Wednesday, March 24, 2010

RootKit: Digital Voodoo

0 comments
Rootkit was first introduced in SunOS operating system by Lane Davis and Steven Dake. This technology is used by Root on Unix (equivalent to the System Administrator on Windows) to recovery (restore) the root password they forget. To be able to restore the root password is not easy because it needs authorization and unlimited access to a system. Finally, a special technology was discovered that can do that later known as this rootkit.

The term rootkit is so famous after a world-class music companies who apply to secure the CD music from piracy. The case has become a very horrendous scandal because even though the goal to avoid piracy, the use of this technique allows malicious applications rootkits planted aboard the music companies.


Rootkit techniques are prone to be used for evil purposes. If you remember, a virus such as Alman or Bacalid using rootkit techniques so difficult to detect. Removal of his application could not finish 100% due to a virus of malware that uses rootkit technology to walk residents and difficult to detect. He runs invisibly, silently without a sound, and did attack you never know. No wonder so many who think like voodoo rootkit in the computer world. In fact, the rootkit is basically a technology and can be used for good and useful. An example is the use of applications rootkir antivirus, firewall, software protection, DRM (Digital Right Management), and simulation applications such as daemontools disc media. The problem, rootkit techniques can also be used to create malicious applications are difficult to overcome.

Rootkit various

Like viruses, rootkits also has many variants. Classified according to the target being attacked, rootkits distributed into 6 kinds, namely:

1. Application Rootkit
Rootkits are made by modifying the binary code of an application directly or commonly referred to as binary code patching. This type of rootkit is usually found in the type of trojan malware to inject the virus into an object or system.

2. Library rootkit
This is a rootkit targeting libraries. Library itself is a file such as a library function that has been collected into one with a view to memermudah programmers in creating and developing an application. Library marked with the suffix "etc." as "kernel.dll".

3. Kernel Rootkit
Kernel rootkit is a type of rootkit is more terrible than the previous types. Kernel rootkits run at the kernel level (mode
not protected), or on the x86 architecture system known as ring 0. About how rootkits work will be presented at next month InfoKomputer.

4. Bootloader Rootkit
Is the type of rootkit that resides on the MBR (Master Boot Records), so as to control the course of booting the operating system. This type of rootkit is also known as Bootkit or "Evil Maid Attack",

5. Level hypervisor rootkit
This type of rootkit capable memvirtualisasikan original operating system so that the guest operating system, so that the entire control of the operating system can be taken over by this type of rootkit. One of the existing rootkit is a type SubVirt, are virtual machine based rootkits are developed by Microsoft and the University of Michigan.

6. BIOS rootkits
BIOS rootkits, collectively, the firmware rootkit, the rootkit that was the most horrible deepest level, living in the neighborhood and began active firmware when all computer activity occurred early initialization.

Poverty
There are several ways to clean up malware that uses rootkit technology on an infected computer. But the method used depends on the type of rootkit that infects, so as to overcome a bit difficult when we can not exactly know what type of rootkit that may be infecting our computers. To detect a rootkit, you should run the infected computer as a slave and use the operating system of PE (preinstalled environment) or liveCD to menginvestigasinya. There are many types of this LiveCD operating system such as DSL (Damn Small Linux)-had bundled the DVD edition of congenital magazine InfoKomputer ago - and many more. Perform scanning using special software designed to clean the rootkit, then do an investigation on areas inhabited by vulnerable rootkit. Since cleaning a rootkit is operating very close relationship with the system configuration, I suggest you ask for help to people who are experts to do so. If not careful, the consequences would be fatal.

AVI vs Rootkit
For now AVI not designed to deal with rootkits, but we will continue to develop AVI to possess anti-rootkit feature. AVI itself is currently in transition or developing the latest version (version 3), which features one of the Anti-Rootkit. Not only that, AVI version 3 also has many new features that will optimize your computer security from the attacks malicious programs. Just wait for the game date.

Next month, we will explain in more detail about how each of our rootkit described above. So, do not miss!
Read more...

