Showing posts with label Tips And Tricks. Show all posts
Showing posts with label Tips And Tricks. Show all posts

Wednesday, February 9, 2011

'Take the Classroom',Local Virus Make Cracks in Windows

Indonesia's Most
local virus attacks by using the
user mere negligence. But this one
virus has been 'first class' by
exploiting Windows vulnerabilities.
The presence of virus was
delivered by antivirus researchers
of Vaksincom, Alfons Tanujaya.
"He made a shortcut and exploit
vulnerabilities. Seldom local virus
exploits a security hole," said
Alfons to ITGazine, Thursday
(26/08/2010).

Adang Jauhar Taufik, antivirus
Vaksincom analyst, said the first
report of this virus came from the
city of Gorontalo on Sulawesi. The
spread of this virus is known via a
USB Flashdrive.

These viruses change the folder
that is in the USB stick into the
shortcut. Then, if a shortcut is
accessed virus will infect the
computer until the computer's
performance become poor.

In addition, Alfons said, this virus
to protect himself from the tool as
Security Task Manager or other
process killer application. If used,
the application could hang or die.

"Apparently, the virus makers pay
attention to virus eradication
articles Vaksincom often using
Security Task Manager. So if
cleared, he was prepare," said
Alfons.

Cracks are utilized by this virus is a
Microsoft Windows Shell shortcut
handling remote code execution
vulnerability, MS10-046. Microsoft
has provided a patch to patch
this vulnerability .
Norman Security Suite detects this
virus as W32/VBWorm.BEUA. For
its shortcut files identified as Trojan:
LNK / CplLnk.A and files. DLL
detected as W32/
Suspicious_Gen2.BTDDL.

Dr.Web Anti-virus detects the virus
as W32/HLLW.Autoruner.25850.
File shortcuts are recognized as the
Exploit.Cpllnk and files. DLL
detected as Win32.HLLW.VBNA.3.

Adang said the virus is created by
using Visual Basic language
program. Viruses with the size of
128 KB it thinks will have the
extensions EXE or SCR, as well as
Microsoft Visual Basic Project icon.

8 Steps Viruses Ejecting Exploiters Windows Gap

W32/
VBWorm.BEUA The presence of
virus, better known as a shortcut
virus that exploits the security hole
is quite disturbing. For, although
labeled local virus, he not only take
advantage of user negligence. But
has 'first class' to break through
Windows security holes.

Consider the 8 practical steps to
kick the virus is able to change the
folder that is in the USB flash disk
into the shortcut, according to
Jauhar Adang Taufik, an analyst
with Vaksincom:

1. Disable 'System Restore' for a
while during the cleaning process.

2. Decide who will clean your
computer from the network.

3. Turn off the virus active in
memory by using the tools 'Ice
Sword'. Once the tools are
installed, select the file that has the
icon 'Microsoft Visual Basic Project'
and click 'Terminate Process'.
Please download these tools at
http://icesword.en.softonic.com/

4. Delete the registry that has been
created by the virus by:
-. Click the [Start]
-. Click [Run]
-. Type Regedit.exe, and click the
[OK]
-. In the Registry Editor application,
browse the key
[HKEY_CURRENT_USER \ Software \
Microsoft \ Windows \
CurrentVersion \ Run]
-. Then delete the key that has the
data [C: \ Documents and Settings \
% username%].

5. Disable the autoplay / autorun
Windows. Copy the script below in
notepad and then save it as
repair.inf, install the files in the
following manner: Right-click
repair.inf ->

INSTALL

[Version]
Signature = "$ Chicago $"

Provider = Vaksincom

[DefaultInstall]

AddReg = UnhookRegKey

DelReg = del

[UnhookRegKey]

HKLM, Software \ CLASSES \ batfile
\ shell \ open \ command ,,,"""% 1
""% * "

HKLM, Software \ CLASSES \
comfile \ shell \ open \
command ,,,"""% 1 ""% * "

HKLM, Software \ CLASSES \ exefile
\ shell \ open \ command ,,,"""% 1
""% * "

