<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Tutoriale PC &#187; VIRUSI</title> <atom:link href="http://www.tutorialepc.ro/category/securitate/protectie-virusi-spyware-malware/feed" rel="self" type="application/rss+xml" /><link>http://www.tutorialepc.ro</link> <description>Tutoriale Windows - Tutoriale securitate PC</description> <lastBuildDate>Fri, 03 Feb 2012 21:16:38 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Devirusare &#8220;It is you on the video&#8221; &#8211; virus de Facebook</title><link>http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html</link> <comments>http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html#comments</comments> <pubDate>Tue, 26 Jul 2011 11:50:06 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[devirusare]]></category> <category><![CDATA[Facebook]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=2621</guid> <description><![CDATA[De ceva vreme pe Facebook se propaga un nou virus ce intampina utilizatorul cu un set de mesaje inainte de ai distribui un link catre acesta. Mesajele sunt in Engleza si arata in genul urmator: hi, how are you? Wanna laugh? It is you on the video? )) want to see? dupa care vi se [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: left;">De ceva vreme pe Facebook se propaga un nou virus ce intampina utilizatorul cu un set de mesaje inainte de ai distribui un link catre acesta. Mesajele sunt in Engleza si arata in genul urmator:</p><ul
style="text-align: left;"><li>hi, how are you?</li><li>Wanna laugh?</li><li>It is you on the video? )) want to see?</li></ul><div
style="text-align: left;">dupa care vi se va distribui un link asemanator cu: http://207.204.110.114/100001765568988, care de asemenea va poate redirectiona catre un link ca acesta: <em>http://94.103.209.30/Flash-Player.exe urmand descarcarea fizica a virusului. </em></div><div
style="text-align: left;">De preferat ca atunci cand mai intalniti update-uri de genul flash player sau java sa le faceti de pe site-urile sursa http://www.adobe.com si http://www.java.com.</div><div><span
id="more-2621"></span></div><div><p><a
href="http://www.tutorialepc.ro/wp-content/uploads/2011/07/conversatie-virus-facebook.png"><img
class="aligncenter size-full wp-image-2647" title="conversatie virus facebook" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/conversatie-virus-facebook.png" alt="" width="493" height="543" /></a></p><p>In momentul de fata cam 65% din antivirusii cu care Virustotal scaneaza il detecteaza si va fi blocat, insa daca l-ati luat cu ceva zile inainte veti avea supriza ca Facebook-ul si anumite website-uri sa nu le mai puteti accesa.</p></div><h2><span
class="Apple-style-span" style="font-size: 15px;">Devirusare &#8220;It is you on the video&#8221;</span></h2><p>Avand in vedere ca marea majoritate a antivirusilor il detecteaza nu ar mai trebui sa fie vreo problema in a va remedia aceasta problema.</p><p>In cazul in care nu dispuneti de vreun antivirus cel mai usor mod de a scapa de acest virus luat de pe Facebook este sa descarcati Malwarebytes de aici.</p><p><a
title="Download Malwarebytes " href="http://malwarebytes-anti-malware.en.softonic.com/download"><img
class="aligncenter size-full wp-image-2648" title="Download Malwarebytes" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/Download-Malwarebytes.png" alt="" width="478" height="46" /></a></p><p>Dupa instalarea care este una extrem de usoara gen: next next next si finish lasati-l sa isi faca update, dupa care dati o scanare Quick eventual, apasati pe <strong>Remove Selected</strong> (un buton cu negru undeva in dreapta jos) apoi un restart pentru a sterge tot ce a gasit si nu a putut sa stearga in modul activ al windows-ului.</p><h2><span
class="Apple-style-span" style="font-size: 20px;">Virus &#8211; Nu mai pot accesa Facebook-ul</span></h2><div>Dupa ce v-ati asigurat ca a-ti scapat de acest virus, pentru a putea <strong>accesa</strong> in continuare <strong>Facebook</strong>-ul va trebui sa stergeti fisierul <strong>hosts</strong> aflat in urmatoarea cale:</div><div><ul><li>%windir%\system32\drivers\etc\</li><li>unde %windir% reprezinta calea catre folderul windows, care de obicei C:\Windows\</li><li>de asemenea pentru a naviga mai repede catre aceea destinatie copiati calea de mai sus si introduceti-o in RUN (start &#8211;&gt; RUN) &#8211;&gt; OK</li></ul><div>In cazul in care aveti Windows 7 si din diverse motive nu va lasa sa stergeti fisierul hosts va trebui sa dezactivati UAC-ul (start &#8211;&gt; scrieti uac numai daca e in engleza windows-ul, in noua fereastra trageti de bara in jos de tot si dati OK), dati restart si acum ar trebui sa va lase, dupa care de preferat ar fi sa activati din nou UAC-ul.</div><h3>Date tehnice virus Facebook</h3><p>Creaza in folderul %windir% urmatoarele fisiere si foldere, dintre care</p><pre>%windir%\btc_client_iplist.txt
%windir%\ddh_iplist.txt
%windir%\front_ip_list.txt
%windir%\geoiplist
%windir%\geoiplist.rar
%windir%\iecheck_iplist.txt
%windir%\info1
%windir%\iplist.txt
%windir%\l1rezerv.exe
%windir%\phoenix
%windir%\phoenix.rar
%windir%\proc_list1.log
%windir%\rpcminer
%windir%\rpcminer.rar
%windir%\services32.exe
%windir%\sysdriver32.exe
%windir%\sysdriver32_.exe
%windir%\systemup.exe
%windir%\ufa
%windir%\ufa.rar
%windir%\unrar.exe
%windir%\update.1
%windir%\update.2
%windir%\update.5.0</pre><a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/download-malwarebytes' title='Download Malwarebytes'><img
width="128" height="39" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/Download-Malwarebytes-150x46.png" class="attachment-thumbnail" alt="Download Malwarebytes" title="Download Malwarebytes" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/conversatie-virus-facebook' title='conversatie virus facebook'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/conversatie-virus-facebook-150x150.png" class="attachment-thumbnail" alt="conversatie virus facebook" title="conversatie virus facebook" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/conversatie-virus-facebook-2' title='conversatie virus facebook'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/conversatie-virus-facebook1-150x150.png" class="attachment-thumbnail" alt="conversatie virus facebook" title="conversatie virus facebook" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/10' title='10'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/10-150x150.png" class="attachment-thumbnail" alt="10" title="10" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/8' title='8'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/8-150x150.png" class="attachment-thumbnail" alt="8" title="8" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/7' title='7'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/7-150x150.png" class="attachment-thumbnail" alt="7" title="7" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/6' title='6'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/6-150x150.png" class="attachment-thumbnail" alt="6" title="6" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/5' title='5'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/5-150x150.png" class="attachment-thumbnail" alt="5" title="5" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/4' title='4'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/4-150x150.png" class="attachment-thumbnail" alt="4" title="4" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/3' title='3'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/3-150x150.png" class="attachment-thumbnail" alt="3" title="3" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/2-2' title='2'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/2-150x150.png" class="attachment-thumbnail" alt="2" title="2" /></a> <a
href='http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/attachment/1' title='1'><img
