="http://www.spywareguide.com/category_show.php?id=5"&gt;Adware&lt;/a&gt;, also known as an Adbot, can do    a number of things from profile your online surfing and spending habits to popping    up annoying ad windows as you surf. In some cases Adware has been bundled (i.e.    peer-to-peer file swapping products) with other software without the user's    knowledge or slipped in the fine print of a EULA (End User License Agreement).    Not all Adware is bad, but often users are annoyed by adware's intrusive behavior.    Keep in mind that by removing Adware sometimes the program it came bundled with    for free may stop functioning. Some Adware, dubbed a "BackDoor Santa"    may not perform any activity other then profile a user's surfing activity for    study.&lt;/p&gt;  &lt;p align="justify"&gt;AdWare can be obnoxious in that it performs "drive-by downloads".    Drive-by downloads are accomplished by providing a misleading dialogue box or    other methods of stealth installation. Many times users have no idea they have    installed the application. Often Adware makers make their application difficult    to uninstall.&lt;/p&gt;  &lt;p align="justify"&gt;A "EULA" or End User License Agreement is the agreement you accept    when you click "OK" or "Continue" when you are installing    software. Many users never bother to read the EULA. &lt;/p&gt;  &lt;p align="justify"&gt;It is imperative to actually read this agreement before you install any software.    No matter how tedious the EULA, you should be able to find out the intent BEFORE    you install the software. If you have questions about the EULA- e-mail the company    and ask them for clarification.&lt;/p&gt;&lt;span style="font-weight: bold;"&gt;Spyware&lt;/span&gt; &lt;p&gt;&lt;a href="http://www.spywareguide.com/category_show.php?id=3"&gt;Spyware&lt;/a&gt; is potentially more dangerous    beast than Adware because it can record your keystrokes, history, passwords,    and other confidential and private information. Spyware is often sold as a spouse monitor,    child monitor, a surveillance tool or simply as a tool to spy on users to gain    unauthorized access. Spyware is also known as: snoopware, PC surveillance, &lt;a href="http://www.spywareguide.com/category_show.php?id=3"&gt;key    logger&lt;/a&gt;, system recorders, Parental control software, PC recorder, Detective    software and Internet monitoring software. &lt;/p&gt;  &lt;p&gt;Spyware covertly gathers user information and activity without the user's knowledge.    Spy software can record your keystrokes as you type them, passwords, credit    card numbers, sensitive information, where you surf, chat logs, and can even    take random screenshots of your activity. Basically whatever you do on the computer    is completely viewable by the spy. You do not have to be connected to the Internet    to be spied upon. &lt;/p&gt;  &lt;p&gt;The latest permutations of Spyware include the use of routines to mail out    user activity via e-mail or posting information to the web where the spy can    view it at their leisure. Also many spyware vendors use "stealth routines"    and "polymorphic" (meaning to change" techniques to avoid detection    and removal by popular anti-spy software. In some cases Spyware vendors have    went as far as to counter-attack anti-spy packages by attempting to break their    use. In addition they may use routines to re-install the spyware application    after it has been detected.&lt;/p&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Malware&lt;/span&gt; &lt;p&gt;Malware is slang for malicious software. Malware is software designed specifically    to disrupt a computer system. A &lt;a href="http://www.spywareguide.com/category_show.php?id=1"&gt;trojan horse&lt;/a&gt;    , &lt;a href="http://www.spywareguide.com/category_show.php?id=4"&gt;worm&lt;/a&gt; or a &lt;a href="http://www.spywareguide.com/category_show.php?id=2"&gt;virus&lt;/a&gt;    could be classified as Malware. Some advertising software can be malicious in    that it can try to re-install itself after you remove it. &lt;/p&gt;  &lt;p&gt;For the purpose of simplicity Malware is software specifically engineered to    damage your machine or interrupt the normal computing environment. &lt;/p&gt;  &lt;p&gt;Examples of Malware include:&lt;/p&gt;  &lt;h3 style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;Page Hijackers&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;&lt;a href="http://www.spywareguide.com/category_show.php?id=7"&gt;Hijackers&lt;/a&gt; are applications that attempt    to usurp control of the user's home page and reset it with one of the hijackers    choosing. They are a low security threat, but obnoxious. Most Hijackers use    stealth techniques or trick dialogue boxes to perform installation.&lt;/p&gt;  &lt;h3 style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt; Dialers&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;A &lt;a href="http://www.spywareguide.com/category_show.php?id=8"&gt;dialer&lt;/a&gt; is a type of software used by    pornographic vendors. Once dialer software is downloaded the user is disconnected    from their modem's usual Internet service provider and another phone number    and the user is billed. While dialers do not spy on users they are malevolent    in nature because they can cause huge financial harm to the victim.&lt;/p&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;Source: http://www.spywareguide.com/txt_intro.php&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4786044300069758806?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4786044300069758806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4786044300069758806'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/parasiteware-adware-spyware-malware.html' title='ParasiteWare, Adware, Spyware, Malware, Page Hijackers,  Dialers'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-5289102981119569973</id><published>2007-06-21T00:42:00.000-07:00</published><updated>2007-06-21T00:43:50.236-07:00</updated><title type='text'>About Spyware</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;What Is Spyware?&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Spyware is a general term used to describe software that performs certain behaviors such as advertising, collecting personal information, or changing the configuration of your computer, generally without appropriately obtaining your consent first. &lt;p&gt;Spyware is often associated with software that displays advertisements (called adware) or software that tracks personal or sensitive information. &lt;/p&gt;&lt;p&gt;That does not mean all software that provides ads or tracks your online activities is bad. For example, you might sign up for a free music service, but you "pay" for the service by agreeing to receive targeted ads. If you understand the terms and agree to them, you may have decided that it is a fair tradeoff. You might also agree to let the company track your online activities to determine which ads to show you.&lt;/p&gt;&lt;p&gt;Other kinds of spyware make changes to your computer that can be annoying and can cause your computer slow down or crash. &lt;/p&gt;&lt;p&gt;These programs can change your Web browser's home page or search page, or add additional components to your browser you don't need or want. These programs also make it very difficult for you to change your settings back to the way you originally had them. &lt;/p&gt;&lt;p&gt;The key in all cases is whether or not you (or someone who uses your computer) understand what the software will do and have agreed to install the software on your computer.&lt;/p&gt;&lt;p&gt;There are a number of ways spyware or other unwanted software can get on your computer. A common trick is to covertly install the software during the installation of other software you want such as a music or video file sharing program. &lt;/p&gt;Whenever you install something on your computer, make sure you carefully read all disclosures, including the license agreement and privacy statement. Sometimes the inclusion of unwanted software in a given software installation is documented, but it might appear at the end of a license agreement or privacy statement.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Source: www.microsoft.com&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-5289102981119569973?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5289102981119569973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/5289102981119569973'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/about-spyware.html' title='About Spyware'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2280092410994243509</id><published>2007-06-20T23:38:00.000-07:00</published><updated>2007-06-20T23:39:36.223-07:00</updated><title type='text'>Downloader-BCS</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Profile&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table class="newTableFrame" border="0" cellspacing="1" width="96%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="newTableSubHeading" width="35%"&gt;Risk Assessment&lt;/td&gt;     &lt;td class="newTableBody"&gt; &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Home Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Corporate Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Discovered:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/18/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Added:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/18/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Origin:&lt;/td&gt;     &lt;td class="newTableBody"&gt;N/A&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Length:&lt;/td&gt;     &lt;td class="newTableBody"&gt;game.class (24,739 bytes)&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Type:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Trojan&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;SubType:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Downloader&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;DAT Required:&lt;/td&gt;     &lt;td class="newTableBody"&gt;5055&lt;/td&gt;   &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Virus Characteristics&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;&lt;p&gt;Downloader-BCS is a java applet trojan intended to silently download and execute malicious content from a remote server.