<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Istanto Blog - Online Business, Short Reviews, Computers and Internet, Tips and Trick, Make Money Online. &#187; Worm</title>
	<atom:link href="http://www.istanto.net/tag/worm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.istanto.net</link>
	<description>Online Business, Short Reviews, Computers and Internet, Tips and Trick, Make Money Online.</description>
	<lastBuildDate>Sun, 08 Jan 2012 02:56:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Remove Worm VBS/Cryf.A, Shemale by CRY</title>
		<link>http://www.istanto.net/remove-worm-vbs-cryf-a-shemale-by-cry.html</link>
		<comments>http://www.istanto.net/remove-worm-vbs-cryf-a-shemale-by-cry.html#comments</comments>
		<pubDate>Sun, 19 Jul 2009 21:37:58 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Tips & Trick]]></category>
		<category><![CDATA[cd-rom]]></category>
		<category><![CDATA[dvd-rom]]></category>
		<category><![CDATA[MSC]]></category>
		<category><![CDATA[OK]]></category>
		<category><![CDATA[remove VBS/Cryf.A]]></category>
		<category><![CDATA[SECPOL]]></category>
		<category><![CDATA[vbs]]></category>
		<category><![CDATA[VBS/Cryf.A]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus remover]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=1248</guid>
		<description><![CDATA[VBS/Cryf.A was created using visual basic scripting (not visual basic), first case happen on my cyber cafe on date 18 July 2009 it spreading from user flash disk and try to infected all PC in my network. I&#8217;m not sure why so much Indonesian virus maker using lot of this  VBS technique (maybe they know [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">VBS/Cryf.A was created using visual basic scripting (not visual basic), first case happen on my cyber cafe on date <span style="text-decoration: underline;">18 July 2009</span> it spreading from user flash disk and try to infected all PC in my network.</p>
<p style="text-align: justify;">I&#8217;m not sure why so much Indonesian virus maker using lot of this  VBS technique (maybe they know without msvbvm.dll VBS can executed on a lot target), Since I write about VBS article long long time ago (I forget maybe around year 2003-2005) in jasakom website with title &#8220;<a href="http://www.google.co.id/#hl=id&amp;q=vbs+sederhana+yang+berbahaya" target="_blank">VBS sederhana yang berbahaya</a>&#8221; many people has try to manipulate that simple code to become advanced code. Now I&#8217;m fell really stupid by share that Article to public&#8230;</p>
<p style="text-align: justify;"><strong><span style="text-decoration: underline;">How to know if you&#8217;re infected by this worm VBS/Cryf.A:</span></strong></p>
<p style="text-align: justify;">1.First time your computer turned on it will open web browser and show this pictures.</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-3.png"><img class="alignnone size-medium wp-image-1250" title="VBS-Cryf.A-3" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-3-300x225.png" alt="VBS-Cryf.A-3" width="300" height="225" /></a></strong></span></span></p>
<p style="text-align: justify;"><span style="font-family: Arial; font-size: x-small;"><span style="font-family: Arial,sans-serif; font-size: x-small;">2. </span></span>VBS/Cryf.A will change your web browser start page become:</p>
<p style="text-align: justify;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-4.png"><img class="alignnone size-medium wp-image-1251" title="VBS-Cryf.A-4" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-4-300x216.png" alt="VBS-Cryf.A-4" width="300" height="216" /></a></strong></p>
<p style="text-align: justify;">3. There is folder &#8220;album bokep&#8221; (in Indonesian language this mean <span style="text-decoration: line-through;">porn</span>) in all folder.</p>
<p style="text-align: justify;">4. VBS/Cryf.A will change your system properties become like this:</p>
<p style="text-align: justify;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-5.png"><img class="alignnone size-medium wp-image-1252" title="VBS-Cryf.A-5" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-5-262x300.png" alt="VBS-Cryf.A-5" width="262" height="300" /></a></strong></p>
<p style="text-align: justify;">5. Change file type .lnk become &#8220;movie clip&#8221;</p>
