<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8644128944056388422</id><updated>2012-01-13T22:01:26.923-08:00</updated><title type='text'>Removal Virus</title><subtitle type='html'>restrict by bro act</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-2866237866083527968</id><published>2007-06-04T21:16:00.000-07:00</published><updated>2008-05-07T06:58:36.404-07:00</updated><title type='text'>What is the difference between viruses, worms, and Trojans?</title><content type='html'>&lt;p class="MsoNormal"&gt;As a user of the computer, Virus is the one of the killer in our program. So, every user of the computer should know what is the virus and others types of it.&lt;/p&gt;&lt;p class="MsoNormal"&gt;A computer virus is a small program written to alter the way a computer operates, without the permission or knowledge of the user. A virus must meet two criteria:&lt;br /&gt;&lt;/p&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;It must execute itself. It often places its own code in the path of execution of another program. &lt;/li&gt;&lt;li class="MsoNormal"&gt;It must replicate itself. For example, it may replace other executable files with a copy of the virus infected file. Viruses can infect desktop computers and network servers alike.&lt;/li&gt;&lt;/ul&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="font-size:10;"&gt;&lt;span style="font-size:100%;"&gt;Some viruses are programmed to damage the computer by damaging programs, deleting files, or reformatting the hard disk. Others are not designed to do any damage, but simply to replicate themselves and make their presence known by presenting text, video, and audio messages. Even these benign viruses can create problems for the computer user. They typically take up computer memory used by legitimate programs. As a result, they often cause erratic behavior and can result in system crashes. In addition, many viruses are bug-ridden, and these bugs may lead to system crashes and data loss.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt; &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(102,0,0)"&gt;Five recognized types of viruses&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;/o:p&gt; &lt;/p&gt;&lt;ul style="MARGIN-TOP: 0in; FONT-WEIGHT: bold; COLOR: rgb(51,51,153)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:';font-size:130%;"&gt;File infector viruses&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="MARGIN-LEFT: 0.25in"&gt;&lt;span style="font-size:9;"&gt;&lt;span style="font-size:+0;"&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoBodyTextIndent"&gt;&lt;?xml:namespace prefix = v /&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;v:path connecttype="rect" gradientshapeok="t" extrusionok="f"&gt;&lt;o:lock aspectratio="t" ext="edit"&gt;&lt;v:imagedata title="BD10263_" src="file:///C:/DOCUME~1/hafiz/LOCALS~1/Temp/msoclip1/01/clip_image001.gif"&gt;File infector viruses infect program files. These viruses normally infect executable code, such as .com and .exe files. The can infect other files when an infected program is run from floppy, hard drive, or from the network. Many of these viruses are memory resident. After memory becomes infected, any noninfected executable that runs becomes infected. Examples of known file infector viruses include Jerusalem and Cascade.&lt;/p&gt;&lt;ul style="MARGIN-TOP: 0in; FONT-WEIGHT: bold; COLOR: rgb(51,51,255)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;Boot sector viruses&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal"&gt;&lt;v:imagedata title="BD10263_" src="file:///C:/DOCUME~1/hafiz/LOCALS~1/Temp/msoclip1/01/clip_image001.gif"&gt;Boot sector viruses infect the system area of a disk; that is, the boot record on floppy disks and hard disks. All floppy disks and hard disks (including disks containing only data) contain a small program in the boot record that is run when the computer starts up. Boot sector viruses attach themselves to this part of the disk and activate when the user attempts to start up from the infected disk. These viruses are always memory resident in nature. Most were written for DOS, but, all PCs, regardless of the operating system, are potential targets of this type of virus. All that is required to become infected is to attempt to start up your computer with an infected floppy disk Thereafter, while the virus remains in memory, all floppy disks that are not write protected will become infected when the floppy disk is accessed. Examples of boot sector viruses are Form, Disk Killer, Michelangelo, and Stoned.&lt;/p&gt;&lt;ul style="MARGIN-TOP: 0in; FONT-WEIGHT: bold; COLOR: rgb(51,51,255)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;Master boot record viruses&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoBodyTextIndent"&gt;&lt;v:imagedata title="BD10263_" src="file:///C:/DOCUME~1/hafiz/LOCALS~1/Temp/msoclip1/01/clip_image001.gif"&gt;Master boot record viruses are memory-resident viruses that infect disks in the same manner as boot sector viruses. The difference between these two virus types is where the viral code is located. Master boot record infectors normally save a legitimate copy of the master boot record in an different location. Windows NT computers that become infected by either boot sector viruses or master boot sector viruses will not boot. This is due to the difference in how the operating system accesses its boot information, as compared to Windows 98/Me. If your Windows NT systems is formatted with FAT partitions you can usually remove the virus by booting to DOS and using antivirus software. If the boot partition is NTFS, the system must be recovered by using the three Windows NT Setup disks. Examples of master boot record infectors are NYB, AntiExe, and Unashamed.&lt;/p&gt;&lt;ul style="MARGIN-TOP: 0in; FONT-WEIGHT: bold; COLOR: rgb(51,51,255)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;Multipartite viruses&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal"&gt;&lt;v:imagedata title="BD10263_" src="file:///C:/DOCUME~1/hafiz/LOCALS~1/Temp/msoclip1/01/clip_image001.gif"&gt;&lt;span style="font-size:9;"&gt;&lt;span style="font-size:100%;"&gt;Multipartite (also known as polypartite) viruses infect both boot records and program files. These are particularly difficult to repair. If the boot area is cleaned, but the files are not, the boot area will be reinfected. The same holds true for cleaning infected files. If the virus is not removed from the boot area, any files that you have cleaned will be reinfected. Examples of multipartite viruses include One_Half, Emperor, Anthrax and Tequilla.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="MARGIN-TOP: 0in; FONT-WEIGHT: bold; COLOR: rgb(51,51,255)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;Macro viruses&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal"&gt;&lt;v:imagedata title="BD10263_" src="file:///C:/DOCUME~1/hafiz/LOCALS~1/Temp/msoclip1/01/clip_image001.gif"&gt; &lt;span style="font-size:9;"&gt;&lt;span style="font-size:100%;"&gt;These types of viruses infect data files. They are the most common and have cost corporations the most money and time trying to repair. With the advent of Visual Basic in Microsoft's Office 97, a macro virus can be written that not only infects data files, but also can infect other files as well. Macro viruses infect Microsoft Office Word, Excel, PowerPoint and Access files. Newer strains are now turning up in other programs as well. All of these viruses use another program's internal programming language, which was created to allow users to automate certain tasks within that program. Because of the ease with which these viruses can be created, there are now thousands of them in circulation. Examples of macro viruses include W97M.Melissa, WM.NiceDay and W97M.Groov.