Blur Store - The Best Gadget Store

Online shopping from the earth's biggest selection of gadget and just about anything else.

All of cool stuff will be there, so enjoyed bro..

Powered by Blogger.

Popular

Blogger templates

Counter Powered by  RedCounter
powered by PRBbutton

Blogger news

below ad

Cool search

translate

About

Photobucket

Virus Windows Media Player Making Computers' sigh '



Golden Ghost virus or virus that is W32/Agent.GYMR fraudulent and sigh, and then access playboy.com. Following characteristics of viruses is:



1. The emergence of an error message "16 bit MS-DOS Subsystem" when the computer switched on.
Golden Ghost

2. Changing the name of the owner and the name of the organization into the computer:

* RegisteredOrganization = GoldenGhost.Inc
* RegisteredOwner = GoldenGhost

Golden Ghost

3. Adding a string GoldenGhost -= =- Was Here on the file C: Boot.ini so at the time of booting a Windows menu will appear with the name of additional GoldenGhost Was Here =-

Golden Ghost

The virus is made using the program language Visual Basic and compressed using UPX, the size of this virus is quite large around 1.312 KB. To trick the user it will use the icon "Windows media player."
At the time of the file in the virus run it will create some files that will be run by parent every time the computer is turned on / restart in the following locations:
• C: Windows folder%%% file%. Exe (random)
• C: folder Windowssystem32%%% file%. Exe (random)

Here are some of the file name that will be in a (random)
• devil.ocx
• pluto.ocx
• capiw.exe
• dusiw.exe
• gexuw.exe
• GoldenGhost.exe
• mamuv.exe
• ridec.exe
• msvbvm60.dll
• heluh.exe
• muxim.exe
• quniw.exe
• gutum.exe
• helef.exe
• kabuh.exe
• mideg.exe
• tixec.exe
• vuvey.exe

So that the file can be run automatically, it will create a string in the registry below:
• HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCur rentVersionrun
o GoldenGhost = C:% SystemRoot%%%% File Folder%. exe or C:% windir% folder%%% Files. exe
• HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
o Shell = Explorer.exe C:% SystemRoot%%%% File Folder%. exe or C:% windir% folder%%% Files. exe

To defend himself virus akan windows to block some functions such as:
• Disable function "paste"
• Disable run
• Disable Searh
• Disable FolderOptions
• Disable Recent Documents menu
• Right-click Disble
• Disable CMD
• Disable RegistryTools
• Disable TaskMgr
• Not able to display the hidden files

To do this it will create a string in the registry below:
• HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurr entVersionExplorerAdvanced
o Hidden = 2
o HideFileExt = 1
o ShowSuperHidden = 0
• HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentV ersionPolicies
o = NoClose Explorer
• HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentV ersionPoliciesexplorer
• NoFInd
o NoFOlderOption
o NoRecentDocsMenu
o NoRUn
o NoSaveSettings
o NoSetFolders
o NoTrayContextMenu
o NoViewContextMenu
• HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentV ersionPoliciesSystem
o DisableCMD
o DisableRegistryTools
o DisableTaskMgr
• HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderHidden
type o = --
o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderHideFileExt
type o = --
o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderSuperHidden
type o = --

This virus will also create a string in the registry below:
HKEY_LOCAL_MACHINESOFTWAREGoldenGhost.A
- AppAll = tupin.exe (random)
- AppMirc = heluh.exe (random)
- AppOther = quniw.exe (random)
- AppSetan = gutum.exe (random)
- AppUtama = muxim.exe (random)
- Location = C: WINDOWSSystem32config (random)

In addition to the function block on Windows, it will also be trying to block security tools such as proceexp, curr preoces, pocket killbox, security task manager and other tools. Besides changing the name of the owner of Windows, it will also change the primary address into Internet Explorer with http://www.playboy.com/ first create a string in the registry below:

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
- Start Page = http://www.playboy.com/

Hosts file windows also do not escape from the attack of this virus manghapus with the contents of the file "C: WindowsSystem32Driversetchost", then add string @ echo off on the file "C: autoexec.bat", then add the string "-= =- GoldenGhost Was Here" on the file "C: boot.ini" so that every time the computer booting a menu will appear with the name GoldenGhost =- Was Here, and if this menu is selected then the computer will restart.

