Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Sunday, March 27, 2011

30 World's Most Dangerous Site

Be careful in browsing or open certain sites are not yet clear. Because it could contain dangerous viruses that would harm us. Here is the site of the dirtiest in the world, on the site there are many different kinds of viruses that cause the phone / pc you damaged

1. 17ebook.com
2. aladel.net
3. bpwhamburgorchardpark.org
4. clicnews.com
5. dfwdiesel.net
6. divineenterprises.net
7. fantasticfilms.ru
8. gardensrestaurantandcatering.com
9. ginedis.com
10. gncr.org
11. hdvideoforums.org
12. hihanin.com
13. kingfamilyphotoalbum.com
14. likaraoke.com
15. mactep.org
16. magic4you.nu
17. marbling.pe
18. krnacjalneg.info
19. pronline.ru
20. purplehoodie.com
21. qsng.cn
22. seksburada.net
23. sportsmansclub.net
24. stock888.cn
25. tathli.com
26. teamclouds.com
27. texaswhitetailfever.com
28. wadefamilytree.org
29. xnescat.info
30. yt118.com


There is a bold attempt to open ..?
 please test your mainstay AntiVirus ......! hehehe ...
  ........ beware
........... beware

Sunday, January 24, 2010

Berantas virus Conflicker

Virus itu nyerang via LAN dan USB. 1 computer aja kena, begitu aktif dia mencoba nyebar ke seluruh computer di LAN dan internet
Denger denger dia bisa masuk ke OS yang di password , karena itu virus bisa secara acak nembusin OS Windows.
Kalau ada 10 computer, di basmi di 9. 1 nya bisa nyerang ke 9 computer yang belum di patch

download antivirus
atau
download Fix dari Confliker buatan Symantec (FixDwndp.exe)

dan update windows
download

Wednesday, December 2, 2009

Tips remove Virus OnlineGames

For the you don't wish the important data lose is and or stolen better virus infection don't OnlineGames. Avoid to execute and installation [at] program and software which unknown to
Besides to be remembered, beware of [at] online forum in internet providing link-link the compromisingness or you don't believe his authenticity.

Special for company with computer in the network many, you do filter IP-IP the compromisingness. Result of filtering use NNP done [at] traffic ISP confirm that W32/OnlineGames is real threat to be taken heed in this time.
But, if have have come too far unintentionally the infection trojan this, will you do not willing to have to a little a few to clean the virus OnlineGames, before important data you is stolen by trojan this. Following stages;steps to fight against it:
1. Kill System Restore ( XP/ME) ( at the (time) of used)
2. Kill the virus process. Use Windows Task Manager to kill the virus process.
3. Do End Process [at] active virus file ( liser.exe)
4. Vanish string registry which have been made by the virus. To water down can use script registry hereunder.
[Version]
Signature="$Chicago$"
Provider=Vaksincom Oeyy

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe ""%1"""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs, 0

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Kell

Use notepad, then keep by the name of Repair.inf ( use the choice Save As Type become All Files in order not to happened mistake).
5. Vanish the virus file ( liser.exe & liser.dll) manually, that is [at] folder " C:\Program Files\Manson" or can use tools Norman Malware Cleaner. you can mendownload [at] link following http://normanasa.vo.llnwd.net/o29/public/Norman_Malware_Cleaner.exe

Friday, July 10, 2009

6 Step Install free antivirus microsoft

Microsoft Security Essentials is antivirus free of charge from Microsoft. version Beta of this product have didownload for operating system Microsoft be like Windows 7 Beta and RC ( 32 or 64 beet), Vista RTM, SP1 and SP2 and also Windows XP SP3 32 beet.
Way pengunduhannya even also including easy to. Following is 6 kiat to menginstall Microsoft Security Essentials Beta
1. Ensure that the minimum specification PC Anda have fufilled to run this application. But don't worry, because software this including light. Following is the specification of his minimum:
* To XP-CPU with clock speed 500 MHz or higher
* To XP - Memory: 256 MB RAM or higher
* To Vista / W7 - CPU with clock speed 1.0 GHz or higher * To Vista / W7 - Memory: 1 GB RAM or higher
* VGA ( Display): 800 x 600 or higher * Storage: 140 MB