Challenger Little Wormwood W32/Email-Worm.Assiral Antivirus

0 comments
Let the little, tiny worm will turn off a process related to antivirus. Small chili?
Unlike the discussions on malicious programs at the previous articles, this time I am not discussing local malware, but malware is no less foreign cried with locally made.

Which will be discussed this time was W32/Email-Worm.Assiral. He is a type of malware worm that comes from abroad and the small body size, this is why I call it a small worm. Created using programming language C + +, up to now has many variants emerged. Assiral name itself is taken from the name Larissa is reversed, showing the maker's name used to introduce himself.

Endemic and Assault

Although small, this worm has the ability to spread itself via a USB Flash storage, share directories (shared directory), and e-mail. In addition he also will try to beat the antivirus in a way to stop (kill) any process which has one of the following names: 
 
AGENTSVR.EXE, ANTI-TROJAN.EXE, ANTIVIRUS.EXE, ANTS.EXE, APIMONITOR.EXE, APLICA32.EXE, APVXDWIN.EXE, ATCON.EXE, ATGUARD.EXE, ATRO55EN.EXE, ATUPDATER.EXE, ATWATCH.EXE, AUPDATE.EXE, AUTODOWN.EXE, AUTOTRACE.EXE, AUTOUPDATE.EXE, AVCONSOL.EXE, AVGSERV9.EXE, AVLTMAIN.EXE, AVPUPD.EXE, AVSYNMGR.EXE, AVWUPD32.EXE, AVXQUAR.EXE, AVprotect9x.exe, Au.exe, BD_PROFESSIONAL.EXE, BIDEF.EXE, BIDSERVER.EXE, BIPCP.EXE, BIPCPEVALSETUP.EXE, BISP.EXE, BLACKD.EXE, BLACKICE.EXE, BOOTWARN.EXE, BORG2.EXE, BS120.EXE, CCAPP.exe, CDP.EXE, CFGWIZ.EXE, CFIADMIN.EXE, CFIAUDIT.EXE, CFINET.EXE, CFINET32.EXE, CLEAN.EXE, CLEANER.EXE, CLEANER3.EXE, CLEANPC.EXE, CMGRDIAN.EXE, CMON016.EXE, CPD.EXE, CPF9X206.EXE, CPFNT206.EXE, CV.EXE, CWNB181.EXE, CWNTDWMO.EXE, D3dupdate.exe, DEFWATCH.EXE, DEPUTY.EXE, DPF.EXE, DPFSETUP.EXE, DRWATSON.EXE, DRWEBUPW.EXE, ENT.EXE, ESCANH95.EXE, ESCANHNT.EXE, ESCANV95.EXE, EXANTIVIRUS-CNET.EXE, FAST.EXE, FIREWALL.EXE, FLOWPROTECTOR.EXE, FP-WIN_TRIAL.EXE, FRW.EXE, FSAV.EXE, FSAV530STBYB.EXE, FSAV530WTBYB.EXE, FSAV95.EXE, GBMENU.EXE, GBPOLL.EXE, GUARD.EXE, HACKTRACERSETUP.EXE, HTLOG.EXE, HWPE.EXE, IAMAPP.EXE, IAMSERV.EXE, ICLOAD95.EXE, ICLOADNT.EXE, ICMON.EXE, ICSSUPPNT.EXE, ICSUPP95.EXE, ICSUPPNT.EXE, IFW2000.EXE, IPARMOR.EXE, IRIS.EXE, JAMMER.EXE, KAVLITE40ENG.EXE, KAVPERS40ENG.EXE.

List the name of antivirus programs are just a small part, actually still very much to save the page so not all written here. But if you notice, a process that killed the processes related to anti-virus. So it seems this worm to disable the antivirus application to then make a larger attack.

Besides trying to attack antivirus programs, this worm also tried to beat the seperjuangannya friend who has W32/Worm.Bropia another name IM-Worm.Win32.VB.a. W32/Worm.Bropia also a propertied foreign worm spreading ability itself through instant messenger or Intant Messenger. This is why there is a sign of "IM-Worm" at the beginning of its name, the sign that usually provided by antivirus developers to mark the characteristics of a malicious program.