width="96" height="96" src="http://www.tutorialepc.ro/wp-content/uploads/2011/07/1-150x150.png" class="attachment-thumbnail" alt="1" title="1" /></a><pre><span class="Apple-style-span" style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; font-size: 13px; line-height: 19px; white-space: normal;">Virusul creaza in folderul %temp% urmatoarele fisiere:</span></pre><pre>55033_myunrar2.exe
2136041.exe
7637544.exe</pre><p>Deci, pentru cei care vor sa isi deviruseze calculatorul manual va trebui sa stearga fisierele indicate mai sus.</p><p>Aveti grija ca in folderele update.1 &#8230;update.5.0 exista virusi cu denumirea de <strong>svchost.exe </strong>ce ruleaza cu drepturi de SYSTEM lucru va face imposibil deosebirea virusului in Task Manager de svchost-urile bune ale windows-ul.</p><p>Pentru acest lucru va sfatuiesc sa folositi in loc de Task Manager soft-ul<a
title="Process Explorer" href="http://technet.microsoft.com/en-us/sysinternals/bb896653" target="_blank"> Process Explorer</a> de la Microsoft in combinatie cu <a
title="Descarca autoruns" href="http://technet.microsoft.com/en-us/sysinternals/bb963902" target="_blank">Autoruns</a> (aveti grija ce stergeti cu acesta din urma).</p></div> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/devirusare-it-is-you-on-the-video-virus-de-facebook.html/feed</wfw:commentRss> <slash:comments>31</slash:comments> </item> <item><title>Devirusare Xp Security Antivirus 2011 sau Xp Anti-Spyware 2011</title><link>http://www.tutorialepc.ro/devirusare-xp-security-antivirus-2011.html</link> <comments>http://www.tutorialepc.ro/devirusare-xp-security-antivirus-2011.html#comments</comments> <pubDate>Wed, 20 Apr 2011 18:47:50 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[Antivirusi]]></category> <category><![CDATA[devirusare]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=2390</guid> <description><![CDATA[De ceva vreme circula pe net tot felul de mesaje, in special de email ce raspandesc fisiere executabile si au ca si icoana cea de la fisierele de tip PDF. De preferat ar fi sa nu rulati aceste fisiere, insa daca a-ti facut-o ceea ce asa cred, pentru ca altfel nu a-ti fi ajuns aici, [...]]]></description> <content:encoded><![CDATA[<p>De ceva vreme circula pe net tot felul de mesaje, in special de email ce raspandesc fisiere executabile si au ca si icoana cea de la fisierele de tip PDF.</p><p>De preferat ar fi sa nu rulati aceste fisiere, insa daca a-ti facut-o ceea ce asa cred, pentru ca altfel nu a-ti fi ajuns aici, iata cum puteti sa scapati de acest tip de malware:</p><p>O data ce rulati acel executabil in calculatorul vostru incepe sa ruleze un antivirus fals asemanator ca si denumirea celor de mai jos:</p><ul><li><strong>Xp antivirus 2011</strong></li><li><strong>Xp security 2011</strong></li><li><strong>Xp internet security 2011</strong></li><li><strong>Win 7 antivirus</strong></li><li><strong>Xp Anti-Spyware 2011<br
/> </strong></li></ul><p>Dupa rularea acestui fals antivirus veti fi intampinati de diferite mesaje cum ca aveti calculatorul infectat, insa chiar el este virusul.</p><div
class="wp-caption aligncenter" style="width: 550px"><img
title="Xp security antivirus 2011" src="https://lh3.googleusercontent.com/_kUAOM7IGd90/Ta8jSnxVZtI/AAAAAAAAB2s/yOBZ6SXylUo/xp%20antivirus%202011.png" alt="Xp security antivirus 2011" width="540" height="386" /><p
class="wp-caption-text">Xp security antivirus 2011</p></div><h4><span
style="color: #000000;"><span
id="more-2390"></span>Specificatiile generale</span> xp antivirus 2011, xp security 2011 si xp internet security 2011:</h4><ul><li>o data rulat acest fals antivirus se copiaza in <span
style="text-decoration: underline;">%AppData%\Local\[aleator].exe</span> si ruleaza in taskmanager sub denumirea <span
style="text-decoration: underline;">[aleator.exe]</span>. De obicei<em><span
style="text-decoration: underline;"> [aleator] inseamna 3 litere .exe</span></em> (<em>nu confundati cu alg.exe</em>)</li><li>creaza urmatoarele chei de registri:</li></ul><p
style="text-align: left;"><span
class="textarea"> HKEY_CURRENT_USER\Software\Classes\.exe<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\open<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\start<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\DefaultIcon<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas\command<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start\command<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = &#8220;&#8221;%AppData%\yun.exe&#8221; /START &#8220;%1&#8243; %*&#8221;<br
/> HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = &#8220;&#8221;%1&#8243; %*&#8221;<br
/> HKEY_CURRENT_USER\Software\Classes\.exe | @ = &#8220;pezfile&#8221;<br
/> HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = &#8220;application/x-msdownload&#8221;<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | @ =&#8221;%AppData%\yun.exe&#8221; /START &#8220;%1&#8243; %*&#8221;<br
/> HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | IsolatedCommand =&#8221;"%1&#8243; %*&#8221;</span></p><p
style="text-align: left;"><span
class="textarea"> </span></p><div
class="wp-caption aligncenter" style="width: 550px"><a
href="https://lh3.googleusercontent.com/_kUAOM7IGd90/Ta8jSm0NOhI/AAAAAAAAB20/Kde27WMBiKc/s800/xp%20internet%20security%202011.png"><img
title="Internet Security 2011" src="https://lh6.googleusercontent.com/_kUAOM7IGd90/Ta8jSoXMQYI/AAAAAAAAB2w/htIJPBvzHJQ/xp%20security%202011.png" alt="Internet Security 2011" width="540" height="415" /></a><p
class="wp-caption-text">Internet Security 2011</p></div><p>&nbsp;</p><p
style="text-align: left;"><span
style="font-size: 15px; font-weight: bold;">Devirusare Xp Antivirus 2011, Xp Anti-Spyware 2011</span></p><p>Iata ce trebuie sa faceti pentru a devirusa calculatorul infectat cu xp antivirus 2011, xp internet security 2011 sau xp security 2011:</p><ul><li>in primul rand trebuie sa stergeti urmatoarele key de registri:</li></ul><blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br
/> HKEY_CURRENT_USER\Software\Classes\exefile</p></blockquote><ul><li>stergeti fisierul creat de virus, acesta poate fi gasit in calea: %AppData%\[aleator].exe, dar aveti grija el este <a
title="Restaureaza setarile facute de virusi" href="http://www.tutorialepc.ro/restaureaza-setarile-facute-de-virusi-cu-un-singur-click.html">ascuns</a></li></ul><p>Daca stiti ca aceste lucruri nu le puteti duce la bun sfarsit si in deplina siguranta pentru sistemul vostru de operare mai jos aveti un utilitar creat de mine special  pentru acest tip de malware.</p><h3><a
title="xp security antivirus 2011 remover" href="http://www.tutorialepc.ro/wp-content/download/xp%20security%20antivirus%202011%20remover.rar" target="_blank">Download xp security antivirus 2011 remover</a></h3><p><span
style="color: #ff0000;">Atentie</span>: Utilitarul este facut in asa fel incat acesta sterge toate fisierele <strong>.exe</strong> din folderul <strong>%AppData%</strong>. De obicei aici nu ar trebui sa existe nici un executabil, insa daca stiti ca aveti ceva salvat pe acolo ar fi bine sa il copiati in alta parte</p><p>In cazul in care antivirusul a sters acest antivirus fals, iar atunci cand  rulati orice executabil sunteti intampinati de fereastra de mai jos, va trebui sa stergeti cheile de registri indicate mai sus ruland utilitarul <em>regedit.exe</em> din windows cu <em><strong>click dreapta </strong></em>si <strong> </strong><em><strong>run as </strong></em>apoi click direct pe OK, ori ruland <strong><a
title="xp antivirus 2011 remover" href="http://www.tutorialepc.ro/wp-content/download/xp%20security%20antivirus%202011%20remover.rar" target="_blank">Xp Anti-Spyware 2011 remover</a></strong>.</p><p>Virusul nu afecteaza doar rularea programelor la dublu click, lasand posibilitatea utilizatorului sa ruleze orice program numai cu functia RUN AS.</p><div
class="wp-caption aligncenter" style="width: 407px"><img