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(102,0,0)"&gt;What is a Trojan horse?&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoBodyText"&gt;&lt;span style="font-size:100%;"&gt;Trojan horses are impostors—files that claim to be something desirable but, in fact, are malicious. A very important distinction between Trojan horse programs and true viruses is that they do not replicate themselves. Trojan horses contain malicious code that when triggered cause loss, or even theft, of data. For a Trojan horse to spread, you must invite these programs onto your computers; for example, by opening an email attachment or downloading and running a file from the Internet. Trojan.Vundo is a Trojan horse.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(102,0,0)"&gt;What is a worm?&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoBodyText"&gt;&lt;span style="font-size:100%;"&gt;Worms are programs that replicate themselves from system to system without the use of a host file. This is in contrast to viruses, which requires the spreading of an infected host file. Although worms generally exist inside of other files, often Word or Excel documents, there is a difference between how worms and viruses use the host file. Usually the worm will release a document that already has the "worm" macro inside the document.W32.Mydoom.AX@mm is an example of a worm&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(102,0,0)"&gt;What is a virus hoax?&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;Virus hoaxes are messages, almost always sent by email, that amount to little more than chain letters. Following are some of the common phrases that are used in these hoaxes:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="COLOR: rgb(153,51,0)" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;If you receive an email titled [email virus hoax name here], do not open it! &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;Delete it immediately! &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;It contains the [hoax name] virus. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;It will delete everything on your hard drive and [extreme and improbable danger specified here]. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;This virus was announced today by [reputable organization name here]. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;Forward this warning to everyone you know!&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="FONT-WEIGHT: bold; COLOR: rgb(0,0,153)font-family:';font-size:100%;"  &gt;Most virus hoax warnings do not deviate far from this pattern&lt;/span&gt;&lt;br /&gt;&lt;/v:imagedata&gt;&lt;/v:imagedata&gt;&lt;/v:imagedata&gt;&lt;/v:imagedata&gt;&lt;/v:imagedata&gt;&lt;/o:lock&gt;&lt;/v:path&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:f&gt;&lt;/v:stroke&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-2866237866083527968?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/2866237866083527968/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=2866237866083527968' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/2866237866083527968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/2866237866083527968'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/06/what-is-difference-between-viruses.html' title='What is the difference between viruses, worms, and Trojans?'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-1315911838176344591</id><published>2007-06-04T02:54:00.001-07:00</published><updated>2008-05-07T06:59:24.700-07:00</updated><title type='text'>W32/Almanahe.c</title><content type='html'>&lt;h4&gt;Overview -&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Almanahe.a is a parasitic worm that infects Win32 executable files (*.exe) that can also download and execute additional malware.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;h4&gt;Aliases&lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;pe_corelink.a (TrendMicro)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;w32.almanahe.b!inf (Symantec)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;w32/alman-a (Sophos)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Characteristics&lt;o:p&gt;&lt;/o:p&gt;&lt;/h3&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;It also attempts to access network shares using the following passwords as "Administrator" user:&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;zxcv&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;qazwsx&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;qaz&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;qwer&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%^&amp;amp;*()&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%^&amp;amp;*(&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%^&amp;amp;*&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%^&amp;amp;&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%^&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$%&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;asdfgh&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;asdf&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;!@#$&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;654321&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;123456&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;12345&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;1234&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;123&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;1111&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;admin&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;The virus contains a list of hardcoded of filename(s) that are excluded from infection:&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;wooolcfg.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;woool.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;ztconfig.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;patchupdate.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;trojankiller.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;xy2player.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;flyff.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;xy2.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;au_unins_web.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;cabal.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;cabalmain9x.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;cabalmain.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;meteor.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;patcher.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;mjonline.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;config.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;zuonline.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;userpic.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;main.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;dk2.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;autoupdate.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;dbfsupdate.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;asktao.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;sealspeed.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;xlqy2.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;game.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;wb-service.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;nbt-dragonraja2006.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;dragonraja.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;mhclient-connect.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;hs.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;mts.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;gc.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;zfs.