This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Sunday, April 19, 2009

Top 10 Virus on January 2009

Here are the top 10 Virus/Trojan on January 2008

1. Windx-Maxtrox

Display your desktop wallpaper after modified by the virus Windx-Maxtrox.Virus created with Visual Basic has a body the size of the original around 77Kb, without in-pack. The virus is suspected to originate from the strong North Sulawesi has an executable file infection capabilities. Precisely, it will infected program in the Program Files directory. Technical infection canny enough to avoid implementing it detection heuristic antivirus engine. Characteristics that can be recognized on the infected computer is changing the image of the desktop wallpaper images into animation.

2. Autoit variants

Most variants use Autoit folder icon in the typical virus impersonation.Ciri this one is made using a scripting automation. That if the compile into a executable file, which is also in-pack using UPX. And nearly 90% of all viruses and their variants autoit that we have, using similar folder icon in impersonation. This virus will also create an autorun.inf file at the time of the disk drive or flash drive.

3. Malingsi

The virus attacks the other virus Malingsi fat.Virus well with the size of 705,312 bytes is created using Visual Basic in the pack-use PECompact. It seems this virus is intended to attack another virus, this is seen from the message in the body. This virus breed and spread using intermediaries Personalization, which acts as a bot.

4. Recycler variants

File viruses hiding behind the false Recycle .Whom become typical of this virus is a technique, how it spread. Of all the variants that we have, how that is done the same, namely masquerade as Recycle Bin. For example the virus attacks the flash disk. In the flash disk of the victim will be the folder with the name of Recycler in which there is a folder using the name of alpha numeric example “S-1-5-21-1482476501-1644491937-682003330-1013″ with the icon is similar to the Recycle Bin icon. If this folder, click on or accessed from the Explorer, the file the virus will not be visible. To view them, you can go to command prompt with the command “dir / a”.

5. Fdshield

The name used by Fdshield time spread.Virus made using Delphi language using this icon that resembles the Internet Explorer. Has a file size of 553,472 bytes, without in-pack. One thing the light of this virus is of the name used when spread, labeled “17 + + & Confidential Sexs Women artists Indonesia (foto2_kamera tersembunyi_liputan). Exe”. For users who do not careful - careful, will take the file is an HTML file. If you see in the directory C: \ Windows \ System32, the mother found a file with the name “rundl32.exe”. Do not be deceived again! That is not part of the Windows files, but it really is a file virus. Note the letter “L” is just one. And now see in the Schedule Task, have a new job with the name “Windows FD Shield” which will execute the virus file at the time that he has set.

6. Purwo variant

Message delivered creator.One more new variants, Purwo.C, still created using Visual Basic, with the body size of about 56KB, without the pure-pack. This virus uses Word document icon similar property MsOffice to deceive potential victims. When he infected create a folder with the name “Purwokerto Under Cover” of the hidden attributes, and contain a file called “KoruptorPurwokerto.exe” on each drive that he find. In the folder C: \ Windows \ System32 \ file system also have windowss.exe, and in the C: \ Windows \ javaa \ service.exe. At the time it will show a black screen that contains the text of the message from the author. And be careful, this virus will also remove some of the files belong to you that he met.

7.Formalin

File properties Formalin.Icon virus that is used by this virus resembles the withdrawal folder, and it is created using Visual Basic. On Formalin.D, the file size of 18,432 bytes, with the condition of the pack using UPX. The virus creates a folder “disguise” with names such as seepage problems UAN and UAS, My Completed Downloads, Picture Wallpaper, Crack Program, don’t opened !,Ensurt Data (dont’ removed), and others. At the infected computer, Internet Explorer in the caption will be changed to “Your computer has been infected Formalin virus.” He also tries to disable “safe-mode” with how to remove some registry related. And in the file properties of the virus, the property description in the version information will have any posts such as “Kasian dch loe”.

8. Raider.vbs variant

Raider habits virus body has up-to-encryption.Virus if this type of VBScript, its file opened with Notepad, not a lot of strings that can be read as in most encryption. This has become a habit in every variant. Typically, the Registry, it will provide a key to making the new HKLM \ Software with the same name as the name on the computer name, with its contents as a string value is the name of the virus, Raider, and the date the first time the computer is infected.

9. Autorunme variant

Virus Autorunme hide the Recycle Bin folder that is not a production dibuatnya.Virus local programmers use this pack PECompact. He does not have the icon, only the icon from the standard Windows applications. infected time, he tried to embed the file on the parent directory C: \ Windows \ System with the name and msvc32s.exe with hidden and system attributes, and create new autorun in registry with the name “Windows msvc Control Centers.” The virus can spread through the data storage media such as flash disks can also be spread through Instant Messaging application. In the flash disk, it will make the Recycle Bin folder imitation that contains files with the name autorunme.exe, and direct autorun.inf file to run the virus. So when a user plug and play their flash disk drive and access is, the virus will be active.