&lt;/p&gt; &lt;p target="_blank"&gt;The trojan exploits a Buffer Overflow Vulnerability in &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1"&gt;Java Runtime Environment&lt;/a&gt; (JRE) while parsing certain image file formats like GIF.&lt;/p&gt; &lt;p&gt;When the applet is run on the victim machine having a vulnerable installation of Java Runtime Environment, the trojan downloads another malware from the remote server and executes it. &lt;/p&gt; &lt;p&gt;The following files are downloaded . The applet file (game.class) is of 24,739 bytes in size.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;game.class --&gt; Malicious Java applet &lt;/li&gt;&lt;li&gt;picsj.exe  --&gt; variant of &lt;a href="http://vil.nai.com/vil/content/v_134762.htm"&gt;Proxy-Agent.o&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The trojan automatically connects to the following domain to download additional malware.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;http://216.32.92[blocked]/&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Indications of Infection&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;&lt;ul&gt;&lt;li&gt; Outgoing HTTP traffic to the domain  http://216.32.92[blocked]/&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; As the website being communicated is normally controlled by the malware author, any files being downloaded can be remotely modified and the behavior of these new binaries altered - possibly with every user infection.&lt;/p&gt;&lt;/div&gt;  &lt;h3 style="font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;Method of Infection&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;   &lt;p onclick="javascript:window.open('/VirusInfo/VIL/', 'VIL', 'width=565,height=400,scrollbars=yes,resizable=yes,menubar=no,toolbar=no,directories=no')" href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=142494#"&gt;This downloader trojan exists purely to steal sensitive information, download and run other remote files. The downloader is run on the victim machine in a way that assists in masking its activity.&lt;/p&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Removal Instructions&lt;/span&gt;&lt;/div&gt;   &lt;div class="vilProfileSection"&gt;&lt;p&gt;&lt;span style="color:#000000;"&gt;A combination of the &lt;a href="http://www.mcafee.com/apps/downloads/security_updates/dat.asp"&gt;latest DATs and the Engine &lt;/a&gt;will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx" target="_blank"&gt;Additional Windows ME/XP removal considerations&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Aliases&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;Exploit.java.gimsh.a (Kaspersky), Troj/Dloadr-AYQ (Sophos)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2280092410994243509?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2280092410994243509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2280092410994243509'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/downloader-bcs.html' title='Downloader-BCS'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-8270461793840849239</id><published>2007-06-20T23:23:00.000-07:00</published><updated>2007-06-20T23:25:31.044-07:00</updated><title type='text'>W32/Naplik.a</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Profile&lt;br /&gt;&lt;/span&gt;&lt;table class="newTableFrame" border="0" cellspacing="1" width="96%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="newTableSubHeading" width="35%"&gt;&lt;br /&gt;Risk Assessment&lt;/td&gt;     &lt;td class="newTableBody"&gt; &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Home Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Corporate Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Discovered:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/18/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Added:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/18/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Origin:&lt;/td&gt;     &lt;td class="newTableBody"&gt;N/A&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Length:&lt;/td&gt;     &lt;td class="newTableBody"&gt;N/A&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Type:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Virus&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;SubType:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Win32&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;DAT Required:&lt;/td&gt;     &lt;td class="newTableBody"&gt;5055&lt;/td&gt;   &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Virus Characteristics&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;&lt;p&gt;W32/Naplik.a is an appending virus for the Windows platform.  This file infector infects .EXE files by copying its code to the end of the file, in a new section &lt;strong&gt;".k0kus"&lt;/strong&gt; and the file's entry point is modified to point to the virus code. &lt;em&gt;(&lt;u&gt;Note&lt;/u&gt;: The virus did not replicate when we test it).&lt;/em&gt;&lt;/p&gt; &lt;p&gt;Upon execution, it injects its dll routine "VirusBoot.dll" into explorer.exe, which is in charge of the infection.&lt;br /&gt;It also contacts three different pages from the following website:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;http://www.aabbcc.us/sys/lm/&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;to download an eventual update of the virus (the downloaded updates are stored in &lt;strong&gt;%Sysdir%\svchost.exe&lt;/strong&gt;.) &lt;/li&gt;&lt;li&gt;to report that a machine has been infected  &lt;/li&gt;&lt;li&gt;to send information collected from the machine.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;em&gt;&lt;u&gt;Note:&lt;/u&gt; this virus is currently being investigated and more information will probably come later.&lt;/em&gt;&lt;/p&gt; &lt;p style="font-weight: bold;"&gt;Indications of Infection&lt;/p&gt;&lt;/div&gt;   &lt;div class="vilProfileSection"&gt;&lt;ul&gt;&lt;li&gt;Attempts to connect to &lt;strong&gt;www.aabbcc.us&lt;/strong&gt; &lt;/li&gt;&lt;li&gt;Increase the size of EXE files&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Method of Infection&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;   &lt;p onclick="javascript:window.open('/VirusInfo/VIL/', 'VIL', 'width=565,height=400,scrollbars=yes,resizable=yes,menubar=no,toolbar=no,directories=no')" href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=142490#"&gt;W32/Naplik.a is a file infecting virus. Infection starts with manual execution of the binary.&lt;br /&gt;&lt;/p&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Removal Instructions&lt;/span&gt;&lt;/div&gt;   &lt;div class="vilProfileSection"&gt;AVERT recommends to always use &lt;a href="http://www.mcafee.com/apps/downloads/security_updates/dat.asp" target="_blank"&gt;latest DATs and engine&lt;/a&gt;. This threat will be cleaned if you have this combination.&lt;b&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx" target="_blank"&gt;Additional Windows ME/XP removal considerations&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/b&gt;&lt;/div&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Aliases&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;W32.Naplik (NAV)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-8270461793840849239?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8270461793840849239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/8270461793840849239'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/w32naplika.html' title='W32/Naplik.a'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4484461203732522422</id><published>2007-06-20T23:20:00.000-07:00</published><updated>2007-06-20T23:22:58.693-07:00</updated><title type='text'>W32/Zaflen.a</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Profile&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table class="newTableFrame" border="0" cellspacing="1" width="96%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="newTableSubHeading" width="35%"&gt;Risk Assessment&lt;/td&gt;     &lt;td class="newTableBody"&gt; &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Home Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Corporate Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Discovered:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/15/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Added:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/15/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Origin:&lt;/td&gt;     &lt;td class="newTableBody"&gt;N/A&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Length:&lt;/td&gt;     &lt;td class="newTableBody"&gt;1,72,032 bytes&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Type:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Virus&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;SubType:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Win32&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;DAT Required:&lt;/td&gt;     &lt;td class="newTableBody"&gt;5054&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;h3&gt;Virus Characteristics&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;&lt;p&gt;When this malware is executed, it creates the following folders.