This virus will also alter the results copy and paste the text into notepad desahan, with display text "Oohhh ... Aughhhh ... yess ... babbby ...!!" each time the user copy and paste the contents of text files. In addition to creating a duplicate file, the virus will also try to inject a file that has the extension EXE, the size of the file that was successful in this injection will be approximately 1312 KB of size at first, so if the user runs the file it will automatically run itself. Each time the computer is switched virus akan bring the message "error 16 bit MS-DOS Subsystem" error message will also appear how many minutes each time in accordance with the specified file and create a duplicate (random) in the directory "C: Windows", which was then file that is created will be removed again.

Golden Ghost

Golden Ghost

Here are some messages to be sent:
• nick, indonesia free sex picture double click on the url
• nick have ne new info Marshanda, Agnes Monica, Dian Sastro, Dah Bunga.C Which Bugil, liat Fotonya To double-click the url
• artis indonesia nude, double click on the url
• nick, indo artist magazine playboy double click on the url
• nick mo liat artis indo playboy magazine
• nick indonesia free porn, double click on the url
• ce indo nation, double click
W32/Agent.GYMR this virus will also use the flash disk as a medium itself with the spread of duplicates to create a file with the characteristics:
o Windows Media Player Icon
o Size 1312 KB
o Extension EXE
o File Type "Application"

Overcoming Virus Windows Media Player


As dikabarkan some time ago about the virus that can make computer 'sigh'. To remove this virus on the flash disk can begin to identify and remove files with the extension *. mov, *. wmv, *. 3gp, *. avi, *. mpg, *. mpeg.

Meanwhile, to clean the virus or the golden ghost W32/Agent.GYMR on how hard you can do the following:

To speed up the process of removal of the virus using tools "Ice Sword" (http://www.4shared.com/file/62289467/cf8da562/Ice_Swor d_v122.html? DirPwdVerified = feea1d94). Block the process that has Windows Media Player icon and then right click on the process and click "terminate Process."

Repair registry with a script to copy under this program in Notepad and save it with the name:

"repair.vbs" and run the file.
Dim oWSH: Set oWSH = CreateObject ( "WScript.Shell")
on error resume Next

* WSH.Regwrite "HKEY_LOCAL_MACHINESoftwareCLASSESbatfileshellopen command ","""% 1" "% *"
* WSH.Regwrite "HKEY_LOCAL_MACHINESoftwareCLASSEScomfileshellopen command ","""% 1" "% *"
* WSH.Regwrite "HKEY_LOCAL_MACHINESoftwareCLASSESexefileshellopen command ","""% 1" "% *"
* WSH.Regwrite "HKEY_LOCAL_MACHINESoftwareCLASSESpiffileshellopen command ","""% 1" "% *"
* WSH.Regwrite "HKEY_LOCAL_MACHINESoftwareCLASSESscrfileshellopen command ","""% 1" "/ S"
* WSH.Regwrite "HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSafeB ootAlternateShell", "cmd.exe"
* WSH. Regwrite "HKEY_LOCAL_MACHINESYSTEMControlSet002ControlSafeB ootAlternateShell", "cmd.exe"
* WSH. Regwrite "HKEY_LOCAL_MACHINESYSTEMControlSet003ControlSafeB ootAlternateShell", "cmd.exe"
* WSH. Regwrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlS afeBootAlternateShell", "cmd.exe"
* WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell", "Explorer.exe & quot;
* WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonsystem", ""
*
  • WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionRegisteredOrganization", "Your Organization" WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionRegisteredOwner", "YourOwner & q uot;
    * WSH.Regwrite "HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMainStart Page", "about: Blank"
    * WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderHiddentype", "Gro up"
    * WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderHideFileExttype", & quo t; checkbox "
    * WSH.Regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderSuperHiddentype", & quo t; checkbox "
    * WSH.RegDelete ( "HKEY_LOCAL _MACHINESoftwareMicrosoftWindowsCurrentVersionRunGolden Ghost")
    * WSH.RegDelete ( "HKEY_CURRENT_U SERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplor er")
    * WSH.RegDelete ( "HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerN oSetFolders")
    * WSH.RegDelete ( "HKEY_CUR RENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies ExplorerNoFolderOptions")
    * WSH.RegDelete (& q uot; HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVer sionPoliciesExplorerNoTrayContextMenu ")
    * WS RegDelete H. ( "HKEY_CURRENT_USERSoftwareMicrosoftWin dowsCurrentVersionPoliciesExplorerNoViewContextMenu & quo t;)
    * WSH.RegDelete ( "HKEY_CURRENT_USERSoftwa reMicrosoftWindowsCurrentVersionPoliciesExplorerNoSaveS ettings")
    * WSH.RegDelete ( "HKEY_CURRENT _USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExpl orerNoRecentDocsMenu")
    WSH.RegDelete * ( "; HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersio nPoliciesExplorerNofind")
    * WSH.RegDelete (& q uot; HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVer sionPoliciesExplorerNoRun ")
    * WSH.RegDelete ( "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentV ersionPoliciesSystemDisableTaskMgr")
    * WSH.R egDelete ( "HKEY_CURRENT_USERSoftwareMicrosoftWindow sCurrentVersionPoliciesSystemDisableCMD")
    * WSH.RegDelete ( "HKEY_CURRENT_USERSoftwareMicrosoftW indowsCurrentVersionPoliciesSystemDisableRegistryTools & quot;)
    * WSH.RegDelete ( "HKEY_LOCAL_MACHINESO FTWAREGoldenGhost.A")