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;neuz.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;maplestory.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;nsstarter.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;nmcosrv.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;ca.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;nmservice.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;kartrider.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;audition.exe&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;zhengtu.exe&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-size:100%;"&gt;Symptoms&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h4&gt;&lt;span style="font-size:100%;"&gt;Symptoms - &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h4&gt;&lt;ul type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;Presence of the files and registry keys mentioned.&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;Increase in file size in existing executable files.&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;Unexpected network connections to the mentioned site(s).&lt;/span&gt; &lt;span style="font-size:100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;Unexpected access to network shared folders.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;h3&gt;Method of Infection&lt;o:p&gt;&lt;/o:p&gt;&lt;/h3&gt;&lt;h4&gt;Method of Infection - &lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Almanahe.a is a parasitic worm that propagates by infecting Win32 executable files (*.exe) on local drives and network shares.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-1315911838176344591?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/1315911838176344591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=1315911838176344591' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/1315911838176344591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/1315911838176344591'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/06/w32almanahec.html' title='W32/Almanahe.c'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-858947453722366472</id><published>2007-05-30T23:46:00.001-07:00</published><updated>2008-05-07T06:59:56.942-07:00</updated><title type='text'>"Hacked by Pokemon" virus</title><content type='html'>&lt;a title="Permanent Link to Step by Step Removing "&gt;&lt;/a&gt;&lt;a href="http://curutmacho.wordpress.com/"&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Removing "Hacked by Pokemon" virus&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;Did your Internet Explorer title bar shown this&lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt; "&lt;b&gt;Hacked by Pokemon&lt;/b&gt;"?Don't worry &lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;this is not a high risk &lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;virus.Just some visua&lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;l basic program.The file that run this v&lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;isual basic is &lt;b&gt;BHA.VBS.DLL&lt;/b&gt;. I will sho&lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;"&gt;w you how to remove this bug manually.&lt;/span&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(51,51,255);font-family:Verdana;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(51,51,255);font-family:Verdana;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://curutmacho.2pt.net/"&gt;&lt;img id="BLOGGER_PHOTO_ID_5070617265055870946" style="CURSOR: pointer" alt="" src="http://4.bp.blogspot.com/_0YnLJzI-OZw/Rl5ziYueL-I/AAAAAAAAADA/CCU_3pnCM-A/s320/hakced.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(51,51,255);font-family:Verdana;" &gt;What will This Virus Do ?&lt;/span&gt;&lt;/strong&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-Infected every of your &lt;b&gt;partition&lt;/b&gt; including &lt;b&gt;removable drive&lt;/b&gt;.This is because the script was written to generate bha.vbs.dll and &lt;b&gt;autorun.inf&lt;/b&gt;.&lt;?xml:namespace prefix = u1 /&gt;&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-Spread via removable drive such as &lt;b&gt;pendrive&lt;/b&gt; or other storage device because of its capability to generate dll file using vbs script. &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-Will generate new registry value in your windows registry that is:&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;&lt;span style="color:black;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL - winpath&amp;amp;"\Bha.dll.vbs&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;&lt;span style="color:black;"&gt;HKCR\vbsfile\DefaultIcon - shell32.dll&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;And also modify this registry value:&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;&lt;span style="color:black;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title","Hacked by pokemon" &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;&lt;u1:p&gt;&lt;/u1:p&gt;-All your &lt;b&gt;partition cannot open normally&lt;/b&gt; if your PC infected because the authority was given to the 'autoplay' option not 'open' option if normal condition.To ensure this,just right click one of your drives and see the first bolt option,is it &lt;/span&gt;&lt;strong&gt;&lt;span style="font-family:Verdana;color:black;"&gt;open&lt;/span&gt;&lt;/strong&gt;&lt;span style="color:black;"&gt; or &lt;/span&gt;&lt;strong&gt;&lt;span style="font-family:Verdana;color:black;"&gt;autoplay.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(51,51,255)"&gt;How to Show Autorun.inf &amp;amp; bha.vbs.dll in Your Computer?&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;span style="COLOR: rgb(51,51,255)"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.download-hardware.blogspot.com/"&gt;&lt;img id="BLOGGER_PHOTO_ID_5070614202744188882" style="CURSOR: pointer" alt="" src="http://3.bp.blogspot.com/_0YnLJzI-OZw/Rl5wwIueL9I/AAAAAAAAAC4/cMuxISojNsI/s320/hacked2.jpg" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.download-hardware.blogspot.com/"&gt;&lt;br /&gt;&lt;/a&gt;&lt;span style="COLOR: rgb(51,51,255)"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Verdana;font-size:130%;color:black;"&gt;-Go to Tools&gt;Folder Option&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Verdana;font-size:130%;color:black;"&gt;-&lt;b&gt;Uncheck Hide protected operating system files&lt;/b&gt; (Recommended) and Use simple file sharing(Recommended) &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Verdana;font-size:130%;color:black;"&gt;-Click Apply and Close the window.&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(204,0,0);font-family:Verdana;" &gt;WARNING&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family:Verdana;font-size:130%;color:black;"&gt;: When you open your drive partition, MAKE SURE you open by right clicking it and choose Open, IF NOT,the thread will RUNNING again.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(51,51,255)"&gt;How to Delete/Remove *vbs File ?&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;1) &lt;b&gt;CTRL + ALT + DEL&lt;/b&gt; and find &lt;b&gt;wscript.exe&lt;/b&gt; if exist to make sure its running or not. If exist, click End Process.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;2)You may delete 2 files that i mention above manually in every partition.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;3) or, &lt;b&gt;Start -&gt; Search&lt;/b&gt;. Search for *vbs files . Delete the file if it is found.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="COLOR: rgb(51,51,255)"&gt;How To Clean The Registry ?&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-After clean and delete the file, now you must clean the windows registry because this thread generate new registry value after they were activated.