Showing posts with label Tips And Tricks. Show all posts
Showing posts with label Tips And Tricks. Show all posts

Tuesday, February 8, 2011

'Take the Classroom',Local Virus Make Cracks in Windows

Indonesia's Most local virus attacks by using the user mere negligence.But this one virus has been 'first class' by exploiting Windows vulnerabilities.The presence of virus was delivered by antivirus researchers of Vaksincom,Alfons Tanujaya."He made a shortcut and exploit vulnerabilities.Seldom local virus exploits a security hole," said Alfons to ITGazine.

Adang Jauhar Taufik,antivirus Vaksincom analyst,said the first report of this virus came from the city of Gorontalo on Sulawesi.The spread of this virus is known via a USB Flashdrive.

These viruses change the folder that is in the USB stick into the shortcut.Then,if a shortcut is accessed virus will infect the computer until the computer's performance become poor.

In addition,Alfons said,this virus to protect himself from the tool as Security Task Manager or other process killer application.If used,the application could hang or die.

"Apparently,the virus makers pay attention to virus eradication articles Vaksincom often using Security Task Manager.So if cleared,he was prepare," said Alfons.

Cracks are utilized by this virus is a Microsoft Windows Shell shortcut handling remote code execution vulnerability,MS10-046.Microsoft has provided a patch to patch this vulnerability.Norman Security Suite detects this virus as W32/VBWorm.BEUA.For its shortcut files identified as Trojan:LNK / CplLnk.A and files.DLL detected as W32/Suspicious_Gen2.BTDDL.

Dr.Web Anti-virus detects the virus as W32/HLLW.Autoruner.25850.File shortcuts are recognized as the Exploit.Cpllnk and files.DLL detected as Win32.HLLW.VBNA.3.

Adang said the virus is created by using Visual Basic language program.Viruses with the size of 128 KB it thinks will have the extensions EXE or SCR,as well as Microsoft Visual Basic Project icon.

8 Steps Viruses Ejecting Exploiters Windows Gap

W32/VBWorm.BEUA The presence of virus,better known as a shortcut virus that exploits the security hole is quite disturbing.For,although labeled local virus,he not only take advantage of user negligence.But has 'first class' to break through Windows security holes.

Consider the 8 practical steps to kick the virus is able to change the folder that is in the USB flash disk into the shortcut,according to Jauhar Adang Taufik,an analyst with Vaksincom:

  • Disable 'System Restore'for a while during the cleaning process.
  • Decide who will clean your computer from the network.
  • Turn off the virus active in memory by using the tools 'Ice Sword'.Once the tools are installed,select the file that has the icon 'Microsoft Visual Basic Project' and click 'Terminate Process'.Please download these tools at http://icesword.en.softonic.com
  • Delete the registry that has been created by the virus by:-.Click the [Start] -.Click [Run] -.Type Regedit.exe,and click the [OK] -.In the Registry Editor application,browse the key [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] -.Then delete the key that has the data [C:\Documents and Settings\%username%].
  • Disable the autoplay/autorun Windows.Copy the script below in notepad and then save it as repair.inf,install the files in the following manner:Right-click repair.inf->

    INSTALL

    [Version] Signature="$ Chicago $"

    Provider=Vaksincom

    [DefaultInstall]

    AddReg=UnhookRegKey

    DelReg=del

    [UnhookRegKey]

    HKLM,Software\CLASSES\batfile\shell\open\command,,,"""% 1 ""% * "

    HKLM,Software\CLASSES\comfile\shell\open\command,,,"""% 1 ""% * "

    HKLM,Software\CLASSES\exefile\shell\open\command,,,"""% 1 ""% * "

    HKLM,Software\CLASSES\piffile\shell\open\command,,,"""% 1 ""% * "

    HKLM,Software\CLASSES\regfile\shell\open\command,,,"regedit.exe"% 1 ""

    HKLM,Software\CLASSES\scrfile\shell\open\command,,,"""% 1 ""% * "

    HKCU,Software\Microsoft\Windows \CurrentVersion\Policies\Explorer NoDriveTypeAutoRun,0x000000ff,255

    HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer NoDriveTypeAutoRun,0x000000ff,255

  • Delete Files parent and duplicate files are created by the virus included in the flash disk.To expedite the search process,you can use the 'Search'.Before conducting the search should show all hidden files by changing the Folder Options settings.

    Do not let an error occurs when deleting a master file and duplicate files that have been created by the virus.Then delete the master files that have virus characteristics:

    -.Icon 'Microsoft Visual Basic Project'.
    -.File Size 128 KB (for other variants will have varying sizes).
    -.Ekstesi file '.EXE' or '.SCR'.
    -.File type 'Application' or 'Screen Saver'.