    Delete the file and the parent virus duplicate files by using the search windows to show hidden files. If the folder option and the search has not been shown, then restart / logoff the computer first.

    Once the file is found, delete the file that has the size 1.312 KB. addition, remove the file:
    - Devil.ocx = 1 KB
    - Pluto.ocx = 1 KB
    - GoldenGhost.exe = 1 KB
    Remove the string @ echo off on the file [C: Autoexec.bat]
    Remove string GoldenGhost -= =- Was Here on file [C: boot.ini]
    Restore Host File Windows by using the tools Hoster (http://www.4shared.com/file/62290120/73265114/Host sXpert.html? DirPwdVerified = feea1d94). To merestore windows host file, click the "Restore MS Hosts File" on HosterExpert these tools.

    If you use Norman antivirus / McAfee / Kaspersky should re-install the antivirus and then scan the computer to make sure the computer is completely clean of viruses. Update Norman Security Suite is also able to improve any of the files that diinjeksi by W32/Agent.GYMR.
  • New Virus Variant Koobface attack Facebook and Friendster


    Still remember with Koobface virus that had previously attacked the popular social networking site, Facebook?

    Now comes the latest virus variants Koobface. However, it is surprising that there is a link in Facebook inbox page, which actually leads to the 'misguided'. On the front page looks familiar with YouTube, but false, complete with a fake comment from the 'viewer'. If the link is click, the user will be directed to a page hosting a video that is sent by the same person, who has been sending a message from Facebook earlier. The facts of the sender is not only a name, but also photos from the Facebook profile himself.

    With the click the "Install" it will directly download the setup.exe file is detected as a variant Koobface the latest security company TrendMicro detected as a worm "koobface.az". According blog.trendmicro.com, there have been more than 300 unique IP that has to click setup.exe. IP all the victims will be detected as "html_koobface.ba".

    According to the analyst's view of the engineer TrendMicro, worms koobface.az the first time will find the cookies created by the site Pertemanan as follows:

    * Facebook.com
    * Hi5.com
    * Friendst er.com
    * Myyearbook.com
    * Myspace.com
    * bebo.comtagged.com
    * Netlog.com
    * fubar.comlivejournal.com

    Worm will then connect with the social networking site is using user login detail, obtained from cookies. After that, the new worm variants akan find other friends, who will then send a message containing a link, where the worm copy to be downloaded by users. In addition, the virus will also send information from the infected computer to some server.

    Worm spread via spam on Facebook and MySpace

    The security company Kasperky Lab warned that the virus maker has created a pair of worm used to attack users of the MySpace and Facebook. Two variants have got the latest worm Koobface nickname, using social engineering techniques by using a website as a gateway to the victim computer menginfeksi akan make it part of a botnet network.

    When users with computers that have been infected with the worm to access to his MySpace account, then the variants Koobface akan-A link to the post in the "commentaries of friends" who will direct the user to click to a site that contains malicious programs. While the search for B-Koobface target Facebook users by sending spam messages to any "friends" from Facebook users who have tertulari virus.

    Message with some subject such as "Paris Hilton Tosses Dwarf On The Street" or as "Hello, You must see it! LOL. My friend catched you on hidden cam "and the other. The message is aimed so that the candidate pool to click a link that will take them to the website content that contains video clips that have been in pairs as a noose.

    Potential victims will also receive a message to download the "latest version of Flash Player" but which actually is a file with that name codesetup.exe bring worm Koobface.
    Alexander Gostev, a senior virus from Kaspersky Lab Analyst, said similar attacks could happen in the future. "At the beginning of the year 2008, we predicted that we will see an increase in cybercriminal who exploitation on MySpace, Facebook and a few similar websites, and now we have seen the evidence. I believe this is only the first step is simple, and the virus makers will continue to find the target from this source with the intensity increased, "he said in more.