title="Xp antivirus 2011 open with" src="https://lh6.googleusercontent.com/_kUAOM7IGd90/Ta8nsbChgYI/AAAAAAAAB28/xH2JQ_ynzn8/xp%20antivirus%202011%20open%20with.png" alt="Xp antivirus 2011 open with" width="397" height="472" /><p
class="wp-caption-text">Xp antivirus 2011 open with</p></div><p>PS: acestea sunt toate ip-urile site-urilor celor care raspandesc acest fals antivirus. Nu dati curs nici unei comenzi chiar daca pare tentanta. Calculatoarele din spatele ip-urilor listate mai jos au toate ca si sistem de operare linux-ul (de obicei CENTOS) si SSH-ul activat ceea ce ma face sa cred ca acest lucru a fost posibil datorita unui bug in cadrul sistemului de operare neacoperit de catre proprietarii acestor servere.</p><p>208.43.137.17<br
/> 173.193.161.106<br
/> 173.193.161.104<br
/> 173.193.161.105<br
/> 173.193.161.70<br
/> 208.43.137.18<br
/> 208.43.231.77<br
/> 174.37.179.36<br
/> 208.43.231.79<br
/> 209.97.213.9<br
/> 50.23.166.50<br
/> 208.43.231.76<br
/> 50.22.211.145<br
/> 209.97.213.11<br
/> 208.43.231.78<br
/> 50.22.211.146<br
/> 209.97.213.8<br
/> 50.22.211.147<br
/> 209.160.42.96<br
/> 174.37.179.37<br
/> 208.43.137.16<br
/> 174.37.179.38<br
/> 209.160.41.178<br
/> 50.23.166.53<br
/> 209.160.42.91<br
/> 209.160.42.89<br
/> 208.43.231.79<br
/> 208.43.231.77<br
/> 50.23.166.53<br
/> 208.43.231.76<br
/> 174.37.179.38<br
/> 174.37.179.36<br
/> 208.110.67.102<br
/> 50.23.166.50<br
/> 208.43.231.78<br
/> 208.110.67.119<br
/> 174.37.179.37<br
/> 50.22.211.146<br
/> 208.43.137.16<br
/> 64.46.38.130<br
/> 50.22.211.144<br
/> 65-254-54-77<br
/> 208.110.67.121<br
/> 64.46.38.145<br
/> 64.46.38.129<br
/> 208.110.67.122<br
/> 50.22.211.147<br
/> 209.97.213.9<br
/> 50.22.211.145<br
/> 209.97.213.8<br
/> 209.97.213.11<br
/> 209.97.213.9<br
/> 50.23.166.53<br
/> 208.43.231.77<br
/> 208.43.231.79<br
/> 208.43.231.78<br
/> 50.23.166.50<br
/> 174.37.179.36<br
/> 174.37.179.38<br
/> 174.37.179.37<br
/> 208.43.137.16<br
/> 208.43.231.76<br
/> 209.97.213.9<br
/> 50.22.211.145<br
/> 50.22.211.147<br
/> 50.22.211.146<br
/> 64.46.38.145<br
/> 50.22.211.144<br
/> 209.97.213.8<br
/> 64.46.38.130<br
/> 208.110.67.102<br
/> 64.46.38.129<br
/> 208.110.67.119<br
/> 208.110.67.121<br
/> 65-254-54-77<br
/> 208.110.67.122<br
/> 209.97.213.11</p><p>&nbsp;</p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/devirusare-xp-security-antivirus-2011.html/feed</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Atentie! pagini Youtube false “Hot Video” redirectioneaza catre malware</title><link>http://www.tutorialepc.ro/atentie-pagina-youtube-falsa-redirectioneaza-catre-malware.html</link> <comments>http://www.tutorialepc.ro/atentie-pagina-youtube-falsa-redirectioneaza-catre-malware.html#comments</comments> <pubDate>Tue, 31 Aug 2010 18:20:24 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1799</guid> <description><![CDATA[Chiar daca tentative din trecut de virusare a utilizatorilor prin vulnerabilitati ale site-ului Youtube nu au fost unele insemnate si cu efecte majore, iata ca cu ceva timp in urma firma Zscaler a descoperit nu mai putin de 3 milioane de pagini clona a popularului site de media. Toate acestea sunt o copie cei drept nu [...]]]></description> <content:encoded><![CDATA[<p>Chiar daca tentative din trecut de virusare a utilizatorilor prin vulnerabilitati ale site-ului Youtube nu au fost unele insemnate si cu efecte majore, iata ca cu ceva timp in urma firma Zscaler a descoperit nu mai putin de 3 milioane de pagini clona a popularului site de media.</p><p>Toate acestea sunt o copie cei drept nu prea reusita, dar pentru un utilizator incepator chiar si mediu il poate duce in eroare si astfel acesta se poate alege cu un <strong>Antivirus Fals.</strong></p><p><strong> </strong></p><div
class="wp-caption aligncenter" style="width: 409px"><img
title="Atentie! pagini  YouTube false" src="http://lh3.ggpht.com/_kUAOM7IGd90/TH0_h8zabdI/AAAAAAAABms/97oVRnnhoIY/s640/1.png" alt="Atentie! pagini  YouTube false" width="399" height="640" /><p
class="wp-caption-text">Atentie! pagini  YouTube false</p></div><p><span
id="more-1799"></span></p><p
style="text-align: left;">Detectia acestui <strong>Fals Antivirus </strong>(packupdate106_2033.exe, packupdate107_2033.exe, packupdate8_2033.exe, packupdate9_2033.exe,  )<strong> </strong>este destul de slaba doar 6 din 43 conform site-ului VirusTotal.</p><p>Iata si lista acestora:</p><p>AntiVir                  TR/Dropper.Gen<br
/> Panda                     Suspicious file<br
/> PCTools                 HeurEngine.MaliciousPacker<br
/> Sophos                   Mal/Koobface-G<br
/> Sunbelt                  Trojan.Win32.Generic!SB.0<br
/> Symantec             Packed.Generic.306</p><p>deci ca si antivirusi mai cunoscuti si care sunt in stare in acest moment de o detectie nu ar fi decat: Sophos, Panda si Symantec, Avast 5 are doar cateva site-uri in baza de date cu link-uri malitioase, dar chiar si asa tot le lasa sa se incarca. De asemenea si cei care folosesc Google Chrome o sa sesizeze o protectie in plus venit din partea acestui browser prin blocarea link-urilor malitioase.</p><div
class="wp-caption aligncenter" style="width: 550px"><img
title="Detectie Avast a link-urilor malitioase si protectie Google Chrome" src="http://lh3.ggpht.com/_kUAOM7IGd90/TH0_ifnYe3I/AAAAAAAABm0/J1DhWEEjFV4/detectie%20virus%20yotube%20fake%20page%20chrome-%20avast.png" alt="Detectie Avast a link-urilor malitioase si protectie Google Chrome" width="540" height="372" /><p
class="wp-caption-text">Detectie Avast a link-urilor malitioase si protectie Google Chrome</p></div><p>Toate paginile infectate au in componenta URL-ului cuvantul Hot Video, dupa care acestea se poat gasii. Sincer nu v-as sfatui sa faceti o cautare dupa aceasta combinatie de cuvinte deoarece cum am zis si mai sus antivirusii deocamdata au o detectie destul de slaba.</p><p>In cazul in care din curiozitate ati intrat sau pur si simplu ati dat peste o pagina de genul acesta:</p><div
class="wp-caption aligncenter" style="width: 540px"><img
title="Pagina Falsa de YouTube" src="http://lh6.ggpht.com/_kUAOM7IGd90/TH0_2TQjmWI/AAAAAAAABnE/WxagSXGz8-s/2.png" alt="Pagina Falsa de YouTube" width="530" height="504" /><p
class="wp-caption-text">Pagina Falsa de YouTube</p></div><p>dupa care vi se va cere instalarea unui pachet de codecuri pentru vizualizarea filmuletului sau veti fi atentionat de existenta unui malware in calculatorul personal:</p><p><img
class="aligncenter" src="http://lh3.ggpht.com/_kUAOM7IGd90/TH0_iYhYCcI/AAAAAAAABm4/eMtsTKEe1Ao/mesaj%20virus.png" alt="" width="373" height="177" />dupa aceasta etapa o sa fiti intampinati de o imagine destul de reala ca cea din My Computer unde asa zisul Antivirus  face o falsa scanare:</p><div
class="wp-caption aligncenter" style="width: 540px"><img
title="Mesaj Antivirus Fals - NU DESCARCATI- NU INSTALATI NIMIC " src="http://lh4.ggpht.com/_kUAOM7IGd90/TH0_ilDg31I/AAAAAAAABm8/uebc-nV5cl0/virus%20youtube.png" alt="Mesaj Antivirus Fals - NU DESCARCATI- NU INSTALATI NIMIC " width="530" height="354" /><p
class="wp-caption-text">Mesaj Antivirus Fals - NU DESCARCATI- NU INSTALATI NIMIC</p></div><p>In cazul in care ati ajuns aici ar fi bine sa nu descarcati nimic si in special <span
style="color: #ff0000;">sa nu rulati &#8211; instalati nimic.</span></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/atentie-pagina-youtube-falsa-redirectioneaza-catre-malware.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Un nou val de atacuri asupra anumitor website-uri</title><link>http://www.tutorialepc.ro/un-nou-val-de-atacuri-asupra-anumitor-website-uri.html</link> <comments>http://www.tutorialepc.ro/un-nou-val-de-atacuri-asupra-anumitor-website-uri.html#comments</comments> <pubDate>Sun, 09 May 2010 16:54:19 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[Wordpress]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1283</guid> <description><![CDATA[Cu ceva timp in urma a mai fost un val de atacuri cei drept asupra platformei WordPress, dar de data aceasta se pare ca nu numai ea a fost vizata. In urma cu cateva zile au aparut raportari cum ca anumite site-uri web hostate pe Go Daddy, Bluehost, Media temple, Dreamhost si Network Solutions au [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: justify;">Cu ceva timp in urma a mai fost un val de atacuri cei drept asupra platformei WordPress, dar de data aceasta se pare ca nu numai ea a fost vizata.</p><p
