Showing posts with label Computer Virus. Show all posts
Showing posts with label Computer Virus. Show all posts

Test Whether Computer Infected Conficker/ Kido

At this moment maybe the one fast spreading virus is Conficker. Many media that proclaim the danger of this mailware, and even yesterday there was an issue there will be a large-scale attack on 1 April.

How to know that computers has been infected by Conficker? There was some ways to test it.

1. Visit this site http://www.heise.de/security/dienste/browsercheck/tests/conficker/conficker_e.shtml. If 6 image appears, its means your computer safe from that virus, but if there are some image do not appear, it possible infected with the virus.

conficker test2. Almost same with the first method i.e. visit http://www.confickerworkinggroup.org/infection_test/cfeyechart.html. If all image appears, its means your computer safe. But if any images that do not appear, so the computer might be infected by Conficker virus.

conficker eye chart
3. Open this site http://iv.cs.uni-bonn.de/fileadmin/user_upload/werner/cfdetector/. If appears message below. It means your computer is not infected by Conficker

cfdetectorIf your computer infected by Conficker. You can remove it with these following tools

Preparing Face New Conficker.C Worm

Creator of the Conficker have updated the worm for security vendors who are working hard to stop the spread and threat of the worm program. After Conficker.B, now has been attend the Conficker.C that able to shutdown security services, blocking computer from website connection and download a Trojan.

According to Ben Greenbaum, senior manager of Symantec Security Response, Conficker.C also programmed to launch connections in a different 50,000 domain to receive the update copy or other malware, that is 250 domain in one day, like previous Conficker version. That Conficker.C code writers are increasingly themselves strengthen in collecting the infected computer, and in the same time they also try to strengthen their ability to control the infected machine to download 50,000 more domains, Greenbaum added.

The merger company is called "Cabal", including of Microsoft, Symantec, and domain registration provider, has been trying to eradicate Conficker with pre-registration and lock the domain name that has been used by worm to distributing worm updates.

Worm Conficker or Kido or Downadup, was first detected in November and has been trusted infect more than 10,000 computer. The second variant of Conficker, i.e Conficker.B, has been detected last month. The ability of Conficker.B is spread via network shares and via removable media, such as flash disk through the Windows Autorun function. For that, users can apply the patch from Microsoft and update antivirus software, and this week Enigma Software Group and BitDefender has announced the removal tool Conficker.

10 Sadist Computer Virus

Here is ten sadist virus on computer:

1.Storm Worm
Appear in 2006, called "Storm Worm" because spread via email with the title "230 dead as storm batters Europe". Storm worm Trojan is a program house. some versions can be a computer bots or usually use by hacker to spam via mail.

2. A Leap-A/Oompa-
Macs that have a concept of security through obscurity sure it will not attact by virus because the OS system its closed. But in 2006, Leap-A virus or common called Oompa-A appears. It spread via iChat on the Mac. After Mac infected, the virus will search for contacts via iChat and send the message to each contact. The message that contains a corrupt file in the JPEG. It is not dangerous, but this is still possible that there will be a dangerous virus that attacks the MAC.

3. Sasser and Netsky
Create by German children aged 17 years old, Sven Jaschan. Sasser attack Microsoft Windows. This Sasser not spread via email. But if any computer connect to a computer that infected by Sasser. The computer will be can't shutdown till you unplug the cable power. Netsky spread via email with a 22 Kb file attachments and Windows network. It can make DoS attacks. Sven Jaschan not dipenjara only given probation 1 taon 9 months, because they are under age 18 taon.

4. MyDome (Novarg)
Atttacking on 1 Feb 2004, it is a backdoor virus on the OS. First time on date 1 start DDoS. Second, on Feb 12, this virus spread to stop and start creating backdoors. MyDoom spreads via email, beside that always search on search engines such as Google began to receive millions of search queries and slow until I finally crash. Because of MyDoom, U.S. Senator Chuck Schumer launched the National Virus Response Center.

5.SQL Slammer / Saphire
Appear in January 2003, fast spread via Internet. That time make U.S. Bank ATM service crash. Smash of Seattle 911 service and Continental Airlines make it cancel flights because got error in check-in and ticketing. It loss more than $ 1 billion.

6.Nimda
This was also in 2001, opposite of the word "admin". Spreading very fast, according to TruSecure CTO Peter Tippet, Nimda only takes 22 minutes to become a Top Ten at the time. Its target servers on the Internet, spread over the Internet. Nimda will make backdoor to the OS. so attacker can access to the server and do what he want and also become a DDoS.

Red & 7.Code Code Red II
Appear on summer 2001, attack OS Windows 2000 & NT. The virus will make buffer full so run out of memory. Most exciting time was related with White House, all computer that infected will automatic access to a web server in the White House at the same time, so overload, alias DDoS attacks. Microsoft finally releases the patch at that time.

8.The Klez
Appear on 2001, spreads via email, to tell how the replication then send to any people in address book. Make the computer can't operate and disable anti virus program.

9.Melissa
Made in 1999 by David L Smith. Spread via email with the document "Here is that document you asked for, do not show it to anybodey else.". If it opened, the virus will replicate and automatic send to top 50 mail address.

10.ILOVEYOU
After "Melissa", appears virus from the Philippines, its worms form, standalone program can replicate itself-. Spread via email, the title "love letter" from the fans a secret. Original file is LOVE-LETTER-FOR-YOU.TXT. vbs. Vbs Visual Basic Scripting abbreviations. Is the creator Onel de Guzman of the Philippines.

Tips Cleaning Kspoold Virus

Virus Kspoold is a new virus which is very fast spread. This is due to the use of flash disk as a temporary storage file. With flash we will move a lot of files easily. Risk is the spread of the virus.

Often computer users open files without notice the type of file. Because this virus change from document file into the application . It seems this virus spread without having to click on a file that is exposed to the virus. This is my personal experience.

Flashdisk that clean from viruses, when plug to the USB port which infected by virus. So, all document file will change into the application. Whether .Doc or .Xls extensions.

But because the experience, that document file be open then stored with different extension. Such .doc format save as .Rtf and .Xls save as .Xml spreadsheet. But.Xml format only can be opened in office 2003.

If opened in the office before, which appears only html code only. But eventually I also find on the internet how to clean this virus. From one of the blog, i found the way to solve it.

1. Do not clean the virus using anti-virus first, because all the infected files will be deleted (delete).

2. The first step, we must kill the virus that is active then reconstruct the file that has changed to .exe into document file.

3. Check the document file on the computer, doc, xls, MDF, ldf, DBF). When all become application, its mean that the computer is infected.

4. Run the command prompt, with click start - run, type cmd - enter, type services.msc. See, are there service named Kprintspooler?

5. Open windows explorer, file kspoold.exe check whether there are in c: \ windows \ system32 \ (if there means positive virus infected).

5 point above shows the characteristics of virus infected computers kspoold. Now the process of cleaning the virus.

1. Shut down the virus process in windows service:
  • disable your anti virus
  • Run the command prompt, with click start - run, type cmd - enter,
  • Type services.msc.
  • Search service with the name kprintspooler, turn it off
  • Double-click Kprintspooler , select stop,
  • Then in start-up type select disable.
2.Delete Kspoold.exe files in c: \ windows \ system32 \
- If it can not be deleted, change the file extension, for example kspoold.exx, then remove.

3. Restart your computer.

4. Activate your antivirus, update its virus definitions.

Done, now let the anti virus work. Be careful with files that have been infected. Do not let your anti virus delete them. I already try Norton Anti virus, when the virus was detected, it remove immediately. Different with AVG that ask for confirmation first.