<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Un blog simplu. Ca buna ziua. &#187; virus</title>
	<atom:link href="http://www.probabil.eu/tag/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.probabil.eu</link>
	<description>mai mult ca sigur eu!</description>
	<lastBuildDate>Mon, 14 May 2012 20:26:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Cum scap de virusul din messenger?</title>
		<link>http://www.probabil.eu/cum-scap-de-virusul-din-messenger.html</link>
		<comments>http://www.probabil.eu/cum-scap-de-virusul-din-messenger.html#comments</comments>
		<pubDate>Sat, 01 May 2010 12:18:59 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=1273</guid>
		<description><![CDATA[Pai relativ simplu. Downloadati combofix, instalati-l si lasati-l sa-si faca treaba!]]></description>
			<content:encoded><![CDATA[<p>Pai relativ simplu.</p>
<p>Downloadati <a href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" target="_blank" onclick="pageTracker._trackPageview('/outgoing/download.bleepingcomputer.com/sUBs/ComboFix.exe?referer=');">combofix</a>, instalati-l si lasati-l sa-si faca treaba!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/cum-scap-de-virusul-din-messenger.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Virus Yahoo Messenger!</title>
		<link>http://www.probabil.eu/virus-pe-yahoo-messenger.html</link>
		<comments>http://www.probabil.eu/virus-pe-yahoo-messenger.html#comments</comments>
		<pubDate>Fri, 30 Apr 2010 13:38:10 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=1266</guid>
		<description><![CDATA[A aparut un nou tip de virus care se propaga prin intermediul messengerului. Este o alternativa mult mai inteligenta a acestui virus. O sa primiti mesaje de tipul: foto http://zhelefun.com/image.php foto http://tviceimg.com/image.php foto http://tuesimages.com/image.php foto http://ariafotos.com/image.php Ideea este sa nu accesati aceste linkuri infectate. Nici macar de curiozitate. Pana in prezent, virusul nu este detectat [...]]]></description>
			<content:encoded><![CDATA[<p>A aparut un nou tip de virus care se propaga prin intermediul messengerului.<br />
Este o alternativa mult mai inteligenta a acestui <a href="http://www.probabil.eu/2010/01/29/virusi-pe-yahoo-messenger/" target="_blank">virus</a>.</p>
<p>O sa primiti mesaje de tipul:</p>
<blockquote><p><strong>foto http://zhelefun.com/image.php<br />
foto http://tviceimg.com/image.php<br />
foto http://tuesimages.com/image.php<br />
foto http://ariafotos.com/image.php</strong></p></blockquote>
<p>Ideea este sa nu accesati aceste linkuri infectate. Nici macar de curiozitate.<br />
Pana in prezent, virusul nu este detectat decat de vreo trei antivirusuri.</p>
<p><a href="http://anubis.iseclab.org/?action=result&amp;task_id=172acf51752ef7b94b9d4af508f21de00&amp;format=html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/anubis.iseclab.org/?action=result_amp_task_id=172acf51752ef7b94b9d4af508f21de00_amp_format=html&amp;referer=');">Aici</a> aveti o analiza a virusului (anubis sandbox).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/virus-pe-yahoo-messenger.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hallmark face lumea virtuala mai fericita! &#8211; Virus</title>
		<link>http://www.probabil.eu/hallmark-face-lumea-virtuala-mai-fericita-virus.html</link>
		<comments>http://www.probabil.eu/hallmark-face-lumea-virtuala-mai-fericita-virus.html#comments</comments>
		<pubDate>Fri, 26 Feb 2010 14:59:10 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=1064</guid>