2. Ascertain the operating system used, [whether/ what] 32 beet or 64 beet.
3. Download [at] situs Microsoft following. Before all consumer have to do the registration Microsoft Connect beforehand, henceforth fill the brief survey from Microsoft.
4. [At] column download, select;choose the appropriate operating system.
5. Select;Choose your location, then click ' Download' under article Download Single File.
6. Then opened the file of result of unduhan, and follow the instruction hereinafter [so/till] Microsoft Security Essentilas attached.
Thank you for your interest in joining the Microsoft® Security Essentials Beta. We are not accepting additional participants at this time. Please check back at a later date for possible additional availability.
Sebagai alternatif, situs Softpedia menyediakan download MSE untuk beberapa versi:
- MSE untuk Windows XP
- MSE untuk Windows 7 & Vista 32 bit
- MSE untuk Windows 7 & Vista 64 bit

Tuesday, July 7, 2009

Top Virus Dangerous

Serangan malware kian menggila. Ada begitu banyak jenis malware yang mengintai dan siap menyerang pengguna komputer.
Berikut daftar nama-nama malware terganas yang beredar periode 18 Juni 2009-25 Juni 2009, menurut laporan Kaspersky Lab.
1. Net-Worm.Win32.Kido.ih ( 41.9714%)
2. Exploit.Win32.SqlShell.a (9.7527%)
3. HEUR:Trojan.Win32.Generic (7.6628%)
4. Heur.Win32.Trojan.Generic (3.309%)
5. Trojan.Win32.FraudPack.owo (3.1%)
6. Trojan-Downloader.Win32.Agent.cgns (2.5427%)
7. Trojan.Win32.Agent.cltm (1.846%)
8. Trojan.Win32.FraudPack.oxv (1.7416%)
9. Trojan-Dropper.Win32.Small.axv (1.5674%)
10. Trojan.Win32.FraudPack.ovx (1.5674%)

