<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-27749677</id><updated>2009-03-01T12:22:18.750+07:00</updated><title type='text'>Anti Virus Update</title><subtitle type='html'>if your computer infected by virus software, update anti virus on your computer or format it..</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>GG</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-27749677.post-115626070889866676</id><published>2006-11-06T22:04:00.000+07:00</published><updated>2006-11-06T12:32:19.910+07:00</updated><title type='text'>Brontok</title><content type='html'>W32.Rontokbro@mm – Symantec, W32/Brontok-N – Sophos, Win32/Brontokbro.A.A – Eset, Win32/Robknot!Variant!Worm – CA eTrust, Worm.Win32.Brontok.a – Kaspersky, W32/Rontokbro.gen@MM - McAfee&lt;br /&gt;&lt;br /&gt;infection method by email attachment.&lt;br /&gt;&lt;table cellspacing="2" cellpadding="2" width="361" border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;u&gt;Subject:&lt;/u&gt; &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN-BOTTOM: 0.5cm"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Film Terbaru Dian Satro dan Tora Sudiro&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN-BOTTOM: 0.5cm"&gt;&lt;strong&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;u&gt;Body:&lt;/u&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN-BOTTOM: 0.5cm"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Salam&lt;br /&gt;Hangat,&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p align="justify"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Bagi&lt;br /&gt;Anda yang mengidolakan artis Dian Sastro atau Tora Sudiro, maka Anda akan segera&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;terpuaskan, karena sebuah film komedi romantis terbaru mereka (judul film masih dirahasiakan)&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;telah siap beredar.&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Untuk menambah koleksi foto idola Anda, berikut adalah salah satu potongan gambar film&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;ketika mereka beradegan romantis di sebuah danau, (terlampir pada file "Sample Picture.zip").&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="MARGIN-BOTTOM: 0.5cm" align="justify"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Menurut sutradaranya, film tersebut akan beredar dua bulan mendatang dan diperkirakan akan&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;melebihi kesuksesan film-film terdahulu mereka.&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="MARGIN-BOTTOM: 0.5cm"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Terima&lt;br /&gt;kasih,&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;strong&gt;&lt;u&gt;Attachment:&lt;/u&gt;&lt;br /&gt;&lt;/strong&gt;Sample Picture.Zip&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;varian of virus brontok :&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Sophos :&lt;/strong&gt;&lt;/p&gt;&lt;table bordercolor="#000000" cellspacing="0" cellpadding="4" width="100%" border="0"&gt;&lt;colgroup&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;thead&gt;&lt;tr valign="top"&gt;&lt;td width="25%"&gt;&lt;p&gt;W32/Brontok-AJ W32/Brontok-W W32/Brontok-AI W32/Brontok-E W32/Brontok-Zs W32/Brontok-D W32/Brontok-S W32/Brontok-AE W32/Brontok-C W32/Brontok-B W32/Brontok-AZ&lt;/p&gt;&lt;/td&gt;&lt;td width="25%"&gt;&lt;p&gt;W32/Brontok-AQ W32/Brontok-J W32/Brontok-V W32/Brontok-X W32/Brontok-AK W32/Brontok-A W32/Brontok-L W32/Brontok-K W32/Brontok-N W32/Brontok-F W32/Brontok-G &lt;/p&gt;&lt;/td&gt;&lt;td width="25%"&gt;&lt;p&gt;W32/Brontok-I W32/Brontok-BBW32/Brontok-R W32/Brontok-M W32/Brontok-Fam W32/Brontok-H W32/Rontokbr-A W32/Korbo-B W32/Bobandy-A &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;symantec: &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;W32.Rontokbro@mm&lt;br /&gt;W32.Rontokbro.AN@mm&lt;br /&gt;W32.Rontokbro.B@mm&lt;br /&gt;W32.Rontokbro.D@mm&lt;br /&gt;W32.Rontokbro.K@mm&lt;br /&gt;W32.Rontokbro.U@mm&lt;br /&gt;W32.Rontokbro.X@mm&lt;br /&gt;W32.Rontokbro.Z@mm&lt;br /&gt;W32/Rontokbro.gen@MM&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Kaspersky:&lt;/strong&gt;&lt;/p&gt;&lt;table bordercolor="#000000" cellspacing="0" cellpadding="4" width="100%" border="0"&gt;&lt;colgroup&gt;&lt;colgroup&gt;&lt;col width="128"&gt;&lt;colgroup&gt;&lt;col width="128"&gt;&lt;thead&gt;&lt;tr valign="top"&gt;&lt;td width="50%"&gt;&lt;p&gt;Email-Worm.Win32.Brontok.K&lt;br /&gt;Email-Worm.Win32.Brontok.a&lt;br /&gt;Email-Worm.Win32.Brontok.b&lt;br /&gt;Email-Worm.Win32.Brontok.c&lt;br /&gt;Email-Worm.Win32.Brontok.d&lt;br /&gt;Email-Worm.Win32.Brontok.e&lt;br /&gt;Email-Worm.Win32.Brontok.f&lt;br /&gt;Email-Worm.Win32.Brontok.g&lt;br /&gt;Email-Worm.Win32.Brontok.h&lt;br /&gt;Email-Worm.Win32.Brontok.i&lt;br /&gt;Email-Worm.Win32.Brontok.l&lt;/p&gt;&lt;/td&gt;&lt;td width="50%"&gt;&lt;p&gt;Email-Worm.Win32.Brontok.m&lt;br /&gt;Email-Worm.Win32.Brontok.n&lt;br /&gt;Email-Worm.Win32.Brontok.o&lt;br /&gt;Email-Worm.Win32.Brontok.p&lt;br /&gt;Email-Worm.Win32.Brontok.q&lt;br /&gt;Email-Worm.Win32.Brontok.r&lt;br /&gt;Email-Worm.Win32.Brontok.s&lt;br /&gt;Email-Worm.Win32.Brontok.t&lt;br /&gt;Trojan-Downloader.Win32.Brontok.a&lt;br /&gt;Worm.Win32.Brontok.a&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Eset:&lt;/strong&gt; &lt;table bordercolor="#000000" cellspacing="0" cellpadding="4" width="100%" border="0"&gt;&lt;colgroup&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;colgroup&gt;&lt;col width="64"&gt;&lt;thead&gt;&lt;tr valign="top"&gt;&lt;td width="25%"&gt;&lt;p&gt;Win32/Brontok&lt;br /&gt;Win32/Brontok.A&lt;br /&gt;Win32/Brontok.B&lt;br /&gt;Win32/Brontok.C&lt;br /&gt;Win32/Brontok.D&lt;br /&gt;Win32/Brontok.E&lt;br /&gt;Win32/Brontok.F&lt;br /&gt;Win32/Brontok.G&lt;br /&gt;Win32/Brontok.H&lt;br /&gt;Win32/Brontok.I&lt;br /&gt;Win32/Brontok.J&lt;br /&gt;Win32/Brontok.K&lt;br /&gt;Win32/Brontok.L&lt;br /&gt;Win32/Brontok.M&lt;br /&gt;Win32/Brontok.N&lt;br /&gt;Win32/Brontok.O&lt;br /&gt;Win32/Brontok.P&lt;br /&gt;Win32/Brontok.Q&lt;br /&gt;Win32/Brontok.R&lt;br /&gt;Win32/Brontok.S&lt;br /&gt;Win32/Brontok.T&lt;br /&gt;Win32/Brontok.U&lt;br /&gt;Win32/Brontok.V&lt;br /&gt;Win32/Brontok.W&lt;br /&gt;Win32/Brontok.X&lt;br /&gt;Win32/Brontok.Y&lt;br /&gt;Win32/Brontok.Z&lt;/p&gt;&lt;/td&gt;&lt;td width="25%"&gt;&lt;p&gt;Win32/Brontok.AA&lt;br /&gt;Win32/Brontok.AB&lt;br /&gt;Win32/Brontok.AC&lt;br /&gt;Win32/Brontok.AD&lt;br /&gt;Win32/Brontok.AE&lt;br /&gt;Win32/Brontok.AF&lt;br /&gt;Win32/Brontok.AG&lt;br /&gt;Win32/Brontok.AH&lt;br /&gt;Win32/Brontok.AI&lt;br /&gt;Win32/Brontok.AJ&lt;br /&gt;Win32/Brontok.AK&lt;br /&gt;Win32/Brontok.AL&lt;br /&gt;Win32/Brontok.AM&lt;br /&gt;Win32/Brontok.AN&lt;br /&gt;Win32/Brontok.AO&lt;br /&gt;Win32/Brontok.AP&lt;br /&gt;Win32/Brontok.AQ&lt;br /&gt;Win32/Brontok.AR&lt;br /&gt;Win32/Brontok.AS&lt;br /&gt;Win32/Brontok.AT&lt;br /&gt;Win32/Brontok.AU&lt;br /&gt;Win32/Brontok.AX&lt;br /&gt;Win32/Brontok.AZ Win32/Brontok.BA Win32/Brontok.BB Win32/Brontok.BC Win32/Brontok.BD Win32/Brontok.BE &lt;/p&gt;&lt;/td&gt;&lt;td width="25%"&gt;&lt;p&gt;Win32/Brontok.BF&lt;br /&gt;Win32/Brontok.BG&lt;br /&gt;Win32/Brontok.BH&lt;br /&gt;Win32/Brontok.BI&lt;br /&gt;Win32/Brontok.BJ&lt;br /&gt;Win32/Brontok.BK&lt;br /&gt;Win32/Brontok.BL&lt;br /&gt;Win32/Brontok.BM&lt;br /&gt;Win32/Brontok.BN&lt;br /&gt;Win32/Brontok.BO&lt;br /&gt;Win32/Brontok.BP&lt;br /&gt;Win32/Brontok.BQ&lt;br /&gt;Win32/Brontok.BR&lt;br /&gt;Win32/Brontok.BS&lt;br /&gt;Win32/Brontok.BU&lt;br /&gt;Win32/Brontok.BV&lt;br /&gt;Win32/Brontok.BW&lt;br /&gt;Win32/Brontok.BX&lt;br /&gt;Win32/Brontok.BY&lt;br /&gt;Win32/Brontok.BZ Win32/Brontok.CA Win32/Brontok.CB Win32/Brontok.CC Win32/Brontok.CD Win32/Brontok.CE Win32/Brontok.CF Win32/Brontok.CG Win32/Brontok.CH &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-115626070889866676?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/115626070889866676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=115626070889866676' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115626070889866676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115626070889866676'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/11/brontok.html' title='Brontok'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-115652119775996576</id><published>2006-08-25T22:46:00.000+07:00</published><updated>2006-08-25T22:53:17.776+07:00</updated><title type='text'>Latest Kaspersky Virus Watch</title><content type='html'>P2P-Worm.Win32.VB.el&lt;br /&gt;Trojan-Downloader.Win32.Agent.auv&lt;br /&gt;Trojan-Downloader.Win32.Small.dow&lt;br /&gt;Trojan-Downloader.Win32.VB.alg&lt;br /&gt;Trojan-Spy.Win32.Bancos.wy&lt;br /&gt;SpamTool.Win32.Bagle.m&lt;br /&gt;Trojan-Downloader.Win32.Banload.bgq&lt;br /&gt;Trojan-Clicker.Win32.VB.ox&lt;br /&gt;Virus.Win32.Lanc.a&lt;br /&gt;Trojan-Downloader.Win32.Zlob.agp&lt;br /&gt;Trojan.Win32.KillFiles.lb&lt;br /&gt;HackTool.Win32.VB.ik&lt;br /&gt;Trojan-PSW.Win32.Delf.ow&lt;br /&gt;Trojan-PSW.Win32.Delf.ov&lt;br /&gt;Trojan.Win32.Delf.wt&lt;br /&gt;Trojan-PSW.Win32.Delf.ou&lt;br /&gt;Trojan-Downloader.Win32.Agent.auu&lt;br /&gt;Trojan-PSW.Win32.Delf.ot&lt;br /&gt;Backdoor.Win32.Hupigon.cea&lt;br /&gt;Trojan-Downloader.Win32.Agent.aut&lt;br /&gt;Trojan-Downloader.Win32.Small.dov&lt;br /&gt;Trojan-PSW.Win32.Lineage.ahb&lt;br /&gt;Trojan-Downloader.Win32.Small.dou&lt;br /&gt;Backdoor.Win32.Small.mr&lt;br /&gt;Trojan-PSW.Win32.Delf.os&lt;br /&gt;Trojan-Spy.Win32.Agent.or&lt;br /&gt;Backdoor.Win32.Hupigon.cdz&lt;br /&gt;not-a-virus:Monitor.Win32.SpyAgent.n&lt;br /&gt;Trojan.Win32.FlyStudio.s&lt;br /&gt;Backdoor.Win32.Hupigon.cdy&lt;br /&gt;Trojan-Spy.Win32.Bancos.wx&lt;br /&gt;Backdoor.Win32.Hupigon.cdx&lt;br /&gt;Trojan-Downloader.Win32.Small.dot&lt;br /&gt;Trojan.Win32.VB.ary&lt;br /&gt;Trojan-Downloader.Win32.Small.dos&lt;br /&gt;Trojan-Spy.Win32.Banker.bvv&lt;br /&gt;Trojan-PSW.Win32.Lmir.bab&lt;br /&gt;Trojan.Win32.Opnis.u&lt;br /&gt;Trojan-Downloader.Win32.Small.dor&lt;br /&gt;Trojan-Downloader.Win32.Agent.aus&lt;br /&gt;Trojan-PSW.Win32.Lineage.wd&lt;br /&gt;Trojan-Spy.Win32.Banker.bvu&lt;br /&gt;Backdoor.Win32.Rbot.bhj&lt;br /&gt;Trojan-Spy.Win32.Banbra.is&lt;br /&gt;Trojan.Win32.Qhost.ht&lt;br /&gt;Trojan-Downloader.BAT.Ftp.cn&lt;br /&gt;Backdoor.Win32.Agent.agf&lt;br /&gt;Trojan-Downloader.Win32.Banload.bgp&lt;br /&gt;Trojan-Downloader.Win32.Banload.bgg&lt;br /&gt;Trojan-Downloader.Win32.Delf.avj&lt;br /&gt;Backdoor.Win32.Rbot.bhi&lt;br /&gt;Trojan-Downloader.Win32.Delf.avi&lt;br /&gt;Backdoor.Win32.ServU-based.br&lt;br /&gt;Trojan-Downloader.Win32.Banload.bgf&lt;br /&gt;not-a-virus:Porn-Dialer.Win32.PluginAccess.p&lt;br /&gt;Trojan-Downloader.Win32.Banload.bge&lt;br /&gt;not-a-virus:AdWare.Win32.Softomate.s&lt;br /&gt;not-a-virus:AdWare.Win32.Softomate.r&lt;br /&gt;Virus.Lua.LuaDef.d&lt;br /&gt;Virus.Lua.LuaDef.c&lt;br /&gt;Virus.Lua.LuaDef.b&lt;br /&gt;Virus.Lua.LuaDef.a&lt;br /&gt;Trojan-Downloader.Win32.Zlob.ago&lt;br /&gt;not-a-virus:PSWTool.Win32.PassView.d&lt;br /&gt;Trojan-PSW.Win32.Delf.or&lt;br /&gt;Trojan-Downloader.Win32.Small.doq&lt;br /&gt;Trojan-Dropper.Win32.Small.asd&lt;br /&gt;Trojan-Proxy.Win32.Dlena.u&lt;br /&gt;Trojan-Spy.Win32.BZub.cr&lt;br /&gt;Trojan.Win32.Agent.rm&lt;br /&gt;Trojan-Dropper.Win32.Agent.avb&lt;br /&gt;Trojan-Downloader.Win32.Small.dop&lt;br /&gt;Packed.Win32.PePatch.ef&lt;br /&gt;IM-Worm.Win32.Small.i&lt;br /&gt;Backdoor.Win32.Hupigon.cdw&lt;br /&gt;Trojan.Win32.Haradong.n&lt;br /&gt;Trojan-PSW.Win32.QQPass.kj&lt;br /&gt;Trojan-Downloader.Win32.Delf.avh&lt;br /&gt;Backdoor.Win32.Rukap.ca&lt;br /&gt;Trojan-Downloader.Win32.PurityScan.dg&lt;br /&gt;Backdoor.Win32.Rukap.bz&lt;br /&gt;Trojan-Downloader.Win32.Zlob.agn&lt;br /&gt;Trojan-Downloader.Win32.Zlob.agm&lt;br /&gt;Trojan-Downloader.Win32.Agent.aur&lt;br /&gt;not-a-virus:AdWare.Win32.NaviPromo.ab&lt;br /&gt;Worm.Win32.Agent.k&lt;br /&gt;Trojan-Spy.Win32.Bancos.ww&lt;br /&gt;Trojan-Dropper.Win32.Agent.ava&lt;br /&gt;Backdoor.Win32.DSNX.05.e&lt;br /&gt;Backdoor.Win32.Protux.j&lt;br /&gt;Backdoor.Win32.Hupigon.cdv&lt;br /&gt;Trojan.Win32.BHO.e&lt;br /&gt;Backdoor.Win32.IRCBot.vj&lt;br /&gt;Backdoor.Win32.Cakl.l&lt;br /&gt;Backdoor.Win32.SdBot.avb&lt;br /&gt;not-a-virus:AdWare.Win32.Virtumonde.dk&lt;br /&gt;Backdoor.Win32.Rbot.bhh&lt;br /&gt;Backdoor.Win32.IRCBot.vi&lt;br /&gt;Backdoor.Win32.Prorat.fe&lt;br /&gt;Trojan.Win32.Disabler.o&lt;br /&gt;Trojan-Spy.Win32.Bancos.wv&lt;br /&gt;not-a-virus:AdWare.Win32.NaviPromo.aa&lt;br /&gt;Trojan-Spy.Win32.Bancos.wu&lt;br /&gt;Trojan-PSW.Win32.Lineage.aha&lt;br /&gt;Backdoor.Win32.Prorat.fd&lt;br /&gt;Trojan-Downloader.Win32.Agent.auq&lt;br /&gt;Trojan-PSW.Win32.Lineage.agz&lt;br /&gt;Trojan-Proxy.Win32.Dlena.t&lt;br /&gt;Trojan-Spy.Win32.Bancos.wt&lt;br /&gt;Backdoor.Win32.Hupigon.cdu&lt;br /&gt;Backdoor.Win32.Bifrose.yu&lt;br /&gt;Exploit.Win32.Agent.ad&lt;br /&gt;Trojan-Dropper.Win32.VB.dn&lt;br /&gt;not-a-virus:Joke.Win32.Lemmirc&lt;br /&gt;Trojan-Downloader.Win32.Zlob.agl&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-115652119775996576?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/115652119775996576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=115652119775996576' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115652119775996576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115652119775996576'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/08/latest-kaspersky-virus-watch.html' title='Latest Kaspersky Virus Watch'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-115380218079518425</id><published>2006-07-25T11:22:00.000+07:00</published><updated>2006-07-25T11:36:20.796+07:00</updated><title type='text'>Nyxem.E</title><content type='html'>Malware type: Worm&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Alias:&lt;/strong&gt;&lt;br /&gt;W32.Blackmal.E@mm, Kama Sutra, W32/MyWife.d@MM, Email-Worm.Win32.Nyxem.e, JS/Blackmal.F, W32.Blackmal.E@mm, W32/Kapser.A@mm, W32/MyWife&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Additional Aliases:&lt;/strong&gt;&lt;br /&gt;Email-Worm.Win32.Nyxem.e, Email-Worm.Win32.VB.bi, I-Worm.VB.bi, Kama Sutra, Nyxem.E, Small.KI@mm, W32/Grew.A!wm, W32/Kapser.A@mm, W32/MyWife.d@MM!M24, W32/Nyxem-D, W32/Small.KI, W32/Tearec.A.worm, W32/Tearec.A.worm!CME-24, Win32.Blackmal.e, Win32.Nyxem.F@mm, Win32.VB.bi, Win32/Blackmal.F!Worm, Win32/Blackmal.F, Win32/VB.NEI worm, Win32:VB-CD [Wrm], Worm.P2P.VB.CIL!CME-24, Worm.VB-8, Worm.VB.bi, Worm/KillAV.GR&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Also Known As:&lt;/strong&gt;&lt;br /&gt;CME-24, Win32.Blackmal.F [Computer Associates], Email-Worm.Win32.Nyxem.e [F-Secure], Email-Worm.Win32.Nyxem.e [Kaspersky], W32/MyWife.d@MM [McAfee], W32/MyWife.d@MM!M24 [McAfee], Win32/Mywife.E@mm [Microsoft], W32/Small.KI@mm [Norman], Tearec.A [Panda Software], W32/Nyxem-D [Sophos], WORM_GREW.{A, B} [Trend Micro]&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Systems Affected:&lt;br /&gt;&lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;br /&gt;&lt;br /&gt;Size: 95744&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-115380218079518425?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/115380218079518425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=115380218079518425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115380218079518425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115380218079518425'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/07/nyxeme_25.html' title='Nyxem.E'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-115337139930532506</id><published>2006-07-20T11:48:00.000+07:00</published><updated>2006-08-25T23:48:50.083+07:00</updated><title type='text'>Worm/Levona.A</title><content type='html'>File size: 43.008 Bytes&lt;br /&gt;&lt;br /&gt;Aliases:&lt;br /&gt;• Mcafee: W32/Avon@MM&lt;br /&gt;• Kaspersky: Email-Worm.Win32.Levona.a&lt;br /&gt;• TrendMicro: WORM_LEVONA.A&lt;br /&gt;• VirusBuster: iworm I-Worm.Levona.A&lt;br /&gt;• Eset: Win32/Levona.A worm&lt;br /&gt;• Bitdefender: Win32.Worm.Levona.A&lt;br /&gt;&lt;br /&gt;Platforms / OS:&lt;br /&gt;• Windows 95&lt;br /&gt;• Windows 98&lt;br /&gt;• Windows 98 SE&lt;br /&gt;• Windows NT&lt;br /&gt;• Windows ME&lt;br /&gt;• Windows 2000&lt;br /&gt;• Windows XP&lt;br /&gt;• Windows 2003&lt;br /&gt;&lt;br /&gt;effects:&lt;br /&gt;• Disable security applications&lt;br /&gt;• Lowers security settings&lt;br /&gt;• Registry modification&lt;br /&gt;&lt;br /&gt;It copies itself to the following locations:&lt;br /&gt;• %SYSDIR%\Emma.exe&lt;br /&gt;• %SYSDIR%\Nova.exe&lt;br /&gt;• %SYSDIR%\Alisa.exe&lt;br /&gt;• %WINDIR%\Mstry.exe&lt;br /&gt;&lt;br /&gt;• C:\Program Files\Common Files\Renova.exe&lt;br /&gt;• D:\Program Files\Common Files\Renova.exe&lt;br /&gt;• E:\Program Files\Common Files\Renova.exe&lt;br /&gt;• F:\Program Files\Common Files\Renova.exe&lt;br /&gt;• G:\Program Files\Common Files\Renova.exe&lt;br /&gt;&lt;br /&gt;• c:\\winnt\regedit.exe&lt;br /&gt;• c:\windows\regedit.exe&lt;br /&gt;• c:\winnt\system32\regedit.exe&lt;br /&gt;• c:\windows\system32\regedit.exe&lt;br /&gt;• D:\winnt\regedit.exe&lt;br /&gt;• D:\windows\regedit.exe&lt;br /&gt;• D:\winnt\system32\regedit.exe&lt;br /&gt;• D:\windows\system32\regedit.exe&lt;br /&gt;• E:\winnt\regedit.exe&lt;br /&gt;• E:\windows\regedit.exe&lt;br /&gt;• E:\winnt\system32\regedit.exe&lt;br /&gt;• E:\WINDOWS\system32\regedit.exe&lt;br /&gt;• F:\WINNT\regedit.exe&lt;br /&gt;• F:\WINDOWS\regedit.exe&lt;br /&gt;• F:\WINNT\system32\regedit.exe&lt;br /&gt;• F:\WINDOWS\system32\regedit.exe&lt;br /&gt;• G:\WINNT\regedit.exe&lt;br /&gt;• G:\WINDOWS\regedit.exe&lt;br /&gt;• G:\WINNT\system32\regedit.exe&lt;br /&gt;• G:\WINDOWS\system32\regedit.exe&lt;br /&gt;&lt;br /&gt;• c:\windows\System\msconfig.exe&lt;br /&gt;• c:\windows\system32\msconfig.exe&lt;br /&gt;• c:\winnt\system32\msconfig.exe&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;It tries to executes the following files:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;– Filenames:&lt;br /&gt;• %SYSDIR%\Emma.exe&lt;br /&gt;• %SYSDIR%\Alisa.exe&lt;br /&gt;&lt;br /&gt;The following registry keys are added in order to run the processes after reboot:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;• Renova = Nova.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;• Shell = %PROGRAM FILES%\Common Files \Renova.exe&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;The following registry keys are added:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Policies\Microsoft\Windows\System]&lt;br /&gt;&lt;/span&gt;• DisableCMD = 0&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]&lt;br /&gt;&lt;/span&gt;• DisableConfig = 1&lt;br /&gt;• DisableSR = 1&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;The following registry keys are changed:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion]&lt;/span&gt;&lt;br /&gt;Old value:&lt;br /&gt;• ProductName = %user defined settings%&lt;br /&gt;• RegisteredOrganization = %user defined settings%&lt;br /&gt;• RegisteredOwner = %user defined settings%&lt;br /&gt;• ProductId = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• ProductName = RENOVA&lt;br /&gt;• RegisteredOrganization = XENOVA&lt;br /&gt;• RegisteredOwner = RENOVA&lt;br /&gt;• ProductId = RENOVA&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersion]&lt;/span&gt;&lt;br /&gt;Old value:&lt;br /&gt;• RegisteredOrganization = %user defined settings%&lt;br /&gt;• RegisteredOwner = %user defined settings%&lt;br /&gt;• ProductId = %user defined settings%&lt;br /&gt;• ProductName = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• RegisteredOrganization = XENOVA&lt;br /&gt;• RegisteredOwner = RENOVA&lt;br /&gt;• ProductId = RENOVA&lt;br /&gt;• ProductName = RENOVA&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Control Panel\Desktop]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• AutoEndTasks = 0&lt;br /&gt;New value:&lt;br /&gt;• AutoEndTasks = 1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• AlternateShell = cmd.exe&lt;br /&gt;New value:&lt;br /&gt;• AlternateShell = %PROGRAM FILES%\Common Files\Renova.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SYSTEM\ControlSet%number%\Control \SafeBoot]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• AlternateShell = cmd.exe&lt;br /&gt;New value:&lt;br /&gt;• AlternateShell = %PROGRAM FILES%\Common Files\Renova.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• Shell = explorer.exe&lt;br /&gt;• Userinit = explorer.exe&lt;br /&gt;New value:&lt;br /&gt;• Shell = explorer.exe %PROGRAM FILES%\Common Files\Renova.exe&lt;br /&gt;• Userinit = explorer.exe %PROGRAM FILES%\Common Files\Renova.exe&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Disable Regedit and Task Manager:&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;&lt;/span&gt;New value:&lt;br /&gt;• DisableRegistryTools = 1&lt;br /&gt;• DisabletaskMgr = 1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersionGroup Policy Objects\LocalUser\Software\Microsoft\ WindowsCurrentVersion\Policies\System]&lt;/span&gt;&lt;br /&gt;New value:&lt;br /&gt;• DisableRegistryTools = 1&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Various Explorer settings:&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ AdvancedFolder\HideFileExt]&lt;/span&gt;&lt;br /&gt;Old value:&lt;br /&gt;• Type = checked&lt;br /&gt;New value:&lt;br /&gt;• Type =&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\NOHIDDEN]&lt;/span&gt;&lt;br /&gt;Old value:&lt;br /&gt;• CheckedValue = %user defined settings%&lt;br /&gt;• DefaultValue = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• CheckedValue = 2&lt;br /&gt;• DefaultValue = 2&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;– &lt;/span&gt;&lt;span style="font-size:78%;"&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ AdvancedFolder\Hidden\SHOWALL]&lt;/span&gt;&lt;br /&gt;Old value:&lt;br /&gt;• CheckedValue = %user defined settings%&lt;br /&gt;• DefaultValue = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• CheckedValue = 1&lt;br /&gt;• DefaultValue = 2&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ AdvancedFolder\HideFileExt]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• CheckedValue = %user defined settings%&lt;br /&gt;• DefaultValue = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• CheckedValue = 1&lt;br /&gt;• DefaultValue = 1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersion\Explore\Advanced]&lt;br /&gt;&lt;/span&gt;Old value:&lt;br /&gt;• Hidden = %user defined settings%&lt;br /&gt;• HideFileExt = %user defined settings%&lt;br /&gt;New