Headlines News :
Tampilkan postingan dengan label VirusWorm. Tampilkan semua postingan
Tampilkan postingan dengan label VirusWorm. Tampilkan semua postingan

Mozilla Firefox Palsu Beredar Berisikan Virus Trojan yang Dapat Mencuri Password

Mozilla Firefox Palsu Beredar Berisikan Virus Trojan yang Dapat Mencuri Password. Seorang peneliti dari Sophos mengingatkan perihal adanya virus trojan yang mengancam para pengguna Mozilla Firefox.

Peneliti tersebut mengatakan, penyebaran virus ini adalah dengan email. Disebutkannya bahwa jika ada notifikasi email dengan subyek ‘New Version released’ dari email dengan alamat @firefox.com adalah palsu. Email tersebut adalah sarana virus untuk menginfeksi Mozilla yang sudah terinstal di PC.

Email tersebut berisikan pesan bahwa untuk mendapatkan update terbaru dari Mozilla Firefox, pemilik PC harus mendownload sebuah file kecil yang merupakan patch file. Selanjutnya patch tersebut, ujar pesan dalam email itu, akan memperbaiki sejumlah fitur keamanan dan sedikit perubahan pada tampilan browser.

Mozilla Firefox Palsu Beredar Berisikan Virus Trojan yang Dapat Mencuri Password

Berikut ini adalah pesan email secara lengkap:
“A Firefox software update is a quick download of small amounts of new code to your existing Firefox browser. These small patches can contain security fixes or other little changes to the browser to ensure that you are using the best version of Firefox available.

“Firefox is constantly evolving as our community finds ways to make it better, and as we adjust to the latest security threats. Keeping your Firefox up-to-date is the best way to make sure that you are using the smartest, fastest and . most importantly . safest version of Firefox available.

“A Firefox update will not make any changes to your bookmarks, saved passwords or other settings. However, there is a possibility that some of your Add-ons won.t be immediately compatible with new updates.”

Di bagian bawah email, terdapat link yang merujuk ke alamat btopenworld.com. File eksekutabel ini sebenarnya adalah installer untuk Mozilla Firefox 5.0.1 dengan password stealer. Virus ini akan mencoba mengalihkan perhatian pemilik PC, sedangkan virus ini tetap bekerja secara underground.

There is Valentine Malware in Theme Free on Facebook

There is Valentine Malware in Theme Free on Facebook. Clickjacking activities that utilize social media pages on Facebook already carry out the action. Recently, Trend Micro, locate and identify malware targeting Facebook users Valentine worldwide.

Valentine Malware in Theme Free on Facebook
The attack began with the discovery of a posting on the wall of users and others, which contains an invitation to click and install a free theme for the display with the feel of a typical personal Facebook Valentine.

Trend Micro detects as TROJ_FOOKBACE.A installer, and when executed it TROJ_FOOKBACE.A will execute a script that displays ads from certain sites.

For a user who clicks through and install the Google Chrome browser and Mozilla Firefox, malware by itself will lead to the installation of a Facebook Environment / Facebook.com that appears in the top right tab the user's Facebook page.

Furthermore, with this apikasi installed, it will monitor the activities of users at once directed to a page survey, which asks you to enter your phone number. For those who use the Internet Explorer browser, without installing a Facebook Environment, you will be immediately directed to the survey page.

From observation of the activity of Trend Micro's browser, TROJ_FOOBACE.A until now is not the case of data theft techniques. However, Trend Micro, still gives a warning that users remain wary of traps for free nuanced this Valentine theme.

Also recently circulated an email scam that profiteer name Mark Zuckerberg directly through the lure of a free-for iPad 3.

Five Million Android Gadget infected with Virus

Five Million Android Gadget infected with Virus.This type of virus is the most attacking Counterclank. This malicious program has the ability to download a special file, and sends information to the victims of the virus with no known owner.

In his official site, Symantec states that Counterclank attacking through applications made by three different developers namely, iApps 7 inc, Ogre Games, and redmicapps. Actually this is not a new type of virus, this is the development of viruses that have been detected Tonclank June 2011 and with a similar attack mode.

Counterclank currently still exists in some games and applications on the Android market. It is not certain how many devices have been infected, yet the amount is not less than five million units.

Ramnit virus

Ramnit virus. Which has long been horrendous computer users... it does not stay silent, the evidence so far RAMnit save / make watermark.exe file in the folder% programfiles% / microsoft / watermark.exe, it has migrated to:

1.  % Windir% \ system32 \ microsoft \ watermark.exe and
2.  % Userprofile% \ application data \ microsoft \ watermark.exe

This suggests that the creator of this RAMnit Virus, actually have observed how the development of Viruses of the creation and always wanted to make it more powerful...