HKLM, Software \ CLASSES \ piffile
\ shell \ open \ command ,,,"""% 1
""% * "

HKLM, Software \ CLASSES \ regfile
\ shell \ open \ command,,,
"regedit.exe"% 1 ""

HKLM, Software \ CLASSES \ scrfile
\ shell \ open \ command ,,,"""% 1
""% * "

HKCU, Software \ Microsoft \
Windows \ CurrentVersion \
Policies \ Explorer
NoDriveTypeAutoRun, 0x000000ff,
255

HKLM, SOFTWARE \ Microsoft \
Windows \ CurrentVersion \
Policies \ Explorer
NoDriveTypeAutoRun, 0x000000ff,
255

6. Delete Files parent and duplicate
files are created by the virus
included in the flash disk. To
expedite the search process, you
can use the 'Search'. Before
conducting the search should
show all hidden files by changing
the Folder Options settings.

Do not let an error occurs when
deleting a master file and duplicate
files that have been created by the
virus. Then delete the master files
that have virus characteristics:

-. Icon 'Microsoft Visual Basic
Project'.
-. File Size 128 KB (for other
variants will have varying sizes).
-. Ekstesi file '. EXE' or '. SCR'.
-. File type 'Application' or 'Screen
Saver'.

Then delete the duplicate shortcut
files that have the characteristics:

>. Folder Icon or icons
>. Extension. LNK
>. File Type 'Shortcut'
>. 1 KB file size
Delete the file.

DLL (example: ert.dll)
and Autorun.inf file on flash disk or
a shared folder. Meanwhile, to
avoid the virus is active again,
delete the master file that has an
EXE or SCR extensions first and
then remove Shortcut file (. LNK).

7. Show re-folders have been
hidden by the virus. To speed up
the process, please download the
tools Unhide Files and Folders in
http://www.flashshare.com/bfu/
download.html
.

Once installed, select the directory
[C: \ Documents and Settings] and
folders that exist on the flash disk
by moving into fields that are
already available. In the [Attributes]
clear all the options, then click the
[Change Attributes].

8. Install security patches 'Microsoft
Windows Shell shortcut handling
remote code execution
vulnerability, MS10-046'. Please
download the security patch at
http://www.microsoft.com/
technet/security/Bulletin/
MS10-046.mspx

As usual, for an optimal cleaning
and Prevent re-infection, should
install and scan with antivirus
software up-to-date and was able
to detect this virus very well.

Thursday, February 3, 2011

7 Tips For Keeping Passwords

Password is a secret
code that must be protected. Many
negative things can happen
when your password leak into the
hands of others. Learn 7 tips to keep
it brief.

1. Not Using Default Password
The default password is the
password that we can be the first
time. This default password should
indeed be quickly replaced because
of very vulnerable. The reason, the
default password can be easily
searched on google search, even
there are listed the name of a
machine, type and default password
with a magnificent plastered on
some website creators vendors.

Sometimes administrators fear of
forgetting to change-change the
default password, so that an
intruder can take over the system
with default passwords.

Wearing 2.Not Password Hint
Sometimes we are afraid to forget
the password that was our entry
into the system / account, so we
need to create a reminder if we
forget the password. Now this is
called password reminder Hint, if
we create a password hint question
with this then we can quickly recall
these forgotten passwords.

Likewise with the hackers, they'll
experiment with us to guess the
password in the password hint
questions, over time the password
will be predictable, if the questions
listed in the password hint can be
answered by the guesst
password.

Writing 3.Not Password
Owners are often afraid to forget
your password with the password
has been entered, so the owner
would write different passwords
user id and password into other
media such as a notebook, notepad,
Stickies (mac), password folders,
books, mobile phones and other.

It is also quite vulnerable to leaking.
Why vulnerable? Because if the
various equipment is lost, then all
information about a user id and
password are sooner or later will be
known by the thief equipments /
gadgets are missing.

