Nono....i just ask ppl to go and see how a destructive spyware looks like when it looks like Anti spyware.Originally posted by ndmmxiaomayi:Hmm, I don't know what he is up to.
But also don't give this kind of suggestion ma.Originally posted by M©+square:Nono....i just ask ppl to go and see how a destructive spyware looks like when it looks like Anti spyware.
Yuanwang....![]()
Hmm...they kanna spyware then they will come in for solutions...Originally posted by ndmmxiaomayi:But also don't give this kind of suggestion ma.
Hmm, another good way to increase ratings.![]()
Yup. But afraid that this strategy will not last.Originally posted by M©+square:Hmm...they kanna spyware then they will come in for solutions...
Hmm....marketing strat.![]()
haih..pity.. i didnt strikeOriginally posted by ndmmxiaomayi:New virus spreading. If you are one of those porno users out there, be careful. Do not click on anything attachments.
These are the common attachments:
The Best Videoclip Ever
School girl fantasies gone bad
A Great Video
Fuckin Kama Sutra pics
Arab sex DSC-00465.jpg
give me a kiss
*Hot Movie*
Fw: Funny
Fwd: Photo
Fwd: image.jpg
Fw: Sexy
Re:
Fw:
Fw: Picturs
Fw: DSC-00465.jpg
Word file
eBook.pdf
the file
Part 1 of 6 Video clipe
You Must View This Videoclip!
Miss Lebanon 2006
Re: Sex Video
My photos
If you can't resist the temptations to view them, then I wish you good luck. I will post the removal tools after you click them.![]()
He kena?Originally posted by alexkusu:haih..pity.. i didnt strike
guess the man who was death more lucky than me
he higher chance to kena.. neway, hasnt seen him on9 rite?Originally posted by ndmmxiaomayi:He kena?
He don't come here de.Originally posted by alexkusu:he higher chance to kena.. neway, hasnt seen him on9 rite?![]()
Originally posted by ndmmxiaomayi:wah thx...nex time i hav itchy hands or have a sudden wave of teenage hormones i don need 2 be scared these virus/spyware anymore...
I changed my mind. Decides to help you guys in case you all itchy fingers and cannot resist temptations.
Disinfection utility by F-Secure.
Disinfection utility by F-Secure (in case you can't access the above link)
The utility is distributed only in a ZIP archive that contains the following files:
* f-force.exe - the main executable file
* eult.rtf - End User License Terms document
* readme.rtf - Readme file in RTF format
* readme.txt - Readme file in ASCII format
[b]Important Notice
Please make sure that you read the End User License Terms document (Eult.rtf) and the Readme file (either Readme.txt or Readme.rtf) before using the F-Force utility!
Please note that the F-Force utility can disinfect only certain malicious programs. Besides the utility does not scan inside archives. So after cleaning a computer with the F-Force utility it is recommended to scan all hard drives with F-Secure Anti-Virus and the latest updates to make sure that no infected files remain there.
If you don't like F-Secure, here are other sites that can help you:
Symantec
McAfee
Computer Associates
Sophos
Trend Micro
Trend Micro
Kaspersky
Norman[/b]
ang moh sites?Originally posted by ndmmxiaomayi:New virus spreading. If you are one of those porno users out there, be careful. Do not click on anything attachments.
These are the common attachments:
The Best Videoclip Ever
School girl fantasies gone bad
A Great Video
Fuckin Kama Sutra pics
Arab sex DSC-00465.jpg
give me a kiss
*Hot Movie*
Fw: Funny
Fwd: Photo
Fwd: image.jpg
Fw: Sexy
Re:
Fw:
Fw: Picturs
Fw: DSC-00465.jpg
Word file
eBook.pdf
the file
Part 1 of 6 Video clipe
You Must View This Videoclip!
Miss Lebanon 2006
Re: Sex Video
My photos
If you can't resist the temptations to view them, then I wish you good luck. I will post the removal tools after you click them.![]()
Nope. Spread by email attachments. But it has the tendency to lead to other virulent sites as well.Originally posted by dragg:ang moh sites?