When first run, will create bookmarks W32/Email-Worm.Assiral himself a mutex (Mutual Exclusion) with the name "-)(-=| L4r1 $ $ 4 Note |=-)(-". mutex is typically used for inter singkronisasi application or thread reply contained in most multi-threading applications. But here, mutex Assiral worm used to mark him with the intention to prevent re-infection (reinfection) on washed-infected computers.

For the sake of keeping himself in order to keep running every time the computer is turned on, this worm will create 3 triggers by adding value to the address registry: HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run

Registry keys made, among others:

* "MSLARISSA" => leads to: "[system-dir] \ MSLARISSA.pif"
* "Command Prompt32" => leads to: "[system-dir] \ CmdPrompt32.pif"
* "($ 4 $ L4r1) (4nt1) (V1ruz)" => leads to: "[a win-dir] \ SP00Lsv32.pif"
* Try to open the browser directly to the destination address "http://roattack.go.ro".
* Trying to convey a message to the user and antivirus products by writing a message in the file "C: \ MESSAGE_TO_USER.txt", "C: \ MESSAGE_TO_AVs.txt", and "C: \ MESSAGE_TO_BROPIA.txt" which contains: 
 
C:\MESSAGE_TO_USER.txt:
Greetz to infected user!
I will survive
In this moment in time.
Your computer will crash,
So, you will be mine.
I will not crash,
I will not fail.
So, in this moment in time,
I will survive...
– LARISSA AUTHOR

C:\MESSAGE_TO_AVs.txt:
Greetz to AVs!
I wanna be in AV industry when I grow up :-)
  ---------------------------------------- 
       - LARISSA AUTHOR

C:\MESSAGE_TO_BROPIA.txt:
Hey Bropia.. stop making MSN worms it's stupid...
... lol -- Larissa Anti Bropia... -- Saving the world from BROPIA!!!
         - LARISSA AUTHOR

Cleaning and Prevention

To clean this worm, you can simply run the AVI which was updated you can get the DVD of this magazine innate or download at: http://www.infokomputer.com/avi/download-avi/download-link-for-avi. For prevention, install AVI as a real-time protection, and do not forget to always update your AVI to always up-to-date.
Read more...

W32/Moonlight.L: Moon Light Hazardous

0 comments
Although classified as a veteran, this worm still exist thanks to the emergence of variants. Do not want exposed to the harmful rays? Be careful and put AVI.

"Moonlight", so the worm type malware is named herself. Local worm actually been around since W32/Brontok or W32/Rontokbro era, but still exist until now. This is because variants that keep coming up now, even many reports from users of computer AVI infected by this worm. Because of that, I was interested to discuss the issue of Moonlight at this time.


Characteristic

Made using the compiler W32/Moonlight mainstay vxer (term for malicious programmers) that local VB6 (Visual Basic 6) and compressed using FSG packer PE programs. Original size of 324 KB, and after compressed to 144 KB. Its own identity using Windows XP folder icon standard.

Action (Payload)
When first run, W32/Moonlight.L will create the file "systear.dll" in a system directory, example: "C: \ WINDOWS \ system32 \ systear.dll". This file is an initialization file so that the worm can identify himself and to mark the position where the worm has spread. After that, create a file of supporting Moonlight shaped dynamic link library (DLL) "moonlight.dll" in the Windows directory (example: "C: \ WINDOWS \ moonlight.dll") and extract the MIDI-formatted music files "onceinabluemoon.mid" to the Windows directory . After that, the worm makes a directory with a random name in Windows and System subdirectory in the format "C: \ WINDOWS \ [random]". Mean "[random]" here contains random names such as:
"C: \ WINDOWS \ FLR1S4G"
"C: \ WINDOWS \ system32 \ LDF6I7R"
Use a random name is probably intended to complicate the process of investigation and cleanup.
Then the worm will reproduce itself in the following places:
* C: \ WINDOWS \ [random] \ service.exe
* C: \ WINDOWS \ [random] \ smss.exe
* C: \ WINDOWS \ [random] \ system.exe
* C: \ WINDOWS \ [random] \ winlogon.exe
* C: \ WINDOWS \ lsass.exe
* C: \ WINDOWS \ system32 \ [random] \ [random]. Cmd
* C: \ WINDOWS \ [random]. Exe
* C: \ WINDOWS \ system32 \ [random]. Exe
* C: \ WINDOWS \ [random] \ [random]. Com