    Local deracinate Virus Manually

    The various virus attacks the computer - with Microsoft Windows OS, of course - most people will consider how to obtain the latest antivirus and anti-virus specific to a particular local because most antivirus software is not able mendeteksinya. Different way of thinking is very common, I offer alternative solutions to the local membasminya virus manually.

    The virus is a program / application (= series of commands) that is able to reproduce themselves. Most programmers create a virus-virus as a series of commands that penetrate into the command-line commands in other applications. Virus-specific virus even able to sneak into the master boot record or sector specific in the disk with no special protection can be identified as a user file. Unfortunately this job jockey does not apply to most of the local presence of virus is very light and inviting hostility.

    Based on this weak point we can eradicate the virus local manually. There are two general reference in killing the virus manually stop running virus-virus and destroy the virus. Based on these two reference you can develop your own strategy depending on the cases that you face.

    Part I: Stop Running Virus

    To attack the virus is created with Visual Basic (VB) - there most virus made with the local VB - you can stop running with the virus' remove 'msvbvm50.dll and msvbvm60.dll which is in the directory c: windowssystem32 which is a virtual machine's program programs created with VB. The term 'throw away' can be realized in different ways depending on the circumstances or the taste, that is removed (not recommended), moved to another folder, or replaced with another name. Besides, how can be done in different ways depending on the level of virus from using the Windows Explorer, command prompt on Windows emulator (when the virus to disable the Windows Explorer), or have to run in windows mode 'save mode with command prompt only' by pressing F8 on the initial startup to display the windows startup menu. If the virus is still running, the virus is not created with VB and run to the next step you have to use Linux or another OS emulator that is not attached to windows programs.

    Part II: Removing Virus-virus

    To destroy the virus-the virus that you have to do is collect all the files through the application find the entry with the name *. exe, identify the applications which is a virus, and delete them. If the menu has been disabled by a virus, you can memanggilnuya by pressing F3 (far easier than have to edit the registry editor). Sentence to the application as the virus is highly dependent of experience and insting you, because the characteristics-characteristics can vary widely, but which must be a reference that you are looking for things' not as a proper and should be in place 'or hidden impressed. Applications with a Microsoft word Document icon or folder icon can be convicted as the virus directly, but with application icons also should be regular, if you suspect you do not believe anyone had to move there. To reduce the scope, you also need to pay attention to the file size because many viruses that each have the same file size.

    Applications that you have vonis as the virus should be removed immediately with a sift + delete. Previously, make sure all the data you've saved with the document and copy-paste in other places in the virus is not runnig. Good LUCK...

    New Virus Info

    A new virus has been found, and classified by Microsoft as the most damage! New virus is found on Sunday afternoon ago by McAfee, and have not found a vaccine for
    mengalahkannya.

    This destructive virus Sector Zero from the hard disc, a save function of the most important information. The virus is running as follows: The virus will be automatically sent to all names in the address list
    you with the title "A Card For You" (Une carte Pour Vous, atau A Card For You); the virtual card is opened, the virus that will freeze the computer so that users must start again, if you hit CTRL + ALT + DEL or commands to restart, the virus that will damage the Boot Sector Zero from the hard disk, hard disk so that it will be damaged permanently.

    According to CNN, the virus is already in a few hours cause panic in New York. This warning has been received by Microsoft employees themselves. Do not open e-mail with the title "A virtual card for you" (Une carte Virtuelle Pour Vous or A Virtual Card For You).

    "hoax Life is Beautiful", new virus

    Under this is the sound of the e-mail that contains the virus "hoax Life is Beautiful"
    The virus is also possible to send e-mail the same in Spanish, Portuguese, German, and Hungarian.

    It is too late now, your life is no longer beautiful", subsequently you will LOSE EVERYTHING IN YOUR PC and the person who sent it to you will gain access to your name, email and password.
    This is a new virus which started to circulate on Saturday afternoon.

    The antivirus Softs are not capable of destroying it.

    The virus has been created by a hacker who calls himself "life owner", and who aims to destroying domestic PCs and who also fights Microsoft in court! That's why it comes disguised with extension pps. He fights in court for the Windows-XP patent.

    MAKE A COPY OF THIS EMAIL TO ALL YOUR FRIENDS"
    If TERIMA E-MAIL TO THE CONTENTS OF SUCH IN IMMEDIATE Del! AND YOU DO NOT forward TO YOUR FRIENDS!