style="text-align: justify;">In urma cu cateva zile au aparut raportari cum ca anumite site-uri web hostate pe <strong>Go Daddy, Bluehost, Media temple, Dreamhost si Network Solutions </strong>au fost infectate cu un script java prin care utilizatorului i se prezinta o pagina falsa de scanare a calculatorului urmand ca apoi sa indrume utilizatorul spre descarcarea unui antivirus <strong>FALS</strong>.</p><p
style="text-align: justify;">Mesajul afisat de catre pagina web infectata este urmatorul:</p><div
id="_mcePaste" style="padding-left: 60px; text-align: justify;"><em>Warning! Your computer is at risk of malware attacks</em></div><div
style="padding-left: 60px; text-align: justify;"><em><br
/> </em></div><div
id="_mcePaste" style="padding-left: 60px; text-align: justify;"><em>We recommend you to check your system immediately.</em></div><div
id="_mcePaste" style="padding-left: 60px; text-align: justify;"><em>Press OK to start the process now</em></div><p
style="text-align: justify;"><a
href="http://www.tutorialepc.ro/wp-content/uploads/2010/05/rogue-warning.png"><img
class="aligncenter size-full wp-image-1284" title="rogue warning" src="http://www.tutorialepc.ro/wp-content/uploads/2010/05/rogue-warning.png" alt="" width="371" height="182" /></a>Fie ca dati Ok ori apasati pe X pentru a inchide acest mesaj pagina va continua sa se incarce si va prezenta o fereastra in care este simulata scanarea calculatorului prin care se incerca pacalirea utilizatorul sa descarce si sa ruleze <strong>FALS-UL</strong> antivirusul .</p><div
id="attachment_1285" class="wp-caption aligncenter" style="width: 560px"><a
href="http://www.tutorialepc.ro/wp-content/uploads/2010/05/antivirus-fals-fake-antivirus-warning.png"><img
class="size-full wp-image-1285" title="antivirus fals - fake antivirus warning" src="http://www.tutorialepc.ro/wp-content/uploads/2010/05/antivirus-fals-fake-antivirus-warning.png" alt="Antivirus fals - Fake antivirus warning" width="550" height="396" /></a><p
class="wp-caption-text">Antivirus fals - Fake antivirus warning</p></div><p>Pentru a evita infectarea calculatorului sfatul meu este sa inchideti pagina web iar daca vi se va cere sa descarcati sau sa rulati vreun program eu va sfatuiesc sa nu o faceti.</p><p>Din fericire <strong>Avast antivirus versiunea 5 detecteaza</strong> acest fisier (<span
style="font-family: monospace; line-height: normal; font-size: small; color: #881280; white-space: pre-wrap;">107a5f7b5729bc00d1c796f03b295bcb24b03009011.js</span>) ce incearca sa descarce automat antivirusul fals in calculatoarele voastre si va bloca orice conexiune cu site-ul infectat. Avand in vedere ca antivirusul Avast pe care il folosesc eu este unul gratuit tind sa cred ca si ceilalti antivirusi il detecteaza.</p><p>Chiar daca am deviat putin de la subiect facand aceasta lunga paranteza se pare ca web site-urile au fost infectate atat datorita  parolelor simple cat si a folderelor cu permisiuni de scriere prin care Hackeri au inserat acel cod malitios in site-uri.</p><h3>Cum poti sa iti dai seama daca ai site-ul virusat</h3><p
style="padding-left: 30px;">Urmatoarele site-uri sunt infectate avand aceste fisiere:</p><p
style="padding-left: 30px;"><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><em>http://www.indesignstudioinfo.com/ls.php</p><p>http://zettapetta.com/js.php</em></span></p><h2><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><strong>In cazul in care ai site-ul infectat aici exista o modalitate de devirusare:</strong></span></h2><p><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/" target="_blank">http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/</a></span></p><h3><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;">Conform site-ului <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com" target="_blank">VirusTotal.com</a> iata si statisticile de detectie ale acestui virus:</span></h3><p><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><strong>Pentru fisierul ce incearca descarcarea automata a virusului in calculator rata de detectie este de doar 12 din 41 adica undeva sub 30%:</strong></span></p><p><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><span
style="font-family: arial, sans-serif;"><span
style="border-collapse: collapse; line-height: normal;"><a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com/analisis/3a0cd9fd0b23ff54f28f5cbe774aea26475b78251882576f9fe09855a5ed49f7-1273424378  " target="_blank">http://www.virustotal.com/analisis/3a0cd9fd0b23ff54f28f5cbe774aea26475b78251882576f9fe09855a5ed49f7-1273424378</a></span></span></span></p><p><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><span
style="font-family: arial, sans-serif;"><span
style="border-collapse: collapse; line-height: normal;"><strong>Tot aceasi rata de detectie o au si antivirusii pentru antivirusul fals (executabilul):</strong></span></span></span></p><p><span
style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><span
style="font-family: arial, sans-serif;"><span
style="border-collapse: collapse; line-height: normal;"><a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com/analisis/1b16a4c70c83b067c7cb2f6712967ce09c4a712b71408d69d2eb04c8dcf7e938-1273419353" target="_blank">http://www.virustotal.com/analisis/1b16a4c70c83b067c7cb2f6712967ce09c4a712b71408d69d2eb04c8dcf7e938-1273419353</a></span></span></span></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/un-nou-val-de-atacuri-asupra-anumitor-website-uri.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Alt virus de messenger Show la webcam gratis http://webcamsex.lx.ro</title><link>http://www.tutorialepc.ro/alt-virus-de-messenger-show-la-webcam-gratis-httpwebcamsex-lx-ro.html</link> <comments>http://www.tutorialepc.ro/alt-virus-de-messenger-show-la-webcam-gratis-httpwebcamsex-lx-ro.html#comments</comments> <pubDate>Mon, 03 May 2010 23:53:54 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <category><![CDATA[yahoo messenger]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1259</guid> <description><![CDATA[Nici nu am scapat bine de virusul despre care va povesteam in urma cu doua zile  si iata ca astazi isi face simtita prezenta un altul. Acest virus ca si cel de aici se raspandeste tot cu ajutorul clientului de Yahoo Messenger, dar spre deosebire de acela acesta este 100% detectabil de toti antivirusi de pe [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: justify;">Nici nu am scapat bine de virusul despre care va povesteam in urma cu doua zile  si iata ca astazi isi face simtita prezenta un altul.</p><p
style="text-align: justify;">Acest virus ca si cel de <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/un-nou-virus-circula-prin-messenger-im56245-jpg-www-myspace-com-exe.html">aici </a>se raspandeste tot cu ajutorul clientului de Yahoo Messenger, dar spre deosebire de acela acesta este <strong>100% detectabil </strong>de toti antivirusi de pe piata conform site-ului <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com/analisis/77c4e63f51d261fc658f19bbee2dea8f0c0c433b96a53712e3b21dd0e638ac4d-1272912260" target="_blank">VirusTotal.com</a>.</p><p
style="text-align: justify;"><strong>Mesajul primit este unul ca cel de mai jos:</strong></p><h2 style="text-align: justify;"><strong><span
style="color: #ff0000;">Show la webcam gratis http://webcamsex.lx.ro asteapta sa se incarce java si dai run</span></strong></h2><p
