Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

10 Types of Computer Virus

Sunday, April 17, 2011
Every day new computer viruses created to disrupt and create major damage by destroying our computer system. Here are ten viruses are common and potentially cause damage. New viruses are created every day. This means that many viruses that are not included in this list. Terbaikyang things we can do is remain vigilant, constantly updating anti-virus, and always consider whether your computer is virus or not.
 

  1. Virus: Trojan.LodearTrojan Horse attack when we download data from the internet. This virus will inject the file. etc. to internetexplorer.exe that cause system instability.
  2. Virus: W32.Beagle.CO @ mmIs a virus that sends mass emails to sites that have low security level. This virus can delete registry keys and its parts and may block access to security network website.
  3. Virus: Backdoor.ZagabanTrojan virus on this one particular computer injects to be used as a refuge to damage the network or network related.
  4. Virus: W32/Netsky-PThe virus is able to deploy bulk mail itself to email addresses that are produced by a file on your PC / local drives.
  5. Virus: W32/Mytob-GHVirus spreader bulk mail and IRC is a Trojan for the Windows-based computers. Messages sent by this virus with a title chosen at random from lists that already exist such as: warning barring an account, email account suspension, safety measures, member support, a warning is important.
  6. Virus: W32/Mytob-EXViruses that spread the bulk mail and IRC Trojan-like W32-mytob-gh. W32/mytob-ex continuously in the background, providing a back door for the server to reach another computer via IRC channels. The virus is spread by itself, particularly to address email attachments.
  7. Virus: W32/Mytob-AS, Mytob-BE, Mytob-C, and Mytob-ERThis virus family have the same karasteristik for what they are doing. They spread the bulk email that can be controlled via Internet Relay Chat (IRC) network. In addition, they can distribute email via a variety of computer operating systems are weak such as LSASS (MS04-011). 
  8. some sourcesVirus: Zafi-DBrazilians virus bulk email sender and peer-to-peer which makes copies of itself to the Windows system folder with filenames nortonupdate. exe. This virus can make a number of files in the Windows system folder with filenames consisting of 8 random characters and a DLL extension. w32/zafi-d copying itself to folders with names containing share, upload, or music as ICQ 2005anew! . exe or winamp 5.7 new! . exe. W32/zafi-d declarant will also display an error box that deceive with the title "CRC: 04f6Bh" and the text "Error in packed file!".
  9. Virus: W32/Netsky-DThe virus is also sent through an IRC backdoor attack that serves also infect computers vulnerable.
  10. Virus: W32/Zafi-BThis virus attacks the peer-to-peer (P2P) and email the virus will copy itself to the windows system folder which will be named automated random.
from several sources

The following name / The types of viruses and how each virus:

   1. Virus Files
      
This virus has infected the workings of an existing application or document on your computer. When an infected application is executed, the virus will spread by infecting files or documents accessed by the application.

   
2. Boot Sector Virus
      
This virus has a way of working that is infecting the hard disk boot sector (boot sector is an area in the hard drive is accessible when the computer is first turned on). If the boot sector virus is active, users will not be booting the computer normally.

   
3. E-mail Virus
      
This virus has a way of working that is spread via e-mail (usually in the form of attached files / attachments). The virus has a special characteristic of the extension. Scr,. Exe,. PIF, or. Bat.
      
If the virus is active, it will transmit itself to a variety of names e-mail addresses contained in the user's address book.

   
4. Multipartite Virus
      
This virus has a way of working that infects computer files on the hard disk boot sector as well. This type of virus will cause many problems because it causes a fatal damage.

   
5. Polymorphic virus
      
This virus has a unique way of working with this virus can change the code itself (change form) while spreading itself to other computers.
      
The virus type is more difficult to detect because they have such properties.

   
6. Virus Beast (stealth virus)
      
This virus has a way of working that is he able to hide himself by making an infected file as if the file is not infected.

   
7. Macro Virus
      
This virus has a way of working which infect Microsoft Office applications, such as Word and Excel.
      