&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-Run registry editor:START---&gt;Run (type &lt;b&gt;regedit&lt;/b&gt;)&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-Open this location: &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;Delete registry named MS32DLL&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-And open this location: &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Verdana;font-size:180%;"&gt;-Choose Window title and edit the string.&lt;/span&gt;&lt;span style="font-family:Verdana;"&gt; &lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-You may put any names or delete the string value (Window title)&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;span style="color:black;"&gt;&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="color:black;"&gt;-&lt;b&gt;Then reboot your PC&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;br /&gt;&lt;span style="color:black;"&gt;&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;I hope this GUIDE will help you to eliminate this annoying virus . Good Luck !!!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-858947453722366472?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/858947453722366472/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=858947453722366472' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/858947453722366472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/858947453722366472'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/removing-hacked-by-pokemon-virus-did.html' title='&quot;Hacked by Pokemon&quot; virus'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0YnLJzI-OZw/Rl5ziYueL-I/AAAAAAAAADA/CCU_3pnCM-A/s72-c/hakced.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-8544491322526594265</id><published>2007-05-30T23:25:00.000-07:00</published><updated>2007-05-30T23:30:36.633-07:00</updated><title type='text'>Step-By-Step</title><content type='html'>&lt;font style="font-weight: bold;"&gt;To Get Rid Of Spylocked or Iesmin.exe&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Yesterday, my &lt;a style="font-weight: bold;" href="http://www.download-hardware.blogspot.com"&gt;laptop&lt;/a&gt; has been infected by Spylocked spyware. I believe that it is due to my brother has installed a fake anti-spyware.&lt;br /&gt;&lt;br /&gt;Windows keeps giving me a warning that I have spyware and that i should get rid of it.Spylock kept coming up, and even though I've uninstalled it, the icon keeps flashing in system tray...&lt;br /&gt;&lt;br /&gt;If you open the &lt;font style="font-weight: bold;"&gt;Task Manager&lt;/font&gt;, you will see &lt;font style="font-weight: bold; color: rgb(153, 0, 0);"&gt;iesmn.exe, iesmin.exe, imsmain, imsmn &lt;/font&gt;in the process. That's the spyware.  Iesmin.exe is actually &lt;font style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Trojan-Downloader.Zlob.Media-Codec&lt;/font&gt;.&lt;br /&gt;&lt;br /&gt;After searching some info about the virus, I am able to remove the spyware. So, what you have to do to get rid of this spyware?&lt;br /&gt;&lt;br /&gt;First, &lt;font style="font-weight: bold;"&gt;kill the process&lt;/font&gt; of those I've stated above one by one in the Task Manager.&lt;br /&gt;&lt;br /&gt;Then run &lt;font style="font-weight: bold;"&gt;Hijack This &lt;/font&gt;or Startup Manager to remove iesmin.exe and the gang from &lt;font style="font-weight: bold;"&gt;Windows startup&lt;/font&gt;.&lt;br /&gt;&lt;br /&gt;Final step, after making sure that&lt;font style="font-weight: bold; color: rgb(153, 0, 0);"&gt; iesmin.exe&lt;/font&gt; and the gang are not running in the process( open Task Manager and look at the process whether they still running or not ), go to&lt;br /&gt;&lt;br /&gt;&lt;font style="font-weight: bold; font-style: italic;"&gt;C:\Program Files\Video ActiveX Access\&lt;/font&gt;   and find &lt;font style="font-weight: bold; color: rgb(153, 0, 0);"&gt;iesbpl.dll&lt;/font&gt; and delete that file.&lt;br /&gt;&lt;br /&gt;DONE !!! Now you will be able to remove the spyware manually.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-8544491322526594265?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/8544491322526594265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=8544491322526594265' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/8544491322526594265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/8544491322526594265'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/step-by-step.html' title='Step-By-Step'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-4623841882010595975</id><published>2007-05-29T18:10:00.000-07:00</published><updated>2008-05-07T07:00:48.813-07:00</updated><title type='text'>Information W32/Netsky-P Worm</title><content type='html'>&lt;h2&gt;This section helps you to understand how it behaves&lt;/h2&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;NOTE: The information contained in this analysis may be considered offensive by some customers.&lt;/b&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Netsky-P is a mass-mailing worm which spreads by emailing itself to addresses harvested from files on the local drives. &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;The worm will also copy itself to various peer-to-peer shared folders as the following files: &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;tt&gt;&lt;span style="font-size:10;"&gt;1001 Sex and more.rtf.exe&lt;/span&gt;&lt;/tt&gt;&lt;span style="font-size:10;"&gt;&lt;br /&gt;&lt;tt&gt;3D Studio Max 6 3dsmax.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;ACDSee 10.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Adobe Photoshop 10 crack.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Adobe Photoshop 10 full.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Adobe Premiere 10.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Ahead Nero 8.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Altkins Diet.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;American Idol.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Arnold Schwarzenegger.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Best Matrix Screensaver new.scr&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney sex xxx.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears and Eminem porn.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears blowjob.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears cumshot.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears fuck.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears full album.mp3.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears porn.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears Sexy archive.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears Song text archive.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Britney Spears.mp3.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Clone DVD 6.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Cloning.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Cracks &amp;amp; Warez Archiv.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Dark Angels new.pif&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Dictionary English 2004 - France.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;DivX 8.0 final.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Doom 3 release 2.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;E-Book Archive2.rtf.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem blowjob.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem full album.mp3.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem Poster.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem sex xxx.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem Sexy archive.