style="text-align: justify;"><span
style="color: #000000;">Virusul creeaza urmatoarele foldere fisiere:</span></p><p
style="text-align: justify;"><span
style="color: #000000;"><strong>%AppData%\addon.dat<br
/> %System%\Bifrost\servver.exe<br
/> %System%\Bifrost</strong></span></p><p
style="text-align: justify;"><span
style="color: #000000;">Pentru a putea rula de fiecare data cand computerul este pornit virusul isi insereaza codul in procesul explorer.exe si creaza urmatoarele chei de registri:</span></p><p
style="text-align: justify;"><strong>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost<br
/> HKEY_CURRENT_USER\Software\Bifros</strong></p><p
style="text-align: justify;">De asemenea in momentul in care utilizatorul da click pe run din apletul java, se descarca un fisier jar: http://webcamsex.lx.ro/<span
style="font-weight: normal; font-size: 13px;">Client.jar ce creeaza fisierul: %temp%\winconfig.vbs.</span></p><p
style="text-align: justify;">Acesta v-a descarca virusul de pe server: http://webcamsex.lx.ro/server.exe in folderul %temp%\update.exe si il va rula in calculatorul victimei, dupa care acesta se va copia in %System%\Bifrost.</p><p><script type="text/javascript">// 
 google_ad_client = "pub-9293175036962197"; /* 468x60, created 11/3/09 */ google_ad_slot = "1143478979"; google_ad_width = 468; google_ad_height = 60;
// ]]&gt;</script><br
/> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p><p
style="text-align: justify;">Deci ca un rezumat nici unul din fisierele amintite mai sus nu sunt simportante, ca atare nu trebuie sa faceti altceva decat sa stergeti folderul %System%\Bifrost (de cel mai multe ori c:\windows\sysmte32\Bifrost) si sa ii dati un restart la calculator.</p><p
style="text-align: justify;"><strong>Si ca o paranteza Avast versiunea 5 cu Web Shield activat va bloca accesul la site, in rest atentie mare pe ce mai dati click.</strong></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/alt-virus-de-messenger-show-la-webcam-gratis-httpwebcamsex-lx-ro.html/feed</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Un nou virus circula prin messenger &#8211; IM56245.JPG-www.myspace.com.exe</title><link>http://www.tutorialepc.ro/un-nou-virus-circula-prin-messenger-im56245-jpg-www-myspace-com-exe.html</link> <comments>http://www.tutorialepc.ro/un-nou-virus-circula-prin-messenger-im56245-jpg-www-myspace-com-exe.html#comments</comments> <pubDate>Sat, 01 May 2010 00:02:16 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[devirusare]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1248</guid> <description><![CDATA[ATENTIE: Un nou virus se transmite prin clientul de Yahoo Messenger si este inca la aceasta ora nedetectabil de catre antivirusi. Se pare ca de azi cel putin prin Romania circula un nou virus ce se raspandeste cu repeziciune prin Yahoo Messenger. Virusul  a fost activ pe aceste website-uri si apartin in totalitate Yahoo-ului : [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: justify;"><span
style="color: #ff0000;">ATENTIE: Un nou virus se transmite prin clientul de Yahoo Messenger si este inca la aceasta ora nedetectabil de catre antivirusi.</span></p><p
style="text-align: justify;">Se pare ca de azi cel putin prin Romania circula un nou virus ce se raspandeste cu repeziciune prin Yahoo Messenger.</p><p
style="text-align: justify;">Virusul  a fost activ pe aceste website-uri si apartin in totalitate Yahoo-ului :</p><p
style="text-align: justify;"><strong>hxxp://ariafotos.com/image.php</strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><strong> </strong></p><p
style="text-align: justify;"><span
style="color: #ff0000;">hxxp://zhelefun.com/image.php</span></p><p
style="text-align: justify;"><span
style="color: #ff0000;">hxxp://ceceliaimg.com/image.php</span></p><p
style="text-align: justify;"><p
style="text-align: justify;"><p
style="text-align: justify;"><strong>hxxp://tviceimg.com/image.php</strong></p><p
style="text-align: justify;">In momentul acesta link-uurile din mijloc (cele cu rosu) inca mai functioneaza asa ca atentie mare pe ce dati click in clientul de Yahoo Messenger.</p><p
style="text-align: justify;">Conform website-ului: <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com/analisis/c6501edaf1dd8e1e47eb7c04e528e7e79224df697b89471c0dd6333ef46497ed-1272436560" target="_blank">http://www.virustotal.com</a> acest virus nu este detectabil decat de doar <strong>2</strong> antivirusi (<strong>Comodo</strong> si <strong>Sophos</strong>) din <strong>40</strong> ceea ce ii confera dreptul sa faca ce vrea prin calculatoarele victimelor.</p><p
style="text-align: justify;">Virusul care poarta denumirea <strong>IM56245.JPG-www.myspace.com.exe</strong> este recunoscut de <strong>Comodo Antivirus</strong> ca <span
style="color: #ff0000;">P2PWorm.Win32.Palevo.GZA <span
style="color: #000000;">si de <strong>Sophos </strong>ca <span
style="color: #ff0000;">Mal/Rimecud-D, <span
style="color: #000000;">avand aceeasi caracteristica a numelui ca si trojanul Michael Jackson. Daca va mai amintiti de el si acela prezenta in componenta numelui un website. In cazul de fata este vorba de www.myspace.com pentru a duce utilizatorul in eroare.</span></span></span></span></p><p
style="text-align: justify;"><span
style="color: #ff0000;"><span
style="color: #000000;"><span
style="color: #ff0000;"><span
style="color: #000000;"><br
/> </span></span></span></span></p><p
style="text-align: justify;"><span
style="color: #ff0000;"><span
style="color: #000000;"><span
style="color: #ff0000;"><span
style="color: #000000;">Acest executabil de tip trojan isi creeaza urmatoarele fisiere:</span></span></span></span></p><p><script type="text/javascript">// 
 google_ad_client = "pub-9293175036962197"; /* 468x60, created 11/3/09 */ google_ad_slot = "1143478979"; google_ad_width = 468; google_ad_height = 60;
// ]]&gt;</script><br
/> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p><p
style="text-align: justify;"><strong><strong>%Windir%\infocard.exe (acesta va fi si procesul activ)<br
/> %Windir%\mds.sys<br
/> %Windir%\mdt.sys<br
/> %Windir%\winbrd.jpg</strong></strong></p><p
style="text-align: justify;"><span
style="color: #ff0000;">Scanarea am realizat-o cu <a
title="Descarca Hijackthis " href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe" target="_blank">Hijackthis </a>de la <strong>TrendMicro </strong>si <a
title="Descarca - Micorosoft Autoruns" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" target="_blank">Autoruns </a>de la <strong>Microsoft </strong>doua softuri care folosite impreuna e cam improbabil sa le scape ceva in materie de tot ce inseamna malware, spyware si troieni, mai putin virusi ce infecteaza executabilele.</span></p><p
style="text-align: justify;">De asemenea urmatoarele chei registry ii apartin:</p><p
style="text-align: left;"><span
style="color: #ff0000;"><span
style="color: #000000;"><span
style="color: #ff0000;"><span
style="color: #000000;"><strong><em><span
style="font-weight: normal;">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [Firewall Administrating = "%Windir%\infocard.exe"]<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\ [Firewall Administrating = "%Windir%\infocard.exe"]<br
/> HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ [Firewall Administrating = "%Windir%\infocard.exe"]</span></em></strong></span></span></span></span></p><p
style="text-align: justify;">In urma rularii troianului <strong>IM56245.JPG-www.myspace.com.exe </strong>acesta tine o conexiune deschisa cu ip-ul: 123.176.40.3 pe portul 2345 ce se afla in India, fiind un server apache avand porturile 443, 21 deschise si cel mai probabil vulnerabil daca nu chiar spart de hackeri.</p><p
style="text-align: justify;">Acest ip poate fi chiar sediul central al acestui virus de unde poate prelua comenzi, de aceea va recomand ca in firewall sa realizati o blocare a oricaror activitati TCP si UDP catre ip 123.176.40.3.</p><h3 style="text-align: justify;">Devirusare <strong>infocard.exe </strong><span