Documents are usually infected by Macro Virus will modify the existing command in Microsoft Office such as the "Save" to spread itself when the command is run.

History of Virus

A. Origin VIRUS
1949, John Von Neuman, menggungkapkan "self-altering automata theory"which is the result of research mathematicians.
1960, lab BELL (AT & T), experts in the lab BELL (AT & T) trial and error theoryrevealed by john v neuman, they play around with the theoryis for a type of game / game. The experts makeprogram that can reproduce itself and to destroy the programartificial lawan.Program which can survive and destroy all programsanother, it will be considered a winner. The game was eventuallya favorite game in each and every lab komputer.semakin their oldwas conscious and started to be aware of this game because the programcreated more and more dangerous, so they dosupervision and strict security.
1980, the program that became known as the "virus" ismanaged to spread beyond the lab environment, and began to circulate incyber world.
1980, the start is known viruses that spread in the cyber world.
B. UNDERSTANDING THE VIRUS
"A program cans That Infect other programs by modifying Them to includea slighty altered copy of itself.A virus spreads cans Throughout a computersystem or network using the authorization of every user using it toTheir programs Infect. That gets infected every programs act as cans AlsoThat a virus infection grows "(Fred Cohen)
The first time the term "virus" is used by Fred Cohen in 1984 inUnited States. A computer virus called "virus" because it has somefundamental equation with the virus in medical terms (biological viruses).
Computer viruses can be interpreted as a computer program biasa.Tetapihave fundamental differences with other programs, namelyvirus designed to infect other programs, change,manipulate it even hurt it. There is to be noted here,virus will infect only if a trigger program or programs you haveinfected was executed, where it differs with the "worm". WritingThis worm will not be discussed because the later will divert us fromdiscussion of this virus.


C. CRITERIA FOR VIRUS
A program called the new virus can be said is completely truevirus when at least have 5 criteria:

   
1. The ability of a virus to obtain information
   
2. His ability to examine a program
   
3. His ability to reproduce and transmit
   
4. His ability to manipulate
   
5. His ability to conceal themselves.
Now will try to explain briefly what is meant from eachEvery ability is and why it is needed.
1.Kemampuan to obtain information
In general, a virus requires a list of file names that exist ina directory, for what? so that he can identify what programsJust who will he tulari, such as macro viruses that will infect allfiles ending in *. doc after the virus was found, this is where the abilitygather the information necessary for the virus to create a list /all data files, continue to sort them by looking for files that can beditulari.Biasanya this data is created when a program infected / infectedor even a virus program is executed. The virus will immediately takedata collection and put it in RAM (usually: P), so that ifcomputer is turned off all the data is lost but will be created each programbervirus run and is usually created as hidden files by virus.
2.Ability check divulging program
A virus must also be biased to examine a program that willtransmitted, for example, he served infect *. doc extension program, hemust check if a file document has been infected or not,because if it is then he will be useless menularinya 2 times. It's veryuseful to improve the ability of a virus in terms of speedinfect a file / program.Yang commonly performed by the virus ishave / give a mark on the files / programs that have been infectedso easy to recognize by the virus. Sample markingis such as to provide a unique bytes in each filehave been infected.

 
3.Kemampuan to multiply

This Kalo emang virus "bang-get", meaning without this is not a virus.
The core of the virus is the ability mengandakan itself by infecting
other programs. A virus if the victim has found candidates
(either a file or program), then he will recognize it with a check,
if it is not infected then the virus will initiate action to infect
by writing the byte identifiers in the program / ​​file, and
onwards mengcopikan / write virus code above object files / programs
infected. Some common ways that done by the virus to
infect / reproduce itself are:

a.File / programs that will be transmitted deleted or renamed. then
created a file using that name by using the virus
it (ie virus name change by the name of the deleted file)
b.Program virus already in the execution / memory load to be directly
infect other files by way of riding all the files / programs
existing.

