| Donalddick
Virus
The
most important companies of
Antivirus reported the appearance of
new variants of the Donalddick
virus, of the category of the
Troyanos, allows other users to
enter to your PC and to make
modifications in your hard disk,
like copying, erasing and modifying
archives. Virus similar to this one
is the BackOrifice and the Netbus.
The
virus can be eliminated manually:
In
the systems W95 and 98, you must
eliminate the archives Oleproc.exe,
Vmldr.vxd, Ipegcomp.Dll, Pnpmgr.pci
and erase the following registry (To
enter the registry* open Startand
write regedit.exe, then
Enter):
KEY_LOCAL_MACHINE
and
to return to ignite the machine.
*
Take care when publishing the
registry of your computer becuase if
you eliminate or you modify
incorrect items some, programs (or
even your PC) can stop working.
In
NT you must eliminate the
Bootexec.exe, Pmss.exe, Oleproc.exe,
Jpegcomp.dll and the register
HKEY_LOCAL_MACHINE
ControlManagerfrom BootExec to
BootExecute and restart the machine.
A
slippery virus
The
Sophos investigation center reported
that in the Web there is a new
version of the macro.virus for Word
97 WM97/Verlor-A, now with the
WM97/Verlor-I name. This virus uses
several methods of security to
become way inside the system: When
you open Visual Basic Editor (VBE)
of Word, the virus creates archives
OVERLORD.b.vbs and OVERLORD.b.dll in
the directory of Windows, file
WIN.ini is altered so that it
executes file VBS whenever Windows
is initiated. The virus eliminates
itself automatically of template of
Word, but it maintains log in c:.SYS
of those archives of which it was
eliminated. When Windows is
reinitiated, file VBS reinfects the
archives previously "
desinfected " concerning the
code of the OVERLORD.b.dll (this
file is not a real DLL, but an ASCII
that contains the code of the
macro-virus). File VBS uses log that
is stored in c:.SYS to determine
which file needs to be desinfected.
List
of dangerous Virus
Be
alert. Here there is a list sent by
IBM of the email does not have to be
open because they have virus, that
can come like annexed to an email.
You have to erase them without
opening, so that the computer will
be safe and it will not suffer
damages.
The
viruses are:
1)
buddylst.exe
2)
calcu18r.exe
3)
deathpr.exe
4)
einstein.exe
5)
happ.exe
6)
girls.exe
7)
happy99.exe
8)
japanese.exe
9)
keypress.exe
10)
kitty.exe
11)
monday.exe
12)
teletubb.exe
13)
the phantom menace
14)
prettypark.exe
15)
up-grade internet2
16)
perrin.exe
17)
i love you
18)
celcom screen saver o celsaver.exe
19)
win a holiday (e-mail)
20)
join the crew o penpals
21)
eat shit.
If
you receive a message titled
"freepizza" do not open
it, eliminate it immediately.
What
is a virus?
It
is a small written program
intentionally to settle in the
computer of an user without the
knowledge or the permission of him.
We say that it is a parasitic
program because the program attacks
the archives or sectors of "
boot " and it is talked back to
itself to continue his relaxation.
They cause from the loss of data or
archives in storage medias of
information (floppy disks, hard
disk), until damages to the system
and, sometimes, include instructions
that can cause damages to the
equipment.
Some
are only limited to reproduce
themselves, whereas others can
produce serious damages that can
affect the systems. It has been
arrived at a point so, that a new
called virus W95/CIH-10xx or also as
Chernobyl (it can appear the 26 of
every month, specially 26 of June
and 26 of April) attacks the BIOS of
the PC host and to change its
configuration of such form that is
required to change it. It can be
assumed that a virus is inoffensive
and never be left " floating
" in the system.
The
classification of the virus is the
following one:
-
" pure "Virus - Trojan
horse
-
Logic bomb
-
Worm or " worm " All these
programs has in common the creation
of pernicious effects; nevertheless,
all cannot be considered like virus
themselves.
|