4.Use a Strong
Password
Owner passwords often using a
short password only, if it could be
shorter than 3 characters then the
user will give a short password.
Fortunately this time the system
provides a minimum password
length of 6 characters and a
maximum of 254 characters. The
longer a password the stronger it
will be the password security.

Strong passwords can be created
with a combination of numbers and
letters and even a variety of other
characters. Some admins are
currently using a password that is
long enough, coupled with
encryption such as PGP key and
others, so it is quite difficult to guess
password.

5.Often Change Password
Owners should periodically change
your password for authentication
password, the more frequent
password changes, the better,
because the more difficult the
guess password hacking
account / your system. Changes to
the password depends on the
owner, could be a week, a month,
three months, and others. Originally
the owner does not forget the
password that was changed earlier.

6.Not Using Same Password
on Multiple Accounts
Owners often forget and sometimes
passwords frequently enough to
create an account, so they each
create a new account using the
same user id and password are the
same, this is very vulnerable and
dangerous. Because these
passwords through a single
account, all accounts will be taken
by the hacker.

7. Using Password Management
To help recall the various
passwords and various accounts,
we are often very difficult, but not to
worry because it has many current
applications to help organize our
passwords. This application can be
downloaded for free from the
internet and paid, so that regardless
of our account and whatever we
can with the password easy to
remember and re-opened, of
course, to open it with an
encryption method as well.

*) The author is IGN Mantra, Senior
Analyst Network Security and Traffic
Monitoring Internet ID-SIRTII once
Lecturer Network Security and
Cybercrime.

3rd Stage Opening Windows With Ubuntu Password.

Lost is a common
problem faced by humans. If you
forget your Windows login
password, no way to recover it
using the Ubuntu Linux operating
system.

The first thing to do is create a
Live CD or Live USB stick Ubuntu
Linux. Ubuntu Live will be used to
boot into the system and perform
the procedures required to
dismantle the Windows password
earlier.

The easiest way to do that is by
downloading UNetbootin and run
it. This simple application will
download the selected Ubuntu
version and install on the flash that
you prepared.

The second stage is to install
Open Source utility called chntpw.
This is done from Ubuntu by
running Synaptic Package Manager.

To be able to get chntpw, Synaptic
Package Manager should be directed
to look at storage applications
Universe. This can be done by
clicking the Settings menu>
Repositories in Synaptic window.
Then, check the option
'Community-maintained Open
Source software (universe) "and
click Close.

After that, click the Reload button
and Synaptic will download the
latest package information from the
Universe. When finished, type
chntpw on the Quick Search box.

If it appears, check the box on the
side chnptw writing, choose 'Mark
for Installation'. Then click Apply to
install it.

The third stage is to change the
Windows password with chntpw.

1. Mount the hard disk / drive that
contains your Windows installation
2. Open the hard drive it (click on
Places) and record labels drive that
appears on the menu bar window
file browser
3. Open a Terminal window
(Applications> Accessories>
Terminal)
4. Type the following command in
Terminal:
cd / media
ls
5. Type: cd [label hard drive that
you noted earlier]
6. type: cd WINDOWS/system32/
config
7. To change the Administrator
password, type the command:
sudo chntpw SAM
8. You will see several commands
that you can choose, the command
is safest to create a password to be
blank. Do this by pressing the
number '1 ', then press' y' to
confirm
9. Select '2 'to change the password
to a particular word, but this has a
greater risk of error
10. To change the passwords of
other users (non-administrator),
type the following command (from
Terminal): sudo chntpw-u [user
name] SAM

Eradicate Tips Ramnit Of Computer Viruses.

Although relatively
new, but the rapid spread of the
virus Ramnit indeed. In fact,
because of sophistication that is
able to download other viruses,
malicious programs are classified as
one of the trojan that difficult to
eradicate.

Well after learning characteristics
-characteristics, here are the steps to
remove viruses delivered Ramnit
Alfons Tanujaya, Vaksincom
antivirus analysts, to ITGazine,
Tuesday (02/01/2011).