4.Kemampuan entered manipulation

Routine (routine) owned by a virus will be executed after the virus
infect a file / program. contents of this routine can be varied
ranging from the lightest to destruction. This routine is generally used
to manipulate the program or popularizing the creators! This routine
advantage of the ability of an operating system (Operating System),
so have the same ability with the present system
operation. example:

a.Membuat image or message on the monitor
b.Mengganti / change to change the label of each file, directory, or the label of
   drive on the pc
c.Memanipulasi programs / files that infected
d.Merusak programs / files
e.Mengacaukan working printer, etc.


Hiding self 5.Kemampuan

The ability to hide themselves must be owned by a virus for all
good job from the beginning to the success of transmission can be accomplished.
the usual steps are:

-original program / ​​virus is stored in coded form and machines combined with
  Other programs that are considered useful by the user.
-virus program is put on the boot record or tracks that rarely
  note by the computer itself
-virus program is made as short as possible, and the results are not infected files
  changing size
-The virus does not change the description of time a file
, etc.


D. VIRUS LIFE CYCLE

Viral life cycle in general, through 4 stages:

o Dormant phase (Phase Rest / Sleep)
In this phase the virus is not active. The virus will be activated by a condition
specific, such as: the date specified, the presence of other programs / execution
other programs, etc.. Not all viruses through this phase

o Propagation phase (Phase Distribution)
In this phase the virus will unite himself to a program or
to a place of storage media (both hard drives, ram etc). Each
Infected programs will be the result of "klonning" virus
(depending on how the virus infects)

o Trigerring phase (Phase Active)
In this phase the virus becomes active and this is also the trigger by some
conditions as in Dormant phase

o Execution phase (Phase Execution)
In this phase the virus is active before going to perform its function.
Such as deleting files, display messages, etc.


E. TYPE - TYPE VIRUS

To further refine our knowledge about the virus, I will try
provide an explanation of the types of viruses that often roam
in the cyber world.

Macro 1.Virus
This virus type is very often we would have written this dengar.Virus
with the programming language of an application rather than by language
programming of an Operating System. The virus is able to walk when
constituent applications to run well, meaning if the
mac computer can run the application word so this virus works on
Mac operating system computers.
virus samples:

W97M-variant, for example W97M.Panther
  1234 bytes long,
  akanmenginfeksi normal.dot and infect the document when opened.
-WM.Twno.A; TW
  41 984 bytes long,
  Ms.Word document will infect that use macro languages​​, usually
  DOT and the extension *. DOC *.
, etc.

2.Virus Boot Sector
Boot sector viruses is very common in doubles this menyebar.Virus
he will move or replace the original boot sector with the program
boot virus. Thus, whenever booting the virus will be loaded kememori
and then the virus will have the ability to control the hardware standard
(ex:: monitor, printer, etc.) and from this memory is also the virus will spread
eseluruh existing drives and connect kekomputer (ex: floppy, another drive
other than drive c).
virus samples:


Wyx virus-variant
 
ex: wyx.C (B) infects the boot record and floppy;
 
length: 520 bytes;
 
characteristics: memory resident and encrypted)-Variant of the V-sign:
 
infect: Master boot record;
 
520 bytes long;
 
characteristics: living in the memory (memory resident), encrypted, and polymorphic)4th-Stoned.june / bloody!:
 
infect: Master boot record and floppy;
 
520 bytes long;
 
characteristics: living in the memory (memory resident), encrypted and display
 
message "Bloody! june 4th 1989 after the computer is booting 128 times
3.Stealth VirusThis virus will master table at the DOS interrupt table that often we knowwith "Interrupt interceptor". this virus is capable to controlDOS level instruction and the instruction they usually hidden as its nameeither full or size.virus samples:-Yankee.XPEH.4928,
 
infect files *. COM and *. EXE;
 
4298 bytes long;
 
characteristics: living in memory, ukurantersembunyi, has a trigger-WXYC (which includes any category because the boot record into stealth kategri
 
Also included here), an infected floppy motherboot record;
 