		<description><![CDATA[Probabil ati primit si voi mail cu subject de genul Hallmark face lumea mai fericita! E un virus! Nu descarcati nimic! Este vorba despre o arhiva .exe facuta cu SFX. In termenii IRC&#8217;ului este vorba despre drone. Odata infectat calculatorul vostru, acesta va realiza o conexiune la un server de tip IRC de unde poate [...]]]></description>
			<content:encoded><![CDATA[<p>Probabil ati primit si voi mail cu subject de genul <em>Hallmark face lumea mai fericita!</em><br />
E un virus! Nu descarcati nimic!<br />
Este vorba despre o arhiva .exe facuta cu SFX. In termenii IRC&#8217;ului este vorba despre <em>drone</em>. Odata infectat calculatorul vostru, acesta va realiza o conexiune la un server de tip IRC de unde poate fi controlat de catre detinatorul botnet&#8217;ului.</p>
<p style="text-align: center;"><a href="http://www.probabil.eu/wp-content/uploads/2010/02/virus-hallmark.JPG"><img class="size-medium wp-image-1065  aligncenter" title="virus-hallmark" src="http://www.probabil.eu/wp-content/uploads/2010/02/virus-hallmark-300x225.jpg" alt="virus-hallmark" width="300" height="225" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/hallmark-face-lumea-virtuala-mai-fericita-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Net-Worm.Win32.Kido &#8211; KidoKiller.exe</title>
		<link>http://www.probabil.eu/virus-net-worm-win32-kido-kidokiller-exe.html</link>
		<comments>http://www.probabil.eu/virus-net-worm-win32-kido-kidokiller-exe.html#comments</comments>
		<pubDate>Thu, 18 Feb 2010 20:38:31 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[yahoo messenger]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=929</guid>
		<description><![CDATA[Dupa varianta romaneasca si spaniola a virusului care se raspandea (si se raspandeste si in prezent &#8211; am primit azi un mesaj) prin Yahoo Messenger, a aparut o alta forma a virusului care are cam aceleasi caracteristici ca ale virusului Net-Worm.Win32.Kido aparut in luna octombrie a anului 2008. O caracteristica importanta a acestui virus este [...]]]></description>
			<content:encoded><![CDATA[<p>Dupa varianta <a href="http://www.probabil.eu/2010/01/29/virusi-pe-yahoo-messenger/" target="_blank">romaneasca</a> si <a href="http://www.probabil.eu/2010/02/10/virusi-pe-yahoo-messenger-varianta-spaniola/" target="_blank">spaniola</a> a virusului care se raspandea (si se raspandeste si in prezent &#8211; am primit azi un mesaj) prin Yahoo Messenger, a aparut o alta forma a virusului care are cam aceleasi caracteristici ca ale virusului Net-Worm.Win32.Kido aparut in luna octombrie a anului 2008.<br />
O caracteristica importanta a acestui virus este aceea ca blocheaza accesul la siteurile de securitate online, nepermitand downloadul aplicatiilor de dezinfectare. In rest, are aceleasi caracteristici ca ale variantei romanesti si spaniole.</p>
<p>Totusi, exista solutie pentru aceasta problema!<br />
<span id="more-929"></span><br />
<em>Avand in vedere ca acest virus blocheaza accesul la siteurile cu aplicatii de dezinfectare, rugati pe cineva sa downloadeze KidoKiller de pe linkul de mai jos si sa vi-l trimita (asa ar trebui sa functioneze).</em></p>
<p><strong>1.</strong> Downloadati KidoKiller.exe -&gt; <a href="http://data2.kaspersky-labs.com:8080/special/KidoKiller_v2.zip" target="_blank" onclick="pageTracker._trackPageview('/outgoing/data2.kaspersky-labs.com_8080/special/KidoKiller_v2.zip?referer=');">http://kaspersky-labs.com:8080/special/KidoKiller_v2.zip</a></p>