10. Rieysha variant

Sma-Virus Found Rieysha variants of Rieysha again, this time with the name Rieysha-high school. Like previous variants, it is still possible to use Visual Basic. This time around the size of 104KB, with the icon that resembles a file Real Media Player. Menginfeksi time, it will create a duplicate file exe, mp3, doc, and replaced with a 3gp himself. In addition, there are at least 2 pieces of virus files on the root drive, with the name “sma3gp.exe” and “CeritaSeru.vbs”.

Source: bibeh.com

Wednesday, March 11, 2009

Skype Trojan poses as the real McCoy to steal your password

A new password-stealing Trojan that targets Skype has been spotted in the wild. It poses as a security plug-in for the popular VoIP service but instead presents its own log-in screen to steal your user name and password.

The Trojan calls itself “Skype-Defender,” and other than attempting to steal your Skype user name and password, it also swipes clean all user names and passwords saved in Internet Explorer.

More information at: http://blogs.techrepublic.com.com/tech-news/?p=1418

Tuesday, March 3, 2009

Tigger.A: Sophisticated trojan that likes stockbrokers

Tigger.A: Sophisticated trojan that likes stockbrokers
Customers and employees of firms that trade stocks and options beware, the Tigger.
A trojan is targeting you. Tigger/Syzor is one of the most sophisticated pieces of malware that exists today.
“The trojan uses a privilege escalation vulnerability (MS08-066), which is almost an exact replica of the public exploit on Milw0rm. It disables Windows Defender, Windows Firewall, Outpost, Avira, Kaspersky, AVG, and CA products in unique ways such as posting malformed messages to windows owned by the daemon processes, sending special byte codes over named pipes, and using the products’ own API.”

“It installs a rootkit that runs in safe mode. The rootkit disables kernel debuggers, hooks FAT and NTFS file system drivers, and also prevents other processes from accessing the kernel driver’s memory so tools like GMER and IceSword can’t recover the .sys from RAM.

Tigger of course also injects code into user-mode processes. This component takes screen shots, hooks COM for spying on browser events, and exports passwords (protected storage, network and dial-up, and at least 11 popular chat, email, and remote access applications). It also steals web cookies, steals certificates, and puts the NIC in promiscuous mode to sniff FTP and POP3 passwords.”


More information on http://blogs.techrepublic.com.com/security/?p=960

Sunday, March 1, 2009

Trojan Horse

The original trojan horse was built by Odysseus, the King of Ithica, during the legendary Trojan Wars. The Greeks were losing the siege of the city of Troy. Odysseus had a large wooden horse built and left as a "gift" outside the walls of the city of Troy. He then ordered the Greek army to sail away.

The Trojans believed the horse to be a peace offering from Odysseus. Instead, the horse was filled with Greek warriors, including Odysseus and Menelaus. As the Trojans slept, the Greek army sailed back to Troy and the soldiers hiding in the wooden horse snuck out and opened the gates of the city for them.

The Computer Trojan Horse

A computer trojan horse is a program which appears to be something good, but actually conceals something bad.

One way to spread a trojan horse is to hide it inside a distribution of normal software. In 2002, the sendmail and OpenSSH packages were both used to hide trojan horses. This was done by an attacker who broke into the distribution sites for these software packages and replaced the original distributions with his own packages.

A more common method of spreading a trojan horse is to send it via e-mail. The attacker will send the victim an e-mail with an attachment called something like "prettygirls.exe." When the victim opens the attachment to see the pretty girls, the trojan horse will infect his system.

A similar technique for spreading trojan horses is to send files to unsuspecting users over chat systems like IRC, AIM, ICQ, MSN, or Yahoo Messenger.

The Trojan Horses Virus

Unlike viruses, trojan horses do not normally spread themselves. Trojan horses must be spread by other mechanisms.
A trojan horse virus is a virus which spreads by fooling an unsuspecting user into executing it.

An example of a trojan horse virus would be a virus which required a user to open an e-mail attachment in Microsoft Outlook to activate. Once activated, the trojan horse virus would send copies of itself to people in the Microsoft Outlook address book.
The trojan horse virus infects like a trojan horse, but spreads like a virus.

Effects of a Trojan Horse

The victim running the trojan horse will usually give the attacker some degree of control over the victim's machine. This control may allow the attacker to remotely access the victim's machine, or to run commands with all of the victim's privileges.

The trojan horse could make the victim's machine part of a Distributed Denial of Service (DDoS) network, where the victims machine is used to attack other victims.

Alternatively, the trojan horse could just send data to the attacker. Data commonly targeted by trojan horses includes usernames and passwords, but a sophisticated trojan horse could also be programmed to look for items such as credit card numbers.

Protecting Against a Trojan Horse

Anti-virus programs detect known trojan horses. However, trojan horse programs are easier to create than viruses and many are created in small volumes. These trojan horse programs will not be detected by anti-virus software.

The best defense against a trojan horse is to never run a program that is sent to you. E-mail and chat systems are not safe methods of software distribution.

Spyware and adware

Many people consider spyware and adware to be forms of a trojan horse.
Spyware programs perform a useful function, and also install a program that monitors usage of the victim's computer for the purpose of marketing to the user.

Adware programs are similiar to spyware programs, except the additional software they install shows advertising messages directly to the user.