520 bytes long;
 
living in the memory; size and hidden viruses.-Vmem (s):
 
infect files *. EXE, *. SYS and *. COM;
 
fie 3275 bytes long;
 
characteristics: living in memory, the size of the hidden, is encrypted., Etc.
4.Polymorphic VirusThe virus is designed to make misleading antivirus program, meaning the virus is alwaystrying to avoid being recognized by antivirus software is always changing the way foxstructure after each infected files / programs.
virus samples:
-Necropolis A / B,
 
infect files *. EXE and *. COM;
 
files 1963 bytes long;
 
characteristics: living in memory, the size and viruses hidden, encrypted and
 
can be changed to change the structure-Nightfall,
 
infect files *. EXE;
 
files 4554 bytes long;
 
characteristics: living in memory, the size and hidden viruses, has a trigger,
 
terenkripsidan can change the structure, Etc.

5.Virus File / ProgramThis virus infects an executable file directly from the operating system,whether the application configuration file (*. EXE), or *. com is usually also the result of infectionof this virus can be identified by changing the size of files that attacked.


Partition 6.Multi VirusThis virus is a combination dariVirus boot sector and file viruses: it meansthe work performed resulted in two, that he can infect files*. EXE file and also infect the Boot Sector.


F. HOW TO SPREAD SOME VIRUS
Viruses as biological viruses must have the media to spread, viruscomputer can control every aspect spread a computer / other machinery as well as through variousways, including:
1.Disket, storage media R / WExternal storage media can be an easy target for the virus tobe the media. Whether as a place to settle or as a distribution media.Media bias operation R / W (read and Write) it is possible tocarrying the virus and serve as media distribution.
2.Jaringan (LAN, WAN, etc.)The relationship between multiple computers directly was possible aviruses follow to move the event of an exchange / execution of files / programswhich contains a virus.
3.WWW (Internet)Very likely a site deliberately induced in a 'virus' that willinfect the computers that access it.
4.Software a Freeware, Shareware or even piracyLots of viruses are deliberately induced in a program that indisseminate good for free, or trial version, which would havevirus embedded in it.
5.Attachment on email, transferring filesAlmost all types of virus spread recently using email attachmentsbecause all Internet service users must be using email tocommunicate, these files are deliberately striking / attract attention, evenoften have a double extension on the file naming.

G. PENANGULANGANNYA
1.Langkah-Step to PreventionFor prevention you can do some of the following steps:o Use Antivirus you trust with the latest updatean, tdak
  
appun care about brand as long as it is always updated, and turn the Auto protecto Always scan all external storage media that will be used,
  
maybe this is a bit inconvenient but if your anti-virus Autoprotect
  
working then this procedure can be skipped.o If you are connected directly to the Internet try to combine
  
Your antivirus with Firewall, Anti-spamming, etc.


Once-Lagkah 2.Langkah Infected
o Detection and determine roughly where the source of the virus if the diskette,
  
network, email etc., if you connect to your network so it's good
  
isolate your computer first (either by unplugging the cable or disable
  
from the control panel)o Identify and classify what type of virus that attacks your pc,
  
by:
  
- Symptoms that arise, for example: messages, files are corrupted or missing, etc.
  
- Scan with your antivirus, if you hit when walking Autoprotect
    
vius definition in the computer means you do not have data of this virus,
    
try to update manually or download a virus definitionnya for
    
you install. If the virus is blocking your efforts to update it
    
then, try to use other media (computer) with antivirus
    
Latest updatean.o Clean, after you've managed to detect and recognize it then try
  
immediately to seek removal or the means to destroy it on site
  
-Site that provides information on virus growth. This is when antivirus
  
latest updates of you do not succeed destroy it.o Step worst, if all the above does not work is the format
  
reset your computer.
CLOSING
Hopefully the discussion about this virus can provide benefits in particularfor writers who are studying and for all of us generally, writingis intended to merely learning so it is expected criticismand suggestions. If the many flaws in this article please understandable.