<p><strong>2.</strong> Rulati aplicatia KidoKiller si asteptati pana finalizeaza scan&#8217;ul.</p>
<p><strong>3.</strong> Dupa ce a terminat, scanati inca o data cu un antivirus, de preferat, Kaspersky.</p>
<p><em>Cred ca am sa revin cu detalii suplimentare zilele astea (daca o sa am timp liber sa analizez virusul mai bine).</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/virus-net-worm-win32-kido-kidokiller-exe.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Virusi pe Yahoo Messenger &#8211; varianta spaniola!</title>
		<link>http://www.probabil.eu/virusi-pe-yahoo-messenger-varianta-spaniola.html</link>
		<comments>http://www.probabil.eu/virusi-pe-yahoo-messenger-varianta-spaniola.html#comments</comments>
		<pubDate>Wed, 10 Feb 2010 21:50:39 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[yahoo messenger]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=816</guid>
		<description><![CDATA[Spiridusul meu de teren &#8211; Alecs &#8211; a semnalat prezenta unui nou virus care trimite mesaje pe Yahoo Messenger. Acest tip de virus seamana cu cel romanesc, mesajele trimise fiind in limba spaniola. veo una foto tuya pero no se si eres tu.. acepta y dime http://find.mytinypic.info:84/shared/ksdk30f/DTV-MiPictura014.JPEG.zip Ideal ar fi sa nu dati click pe [...]]]></description>
			<content:encoded><![CDATA[<p>Spiridusul meu de teren &#8211; <a href="http://alecs.eu/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/alecs.eu/?referer=');">Alecs</a> &#8211; a semnalat prezenta unui nou virus care trimite mesaje pe Yahoo Messenger. Acest tip de virus seamana cu cel <a href="http://www.probabil.eu/2010/01/29/virusi-pe-yahoo-messenger/">romanesc</a>, mesajele trimise fiind in limba spaniola.</p>
<blockquote><p>veo una foto tuya pero no se si eres tu.. acepta y dime <strong>http://find.mytinypic.info:84/shared/ksdk30f/DTV-MiPictura014.JPEG.zip</strong></p></blockquote>
<p><strong><em>Ideal ar fi sa nu dati click pe linkurile astea dubioase si sa avertizati persoana care v-a trimis mesajul ca este virusata!</em></strong></p>
<p><em><strong>Este es un nuevo tipo de virus! Creo firmemente recomendamos que no lo haga clic en este tipo de vínculos y también utilizar un buen antivirus!</strong></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/virusi-pe-yahoo-messenger-varianta-spaniola.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Virusi pe Yahoo Messenger!</title>
		<link>http://www.probabil.eu/virusi-pe-yahoo-messenger.html</link>
		<comments>http://www.probabil.eu/virusi-pe-yahoo-messenger.html#comments</comments>
		<pubDate>Fri, 29 Jan 2010 17:54:31 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[yahoo messenger]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=710</guid>
		<description><![CDATA[In ultimele zile a fost o avalansa de virusi pe Yahoo Messenger. Am primit o gramada de mesaje cu profilul porno: tu ti-ai facut profilu asta?  http://roamateursxx.freehostking.com/profile.php?user=id cine ti-a pus pozele aici?? :0 hxtp://supercool.001webs.com/profile.php?user=id cine ti-a pus pozele aici?? :0 hxtp://realhot.001webs.com/profile.php?user=id tu esti aici http://profilexx.001webs.com/profile.php?user=id Din numarul de mesaje primite pe Yahoo Messenger, imi dau [...]]]></description>
			<content:encoded><![CDATA[<p>In ultimele zile a fost o avalansa de virusi pe Yahoo Messenger.<br />
Am primit o gramada de mesaje cu <em><strong>profilul porno</strong></em>:</p>