11. Trojan-PSW.Win32.Agent.nfo (1.3236%)
12. Trojan.Win32.Buzus.bhqc (1.2539%)
13. Trojan.Win32.Agent2.kov (1.1494%)
14. Net-Worm.Win32.Kido.dam.y (1.1146%)
15. Heur.Win32.Invader (0.8708%)
16. Net-Worm.Win32.Kido.eo (0.8011%)
17. Trojan.Win32.Monder.cmwt (0.8011%)
18. Trojan-GameThief.Win32.Magania.bfru (0.7315%)
19. Trojan-Downloader.Win32.Agent.ansh (0.6618%)
20. Trojan-Dropper.Win32.Agent.zje (0.5921%
21. Trojan-Downloader.Win32.Agent.cgew (0.5921%)
22. Trojan-Downloader.Win32.Agent.wxq (0.5573%)
23. not-a-virus:Porn-Dialer.Win32.InstantAccess.f(0.5573%)
24. Trojan-GameThief.Win32.Magania.bfrp (0.5225%)
25. Trojan-Downloader.Win32.Small.jvl (0.5225%)
26. Net-Worm.Win32.Koobface.d (0.4528%)
27. Trojan-Downloader.Win32.Injecter.cqd (0.418%)
28. HEUR:Trojan-Downloader.Win32.Generic (0.3831%)
29. Virus.Win32.Sality.aa (0.3135%)
30. not-a-virus:AdWare.Win32.Relevant.n (0.3135%)
31. Trojan-GameThief.Win32.Magania.bfdq ( 0.2786%)
32. not-a-virus:AdWare.Win32.Agent.lmz (0.2786%)
33. not-a-virus:AdWare.Win32.Shopper.l (0.209%)
34. Trojan-GameThief.Win32.Magania.bful (0.209%)
35. Trojan-GameThief.Win32.WOW.bie (0.209%)
36. not-a-virus:WebToolbar.Win32.FenomenGame.pxu (0.1742%)
37. Trojan-Dropper.Win32.Small.dhn (0.1742%)
38. Exploit.Win32.DCom.ad
39. Trojan-GameThief.Win32.Magania.bffe (0.1742%)
40. Trojan-GameThief.Win32.Magania.bfws (0.1742%)
41. Trojan-Banker.Win32.Banker.aifb (0.1742%)
42. Packed.Win32.Black.d (0.1742%)
43. Trojan.Win32.Agent.cgof (0.1393%)
44. Trojan-Dropper.Win32.Small.ayg (0.1393%)
45. Trojan-Downloader.Win32.FraudLoad.wcby (0.1393%)
46. Trojan-Downloader.Win32.Small.jwq ( 0.1393%)
47. Trojan-GameThief.Win32.OnLineGames.bktw ( 0.1393%)
48. MultiPacked.Multi.Generic (0.1393%)
49. HEUR:Backdoor.Win32.Generic (0.1045%
50. Suspicious.Win32.Packer (0.1045%)
51. Virus.Win32.Virut.ce (0.1045%)
52. Backdoor.Win32.IEbooot.dfe (0.1045%)
53. Trojan-Downloader.Win32.FraudLoad.erj ( 0.1045%)
54. Trojan-Dropper.Win32.Agent.atvx (0.1045%)
55. Backdoor.Win32.Agent.ahwn (0.1045%)
56. Multi.Win32.Packed (0.1045%)
57. HEUR:Trojan.Win32.Invader (0.1045%)
58. Trojan.Win32.Agent.abud (0.1045%)
59. Backdoor.Win32.Poison.ahgc (0.1045%)
60. Trojan-GameThief.Win32.Magania.bfsy (0.1045%)
61. Trojan-Downloader.Win32.Agent.cdid ( 0.1045%)
62. Trojan.Win32.Stuh.pdm (0.1045%)
63. Trojan.Win32.Buzus.bigq (0.1045%)
64. Backdoor.Win32.Small.icr (0.1045%)
65. Backdoor.Win32.Agent.ahgv (0.1045%)
66. Trojan.Win32.Agent.cngn (0.1045%)
67. Backdoor.Win32.Hupigon.aovn (0.1045%)
68. Trojan-Dropper.Win32.Agent.atmg ( 0.1045%)
69. Packed.Win32.Black.a (0.1045%)
70. HackTool.MSIL.KKFinder.q (0.0697%)
71. Trojan-Downloader.Win32.Small.aliy (0.0697%)
72. not-a-virus:AdWare.Win32.Webdir.e (0.0697%)
73. Email-Worm.Win32.Joleee.bwu (0.0697%)
74. HEUR:Virus.Win32.Generic (0.0697%)
75. Trojan-Dropper.Win32.Small.cdw (0.0697%)
76. Trojan.Win32.Agent.cccr (0.0697%)
77. Trojan.Win32.Midgare.mqa (0.0697%)
78. Backdoor.Win32.Bifrose.aknz (0.0697%)
79. Trojan.Win32.Agent.cmud (0.0697%)
80. not-a-virus:AdWare.Win32.Shopper.v (0.0697%)
81. Backdoor.Win32.Bifrose.fpb (0.0697%)
82. Trojan-Mailfinder.Win32.Mailbot.ec
83. Trojan.Win32.Agent.cjxh (0.0697%)
84. Trojan-Spy.Win32.Zbot.xdj (0.0697%)
85. P2P-Worm.Win32.Archivarius.b (0.0697%)
86. Virus.Win32.Sality.z (0.0697%)
87. HEUR:Worm.Win32.Generic (0.0697%)
88. Trojan-Dropper.Win32.Mudrop.ask (0.0697%)
89. Trojan.Win32.Agent2.hxw (0.0697%)
90. Trojan.Win32.Agent.cmnr (0.0697%)
91. Trojan.Win32.Agent.rzw (0.0697%)
92. Trojan-Downloader.Win32.FraudLoad.eki (0.0697%)
93. Trojan-Downloader.JS.Agent.gj (0.0697%)
94. not-a-virus:AdWare.Win32.AlexaBar.n (0.0697%)
95. Trojan.Win32.KillWin.pi (0.0697%)
96. not-a-virus:AdWare.Win32.Chiem.c (0.0697%)
97. Net-Worm.Win32.Kido.cy
98. Trojan-Downloader.Win32.Agent.cgaw(0.0348%)
99. Trojan-Dropper.Win32.Mudrop.aso (0.0348%)
100. Packed.Win32.Krap.c (0.0348%)

Sunday, September 7, 2008

SIRCAM/Recycled Virus to Clean ?

This is bad, when I check my PC in this morning, my Windows XP invected by SIRCAM/Recycled Virurs, I try to find how clean this dam problem. After I googling, I found some tutorial. And this is the results.