These steps eliminate computer viruses

In recent years many emerging viruses that began to bother the community of computer users. If the first Internet users are confused by the virus because of its spread is still limited by email and network. As the technological development of mobile devices is also developing information technology. Today almost every computer user must have the flash disk data storage media which is highly portable and easy to use because of its nature, such as floppy disks but with large capacity and not easily damaged. But the popularity of flash disk on computer users lure makers virus to create a virus that spreads through these storage media. This makes the users who do not understand computers are sometimes fooled by a virus that thinks running is another file as a Microsoft Word document files, folders, or other file formats. In fact that is being opened is a virus program that has the same icon with these files.
No need to discuss too long the history of the emergence of this virus, but for users who have been hit by a virus then the actual eradication of the virus-virus measures are almost the same. Usually the general public who do not have internet access on her computer more susceptible to viruses because the antivirus is not up to date so that his antivirus does not recognize new viruses. There are several ways to remove viruses from your computer if already infected with this virus. The following techniques are discussed in the Windows XP operating system because the OS is the most common infection and most widely used. Here is the technique of these techniques:Removing the antivirus on another computer
By releasing a computer hard drive that has been infected with viruses and then loaded onto other computers that have the latest antivirus or at least be able to identify the virus in an infected system. Make a full scan of the hard drives of infected systems and remove any viruses found. After finishing the hard drive has been mounted back to computer and run the system as usual. Do check back to see if the computer is still showing the same symptoms when exposed to the virus. This method is powerful to clean the virus throughout the antivirus on another computer that can identify and remove viruses on the hard drive is infected. But the virus still leaves traces in the form or the startup autorun is not functioning. This trail is sometimes raises an error message that is not dangerous but may be a bit annoying.


Removing with other operating systems
On a laptop or computer that is not removable hard drive then the other way is to run other operating systems that are not infected with the virus and do a full scan of your entire hard drive. Usually there is beberpa users who use dual OS such as Linux and Windows or Windows XP and Windows Vista, etc.. Besides it can also use the LiveCD or OS Portable like Knoopix and Windows PE (Windows which has diminimazed and boots from portable storage media such as flash disk or CD.) And then do a full scan with current antivirus. Effective the same as deleting the virus with antivirus on another computer example above. Viruses sometimes still leaving a trail is not dangerous.Removing manually
If you have trouble doing the above still no other way is by manually. These steps are:

   
1. Shut down process run by the virus. Active virus must have a process running on the system. This process usually monitor the activities of the system and perform actions when certain events occur which identified the virus. For example when we install the flash disk, the process will recognize the virus and infect the action flash disk with the same virus. This process should be viewed from the task manager which can be activated with the Ctrl + Alt + Del, but sometimes the virus will block this action by doing a log off, close the Task Manager window, or restart the system. Another way is to use other tools to see and kill the virus. I used to use Process Explorer from http://www.sysinternals.com/. With this tool you can turn off the process which is considered a virus. At the time of the deadly virus belonging to note sometimes the process of the virus consists of more than a process of mutual monitoring. When a process is turned off then the process it will be turned on again by another process. Because of that deadly virus must rapidly process before the process is turned off again by another process. Identify the processes that are considered first and then turn off all virus quickly. Usually the windows process resembling a virus disguised but certainly no different as a mimic IExplorer.exe Explorer.exe. Here are the windows that can be used as reference processes that are categorized safe:

 
C: \ WINDOWS \ system32 \ smss.exeC: \ WINDOWS \ system32 \ csrss.exeC: \ WINDOWS \ system32 \ winlogon.exeC: \ WINDOWS \ system32 \ services.exeC: \ WINDOWS \ system32 \ svchost.exeC: \ WINDOWS \ system32 \ lsass.exeC: \ WINDOWS \ Explorer.exe
In addition to process explorer you can use other tools that may be easier and could erase process as well. Another example is HijackFree. You can search on google tools similar.# After the deadly virus managed to do the default return value parameter system used virus to activate itself and block efforts to remove him. The parameters are located in the windows registry that can be reset to default values. Save the following file with any name with the file extension. Reg. Then execute the file by clicking 2 times. If there is confirmation you can answer Yes / Ok. The following registry file:  


Windows Registry Editor Version 5.00:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000000
"SuperHidden"=dword:00000000
"ShowSuperHidden"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]
"AlternateShell"="Cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot]
"AlternateShell"="Cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="Cmd.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"
"Userinit"="C:\WINDOWS\system32\userinit.exe,"

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\scrfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\piffile\shell\open\command]
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\comfile\shell\open\command]
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile\shell\open\command
@="\"%1\" %*"

   2.  The above registry file will unblock regedit, and prevent the virus transplanting himself to the system, and reset other parameters to prevent the virus from the road again.
   