<blockquote><p><strong>tu ti-ai facut profilu asta?  http://roamateursxx.freehostking.com/profile.php?user=id</strong></p>
<p><strong>cine ti-a pus pozele aici?? :0 hxtp://supercool.001webs.com/profile.php?user=id</strong></p>
<p><strong>c</strong><strong>ine ti-a pus pozele aici?? :0 hxtp://realhot.001webs.com/profile.php?user=id</strong></p>
<p><strong>tu esti aici <img src="http://www.probabil.eu/wp-content/plugins/yahoo-messenger-emoticons/emoticons/laughing.gif" style="border:none;background:none;vertical-align:-25%;" alt="laughing" /> http://profilexx.001webs.com/profile.php?user=id</strong></p></blockquote>
<p>Din numarul de mesaje primite pe Yahoo Messenger, imi dau seama ca au fost infectate multe persoane!</p>
<p>Pentru devirusare urmati pasii de <a href="http://www.probabil.eu/2010/02/18/virus-net-worm-win32-kido-kidokiller-exe/" target="_blank">aici</a> si <a href="http://www.faravirusi.com/2010/01/27/httpprofilexx-001webs-com-site-infectat-propagat-prin-yahoo-messenger-devirusare/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.faravirusi.com/2010/01/27/httpprofilexx-001webs-com-site-infectat-propagat-prin-yahoo-messenger-devirusare/?referer=');">aici</a>! <img src="http://www.probabil.eu/wp-content/plugins/yahoo-messenger-emoticons/emoticons/happy.gif" style="border:none;background:none;vertical-align:-25%;" alt="happy" /><br />
<em><strong>Nu mai dati click pe link&#8217;urile dubioase si folositi un AntiVirus bun si updatat la zi!</strong></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/virusi-pe-yahoo-messenger.html/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>Profilul porno &#8211; un nou virus!</title>
		<link>http://www.probabil.eu/profilul-porno-un-nou-virus.html</link>
		<comments>http://www.probabil.eu/profilul-porno-un-nou-virus.html#comments</comments>
		<pubDate>Wed, 27 Jan 2010 21:03:31 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.probabil.eu/?p=690</guid>
		<description><![CDATA[http://profilexx.001webs.com Dupa virusul de pe Hi5, a aparut un nou virus care se raspandeste pe Yahoo Messenger. Este un virus inteligent, reusind sa poarte adevarate conversatii cu cei din lista celui infectat, iar in cele din urma reuseste (sau nu) sa-si convinga interlocutorul sa dea click pe un link infectat. Metoda folosita de acest virus [...]]]></description>
			<content:encoded><![CDATA[<p><em>http://profilexx.001webs.com</em></p>
<p>Dupa virusul de pe <a href="http://www.probabil.eu/2010/01/03/atentie-virus-nou-pe-hi5/" target="_blank">Hi5</a>, a aparut un nou virus care se raspandeste pe Yahoo Messenger. Este un virus inteligent, reusind sa poarte adevarate conversatii cu cei din lista celui infectat, iar in cele din urma reuseste (sau nu) sa-si convinga interlocutorul sa dea click pe un link infectat.<br />
Metoda folosita de acest virus pare destul de inteligenta: trimite mesaje pe Y!M de genul: &#8220;Ti-am gasit pozele pe profilexx .. &#8220;.<br />
Fetele, in general destul de curioase, fara nicio banuiala, intra pe site-ul cu pricina. Odata ajunse pe acel site, li se cere sa instaleze ultima versiune de Macromedia Shockwave player (la fel ca in imaginea de mai jos).<br />
Ideal ar fi sa nu intrati pe link-uri suspecte primite pe Y!M (si nu numai).</p>
<p><span id="more-690"></span></p>