    Then delete the duplicate shortcut files that have the characteristics:

    >.Folder Icon or icons >.Extension.LNK >.File Type 'Shortcut'>. 1 KB file size Delete the file.

    DLL (example: ert.dll) and Autorun.inf file on flash disk or a shared folder.Meanwhile,to avoid the virus is active again,delete the master file that has an EXE or SCR extensions first and then remove Shortcut file (.LNK).

  • Show re-folders have been hidden by the virus.To speed up the process,please download the tools Unhide Files and Folders in http://www.flashshare.com/bfu/download.html.

    Once installed,select the directory [C:\Documents and Settings] and folders that exist on the flash disk by moving into fields that are already available.In the [Attributes] clear all the options,then click the [Change Attributes].

  • Install security patches 'Microsoft Windows Shell shortcut handling remote code execution vulnerability,MS10-046'.Please download the security patch at http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx

    As usual,for an optimal cleaning
    and Preve.

Thursday, February 3, 2011

7 Tips For Keeping Passwords

Password is a secret
code that must be protected. Many
negative things can happen
when your password leak into the
hands of others. Learn 7 tips to keep
it brief.

1. Not Using Default Password
The default password is the
password that we can be the first
time. This default password should
indeed be quickly replaced because
of very vulnerable. The reason, the
default password can be easily
searched on google search, even
there are listed the name of a
machine, type and default password
with a magnificent plastered on
some website creators vendors.

Sometimes administrators fear of
forgetting to change-change the
default password, so that an
intruder can take over the system
with default passwords.

Wearing 2.Not Password Hint
Sometimes we are afraid to forget
the password that was our entry
into the system / account, so we
need to create a reminder if we
forget the password. Now this is
called password reminder Hint, if
we create a password hint question
with this then we can quickly recall
these forgotten passwords.

Likewise with the hackers, they'll
experiment with us to guess the
password in the password hint
questions, over time the password
will be predictable, if the questions
listed in the password hint can be
answered by the guesst
password.

Writing 3.Not Password
Owners are often afraid to forget
your password with the password
has been entered, so the owner
would write different passwords
user id and password into other
media such as a notebook, notepad,
Stickies (mac), password folders,
books, mobile phones and other.

It is also quite vulnerable to leaking.
Why vulnerable? Because if the
various equipment is lost, then all
information about a user id and
password are sooner or later will be
known by the thief equipments /
gadgets are missing.

4.Use a Strong
Password
Owner passwords often using a
short password only, if it could be
shorter than 3 characters then the
user will give a short password.
Fortunately this time the system
provides a minimum password
length of 6 characters and a
maximum of 254 characters. The
longer a password the stronger it
will be the password security.

Strong passwords can be created
with a combination of numbers and
letters and even a variety of other
characters. Some admins are
currently using a password that is
long enough, coupled with
encryption such as PGP key and
others, so it is quite difficult to guess
password.

5.Often Change Password
Owners should periodically change
your password for authentication
password, the more frequent
password changes, the better,
because the more difficult the
guess password hacking
account / your system. Changes to
the password depends on the
owner, could be a week, a month,
three months, and others. Originally
the owner does not forget the
password that was changed earlier.

6.Not Using Same Password
on Multiple Accounts
Owners often forget and sometimes
passwords frequently enough to
create an account, so they each
create a new account using the
same user id and password are the
same, this is very vulnerable and
dangerous. Because these
passwords through a single
account, all accounts will be taken
by the hacker.

7. Using Password Management
To help recall the various
passwords and various accounts,
we are often very difficult, but not to
worry because it has many current
applications to help organize our
passwords. This application can be
downloaded for free from the
internet and paid, so that regardless
of our account and whatever we
can with the password easy to
remember and re-opened, of
course, to open it with an
encryption method as well.

*) The author is IGN Mantra, Senior
Analyst Network Security and Traffic
Monitoring Internet ID-SIRTII once
Lecturer Network Security and
Cybercrime.

3rd Stage Opening Windows With Ubuntu Password.

Lost is a common
problem faced by humans. If you
forget your Windows login
password, no way to recover it
using the Ubuntu Linux operating
system.

The first thing to do is create a
Live CD or Live USB stick Ubuntu
Linux. Ubuntu Live will be used to
boot into the system and perform
the procedures required to
dismantle the Windows password
earlier.

The easiest way to do that is by
downloading UNetbootin and run
it. This simple application will
download the selected Ubuntu
version and install on the flash that
you prepared.

The second stage is to install
Open Source utility called chntpw.
This is done from Ubuntu by
running Synaptic Package Manager.

To be able to get chntpw, Synaptic
Package Manager should be directed
to look at storage applications
Universe. This can be done by
clicking the Settings menu>
Repositories in Synaptic window.
Then, check the option
'Community-maintained Open
Source software (universe) "and
click Close.