value:&lt;br /&gt;• Hidden = 2&lt;br /&gt;• HideFileExt = 1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;&lt;/span&gt;New value:&lt;br /&gt;• NoDriveTypeAutoRun = 91&lt;br /&gt;• NoSaveSettings = 0&lt;br /&gt;• NoFolderOptions = 0&lt;br /&gt;• NoFind = 1&lt;br /&gt;• NoRun = 0&lt;br /&gt;• NoControlPanel = 0&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]&lt;/span&gt;&lt;br /&gt;New value:&lt;br /&gt;• NoFolderOptions = 0&lt;br /&gt;• NoControlPanel = 0&lt;br /&gt;• NoFind = 1&lt;br /&gt;• NoRun = 0&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;It uses the Messaging Application Programming Interface (MAPI) in order to send a reply to emails stored in the inbox. The characteristics are further described:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;From:&lt;br /&gt;The sender address is the user's Outlook account.&lt;br /&gt;&lt;br /&gt;Email design:&lt;br /&gt;&lt;br /&gt;To: %original sender%&lt;br /&gt;Subject: Re: %original subject%&lt;br /&gt;Body:&lt;br /&gt;• Sorry, Saya lupa nih :)&lt;br /&gt;Attachment:&lt;br /&gt;• Nova.scr&lt;br /&gt;&lt;br /&gt;The attachment is a copy of the malware itself.&lt;br /&gt;The email looks like the following:&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/2459/2902/1600/1.0.jpg"&gt;&lt;img style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/2459/2902/320/1.0.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;In order to infect other systems in the Peer to Peer network community the following action is performed: It retrieves the shared folder by querying the following registry key:&lt;br /&gt;• \Software\Kazaa\Transfer\DlDir0&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;List of processes that are terminated:&lt;/strong&gt;&lt;br /&gt;• GUNBLADE.EXE&lt;br /&gt;• CAV.EXE&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Processes with one of the following strings are terminated:&lt;br /&gt;&lt;/strong&gt;RABIAH; RABI'AH; MANTIK; PLATO; KINDI; IMAMAH; MATURID; HARUN NAS; IZUTSU; TEOLOGI; SUFI; PARTAI; HASAN ALBANA; IKHWANUL MUSLIMIN; TAHRIR; ARISTOTELES; GIBRAN; GHAZALI; IHYA; GENDER; PLURALISME; SYIAH; SYI'AH; DEMOCRA; DEMOKRA; LIBERAL; TASAWUF; SAMIR; YUNAN; QUTH; EMANSIP; PHILOSOP; MUTAZILAH; MU'TAZILAH; FILOSOF; FILSAFAT; REALPLAYER; CLEANER; MOVZX; REMOVER; ZANDA; MACHINE; CILLIN; CILIN; AVAST; GRISOFT; PROCEXP; NORTON; EARTHLINK PROTECTION; WASHER; ERTANTO; COMPACTBYTEAV; ADVANCED REGISTRY TRACER; KILL; CASTLECOPS; SOPHOS; F-SECURE; REGISTRYFIX; PANDA; SECUNIA; TREND; SYMANTEC; KASPERSKY; AVG; MCAFEE; NVC; NORMAN; VAKSIN; HACKER; COMMAND PROMPT; PROCESS EXPLORER - SYSINTERNALS; SYSTEM32; PCMAV; HIJACK; KILLBOX; FOLDER OPTION; CMD; WORM; TROJAN; VIRUS; ANTI; COMMAND BRO!!!; COMMAND BRO !!!; JOWOBOT; FAJAR; SATRIO; KANTUK; KANGEN; CUEX; EVANTA; BORAX; TITTA; CODE-X; MONTELLA; MONTELA; FERDINAND; CAMPBEL; CRUZ; ADRIANO; KAHN; RECOBA; FIGO; RAUL; GONZALES; CISSE; GERRAD; LAMPARD; TERRY; RIVALDO; GATUSO; GATTUSO; VAN DE; SHEARER; AIMAR; CLAUDIO; LOPEZ; TOLDO; CANNAVARO; NESTA; UMIT; HAKAN; LARSON; LARSSON; ETO O; ETO'O; MOVIC; MIDO; FABREGAS; HENRY; BARTHEZ; MANCINI; GILARD; BATIGOL; BATISTUA; TOTTI; COLE; OWEN; DIDA; RONALDINHO; TREZEG; ROBINHO; CARLOS; ROBERTO; RONALDO; MARADONA; PELE; VIDUKA; SALAS; KEWEL; PERUZZI; HOWARD; ZANETI; ZANETTI; GIGGS; ROONEY; BUFFON; VIERI; PIRLO; KAKA; ZLATAN; DECO; SHEVA; SHEVCHENKO; INZAGHI; PIERO; BECKHAM; BOCA J; BORDEUX; MONACO; MUNICH; MUNCHEN; DORTMUND; LEVERKUSEN; SEVILLA; VALENCIA; BARCA; BARCEL; MADRID; PARMA; LAZIO; ROMA; INTER; MILAN; JUVE; NEWCASTLE; LIVERPOOL; ARSENAL; CHELSEA; MANCHESTER; CUMBU; KISS; CIUM; RAYU; JULIET; ROMEO; VALENTINE; HENTAI; MANGA; ANIM; SUCK; FUCK; NAKE; NUDE; TEEN; GIRL; PORN; SEKS; SEX; THOMAS; JEREM; MAYANG S; NIA R; ZAYANT; DEWI; ANJASMARA; DIAN S; DIAN N; SOPIA; SOPHIA; MAYANG SARI; CUT KEKE; FEBIOLA; FEBY; JIHAN; CUT TARI; RIKE DIAH; WIBOWO; SARAH; AZAHRI; AZHARI; RIRIN; RATNASARI; TAMARA; ZUBIR; PRIMUS; REVALDO; ENNO LERIAN; ENO LERIAN; DIAH; KADIR; DOYOK; ULFA; KOMENG; JENIFER; JENNIFER; DICAPRIO; KRISTIN; ANGELLI; LEONARDO; KATE WIN; EMMA WATSON; HARY POTTER; HARRY POTTER; GOSSIP; GOSIP; SASTRA; SENI; ARTIS; BOLYWOOD; HOLYWOOD; SINETRON; VAGANZA; CELEBRI; SELEB; TSUBASA; SLAM DUNK; SAMURAI-X; SAMURAI X; HATTORI; HATORI; KABUTO; SHIZUKA; DORAEMON; NOBITA; INUYASHA; KENSHIN HIMURA; KOTARO MINAMI; KYOKO; EMIKO SHIRATORI; FAYE WONG; UEMATSU; NUOBUO; NOUBUO; NOBUO; NUBUO; MADONNA; MADONA; BENNINGTON; BENINGTON; GUN AND ROSE; GUN N ROSE; BLUR; SAMMY; PEARL; NAZARE; FRENTE; CRANBER; RADIOHEAD; RADIO HEAD; STING; SAYBIA; KEANE; GROBAN; ALTER; STEFAN; GWEN; MAROON; ANTHEM; GROOVE COVARAGE; PRODIGY; AGUILERA; BEDING; METALLICA; GUN N'ROSES; ALICIA KEYS; TATA YOUNG; BOY ZONE; MICHEL; MICHAEL; MICHEAL; MLTR; MARTYN; MARTIN; SCORPION; LINKIN PARK; LINKINPARK; GREEN DAY; GREENDAY; HOOBASTANK; PETER; WEST; SPICE; BRITNEY; DEDI DOR; NIA DANIAT; DAHLIA; NIKE ARD; BAGASKARA; KATON; NAFF; TITIK PUSPA; TITIEK PUSPA; DELON; SNADA; JOSHUA; SHERINA; SERIEUS; SERIUES; SEURIUS; 10 2 5; TENTOFIVE; TEN2FIVE; 10 TO 5; TEN TO FIVE; TEN 2 FIVE; CHRISYE; SO7; SHEILA; GLENN; AURIL; AVRIL; OPICK; AGNES; ANANG; NUGIE; HADAD; HADDAD; AB THREE; REZA; CAFEIN; CAFFEIN; RATU; RADJA; LALUNA; THE RAIN; UTOPIA; SPARK; BASEJAM; ENDANK; JAVA JIVE; MARCEL; BUNGLON; ANDRE HEHANU; FLANELA; BAIM; CANDIL; KOES P; MINORU; NUNO; YOVI; AUDY; TERE; WAYANG; BASE JAM; JIKUSTIK; SAMSON; PAS BAND; BOOMERANG; NAIF; COKELAT; KAPTEN BAND; TIC BAND; JAMRUD; KOTAK BAND; AMERICAN IDOL; INDONESIAN IDOL; TEAM LO; BUNGA; TIPE-X; TIPE X; ELEMENT; EMINEM; RAIHAN; RAYHAN; MELY; MELLY; UNGU; STINGKY; SLANK; INUL; PADI; IWAN FAL; ADABAND; ADA