How much you will pay for not listening:
The worm has a dangerous payload. If the date is equal to 3 (3rd of February, 3rd of March, etc) and the worm's UPDATE.EXE file is run, it destroys files with those extensions on all available drives:
*.doc
*.xls
*.mdb
*.mde
*.ppt
*.pps
*.zip
*.rar
*.psd
*.dmp
The files' contens get replaced with a text string "DATA Error [47 0F 94 93 F4 K5]". The payload is activated 30 minutes after the worm's file UPDATE.EXE is loaded into memory (basically 30 minutes after logon). We can confirm that the payload works at least on Windows XP.
The worm attempts to disable several security-related and file sharing programs. It deletes startup key values from the Registry if they contain any of the following:
NPROTECT
ccApp
ScriptBlocking
MCUpdateExe
VirusScan Online
MCAgentExe
VSOCheckTask
McRegWiz
CleanUp
MPFExe
MSKAGENTEXE
MSKDetectorExe
McVsRte
PCClient.exe
PCCIOMON.exe
pccguide.exe
Pop3trap.exe
PccPfw
PCCIOMON.exe
tmproxy
McAfeeVirusScanService
NAV Agent
PCCClient.exe
SSDPSRV
rtvscn95
defwatch
vptray
ScanInicio
APVXDWIN
KAVPersonal50
kaspersky
TM Outbreak Agent
AVG7_Run
AVG_CC
Avgserv9.exe
AVGW
AVG7_CC
AVG7_EMC
Vet Alert
VetTray
OfficeScanNT Monitor
avast!
DownloadAccelerator
BearShare
The following startup Registry keys are affected:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices]
In addition the worm deletes files from the following subfolders in the Program Files folder:
\DAP\*.dll
\BearShare\*.dll
\Symantec\LiveUpdate\*.*
\Symantec\Common Files\Symantec Shared\*.*
\Norton AntiVirus\*.exe
\Alwil Software\Avast4\*.exe
\McAfee.com\VSO\*.exe
\McAfee.com\Agent\*.*
\McAfee.com\shared\*.*
\Trend Micro\PC-cillin 2002\*.exe
\Trend Micro\PC-cillin 2003\*.exe
\Trend Micro\Internet Security\*.exe
\NavNT\*.exe
\Kaspersky Lab\Kaspersky Anti-Virus Personal\*.ppl
\Kaspersky Lab\Kaspersky Anti-Virus Personal\*.exe
\Grisoft\AVG7\*.dll
\TREND MICRO\OfficeScan\*.dll
\Trend Micro\OfficeScan Client\*.exe
\LimeWire\LimeWire 4.2.6\LimeWire.jar
\Morpheus\*.dll
In addition the worm reads location of certain programs from Windows Registry and deletes certain files in these locations. The affected software is:
VirusProtect6
Norton AntiVirus
Kaspersky Anti-Virus Personal
Iface.exe
Panda Antivirus 6.0 Platinum
Also the worm closes application windows that have the following strings in their captions:
SYMANTEC
SCAN
KASPERSKY
VIRUS
MCAFEE
TREND MICRO
NORTON
REMOVAL
FIX
For some reason the worm adds several license keys to the Registry. Most of them seem to belong to VB6 controls. Also the worm makes the following changes to the Registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
"FullPath" = dword:00000001
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" = dword:00000000
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"WebView" = dword:00000000
The worm can modify Active Desktop files in order to launch another copy of itself named 'WinZip_Tmp.exe' using the ActiveX control.
Originally posted by laurence82:nan dao xiao mayi also.........![]()
Wah... me don't visit those sites ok.Originally posted by laurence82:nan dao xiao mayi also.........![]()
Reformat can cure.Originally posted by seow:If kanna and no protection, reformat can cure?
Normal surfing will still kanna hor?
I'm safe.Originally posted by ndmmxiaomayi:Reformat can cure.
Normal surfing won't get it, unless like I said, you itchy fingers go and click those email attachments.
Or you cannot resist temptations and click it.![]()
Really?Originally posted by freestyle:lucky thing i dont watch porn
Originally posted by seow:I'm safe.