Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Phising For Love

Valentine: Love. That's all what we think about that word, but, actually many phisher that use this condition to make you him/her victims.


And in this post i would like to tell you how to being save.

Click for Save Steps :
Use a reputable, paid dating service – Famous brand names are an easy security win. They’ll have secure websites and the paid subscription should deter some trouble makers. The large user base will help you find your match too!
Think carefully about your profile – Make sure that you’re not revealing anything that you don’t want to in your profile. Details such as your salary and phone number are things that you don’t need to be sharing in public and could make you a target for scammers.
Take Your Time- Most dating services come with some sort of communication system, be it chat, video, email or phone call. There’s no need to hand out your phone number any more, your matchmaking service can help you protect you and your identity. Don’t rush into something headlong; think about what you are comfortable with.
Use your profile inbox - Emails asking to “reset your password” or “confirm your details” could easily be from scammers posing as official emails from your dating service. These days most services come with profile emails allowing you to contact other members and for the site itself to contact you. If you’re worried about the authenticity of an email, check your profile’s inbox before giving away any information.
That's all about my post, and hope you will be save, in 'Love' date ;)

Original: AVG Blog

NgrBot

Ngrbot is a malware that can stole our email, usename, and password. NgrBot is a malware like worm with type trojan that can spread rapidly, because this malware using a different shortcut type normally.


NgrBot we known as a alphabetic icon


And it made using C++ another ability from this malware is can't read by memory (rootkit) to protect itself, they use hooking technique in some API function. But this malware isn't active when the user on safe mode.

The best ability from this malware is how they can steal our user data, ID, or another private account.
And this is the website target from this malware

Click for Website Target :
1. Web Hosting & Domain
- dotster
- 1and1.com
- enom.com
- moniker.com
- namecheap.com
- godaddy.com
- sms4file.com
- dyndns.com

2. Online Payment
- alertpay.com
- paypal.com

3. E Commerce
- netflix.com
- thepiratebay.org
- ebay.com

4. Hacking
- torrentleech.org
- hackforums.com

5. Premium Account
- vip-file.com
- what.cd
- loginid.com
- secure.logmein.com

6. FileHosting
- letitbit.net
- oron.com
- filesonic.com
- speedyshare.com
- uploaded.to.com
- uploading.com
- fileserve.com
- hotfile.com
- 4shared.com
- netload.in.com
- freakshare.com
- mediafire.com
- sendspace.com
- megaupload.com
- depositfiles.com

7. Internet Banking
- officebanking.cl.com
- moneybookers.com
- bcointernacional.com

8. Game
- runescape.com
- steampowered.com

9. Social Networking
- twitter.com
- facebook.com
- bebo.com
- friendster.com
- vkontakte.ru

10. WebMail
- yahoo.com
- mail.live.com
- gmx.com
- Gmail.com
- fastmail.com
- bigstring.com
- screenname.aol.com

11. WebPorn
- IKnowThatGirl.com
- YouPorn.com
- Brazzers.com

12. Etc
- YouTube.com
And this malware also record our keystroke (Like keylogger) in this application

Click for Application :
- pidgin.exe
- wlcomm.exe
- msnmsgr.exe
- msmsgs.exe
- flock.exe
- opera.exe
- chrome.exe
- ieuser.exe
- iexplore.exe
- firefox.exe
And Ngrbot have many variants, and this is variants from Ngrbot

Click for Variants :
1. NgrBot
Host NgrBot is in the Application Data folder with a random name and extension (.Exe / .Tmp). In addition, NgrBot also hiding behind a RECYCLER folder which made by this malware after the removable disk is connected to the infected computer.

2. NgrBot.drp.A


The one of dropper from NgrBot that in startup folder which extract NgrBot.exe.A and NgrBot.bat

3. NgrBot.drp.B
Variant of NgrBot which places in Application Data, that have a function same with NgrBot.drp.A

4. NgrBot.lnk


Different from the other shortcut, NgrBot.lnk add another parameter in their shortcut, example:

%windir%\system32\cmd.exe /c "start %cd%RECYCLER\bcd8f464.exe &&%windir%\explorer.exe %cd%Removal

%windir%\system32\cmd.exe /c “start => Call Command Prompt that add a parameter “/c” that mean after we execute file will automatically close Command Prompt. And there is “start too, this is use for to execute a file
%cd% => Parameter that use for access a folder
RECYCLER\bcd8f464.exe => This is used to access folder RECYCLER where in this folder have host virus with name “bcd8f464.exe”
%windir%\explorer.exe =>  Call explorer.exe to open folder which name same as shortcut name that we launch, to make other people believed that shortcut is a normally folder
Removal => Example of folder name

5. NgrBot.bat


One of companion that use to execute and add a special parameter to NgrBot.exe.A

6.  NgrBot.exe.A.



Companion of NgeBot that execute by NgrBot.bat in same path that is folder temporary (temp)

7. NgrBot.dat


Companion that in all off this malware just content off random characters that normally in system32 folder or Documents and Settings folder


8. NgrBot.exe.B.
NgrBot.exe.B. always in User Profile and also make a value in registry with name –“u” so it can launch at startup

9. NgrBot.inf


Same with other malware that used Autorun.inf to launch their malware, without exception NgrBot. They make Autorun.inf too, and it always added a random character.