style="font-weight: normal;">- IM56245.JPG-www.myspace.com.exe</span></h3><p
style="text-align: justify;">Pentru devirusare va trebui sa inchideti din Task Manager procesul <strong><strong>infocard.exe</strong><span
style="font-weight: normal;">, dupa care v-a trebui sa stergeti urmatoarele fisiere:</span></strong></p><p
style="text-align: justify;"><span
style="font-weight: 800;"><strong><strong>%Windir%\infocard.exe<br
/> %Windir%\mds.sys<br
/> %Windir%\mdt.sys<br
/> %Windir%\winbrd.jpg</strong></strong></span></p><p
style="text-align: justify;">De asemenea va trebui sa inlaturati si cheile de registri amintite mai sus dar nu este neaparat nevoie ele chiar daca raman nu o sa afecteze in nici un fel sistemul de operare atata timp cat fisierele troianului nu mai exista.</p><h3>Pentru a scapa automat de acest trojan &#8211; infocard.exe am facut pentru voi un mic fisier de tip bat ce inchide si sterge virusul si pe care il puteti descarca <a
title="Devirusare Infocard.exe" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/wp-content/download/devirusare infocard.rar">de aici</a>.</h3><p><span
style="color: #ff0000;">Pentru stergerea virusului va trebui </span><span
style="color: #ff0000;">sa deschideti </span><span
style="color: #ff0000;"><span
style="color: #ff0000;">programul de 2 ori</span><span
style="color: #ff0000;">.</span></span></p><h2><span
style="color: #ff0000;"><span
style="color: #ff0000;"><strong><span
style="color: #000000;">Update virus Yahoo Messenger</span></strong></span></span></h2><p><span
style="color: #ff0000;"><span
style="color: #ff0000;"><span
style="color: #000000;">Datorita faptului ca virusul se raspandeste foarte repede acesta si-a  creat mai multe versiuni daca pot sa le spun asa.</span></span></span></p><p><span
style="color: #ff0000;"><span
style="color: #ff0000;"><span
style="color: #000000;">Pe langa fisierele amintite mai sus e posibil ca infocard.exe sa poarte si alta denumire ca: net.exe si net1.exe care se afla tot in folderul <strong>Windows.</strong></span></span></span></p><p><span
style="color: #ff0000;"><span
style="color: #ff0000;"><span
style="color: #000000;">Conexiunile de aseara pe care micul nostru virus le avea s-au diversificat astfel: </span></span></span></p><p><span
style="color: #ff0000;"><span
style="color: #ff0000;"><span
style="color: #000000;"> </span></span></span></p><div
id="_mcePaste"><div
id="_mcePaste">74.86.97.166-static.reverse.softlayer.com</div><div
id="_mcePaste">server1.beetrootmusic.com</div><div
id="_mcePaste"><span
style="color: #ff0000;">server.noapice.com.br      <strong><span
style="color: #000000;">&#8212;&#8212;&#8211;</span></strong><span
style="color: #000000;"> </span> principal</span></div><div
id="_mcePaste">mail.global.frontbridge.com</div><div
id="_mcePaste">mta-v1.mail.vip.ac4.yahoo.com</div><div
id="_mcePaste">s9b1.psmtp.com</div><div
id="_mcePaste">mxs.mail.ru</div></div><p>Deci avand in vedere ca foloseste mxs.mail.ru si psmtp.com pe portul de smtp acesta va incerca sa faca si spam. De asemenea are si functie de backdoor, deoarece dupa cateva ore de teste am observat si acest fisier umvxcr.exe in folderul utilizatorului de pc: c:\Documents and Settings\User vostru\ , cu proprietati de ascundere &#8211; hidden.</p><h2><strong><em>Pentru acest lucru am adaptat si programelul de devirusare pe care il puteti descarca </em></strong><strong><strong><em><a
title="Devirusare Infocard.exe" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/wp-content/download/devirusare infocard.rar" target="_blank">de aici</a>.</em></strong></strong><br
/> <span
style="font-weight: normal; font-size: 13px;"><span
style="color: #ff0000;">Pentru stergerea virusului va trebui </span><span
style="color: #ff0000;">sa deschideti </span><span
style="color: #ff0000;"><span
style="color: #ff0000;">programul de 2 ori</span><span
style="color: #ff0000;">.</span></span></span></h2><p
style="text-align: justify;"><p
style="text-align: justify;"><span
style="color: #ff0000;"><br
/> </span></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/un-nou-virus-circula-prin-messenger-im56245-jpg-www-myspace-com-exe.html/feed</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Ce inseamna Valentine&#8217;s day pentru Hackeri</title><link>http://www.tutorialepc.ro/ce-inseamna-valentines-day-pentru-hackeri.html</link> <comments>http://www.tutorialepc.ro/ce-inseamna-valentines-day-pentru-hackeri.html#comments</comments> <pubDate>Wed, 03 Feb 2010 20:51:55 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1130</guid> <description><![CDATA[Iata ca nu mai e mult pana o sa vina Valentine&#8217;s Day sau Ziua Indragostitilor si ca in mai toate zilele importante de peste an hackerii nu vor sta degeaba cum nici in alti ani nu au facut-o creeand noi metode din ce in ce mai sofisticate pentru a prelua controlul calculatoare din internet. Tind [...]]]></description> <content:encoded><![CDATA[<p><img
class="alignnone" title="Valentine's Day" src="http://img203.imageshack.us/img203/3826/valentinevirus.jpg" alt="" width="260" height="165" /></p><p>Iata ca nu mai e mult pana o sa vina Valentine&#8217;s Day sau Ziua Indragostitilor si ca in mai toate zilele importante de peste an hackerii nu vor sta degeaba cum nici in alti ani nu au facut-o creeand noi metode din ce in ce mai sofisticate pentru a prelua controlul calculatoare din internet.</p><p>Tind sa cred ca de aceasta zi o sa avem o noua surpriza in materie de <strong>virusi</strong> sau mai bine spus de <strong>trojan horses -cai troieni<span
style="font-weight: normal;">.</span></strong></p><p><strong><span
style="font-weight: normal;"> </span></strong>Hackerii probabil vor profita de <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/microsoft-principalul-vinovat-in-operatiunea-aurora.html" target="_blank">bug-ul din Internet Explorer 6</a> raspandind link-uri infectate prin email sau vor trimite felicitari false ce contin virusi</p><p>Un alt scenariu care se poate intampla poate fi sosirea unor mesaje de tip spam pe email sau cu ajutorul clientilor de messenger fie el Yahoo mesenger, MSN mesenger sau Google Tolk &#8211; mai putin probabil. Toate aceste au un singur scop furtul de parole ale conturile voastre sau transformarea calculatoarele din internet in noi retele de tip bot net cu ajutorul carora vor infecta noi computere.</p><p>Un caz si mai sinistru dar posibil este folosirea celor 3 metode combinate intr-una singura. Pentru cei care sunt curiosi cum s-ar putea face asa ceva am sa va dau si un raspuns in mare:</p><ul><li>Se creeaza o pagina de internet care verifica daca utilizatorul foloseste IE 6</li><li>Daca raspunsul este afirmativ atunci se aplica exploit-ul pentru Internet Explorer 6 si ii afiseaza o poza utilizatorul nestiind ce se intampla cu adevarat in calculatorul sau.</li><li>Se viruseaza calculatorul si incepe sa trimita mesaje de tip spam pe email sau Messenger (aceste 2 metode merg si combinate).</li><li>Daca utilizatorul nu foloseste Internet Explorer 6 atunci il forteaza (pacaleste) sa descare un fisier executabil continand virusul sub forma de felicitare.</li><li>De asemenea pentru o raspandire si mai mare s-ar putea apela si la implementarea functia de autorun pentru stick-urile de memorie.</li></ul><p><script type="text/javascript">// 
 google_ad_client = "pub-9293175036962197"; /* 468x60, created 11/3/09 */ google_ad_slot = "1143478979"; google_ad_width = 468; google_ad_height = 60;
// ]]&gt;</script><br
/> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p><p>Pentru a va proteja impotriva acestor amenintari eu unul va voi recomanda sa aveti instalat un <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/descarca-avast-home-edition-5-download-noua-versiune-avast.html" target="_blank">antivirus </a>cu toate update-urile la zi, un firewall &#8211; cel de Windows e deajuns daca sunteti un utilizator mediu sau avansat si in cele din urma dar poate cel mai important lucru este analiza fiecarui program descarcat de pe internet fie el primit pe messenger, email sau cu ajutorul oricarui alt soft sau browser.</p><p><em>PS: </em><span