<p style="text-align: center;"><a href="http://www.probabil.eu/wp-content/uploads/2010/01/virus-profilul-porno.JPG"><img class="size-medium wp-image-692 aligncenter" title="virus-profilul-porno" src="http://www.probabil.eu/wp-content/uploads/2010/01/virus-profilul-porno-300x225.jpg" alt="virus-profilul-porno" width="300" height="225" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/profilul-porno-un-nou-virus.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Atentie! Virus nou pe Hi5!</title>
		<link>http://www.probabil.eu/atentie-virus-nou-pe-hi5.html</link>
		<comments>http://www.probabil.eu/atentie-virus-nou-pe-hi5.html#comments</comments>
		<pubDate>Sat, 02 Jan 2010 23:09:18 +0000</pubDate>
		<dc:creator>odracir</dc:creator>
				<category><![CDATA[Utile]]></category>
		<category><![CDATA[hi5]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://probabil.eu/?p=333</guid>
		<description><![CDATA[In timp ce ma uitam pe un profil de hi5 mi-a aparut o casuta de download: hi5update.exe. Initial am ignorat casuta de download si m-am uitat mai departe pe alte profiluri de hi5 si din nou surpriza: hi5update.exe. Am observat ca doar pe unele profiluri imi aparea casuta de download. Fara dar si poate este [...]]]></description>
			<content:encoded><![CDATA[<p>In timp ce ma uitam pe un profil de hi5 mi-a aparut o casuta de download: hi5update.exe. Initial am ignorat casuta de download si m-am uitat mai departe pe alte profiluri de hi5 si din nou surpriza: hi5update.exe. Am observat ca doar pe unele profiluri imi aparea casuta de download.<br />
Fara dar si poate este un virus asa ca nu il downloadati! Hi5 nu isi va face niciodata update prin patchuri .exe (sper!).<br />
Eu va recomand sa nu il downloadati. Voi alegeti: cheia e la voi! <img src="http://www.probabil.eu/wp-content/plugins/yahoo-messenger-emoticons/emoticons/tongue.gif" style="border:none;background:none;vertical-align:-25%;" alt="tongue" /></p>
<p>Pentru a sterge acest virus (in cazul in care v-a fost infectat profilul) intrati la sectiunea <em><strong>About me</strong></em> sau <em><strong>Interest</strong></em>, iar acolo veti gasi un cod mai ciudat cu embed:  stergeti-l si salvati modificarile facute.</p>
<p><strong>Scanat Online pe Kaspersky.com:</strong><br />
hi5update.exe –<strong> infected by Trojan.Win32.Buzus.cxad</strong></p>
<p>Cred ca e vorba de virusul ala inteligent de pe mess (ala care reuseste sa poarte discutii cu cei din lista infectata, iar apoi le da linkul infectat, astfel incat ai crede ca vorbesti chiar cu persoana respectiva).</p>
<p><em><strong>Iata de ce este in stare acest virus:</strong></em><br />
<strong>*</strong> Isi creeaza procese care sa fie executate la pornirea calculatorului, de unde pot rezulta actiuni ce pot fi facute in mod automat, fara acordul vostru.<br />
<strong>* </strong>Isi creeaza fisiere in folder-ul in care este instalat Windows-ul. Fisierele malware obisnuiesc sa isi tina copii de rezerva acolo pentru a nu fi descoperite de utilizatorii calculatorului, dat fiind faptul ca acolo nu umbla nimeni.<br />
<strong>*</strong> Creaza si modifica fisiere din calculator care nu sunt temporare.<br />
<strong>*</strong> Creaza procese in timpul executiei sale care va suprasolicita procesorul.<br />
<strong>*</strong> Citeste si modifica intrarile din registri. Se poate sa fie un keylogger care inregistreaza fiecare tasta pe care o apasati si fiecare aplicatie pe care o porniti pe calculator.</p>
<p style="text-align: center;"><a href="http://probabil.eu/wp-content/uploads/2010/01/hi5-update21.JPG" target="_blank" onclick="pageTracker._trackPageview('/outgoing/probabil.eu/wp-content/uploads/2010/01/hi5-update21.JPG?referer=');"><img class="size-medium wp-image-335      aligncenter" title="hi5-update2" src="http://probabil.eu/wp-content/uploads/2010/01/hi5-update21-300x225.jpg" alt="hi5-update2" width="300" height="225" /></a></p>