&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;%My Documents%\Rated R Pictures  &lt;/li&gt;&lt;li&gt;%Windir%\gorgle  &lt;/li&gt;&lt;li&gt;%Windir%\setup&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;   &lt;p&gt;This malware creates multiple copies of itself in several locations. Some of these are,&lt;br /&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;c:\CoolWorld.exe  &lt;/li&gt;&lt;li&gt;c:\Documents and Settings\All Users\Desktop\Microsoft Word Document.scr  &lt;/li&gt;&lt;li&gt;c:\Documents and Settings\All Users\Start Menu\New Microsoft Word Document.scr  &lt;/li&gt;&lt;li&gt;c:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word Document.scr  &lt;/li&gt;&lt;li&gt;c:\Documents and Settings\All Users\Start Menu\Programs\Startup\folderwiz.com  &lt;/li&gt;&lt;li&gt;%userprofile%\My Documents\My Picture.com  &lt;/li&gt;&lt;li&gt;%userprofile%\My Documents\Rated R Pictures.com  &lt;/li&gt;&lt;li&gt;%userprofile%\My Documents\My Pictures\mskernel.exe  &lt;/li&gt;&lt;li&gt;%userprofile%\NetHood\Hot Picture.com  &lt;/li&gt;&lt;li&gt;%userprofile%\PrintHood\Printing Information.com  &lt;/li&gt;&lt;li&gt;%userprofile%\SendTo\Image Editor.com  &lt;/li&gt;&lt;li&gt;%userprofile%\Start Menu\Image Viewer.com  &lt;/li&gt;&lt;li&gt;c:\Program Files\phil.constitution.scr  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\agila.scr  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\AutoRun.ini  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\lsass.exe  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\services.exe  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\gorgle\csrss.exe  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\setup\mskernel.exe  &lt;/li&gt;&lt;li&gt;c:\WINDOWS\system32\mskernel.exe&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;It copies itself into multiple drives in the system.&lt;/p&gt; &lt;p&gt;It also creates the following file, for executing the malware when the drive is accessed.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;C:\autorun.inf&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;This malware then searches for and infects the files with the following extensions&lt;/p&gt; &lt;ul&gt;&lt;li&gt;doc  &lt;/li&gt;&lt;li&gt;rtf  &lt;/li&gt;&lt;li&gt;jpg  &lt;/li&gt;&lt;li&gt;gif  &lt;/li&gt;&lt;li&gt;png&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;p&gt;It infects the above files by prepending itself to these files.&lt;br /&gt;It changes the icon of the infected files to M.S.Word icon and the extension to scr or exe.&lt;br /&gt;It also appends 35 bytes to the end of file along with the extension of the original file.&lt;br /&gt;&lt;br /&gt;This malware adds the follwing registry entries for loading at system startup&lt;/p&gt; &lt;ul&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinRun"   Data - C:\WINDOWS\AutoRun.ini &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "(Default)"   Data - \WINDOWS\lsass.exe&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;It adds the following registry entries to disable Run, folder options and to hide the file extensions.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer "NoFolderOptions" &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer "NoRun" &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer "Run" &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideFileExt "CheckedValue"&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;It also adds/modifies certain other registry entries for its functioning.&lt;/p&gt; &lt;p&gt;This malware also drops the file "email32.vbs" into the Windows directory, which is a mass mailer component detected as W32/PetTick.vbs.&lt;br /&gt;This is used to send out copies of the file infector via e-mail using harvested e-mail addresses from the system.&lt;/p&gt;&lt;/div&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Indications of Infection&lt;/span&gt; &lt;div class="vilProfileSection"&gt;&lt;p&gt;Changing of the file icon for the file types - png, jpg, gif to M.S.Word icon.&lt;/p&gt; &lt;p&gt;Increase in file size by 172067 bytes for the infected files.&lt;/p&gt; &lt;p&gt;Presence of the files and registry entries mentioned.&lt;/p&gt;&lt;/div&gt;  &lt;h3&gt;&lt;span style="font-size:100%;"&gt;Method of Infection&lt;/span&gt;&lt;/h3&gt; &lt;div class="vilProfileSection"&gt;   &lt;p onclick="javascript:window.open('/VirusInfo/VIL/', 'VIL', 'width=565,height=400,scrollbars=yes,resizable=yes,menubar=no,toolbar=no,directories=no')" href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;virus_k=142474#"&gt;This parasitic file infector spreads by copying itself to multiple locations and to different drives in the system.&lt;br /&gt;It also spreads by using the mass mailing component detected as W32/PetTick.vbs.&lt;br /&gt;The files get infected when the user executes the malware which is disguised as being an M.S.Word document.&lt;/p&gt;&lt;span style="font-weight: bold;"&gt;Removal Instructions&lt;/span&gt;&lt;/div&gt;   &lt;div class="vilProfileSection"&gt;&lt;p&gt;&lt;span style="color:#000000;"&gt;A combination of the &lt;a href="http://www.mcafee.com/apps/downloads/security_updates/dat.asp"&gt;latest DATs and the Engine &lt;/a&gt;will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx" target="_blank"&gt;Additional Windows ME/XP removal considerations&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4484461203732522422?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4484461203732522422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4484461203732522422'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/w32zaflena.html' title='W32/Zaflen.a'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4368855364944388954</id><published>2007-06-20T23:12:00.000-07:00</published><updated>2007-06-20T23:17:19.915-07:00</updated><title type='text'>Downloader-BCV Virus</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Profile Virus&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table class="newTableFrame" border="0" cellspacing="1" width="96%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="newTableSubHeading" width="35%"&gt;Risk Assessment&lt;/td&gt;     &lt;td class="newTableBody"&gt; &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Home Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;  - Corporate Users:&lt;/td&gt;     &lt;td class="newTableBody" style="color: rgb(255, 163, 0);"&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Discovered:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/20/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Date Added:&lt;/td&gt;     &lt;td class="newTableBody"&gt;6/20/2007&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Origin:&lt;/td&gt;     &lt;td class="newTableBody"&gt;N/A&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Length:&lt;/td&gt;     &lt;td class="newTableBody"&gt;8.192&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;Type:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Trojan&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;SubType:&lt;/td&gt;     &lt;td class="newTableBody"&gt;Downloader&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td class="newTableSubHeading"&gt;DAT Required:&lt;/td&gt;     &lt;td class="newTableBody"&gt;5059&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;h3&gt;&lt;span style="font-size:100%;"&gt;Virus Characteristics&lt;/span&gt;&lt;/h3&gt;Detection was added to cover for a malicious 32 bit PE downloader file originally called "&lt;strong&gt;systime.exe&lt;/strong&gt;" , having a filesize of 8.192 bytes. &lt;p&gt;Upon running, it runs silently, no gui messageboxes appear on the screen.&lt;/p&gt; &lt;p&gt;It immediately copies itself onto the %system32 folder and creates a registry entry to run automatically upon system start, for example on win2k:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;c:\WINNT\system32\systime.exe&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;It might also copy itself to the root of the c: drive, with the c:\systime.exe location actually hardcoded inside.&lt;/p&gt; &lt;p&gt;It tries to download a binary called "network.exe" from : &lt;a href="http://drsun/####.go#.icp"&gt;http://drsun####.go#.icp&lt;/a&gt;##.## , but at test time the binary was not accessible. The exact address is changes on purpose here with # markings.&lt;/p&gt;&lt;h3&gt;&lt;span style="font-size:100%;"&gt;Indications of Infection&lt;/span&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Presence of "&lt;strong&gt;systime.exe&lt;/strong&gt;" , having a filesize of 8.192 bytes.&lt;/li&gt;&lt;li&gt;Network connections to  &lt;a href="http://drsun/####.go#.icp"&gt;http://drsun####.go#.icp&lt;/a&gt;##.## , the exact address is changes on purpose here with # markings.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Removal Instructions&lt;/span&gt; &lt;div class="vilProfileSection"&gt;&lt;p&gt;&lt;b&gt;All Users&lt;/b&gt;:&lt;br /&gt;Use current &lt;a href="http://www.mcafee.com/apps/downloads/security_updates/dat.asp" target="_blank"&gt;engine and DAT files&lt;/a&gt; for detection and removal.&lt;/p&gt; &lt;p&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx" target="_blank"&gt;Additional Windows ME/XP removal considerations&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-4368855364944388954?