style="color: #ff0000;"><em>Nu mai folositi browser-ul Internet explorer</em></span><em> &#8211; cum multe state europene si-au instinta utilizatorii de acest lucru am ales ca si eu sa fac la fel din metode de securitate.</em></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/ce-inseamna-valentines-day-pentru-hackeri.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Codul folosit impotriva companiei Google a fost facut public</title><link>http://www.tutorialepc.ro/codul-folosit-impotriva-companiei-google-a-fost-facut-public.html</link> <comments>http://www.tutorialepc.ro/codul-folosit-impotriva-companiei-google-a-fost-facut-public.html#comments</comments> <pubDate>Wed, 20 Jan 2010 17:50:24 +0000</pubDate> <dc:creator>jabiilord</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[Google]]></category> <category><![CDATA[INTERNET]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1083</guid> <description><![CDATA[Probabil ca deja a-ti aflat cum ca Google si Adobe au fost tinta unor atacuri prin care hackerii au reusit sa fure anumite date din cele doua compani, iar primul suspect in acest caz ar fi guvernul Chinez. Hackerii s-au folosit de un bug in Internet Explorer versiunile 6, 7 si 8 in care acesta [...]]]></description> <content:encoded><![CDATA[<p>Probabil ca deja a-ti aflat cum ca Google si Adobe au fost tinta unor atacuri prin care hackerii au reusit sa fure anumite date din cele doua compani, iar primul suspect in acest caz ar fi guvernul Chinez.</p><p>Hackerii s-au folosit de un bug in <span
style="color: #ff0000;">Internet Explorer versiunile 6, 7 si 8</span> in care acesta permite rularea de cod fara a mai instinta utilizatorul de descarcarea si rularea acestuia.</p><p>Exploit-ul folosit in atacul asupra celor doua companii a fost facut public pe data de 14.01.2010 fiind uplodat pe site-ul http://wepawet.iseclab.org pentru a fi analizat, astfel el putand fi descarcat de oricine.</p><div
class="wp-caption aligncenter" style="width: 560px"><a
title="Codul folosit in atacul catre Google este acum public" href="http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js" target="_blank"><img
title="Codul folosit in atacul catre Google este acum public" src="http://img63.imageshack.us/img63/8070/codulfolositinataculcat.png" alt="Codul folosit in atacul catre Google este acum public" width="550" height="269" /></a><p
class="wp-caption-text">Codul folosit in atacul catre Google este acum public</p></div><p>Atacul este unul de mare amploare daca se ia in calcul numarul de utilizatori care inca mai folosesc Internet Explorer si faptul ca pe Internet Explorer 6 are cele mai mari sanse de reusita.</p><p><em><span
style="color: #ff0000;">Expertii in securitate remocanda folosirea altor browsere ca Google Chrome, Mozila FireFox sau Opera, toate nefiind afectate de aceasta vulnerabilitate.</span></em></p><p><em><span
style="color: #ff0000;"><br
/> </span></em></p><p><script type="text/javascript">// 
 google_ad_client = "pub-9293175036962197"; /* 468x60, created 11/3/09 */ google_ad_slot = "1143478979"; google_ad_width = 468; google_ad_height = 60;
// ]]&gt;</script><br
/> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p><p><span
style="color: #000000;">Pentru cei care doresc sa afle daca <strong>antivirusul</strong> lor confera o <strong>protectie impotriva acestui exploit</strong> pot descarca codul sursa al acestui de <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.esnips.com/nsdoc/dc309e80-e4be-4c20-ac82-3ec295c8cb9a/?action=forceDL" target="_blank">aici</a> sau puteti trage un ochi pe site-ul <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.virustotal.com/analisis/1fd3ea87d361c365b43fb884087d0590e3a0db6f6799071c6ba9920617ce519a-1263981302" target="_blank">VirusTotal</a> unde va puteti da seama daca acesta are sau nu o definitie implementat.</span></p><p><span
style="color: #000000;"><br
/> </span></p><p><span
style="color: #000000;">Acum 3 zile numarul antivirusilor care confereau protectie era destul de mic (12 din 41) insa acum a ajuns la 51.22% din (21 din 41). Versiunea <a
href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/descarca-avast-home-edition-5-download-noua-versiune-avast.html" target="_blank">Avast Home Edition 5</a> prezentata intr-un articol anterior are deja o definite pentru acest exploit si este gata sa sara in ajutorul utilizatorului.</span></p><p><span
style="color: #000000;">Daca Microsoft nu va scoate un patch cat mai repede la aceasta vulnerabilitate multe firme cat si calculatoare personale ar putea fi intr-un real pericol daca cratorul virusului Conflicker/Downadup ar profita de acesta vulnerabilitate si ar incerca din nou raspandirea acestuia dar sub o alta varianta.</span></p><p><span
style="color: #000000;"><br
/> </span></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/codul-folosit-impotriva-companiei-google-a-fost-facut-public.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Devirusare Data Doctor 2010 &#8211; o noua inventie malware &#8211; rogue</title><link>http://www.tutorialepc.ro/devirusare-data-doctor-2010-o-noua-inventie-malware-rogue.html</link> <comments>http://www.tutorialepc.ro/devirusare-data-doctor-2010-o-noua-inventie-malware-rogue.html#comments</comments> <pubDate>Wed, 13 Jan 2010 18:16:44 +0000</pubDate> <dc:creator>jabiilord</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[devirusare]]></category> <category><![CDATA[SECURITATE]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=1042</guid> <description><![CDATA[Probabill ca multi dintre voi ati avut cel putin o data calculatorul infectat cu malware sau programe de tip rogue care va aratau diverse avertismente cum ca aveti o imensitate de virusi, malware sau trojeni pe calculator si asta numai cu scopul de a va scutura de niste bani. Cu Data Doctor 2010 va puteti [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: justify;">Probabill ca multi dintre voi ati avut cel putin o data calculatorul infectat cu malware sau programe de tip rogue care va aratau diverse avertismente cum ca aveti o imensitate de virusi, malware sau trojeni pe calculator si asta numai cu scopul de a va scutura de niste bani.</p><p
style="text-align: center;"><img
class="aligncenter" title="Devirusare Data Doctor 2010" src="http://img690.imageshack.us/img690/6977/datadoctor2010.jpg" alt="" width="500" height="373" /></p><p
style="text-align: justify;">Cu <strong>Data Doctor 2010 </strong>va puteti alege de pe diverse website-uri, dar numai prin acceptarea acestui fisier si rularea lui, dupa care virusul va afisa un mesaj de eroare &#8220;Unrecognized disk driver command&#8221; si va reporni calculatorul in in safe mode.</p><p
style="text-align: center;"><a
href="http://www.sunbeltsoftware.com/alex/gblog/1.png" target="_blank"><img
class="aligncenter" src="http://www.sunbeltsoftware.com/alex/gblog/1.png" alt="" width="598" height="304" /></a></p><p
style="text-align: justify;"><span
id="more-1042"></span>Ei bine acest program de tip rogue <strong>Data Doctor 2010</strong> nu numai ca este la fel de deranjant ca si celelalte, dar de fiecare data cand incercati sa accesati fisiere de pe hard disk acesta le cripteaza, urmand un mesaj de eroare ca cel de mai jos:</p><p
style="text-align: center;"><a
href="http://www.sunbeltsoftware.com/alex/gblog/3.png" target="_blank"><img
class="aligncenter" title="Devirusare Data Doctor 2010" src="http://www.sunbeltsoftware.com/alex/gblog/3.png" alt="" width="598" height="304" /></a></p><p