<p><strong><span style="color: #ff0000;">!</span>Update</strong><br />
<span id="more-333"></span></p>
<p><a href="http://rstcenter.com/forum/membru-nytro.rst" target="_blank" onclick="pageTracker._trackPageview('/outgoing/rstcenter.com/forum/membru-nytro.rst?referer=');">Nytro</a> a studiat putin mai amanuntit acest virus:</p>
<blockquote><p>Test hi5update.exe<br />
Se copiaza in: Windows/system32/winlog.exe<br />
StartUp: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
Trimite date catre: 188.27.212.206 ( Romania , Bucuresti, RDS ) &#8211; XAMPP<br />
Posibil ca datele sa fie salvate in: http://188.27.212.206/log.txt</p></blockquote>
<blockquote><p>Datele sunt trimise cryptat ( cred ).<br />
Scan simplu ( nmap ):<br />
PORT STATE SERVICE<br />
25/tcp filtered smtp<br />
80/tcp open http<br />
135/tcp filtered msrpc<br />
139/tcp filtered netbios-ssn<br />
443/tcp open https<br />
445/tcp filtered microsoft-ds</p>
<p>Inca nu stiu exact ce vrea sa faca, cred ca este stealer, a &#8220;cautat&#8221; prin Temporary Internet Files si alte foldere gen Cookies de la Internet Explorer. Probabil doar IE pentru ca nu am si Mozilla sau altceva.</p>
<p>Revin cu mai multe detalii dupa ce studiez logurile. Pentru a scapa de el stergeti-l din system32 si scoteti-l de la startup.</p></blockquote>
<p>Intre timp, <a href="http://rp-legal.ro/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/rp-legal.ro/?referer=');">siteul</a> pe care era <em>gazduit</em> initial virusul, a fost suspendat in urma unui mail trimis de <a href="http://rstcenter.com/forum/membru-sonyxbz.rst" target="_blank" onclick="pageTracker._trackPageview('/outgoing/rstcenter.com/forum/membru-sonyxbz.rst?referer=');">sonyxbz</a> companiei respective de hosting, insa virusul (o noua versiune modificata <em>genetic</em>) si-a gasit un nou hosting:</p>
<p style="text-align: center;">
<a href="http://probabil.eu/wp-content/uploads/2010/01/hi5-update-brazi-craciun.png" target="_blank" onclick="pageTracker._trackPageview('/outgoing/probabil.eu/wp-content/uploads/2010/01/hi5-update-brazi-craciun.png?referer=');"><img class="size-medium wp-image-345      aligncenter" title="hi5-update-brazi-craciun" src="http://probabil.eu/wp-content/uploads/2010/01/hi5-update-brazi-craciun-300x176.png" alt="hi5-update-brazi-craciun" width="300" height="176" /></a></p>
<p><a href="http://rstcenter.com/forum/membru-nytro.rst" target="_blank" onclick="pageTracker._trackPageview('/outgoing/rstcenter.com/forum/membru-nytro.rst?referer=');">Nytro</a> a analizat si ce-a de-a doua varianta a virusului:</p>
<blockquote><p>Are 217kb, celalalt avea 60. Sa vad diferente&#8230;<br />
Pentru inceput:<br />
E cryptat cu Polifemo Ebrio Crypter. Encryptia cred ca e RC4. Crypterul e scris tot in Visual Basic 6.<br />
Noul IP e: 79.117.73.154 ( Romania, Constanta, RDS ) &#8211; 3728.zapto.org<br />
Si mai e unul de SUA: nf4-no-ip.com ( 69.65.5.122 ) &#8211; Dar nu imi dau seama ce legatura are.<br />
Se copiaza in : Windows/system32/boot.exe<br />
Ca sa scapati de el stergeti boot.exe din C:\Windows\system32<br />
Se pune la startup la: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Font</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.probabil.eu/atentie-virus-nou-pe-hi5.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