Because infected files ending in exe,
dll, and html, then cleaning should
be done in DOS mode. To facilitate
cleaning please use the Windows
Live CD Mini PE, then downlad free
tools Dr.Web CureIt!

To be optimal, we encourage all
media including hardsisk and flash is
scanned first. This is because
Ramnit will put some storage
media.

Before doing the cleaning should
block viral duplicate files by using
the feature 'Software Restriction
Policies'. This feature is only there
on the operating system Windows
XP Pro, Vista, 7, Server 2003 and
Server 2008.

Connect an external flash or any
hardsik to the computer. Then
download the application free Dr
Web Live CD at the following sites.
After it was over done, the user can
continue the following steps.

After a successful software Dr.Web
LiveCD download, burn into CD /
DVD
Connect the flash and external to the
computer hardsik
Booting the computer through a
CD / DVD ROM
This will bring up the screen
'Welcome to Dr.Web LiveCD
Select 'Dr.Web LiveCD (Default)' and
press 'Enter' key on your keyboard
Wait a few moments to appear
Dr.Web LiveCD interface that will
display the applications 'Dr.Web
Scanner' automatically. Dr.Web
Scanner is working to examine your
computer from possible virus
To scan the hard disk, on screen
'Dr.Web Scanner' select location of
the drive to be in check and make
sure you check list option 'Scan
subdirectories' for Dr.Web can
conduct examination on the
directories and subdirectories for
optimal cleaning. If the screen does
not appear Dr.Web Scanner double
click the icon 'Dr.Web Scanner'
found on the Desktop.
Then click the [Start] to begin the
examination process
Wait a while until the scan is
completed. If you find any viruses,
Dr.Web will inform the infected file
and the type of virus that infects the
virus information is available
column.
Click the [Select All] to select all the
objects / files to be in the clear or
you can specify which files would
you clean it with a check list on the
options available
then click the [Cure] to clean up files
that have been infected with a virus
Wait until the cleaning process is
completed
Scan the computer to ensure clean
your computer from viruses
Restart the computer.

Beware Virus Attacks Ramnit.

After some
horrendous virus like Stuxnet, Sality,
Virut and Shortcut, there are now
Ramnit that is equally sophisticated.
This malicious program is able to
'cooperate' with other viruses to
infect the victim.

Yes that's the uniqueness Ramnit
compared with other viruses. After
infect the victim computer, these
malicious programs will download
variants of other viruses.

And even more confusing, the type
of virus that you download will be
different for each target computer
either from the name and size. This
is what causes many antivirus
programs although difficult to
perform detection and cleaning.

This virus not only
spreads via the Internet, but also
through other media such as flash
by using the Autorun function.

Another action that will be done by
this virus is injected exe files that
have extensions, etc. and htm /
html file either an application
program or Windows file system.
Each file is injected to increase the
size of about 107-109 KB.

Sunday, January 30, 2011

5 Steps To Clean Up Account

A malicious
program that scalp name
'McDonalds' sprang up. If a victim,
your Facebook account will
distribute it to all contacts.

Of course it is very annoying. In
addition there are also potential used
for the benefit that can not be
accounted for.

Then, how do I fix this? Consider the
following steps as presented Alfons
Tanujaya, Vaksincom antivirus
analysts, who quoted on Saturday
(10/30/2010):

If you have already become victims
and spread the Event Invitation to all
your contacts, immediately inform
all contacts up to you to not click the
link provided let alone to approve
the installation of the application.
Click the [Account] [Privacy
Settings]. You will open a menu of
"Choose Your Privacy Settings"
Click [Edit your settings] from the
menu "Applications and Websites"
in the lower left corner to open the
menu of "Choose Your Privacy
Settings> Applications, Games and
Websites"
Click [Remove unwanted or
spammy applications] to open the
screen "Applications, Games and
Websites> Applications You Use"
and click the X on the "Edit Settings"
You will get a confirmation screen
Remove, click the [Remove] to
remove the program HD Video
Player.