Ramnit virus

RAMnit virus is highly contagious due to:
  • Infect dll files, dll files, very few people even notice it but the file extension dll files that are used more often than the files ending in exe, because almost every time we run the exe file then inadvertently we have also run a dll file is, for example: click  right, open, explorer and so on.....Infect html file, html file is a file that is always used by Internet users, both online and offline.Untuk it will make the effects of transmission will be very fast in order to spread this virus ramnit.Infect exe files, exe files are program files / applications that must be used by all computer users, when the application file is infected, how? .... The master program we will be infected and every time we install a program... for example: Office, Photoshop, Corel, acrobat reader, etc.... Then our system will always be infected.
  • Infect the system with the file extension. CPL, besides RAMnit Viruses transmitted through EXE files, the virus also makes files ending in. Cpl, exe and shortcuts in all of the UFD / portable hard drive, especially the FAT format, which by default... if didobel click the shortcut...  will automatically run by control.exe.... and will be dropped as well rename the file watermark.exe watermark.exe running into svchost.exe....  look at the contents of the shortcut copy of a copy of...
  • Autorun Windows.... , Almost all the viruses that infect tercopy to the UFD to rely on its autorun windows.

Please clean with cleaner Anti Virus (PCMAV for ramnit, NOD32 stand-alone, etc.) after successfully cleaned up I recommend to make the program files / master is a RAR file with Winrar program  / 7zip etc., or for a large size can be used as an ISO or NRG files..... with the help of ultra ISO / NERO image... because the file will be more awake than virus infection...

How to clean:
  • Prepare cleaner Anti-Virus (I use NOD32 stand-alone) in a way> download here <and save it in the form of a zip file / RAR to the exe file is not infected.
  • Save the file on the UFD or copy and paste on the infected computer's hard drive.
  • Use task manager, select the task / processes tab and end task all the file svchost.exe and also all that can end task (except: task manager)
  • Open the file which is already cleaner NOD32 zip / RAR, using the file open in the task manager.Rubah program options in order to open the file into allfiles file zip / rar of NOD32 can be seen.
  • after teropen NOD32 with winrar or other application..  please double click the *. exe file of Nod after the next... next dipilihan action, the left select Clean and right select Scan & delete.Lalu run clean
  • after running close / close winrar / applications made to open NOD32 zip / RAR.
  • Please be supervised by the task manager if there is a file svchost.exe / exit processes appear in the task immediately at the end... and as usual when there is no display windows, warning that the computer will shutdown in 60 seconds / 1 minute....  please type in the file menu open / run: shutdown-a meaning-a is the shutdown command to cancel the action...
  • Warning!!!!! , While NOD 32 clean file on your computer, not to open / run any file... because let alone run the exe file, right click aja we have means to run a virus / its svchost.exe Virus Ramnit.
  • Remember... we need to watch are: turn off / end task svchost.exe file for NOD32 to clean files on your computer.....

Maybe useful
Regards

Origin of viruses

The virus, first the which Appeared in the world named [Elk Cloner] was born about 1981 in TEXAS A & M. Spread through Apple II floppy disks are operating systemnya That. The destroyer is displaying a message on the screen: "It Will get on all your disks, It Will infiltrate your chips-yes it is the Cloner!-It Will stick to you like glue-It Will modify RAM too-send in the Cloner " Hi ... ... ... ... ... .... The name "virus" is a new herself, after two years of his birth by Len Adleman on 3 November 1983 in a seminar discussing how to create viruses and protect yourself from viruses. But the people-Those men assume Often Appeared That the first virus is a virus [Brain] Who were the resource persons born in 1986. Fair wrote, Because the virus is the most shocking and the most widespread distribution karean DOS diskette That runs through it again ngetrend time. The birth also coincided with the [PC-Write Trojan] and [Vindent]

1949, John Von Neuman, expressing "self-altering automata theory," which is the result of research mathematicians.

1960, lab BELL (AT & T), experts in the lab BELL (AT & T) dabbled in theories expressed by john v Neuman, They toyed with the theory to a type of game / games. The experts make-a program Itself That can reproduce and can destroy the opponent artificial courses. Programs That are Able to survive and destroy all other programs, it Will be deemed the winner. This game eventually Became the favorite game in each and every computer lab. The longer They were the resource persons aware of and begin to be aware of this game Because the program created more and more dangerous, so They are doing surveillance and strict security.

In 1980, the program That Became known as the "virus" was successfully spread beyond the lab environment and began to Circulate in cyberspace.

In 1980, That begin to known viruses spread in the cyber world.

From then on, `the virus began to take over the world. Development really horrible and frightening! one year later CAME That the virus first infects files. Usually the attack is a file with extension *. exe virus is named [suriv] included in the virus "Jerusalem". Speed ​​of its spread is enough 'thrill' for the moment. But this virus guns' too bad ko 'Because this virus hit and beat up its IBM mainframe guns' for long, just a year.

1988, BIG attacks Appear to Machintosh by viruses [MacMag] and [scores] and the Internet beaten out by Robert Morris-made virus. In 1989 there prankster WHO sent the file "AIDS information program" and unfortunately, so this file is opened, the which is obtained instead of info about AIDS, but the virus mengenskrypsi hard drive and charge for the opening code.

Remove virus shortcut

Remove virus shortcut can be done by using application shortcuts Virus Remover v2.1 (Beta). For those who don't have the application, can download the application here. The following steps should be done:

1. Shortcut install Virus Remover v2.1 (Beta)
2. select the location / drive will be scanned, a removable disk or from a computer
3. then click on scan and let the application run it for viruses.
4. if it is remove, restart your computer

may be useful
regards
 
-
-
Support : Tes
Copyright © 2011. TipsKu - All Rights Reserved
Tes
Proudly powered by Blogger