After that, click the Reload button
and Synaptic will download the
latest package information from the
Universe. When finished, type
chntpw on the Quick Search box.

If it appears, check the box on the
side chnptw writing, choose 'Mark
for Installation'. Then click Apply to
install it.

The third stage is to change the
Windows password with chntpw.

1. Mount the hard disk / drive that
contains your Windows installation
2. Open the hard drive it (click on
Places) and record labels drive that
appears on the menu bar window
file browser
3. Open a Terminal window
(Applications> Accessories>
Terminal)
4. Type the following command in
Terminal:
cd / media
ls
5. Type: cd [label hard drive that
you noted earlier]
6. type: cd WINDOWS/system32/
config
7. To change the Administrator
password, type the command:
sudo chntpw SAM
8. You will see several commands
that you can choose, the command
is safest to create a password to be
blank. Do this by pressing the
number '1 ', then press' y' to
confirm
9. Select '2 'to change the password
to a particular word, but this has a
greater risk of error
10. To change the passwords of
other users (non-administrator),
type the following command (from
Terminal): sudo chntpw-u [user
name] SAM

Eradicate Tips Ramnit Of Computer Viruses.

Although relatively
new, but the rapid spread of the
virus Ramnit indeed. In fact,
because of sophistication that is
able to download other viruses,
malicious programs are classified as
one of the trojan that difficult to
eradicate.

Well after learning characteristics
-characteristics, here are the steps to
remove viruses delivered Ramnit
Alfons Tanujaya, Vaksincom
antivirus analysts, to ITGazine,
Tuesday (02/01/2011).

Because infected files ending in exe,
dll, and html, then cleaning should
be done in DOS mode. To facilitate
cleaning please use the Windows
Live CD Mini PE, then downlad free
tools Dr.Web CureIt!

To be optimal, we encourage all
media including hardsisk and flash is
scanned first. This is because
Ramnit will put some storage
media.

Before doing the cleaning should
block viral duplicate files by using
the feature 'Software Restriction
Policies'. This feature is only there
on the operating system Windows
XP Pro, Vista, 7, Server 2003 and
Server 2008.

Connect an external flash or any
hardsik to the computer. Then
download the application free Dr
Web Live CD at the following sites.
After it was over done, the user can
continue the following steps.

After a successful software Dr.Web
LiveCD download, burn into CD /
DVD
Connect the flash and external to the
computer hardsik
Booting the computer through a
CD / DVD ROM
This will bring up the screen
'Welcome to Dr.Web LiveCD
Select 'Dr.Web LiveCD (Default)' and
press 'Enter' key on your keyboard
Wait a few moments to appear
Dr.Web LiveCD interface that will
display the applications 'Dr.Web
Scanner' automatically. Dr.Web
Scanner is working to examine your
computer from possible virus
To scan the hard disk, on screen
'Dr.Web Scanner' select location of
the drive to be in check and make
sure you check list option 'Scan
subdirectories' for Dr.Web can
conduct examination on the
directories and subdirectories for
optimal cleaning. If the screen does
not appear Dr.Web Scanner double
click the icon 'Dr.Web Scanner'
found on the Desktop.
Then click the [Start] to begin the
examination process
Wait a while until the scan is
completed. If you find any viruses,
Dr.Web will inform the infected file
and the type of virus that infects the
virus information is available
column.
Click the [Select All] to select all the
objects / files to be in the clear or
you can specify which files would
you clean it with a check list on the
options available
then click the [Cure] to clean up files
that have been infected with a virus
Wait until the cleaning process is
completed
Scan the computer to ensure clean
your computer from viruses
Restart the computer.

Beware Virus Attacks Ramnit.

After some
horrendous virus like Stuxnet, Sality,
Virut and Shortcut, there are now
Ramnit that is equally sophisticated.
This malicious program is able to
'cooperate' with other viruses to
infect the victim.

Yes that's the uniqueness Ramnit
compared with other viruses. After
infect the victim computer, these
malicious programs will download
variants of other viruses.

And even more confusing, the type
of virus that you download will be
different for each target computer
either from the name and size. This
is what causes many antivirus
programs although difficult to
perform detection and cleaning.

This virus not only
spreads via the Internet, but also
through other media such as flash
by using the Autorun function.

Another action that will be done by
this virus is injected exe files that
have extensions, etc. and htm /
html file either an application
program or Windows file system.
Each file is injected to increase the
size of about 107-109 KB.

Sunday, January 30, 2011

5 Steps To Clean Up Account

A malicious
program that scalp name
'McDonalds' sprang up. If a victim,
your Facebook account will
distribute it to all contacts.

Of course it is very annoying. In
addition there are also potential used
for the benefit that can not be
accounted for.