First Tutorial
1. Go to command prompt.
2. Type CD\ in drive C to go the root directory
3. Type DIR /AH and press ENTER key. This will display all hidden files in your drive C
4. If you see a file AUTORUN.INF and a folder Recycled, then your system is infected.
5. Try doing this to your USB drive and check if your USB stick contains the same folder and AUTORUN.INF, if it does then your system is really infected.

To remove it download and install a trial version of Trendmicro and scan your system.

To manually remove it follow the following steps (This is the step I take when i repair my computer without an internet connection. Note you should understand what you’re about to do, you try it at your own risk!)

1. Boot your system in Safemode
2. Go to command prompt, in Drive C do the following commands.
3. Type -> ATTRIB -H -R -S AUTORUN.INF then press enter
4. Type -> DEL AUTORUN.INF then press enter
5. Type -> ATTRIB -H -R -S Recycled then press enter
6. In Windows Explorer in Safemode, remove the folder Recycled in drive C use Shift-Delete to delete the folder.
7. Repeat Step 3 to 6 for all drives of your system including the USB drive.
8. Search for CTFMON.EXE in your system using the Search of Windows found in Start Menu. If you find a file that is not located in C:\WINDOWS\SYSTEM32, delete it immediately. Dont forget to empty the recycle bin afterwards (Usually the virus will copy itself in the Startup folder of the Startmenu. Check if the file is present there and delete it then.)

To disable autorun of drives (i.e. everytime you double-click a drive or cd or usb, it is auto open) follow the following step:

1. Click Start->Run->type REGEDIT.EXE
2. Go to this key from the register HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
3. Look for the entry NoDriveTypeAutoRun, double click the entry
4. Type a new value : 03ffffff for the NoDriveTypeAutoRun and press ENTER
5. Reboot the system.


Second Tutorial
You can download and run the automatic cleaning tool for SIRCAM or Follow the directions below to manually remove it.

1. First, rename REGEDIT.EXE to REGEDIT.COM. If you want to use the fix tool, there is no need to rename the file
2. Click Start, Run, type REGEDIT and then press Enter.
3. In the left panel, click the (+) left of each of the below:
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
RunServices
4. In the right panel, look for and then delete the registry value called Driver32.
5. In the left panel, click the (+) left of each of the below:
HKEY_LOCAL_MACHINE
Software
SirCam
6. Click SirCam and then press the Delete key.
7. In the left panel, click the (+) left of each of the below:
HKEY_CLASSES_ROOT
exefile
shell
open
command
8. In the right panel, right-click the (Default) value, then choose Modify.
9. Change “C:\Recycled\SirC32.exe””%1”%* to “%1” %*. In other words, remove “C:\Recycled\SirC32.exe”.

Remove the dropped files:

1. Open an MS-DOS box or Command Prompt
2. Go to the System directory (C:\Windows\System or C:\Winnt\System32).
3. Type ATTRIB -S -H -R SCAM32.EXE to unhide the Trojan file.
4. Type DEL SCAM32.EXE to delete the Trojan file.
5. Go to the Recycled folder (C:\Recycled folder)

Note: Emptying the recycle bin does not effectively delete the dropped Trojan files in the folder. It is suggested that the command prompt be used when deleting the dropped files.

1. Type ATTRIB -S -H -R SIRC32.EXE.
2. Type DEL SIRC32.EXE to delete the Trojan file.

Remove the Worm reference from AUTOEXEC.BAT:

1. Look for the AUTOEXEC.BAT file.
2. Search and remove the string “@win \recycled\Sirc32.exe”

Restore your RUNDLL32.EXE:

1. Search for RUN32.EXE in your WINDOWS folder. If not found, then the worm did not overwrite your RUNDLL32.EXE.
2. If found, delete RUNDLL32.EXE and rename RUN32.EXE to RUNDLL32.EXE.
3. Restart your system

Note: If you found the worm entry in the AUTOEXEC.BAT file or if you found the RUN32.EXE file in the Windows directory, this means that other computers in your network are also infected. For protection, minimize giving full access to your drives and as much as possible DO NOT share your Windows and System folder.