style="text-align: left;">Pentru a devirusa calculatorul si a scapa de <strong>Data Doctor 2010 </strong>va trebui sa stergeti urmatoarele fisiere, dar nu inainte de a inchide procesul virusului din <strong>Task Manager </strong>si anume <strong>fs.exe.</strong></p><p
style="text-align: left;"><p
style="text-align: left;">%UserProfile%\Start Menu\Programs\DataDoctor\DataDoctor.lnk<br
/> %UserProfile%\Start Menu\Programs\DataDoctor\Uninstall DataDoctor.lnk<br
/> %UserProfile%\Start Menu\Programs\DataDoctor\DataDoctor on the Web.url<br
/> %UserProfile%\Start Menu\Programs\DataDoctor<br
/> %ProgramFiles%\DataDoctor 2010\unins000.exe<br
/> %ProgramFiles%\DataDoctor 2010\unins000.dat<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.startup.dll<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.shredder.dll<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.regclean.dll<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.privacy.dll<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.inetopt.dll<br
/> %ProgramFiles%\DataDoctor 2010\modules\module.filefix.dll<br
/> %ProgramFiles%\DataDoctor 2010\fs.exe<br
/> %ProgramFiles%\DataDoctor 2010\ddreg.dll<br
/> %System%\msvcp71.dll</p><p
style="text-align: left;">Dupa stergea fisierelor de mai sus va mai trebui sa stergeti urmatoarea cheie din registri:</p><p
style="text-align: left;">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Uninstall\{C6869864-8987-4067-9666-BEA678E823F3}_is1</p><p
style="text-align: left;">Daca din greseala a-ti accesat unele fisiere si a-ti intimpinat eroarea &#8220;Unable to open the file due to data coruption&#8221; pentru decriptatrea acestora va trebui sa folositi urmatorul program dezvoltat de cei de la <strong>Sunbelt.</strong></p><p
style="text-align: left;"><strong><a
href="http://sunbelt-software.com/support/dd2010_decrypter.rar">http://sunbelt-software.com/support/dd2010_decrypter.rar</a></strong></p><p
style="text-align: left;">Aici aveti o mica descriere cum se foloseste acest program de decriptare:</p><p
style="text-align: left;">The syntax for dd2010_decrypter.exe is: “dd2010_decrypter.exe input_file output_file&#8221;.</p><ol><li>Download dd2010_decrypter.rar.</li><li>Unzip the file (dd2010_decrypter.exe) into a directory</li><li>From a command window, switch to that directory.</li><li>Type &#8220;dd2010_decrypter.exe (input_file) (output_file)&#8221;</li></ol><p>dd2010_decrypter.exe will leave the original encrypted file intact and create the new, unencrypted, file that you named. If you use a different name for the file, you won’t overwrite the original.</p><p>Pentru mai multe informatii puteti accesa urmatorul link: <a
href="http://www.sunbeltsecurity.com/DownLoads.aspx">http://www.sunbeltsecurity.com/DownLoads.aspx</a></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/devirusare-data-doctor-2010-o-noua-inventie-malware-rogue.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>KeyScrambler &#8211; anti-keylogger perfect</title><link>http://www.tutorialepc.ro/keyscrambler-anti-keylogger-perfect.html</link> <comments>http://www.tutorialepc.ro/keyscrambler-anti-keylogger-perfect.html#comments</comments> <pubDate>Thu, 29 Oct 2009 13:34:32 +0000</pubDate> <dc:creator>Ionut</dc:creator> <category><![CDATA[VIRUSI]]></category> <category><![CDATA[INTERNET]]></category> <category><![CDATA[keylogger]]></category> <category><![CDATA[Mozila FireFox]]></category> <category><![CDATA[virusi]]></category> <guid
isPermaLink="false">http://www.tutorialepc.ro/?p=757</guid> <description><![CDATA[KeyScrambler este un plugin ce se instaleaza in browser si confera utilizatorului protectie maxima impotriva programelor de tip keylogger. Acesta cripteaza tot ce se introduce de la tastatura inainte ca un keylogger sa preia informatia dar doar pentru Internet Explorer, Mozila Firefox si Flock. Criptarea datelor se face la nivelul driver-ului tastaturii si decriptarea are [...]]]></description> <content:encoded><![CDATA[<p
style="text-align: justify;"><strong>KeyScrambler </strong>este un plugin ce se instaleaza in browser si confera utilizatorului protectie maxima impotriva programelor de tip keylogger. Acesta cripteaza tot ce se introduce de la tastatura inainte ca un keylogger sa preia informatia dar doar pentru <strong>Internet Explorer, Mozila Firefox si Flock</strong>.</p><p
style="text-align: justify;">Criptarea datelor se face la nivelul driver-ului tastaturii si decriptarea are loc in momentul in care informatia ajunge in browser, astfel protectia conturilor si parolelor voastre in <strong>KeyScrambler Personal </strong>va fi posibila doar in browserele amintite.</p><p><img
class="aligncenter" title="Anti-keylogger KeyScrambler Personal" src="http://www.qfxsoftware.com/screenshots/KS_Windows7_Logon_small.jpg" alt="" width="385" height="289" /></p><p
style="text-align: justify;"><span
style="background-color: #ffffff;">Pentru protectia in alte browsere ca de exemplu Google Chrome, Opera, etc este nevoie de varianta <strong>KeyScrambler Professional</strong> avand un pret de 29.99$, iar daca doriti o protectie a intregului calculator si aici ma refer la Microsoft Office, Yahoo Messenger, logarea in calculator, etc, atunci varianta <strong>KeyScrambler </strong><strong>Premium</strong> va sta la dispozitie care din pacate are un pret destul de mare 44.99$.</span></p><p
style="text-align: justify;"><span
style="background-color: #ffffff;"><strong>KeyScrambler Personal</strong> ma uimit prin faptul ca indiferent daca computer-ul vostru este sau nu infectat cu un keylogger acesta ofera in continuare protectie, numai sa speram ca autorii programelor de tip keylogger nu vor integra optiune in ele de a inlatura acest mic pluggin.</span></p><p
style="text-align: justify;">Pentru a descarca versiunea gratuita: <strong>KeyScrambler Personal &#8211; certificat Softpedia</strong> accesati link-ul de mai jos:</p><p
style="text-align: justify;"><a
style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; vertical-align: baseline; color: #e08105; text-decoration: underline; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.qfxsoftware.com/download/KeyScrambler_Setup.exe" target="_blank">http://www.qfxsoftware.com/download/KeyScrambler_Setup.exe</a></p><p
style="text-align: justify;">sau mergeti la ei pe site-ul  Oficial: <a
style="outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; vertical-align: baseline; color: #e08105; text-decoration: underline; cursor: pointer; padding: 0px; margin: 0px;" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.qfxsoftware.com/download/KeyScrambler_Setup.exe" target="_blank">http://www.qfxsoftware.com</a></p><p
style="text-align: justify;">Pentru a va faceti o idee despre cum lucreaza urmariti videoclipul de mai jos:</p><p><object
classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param
name="allowFullScreen" value="true" /><param
name="allowscriptaccess" value="always" /><param
name="src" value="http://www.youtube.com/v/4Zxn2tiAsKA&amp;hl=en&amp;fs=1&amp;color1=0x2b405b&amp;color2=0x6b8ab6" /><param
name="allowfullscreen" value="true" /><embed
type="application/x-shockwave-flash" width="480" height="385" src="http://www.youtube.com/v/4Zxn2tiAsKA&amp;hl=en&amp;fs=1&amp;color1=0x2b405b&amp;color2=0x6b8ab6" allowscriptaccess="always" allowfullscreen="true"></embed></object></p><p
style="text-align: justify;"><em>Daca  insa doriti totusi o protectie mai extinsa pe care nu vreti sa dati banii asa cum am explicat </em><a
title="Anti-keylogger cu tastatura virtuala" href="http://www.tutorialepc.ro/redirect/redirect.php?url=http://www.tutorialepc.ro/protectie-keyloggers-protejeazati-parolele.html" target="_blank"><em>aici </em></a><em>exista varianta folosiri tastaturii virtuale care este intr-adevar putin cam incomoda dar macar e gratuita.</em></p><p><em><br
/> </em></p> ]]></content:encoded> <wfw:commentRss>http://www.tutorialepc.ro/keyscrambler-anti-keylogger-perfect.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
