Sunday, April 20, 2008

Worm.Win32.Netsky Removal Process

Worm.Win32.Netsky is a new rogue anti-spyware program trojan, which is part of a fake malicious software engineered by Internet hackers. Worm.Win32.Netsky-related anti-spyware is a fake anti-spyware program. Do NOT purchase Worm.Win32.Netsky related spyware under any circumstances since it is a fake anti-spyware software.

The following process will help you remove it from your system easily and safely.

Worm.Win32.Netsky Manual Removal Process:

1. Click on the Start Menu button, then click on the Control Panel option, and then Double-click on the Add or Remove Programs icon.
2. Locate Worm.Win32.Netsky and double-click on it to uninstall Worm.Win32.Netsky. Follow the screen step-by-step screen instructions to complete uninstallation of Worm.Win32.Netsky.
3. Restart the computer.
4. When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.
5. Close all programs.
6. Stop Worm.Win32.Netsky process. If you do not know how to stop a running process, click here to read more.
7. Delete the following infected files from your system.
EasyAV.exe
EasyAV
secound_document4.pif
e-mail3.pif
approved_file7.pif

Remove Worm.Win32.Netsky with SmithfraudFix:


1. Download SmithfraudFix tool and save it to your desktop.
2. Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
3. Double-click SmitfraudFix.exe
4 Select 2 and hit Enter to delete infect files.
5. You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
6. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
7. A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt

Restore Trusted and Restricted site zone
1. To restore Trusted and Restricted site zone, select 3 and hit Enter.
2. You will be prompted: Restore Trusted Zone ? answer Y (yes) and hit Enter to delete trusted zone.

Search
1. Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.tx

(Disclaimers: These instructions are free and not guaranteed to work. Please use it at your own risks. We are not responsible for any damages.)

Monday, April 14, 2008

How Torrent works - Security

Torrent does not involve any type of active desktop software, unlike other file transfer services such as LimeWire and Napster. There are multitudes of Web sites throughout the Internet where you can search for Torrents. Torrents are active Internet connections that download a specific file you are looking for--referred to in the Torrent network as “seeds.” In order for a seed to be available, someone with the file you are looking for must have the Torrent window open. The Torrent window can either be open when someone is downloading the file for themselves from another seed, or once the file has been downloaded, the Torrent window can remain open to allow other people to download the completed file.

Something that makes Torrent unique is that you are never downloading a single completed file from a single vendor. Instead, you are downloading small segments of data that when put together, create the desired file.

Torrent Security

Torrent is a much safer service than other peer-to-peer networks because of how it functions. While other peer-to-peer services allow a certain degree of access to a shared folder or someone’s hard drive, Torrent users cannot share anything outside of the desired file type that is in an open Torrent window.

Due to the fact that you are only downloading segments of the file as opposed to the full thing, it also makes it incredibly difficult (if not impossible) to transmit viruses through the Torrent system. There are a number of people who are opposed to peer-to-peer technologies because of possible security concerns, however, virtually none of these concerns are found in the Torrent service.



Thursday, March 20, 2008

Remove Win32 AutoRun Worm-Funny UST scandal

Win32 AutoRun Worm-Funny UST scandal worm create a hidden background service (xmss.exe). It copied itself on Local disk and Windows Directory (%Windir%). Terminated “Windows Task Manager”, Windows Command Prompt (DOS-Prompt) & crashed System Internal Process Explorer (procxp.exe).

Files created by this worm
* x:autorun.inf
* x:xmss.exe
* x:Funny UST Scandal.avi.exe
* %Windir%\autorun.inf
* %Windir%\xmss.exe
* %Windir%\Funny UST Scandal.avi.exe

How to remove
1. Disabled System Restore for Temporary - KB 264887
2. Boot Windows in Safe Mode - KB 315222

3. In Windows Safe Mode, Open Windows Registry Editor

Windows Start > Run > Regedit
Browse to the following registry settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Shell
Replace the value 'explorer.exe, xmss.exe' with 'exporer.exe'

4. Delete all the following files

* C\autorun.inf
* C\xmss.exe
* C\Funny UST Scandal.avi.exe
* X:\autorun.inf
* X:\xmss.exe
* X:\Funny UST Scandal.avi.exe
* %Windir%\autorun.inf
* %Windir%\xmss.exe
* %Windir%\Funny UST Scandal.avi.exe

5. Clean All Windows Temporary Files
6. Restart the Windows

** edit registry values with false data can damage your OS **

Friday, March 14, 2008

Diiferent Type of Security Threats

SpywareSpyware can make your computer unstable or unusable; enables others to record your keystrokes and steal your private data.