<p style="text-align: justify;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-6.png"><img class="alignnone size-medium wp-image-1253" title="VBS-Cryf.A-6" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-6-300x42.png" alt="VBS-Cryf.A-6" width="300" height="42" /></a></strong></p>
<p style="text-align: justify;">6. It will control your DVD/CD-rom by make it open and close to make you panic.</p>
<p><span id="more-1248"></span></p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong>VBS/Cryf.A Master file:</strong></span></p>
<p style="text-align: justify;">VBS/Cryf.A has a master file called &#8220;<span style="text-decoration: underline;">drconfig.drv</span>&#8221; with file size 218 KB, it already encrypted and little hard to read the code inside it.</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-8.png"><img class="alignnone size-medium wp-image-1256" title="VBS-Cryf.A-8" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-8-300x74.png" alt="VBS-Cryf.A-8" width="300" height="74" /></a></p>
<p style="text-align: justify;">On first time active it will called &#8220;svchost.vbs&#8221; then this vbs will executed this &#8220;drconfig.drv&#8221;. Then it will started created file list:</p>
<ul>
<li>%Drive%\Recycled\S-1-5-21-343818398-18970151121-842a92511246-500\Thumbs.db
<ul>
<li>svchost.vbs</li>
<li>desktop.ini</li>
<li>drvconfg.drv</li>
<li>SHELL32.dll</li>
</ul>
</li>
<li>%Systemroot%\windows
<ul>
<li>appsys.exe</li>
<li>Winupdt.scx</li>
<li>appopen.scx</li>
<li>Windowsopen.mht</li>
<li>Windows.html</li>
<li>Regedit.exe.lnk</li>
<li>Help.htm</li>
</ul>
</li>
<li>%Systemroot%\Windows\system\svchost.exe</li>
<li>%Systemroot%\WINDOWS\system32
<ul>
<li>Svchost.dls</li>
<li>Corelsetup.scx</li>
<li>Appsys.dls</li>
<li>Kernel32.dls</li>
<li>Taskmgr.exe.lnk</li>
</ul>
</li>
<li>%Systemroot%\WINDOWS\system32\
<ul>
<li>Winupdtsys.exe</li>
<li>ssmarque.scr</li>
</ul>
</li>
<li>%Systemroot%\Program Files\FarStone\qbtask.exe</li>
<li>%Systemroot%\Program Files\ACDsee\Launcher.exe</li>
<li>%Systemroot%\Program Files\Common Files\NeroChkup.exe</li>
<li>%Systemroot%\Program Files\ExeLauncher</li>
<li>%ProgramFiles%\drivers\VGA\VGAdrv.lnk</li>
<li>%Systemroot%\Documents and Settings\%user%\Desktop\Local Disk (C).dls</li>
</ul>
<p><span style="text-decoration: underline;"><strong>This virus will make some action to keep him stay in computers target:</strong></span></p>
<ul>
<li>Disable Task Manager</li>
<li>Disable Regedit</li>
<li>Disable CMD (Command Prompt)</li>
<li>Disable MSConfig</li>
<li>Can&#8217;t change wallpapers</li>
</ul>
<p>It will change your screensaver like this:</p>
<p><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-19.png"><img class="alignnone size-medium wp-image-1259" title="VBS-Cryf.A-19" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-19-300x225.png" alt="VBS-Cryf.A-19" width="300" height="225" /></a></p>
<p><span style="text-decoration: underline;"><strong>Spreading Technique and Social Technique:</strong></span></p>
<p style="text-align: justify;">VBS/Cryf.A spreading using 2 technique, One of them as like in my first Article using autorun.inf files, beside that this virus maker know how to using social technique to tricky mostly people out there using <span style="text-decoration: line-through;">porn</span> movie that actually virus.</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-11.png"><img class="alignnone size-medium wp-image-1260" title="VBS-Cryf.A-11" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-11-300x137.png" alt="VBS-Cryf.A-11" width="300" height="137" /></a></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-12.png"><img class="alignnone size-medium wp-image-1262" title="VBS-Cryf.A-12" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-12-300x149.png" alt="VBS-Cryf.A-12" width="300" height="149" /></a></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-20.png"><img class="alignnone size-medium wp-image-1263" title="VBS-Cryf.A-20" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-20-300x51.png" alt="VBS-Cryf.A-20" width="300" height="51" /></a></p>
<p style="text-align: justify;">This virus maker try to manipulate people with his another social technique, he will try to tell people their computers infected and give the removal tools, actually don&#8217;t open that website (www.dinamikasolusi.co.nr) this virus maker maybe using some technique as I write a long time ago by insert some virus into computer target using html code.</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-9.png"><img class="alignnone size-medium wp-image-1264" title="VBS-Cryf.A-9" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-9-300x158.png" alt="VBS-Cryf.A-9" width="300" height="158" /></a></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-10.png"><img class="alignnone size-medium wp-image-1265" title="VBS-Cryf.A-10" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-10-300x216.png" alt="VBS-Cryf.A-10" width="300" height="216" /></a></p>
