Kejadian ini menimpa gw sendiri loh, kmr ad tmn valdo krm message ke YM gw..
trus ada tulisan/link dlm bhs thailand gitu.. Untung buka YM pake HP jadul
gw (yg notebene) gak ada OS nya, jd virusnya gak bs nyebar.. 
Mudah2an Manfaat..

Sebarin ke yg lain ya..

sumber berita : http://ariefew
com/antivirus-portable-windows-windows/messenger-nhattruongquang0catchcom/

Beberapa hari ini, pada chat menggunakan Yahoo Messenger, aku sering dapat
pesan :

    * Biet tin gi chua, vao day coi di http://nhattruongquang.0catch.com
    * E may, vao day coi co con nho nay ngon lam http://nhattruongquang
0catch.com
    * Vao day nghe bai nay di ban http://nhattruongquang.0catch.com
    * Vao day nghe bai nay di ban http://nhattruongquang.0catch.com
    * Biet tin gi chua, vao day coi di http://nhattruongquang.0catch.com
    * Trang Web nay coi cung hay, vao coi thu di http://nhattruongquang
0catch.com
    * Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em
roi? Ve dau khi bao nhieu mo mong gio da vo tan… Ve dau toi biet di ve dau?
http://nhattruongquang.0catch.com
    * Khoc cho nho thuong voi trong long, khoc cho noi sau nhe nhu khong.
Bao nhieu yeu thuong nhung ngay qua da tan theo khoi may bay that
xa…http://nhattruongquang.0catch.com Tha nguoi dung noi se yeu minh toi mai
thoi thi gio day toi se vui hon.
    * Gio nguoi lac loi buoc chan ve noi xa xoi, cay dang chi rieng minh
toi…http://nhattruongquang.0catch.com
    * Loi em noi cho tinh chung ta, nhu doan cuoi trong cuon phim buon.
Nguoi da den nhu la giac mo roi ra di cho anh bat ngo…
http://nhattruongquang.0catch.com
    * Tra lai em niem vui khi duoc gan ben em, tra lai em loi yeu thuong em
dem, tra lai em niem tin thang nam qua ta dap xay. Gio day chi la nhung ky
niem buon http://nhattruongquang.0catch.com

Pesan tersebut pemakai YM tidak menyadari kalau mengirim pesan seperti itu.
Apakah itu ? Ini termasuk worm yang mulai muncul akhir 2006 dan mungkin
sekarang muncul lagi dengan varian barunya..... Virus / worm ini dikenal
dengan berbagai nama antara lain :

    * Symantec : W32.Imaut.U
    * Avira : Worm/Sohanad.bm
    * Kaspersky: IM-Worm.Win32.Sohanad.bm
    * F-Secure: IM-Worm.Win32.Sohanad.bm
    * Sophos: W32/SillyFDC-G atau W32/Sohana-R
    * Panda: W32/Hakaglan.A.worm
    * Grisoft: I-Worm/Sohanad.J
    * Eset: Win32/Hakaglan.AH
    * Bitdefender: Trojan.AutoIt.TD
    * McAfee : w32/Yahlover.worm.gen.c

Platforms / OS :

    * Windows 95
    * Windows 98
    * Windows 98 SE
    * Windows NT
    * Windows ME
    * Windows 2000
    * Windows XP
    * Windows 2003

Imaut / sohanad / Hakaglan / AutoIt / Yahlover ini, menginfeksi lewat Yahoo!
Instant Messenger, Microsoft Windows Live Messenger, dan AOL Instant
Messenger. Worm akan download remote files di compromised computer dan
disable Windows Task Manager dan Registry tools. INFECTED File Copy di :

    * %SYSDIR%\RVHOST.exe
    * %WINDIR%\RVHOST.exe

Menulis schedule :

    * %WINDIR%\Tasks\At1.job File schedule task untuk run malware.

Dan melakukan download di lokasi http://nhatquanglan2.0catch.com/**********
Dan saved ke local hard drive di : %SYSDIR%\setting.ini Registry Registry
keys yg akan ditambahkan pada run the processes setelah reboot :

    * [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] •  Yahoo
Messengger="%SYSDIR%\RVHOST.exe"
    * [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] •  Shell=
Explorer.exe RVHOST.exe"

... Registry keys yang di add :

    * [HKLM\SYSTEM\ControlSet001\Services\Schedule] • 
AtTaskMaxHours=dword:00000000
    * [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
WorkgroupCrawler\Shares] •  shared="%all shared folders%\New Folder.exe"

Registry keys yang berubah : Various Explorer settings :
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] Old value
: •  NofolderOptions=%user defined settings% New value : • 
NofolderOptions=dword:00000001 Disable Regedit dan Task Manager :
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] Old value :
•  DisableTaskMgr=%user defined settings% •  DisableRegistryTools=%user
defined settings% New value : •  DisableTaskMgr=dword:00000001 • 
DisableRegistryTools=dword:00000001 Network Propaganda malware connect pada
PC lain dengan cara : copy sendiri pada network share : •  %all shared
folders%\New Folder.exe Penyembuhan

    * Disable System Restore
    * Update antivirus
    * Scan dengan anti virus yang ter update.
    * Buat file UnHookExec.inf
    * [Version] Signature=”$Chicago$” Provider=Symantec [DefaultInstall]
AddReg=UnhookRegKey [UnhookRegKey] HKLM,
Software\CLASSES\batfile\shell\open\command,,,”"”%1?” %*” HKLM,
Software\CLASSES\comfile\shell\open\command,,,”"”%1?” %*” HKLM,
Software\CLASSES\exefile\shell\open\command,,,”"”%1?” %*” HKLM,
Software\CLASSES\piffile\shell\open\command,,,”"”%1?” %*” HKLM,
Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “”%1?”" HKLM,
Software\CLASSES\scrfile\shell\open\command,,,”"”%1?” %*” HKCU,
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools,0×00000020,0 Save file tersebut dan right click -
install untuk mengembalikan fungsi regedit
    * Change dan Delete registry Windows yang telah diubah oleh worm.
    * Nilai registry yang dihapus :
         1. HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\”Shell” = “Explorer.exe ” RVHOST.exe”
         2. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\”Yahoo
Messengger” = “%System%\RVHOST.exe”
         3.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shar
s\”shared” = “[SHARED DRIVE]\New Folder.exe”
    * Ubah Registry ke nilai semula :
         1.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableTaskMg
” = “1?
         2.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableRegist
yTools” = “1?
         3.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NofolderOpt
ons” = “1?
         4. HKLM\SYSTEM\CurrentControlSet\Services\Schedule\”AtTaskMaxHours”
= “0?
         5. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\”Run” = “BkavFw”
         6. HKCU\Software\Microsoft\Windows\CurrentVersion\”Run” =
“IEProtection”

Exit registry editor / regedit.




 

[Non-text portions of this message have been removed]

Kirim email ke