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4368855364944388954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/4368855364944388954'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/06/downloader-bcv-virus.html' title='Downloader-BCV Virus'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-2804754317903282186</id><published>2007-04-26T06:27:00.000-07:00</published><updated>2007-04-26T12:10:23.976-07:00</updated><title type='text'>Fantibag.B/Email-Worm.Win32.Bagle.bs</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="font-weight: bold;"&gt;Summary&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Fantibag.B is a trojan that installs a packet filter for preventing of downloading AV companies database updates and security patches. It is related to recent Bagle/Mitglieder trojans.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style=";font-family:Arial,sans-serif;" &gt;&lt;span style=";font-family:Arial,sans-serif;" &gt;&lt;span style=";font-family:Arial,sans-serif;" &gt;&lt;span style=";font-family:Arial,sans-serif;" &gt;Detailed Description&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; &lt;b&gt; System installation &lt;/b&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; When the trojan's file is executed, it copies itself in Windows directory with the name 'firewall_anti.exe'. It installs the following registry key for ensuring it will be executed at system startup: &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;pre  style="color: rgb(0, 0, 128);font-size:8pt;"&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"firewall_anti" = "%WinDir%\firewall_anti.exe"&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;  &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; The trojan drops a DLL 'firewall_anti.dll' in the Windows direcory and injects this file in address space of Internet Explorer. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; &lt;b&gt; Packet filtering &lt;/b&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; When the dropped DLL is activated, it modifies the network interface with Microsoft RAS packet filtering API. It adds a filter that blocks access to following AV companies and other security related sites: &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;pre  style="color: rgb(0, 0, 128);font-size:8pt;"&gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;font-size:100%;"  &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt;&lt;span style="color: rgb(0, 0, 64);font-family:Arial,sans-serif;" &gt; ftpav.ca.com&lt;br /&gt;www.pandasoftware.com&lt;br /&gt;pandasoftware.com&lt;br /&gt;clamav.net&lt;br /&gt;www.clamav.net&lt;br /&gt;www.bitdefender.com&lt;br /&gt;bitdefender.com&lt;br /&gt;ravantivirus.com&lt;br /&gt;www.ravantivirus.com&lt;br /&gt;drweb.ru&lt;br /&gt;www.drweb.com&lt;br /&gt;drweb.com&lt;br /&gt;antivir.de&lt;br /&gt;www.antivir.de&lt;br /&gt;216.200.68.152&lt;br /&gt;212.113.20.69&lt;br /&gt;63.210.193.12&lt;br /&gt;84.53.142.22&lt;br /&gt;84.53.142.6&lt;br /&gt;kaspersky.ru&lt;br /&gt;grisoft.com&lt;br /&gt;www3.ca.com&lt;br /&gt;www.viruslist.ru&lt;br /&gt;www.viruslist.com&lt;br /&gt;www.trendmicro.com&lt;br /&gt;www.symantec.com&lt;br /&gt;www.sophos.com&lt;br /&gt;www.networkassociates.com&lt;br /&gt;www.nai.com&lt;br /&gt;www.my-etrust.com&lt;br /&gt;www.mcafee.com&lt;br /&gt;www.kaspersky.ru&lt;br /&gt;www.kaspersky.com&lt;br /&gt;www.kaspersky-labs.com&lt;br /&gt;www.grisoft.com&lt;br /&gt;www.fastclick.net&lt;br /&gt;www.f-secure.com&lt;br /&gt;www.awaps.net&lt;br /&gt;www.avp.ru&lt;br /&gt;www.avp.com&lt;br /&gt;www.avp.ch&lt;br /&gt;windowsupdate.microsoft.com&lt;br /&gt;viruslist.ru&lt;br /&gt;viruslist.com&lt;br /&gt;vil.nai.com&lt;br /&gt;us.mcafee.com&lt;br /&gt;updates5.kaspersky-labs.com&lt;br /&gt;updates4.kaspersky-labs.com&lt;br /&gt;updates3.kaspersky-labs.com&lt;br /&gt;updates2.kaspersky-labs.com&lt;br /&gt;updates1.kaspersky-labs.com&lt;br /&gt;updates.symantec.com&lt;br /&gt;update.symantec.com&lt;br /&gt;trendmicro.com&lt;br /&gt;symantec.com&lt;br /&gt;support.microsoft.com&lt;br /&gt;spd.atdmt.com&lt;br /&gt;sophos.com&lt;br /&gt;service1.symantec.com&lt;br /&gt;securityresponse.symantec.com&lt;br /&gt;secure.nai.com&lt;br /&gt;rads.mcafee.com&lt;br /&gt;phx.corporate-ir.net&lt;br /&gt;office.microsoft.com&lt;br /&gt;networkassociates.com&lt;br /&gt;nai.com&lt;br /&gt;my-etrust.com&lt;br /&gt;msdn.microsoft.com&lt;br /&gt;media.fastclick.net&lt;br /&gt;mcafee.com&lt;br /&gt;mast.mcafee.com&lt;br /&gt;liveupdate.symantecliveupdate.com&lt;br /&gt;liveupdate.symantec.com&lt;br /&gt;kaspersky.com&lt;br /&gt;kaspersky-labs.com&lt;br /&gt;ids.kaspersky-labs.com&lt;br /&gt;go.microsoft.com&lt;br /&gt;ftp.sophos.com&lt;br /&gt;ftp.kasperskylab.ru&lt;br /&gt;ftp.f-secure.com&lt;br /&gt;ftp.downloads2.kaspersky-labs.com&lt;br /&gt;ftp.avp.ch&lt;br /&gt;fastclick.net&lt;br /&gt;f-secure.com&lt;br /&gt;engine.awaps.net&lt;br /&gt;downloads4.kaspersky-labs.com&lt;br /&gt;downloads3.kaspersky-labs.com&lt;br /&gt;downloads2.kaspersky-labs.com&lt;br /&gt;downloads1.kaspersky-labs.com&lt;br /&gt;downloads.microsoft.com&lt;br /&gt;downloads-us3.kaspersky-labs.com&lt;br /&gt;downloads-us2.kaspersky-labs.com&lt;br /&gt;downloads-us1.kaspersky-labs.com&lt;br /&gt;downloads-eu1.kaspersky-labs.com&lt;br /&gt;download.microsoft.com&lt;br /&gt;download.mcafee.com&lt;br /&gt;dispatch.mcafee.com&lt;br /&gt;customer.symantec.com&lt;br /&gt;clicks.atdmt.com&lt;br /&gt;click.atdmt.com&lt;br /&gt;www.ca.com&lt;br /&gt;ca.com&lt;br /&gt;banners.fastclick.net&lt;br /&gt;banner.fastclick.net&lt;br /&gt;awaps.net&lt;br /&gt;avp.ru&lt;br /&gt;avp.com&lt;br /&gt;avp.ch&lt;br /&gt;atdmt.com&lt;br /&gt;ar.atwola.com&lt;br /&gt;ads.fastclick.net&lt;br /&gt;ad.fastclick.net&lt;br /&gt;ad.doubleclick.net&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt; &lt;span style="font-size:100%;"&gt;&lt;span style="font-family:arial;"&gt;Source: http://www.f-secure.com/v-descs/fantibag_b.shtml&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-2804754317903282186?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2804754317903282186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/2804754317903282186'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/04/fantibagbemail-wormwin32baglebs.html' title='Fantibag.B/Email-Worm.Win32.Bagle.bs'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-6428773861690099321</id><published>2007-04-11T20:17:00.000-07:00</published><updated>2008-12-10T13:38:42.344-08:00</updated><title type='text'>MSBLAST.EXE worm aka Blaster.A, LoveSan or Msblast.A?</title><content type='html'>&lt;span style="color: rgb(128, 0, 64);font-family:Arial;" &gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;What is the MSBLAST.EXE worm aka Blaster.A, LoveSan or Msblast.A?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;The MSBLAST.A worm infects machines via network connecti&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;ons. It can attack entire of computers or one single computer connected to the Internet. The worm exploits a known windows  that is easily patched, however few systems seem to have this patch installed. It attacks Windows 2000 and  machines and exploits the DCOM RPC Vulnerablity.  Depending on the system date it will start a Denial of Service attack against windowsupdate.com, this makes it difficult to download the needed p&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;atches and allow the worm to infect as many machines as it can before being disabled. However, as of August 15th, &lt;a href="http://www.msnbc.com/news/952935.asp?vts=081520032225"&gt;Microsoft decided to kill the windowsupdate.com&lt;/a&gt;  to lessen the impact from this denial of service attack. MSBLAST can also cause widespread system instability including but not limited to Windows Blue screens, out of , changes to Control Panel, inability to use functions in browser, and many more oddities&lt;/span&gt;&lt;/small&gt;&lt;br /&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Download the Windows patches for this vulnerability by clicking on the links below:&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;ul&gt;&lt;li&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&amp;displaylang=en&lt;/li&gt;&lt;li&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c8b8a846-f541-4c15-8c9f-220354449117&amp;amp;displaylang=en&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;These Windows vulnerabilities are patched by using Windows Update to download all the critical updates for your system. However in some cases, people have reported getting an &lt;strong&gt;error 0x800A138F&lt;/strong&gt; when trying to download updates. If you are receiving an error similar to this, r&lt;/small&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;ead &lt;a href="http://www.updatexp.com/0x800A138F.html"&gt;Marc Liron's excellent article&lt;/a&gt; about solving this at his &lt;a href="http://www.updatexp.com/"&gt;updatexp.com&lt;/a&gt; website.&lt;br /&gt;&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;span style="color: rgb(128, 0, 64);font-family:Arial;" &gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;What is the DCOM Vulnerability?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;The DCOM vulnerability in Windows 2000 and XP can allow an &lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it. The worm causes a buffer overrun in the Remote Procedure Call (RPC) service. When this service is terminated the virus infects the machine and then tries to infect other machines.&lt;/span&gt;&lt;/small&gt;&lt;br /&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;span style="color: rgb(128, 0, 64);font-family:Arial;" &gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;What are the Symptoms of the MSBLAST worm?