<p style="text-align: justify;"><span style="color: #000000;">Enough, let&#8217;s started to remove this stupid Worm VBS/Cryf.A</span></p>
<p style="text-align: justify;"><span style="color: #008000;"><strong><span style="text-decoration: underline;">HOW TO REMOVE WORM VBS/Cryf.A:</span></strong></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">1. Kill active virus process in your background memory using <a href="http://www.nirsoft.net/utils/cprocess.zip" target="_blank">currprocess</a>, then kill all process with product name &#8220;<span style="text-decoration: underline;">Microsoft (r) Windows Script Host</span>&#8220;</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-13.png"><img class="alignnone size-medium wp-image-1266" title="VBS-Cryf.A-13" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-13-300x225.png" alt="VBS-Cryf.A-13" width="300" height="225" /></a></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">2. Block virus so it can not run for a while when we are in cleaning progress by:</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">Start -&gt; Run -&gt; Type &#8220;<strong>SECPOL.MSC</strong>&#8221; -&gt; Click &#8220;software restriction policies&#8221; -&gt; Click &#8220;additional rules&#8221; -&gt; Right click on &#8220;additional rules&#8221; and choose &#8220;New Hash Rules&#8221;</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-14.png"><img class="alignnone size-medium wp-image-1268" title="VBS-Cryf.A-14" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-14-300x239.png" alt="VBS-Cryf.A-14" width="300" height="239" /></a></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">In &#8220;File Hash&#8221; Click on Browse and choose which file you want to block (<strong><span style="text-decoration: underline;">WSScript.exe</span></strong>) on &#8220;Security level&#8221; choose <strong>Disalllowed</strong> then click <strong>OK.</strong></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-15.png"><img class="alignnone size-medium wp-image-1269" title="VBS-Cryf.A-15" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-15-268x300.png" alt="VBS-Cryf.A-15" width="268" height="300" /></a></strong></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">3. Fix registry by using this 3rd tools, download it from <a href="http://www.istanto.net/wp-content/uploads/2009/07/FixRegistry.zip">HERE</a><strong>&#8230;</strong></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-16.png"><img class="alignnone size-medium wp-image-1270" title="VBS-Cryf.A-16" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-16-300x178.png" alt="VBS-Cryf.A-16" width="300" height="178" /></a></strong></span></span></p>
<ul>
<li>Shell Windows = explorer.exe</li>
<li>UserInit Windows
<ul>
<li>Windows NT/2000 = C:\WinNT\System32\userinit.exe,</li>
<li>Windows XP/2003/Vista = C:\Windows\System32\userinit.exe,</li>
</ul>
</li>
</ul>
<p style="text-align: justify;">4. Deleted Virus Master files and all files he&#8217;s created. To help you deleted it in easy way I recommended to use this tools <a href="http://www.explorerxp.com/explorerxpsetup.exe" target="_blank">ExplorerXP</a>, Then deleted all files list bellow:</p>
<ul>
<li>%Drive%\Recycled\S-1-5-21-343818398-18970151121-842a92511246-500\Thumbs.db
<ul>
<li>svchost.vbs</li>
<li>desktop.ini</li>
<li>drvconfg.drv</li>
<li>SHELL32.dll</li>
</ul>
</li>
<li>%Drive%\Album BOKEP\Naughty America</li>
<li>%systemroot%\windows
<ul>
<li>appsys.exe</li>
<li>Winupdt.scx</li>
<li>appopen.scx</li>
<li>Windowsopen.mht</li>
<li>Windows.html</li>
<li>Regedit.exe.lnk</li>
<li>Help.htm</li>
</ul>
</li>
<li>%systemroot%\Windows\system\svchost.exe</li>
<li>%systemroot%\WINDOWS\system32
<ul>
<li>Taskmgr.exe.lnk</li>
<li>CMD.exe.lnk</li>
<li>Svchost.dls</li>
<li>Corelsetup.scx</li>
<li>Appsys.dls</li>
<li>Kernel32.dls</li>
<li>Winupdtsys.exe</li>
<li>ssmarque.scr</li>
</ul>
</li>
<li>%systemroot%\Program Files\FarStone\qbtask.exe</li>
<li>%systemroot%\Program Files\ACDsee\Launcher.exe</li>
<li>%systemroot%\Program Files\Common Files\NeroChkup.exe</li>