BAND; ROSA; KRISDAYANTI; NURHALIZA; DEWA; ARY LASO; ARY LASSO; ARI LASO; ARI LASSO; GIGI; THE 0THERS; CHEER; DANCE; SING; SONG; MP 3; MP3; MARAWIS; NASYID; DANGDUT; MELODI; MELODY; SENANDUNG; IRAMA; GITAR; GUITAR; NYANYI; LAGU; WINAMP; MUSIK; MUSIC; DANIAT; PHILOSO; FUNNY; MALAS; SOUND; JPG; JPEG; RAGNAROK; FANTASY; IKHWANUL; ARISTO; PLURAL; GAME; DEMOC; DEMOK; FAKE; NORWE; REMOVE; PROTECT; COMPACT; REGISTRY; CASTLE; SOPH; SECUR; MCAFE; DEEP; HIJA; VIR; CRACK; HACK; ACT; BECK; GAMB; FOTO; PHOTO; KASIH; TUNANG; PACAR; CINTA; LOVE; JULIE; ROME; VALENT; LEONARD; KATE W; EMMA WAT; HARY; POTTER; HARRY; ART; BOLY; HOLY; SINE; EMIKO; WONG; FAYE; UEMA; NUO; NOB; NUB; MADO; BENING; BENNING; ROSE; GUN; ZONE; BOY; MICH; MART; SCORP; LINKIN; GREEN; HOOB; RIF; DEDI D; NIKE; PUSPA; JOSH; SHERIN; TEN TO; TEN 2; CHRIS; POTRET; NUGI; AUDI; AMERICA; ELEMEN; DANG&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;The active processes memory is searched for the following strings. If successful the processes become terminated.:&lt;br /&gt;&lt;/strong&gt;XMPLAYER.EXE; REALPLAY.EXE; ACDSEE.EXE; ALOGSERV.EXE; CM GRDIAN.EXE; CMGRDIAN.EXE; RULAUNCH.EXE; VSMAIN.EXE; AVPCC.EXE; AVPM.EXE; AVP32.EXE; AVWUPSRV.EXE; AVGNT.EXE; AVWIN.EXE; AVGEMC.EXE; AVGWB.DAT; AVGCC.EXE; TROJAN GUARDER.EXE; ASHSIMPL.EXE; ASHQUICK.EXE; OPERA.EXE; FIREFOX.EXE; IEXPLORE.EXE; TASKMGR.EXE; EMUSICCLIENT.EXE; ART.EXE; NAVW32.EXE; CCLAW.EXE; NVCOD.EXE; WINAMP.EXE&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Processes containing one of the following window titles are terminated:&lt;br /&gt;&lt;/strong&gt;CompactbyteAV; Advanced Registry Tracer; Setup - iKnowPS; iKnowPS; RamCleaner; System Cleaner; TuneUp RegistryCleaner; Antivirus Scanner; Zanda's little helper; Norman Generic Fix; NVC v5.81 Setup; Norman Virus Control - InstallShield Wizard; Process Explorer - Sysinternals: &lt;a href="http://www.sysinternals.com"&gt;www.sysinternals.com&lt;/a&gt;; Pocket Killbox; RegCleaner 4.1 by Jouni Vuorio; Security Task Manager Versi shareware tanpa registrasi; Security Task Manager; Installation; EULA; PowerDVD; Windows Media Player; Microsoft Configuration Utility; System Restore; System Configuration Utility; Restrictions; Registry Editor; Close Programs; Close Program; Task Manager; Windows Script Host; HijackThis; HijackThis - v1.99.1; Getting Started with Windows 2000; Folder Options&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Mutex:&lt;br /&gt;&lt;/strong&gt;It creates the following Mutexes:&lt;br /&gt;• Renova Aliciana&lt;br /&gt;• Renova Emira&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Programming language:&lt;br /&gt;&lt;/strong&gt;The malware program was written in MS Visual C++.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Runtime packer:&lt;/strong&gt;&lt;br /&gt;In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:&lt;br /&gt;• UPX&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-115337139930532506?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/115337139930532506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=115337139930532506' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115337139930532506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115337139930532506'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/07/wormlevonaa.html' title='Worm/Levona.A'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-115280888958815778</id><published>2006-07-13T23:37:00.000+07:00</published><updated>2006-07-19T01:15:31.683+07:00</updated><title type='text'>List of Virus 2005 - 2006</title><content type='html'>&lt;div align="justify"&gt;Bagle.CP, Bagle-CP.msg, BACKDOOR, w32/Brontok-1, w32.Brontok-3, Brontok-4, Brontok-5.A, Brontok-5.B, Brontok-10.A, Brontok-10.B, Brontok-12.A, Brontok-12.B, Brontok-12.C, Brontok-14.A, Brontok-14.B, Brontok-14.C, Brontok-15, Brontok-16.A, Brontok-16.B, Brontok-16.C, Brontok-17.A, Brontok-17.B, Brontok-17.C, Brontok-17.D, Brontok-17.E, Brontok-18R.A, Brontok-18R.B, Brontok-22.MyBro, Brontok-22.MyBro.msg, Brontok.Downloader, Brontok-Sensasi.A, Brontok-Sensasi.B, Brontok-Sensasi.C, Brontok-Laknats, brontok.z BlueFantasy, BlueFantasy-msg, brontok.gn/rontokbro.gn, brontok.go/rontokbro.go, Borax, Win32/Bagle.EH, Win32/Bagle.EF, Win32/Bagle.EG, Win32.Mydoom.N, Win32.Netsky.P, Cendrawasih, Decoil.A, Decoil.A-2, Decoil.A-3, w32/Detnat.a, w32.Detnat.b, Detnat.c, Detnat.d, Detnat.e, Detnat.f, Detnat.g, Diary, Dodol, Dodol.msg-A, Dodol.msg-B, Dodol.msg-C, Dodol.msg-D, Dodol.msg-E, Dian sastro, W32.Ecup, W32.Ecup!p2p, FunLove, Hopelessly, Infostealer.Orcu, Jeefo, KamaSutra, KamaSutra.htt, Kantuk, Komodo, W32/Kraze.a, LiveForever, MyTob.AL, MyTob.V, mywife, NeverShow, Patient, Pctattletale, Pinfi.a, Qhosts.B, RomanticDevil, RomanticDevil.pic, RomanticDevil.msg, RomanticDevil.htm, RomanticDevil.vbs, Riani jangkaru, W32.Serwab@mm, Shuriken, SomeFool.P, SomeFool.Z, stenit, Tomero, Tomero.doc, worm/vb.cj, w32/vb.cj, Wukill, W32.Icogon, Trojan.Hlinic.B, W97M.Kukudro.A, Kukudro.A, WM97/Kukudro-A, Backdoor.Beasty.J, Trojan.Exobre, BAT.Antir, W32.Kidala.E@mm, Trojan.Hlinic, Downloader.Booli.B, Perl.Lekbot.B, Backdoor.Pahador, Trojan.Kuserv, Backdoor.Rajump, SymbOS.Commdropper.F, Commdropper.C [F-Secure], W32.Amirecivel.E@mm, SymbOS.Commwarrior.N, Commwarrior.H [F-Secure], SymbOS.Commwarrior.M, Commwarrior.N [F-Secure], SymbOS.Commdropper.G, Commdropper.H [F-Secure], SymbOS.Dropper.A, Trojan.Flemex, W32.Kraze, W32.Beagle.FG@mm, W32/Bagle.fb!pwdzip [McAfee], SymbOS.Romride.H, Romride.H [F-Secure], SymbOS.Romride.G, Romride.G [F-Secure], SymbOS.Romride.F, Romride.F [F-Secure], W32.Beagle.FF@mm, W32/Bagle.fb@MM [McAfee], W32/Bagle-KL [Sophos], W32/Bagle-KM [Sophos], Trojan.Rootserv, Hacktool.Rootkit, Infostealer.Nailmews, Downloader.Centim, Infostealer.Orcu, MSIL.Kolilo, PE_IKOL.A [Trend] W32.Sixem.A@mm,W32/Sixem-A [Sophos], W32/Deza.A [F-Secure], Trojan.Haradong, Infostealer.Wowcraft.D, Trojan.Slapew.C, Trojan.Slapew.B, Trojan.Tooso.R, W32.Beagle.KF [Sophos], W32.Beagle.FD@mm, Backdoor.Ripgof.B, W32.Looked.J, Trojan.Lodear.J, W32.Revolnam, Infostealer.Gamania, W32.Sality.R, Backdoor.Naninf.E, BKDR_BREPBOT.A [Trend], Infostealer.Yohokie, Trojan.Slapew, Backdoor.Haxdoor.M, Infostealer.Sealoln, Downloader.Booli.A, Trojan.Mdropper.J, Trojan.Dropper, Bloodhound.Exploit.74, Bloodhound.Exploit.73, Backdoor.Eterok.C, Bloodhound.Exploit.72, Backdoor.Daserf, JS.Yamanner@m, JS/Yamanner@MM [McAfee], JS_YAMANER.A [Trend Micro], Yamanner.A [F-Secure], JS/Yamann-A [Sophos], Downloader.Swif.B, Trojan.Skowr, TROJ_SKOWR.A [Trend], W32.Detnat.G, Downloader.Bancos, W32.Detnat.F, W32.Nopir.D, W32.Serwab@mm, W32.Timeserv@mm, W32.Fijjy, Downloader.Bancos!gen, Bloodhound.NsAnti, W32.Detnat.E, Trojan.Silm, Backdoor.Ginwui.C, Trojan.Mdropper.I, Bloodhound.Exploit.71, Perl.Lekbot, SB.Starbugs, W97M.Tored.A, W2KM_TORED.A[Trend Micro], Backdoor.Haxdoor.L, Trojan.Emcodec.D, SymbOS.Commdropper.E, Infostealer.Bancos.AB, SymbOS.Commwarrior.J, Commwarrior.K [F-Secure], W32.Beagle.FC, SymbOS.Romride.E, Romride.E [F-Secure], SymbOS.Romride.D, Romride.D [F-Secure], SymbOS.Commdropper.D, Commdropper.F [F-Secure], SymbOS.Romride.C, Romride.C [F-Secure], SymbOS.Commwarrior.L, Commwarrior.M [F-Secure], SymbOS.Commwarrior.K, Commwarrior.L [F-Secure], Trojan.Looksky, SymbOS.Romride.B, Romride.B [F-Secure], SymbOS.Romride.A, Romride.A [F-Secure], Bloodhound.Tibs, Backdoor.Rustock.A, W32.Lecna.A, OSX.Exploit.MetaData, Exploit.OSX.Safari.a [Kaspersky], OSX/Exploit-ZipShell [McAfee], SB.Stardust.A!int, XML_DUSTAR.A [Trend Micro], W32.Wamgin, Trojan.Emcodec.C, Backdoor.Sdbot.AT, W32.Pahatia.A, W32.Looked.I, Trojan.Gobrena, W32.Gaobot.EUX, Trojan.Agentdoc.B, W32.Sejese, BlackAngel.A [Panda], W32.Jesse, W32.Ecup, W32.Ecup!p2p, W32.Banwarum@mm, W97M.Lunedo.B, SymbOS.Commwarrior.I, SymbOS.RommWar.D, RommWar.A [F-Secure], SymbOS.RommWar.C, RommWar.C [F-Secure], SymbOS.RommWar.B, Rommwar.B [F-Secure], Backdoor.Darkmoon.C, SymbOS.Doomboot.T, Doomboot.M [F-Secure], Worm/Kelvir, W97M/Kukudro, Backdoor.Bifrose.F, W32.Dozic, Backdoor.Haxdoor.N, Trojan.PPDropper.B, W32.Looked.P, W32.Looked.O, Infostealer.Corepias, Trojan.Dachri, Trojan.Mdropper.K, Backdoor.Sdbot.AU, Backdoor.Pcclient.B, VBS.Birhip, SymbOS.Mabir.B, W32.Jalabed.B@mm, SymbOS.Doomboot.X, SymbOS.Commdropper.H, W32.Banwarum.G@mm, W32.Yawmo, Bloodhound.Exploit.75, Trojan.Nakani, SymbOS.Cabir.X, SymbOS.Ruhag.E, SymbOS.Ruhag.D, Infostealer.Svcstor, Backdoor.Rustock.B, Trojan.Lodeight.C, Trojan.Hongmosa, W32.Esbot.E, SymbOS.Doomboot.W, SymbOS.Doomboot.V, W32.Audio, W32.Sixem.C@mm, W32.Amirecivel.F@mm, W32.Gatt, SymbOS.Cdropper.Q, Trojan.Deoplive , Trojan.Emcodec.E, SymbOS.Cdropper.S, SymbOS.Cdropper.R, SymbOS.Dampig.D, SymbOS.Cdropper.O , W32.Areses.P@mm, Trojan.Zlob.L, OSX.Exploit.Launchd, Trojan.Clagger, Backdoor.Graybird.S, W32.Sality.T, SymbOS.Cdropper.J, W32.Resik.A, Trojan.Bookmarker.K, SymbOS.Cdropper.K, SymbOS.Cdropper.I, SymbOS.Cdropper.G, SymbOS.Cdropper.F, W32.Sality.S, Infostealer.Jianghu, W32.Banleed.B, W32.Icogon, Trojan.Hlinic.B, W97M.Kukudro.A, Backdoor.Beasty.J, Trojan.Exobre , BAT.Antir, Trojan.Gared, Backdoor.Hacarmy.G, Infostealer.Panobu, Downloader.Browsilla, W32/Gatt, W32/Donak.dr, W32/Donak.worm, Racgen, W97M/Kukudro, W32/Kraze.dr, Downloader-AWX.dr, W32/Bagle.fd@MM, Downloader-AXD, W32/Sdbot.worm!605becc1, W32/Sdbot.worm!b37e4475, W32/Bagle.fc@MM, BackDoor-DIP, Downloader-AXA, Del-507, W32/Bagle.fb!pwdzip, W32/Kraze.a, W32/Bagle.fb@MM,MultiDropper-QU, W32/Sdbot.worm.dr!8aa30865, Exploit-MSExcel.b.gen, W32/Sixem.a@MM, Downloader-AWV.dr, BackDoor-CKB.dr!adeb69f7, BackDoor-CKB!f8984a14, Exploit-MSExcel.gen, Downloader-AWX, Downloader-AWW, Exploit-PPT, Downloader-AWV,W32.Stong.A,  Trojan.Gobrena.B,  Trojan.Clagger.B,  Trojan.Riler.F,   Trojan.PPDropper.C,  ACTS.Spaceflash,  Trojan.Frozzie &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-115280888958815778?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/115280888958815778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=115280888958815778' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115280888958815778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/115280888958815778'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/07/list-of-virus-2005-2006.html' title='List of Virus 2005 - 2006'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-114714251091080026</id><published>2006-05-09T09:40:00.000+07:00</published><updated>2006-05-09T09:42:50.760+07:00</updated><title type='text'>Bots</title><content type='html'>&lt;div class="center-col"&gt; &lt;div class="narrative"&gt;&lt;h3&gt;What's a Bot?