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem Song text archive.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem Spears porn.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Eminem.mp3.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Full album all.mp3.pif&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Gimp 1.8 Full with Key.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter 1-6 book.txt.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter 5.mpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter all e.book.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter e book.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter game.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Harry Potter.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;How to hack new.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Internet Explorer 9 setup.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Kazaa Lite 4.0 new.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Kazaa new.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Keygen 4 all new.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Learn Programming 2004.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Lightwave 9 Update.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Magix Video Deluxe 5 beta.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Matrix.mpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Microsoft Office 2003 Crack best.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Microsoft WinXP Crack full.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;MS Service Pack 6.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;netsky source code.scr&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Norton Antivirus 2005 beta.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Opera 11.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Partitionsmagic 10 beta.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Porno Screensaver britney.scr&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;RFC compilation.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Ringtones.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Ringtones.mp3.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Saddam Hussein.jpg.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Screensaver2.scr&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Serials edition.txt.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Smashing the stack full.rtf.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Star Office 9.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Teen Porn 15.jpg.pif&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;The Sims 4 beta.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Ulead Keygen 2004.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Visual Studio Net Crack all.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Win Longhorn re.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;WinAmp 13 full.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Windows 2000 Sourcecode.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Windows 2003 crack.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;Windows XP crack.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;WinXP eBook newest.doc.exe&lt;/tt&gt;&lt;br /&gt;&lt;tt&gt;XXX hardcore pics.jpg.exe&lt;/tt&gt;&lt;/span&gt; &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Netsky-P harvests email addresses from files with the following extensions:&lt;br /&gt;PL, HTM, HTML, EML, TXT, PHP, ASP, VBS, RTF, UIN, SHTM, CGI, DHTM, ADB, TBB, DBX, SHT, OFT, MSG, JSP, WSH, XML.&lt;/p&gt;&lt;br /&gt;The worm has a trigger date of 24 March 2004, at which time it will attempt to mass mail. &lt;p style="MARGIN: 0in 0in 0pt"&gt;Emails have the following characteristics (note that not all variations listed): &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;Subject lines:&lt;/b&gt; constructed from the following groups of strings - &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;Re: Re:&lt;br /&gt;Re: Encrypted Mail&lt;br /&gt;Re: Extended Mail&lt;br /&gt;Re: Status&lt;br /&gt;Re: Notify&lt;br /&gt;Re: SMTP Server&lt;br /&gt;Re: Mail Server&lt;br /&gt;Re: Delivery Server&lt;br /&gt;Re: Bad Request&lt;br /&gt;Re: Failure&lt;br /&gt;Re: Thank you for delivery&lt;br /&gt;Re: Test&lt;br /&gt;Re: Administration&lt;br /&gt;Re: Message Error&lt;br /&gt;Re: Error&lt;br /&gt;Re: Extended Mail System&lt;br /&gt;Re: Secure SMTP Message&lt;br /&gt;Re: Protected Mail Request&lt;br /&gt;Re: Protected Mail System&lt;br /&gt;Re: Protected Mail Delivery&lt;br /&gt;Re: Secure delivery&lt;br /&gt;Re: Delivery Protection&lt;br /&gt;Re: Mail Authentification &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;Message texts:&lt;/b&gt; chosen from - &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;Please confirm my request.&lt;br /&gt;ESMTP [Secure Mail System #334]: Secure message is attached.&lt;br /&gt;Partial message is available.&lt;br /&gt;Waiting for a Response. Please read the attachment.&lt;br /&gt;First part of the secure mail is available.&lt;br /&gt;For more details see the attachment.&lt;br /&gt;For further details see the attachment.&lt;br /&gt;Your requested mail has been attached.&lt;br /&gt;Protected Mail System Test.&lt;br /&gt;Secure Mail System Beta Test.&lt;br /&gt;Forwarded message is available.&lt;br /&gt;Delivered message is attached.&lt;br /&gt;Encrypted message is available.&lt;br /&gt;Please read the attachment to get the message.&lt;br /&gt;Follow the instructions to read the message.&lt;br /&gt;Please authenticate the secure message.&lt;br /&gt;Protected message is attached.&lt;br /&gt;Waiting for authentification.&lt;br /&gt;Protected message is available.&lt;br /&gt;Bad Gateway: The message has been attached.&lt;br /&gt;SMTP: Please confirm the attached message.&lt;br /&gt;You got a new message.&lt;br /&gt;Now a new message is available.&lt;br /&gt;New message is available.&lt;br /&gt;You have received an extended message. Please read the instructions. &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;Attachment description: &lt;/b&gt;chosen from - &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;Your details.&lt;br /&gt;Your document.&lt;br /&gt;I have received your document. The corrected document is attached.&lt;br /&gt;I have attached your document.&lt;br /&gt;Your document is attached to this mail.&lt;br /&gt;Authentication required.&lt;br /&gt;Requested file.&lt;br /&gt;See the file.&lt;br /&gt;Please read the important document.&lt;br /&gt;Please confirm the document.&lt;br /&gt;Your file is attached.&lt;br /&gt;Please read the document.&lt;br /&gt;Your document is attached.&lt;br /&gt;Please read the attached file!&lt;br /&gt;Please see the attached file for details. &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;followed by - &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;attached&gt;: &lt;/attached&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;+++ Attachment: No Virus found&lt;br /&gt;+++ MessageLabs AntiVirus - www.messagelabs.com&lt;br /&gt;+++ Attachment: No Virus found&lt;br /&gt;+++ Bitdefender AntiVirus - www.bitdefender.com&lt;br /&gt;+++ Attachment: No Virus found&lt;br /&gt;+++ MC-Afee AntiVirus - www.mcafee.com&lt;br /&gt;+++ Attachment: No Virus found&lt;br /&gt;+++ Kaspersky AntiVirus - www.kaspersky.com&lt;br /&gt;+++ Attachment: No Virus found&lt;br /&gt;+++ Panda AntiVirus - www.pandasoftware.com&lt;br /&gt;++++ Attachment: No Virus found&lt;br /&gt;++++ Norman AntiVirus - www.norman.com&lt;br /&gt;++++ Attachment: No Virus found&lt;br /&gt;++++ F-Secure AntiVirus - www.f-secure.com&lt;br /&gt;++++ Attachment: No Virus found&lt;br /&gt;++++ Norton AntiVirus - www.symantec.de &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;b&gt;Attached file:&lt;/b&gt; &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;filename&gt;_ &lt;recipient_name&gt;.