<li>%systemroot%\Program Files\ExeLauncher</li>
<li>%ProgramFiles%\drivers\VGA\VGAdrv.lnk</li>
<li>%systemroot%\Documents and Settings\%user%\Desktop\Local Disk (C).dls</li>
<li>%Flash Disk%\Dataku Penting Jangan Dihapus.lnk</li>
</ul>
<p style="text-align: justify;">5. Showing back your files TaskMgr.exe, Regedt32.exe, Regedit.exe, CMD.exe, and Logoff.exe that hidden by virus:</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-21.png"><img class="alignnone size-medium wp-image-1272" title="VBS-Cryf.A-21" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-21-300x146.png" alt="VBS-Cryf.A-21" width="300" height="146" /></a></p>
<p style="text-align: justify;">*repeated on all files you want to shown back.</p>
<p style="text-align: justify;">6. For maximum cleaning I recommended to scan using your best antivirus programs, in my case Norman antivirus can deleted all of this virus part.</p>
<p style="text-align: justify;">7. When all step done and no virus found, deleted blocking rules we made:</p>
<p style="text-align: justify;">Start -&gt; Run -&gt; Type <strong>SECPOL.MSC</strong> -&gt; Click &#8220;Software Restriction Policies&#8221; -&gt; Click &#8220;Additional Rules&#8221; -&gt; Then Deleted Rules we have made.</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-18.png"><img class="alignnone size-medium wp-image-1273" title="VBS-Cryf.A-18" src="http://www.istanto.net/wp-content/uploads/2009/07/VBS-Cryf.A-18-300x181.png" alt="VBS-Cryf.A-18" width="300" height="181" /></a></p>
<p style="text-align: justify;">8. Restart your computer then re-scanned again to make sure there is no left part of worm VBS/Cryf.A<img src="file:///C:/DOCUME%7E1/ANTOPE%7E1/LOCALS%7E1/Temp/moz-screenshot-1.png" alt="" />, then use updated antivirus to prevent it coming back again.</p>
<p style="text-align: justify;">Have a nice day, GBU <img src='http://www.istanto.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/remove-worm-vbs-cryf-a-shemale-by-cry.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Remove Worm Kido</title>
		<link>http://www.istanto.net/remove-worm-kido.html</link>
		<comments>http://www.istanto.net/remove-worm-kido.html#comments</comments>
		<pubDate>Sat, 04 Apr 2009 17:07:43 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Tips & Trick]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=1083</guid>
		<description><![CDATA[Worm kido also known as Conficker or Downadup, on 1st April 2009 there is some rumors out there said this worm will generated new varian. I Personally not hear big problem on that date. Many computers has been infected by this worm because it&#8217;s spreading through network. Kaspersky AntiVirus has free removal tools for this [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Worm kido also known as Conficker or Downadup, on 1st April 2009 there is some rumors out there said this worm will generated new varian. I Personally not hear big problem on that date. Many computers has been infected by this worm because it&#8217;s spreading through network. Kaspersky AntiVirus has free removal tools for this worm.</p>
<p style="text-align: justify;">First before we remove this worm, to prevent it&#8217;s spreading in networks and infected many computers please follow this step.</p>
<ul style="text-align: justify;">
<li>Install Patch from Microsoft for MS08-067, MS08-068, and MS09-001.</li>
<li>Make sure Administrator password not easy to guess.</li>
<li>Turn off autoplay on removable devices.</li>
</ul>
<p><span style="color: #008000;"><span style="text-decoration: underline;"><strong>Follow this step to remove Kido</strong></span></span></p>
<p>1. Download <a href="http://data2.kaspersky.com:8080/special/KKiller_v3.4.3.zip" target="_blank">KKiller_v3.4.3.zip</a>, extract it.</p>
<p style="text-align: justify;">2. Run KKiller.exe program. When scan process completed you might see many command prompt in your desktop, just press any key to close it. If you want to close it automatically please use parameter &#8220;-y&#8221;</p>
<p style="text-align: justify;">3. Wait untill scan process completed, then restart your computer and scan it again with your trusted AntiVirus.</p>
<p style="text-align: justify;">Good Luck <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/remove-worm-kido.html/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Microsoft.lnk Shortcut Virus? Worm:PIF/Starter.A</title>