3. Once the virus is turned off and reset the system parameters. Prevent the virus active again by removing the autorun virus entry and startup of Windows. Can use the default Windows Msconfig tool or directly edit the registry with regedit. To more easily use third party tools like autoruns from http://www.sysinternals.com to delete autorun entry and startup of the virus tsb. Do not forget to check the Startup folder on the Start menu Menu -> Programs -> Startup and make sure no virus entry page.
   
4. Download the latest antivirus and do a full antivirus scan on the system for checking the whole system and remove all viruses found. I suggest avira which can be downloaded from http://www.free-av.com because it is free and the same virus scanner tough with commercial antivirus like Symantec or Kaspersky.
   
5. Before restarting make sure you do not miss either of proces virus or autorun and system startup. Because if not, upon restarting the system will go back like when infected with the virus and in vain all the steps you did before.
   
6. After restarting your computer check back and see if the symptoms appear when the computer is infected is still there or not. If there then you missed beberpa autorun virus or reset the system parameters above does not work. Perform the steps above and check more carefully every step before you restart the system.
That's the virus removal steps on Windows XP systems. To prevent the virus from coming back you should be diligent to update antivirus or install applications such as WinPooch prevention or Comodo Firewall will warn users when there are other programs that will modify the system. So even though the virus is not recognized but before entering the user will be warned by the application of prevention. If you recognize the programs that want to access your system then you can allow such access, but if not should be rejected and blocked access because there is a possibility the program is a virus.
Be cautious when opening flash disk. Do not open the flash disk with a click 2 times. Open with a right click and select the Open menu for autoplay feature on the flash disk can not run a virus ototmatis. Do not forget to note the files that you open. Although iconnya same note that the files that you open open the application or program type. Make sure the word file is the word really and truly a folder with a folder can view the details or properties of the file. Hopefully this article helps you become infected and prevent computer viruses.

VIRUS CLEANING TECHNIQUE "BLUE FANTASY"

I. Brief of "Blue Fantasy"

Maybe you've heard before or even been a user of the computer who are victims of malignancy virus or My My Rose Lorenz. The virus is better known as KillAV in Indonesian language is anti-virus killer. Well, recently has emerged virus symptom similar to KillAV, except that this virus is not installed in order to block all the existing anti-virus. Actually, when examined again, this virus is not too dangerous because he did not do destruction on windows system. But we made enough to make my nerves.


II. The characteristics of this virus and How it Works

Lunge kick from this virus are basically the same as other viruses which mostly based on Visual Basic programming language. By creating a duplicate folder and hide the original folder either from our data, as well as supporting folders other windows. It is very spit us, because when we open the duplicate folders created by the virus, then we might as well help to broaden the spread of the virus itself. Please note the virus blue fantasy (there is also a call virus breakup) will create a folder with the same name as the original folder which he hid. How do we know if we only duplicate folders? that is the way to see the attributes of the folder. Choose a view on the toolbar menu and then select details. From here you can see that all folders in the window the same size, namely 40 Kb with the extension scr.
Another feature of this virus is to always display the message (message box) when you first logon windows that contain the word "Surabaya in Happy Birthday. (Do not kill me, I'm just send message from your computer. Thank you for menamaniku although only moment, but to me very significant.'m sorry if happiness is all I ask is a friend along hidupku.Seharusnya I understand that my existence is not disismu, just a reverie in regret. For that is not my lover I've ever had 3r1k1m0) "