&lt;extension&gt; &lt;/extension&gt;&lt;/recipient_name&gt;&lt;/filename&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;filename&gt;chosen from: &lt;/filename&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;document_all&lt;br /&gt;message&lt;br /&gt;excel document&lt;br /&gt;word document&lt;br /&gt;screensaver&lt;br /&gt;application&lt;br /&gt;website&lt;br /&gt;product&lt;br /&gt;letter&lt;br /&gt;information&lt;br /&gt;details&lt;br /&gt;document &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;&lt;extension&gt;chosen from: &lt;/extension&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;EXE&lt;br /&gt;SCR&lt;br /&gt;PIF&lt;br /&gt;ZIP &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Netsky-P attempts to delete registry entries which may be set by variants of the W32/Mydoom and W32/Bagle worms. &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt"&gt;W32/Netsky-P also creates a number of the TMP files in the Windows folder: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-4623841882010595975?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/4623841882010595975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=4623841882010595975' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/4623841882010595975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/4623841882010595975'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/information-w32netsky-p-worm.html' title='Information W32/Netsky-P Worm'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-4803088684070470388</id><published>2007-05-20T20:04:00.000-07:00</published><updated>2007-05-20T20:16:18.028-07:00</updated><title type='text'>Virus Description - W32.Blackmal.E@mm</title><content type='html'>&lt;address&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;Created: 27/01/06&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/address&gt; &lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;CME-24,&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Win32.Blackmal.F [Computer Associates],&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Email-Worm.Win32.Nyxem.e [F-Secure], &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Email-Worm.Win32.Nyxem.e [Kaspersky],&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;W32/MyWife.d@MM [McAfee],&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;W32/MyWife.d@MM!M24 [McAfee],&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;W32/Small.KI@mm [Norman],&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Tearec.A [Panda Software],&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;W32/Nyxem-D [Sophos] &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;WORM_GREW.{A, B} [Trend Micro&lt;/span&gt;]&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:180%;"&gt;Description&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;W32.Blackmal.E@mm is a mass-mailing worm that tries to spread on networks using open network shares and on the third of each month this virus &lt;span style="font-weight: bold; font-style: italic;"&gt;deletes data&lt;/span&gt; files such as &lt;span style="font-weight: bold; font-style: italic;"&gt;Word documents &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;and Excel spreadsheets.&lt;br /&gt;The 'From' line of the email is spoofed (faked), and its Subject line and message body of the email vary, but tend to be of a 'sexual' nature. The attachment varies but often appears to be a 'zip' file.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Damage&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Spreads, clogs email servers, generates False Alarms, attacks anti-virus programs and &lt;span style="font-weight: bold; font-style: italic;"&gt;deletes Word documents, Excel files, Powerpoint presentations, Access Databases, Zips, RARs and Photoshop files on the third of the month&lt;/span&gt;. The virus also attacks anti-virus and security software installed on your computer (which is a common feature of modern viruses).&lt;br /&gt;On the 3rd of each month, 30 minutes after the victim&lt;br /&gt;computer is rebooted, the worm will overwrite (destroy) files&lt;br /&gt;with the following extensions:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;doc&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;xls&lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;mdb &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;mde &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;ppt &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;pps &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;zip &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;rar &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;pdf &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;psd &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic; color: rgb(102, 0, 0);"&gt;dmp&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Files corrupted by the worm contain the following text:&lt;br /&gt;DATA Error [47 0F 94 93 F4 F5]&lt;br /&gt;It is capable of disabling the mouse and keyboard of an affected system.&lt;br /&gt;May reduce security on your PC.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Occurrence&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Blackmal.E has been seen several times on campus - Symantec AntiVirus is recognising it and is stopping it (providing your 'virus definitions' are dated later than 17/01/06 .&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Advice&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Do &lt;span style="font-weight: bold;"&gt;not &lt;/span&gt;read suspicious email. Do &lt;span style="font-weight: bold;"&gt;not&lt;/span&gt; open the attachments with the above names or any unknown attachments. Keep Windows (&amp; Outlook) up-to-date - see Updating Windows. And do &lt;span style="font-weight: bold;"&gt;not&lt;/span&gt; forward warnings to the apparent sender because the apparent sender is NOT the real sender.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Detecting Blackmal.E&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;An up-to-date copy of Symantec/Norton AntiVirus should detect and prevent infection from Blackmal.E. If you do not have Symantec/Norton AntiVirus and you are worried that you may have infected computer, you could run an online virus check or contact the Student Help Desk in the Library.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Cleaning Blackmal.E&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Use the tool from Symantec: Blackmal Removal Tool.&lt;br /&gt;Further Information&lt;br /&gt;For further info about Blackmal.E:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;Symantec on W32.Blackmal.E@mm&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;Trend on 'WORM_GREW.A' (w32.Blackmal.E@mm)&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-4803088684070470388?