		<link>http://www.istanto.net/microsoftlnk-shortcut-virus-wormpifstartera.html</link>
		<comments>http://www.istanto.net/microsoftlnk-shortcut-virus-wormpifstartera.html#comments</comments>
		<pubDate>Sat, 28 Feb 2009 04:06:36 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[autorun.inf]]></category>
		<category><![CDATA[lnk virus]]></category>
		<category><![CDATA[Microsoft.lnk]]></category>
		<category><![CDATA[shortcut virus]]></category>
		<category><![CDATA[story]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Worm]]></category>
		<category><![CDATA[Worm:PIF/Starter.A]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=1009</guid>
		<description><![CDATA[Hello everyone sorry for late update this blog, I have been really very busy analyze forex market and grown my another business, busy IRL also&#8230; Now my story&#8230;&#8230;. Last week my cousins tell me in his office he got strange virus. He said there is lot shortcut in desktop an computers running slow. How actually [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Hello everyone sorry for late update this blog, I have been really very busy analyze forex market and grown my another business, busy <strong>IRL</strong> also&#8230; <img src='http://www.istanto.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p style="text-align: justify;"><em> Now my story&#8230;&#8230;.</em></p>
<p style="text-align: justify;">Last week my cousins tell me in his office he got strange virus. He said there is lot shortcut in desktop an computers running slow. How actually some <span style="text-decoration: line-through;">newbie</span> out there know exactly which one real programs/folders and which one shortcut? Don&#8217;t say you&#8217;re not <span style="text-decoration: line-through;">noob</span>! <strong>almost</strong> many people not take to much attention on this simple different, that&#8217;s why with simple social technique virus maker can win beating yourself! <img src='http://www.istanto.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p style="text-align: justify;"><span style="color: #ff0000;"><strong>LOOOOOOOOOOOOKKKKKKKK!!!!!!</strong></span></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/shortcut.jpg"><img class="alignnone size-thumbnail wp-image-1010" title="shortcut" src="http://www.istanto.net/wp-content/uploads/2009/02/shortcut-150x117.jpg" alt="shortcut" width="150" height="117" /></a></p>
<p style="text-align: justify;">To know when your computer infected by this virus there is 4 important point:</p>
<ol style="text-align: justify;">
<li>In your &#8220;<strong>My Documents</strong>&#8221; folder there is file named &#8220;<strong>database.mdb</strong>&#8220;.</li>
<li>There is clone folder with extension <strong>.lnk</strong> maximum 5 first folder arranged by name, rules until second sub folders.</li>
<li>There is files <strong>Autorun.inf</strong>, <strong>Thumb.db</strong>, <strong>Microsoft.lnk</strong> in each root drive and folders, rules until second sub folders. (You might not see them because it&#8217;s set hidden)</li>
<li>Your Registry Editor is disabled.</li>
</ol>
<p style="text-align: justify;">This virus master actually in &#8220;<strong>My Document</strong>&#8221; folder named &#8220;<strong>database.mdb</strong>&#8221; Wait&#8230; you will know why this is called as virus master. Actually virus will created clone for folder using &#8220;wscript.exe&#8221; execution. wscript.exe is microsoft windows based script host programs.</p>
<p><span id="more-1009"></span></p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong>Virus will change your registry</strong></span>:</p>
<p style="text-align: justify;">[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]<br />
&#8220;Explorer&#8221;=&#8221;Wscript.exe //e:VBScript \&#8221;C:\Documents and Settings\Administrator\My Documents\database.mdb\&#8221;"</p>
<p>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]<br />
&#8220;WinUpdate&#8221;=&#8221;Wscript.exe /e:VBScript \&#8221;C:\WINDOWS\:Microsoft Office Update for Windows XP.sys\&#8221;"</p>
<p style="text-align: justify;">I think you all know how this registry changed will affect on your computer each time it reboot no need to explain this right? Really simple social technique.</p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><span style="color: #008000;"><strong>Now time for how to clean this virus manually</strong></span></span>:</p>
