14
August , 2010
Saturday

Did You connected with zall?

the great website for most popular information, dedicated all free, trusted and up to date

Ku lihat dimata jernihmu Ada titik kecewa terpendam Ada kesan perjalanan usang Ada tumpahan suhu panas Yang merata disekujur ...
Dalam hidup ada yang datang dan ada yang pergi Hanya orang tertentu saja yang pergi Meninggalkan bekas ...
You can install domain keys on a cPanel server easily for a single domain, in ...
Hari ini aku ketemu ama cewek cantik yang duduk tepat disampingku, duhhh... mesra and manjanya ...
The Audi Q7 earned a Top Safety Pick designation from the Insurance Institute for Highway ...
451 Press, LLC is always looking for bright, talented writers who want to have their ...
Sendiri dikeheningan malam Bayangmu terus hiasi anganku Pancarkan cahaya direlung hati Bangkitkan rindu pada dirimu Yang... Kau bukan tenaga bagiku Tapi ...
Stewardesses adalah kata terpanjang yang dapat diketik di keyboard hanya dengan menggunakan tangan kiri Anda. ...
Playing in the world of blogging, of course, is not far from the name "keywords", ...
HSBC - The world's local bank Now you can apply a Credit Card on HSBC Hongkong ...

Archive for the ‘Viruses’ Category

Kaspersky 2009 Anti-Virus Review

Posted by Afrizal On January - 16 - 2009 |ADD COMMENTS | 845 views

kaspersky-anti-virus-2009

Since the ?Award Winning? Kaspersky Anti-Virus 2009 program was released not too long ago, I figured it is time to give it a try and fork up the $40 bucks. I of course used my second PC which runs Windows XP before I wanted to install it on my primary PC running Windows Vista Ultimate.

Like the previous years versions of Kaspersky Anti-Virus, this version was very good at finding and removing threats. I won?t go into what sites I would visit in order to make sure I infected the Windows XP computer nice, but we can say they were not all G rated. And of course I wrote all the sites down and kept a log of it. Read the rest of this entry »

Virus : Trojan-Downloader.Win32.Banload.dcd

Posted by Afrizal On September - 5 - 2008 |ADD COMMENTS | 52 views

Computer virus, trojak downloader, win32This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user?s knowledge or consent. It is a Windows PE EXE file. It is 113152 bytes in size. It is not packed in any way. This Trojan is written in Visual Basic.
Installation

Once launched, the Trojan copies its body to the Windows program files directory as “lsass.exe“:
%Program Files%\Microsoft Studio Files\lsass.exe

In order to ensure that the Trojan is launched automatically each time the system is rebooted, the Trojan registers its executable file in the system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
“lsass” = “%Program Files%\Microsoft Studio Files\lsass.exe”

The Trojan then creates a command interpreter file called “vcdg.bat” in the same directory:
%Program Files%\Microsoft Studio Files\vcdg.bat

It writes the following strings to this file:
netsh.exe firewall add allowedprogram PROGRAM=”%Program Files%\Microsoft Studio
Files\lsass.exe” NAME=”Session Win32″ MODE=ENABLE PROFILE=ALL

In doing so, the Trojan modifies the configuration of the Windows XP firewall, permitting any network activity created by the malicious process.

“%Program Files%\Microsoft Studio Files\vcdg.bat” is then launched for execution.

Payload Once installed, the Trojan downloads files from the following URLs:
http://www.club-vw.cl/*****/modules/subsmanager/api_apache.tar http://www.*****-consult.net/rcss.res http://www.photo-*****.ru/images/exhibition_moll2005_file0031.jpg

At the time of writing, these links were not active.

http://www.cemm*****ac.at/img/nav/plus19a_RO.jpg

This file is 2603325 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-Spy.Win32.Banbra.bak.

Files which are downloaded are saved to the Trojan’s installation directory under random names and launched for execution.
How to clean If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

1. Use Task Manager to terminate the Trojan process.
2. Delete the following system registry key parameter:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] “lsass” = “%Program Files%\Microsoft Studio Files\lsass.exe”
3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
4. Delete the following directory and its contents:
%Program Files%\Microsoft Studio Files
5. Delete all files from %Temporary Internet Files%.
6. Update your antivirus databases and perform a full scan of the computer

Get Adobe Flash playerPlugin by wpburn.com wordpress themes

Recent Comments

I blog about anything new, Dedicated all for free, Put anything into the words, Share with You what I know. I write anything that I find interesting

Recent Comments

Minggu Kelabu

On Jun-6-2005
Reported by Afrizal

My Honey

On Jun-18-2005
Reported by Afrizal

Running Apple Mac OS X on a Standard PC

On Oct-22-2008
Reported by Afrizal

Sebuah Nama

On Dec-25-2005
Reported by Afrizal