Viruses, worms, Trojan horses - Your computer files can be destroyed; hackers can gain control over your computer, and viruses can quickly spread to other computers

Hackers - Hackers can access your PC
without your knowledge to steal your private data or use your computer for their own purposes

Identity thieves - Thieves can steal your credit-card number, banking passwords, and more, costing you thousands of dollars

Phishing scams - Replying to a phishing scam can cause you to unknowingly provide criminals with your personal inancial information

Sexual predators - Minors providing strangers with too much personal information in chat rooms, IM sessions, and elsewhere

Privacy intrusions - Marketers and others can learn about your online habits, subjecting you to more pop-ups, identity theft is a possibility

Spam - Your inbox ills up with useless, annoying, even pornographic junk e-mail messages

Instant messaging monitoring & spam - Outsiders can spy on your conversations, send spam and more

Wireless network hackers - Hackers can log your keystrokes, steal your private data, direct you to fraudulent Web sites, and more

Friday, March 7, 2008

Klite codec - codec List for V3.8.0

K-Lite Codec Pack Full
Contents of version 3.8.0:

Player:

* Media Player Classic [version 6.4.9.1 rev. 40]

ffdshow:

* ffdshow [revision 1872]
* ffdshow VFW interface
* extra plugins

DirectShow video decoding filters:

* XviD [version 1.2.0-dev build 2008-01-10]
* DivX [version 6.8.0.0]
* On2 VP6 [version 6.4.2.0]
* On2 VP7 [version 7.0.10.0]
* MPEG-2 (Cyberlink) [version 8.1.0.1317]
* MPEG-2 (Gabest) [version 1.0.0.4]
* MPEG-1 (MainConcept) [version 1.0.0.78]

DirectShow audio decoding filters:

* AC3/DTS/LPCM/MP1/MP2 (AC3Filter) [version 1.46]
* Vorbis (CoreVorbis) [version 1.1.0.79]
* AAC (CoreAAC) [version 1.2.0.575]

DirectShow audio parsers:

* MusePack (MONOGRAM) [version 0.9.1.2 | 0.3.1.2]
* WavPack (CoreWavPack) [version 1.1.1]
* FLAC (madFLAC) [version 1.7]
* Monkey's Audio (DCoder) [version 1.0]
* OptimFROG (RadLight) [version 1.0.0.1]
* DC-Bass Source [version 1.1.0.0]
* AC3/DTS Source (AC3File) [version 0.5b]
* AMR (MONOGRAM) [version 0.9.0.1]

DirectShow source filters:

* AVI splitter (Gabest) [version 1.0.0.9]
* AVI splitter (Haali Media Splitter) [version 1.7.401.3]
* MP4 splitter (Haali Media Splitter) [version 1.7.401.3]
* MP4 splitter (Gabest) [version 1.0.0.4]
* Matroska splitter (Haali Media Splitter) [version 1.7.401.3]
* Matroska splitter (Gabest) [version 1.0.3.0]
* Ogg splitter (Haali Media Splitter) [version 1.7.401.3]
* Ogg splitter (Gabest) [version 1.0.0.1]
* MPEG PS/TS splitter (Gabest) [version 1.0.0.4]
* MPEG PS/TS splitter (Haali Media Splitter) [version 1.7.401.3]
* FLV splitter (Gabest) [version 1.0.0.4]
* CDDA Reader (Gabest) [version 1.0.0.2]
* CDXA Reader (Gabest) [version 1.0.0.2]

DirectShow subtitle filter:

* DirectVobSub (a.k.a. VSFilter) [version 2.38]
* DirectVobSub (a.k.a. VSFilter) [version 2.33]

Other filters:

* Haali Video Renderer [version 1.7.401.3]

VFW video codecs:

* XviD [version 1.2.0-dev build 2008-01-10]
* DivX Pro [version 6.8.0.14]
* x264 [revision 736bm]
* On2 VP6 [version 6.4.2.0]
* On2 VP7 [version 7.0.10.0]
* Intel Indeo 4 [version 4.51.16.2]
* Intel Indeo 5 [version 5.2562.15.54]
* Intel I.263 [version 2.55.1.16]
* huffyuv [version 2.1.1 CCE Patch 0.2.5]
* I420 (Helix) [version 1.2]
* YV12 (Helix) [version 1.2]

ACM audio codecs:

* MP3 (Fraunhofer) [version 3.4.0.0]
* MP3 (LAME) [version 3.97]
* AC3ACM [version 1.4]
* Vorbis [version 0.0.3.6]
* DivX ;) Audio [version 4.2.0.0]

Tools:

* Codec Tweak Tool [version 2.2.5]
* GSpot Codec Information Appliance [version 2.70a]
* MediaInfo Lite [version 0.7.5.9]
* VobSubStrip [version 0.11]
* GraphEdit [build 061102]
* Haali Muxer [version 1.7.359.22]
* FourCC Changer
* Bitrate Calculator