<p style="text-align: justify;">1. Disabled &#8220;System Restore&#8221; in cleaning process.</p>
<p style="text-align: justify;">2. Kill wscript.exe process from your computer background programs.</p>
<p style="text-align: justify;">3. In cleaning process you have to rename file wscript.exe to any name  ex:blabla (temporary only in cleaning process) and don&#8217;t forget to rename it back again to wscript.exe once your computer clean.</p>
<p style="text-align: justify;">4. Deleted file &#8220;<strong>database.mdb</strong>&#8221; from &#8220;<strong>My Documents</strong>&#8221; folder.</p>
<p style="text-align: justify;">5. Disabled any <strong>startup process</strong> which has link with &#8220;<strong>database.mdb</strong>&#8221; you can use msconfig or hijackthis.</p>
<p style="text-align: justify;">6. Delete file <strong>autorun.inf,</strong> <strong>microsoft.inf</strong> and <strong>thumb.db</strong> use command prompt and type &#8220;<strong>del Microsoft.inf /s</strong>&#8221; (should in root drive to deleted in all in drive) for autorun.inf  and thumb.db since this file set with attrib RSHA type &#8220;<strong>del autorun.inf /s /ah /f</strong>&#8221; (should in root drive to deleted in all in drive, change autorun.inf with thumb.db to deleted all thumb.db)</p>
<p style="text-align: justify;">7. deleted all .lnk files with size 1kb, you can use advanced search function. Carefully when you want to deleted look on this sample:</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/lnk.gif"><img class="alignnone size-thumbnail wp-image-1013" title="lnk" src="http://www.istanto.net/wp-content/uploads/2009/02/lnk-150x150.gif" alt="lnk" width="150" height="150" /></a></p>
<p style="text-align: justify;">Deleted only shortcut with size 1kb and using folder icon, this is social  virus spreading technique that <strong>mostly</strong> tricky newbie out there.</p>
<p style="text-align: justify;">7. Repair your registry using <a href="http://www.istanto.net/wp-content/uploads/2009/02/repair2.inf">repair.inf</a></p>
<p style="text-align: justify;">[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=Nobody</p>
<p>[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del</p>
<p>[UnhookRegKey]<br />
HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;<br />
HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;<br />
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;</p>
<p>[del]<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate<br />
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer</p>
<p style="text-align: justify;">8. Scan with your best antivirus program to make sure your system clean and restarted your computer. Now see if this virus coming back or not <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p style="text-align: justify;">Good luck <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/microsoftlnk-shortcut-virus-wormpifstartera.html/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>YM and Skype Virus:YouTube Lady_Eats_Her_Shit Worm:Coutsonif.A</title>
		<link>http://www.istanto.net/ym-and-skype-virus-youtube-lady_eats_her_shit.html</link>
		<comments>http://www.istanto.net/ym-and-skype-virus-youtube-lady_eats_her_shit.html#comments</comments>
		<pubDate>Sat, 14 Feb 2009 23:53:43 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Coutsonif.A]]></category>
		<category><![CDATA[Lady_Eats_Her_Shit]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[TMP]]></category>
		<category><![CDATA[TRUSTED]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Worm]]></category>
		<category><![CDATA[Yahoo]]></category>
		<category><![CDATA[yahoo messenger]]></category>
		<category><![CDATA[YM]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=999</guid>
		<description><![CDATA[Last week I got IRC bot virus in my server. I don&#8217;t know the virus name but I cleaned it manually. We&#8217;re not talking about this IRC bot virus cause it really simple cleaned manually using ANSAV UPX tools and Hidden Revealer I cleaned it in within short 1 minutes In this article we will [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Last week I got IRC bot virus in my server. I don&#8217;t know the virus name but I cleaned it manually. We&#8217;re not talking about this IRC bot virus cause it really simple cleaned manually using <a href="http://www.ansav.com/download/" target="_blank">ANSAV</a> <span style="text-decoration: underline;">UPX tools</span> and <span style="text-decoration: underline;">Hidden Revealer</span> I cleaned it in within short 1 minutes <img src='http://www.istanto.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  In this article we will write to clean YM and Skype bot virus Worm:Coutsonif.A</p>