&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;You'll see a screen similar to the one below when you are infected, this will countdown to zero and literally shut down the system completely. The warning will state "This shutdown was initiated by NT AUTHORITY\SYSTEM". The message will read&lt;/span&gt;&lt;/small&gt;&lt;/p&gt;        &lt;p align="center"&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;"Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly"&lt;/span&gt;&lt;/small&gt;&lt;/p&gt;&lt;br /&gt;&lt;p align="center"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_dUgtpZrLHj8/Rh2m_bMH-tI/AAAAAAAAAAU/isaQIJ5XEbE/s1600-h/systemshutdown.jpg"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_dUgtpZrLHj8/Rh2m_bMH-tI/AAAAAAAAAAU/isaQIJ5XEbE/s320/systemshutdown.jpg" alt="" id="BLOGGER_PHOTO_ID_5052377965540145874" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;You can disable this shutdown by following the steps below during the countdown&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;ul&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Click on Start, Run&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Type in CMD and press ENTER&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Type in the following command and press Enter and than&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;  SHUTDOWN -A&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;/ul&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;This will terminate the shutdown, however in most cases the system may be to unstable to try to recover and may need to be rebooted anyway.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;span style="color: rgb(128, 0, 64);font-family:Arial;" &gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;How Does MSBLAST Infect My Computer?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;The worm creates a &lt;a href="http://www.webopedia.com/TERM/M/mutex.html"&gt;Mutex&lt;/a&gt; named "BILLY." If the &lt;a href="http://www.webopedia.com/TERM/M/mutex.html"&gt;mutex&lt;/a&gt; exists, the worm will exit.&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Adds the value:&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;  ”windows auto update" = MSBLAST.EXE (variant A)&lt;br /&gt;”windows auto update" = PENIS32.EXE (variant B)&lt;br /&gt;”Microsoft Inet xp.." = TEEKIDS.EXE (variant C)&lt;/small&gt;&lt;br /&gt;          &lt;small&gt;"Nonton Antivirus=mspatch.exe" (variant E)&lt;/small&gt;&lt;br /&gt;          &lt;small&gt;"Windows Automation" = "mslaugh.exe"&lt;/small&gt;           &lt;small&gt;(variant F)&lt;/small&gt;&lt;br /&gt;          &lt;small&gt;"www.hidro.4t.com"="enbiei.exe" (variant G)&lt;/small&gt;         &lt;br /&gt;          &lt;small&gt;&lt;br /&gt;to the registry key:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;so that the worm runs when you start Windows.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Calculates the IP address, based on the following algorithm, 40% of the time:&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;  Host IP: A.B.C.D&lt;br /&gt;sets D equal to 0.&lt;br /&gt;if C &gt; 20, will subtract a random value less than 20.&lt;br /&gt;Once calculated, the worm will start attempting to exploit the computer based on A.B.C.0, and then count up.&lt;br /&gt;This means the &lt;a id="KonaLink6" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.pchell.com/virus/msblast.shtml#"&gt;&lt;span style="font-weight: 400; position: static;font-family:Arial;font-size:13;color:#b00000;"   &gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-weight: 400; position: static; padding-bottom: 1px;font-family:Arial;font-size:13;color:#0000e0;"   &gt;Local &lt;/span&gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-weight: 400; position: static; padding-bottom: 1px;font-family:Arial;font-size:13;color:#0000e0;"   &gt;Area &lt;/span&gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-weight: 400; position: static; padding-bottom: 1px;font-family:Arial;font-size:13;color:#0000e0;"   &gt;Network&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; will be infected almost immediately and become become saturated with port 135 requests prior to exiting the local subnet.&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Calculates the IP address, based on many random numbers, 60% of the time:&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;  A.B.C.D&lt;br /&gt;set D equal to 0.&lt;br /&gt;sets A, B, and C to random values between 0 and 255.&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Sends data on TCP port 135 that may exploit the DCOM RPC vulnerability to allow the following actions to occur on the vulnerable &lt;a id="KonaLink7" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.pchell.com/virus/msblast.shtml#"&gt;&lt;span style="font-weight: 400; position: static;font-family:Arial;font-size:13;color:#b00000;"   &gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-weight: 400; position: static; padding-bottom: 1px;font-family:Arial;font-size:13;color:#0000e0;"   &gt;computer&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;:&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;  Create a hidden Cmd.exe remote shell that will listen on TCP port 4444.&lt;br /&gt;          &lt;b&gt;&lt;br /&gt;NOTE: &lt;/b&gt;Due to the random nature of how the worm constructs the exploit data, it may cause computers to crash if it sends incorrect data. This can cause blue screens, out of memory errors, etc.&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Listens on UDP port 69. When the worm receives a request, it will return the Msblast.exe binary.&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Sends the commands to the remote computer to reconnect to the infected host and to download and run Msblast.exe.&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on "windowsupdate.com."&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;  With the current logic, the worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;The &lt;a id="KonaLink9" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.pchell.com/virus/msblast.shtml#"&gt;&lt;span style="font-weight: 400; position: static;font-family:Arial;font-size:13;color:#b00000;"   &gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-weight: 400; position: static; padding-bottom: 1px;font-family:Arial;font-size:13;color:#0000e0;"   &gt;worm&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; contains the following text, which is never displayed:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;I just want to say LOVE YOU SAN!!&lt;br /&gt;billy gates why do you make this possible ? Stop making money and fix your software!!&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/small&gt;&lt;p align="left"&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;Windows 2000 Machines&lt;/strong&gt;&lt;/span&gt;&lt;/small&gt;&lt;/p&gt;        &lt;p&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;On Windows 2000 machines, I have seen the Control Panel icons switch to the left pane, functions like FIND in the browser stop working, and many other oddities.&lt;/span&gt;&lt;/small&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="color: rgb(128, 0, 64);font-family:Arial;" &gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;How can remove MSBLAST Worm?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Follow these steps in removing the MSBLAST or MSBLASTER worm.&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Disconnect your computer from the local area network or Internet&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Terminate the running program&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Open the Windows Task Manager by either pressing CTRL+ALT+DEL, selecting the Processes tab or selecting Task Manager and then the process tab on WinNT/2000/XP machines.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Locate one of the following programs (depending on variation), click on it and End Task or End Process&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;blockquote&gt;         &lt;p&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;&lt;small&gt;MSBLAST.EXE&lt;/small&gt;&lt;/strong&gt;&lt;br /&gt;        &lt;strong&gt;&lt;small&gt;PENIS32.EXE&lt;br /&gt;TEEKIDS.EXE&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;MSPATCH.EXE&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;MSLAUGH.EXE&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;ENBIEI.EXE&lt;/small&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Close  Task Manager&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Install the patches for the DCOM RPC Exploit, you can download the patches from the links below before disconnecting&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&amp;displaylang=en&lt;/li&gt;&lt;li&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c8b8a846-f541-4c15-8c9f-220354449117&amp;amp;displaylang=en&lt;/li&gt;&lt;li&gt;http://download.microsoft.com/download/6/5/1/651c3333-4892-431f-ae93-bf8718d29e1a/Q823980i.EXE&lt;/li&gt;&lt;li&gt;http://download.microsoft.com/download/6/5/1/651c3333-4892-431f-ae93-bf8718d29e1a/Q823980i.EXE&lt;/li&gt;&lt;li&gt;http://download.microsoft.com/download/a/7/5/a75b3c8f-5df0-451b-b526-cfc7c5c67df5/WindowsXP-KB823980-ia64-ENU.exe&lt;/li&gt;&lt;li&gt;http://download.microsoft.com/download/8/f/2/8f21131d-9df3-4530-802a-2780629390b9/WindowsServer2003-KB823980-x86-ENU.exe&lt;/li&gt;&lt;li&gt;http://download.microsoft.com/download/4/0/3/403d6631-9430-4ff6-a061-9072a4c50425/WindowsServer2003-KB823980-ia64-ENU.exe&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;If