10. NgrBot.mem


Threads that are in memory and can not be detected by ordinary detection technique because it is a thread that is hidden by a rootkit techniques, also using hooking techniques while monitoring user activity and continue to spread the companion every time removable disks connected to the computer.
And this is some tricks to prevent from this malware

Click for Prevent :
1. Don't click any links that we don't know what is that from chat
2. Tell to friends if they're send a link in chat
3. Update antivirus
4. Always use HTTPS
5. Sign out after use from any website that required login

But if you had infected by this malware you can download PCMAV Express for NgrBot from Here.

Hopefully it will add your knowledge :)

Original: Virus Indonesia

10 Popular Virus

Virus has give a big effect in our computer. From virus with extension .lnk until .vbs, and now i want to share 10 old popular virus for our computer.

Click for 10 Popular Virus :
1. Pray


Local virus was created using Visual Basic. We found two variants of this virus, for variant Pray.A not have an icon, while for variant Pray.B use Windows Explorer-like icons. If your computer is infected by this virus, when the computer clock on the show at 05:15, 13:00, 16:00, 18:30, or 19:45, the virus displays a message reminding the user to prayer.

2. Explorea


Viruses that are compiled using Visual Basic comes with a size of about 167,936 bytes, without being compressed. Using the standard Windows folder icon similar to defraud victims. This virus will attack your Windows Registry to change the default open of some extensions like .lnk , .pif , .bat, and .com. At the infected computer, in times when certain error messages sometimes appear, for example when opening the System Properties.

3. Hampa


Viruses are also created using Visual Basic and had a folder icon has a size of about 110,592 bytes, without being compressed. Lots of changes he made ​​in Windows, such as the Registry, File System, and so forth, which can even cause Windows can not be used as appropriate. On computers that are infected by this virus, when you start Windows will display a message from the virus creator.

4. Code Red


Code Red shows itself on July 13, 2001, by attacking every server that uses Microsoft Internet Information Server (IIS). Worm or virus takes advantage of the open space on the IIS System. Also known as Bady, the virus is designed to inflict severe damage, being able to perform Denial of Service attacks on the IP-specific IP, so not surprisingly capable of causing damage to hundreds of trillions of dollars, and in less than a week the 400 000 server successfully conquered by this virus.

5. Nimda


It was also the year 2001, the opposite of the word "admin". It spreads very rapidly, according to TruSecure CTO Peter Tippett, Nimda only takes 22 minutes to make into the Top Ten at the time. It target is server 2 Internet, spread over the Internet. Nimda will make back door into the OS. so an attacker can access to the server and do anything Nimda also a DDoS.

6. CIH


Detected in June 1998 is also known by the name Chernobil virus, capable of causing losses to 800 billion rupiah. CIH virus attack any files. Exe on computers using Windows 98 operating system, Windows 95 and Windows ME to be his victim. Once your computer is infected, the virus will continue to keep silence in memory, so the result each time you turn on the computer, the virus will always be active. Not only that, the CIH virus able to cause your computer will not boot, because all the system files have been too overwritten by the virus. But now, for users of Windows 2000, Windows XP or Vista, the virus is no longer a threat.

7. SQL Slammer/Saphire


Appeared in January 2003, quickly spread via the Internet. At that time Bank of America ATM service makes a crash, the collapse of Seattle 911 service, and Continental Airlines canceled some flights due to error check in and ticketing. Make a loss of more than $ 1 billion.

8. Blaster


Capable of causing losses to more than 100 trillion more, detected in 2003 also known as Lovsan or MSBlast attacked thousands of users of Windows 2000 and Windows XP all over the world via the Internet or network traffic.

9. Melissa


Friday March 26, 1999, The Melissa virus was the topic everywhere because it infects every PC that uses Microsoft Outlook. This virus could spread quickly because once the victim's computer is infected, Melissa automatically sends itself (in the form of file attachments. Doc) to 50 addresses found in the contacts in Microsoft Outlook. Once the victim opens the file. Doc, then automatically switches the Melissa virus. From Intel to Microsoft and several other major companies that use Microsoft Outlook, until forced to shut down their email systems, to prevent the further spread of this virus. losses incurred so fantastic because almost reach 6 trillion rupiah.