This virus spreads very fast through your storage media, such as floppy disks or USB flash. So be careful when you work on computers that are infected with this virus. Once the flash is connected, then we can be sure your flash is infected. Why? one of the characteristics of the virus in general is to be as smart as possible to spread from one computer to another. This is the basis of why they should automatically direct spread to flash or floppy disk without having you to click though. If the virus has been entered into the windows system, then he will run the program from its parent files automatically without we can see and realize before. With skill-doer virus, the master file is put himself in the location where we rarely open. Examples of viral Blue Fantasy parent file pathname found in the location C: \ Documents and settings \ Alluser \ STARTMENU \ Adobe online.com and Adobe Update.com. The two files are hidden so it can not dilihat.Biasanya to display hidden files or folders, we always use the option Folder Options and then Show hidden files. But do not be excited because this virus also disable the option.


III. How Extermination

Noteworthy in the process of cleaning this virus is as follows:

1. Decide first of all access networks connected to infected computers both local network (LAN) or internet.


2. Turn off system restore option windows by clicking on Start-Allprogram-Accessories-System Tools-System Restore.

3. Try cleaning done in Safe Mode (this option only to process a virus scan using the anti-virus up to date)

After that you can begin to stop the service or the hidden virus program first. Because even if you've managed to find the master files from this virus, you will not be able to delete the file because windows will reject any exe files that are working to be removed.

How to stop it is to use an additional tool in the form of task manager (the default Windows task manager can not recognize this service and even viruses can also be blocked)

But do not worry because there are tools that can overcome this problem, an example program or CProcess Security Task Manager. We suggest you use CProcess because this software can also stop the service that are stored in memory though.


 Once you have successfully downloaded, do the installation. When finished, you try to run it. On the list of process list, you can see some program or service that is active. Stop (Kill) the Adobe Online and Adobe Update. After that, close the program.

Next is the process of identification of the virus file and folder duplicate results by using the menu on the Start menu Searching windows by setting the All files and folders, type: *. com *. scr, setting the size of the file select at most to the size of 41 Kb, the more advanced settings check the box hidden files and folders, and click search ...

In the search results there are the folders size 40 Kb with the extension *. scr.Adobe Online.com, Adobe Update.com, Thumbs. db danThumbs.com, Delete files and folders are blocked by the right-click-delete. Do not forget to also empty the recycle bin it.


Then search also searches the autorun.inf file with the settings like diatas.Hapus file located at C: \, D: \, E: \ etc..

Well, after you perform the above steps, it's time to restore the registry settings in windows that randomly by the virus ini.Agar quickly without having you sort out the registry setting anywhere in the defective virus, copy the script below and save it with the name of repair. inf. How to use it is to the right on repair.inf mengkilk and select "install ".


The script is as follows:  

[Version]
Signature="$Chicago$"
Provider=PCNUSANTARA
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0
HKLM, SOFTWARE\Classes\scrfile,,,"Screen Saver"
[del]
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeCaption
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeText
HKLM, SOFTWARE\Classes\scrfile, InfoTip
HKLM, SOFTWARE\Classes\scrfile, NeverShowExt
HKLM, SOFTWARE\Classes\scrfile, TileInfo
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

To ensure the persistence of the virus or not, you can perform the scan with the latest anti-virus updates, for example: AVG, Norman, etc.. For AVG Anti-virus updates as of March 31, 2007 was able to identify this virus. Remember, try the scan is done in Safe Mode by restarting your computer then before booting tap the F8 key on the keyboard (not all products or notebook PC supports this way, but most of the same)

Then how do you restore the folders are hidden. Easy, by way of calling a command prompt via the Start menu-Run-and type "cmd" and then enter.Setelah command prompt window open, move the cursor at the location of "drive": \>. "Drive" means that the drive letter where your data folder berlokasi.Setelah it type the command "attrib-s-h / s / d" then enter.Tunggu to appear "drive": \> lagi.Sekarang try to check the folders in windows explorer.

Good luck ...
 
 

Popular Posts