you receive a "cryptographic service" error when you try to apply the patch, please read the following excellent article on how to fix this error:&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;http://www.updatexp.com/cryptographic-service.html&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Block access to TCP port 4444 at the &lt;a id="KonaLink12" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.pchell.com/virus/msblast.shtml#"&gt;&lt;span style="font-weight: 400; position: static;font-family:serif;font-size:16;color:#b00000;"   &gt;&lt;span class="kLink" style="font-weight: 400; position: static;font-family:serif;font-size:16;color:#b00000;"   &gt;firewall&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; level, and then block the following ports, if they do not use the applications listed:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;TCP Port 135, "DCOM RPC"&lt;/li&gt;&lt;li&gt;UDP Port 69, "TFTP"&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Remove the Registry entries&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Click on Start, Run, Regedit&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;In the left panel go to&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;HKEY_LOCAL_MACHINE&gt;Software&gt;Microsoft&gt;Windows&gt;Current Version&gt;Run&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;In the right panel, right-click and delete the following entry&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;”windows auto update" = MSBLAST.EXE (variant A)&lt;br /&gt;”windows auto update" = PENIS32.EXE (variant B)&lt;br /&gt;”Microsoft Inet xp.." = TEEKIDS.EXE (variant C)&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;"Nonton Antivirus"=MSPATCH.EXE (variant E)&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;"Windows Automation" = "mslaugh.exe"&lt;/small&gt;         &lt;small&gt;(variant F)&lt;/small&gt;&lt;br /&gt;        &lt;small&gt;"www.hidro.4t.com"="enbiei.exe" (variant G)&lt;/small&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Close the Registry Editor&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Delete the infected files&lt;/small&gt; &lt;small&gt;(for Windows ME and XP remember to &lt;strong&gt;&lt;a href="http://www.pchell.com/virus/systemrestore.shtml"&gt;turn off System Restore&lt;/a&gt;&lt;/strong&gt; before searching for and deleting these files to remove infected backed up files as well)&lt;br /&gt;&lt;/small&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Click Start, point to Find or Search, and then click Files or Folders.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Make sure that "Look in" is set to (C:\WINDOWS).&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;In the "Named" or "Search for..." box, type, or copy and paste, the file names:&lt;br /&gt;          &lt;strong&gt;msblast*.* (or other filenames listed above)&lt;/strong&gt;&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Click Find Now or Search Now.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Delete the displayed files.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Empty the Recycle bin, the worm can reinfect even if the files are in the recycle bin.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial;"&gt;&lt;small&gt;Reboot the computer, reconnect the network, and &lt;strong&gt;&lt;a href="http://www.pchell.com/virus/virusupdates.shtml"&gt;update your antivirus software&lt;/a&gt;&lt;/strong&gt;, and run a thorough virus scan using your favorite antivirus program.&lt;/small&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;Now check for the worm again, if it returns, complete these steps once more until the virus is gone. With the patch in place, the virus wont be able to exploit the system, but sometimes it is difficult to remove the files for good.&lt;/span&gt;&lt;/small&gt;&lt;/li&gt;&lt;/ol&gt;&lt;small&gt;&lt;span style="font-family:Arial;"&gt;&lt;strong&gt;For Automatic Removal of MSBLAST&lt;/strong&gt;, download the &lt;strong&gt;&lt;a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html"&gt;Symantec removal tool&lt;/a&gt;, &lt;/strong&gt;you'll still need to download the patches above and install them, however this removal tool will stop the MSBLAST program from running, remove the items in the registry, and delete the infected files.&lt;br /&gt;&lt;br /&gt;Source : http://www.pchell.com/virus/msblast.shtml&lt;br /&gt;&lt;/span&gt;&lt;/small&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-6428773861690099321?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6428773861690099321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/6428773861690099321'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/04/msblastexe-worm-aka-blastera-lovesan-or.html' title='MSBLAST.EXE worm aka Blaster.A, LoveSan or Msblast.A?'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_dUgtpZrLHj8/Rh2m_bMH-tI/AAAAAAAAAAU/isaQIJ5XEbE/s72-c/systemshutdown.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-7178971580002221283</id><published>2007-04-09T18:29:00.000-07:00</published><updated>2007-04-09T18:34:31.548-07:00</updated><title type='text'>About Trojan Horse</title><content type='html'>&lt;span style="font-weight: bold;"&gt;History of Trojan Horse&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;The original trojan horse was built by Odysseus, the King of Ithica, during the legendary Trojan Wars. The Greeks were losing the siege of the city of Troy. Odysseus had a large wooden horse built and left as a "gift" outside the walls of the city of Troy. He then ordered the Greek army to sail away.&lt;br /&gt;&lt;br /&gt;The Trojans believed the horse to be a peace offering from Odysseus. Instead, the horse was filled with Greek warriors, including Odysseus and Menelaus. As the Trojans slept, the Greek army sailed back to Troy and the soldiers hiding in the wooden horse snuck out and opened the gates of the city for them.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;A Computer Trojan Horse&lt;/span&gt;&lt;br /&gt;&lt;p&gt;A &lt;i&gt;computer&lt;/i&gt; trojan horse is a program which appears to be something good, but actually conceals something bad.&lt;/p&gt;  &lt;p&gt;One way to spread &lt;a name="0060842261" id="amzn_cl_link_2" target="_blank" href="http://www.amazon.com/gp/product/0060842261?ie=UTF8&amp;tag=entrepreneu0a-20&amp;amp;link_code=em1&amp;camp=212341&amp;amp;creative=380429&amp;creativeASIN=0060842261&amp;amp;adid=05b4d3bf-cd32-4c32-9b36-1c968c9efb17"&gt;a trojan horse&lt;/a&gt; is to hide it inside a distribution of normal software. In 2002, the sendmail and OpenSSH packages were both used to hide trojan horses. This was done by an attacker who broke into the distribution sites for these software packages and replaced the original distributions with his own packages.&lt;/p&gt;  &lt;p&gt;A more common method of spreading a trojan horse is to send it via e-mail. The attacker will send the victim an e-mail with an attachment called something like "prettygirls.exe." When the victim opens the attachment to see the pretty girls, the trojan horse will infect his system.&lt;/p&gt;  &lt;p&gt;A similar technique for spreading trojan horses is to send files to unsuspecting users over chat systems like IRC, AIM, &lt;a id="KonaLink0" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.tech-faq.com/trojan-horse-virus.shtml#"&gt;&lt;span style="color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static;color:blue;" &gt;&lt;span class="kLink" style="color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static;"&gt;ICQ&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, MSN, or Yahoo Messenger.&lt;/p&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Trojan Horse Virus&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;Unlike viruses, trojan horses do not normally spread themselves. Trojan horses must be spread by other mechanisms.&lt;/p&gt;  &lt;p&gt;A trojan horse virus is a virus which spreads by fooling an unsuspecting user into executing it.&lt;/p&gt;  &lt;p&gt;An example of a trojan horse virus would be a virus which required a user to open an e-mail attachment in Microsoft Outlook to activate. Once activated, the trojan horse virus would send copies of itself to people in the Microsoft Outlook address book.&lt;/p&gt;  &lt;p&gt;The trojan horse virus infects like a trojan horse, but spreads like a virus.&lt;/p&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Effects of a Trojan Horse&lt;/span&gt;&lt;br /&gt;&lt;p&gt;The victim running the trojan horse will usually give the attacker some degree of control over the victim's machine. This control may allow the attacker to remotely access the victim's machine, or to run commands with all of the victim's privileges.&lt;/p&gt;  &lt;p&gt;The trojan horse could make the victim's machine part of a Distributed Denial of Service (DDoS) network, where the victims machine is used to attack other victims.&lt;/p&gt;  &lt;p&gt;Alternatively, the trojan horse could just send data to the attacker. Data commonly targeted by trojan horses includes usernames and passwords, but a sophisticated trojan horse could also be programmed to look for items such as &lt;a id="KonaLink1" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.tech-faq.com/trojan-horse-virus.shtml#"&gt;&lt;span style="color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static;color:blue;" &gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static; padding-bottom: 1px; background-color: transparent;"&gt;credit &lt;/span&gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static; padding-bottom: 1px; background-color: transparent;"&gt;card &lt;/span&gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static; padding-bottom: 1px; background-color: transparent;"&gt;numbers&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Protecting Against The Trojan Horse&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;Anti-virus programs detect &lt;i&gt;known&lt;/i&gt; trojan horses. However, trojan horse programs are easier to create than viruses and many are created in small volumes. These trojan horse programs will not be detected by anti-virus software.