• Home
  • About
  • Contact
  • Forum
  • Portofolio
logo
  • Business & Economy
  • Featured Articles
  • iNet
  • Insurance
  • Science
  • Tricks
  • Various

Virus confess’ Friends’ in Yahoo Messenger

icon1 Posted by jackmedia in Featured Articles, iNet on 02 10th, 2009 | 2 responses

Chat applications like Yahoo Messenger and Skype to be the target of malicious programs. This virus spreads by sending itself to all contacts in the address of the application to include a link to download the file.

The message as if the authentic message that is sent by a contact in YM / Skype you. But be careful never click the link provided, though sent by your friend.

“The actual message is not sent by your friend, but by ‘love rat’ alias to a successful virus infection of your friend’s computer,”.

According to the latest watched Vaksincom 10 February 2009, the link in the start-update by the creator of the virus and the file name changed to ‘Your_Dad_Has_Shit_Fetish_Too.PIF’.

Link in the message is that lead to YouTube, but it is false and in fact directed to the download site for free Rapidshare used to save a file virus.
Using free Rapidshare file sharing to spread itself is very effective and efficient because it does not require high effort and infrastructure / bandwidth Rapidshare is very good to spread the virus file.

“So you do not actually download the file from YouTube but from rapidshare.com address. This file has size of 130 KB is created by using Visual C ++ Language Program “.

Impact

If the file that is downloaded is executed, it will automatically create a random file name with the extension .tmp and .exe that will be stored in the directory [C: \ Documents and Settings \% username% \ Local Settings \ Temp] with a different name backgrounds.

For example, A415.tmp or 034.exe and drop files with the name Lady_Eats_Her_Shit – www.youtube.com, then this virus will execute a file . Tmp and . Exe has a dewdrop it.

At the time of the file that has the extension. Tmp on the run and he will copy the file into another file name that is vshost.exe which has 122 KB size, this file will be saved in the root of each drive [c: \ or d: \].

This virus will also take advantage of the Windows autorun feature to create file [autorun.inf] at the root of each drive and the Flash Disk, the making of this file is that it can be activated automatically every time the user access the drive / Flash Disk. Autorun file containing this script to run the file [vshost.exe].

2 Comments »

  1. avatar wade Says:
    February 11th, 2009 at 6:01 am

    How do you get rid of this thing? Got this and Troj/Buzus-E at the same time.

  2. avatar jackmedia Says:
    February 11th, 2009 at 6:34 am

    Please visit this site http://vaksin.com/2009/0209/coutsonif/Coutsonif.html in indonesian language

RSS feed for comments on this post. TrackBack URL

Leave a comment

Recent Posts

  • Apple launches music networking Ping compete with Facebook
  • Diaspora, a serious challenger Facebook
  • Location Features stretcher, Facebook and Gowalla Foursquare Hold
  • Wi-Fi Child Health Harm?
  • Internet Explorer 9 (Probably) Not Running on Windows XP
  • Google Prepare “Phone Call” While Chatting
  • 5 The fun of Facebook
  • Site 4 ‘Replacement’ Photoshop
  • Ex-blocker, Bury Memories of Ex-Boyfriend Application
  • Microsoft infiltrated by Russian spies

Archives

  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008

Blogroll

  • Jackmedia – Tips & Trik
  • Jackmedia – Total Solution For Web
  • Jogjasecure – Indonesian Network Hosting
  • Tempe Basah
  • Uyung.Com – Simplicity Personal Blog

Partner

  • Add to Technorati Favorites
  • Join 4Shared Now!
  • Blog Text Link Ads
  • Buy and sell Text Links
    • Buy Text Links
    • Text Link Brokers
    • Order Text Link Here
  • YouSayToo - Promote Blog
  • Yousaytoo Blog Awards
  • Your Ad Here
  • Blog Advertising - Get Paid to Blog

Meta:

  • RSS
  • Comments RSS
  • Valid XHTML
© Copyright Jackmedia – Footnote 2008. All rights reserved. | Powered by Wordpress | Designed by Elegant WPT