W32/Moonlight.L deliberately duplicate themselves with names similar to the Windows services such as innate "smss.exe", "service.exe" with the intention that the process is not easy to stop using the Windows Task Manager built. Keep in mind, the Task Manager will refuse to stop the process with the name include: "service.exe", "smss.exe", "system.exe", "winlogon.exe", and "lsass.exe".

Because the worm is made using VB6, and because each application requires VB6 runtime named "msvbvm60.dll", the worm is smart strategy to make the runtime file is not deleted or deleted (which makes the worm can not run). Way, by making backups of the runtime files to "C: \ WINDOWS \ system \ msvbvm60.dll".
Another thing done is to make Moontime file named "MooNlight.txt" in the Windows directory (example: "C: \ Windows \ MooNlight.txt"). This file contains a message from the creators who called himself the nick "Lunalight" aka "Moonlight":


Endemic

W32/Moonlight.L dissemination is very similar to the worm aka W32/Brontok legendary W32/Rontokbro, by doubling itself to every directory with a name similar to the parent directory.

Cleaning and prevention

Fairly easy to clean, you need to do is run the AVI (Antivirus Info Computer) that has been bundled into one DVD inherent in this magazine. Run, and do checks to each location and storage media connected to your computer. Keep in mind, do not do any activity during the review process. For prevention we recommend you to install the AVI as a guard to prevent your computer infected by this worm again.


AVI 2.0.4.9 Changelog:
* Improved buffer overflow bug that caused crashes when AVI to update online.
* Improved compatibility bug with Windows Vista / 7.
* Improved access violation bug that caused crashes AVI while scanning.
* Improvement of detection of some Windows system files 7.
Read more...

AVI + Clamav: Tens of thousands Tree Attack

0 comments
One of the advantages is the existence AVI add-on (plugin). Thanks to this facility, capacity can be improved AVI easily. One of the latest add-on is owned AVI Clamsav. This is the add-ons that integrate the database into a database Clamav AVI. That way, AVI now can ward off tens of thousands of types of attacks, both locally and internationally. One who makes a good antivirus in detecting computer viruses is the definition of the threat they have. The more definition, the better antivirus in a variety of threats facing trying to enter into the computer.


AVI is one of the local antivirus that has a number of threats that limited definition. So far, the database contains AVI more local viruses. This limitation is because the number of new viruses AVI users reported only ranges from Indonesia alone. This is why many people consider the local anti-virus only works to overcome local virus alone.

And vice versa, only a potent antiviral out beyond just tackle the virus. Based on these facts, many people who eventually install two antivirus at once: one local antivirus, antivirus one out.

But the AVI has a smart solution for solving this problem. AVI now have add-on (plugin) that integrates new AVI with Clamav antivirus engines. What is Clamav? Clamav antivirus which is developed by the developers of the open source community http://www.clamav.net GPL (General Public License). You can get more information about Clamav on his official website. Current definition of a recognizable threat Clamav approximately 49 thousand threats mostly dominated by foreign viruses. Now, by combining the original database and Clamav AVI, AVI is now able to recognize approximately 50 thousand threats!

 How to Use Clamsav Plugin

To take advantage of add-on Clamav, ekstraklah file "plugin-0.4-clamsav-avi.zip" into the directory "plugins" which can be found at the location where AVI installed. For example you install the AVI in the directory "C: \ Program Files \ AVI" then ekstraklah to "C: \ Program Files \ AVI \ plugins".

Clamav add this file yourself you can get here. Make sure the add-on has been successfully integrated. How to run the AVI, then see the "Plugins". If you see a new add-shell-shaped symbol, it means that add Clamav has been successfully integrated with AVI. To make sure whether the add-Clamsav been able to work well, try double-click on the icon shaped shells. I'll get a window with information about add-on version, version of the definition of the threat, the number of threats, and info about the last definition update.


