&lt;/p&gt;  &lt;p&gt;The best defense against a trojan horse is to never run a program that is sent to you. E-mail and chat systems are not safe methods of software distribution.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Spyware and Adware&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Many people consider &lt;a href="http://www.tech-faq.com/free-spyware-removal.shtml"&gt;spyware and adware&lt;/a&gt; to be forms of a trojan horse.&lt;/p&gt;  &lt;p&gt;Spyware programs perform a useful function, and also install a program that monitors usage of the victim's &lt;a name="0321344758" id="amzn_cl_link_3" target="_blank" href="http://www.amazon.com/gp/product/0321344758?ie=UTF8&amp;tag=entrepreneu0a-20&amp;amp;link_code=em1&amp;camp=212341&amp;amp;creative=380429&amp;creativeASIN=0321344758&amp;amp;adid=f94ff6cd-965f-46b3-a5e2-a5764aeb3d42"&gt;computer&lt;/a&gt; for the purpose of marketing to the user.&lt;/p&gt;  &lt;p&gt;Adware programs are similiar to &lt;a id="KonaLink2" target="_top" class="kLink" style="text-decoration: underline ! important; position: static;" href="http://www.tech-faq.com/trojan-horse-virus.shtml#"&gt;&lt;span style="color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static;color:blue;" &gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static; padding-bottom: 1px; background-color: transparent;"&gt;spyware &lt;/span&gt;&lt;span class="kLink" style="border-bottom: 1px solid blue; color: blue ! important; font-family: Verdana; font-weight: 400; font-size: 11px; position: static; padding-bottom: 1px; background-color: transparent;"&gt;programs&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, except the additional software they install shows advertising messages directly to the user.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5465651690170995482-7178971580002221283?l=virusandtrojan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7178971580002221283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5465651690170995482/posts/default/7178971580002221283'/><link rel='alternate' type='text/html' href='http://virusandtrojan.blogspot.com/2007/04/about-trojan-horse.html' title='About Trojan Horse'/><author><name>Agus</name><uri>http://www.blogger.com/profile/07259024377425401989</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5465651690170995482.post-4673207304488393925</id><published>2007-04-08T18:32:00.000-07:00</published><updated>2007-04-08T18:56:54.150-07:00</updated><title type='text'>Win32/Lightmoon.M</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Description&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Win32/Lightmoon.M is a worm that spreads via email and network shares. It makes trivial changes to its PE header as it replicates in order to evade detection methods such as MD5 matching.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method Infection&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;When executed, the worm makes many copies of itself on the affected system and drops several additional component files. It creates the follwing copies:&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;&lt;em&gt;%Windows%\lsass.exe&lt;/em&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.exe  &lt;/em&gt;(the worm creates 3 copies of itself with different filenames that follow this format)&lt;/li&gt;&lt;li&gt;&lt;em&gt;%System%\&lt;/em&gt;&lt;random&gt;\&lt;random&gt;.&lt;em&gt;cmd&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%System%\&lt;/em&gt;&lt;random&gt;&gt;.exe&lt;br /&gt;&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;Note: '%System%' and '%Windows%' are variable locations. The malware determines the location of these folders by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP and Vista is C:\Windows\System32.The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP and Vista is C:\Windows.&lt;br /&gt;&lt;br /&gt;It also creates the following files:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;%Windows%\cypreg.dll&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\moonlight.dll&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%System%\systear.dll &lt;/em&gt;- data file used to store the random filename.&lt;/li&gt;&lt;/ul&gt;A folder with Recycle Bin attributes is created to store more copies of the worm:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;div style="text-align: left;"&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\service.exe&lt;/em&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\winlogon.exe&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\smss.exe&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.com&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.exe&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\MYpIC.zip&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;The following registry modifications are made in order to ensure that the worm is executed:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\LOAD = ""%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.com""&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\RUN\&lt;/em&gt;&lt;random&gt; &lt;em&gt;= "%System%\&lt;&lt;/em&gt;random 14 characters&gt;&lt;em&gt;.exe"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell = "explorer.exe, "%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.exe""&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell = "&lt;/em&gt;&lt;random&gt;&lt;em&gt;l.exe"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\debugger = "%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\RUN\&lt;/em&gt;&lt;random&gt;&lt;em&gt; = "%Windows%\&lt;/em&gt;&lt;random&gt;&lt;em&gt;.exe"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;The worm also creates a copy of itself in each subfolder under My Documents, using the same name as the subfolder it is created in, for example:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;\Documents and Settings\&lt;/em&gt;&lt;user&gt;&lt;em&gt;My Documents\My Pictures\My Pictures.exe&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;\Documents and Settings\&lt;/em&gt;&lt;user&gt;&lt;em&gt;\My Documents\My Music\My Music.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;The worm makes several additional registry modifications that are not critical to its replication:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden = 0&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt = 1&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden = 0&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\UncheckedValue = 0&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig = 1&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR = 1&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCR\exefile\(Default) SUCCESS "File Folder"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKCR\scrfile\(Default) SUCCESS "File Folder"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\debugger = "%Windows%\notepad.exe"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\debugger = "%Windows%\notepad.exe"&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start = 0&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;The worm uses the File Folder icon.&lt;/p&gt; &lt;p&gt;Copies of the worm, as many as 10, are inserted into ZIP files found in the infected system. The inserted filenames are selected from below:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;RealPlayer13-5GOLD.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Icon Cool-Editor 3.4.30315.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;CheatEngine52.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;framework-4.4.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Vista Transformation Pack 4.0.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Pack_Vista_Inspirat_1.6.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;DeepUnfreezerU1.6.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Pack_Longhorn_Inspirat_1.6_code32547.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;TeamViewer_Setup.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;License.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method of Distribution&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Via Email&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;p&gt;The worm spreads via e-mail with a variable Subject and Message Body. The attachment also uses a variable filename and extension. The From address is 'spoofed', chosen from e-mail collected from the affected system.  The e-mail address of the infected user is also used.&lt;/p&gt; &lt;p&gt;E-mail sent by the worm have the following characteristics:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Possible Subjects:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;miss Indonesian&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Cek This&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;hello&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Japannes Porn&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;xxx&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Possible Message Bodies:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;hey Indonesian porn&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Agnes Monica pic's&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Fucking With Me :D&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;sisilia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Hilda&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;please read again what i have written to you&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Hot ...