<p style="text-align: justify;">This virus spreading using social technique and autorun.inf, since it using social technique this virus can spreading easy. Did you ever received message from your <span style="text-decoration: underline;"><strong>TRUSTED</strong></span> friend like this sample?</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif.png"><img class="alignnone size-thumbnail wp-image-1001" title="coutsonif" src="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-150x150.png" alt="coutsonif" width="150" height="150" /></a></p>
<p style="text-align: justify;">Listen to me, don&#8217;t so easy clicked any link in email or anything! even it come from trusted source. In this case social technique can make you in danger position, Think if virus collecting your financial information :p</p>
<p style="text-align: justify;">When you download this virus it will making 2 random file in %systemroot%\Documents and Settings\%user%\Local Settings\Temp with extension .tmp and .exe then created <strong>vshost.exe</strong> with size <strong>122kb,</strong> file will available on every drive root.</p>
<p style="text-align: justify;">Virus will also make another files:</p>
<ul>
<li>%systemroot%\autorun.inf [all drive]</li>
<li>%systemroot%\RECYCLER\S-1-5-21-9949614401-9544371273-983011715-7040\winservices.exe</li>
<li>%systemroot%\WINDOWS\system32\sysmgr.exe</li>
<li>%systemroot%\WINDOWS\TEMP\5755.tmp</li>
<li>%systemroot%\windows\system32\crypts.dll</li>
<li>%systemroot%\windows\system32\msvcrt2.dll</li>
</ul>
<p style="text-align: justify;">It wil also change your registry to automatically started when your computers booting. Beside that, old autorun.inf technique also adopted in this virus spreading:</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autorun.png"><img class="alignnone size-thumbnail wp-image-1002" title="coutsonif-autorun" src="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autorun-150x150.png" alt="coutsonif-autorun" width="150" height="150" /></a></p>
<p style="text-align: justify;">Virus will change your registry to allowed only <span style="text-decoration: underline;">11</span> maximum active application, it also blocking your maximum port to only port <span style="text-decoration: underline;">8000</span>.</p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong>Automatic Update:</strong></span></p>
<p style="text-align: justify;">This virus will try to automatically update himself to this address list:</p>
<p style="text-align: justify;">66.90.103.169:99/a.exe<br />
66.90.103.169:6666/lsass .exe<br />
66.90.103.169:443/crss .exe<br />
TCP:72.249.94.146:7008 Port:27<br />
TCP:127.0.0.1:1092 Port:30<br />
TCP:66.90.103.169:99 Port:29<br />
TCP:66.90.103.169:6666 Port:30<br />
TCP:66.90.103.169:443 Port:30<br />
Port 80 IP:83.133.127.5<br />
Port 80 IP:68.180.151.74<br />
Port 25 IP:127.0.0.1<br />
Port 80 IP:65.55.21.250<br />
TCP:83.133.127.5:443 Port:17<br />
TCP:65.54.186.47:443 Port:17<br />
Port 80 IP:87.248.208.54<br />
TCP:89.149.254.14:443 Port:21<br />
Port 80 IP:64.4.33.7<br />
Port 80 IP:207.46.11.121<br />
Port 80 IP:65.54.186.47<br />
Port 80 IP:88.221.26.64<br />
TCP:65.55.16.123:443 Port:28<br />
TCP:92.122.112.124:443 Port:28<br />
TCP:92.122.112.124:443 Port:28<br />
TCP:88.221.165.186:443 Port:29<br />
TCP:88.221.165.186:443 Port:29<br />
TCP:83.133.127.5:443 Port:18<br />
TCP:89.149.254.14:443 Port:2<br />
TCP:65.55.16.123:443 Port:27<br />
TCP:65.54.186.47:443 Port:27<br />
TCP:92.122.112.124:443 Port:27<br />
TCP:92.122.112.124:443 Port:28<br />
TCP:88.221.165.186:443 Port:28<br />
TCP:89.149.254.14:443 Port:21</p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><span style="color: #008000;"><strong>Simple steps to cleaning Coutsonif.A:</strong></span></span></p>
<p style="text-align: justify;"><span style="color: #000000;">1. </span><span style="color: #008000;"><span style="color: #000000;">Disable &#8220;<span style="text-decoration: underline;"><strong>System Restore</strong></span>&#8221; when in cleaning process.</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">2. Disable &#8220;<span style="text-decoration: underline;"><strong>autoplay/autorun</strong></span>&#8221; function by:</span></span></p>