Then, how do I fix this? Consider the
following steps as presented Alfons
Tanujaya, Vaksincom antivirus
analysts, who quoted on Saturday
(10/30/2010):

If you have already become victims
and spread the Event Invitation to all
your contacts, immediately inform
all contacts up to you to not click the
link provided let alone to approve
the installation of the application.
Click the [Account] [Privacy
Settings]. You will open a menu of
"Choose Your Privacy Settings"
Click [Edit your settings] from the
menu "Applications and Websites"
in the lower left corner to open the
menu of "Choose Your Privacy
Settings> Applications, Games and
Websites"
Click [Remove unwanted or
spammy applications] to open the
screen "Applications, Games and
Websites> Applications You Use"
and click the X on the "Edit Settings"
You will get a confirmation screen
Remove, click the [Remove] to
remove the program HD Video
Player.

Saturday, January 29, 2011

6 Thing Forbidden By Dispel Spam

Global spam volume
may decrease, but pointed out the
danger level rises. Here are six
things to avoid to dispel the spread
of spam.

In a monthly report Symantec
Messaging and Web Security
quoted on Wednesday (24/11/2010)
mentioned that the global volume of
junk email (spam) decreased.

However this is not a reason to
become complacent and no longer
perform the required safety
procedures.

Well, here are six things you think
Symantec should not be done by
Internet users. The ban is necessary
to block the spread of spam.

1. Opening email attachments
from unknown
Do not be tempted to open an
attachment in an email that looks
suspicious. Sometimes the
attachment is a name that is
tempting, but it could be the
contents are malicious programs.

2. Replying to spam
Perhaps because of upset or other
reasons, users may be tempted to
reply to spam email with the oath-
curse or a request to not send
emails anymore.

Be careful, because usually the
address used was a fake and if
returned it will give birth to more
spam back to the Inbox.

3. Fill Form via Email
Tricks of data theft often do is to ask
potential victims to fill personal data
through forms that exist in the
email, or form that the link is
displayed in the email.

Symantec said the company is not
leading you may ask for personal
information via email. If in doubt,
contact the company through the
official channels separately. Do not
click or copy-paste from the link in
the message.

4. Purchase products or
services from spam messages
Although the product or service that
sounds interesting, you should not
try to buy products or services
offered via spam. This will only
encourage people to continue using
spam.

5. Opening spam messages
If a message is spam is obvious, for
example because it is characterized
by the Spam Filter is used, this
means that the message was
already supposed to be discarded.

6. Chain Email Forwards
Many warnings about viruses,
security dangers and other things
that spread by email. Because there
is a possibility that kind of thing only
a rumor (hoax) alone, should not
the bandwagon to send the
message chain.

4 Ways Of Preventing Phishing Scam Customer.

Action aka phishing
attempts targeting the theft of
sensitive information that bank
customers have repeatedly
occurred. Here are four tips adala
who could hold onto customers so
as not to fall for the trick-trick this
action.

1. Origin Check Email
Usual mode waged cyber criminals
is to send an email teaser to a
number of people. The contents of
electronic mail will usually ask the
prospective victim to visit a
particular site, to then re-register
(include your username and
password e-banking customers.)

Well, for those customers do not
necessarily believe if you get an
email with a model like this. First
check the origin of the sender's
email, if using an official email
domain from a particular bank or
not.

Because, if they use the email
domain is not clear, it need not be
trusted email. Although at the end of
their email claim from the
concerned bank.

2. Not Quite Through Email
Re-register by entering your
username and password is a
sensitive activity. So, delivery-
related information of this activity
also can not be arbitrary, only via
email.
A number of banks admitted if they
want their customers to re-register,
they usually do not just let me
know via email.

But also through
more personal means, namely
contacted directly. There also are
using an official letter, although the
combined-match with the email as
well. At least, the bank treats these
events with more professional.

3. Reverse Phone
Do not hesitate to call customer
service bank you use. Better to be
alert, rather than hesitate, but
instead led to bad things for you.

4. Distinguishing Genuine or
Fake Site
Sites that financial institutions use to
login normally have a security
system tighter. First, see the website
address. Site logins should use the
prefix 'https' instead of 'http'. Https is
a secure version of http.

Suffix 's' in 'http' indicates that these
sites actually have 'secure', because
the technology is protected by
Verisign SSL encryption of data.

On the site e-banking, Bank
Permata is asphalt , also
contained the logo 'Security Verisign
Site'. To the layman, it would be
difficult to distinguish. That can be
one benchmark validity of an e-
banking site is the URL that is written
is 'https'.

Then at the bottom right of the
browser (for Firefox) there is a
locked padlock image. As for
Internet Explorer (IE), this yellow
padlock in the URL field.

If the victim involuntarily fill your
username and password in asphalt
sites, it can be ascertained that such
personal data, including records e-
banking activities of his, will be
known by other parties who are not
responsible.