&lt;/h3&gt; &lt;p&gt;“Bot” is actually short for robot – not the kind found in science fiction movies or on the production line in a manufacturing business. Bots are one of the most sophisticated types of crimeware facing the Internet today. Bots are similar to worms and Trojans, but earn their unique name by performing a wide variety of automated tasks on behalf of their master (the cybercriminals) who are often safely located somewhere far across the Internet. Tasks that bots can perform run the gamut from sending spam to blasting Web sites off the Internet as part of a coordinated “denial-of-service” attack. Since a bot infected computer does the bidding of its master, many people refer to these victim machines as “zombies.” &lt;/p&gt;&lt;/div&gt;&lt;/div&gt; Bots sneak onto a person’s computer in many ways. Bots oftentimes spread themselves across the Internet by searching for vulnerable, unprotected computers to infect. When they find an exposed computer, they quickly infect the machine and then report back to their master. Their goal is then to stay hidden until they are awoken by their master to perform a task. Bots are so quiet that sometimes the victims first learn of them when their Internet Service Provider tells them that their computer has been spamming other Internet users. Sometimes a bot will even clean up the infected machine to make sure it does not get bumped off of the victim’s computer by another cybercriminal’s bot. Other ways in which a bot infects a machine include being downloaded by a Trojan, installed by a malicious Web site or being emailed directly to a person from an already infected machine.&lt;br /&gt;Bots do not work alone, but are part of a network of infected machines called a “botnet.” Botnets are created by attackers repeatedly infecting victim computers using one or several of the techniques mentioned above. Each one of the zombie machines is controlled by a master computer called the command and control server. From the command and control server, the cybercriminals manage their botnets and instructs the army of zombie computers to work on their behalf. A botnet is typically composed of large number victim machines that stretch across the globe, from the Far East to the United States. Some botnets might have a few hundred or a couple thousand computers, but others have tens and even hundreds of thousands of zombies at their disposal.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-114714251091080026?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/114714251091080026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=114714251091080026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114714251091080026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114714251091080026'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/05/bots.html' title='Bots'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-114713977560786077</id><published>2006-05-09T08:52:00.001+07:00</published><updated>2006-05-17T22:10:51.746+07:00</updated><title type='text'>Definitions</title><content type='html'>&lt;p&gt;&lt;strong&gt;Virus?&lt;/strong&gt;&lt;br /&gt;A virus is a manmade program or piece of code that causes an unexpected, usually negative, event. Viruses are often disguised games or images with clever marketing titles such as "Me, nude."&lt;!--a href="#"&gt;Read on...&lt;/a--&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Worm?&lt;/strong&gt;&lt;br /&gt;Computer Worms are viruses that reside in the active memory of a computer and duplicate themselves. They may send copies of themselves to other computers, such as through email or Internet Relay Chat (IRC).&lt;!--a href="#"&gt;Read on...&lt;/a--&gt;  &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Trojan Horse?&lt;/strong&gt;&lt;br /&gt;A Trojan horse program is a malicious program that pretends to be a benign application; a Trojan horse program purposefully does something the user does not expect. Trojans are not viruses since they do not replicate, but Trojan horse programs can be just as destructive. &lt;/p&gt; &lt;div style="text-align: center; font-weight: bold; color: rgb(153, 0, 0);"&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://anti-decoil.atspace.com/download/" target="_blank"&gt;Download Anti Virus Now&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-114713977560786077?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/114713977560786077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=114713977560786077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114713977560786077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114713977560786077'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/05/definitions_08.html' title='Definitions'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27749677.post-114709904952806787</id><published>2006-05-08T21:13:00.000+07:00</published><updated>2006-07-13T23:37:40.136+07:00</updated><title type='text'>Virus Brontok/Rontok.bro</title><content type='html'>first time my computer infected by virus brontok i'm panic...&lt;br /&gt;but now i'm not panic again if the Virus brontok/rontok.bro infected my computer.. because the anti virus can be remove the brontok virus..&lt;br /&gt;&lt;br /&gt;update anti virus on your computer like norton anti virus, avira antivir, norman anti virus, panda anti virus, pc cllin anti virus, and many more of anti virus. i guarantee the virus brontok/rontok.bro is gone in your computer&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anti-virus-remover.atspace.com"&gt;try open this link if your computer infected by virus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27749677-114709904952806787?l=antiviruscomputer.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antiviruscomputer.blogspot.com/feeds/114709904952806787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=27749677&amp;postID=114709904952806787' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114709904952806787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27749677/posts/default/114709904952806787'/><link rel='alternate' type='text/html' href='http://antiviruscomputer.blogspot.com/2006/05/virus-brontokrontokbro.html' title='Virus Brontok/Rontok.bro'/><author><name>GG</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16453353751672075319'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry></feed>