&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The attachment is a ZIP file that contains one executable with a filename selected from this list:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;Licence.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Pictures.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Secret.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Documents.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Vivid.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;update.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;XXX.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;cool.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;vitae.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;error.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The ZIP filename consists of a string selected from this list, following by a random number:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;Miyabi&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;nadine&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;hell&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;video&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Doc&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;file&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;thisfile&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;need you&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;The sender address may be "spoofed" using one of these names and domains in addition to those collected from the affected system: &lt;ul&gt;&lt;li&gt;&lt;em&gt;Agnes&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Ami&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Anata&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Anton&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Cicilia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Claudia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;CoolMan&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Davis&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Emily&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Firmansyah&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Fransisca&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Fransiska&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Fria&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;HellSpawn&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Joe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Joko&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Julia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;JuwitaNingrum&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Lanelitta&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Lia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Linda&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Nana&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Natalia&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Riri&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Rita&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;sasuke&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;SaZZA&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Susi&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Titta&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Valentina&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Vivi&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The spoofed domain names are:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;hackersmail.com&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;hotmail.com&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;gmail.com&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;msn.com&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;yahoo.com.sg&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Lovemail.com&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The worm collects email addresses to send itself to by searching files on all local fixed drives. It searches in any files with the following extensions:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;txt&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;tml&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;asp&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;php&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;rtf&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;eml&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;.pl&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;spx&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;.js&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;It avoids using addresses containing any of the following strings:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;security&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;avira&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;norman&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;norton&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;panda&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;mcafee&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Syman&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;sophos&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Trend&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;vaksin&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;novell&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;virus&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Via Mapped Drives&lt;/span&gt; &lt;p&gt;A copy of the worm is written to the root of all mapped drives, and ZIP files found on the drive, using one of these filenames:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;RealPlayer13-5GOLD.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Icon Cool-Editor 3.4.30315.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;CheatEngine52.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;framework-4.4.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Vista Transformation Pack 4.0.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Pack_Vista_Inspirat_1.6.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;DeepUnfreezerU1.6.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Pack_Longhorn_Inspirat_1.6_code32547.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;TeamViewer_Setup.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt; &lt;h4&gt;Via Network Shares&lt;/h4&gt; &lt;p&gt;A copy of the worm is written to all subfolders, using the subfolder name as the filename, on all network shares to which the affected user has write access.  For example, with a target subdirectory of \MyDocs, &lt;em&gt;\Mydocs\MyDocs.exe &lt;/em&gt;is created.&lt;/p&gt; &lt;p&gt;If the network share is found to contain the Windows directory, the worm creates a subdirectory "&lt;em&gt;moon&lt;/em&gt;" off the root of the network share. It then creates two files:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Elitta.htt&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;moonlight.exe&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;em&gt;Desktop.ini &lt;/em&gt;is then modified to activate "&lt;em&gt;Elitta.htt&lt;/em&gt;", which in turn executes "&lt;em&gt;moonlint.exe&lt;/em&gt;".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Payload&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Before the worm takes any further actions, it checks &lt;em&gt;http://www.google.com/&lt;/em&gt; to determine whether the affected system has Internet access.&lt;/p&gt; &lt;h4&gt;Deletes Services&lt;/h4&gt; &lt;p&gt;The worm attempts to delete these NT services (these services are components of Norman Virus Control):&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;em&gt;nipsvc&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Norman NJeeves&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;nvcoas&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;Norman Zanda&lt;/em&gt;&lt;/p&gt; &lt;h4&gt;Deletes Registry Values&lt;/h4&gt;&lt;h4 style="font-weight: normal;"&gt;The worm deletes these registry values from &lt;em&gt;&lt;/em&gt;&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;&lt;h4 style="font-weight: normal;"&gt;&lt;em&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\run&lt;/em&gt; and &lt;em&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\run&lt;/em&gt;:&lt;/h4&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;ul&gt;&lt;li&gt;&lt;em&gt;ADie suka kamu&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;AllMyBallance&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Alumni Smansa&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;AutoSupervisor&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;avgnt&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;BabelPath&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Bron-Spizaetus&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;CueX44_stil_here&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;dago&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;dkernel&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;DllHost&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Driver&lt;