    News about the latest virus

    A new virus has been found, and classified by Microsoft as the most damage! New virus is found on Sunday afternoon ago by McAfee, and have not found a vaccine for mengalahkannya.

    This destructive virus Sector Zero from the hard disc, a save function of the most important information. The virus is running as follows:

    "H the virus is automatically sent to all akan name in your address list with the title" A Card For You "(Une carte Pour Vous, atau A Card For You);

    "H the virtual card is opened, the virus that will freeze the computer so that users must start again, if you hit CTRL + ALT + DEL to restart or command, the virus that will damage the Boot Sector Zero from the hard disk, hard disk so that it will be permanently damaged .

    According to CNN, the virus is already in a few hours cause panic in New York .. This warning has been received by Microsoft employees themselves.

    Do not open e-mail with the title "A virtual card for you" (Une carte Virtuelle Pour Vous or A Virtual Card For You).

    Send this message to all your friends. I think that most people, like myself, prefer to get a warning this 25 times than not at all.

    CAUTION!

    Do not accept a contact, "pti_bout_de_ chou@hotmail.com". This virus will format your computer. Send this message to all those who are in your address list.

    If you do not do this and one of his friends in the list enter your address, your computer will also be affected.


    URGENTTT !!!!!

    ATTENTION !!!!!

    To a friend - all friends,

    If one day you receive the e-mail with a Powerpoint Presentation titled "Life is beautiful.pps", was opened with a DO NOT for any reason, and delete it immediately. When you open the page file, then you will be on display legible "Now it is too late, your life is nolonger beautiful", then you akan Overall WHETHER LOSS OF DATA, SOFTWARE, PROGRAMS OR ANY like YA NG INSIDE your PC, this jenisvirus and damage the very people who get mengirimkanya akan namaakses, e-mail & password. That was a new type of virus that started on the Saturday night and there is no anti virusnya. The creator of this virus was a hacker who claimed himself as the owner of Life danakan against Microsoft in justice menegakan. Therefore the virus itudatang disguise themselves as pps extension. This news sent me by a friend (software engineering) who is now living in Singapore, Pan PC friends have been infected this virus.

    News about the latest virus

    A new virus has been found, and classified by Microsoft as the most damage! New virus is found on Sunday afternoon ago by McAfee, and have not found a vaccine for mengalahkannya.

    This destructive virus Sector Zero from the hard disc, a save function of the most important information. The virus is running as follows:

    "H the virus is automatically sent to all akan name in your address list with the title" A Card For You "(Une carte Pour Vous, atau A Card For You);

    "H the virtual card is opened, the virus that will freeze the computer so that users must start again, if you hit CTRL + ALT + DEL to restart or command, the virus that will damage the Boot Sector Zero from the hard disk, hard disk so that it will be permanently damaged .

    According to CNN, the virus is already in a few hours cause panic in New York .. This warning has been received by Microsoft employees themselves.

    Do not open e-mail with the title "A virtual card for you" (Une carte Virtuelle Pour Vous or A Virtual Card For You).

    Send this message to all your friends. I think that most people, like myself, prefer to get a warning this 25 times than not at all.

    CAUTION!

    Do not accept a contact, "pti_bout_de_ chou@hotmail.com". This virus will format your computer. Send this message to all those who are in your address list.

    If you do not do this and one of his friends in the list enter your address, your computer will also be affected.


    URGENTTT !!!!!

    ATTENTION !!!!!

    To a friend - all friends,

    If one day you receive the e-mail with a Powerpoint Presentation titled "Life is beautiful.pps", was opened with a DO NOT for any reason, and delete it immediately. When you open the page file, then you will be on display legible "Now it is too late, your life is nolonger beautiful", then you akan Overall WHETHER LOSS OF DATA, SOFTWARE, PROGRAMS OR ANY like YA NG INSIDE your PC, this jenisvirus and damage the very people who get mengirimkanya akan namaakses, e-mail & password. That was a new type of virus that started on the Saturday night and there is no anti virusnya. The creator of this virus was a hacker who claimed himself as the owner of Life danakan against Microsoft in justice menegakan. Therefore the virus itudatang disguise themselves as pps extension. This news sent me by a friend (software engineering) who is now living in Singapore, Pan PC friends have been infected this virus.

    bitdefender antivirus

    bitdefender is not strange with computer user, this one of wonderful antivirus product..
    you can use this antivirus to protect your computer from virus
    this is link taht you can use to download bitdefender antivirus :
    Download BitDefender Free Edition 32 bit <59 MB>
    Download BitDefender Free Edition 64 bit <70 MB>