6 Thing Forbidden By Dispel Spam

Global spam volume
may decrease, but pointed out the
danger level rises. Here are six
things to avoid to dispel the spread
of spam.

In a monthly report Symantec
Messaging and Web Security
quoted on Wednesday (24/11/2010)
mentioned that the global volume of
junk email (spam) decreased.

However this is not a reason to
become complacent and no longer
perform the required safety
procedures.

Well, here are six things you think
Symantec should not be done by
Internet users. The ban is necessary
to block the spread of spam.

1. Opening email attachments
from unknown
Do not be tempted to open an
attachment in an email that looks
suspicious. Sometimes the
attachment is a name that is
tempting, but it could be the
contents are malicious programs.

2. Replying to spam
Perhaps because of upset or other
reasons, users may be tempted to
reply to spam email with the oath-
curse or a request to not send
emails anymore.

Be careful, because usually the
address used was a fake and if
returned it will give birth to more
spam back to the Inbox.

3. Fill Form via Email
Tricks of data theft often do is to ask
potential victims to fill personal data
through forms that exist in the
email, or form that the link is
displayed in the email.

Symantec said the company is not
leading you may ask for personal
information via email. If in doubt,
contact the company through the
official channels separately. Do not
click or copy-paste from the link in
the message.

4. Purchase products or
services from spam messages
Although the product or service that
sounds interesting, you should not
try to buy products or services
offered via spam. This will only
encourage people to continue using
spam.

5. Opening spam messages
If a message is spam is obvious, for
example because it is characterized
by the Spam Filter is used, this
means that the message was
already supposed to be discarded.

6. Chain Email Forwards
Many warnings about viruses,
security dangers and other things
that spread by email. Because there
is a possibility that kind of thing only
a rumor (hoax) alone, should not
the bandwagon to send the
message chain.

4 Ways Of Preventing Phishing Scam Customer.

Action aka phishing
attempts targeting the theft of
sensitive information that bank
customers have repeatedly
occurred. Here are four tips adala
who could hold onto customers so
as not to fall for the trick-trick this
action.

1. Origin Check Email
Usual mode waged cyber criminals
is to send an email teaser to a
number of people. The contents of
electronic mail will usually ask the
prospective victim to visit a
particular site, to then re-register
(include your username and
password e-banking customers.)

Well, for those customers do not
necessarily believe if you get an
email with a model like this. First
check the origin of the sender's
email, if using an official email
domain from a particular bank or
not.

Because, if they use the email
domain is not clear, it need not be
trusted email. Although at the end of
their email claim from the
concerned bank.

2. Not Quite Through Email
Re-register by entering your
username and password is a
sensitive activity. So, delivery-
related information of this activity
also can not be arbitrary, only via
email.
A number of banks admitted if they
want their customers to re-register,
they usually do not just let me
know via email.

But also through
more personal means, namely
contacted directly. There also are
using an official letter, although the
combined-match with the email as
well. At least, the bank treats these
events with more professional.

3. Reverse Phone
Do not hesitate to call customer
service bank you use. Better to be
alert, rather than hesitate, but
instead led to bad things for you.

4. Distinguishing Genuine or
Fake Site
Sites that financial institutions use to
login normally have a security
system tighter. First, see the website
address. Site logins should use the
prefix 'https' instead of 'http'. Https is
a secure version of http.

Suffix 's' in 'http' indicates that these
sites actually have 'secure', because
the technology is protected by
Verisign SSL encryption of data.

On the site e-banking, Bank
Permata is asphalt , also
contained the logo 'Security Verisign
Site'. To the layman, it would be
difficult to distinguish. That can be
one benchmark validity of an e-
banking site is the URL that is written
is 'https'.

Then at the bottom right of the
browser (for Firefox) there is a
locked padlock image. As for
Internet Explorer (IE), this yellow
padlock in the URL field.

If the victim involuntarily fill your
username and password in asphalt
sites, it can be ascertained that such
personal data, including records e-
banking activities of his, will be
known by other parties who are not
responsible.