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/4803088684070470388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=4803088684070470388' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/4803088684070470388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/4803088684070470388'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/virus-description-w32blackmalemm.html' title='Virus Description - W32.Blackmal.E@mm'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-5524403539878386044</id><published>2007-05-18T21:45:00.000-07:00</published><updated>2008-05-07T07:02:40.784-07:00</updated><title type='text'>Combating Viruses, Worms and Trojan Horses</title><content type='html'>&lt;p&gt;&lt;span style="font-family:Arial;font-size:10;"&gt;The first steps to protecting your computer are to ensure your &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:Arial;"&gt;Operating System&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;font-size:10;"&gt; (OS) is up-to-date. This is essential if you are running a Microsoft Windows OS. Secondly, you should have &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:Arial;"&gt;anti-virus software&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;font-size:10;"&gt; installed on your system and ensure you &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:Arial;"&gt;download&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;font-size:10;"&gt; updates frequently to ensure your software has the latest fixes for new viruses, worms, and Trojan horses. Additionally, you want to make sure your anti-virus program has the capability to scan e-mail and files as they are downloaded from the Internet. This will help prevent malicious programs from even reaching your computer. You should also install a &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:Arial;"&gt;firewall&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;font-size:10;"&gt; as well.&lt;/span&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:10;"&gt;A firewall is a system that prevents unauthorized use and access to your computer. A firewall can be either hardware or software. Hardware firewalls provide a strong degree of protection from most forms of attack coming from the outside world and can be purchased as a stand-alone product or in &lt;span class="body"&gt;broadband routers.&lt;/span&gt; Unfortunately, when battling viruses, worms and Trojans, a hardware firewall may be less effective than a software firewall, as it could possibly ignore embedded worms in out going e-mails and see this as regular network traffic. For individual home users, the most popular firewall choice is a software firewall. A good software firewall will protect your computer from outside attempts to control or gain access your computer, and usually provides additional protection against the most common &lt;span class="body"&gt;Trojan programs or e-mail worms&lt;/span&gt;. The downside to software firewalls is that they will only protect the computer they are installed on, not a network.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:10;"&gt;It is important to remember that on its own a firewall is not going to rid you of your computer virus problems, but when used in conjunction with regular operating system updates and a good anti-virus scanning software, it will add some extra security and protection for your computer or network.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-5524403539878386044?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/5524403539878386044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=5524403539878386044' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/5524403539878386044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/5524403539878386044'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/combating-viruses-worms-and-trojan.html' title='Combating Viruses, Worms and Trojan Horses'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-319039156818506640</id><published>2007-05-15T20:46:00.000-07:00</published><updated>2007-05-18T03:29:51.447-07:00</updated><title type='text'>New Worm Name : W32.Fubalca.E-</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;strong&gt;Systems Affected&lt;/strong&gt;: &lt;em&gt;&lt;span style="color: rgb(102, 0, 0);"&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;br /&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;When the worm executes, it copies itself to the following location&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);font-size:100%;" &gt;&lt;span style="color: rgb(0, 0, 0);"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);font-size:100%;" &gt;&lt;em&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;%&lt;/span&gt;System%\servet.exe&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;The worm then enables the autorun facitility on all drives by modifying the following registry entry:&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;em&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoDriveTypeAutoRun" = "0"&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Next, the worm scans all drives from A through Z and creates the following file:[DRIVE LETTER]:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);font-size:100%;" &gt;&lt;em&gt;\AutoRun.inf&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);font-size:100%;" &gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;The worm then sets the system date to January 12th 1981, if the following file exists&lt;em&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;:&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);font-size:100%;" &gt;%System%\drivers\klick.sys&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;It then creates a service with the following characteristics:&lt;/span&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;Servicename:&lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);font-size:100%;" &gt;&lt;strong&gt;WindowsDownService&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;description: &lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);font-size:100%;" &gt;&lt;strong&gt;Windows&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;The worm creates the following registry subkey for the above service: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsDown&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;The worm uses advanced techniques to hide itself on the computer as the following file: %System%\svchost.exe&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;Once the worm has completed its installation, it deletes itself.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;The worm then attempts to download and execute the following malicious files every sixty seconds: &lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/10.[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/11.[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/12.[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/13.[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dmm.com/arp/14.[REMOVED] &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;[http://]www.18dd.net/new/system[REMOVED]&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;The above files are saved to the following location:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;%System%\1.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\2.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\3.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\4.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\5.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\6.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\7.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\8.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\9.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\10.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\11.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\12.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\13.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\14.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;%System%\system22.exe&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-319039156818506640?