Showing posts with label Encryption system. Show all posts
Showing posts with label Encryption system. Show all posts

4/05/2009 04:14:00 AM

(0) Comments

7 Tips Discontinue Virus Floods Shortcut 


Virus PIF / Starter or better known as the virusshortcut make victims of sorts with many shortcut created by the virus. Its fuss, if virus handle trick this imprecise, then it will come back

Lets we go to stopping the virus with 7 steps.

  1. Turn off system restore on your computer
  2. Turn off the process of Wscript file located in C: \ Windows \ System32, with how to use tools such as CProcess, HijackThis or can also use the Task Manager of Windows.
  3. After switch off process from Wscript. We must delete or renaming of the file, so that's not to be used by the virus.

 

For notes, If we will rename of  the Wscript.Exe with automatic. Therefore copied again at the folder, therefore, we must scan where is another Wscript.exe exist, eventually at  C:\Windows\$NtservicepackUninstall$, C:\windows\ServicePackFiles\i386.

 

As not as another VBS’s , we can subtitute Open with from VBS file become Notepad, this virus having extention MDB its mean is access’s Microsoft file. So Wscript will carry on DATABASE.mdb file pretend its VBS’s File.

 

  1. Delete parented file at C:\my document and setting\my documents\database.mdb, that everytime Computer on not loading this file. And don’t forgeted also to open Msconfig, and Disable command to run it.
  2. Now we will to delete Autorun.INF, Microsoft INF file and thumb.db its trick is “ Click start button,open run then type CMD, move to drive wich will cleared, e.g Drive c:\ therefore we must doing is:

 

Type C:\del Microsoft.inf/s, this instruction will deleted all file Microsoft.inf at folder in drive c:. while if want’s move to drive stay to substituted by name of the drive exp: D:\del Microsoft.inf/s.

 

For autorun.inf file “ type c:\del autorun.inf/s/ah/f. instruction will be to deleted autorun.inf file, ( syntax /ah/f ) utilized because that file uses attribute RSHA, also to file thumb.db do it same as.

  1. To deleted file besides 4 former files, we must scan by search file with ext .lnk its measure 1 kb. On “more advanced option” ensure option “ search system folder” and “ search hidden files and folders” both have to centang.

Be Carefully, not of all shortcut lnk file with size 1 kb is virus. We can differentiate it from icon , size and type file. For shortcut created by virus its icon always utilizes folder icon , fairish 1 kb and get type shortcut, whereas that right folder is no have size and its type is foder file.

  1. Fix registry already being changed by virus. To fasting registry’s repair process, please copied script bellow above on Notepad and then save as with name Repair.inf start the file by:

 

-     Right click repair.inf

-          Install's click

 

this is script to copied

[Version]
Signature="$Chicago$"
Provider=Vaksincom Oyee

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"

[del]
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer

 

3/20/2009 08:21:00 PM

(0) Comments

DANGEROUS HOLE ENCRYPTION SYSTEM

Encryption of HARD Drive like The Locker VISTA doesn't warrant security avoid Hacker.this is evidenced by group of researchers from the U.S.
A super computer may not be able to break through 256-bit AES encryption key that is used in the microsoft software to encrypt bitlocker Vista.This could be wrong.A team of researchers from Princeton University have developed a process that can be read harddisc with encryption from bitlocker, File Vault (Apple) and open source encryption tool (true crypt). and they only use a small computer resource.
Metode of them nothing else with the encrypt, but reading password that saved at RAM. They are attack with a trick, Hacker connect external Harddisc to PC with USB connection then they are reboot. Then pc will run from usb hard drive and run the program to analyze the RAM. Because the password and the data is not erased simply after the PC is turned off,have remaining time about 3 to 5 seconds. This is enough to re-start the PC without having to lose data in RAM.
when the computer is protected with a password Bios does not allow for booting from the hard drive memory external, researchers will release the module RAM.waktu 10 seconds may be too short.solution, cooled RAM module with compressed air. Within temperature up to -50 degrees celcius, the data can be read for about 10 minutes. in fact material with nitrogen (- 196 degrees celcius ) can survive up to 1 hour.

PREVENTION SOLUTION FOR THIS TRICK
- ALWAYS DISCONNECT POWER SUPLY
HOW THIS, Temporary memory will be deleted entirely. Because Standby system on notebook not safe, is different from the standby MODE ON WINDOWS PC (PC system, will write data into the disc drive system before log of the system )
- ICQ 6 BUILD 6043 ( Update new version from ICQ website, info : http://www.icq.com/)
With messages that manipulated, instant-messenger ICQ can be made to stop work. is due to a bug in the HTML processor in this program. destructive code can inserting into the computer.
- SUN JAVA ( Update new version Java-software 6 update 5 manualy recycle old version from PC, Info : http://www.sun.com/ )
Not information yet, where is hole it can hacker coming 

VIRUS AND MALWARE ITS MOST DOGHOUSE
1. Trojan-Spy. Win32.Banker.ciy >>> Money Card System 
2. Trojan-PSW.Win32.VB.kq >>> Payment system
3. Varian of Trojan-Spy >>> Online Banking
4. Email-Worm.Win32.Netsky.q >>> E-Mail-Trojaner 
5. Trojan-Down-loader.Win32 >>> MOst Hidden
6. Trojan.Dos.DiskEraser.b >>> Smallest Varian Virus
7. Trojan.Win32.killfiles.mb >>> Bigest Varian virus
8. Backdoor.Win32.Aebot.e >>> Destructive virus
9. ITrojan-Downloader.Win32 >>> Very Wide virus 

Every virus catagory is no.1 and can a large financial loss 

Please click This link if you want know todayTodayIs.com