To determine whether the definition of threats that can be recognized by the AVI has increased, you can see it in the "Signature". When we use the definitions of August 13, 2009, the number of definitions reaching over 64 thousand pieces. After the successful add-on installed, AVI automatically be able to detect foreign viruses or viruses that have not been recognized by the AVI using Clamav engine. The threat is successfully detected by Clamsav have a mark on the columns of information as you can see in the picture below. You still can disable the add-on that does not come Clamsav scanning by removing the check mark on the window Clamsav the "Settings"> "Enable plugin".










Threat definition update Clamav

You can update Clamav definitions of threats in a way to download the file "daily.cvd" and "main.cvd" Clamav site. Put the two files in the directory where the add-Clamsav placed. Please note that the file "daily.cvd" is always updated every day.
Read more...

Beware! Presence of a trigger VoIP Spammers

0 comments
As we know, spam is an "enemy" email users. Her presence was already terendus for years. Then, still remember you with 419 spam? Yes, spam related to the 419 present the emergence of spam Harry Porter, a name of "slippage" of the Harry Potter character. In July, the spam is claimed amounted to 419 for 9% of all spam.

419 spammers usually enter the users email through a text-based email, document, document in the form of word, PDF format, and even now they are also often appear on sites such as Facebook friends.

Well, of all attempts to send spam is 419, found a similarity, namely false story about the inheritance money in large quantities, familial and financial aid are notified through written messages.

However the business of the owner to block the arrival of email spam, but spammers have a thousand ways and continue to seek techniques that can bring them to the owner of the inbox. The way the other can not avoid anti-spam filters.

Recently, Symantec found a new variant of spam 419, which in this case spammers trying to exploit the service Voice over Internet Protocol (VoIP). From there, spammers will create fake accounts on sites that provide VoIP services, then this false account used to send users email invitations to invite friends using the function / invite friends via VoIP services.

On the face of spam messages that have signed the invitation will look like the original VoIP, but here in action with a slipped spammers 419 stories related to the fund or inheritance in the invitation email message.
Read more...

Virus alert "Deadlock", The message is positive but Destroy Computers

0 comments
KOMPAS.com - The message was positive with words that evoke patriotism. However, do not be lulled into sweet words that brought a new local computer virus called Deadlock. Check out the following message.

Indonesia freed our country from terrorism, Anarchists, and CCN (Collusion, Corruption & Nepotism) at the Government of the Republic of Indonesia Kubu (Civil, Army & Police) and the Catch, Fight and spacing? Without exception. Clean us from Portitusi Affairs, Social Gambling and Crime. Merdekakan ourselves from Poverty, Misery and Injustice! Along with the Democratic Party? SBY & BOEDIONO, Indonesia Joint Building Fair, Makmur & Prosperous

In the Name of the Indonesian nation
Prince Deadlock

I? M Everyone, but No one
I? M Everything, but Nothing
I? M Everywhere, but Nowhere

If your computer suddenly displays a picture with the message (see picture), you are advised to immediately take action. The reason your computer is attacked by a virus that is active and deadly.

The virus will display the message in the desktop that has taken over. Usually this message will only appear at the appointed time. Along with the emergence of this message, then all files in all drives will be deleted, including the program and the file system of Windows.

So, if you see this message on your computer, chances are it's too late for a minute of data on your computer will be destroyed. Like the saying goes "calm waters washed away", apparently in these viruses keep silent time bomb in the victim computer to be activated in accordance with the time specified.

Peak, on 12 and 13 later, Deadlock will make your computer completely destroyed deadlock aka all the data, good data throughout the hard drive, flash, and Windows file that displays the message "NTLDR is Missing".

Recognize characteristic

The virus is actually still go to the family of Visual Basic program is compressed using 2.x Petite sizes around 80 KB. Icons that are used are also not camouflaged, still use the application icon and probably came from one of the cities in Kalimantan (Samarinda).