10. ILOVEYOU


Was first detected in Hong Kong on May 3, 2000, causing losses which was fantastic because hampis reach hundreds of trillions of rupiah. Created by using Visual Basic Script, the virus is so seductive because it spreads via email with the subject "ILOVEYOU". You must be curious about it if you receive an email with frills "ILOVEYOU", and the virus takes advantage of all your curiosity, because once you open the email, the virus automatically infects your computer. Once your computer is infected, the virus automatically sends itself to all addresses found on the contact in Microsoft Outlook.Virus is also known as Loveletter and The Love Bug.
Just for sharing, hope this information will give you a new knowledge

Thanks to: Indahnya Kebersamaan, Math is My Activity, tasikisme

Shortcut Virus[Part 2]

If long time ago i has posted about Shortcut Virus[Part 1] today I will share the second part, Check It Out!



Click for Identifying :
1. At the first this virus will create main file database.mdb in My Documents
2. Will create autorun.inf in all drives (Hard Disk, Flash Disk, Folder, etc) without exception
3. Will create file Thumb.db (Watch out! This file is without ' s ' if the real file of thumbnail catch in our computer is using ' s ' is it like Thumbs.db) in every folder
4, To make this virus more interesting for the target, this virus will create file Microsoft.lnk & New Harry Potter and….lnk in every folder, that if we click it, this virus will automatically activated.
5. Will made a duplicate file in every folder, but this virus is not with extension .exe but .lnk (Shortcut)
6. Have wscript.exe process that run in task manager, but on normally condition there is nothing  
Click for Delete Virus Shortcut :
1. Turn off System Restore
2. End virus process wsrcipt.exe (C:\WINDOWS\System32\wscript.exe)
You can use Task manager or misc on Hijack This 
3. Delete file database.mdb in my documents
4.Delete duplicate file of virus
*You can use Search facility on windows to delete a file, and on 'More advanced search' tick on "Search system folders” and “Search hidden files and folders"

What you must to do:

*Search file with name autorun.inf (Size 8 KB)
*Search file with name Thumb.db (Size 8 KB)
*Search file with extension .lnk (Size 1 KB)

Delete all file that you've found

5. Delete registry autorun using Hijack This

Find in HKCU\..\Run: that related with database.mdb

regedit_run

That's all for this post, and once more big thanks i give to Binus Hacker For all they good post

Shortcut Virus[Part 1]

Today I will share about how to delete shortcut virus

and for this is the tutorial:



Click for Virus Shortcut[Part 1] :
1. Disable 'System Restore' for a while during the cleaning process.

2. Disconnect the computer that you want to clean from internet

3. Turn of the process of virus use ‘Ice Sword’ tools, after you’ve installed it on your computer, choose a file with icon ‘Microsoft Visual Basic Project' click 'Terminate Process'. You can download ‘Ice Sword’ tool at http://icesword.en.softonic.com/

4. Delete the registry is created by the virus by:
-. Click the [Start]
-. Click [Run]
-. Type Regedit.exe, and click the [OK]
-. On application the Registry Editor, browse the key [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run]
-. Then delete the key that has the data [C: \ Documents and Settings \% user%].

5. Disable autoplay/autorun Windows. Copy the script under here paste in notepad and then save with name REPAIR.INF choose for ‘All Programs’ after that install that file with Right Click on the REPAIR.INF file ==> And click instal

[Version]
Signature=”$Chicago$”
Provider=Vaksincom
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255

6. Delete main files and duplicate files are created by the virus included in the flash disk. To make easier the search process, you can use the 'Search' feature. Before you search the file, you should show all hidden files by changing the Folder Options settings.

Don't get a mistake when deleting a main files and duplicate files that have been created by the virus. Then delete the main files that have characteristics:

-. Icon 'Microsoft Visual Basic Project'.
-. File Size 128 KB (for other variants will have varying sizes).
-. Extension. file '. EXE' or '. SCR'.
-. File type 'Application' or 'Screen Saver'.

Then delete the files duplicate shortcut that have characteristics:

>. 'Folder' icon or the 'icon' icon
>. Extension. LNK
>. File Type 'Shortcut'
>. 1 KB file size

Delete the file. DLL (example: ert.dll) and the Autorun.inf file on flash disk or a shared folder. Meanwhile, to avoid the virus is active again, delete the master file that has the extension EXE or SCR first and then remove Shortcut file (. LNK).

7. Unhide the folders have been hidden by the virus. To speed up the process, please download the tools Unhide Files and Folders in http://www.flashshare.com/bfu/download.html.

Once installed, select the directory [C: \ Documents and Settings] and folders that exist on the flash disk by sliding into a column that is already available. In the [Attributes] empty of all the options, then click the [Change Attributes].

8. Install security patches 'Microsoft Windows Shell shortcut handling remote code execution vulnerability, MS10-046'. Please download the security patch at http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx

As always, for optimal cleaning and prevent re-infection, you should install and scan with antivirus software that up-to-date and was able to detect this virus very well.
I hope this tutor is useful for us
~Thank you~

Original: BinusHacker