<p><span id="more-999"></span></p>
<ul>
<li><span style="color: #008000;"><span style="color: #000000;">Start -&gt; Run -&gt; Type &#8220;<span style="text-decoration: underline;"><strong>gpedit.msc</strong></span>&#8221; -&gt; Computer Configuration -&gt; Administrative Templates -&gt; System -&gt; look on &#8220;<strong>Turn off autoplay</strong>&#8221; -&gt; Properties -&gt; Setting tab -&gt; Enabled</span></span></li>
</ul>
<p><span style="color: #008000;"><span style="color: #000000;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autoplay-disabled.png"><img class="alignnone size-thumbnail wp-image-1004" title="coutsonif-autoplay-disabled" src="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autoplay-disabled-150x150.png" alt="coutsonif-autoplay-disabled" width="150" height="150" /></a><br />
</span></span></p>
<p><span style="color: #008000;"><span style="color: #000000;"><a href="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autoplay-disabled-2.png"><img class="alignnone size-thumbnail wp-image-1003" title="coutsonif-autoplay-disabled-2" src="http://www.istanto.net/wp-content/uploads/2009/02/coutsonif-autoplay-disabled-2-150x150.png" alt="coutsonif-autoplay-disabled-2" width="150" height="150" /></a></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">3. Kill active virus process in background, You can use any task manager tools such as <a href="http://www.neuber.com/taskmanager/download.html" target="_blank">Security Task Manager</a>, just killed sysmgr.exe, vshost.exe, winservices.exe, *.tmp</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">*<strong>TMP</strong> is random.</span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">4. Repair your registry files using code below or download <a href="http://www.istanto.net/wp-content/uploads/2009/02/repair1.inf">repair.inf</a></span></span></p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=Nobody</span></span></p>
<p>[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del</p>
<p>[UnhookRegKey]<br />
HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;<br />
HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;<br />
HKCU, SessionInformation, ProgramCount, 0&#215;00010001,3<br />
HKCU, AppEvents\Schemes\Apps\Explorer\BlockedPopup\.current,,,&#8221;C:\WINDOWS\media\Windows XP Pop-up Blocked.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\.Current,,,&#8221;C:\Windows\media\Windows XP Recycle.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\Navigating\.Current,,,&#8221;C:\Windows\media\Windows XP Start.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\SecurityBand\.current,,,&#8221;C:\WINDOWS\media\Windows XP Information Bar.wav&#8221;</p>
<p>[del]<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Microsoft(R) System Manager<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, bMaxUserPortWindows Service help<br />
HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, MaxUserPort</p>
<p style="text-align: justify;"><span style="color: #008000;"><span style="color: #000000;">5. Deleted this file list, when it hard you can use <a href="http://www.malwarebytes.org/fileassassin.php" target="_blank">File Assasin</a> tools:</span></span></p>
<ul>
<li><span style="color: #008000;"><span style="color: #000000;">\vshost.exe [all drive]</span></span></li>
<li>\autorun.inf [all drive]</li>
<li>\RECYCLER\S-1-5-21-9949614401-9544371273-983011715-7040\winservices.exe</li>
<li>\Documents and Settings\%user%\Local Settings\Temp</li>
</ul>
<p>A415.tmp (random)<br />
034.exe (Random)<br />
Lady_Eats_Her_Shit&#8211;www.youtube.com</p>
<ul>
<li><span style="color: #008000;"><span style="color: #000000;">\WINDOWS\system32\sysmgr.exe</span></span></li>
<li>\WINDOWS\TEMP\5755.tmp</li>
<li>\windows\system32\crypts.dll</li>
<li><span style="color: #008000;"><span style="color: #000000;">\windows\system32\msvcrt2.dll</span></span></li>
</ul>
<p><span style="color: #008000;"><span style="color: #000000;">6. Re-checking your system to make sure it clean using your best antivirus or use <a href="http://download.norman.no/public/Norman_Malware_Cleaner.exe" target="_blank">Norman Malware Cleaner</a></span></span></p>
<p><span style="color: #008000;"><span style="color: #000000;">Done, Have a good day everyone <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/ym-and-skype-virus-youtube-lady_eats_her_shit.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