If the virus is active on the computer, it will create some files that will run on your computer when switched on.
- C:-Windows-system32-apache.exe
- C:-Windows-system32-mysql.exe

Selection name apache and mysql likely aimed at disguising himself as a popular programs Apache and Mysql. In order for these files can be automatically activated when the computer starts, he will make a few strings in the following registry:
-HKEY_LOCAL_MACHINE-SOFTWARE-Microsoft-Windows-CurrentVersion-Run
-mysql = C:-Windows-system32-mysql.exe
-HKEY_LOCAL_MACHINE-SOFTWARE-Microsoft-Windows-CurrentVersion-Run
-apache = C:-Windows-system32-apache.exe

The virus is quite clever in fooling the user. Users will not be suspicious if the computer is actually infected because there are no signs that usually done by other local viruses, such as disable the Task Manager / Msconfig / Regedit or Folder Options, other than that created the file did not suspicious because it seems to be the program Apache and MySql. Users realized that the computer has been infected at the time of late, which at that time will appear the message from the virus makers are then followed by the emergence of the message "Windows File Protection error". This indicates that there is a program that seeks to remove the Windows system files.

This virus will start automatically each time users access a drive / flash disk by using the Windows autorun by making fruit 3 files, namely:
- [Desktop.ini] that contains the script to run the file [folder.htt]
- [Folder.htt], contains the script to run the main file ie [flashguard.exe]
- [Flashguard.exe] is a master file that will be run.

Flash media is one of the most widely used by the user. This is what will be used by some even virtually all of the virus to spread itself. This will also be carried out by a virus Deadlock by making some of the following files.
-Desktop.ini
-Folder.htt
-Flashguard.exe

Time bomb

Virus Deadlock like a time bomb that will destroy the target computer at the appointed time. This virus will execute the action every 12-13 dated at about 08.00-09.00 each month by ALL ERASE FILE / DATA INCLUDING WINDOWS FILE SYSTEM in all drives, including flash media using the command cmd.exe / c del / f / s / q / a and cmd.exe / c rd / s / q so that, if the computer is restarted, it will display the message "error".

So, the best way to anticipate, do not forget to do a back-up data. To prevent this viral infection, you are advised to use antivirus program that can detect this virus very well.

According Vaksincom Lab testing, current viruses detected by Norman as Deadlock not detected by the majority of existing anti-virus in Indonesia, both local and antivirus antivirus abroad. Norman Endpoint Protection detected the virus as Tibs.DKKR Deadlock.

If you want your data to be victims of this Deadlock again, never to reinstall your operating system to a hard drive that contains your data is lost. Perform critical data recovery process by using a data recovery and true methods.

If you reinstall your operating system to a hard drive that contains data you want to save, likelihood of successful recovery will be very low. If you are not experienced in data recovery and want to get professional help with data recovery of reasonable price, please contact the division Vaksincom Data Recovery in an e-mail info [at] vaksin.com.
Read more...

Time To

0 comments
As a complement and companion you every time, take advantage of Time To free the application of this. There are facilities "Memorizes" that will remind you of the commitments and agreements meeting.

There is also a menu "Balance" which can be used to mencata priorities, deadlines, and time budget. If there is a commitment which ultimately clashed job, you will be given a warning

This application is equipped with a calendar and notes, but unfortunately no list of contacts. However, this application is equipped with an alarm facility reminders, notes web page, pendata files, until the facilities Skype calls. You can also use it to install it on a portable flash disk. Facilities to import and export-related applications are also available.

Although slengkap facility, unfortunately, the visual appearance is rather tersepelekan applications. These applications seem outdated when viewed from its interface. To use, in the beginning you may be confusing and need to habituation process.

There are options to balance the schedule of activities, but still done manually. You can move the schedule from one time to another time if necessary simply by clicking on the entry attracted to schedule another time. Time for business, the stopwatch facility was very helpful. This timer will calculate an activity or project work.

As pendata schedule, Time To be very useful. Indeed, without the facility contact list, this application was lame. However, given the complete features, plus features synchronization with handheld devices, support 17 languages, and others, not easily turned away from Time To.
Read more...

Labels

 
Temporary © 2011 DheTemplate.com & Main Blogger. Supported by Makeityourring Diamond Engagement Rings

You can add link or short description here