Tuesday, July 8, 2008

WORM_VB.EFU

Overview
This detection is for a worm which spreads by copying itself to network shared drives. It also has the ability to terminate security applications.
Characteristics
When the worm is executed, it creates a copy of itself using the following filenames:
C:\BootEx.exe C:\Log.exe C:\WINDOWS\ErrorReport.exe C:\WINDOWS\MonitorMission.run C:\WINDOWS\MonitorSetup.exe C:\WINDOWS\regedif.exe C:\WINDOWS\SystemMonitor.exe C:\WINDOWS\Win System.exe C:\WINDOWS\windows.exe C:\WINDOWS\WinSystem C:\WINDOWS\WinSystem.exe C:\WINDOWS\WinSystem32.exe C:\WINDOWS\SYSTEM\mscomfig.exe C:\WINDOWS\SYSTEM\msiexece.exe C:\WINDOWS\SYSTEM\rundlI.exe C:\WINDOWS\SYSTEM\WindowsUpadate.exe C:\WINDOWS\SYSTEM\msidlI.exe C:\WINDOWS\SYSTEM\msiexee.exe C:\WINDOWS\SYSTEM\regedif32.exe C:\WINDOWS\SYSTEM\SCCONFIG.exe C:\WINDOWS\SYSTEM\WindowsProtection.exe C:\WINDOWS\SYSTEM\winlocon.exe C:\WINDOWS\SYSTEM\wpa.bdlx D:\BootEx.exe D:\help.exe D:\materi.exe D:\SwapDrive.exe
The following files are also created:
C:\WINDOWS\SYSTEM\oemlogo.bmp C:\WINDOWS\SYSTEM\oeminfo.ini

It also drops a log.txt on the desktop which contains the strings 'no error found'.
The following registry keys are created :
HKEY_CURRENT_USER\Software\KyrentSoft HKEY_CLASSES_ROOT\*\shell\Scan for Virus\Command HKEY_CLASSES_ROOT\.bin "Default" = cfgFile HKEY_CLASSES_ROOT\.cfg "(Default)" = cfgFile HKEY_CLASSES_ROOT\.cvd "(Default)" = cfgFile HKEY_CLASSES_ROOT\.dat "(Default)" = cfgFile HKEY_CLASSES_ROOT\.exed "(Default)" = exedfile HKEY_CLASSES_ROOT\.run "(Default)" = exefile HKEY_CLASSES_ROOT\cfgfile "NeverShowExt" HKEY_CLASSES_ROOT\cfgfile\shell\Open\command "(Default)" = c:\windows\windows.exe HKEY_CLASSES_ROOT\excfile "NeverShowExt" HKEY_CLASSES_ROOT\excfile\DefaultIcon "(Default)" = %SystemRoot%\System32\shell32.dll,3 m 3 2 \ s h e l l 3 2 . d l l , 3 HKEY_CLASSES_ROOT\exedfile\DefaultIcon "(Default)" = C:\windows\windows.exe i n d o w s . e x e HKEY_CLASSES_ROOT\Folder\shell\Scan for Virus\Command "(Default)" = C:\windows\MonitorMission.run HKEY_CLASSES_ROOT\htmlfile "NeverShowExt" HKEY_CLASSES_ROOT\Folder\shell\Search\Command "(Default)" = C:\windows\MonitorMission.run HKEY_CLASSES_ROOT\Word.Document.8 "NeverShowExt" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run " SysMonitor" = C:\windows\WinSystem.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "explores" = C:\BootEx.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = 0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "HideFileExt" = 1 HKEY_CLASSES_ROOT\Access.Application.9 "(Default)" = %SystemRoot%\System32\shell32.dll,3 m 3 2 \ s h e l l 3 2 . d l l , 3 HKEY_CLASSES_ROOT\dbfile "(Default)" = %SystemRoot%\System32\shell32.dll,3 m 3 2 \ s h e l l 3 2 . d l l , 3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL "RegPath" = Software\Microsoft\Windows\CurrentVersions\Explorer\Advanced HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt "RegPath" = Software\Microsoft\Windows\CurrentVersions\Explorer\Advanced
The worm minimises applications which contain the following window titles:
Updatex Updatingx Upgradex p.c.m.a.v system restore kill process Task Manager Warning Confirm Value Delete Confirm Key Delete Edit String process xp Process View Process Control Process Explorer process Patrol hijack raypc
Symptoms
Symptoms -
Presence of the mentioned files. Presence of the mentioned registry entries.
Method of Infection
Method of Infection -
The worm spreads by trying to copy itself to local & mapped drives.
Removal -