Saturday, September 3, 2011

Yahoo Messenger Virus "MacGyver"




Still remember MacGyver action movies, which often makes sophisticated tools even if only simple equipment. It also seems that occurs with viruses Yahoo Messenger, though blended with a programming language (VB Script) is underestimated, but a deadly virus.

The virus is generically known as the de facto W32/VBTroj.CEPA and become the most vicious viruses and most disturbing in the beginning of 2011. The virus is capable of doing many things such as installing rootkits, block network access and manipulate the Windows hosts file so I can do blocking access to security sites on the victim computer.

"And the more sophisticated, the hosts file is encrypted to avoid detection by antivirus programs and improvements,". and this virus will also block access to several security sites or other sites that have been determined by means of redirecting to the IP number 209.85.225.99 which is the public ip, it is actually indirectly cause the DDos on the site.

These viruses spread very rapidly by taking advantage of chat media commonly used by users such as Yahoo Messenger, MSN Messenger and Skype by sending a message and attach a link to download a file that is engineered like image files (JPG), but is actually a virus file been compressed with different sizes berdeda tegantung on the variant that infects the computer. The compressed file has an exe extension.

If you receive the message you receive should not be let alone run the included file while the Messenger contact a friend who you know, it's not your friend who sent the virus but the virus that infects the computer and use messenger accounts. One of the things that cause the virus successfully spread in addition to using the media mentioned above, it will also update to renew itself it is this which causes the antivirus scanner can not detect the virus.

The virus is more strongly entrenched with the help of a rootkit file serving to protect the master file that is active in memory, so the cleanup is done through windows Normal, Safe Mode or Safe Mode With Command Prompt sometimes can not solve the problem.

0 comments:

Post a Comment

Popular Posts