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/319039156818506640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/319039156818506640'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/05/new-worm-name-w32fubalcae.html' title='New Worm Name : W32.Fubalca.E-'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-687205383216092688</id><published>2007-04-30T01:15:00.000-07:00</published><updated>2007-06-04T23:09:01.819-07:00</updated><title type='text'>BrO_AcT (That You Need To Know)</title><content type='html'>&lt;span style="font-size:85%;"&gt;BrO_AcT Facts That You Need To KnowLately, a lot of my friend's computer have been infected by BrO_AcT worm/virus. And it cause them a lot of trouble to get rid of this new virus. Moreover, the information on the Net is still very limited since it is a new virus. Recently, I've found the facts about this virus on the Net and want to share with you so that you will know if you've been a victim or not.1)What is BrO_AcT ?Symantec AV -&gt; identify it as W32.sillyDC.DrWeb CureIT -&gt; identify it as Win32.HLLW.BroactTrenMicro -&gt; identify it as WORM_VB.BHEPanda AV -&gt; identify it as W32/SexyGirl.A.wormAvira -&gt; identify it as Worm/VB.DH.12)How it Spreads ?Normally it spread via removable storage devices(USB drive) . Infected thumb drive will show these files: "MySexy.exe", "User.exe" and "Sexy.Dat".3)Symptomps -Popup box appears after login into the Windows, with the title "BrO_AcT.exe". It contains a message but I don't remember what it is written.-Look at your title bar. An infected hardi...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;Tips&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;BrO_AcT Facts That You Need To Know&lt;br /&gt;&lt;br /&gt;Lately, a lot of my friend's computer have been infected by BrO_AcT worm/virus. And it cause them a lot of trouble to get rid of this new virus. Moreover, the information on the Net is still very limited since it is a new virus. Recently, I've found the facts about this virus on the Net and want to share with you so that you will know if you've been a victim or not.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;1)What is BrO_AcT ?&lt;br /&gt;&lt;br /&gt;Symantec AV -&gt; identify it as W32.sillyDC.&lt;br /&gt;DrWeb CureIT -&gt; identify it as Win32.HLLW.Broact&lt;br /&gt;TrenMicro -&gt; identify it as WORM_VB.BHE&lt;br /&gt;Panda AV -&gt; identify it as W32/SexyGirl.A.worm&lt;br /&gt;Avira -&gt; identify it as Worm/VB.DH.1&lt;br /&gt;&lt;br /&gt;2)How it Spreads ?&lt;br /&gt;&lt;br /&gt;Normally it spread via removable storage devices(USB drive) . Infected thumb drive will show these files: "MySexy.exe", "User.exe" and "Sexy.Dat".&lt;br /&gt;&lt;br /&gt;3)Symptomps&lt;br /&gt;&lt;br /&gt;-Popup box appears after login into the Windows, with the title "BrO_AcT.exe". It contains a message but I don't remember what it is written.&lt;br /&gt;-Look at your title bar. An infected hardisk will show the folder name + [:Restricted by BrO_Act:]&lt;br /&gt;- When you try to open C:\Windows\System32 folder, explorer close itself.&lt;br /&gt;- Right click My Computer, select Properties, select Computer, click Change button, you find that your computer name has been changed to "ReAct_User"&lt;br /&gt;-Your antivirus has been deactivated.&lt;br /&gt;-You can't access Task Manager, Regedit, Msconfig, Folder option, and Command prompt.&lt;br /&gt;&lt;br /&gt;4)How Do I Confirm that I'm Infected ?&lt;br /&gt;&lt;br /&gt;Run Hijackthis. These are the entries added:&lt;br /&gt;C:\WINDOWS\system32\BrO_AcT.exe&lt;br /&gt;F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\default__.pif"&lt;br /&gt;O4 - HKLM\..\Run: [System] C:\WINDOWS\SYSTEM32\BrO_AcT.exe&lt;br /&gt;O4 - HKCU\..\Run: [svchost] C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5)What Will This Virus Do or Create in Your Computer ?&lt;br /&gt;&lt;br /&gt;It will create and add the following files :-&lt;br /&gt;&lt;br /&gt;-C:\Windows\system32\BrO_AcT.exe-C:\WINDOWS\default__.pif&lt;br /&gt;-C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe&lt;br /&gt;-C:\WINDOWS\SYSTEM32\ReAct_User\winlogon.exe&lt;br /&gt;-C:\ReActLog (Something with this name)&lt;br /&gt;-NTDETCH.com (on all your drive, root folder)&lt;br /&gt;-Autorun.inf (on all your drive, root folder)&lt;br /&gt;-Hundreds of files in C:\System Volume -Information\_restore{7C0D0734-E9F5-4A30-ABD4-977206CFACB2}\RP411 (With name like -A0062080.com, A0062083.pif, A0062092.exe and etc)&lt;br /&gt;-C:\WINDOWS\system32\MySexy.exe&lt;br /&gt;-C:\WINDOWS\system32\regedit.com&lt;br /&gt;-C:\WINDOWS\system32\msconfig.com&lt;br /&gt;&lt;br /&gt;It also will copy itself to any portable USB drive connected to the infected system and creating:-&lt;br /&gt;-&gt;Autorun.innf&lt;br /&gt;-&gt;BrO_AcT.exe&lt;br /&gt;-&gt;My_SeXy.exe&lt;br /&gt;&lt;br /&gt;and the USB drive will autorun anytime you connect it to the system. "THIS IS THE WAY HOW THE VIRUS SPREAD".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6) How Do I Get Rid of BrO_Act.exe ?&lt;br /&gt;&lt;br /&gt;Update your anti-virus with latest virus definition. As far as I know :-&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;Nod32 AV - not detect, system infected&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;BitDefender 10 - not detect, system infected&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;McAfee - not detect, system infected&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;Avira - detected as Worm/VB.DH.1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;AVG 7.5 Pro - detected as W32/VB&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0); font-weight: bold;"&gt;Kapersky - detected as Win32.VB.DH&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I hope this little info will help you to eliminate this annoying virus.&lt;br /&gt;&lt;br /&gt;All The Best....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-687205383216092688?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/687205383216092688/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=687205383216092688' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/687205383216092688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/687205383216092688'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/04/broact-that-you-need-to-know.html' title='BrO_AcT (That You Need To Know)'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8644128944056388422.post-5753311094495589576</id><published>2007-04-25T23:20:00.000-07:00</published><updated>2007-04-26T01:12:44.738-07:00</updated><title type='text'>killerWorm</title><content type='html'>&lt;div class="postcontent"&gt;For u guys in the Lab, it might be a tiny problem for u  guys in there. but there is a virus named &lt;b&gt;bro_act&lt;/b&gt; associated with &lt;b&gt;my  sexy.exe, ntdetech.com, autorun.inf, winlogon&lt;/b&gt; and it stamped the folder  title with &lt;b&gt;"restrict by bro act". &lt;/b&gt;so far the only method to romove it is  by manually editing the registry and deleting those files and others. and some  how it misses ur scanning capability. i hope u guys can fixed that for us out  here, soon, cause it's really like hell&lt;br /&gt;&lt;br /&gt;&lt;b&gt;autorun.inf [Open with note and delete text]&lt;br /&gt;                         [save the files]&lt;br /&gt;                         [Hidden files]&lt;br /&gt;&lt;/b&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8644128944056388422-5753311094495589576?l=lightcyber.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lightcyber.blogspot.com/feeds/5753311094495589576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8644128944056388422&amp;postID=5753311094495589576' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/5753311094495589576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8644128944056388422/posts/default/5753311094495589576'/><link rel='alternate' type='text/html' href='http://lightcyber.blogspot.com/2007/04/killerworm.html' title='killerWorm'/><author><name>curutMaCho</name><uri>http://www.blogger.com/profile/14663231058629177500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_0YnLJzI-OZw/SOjINgBXsnI/AAAAAAAAAUo/GNGXuq8OSaI/S220/It%60s+Me.jpg'/></author><thr:total>1</thr:total></entry></feed>
