PDA

View Full Version : A nasty virus that you should block



coldfire01
07-10-2009, 08:02 PM
There is something going on today with our current yahoo messengers lately or msn

a message or an email popping up messages such as this....


prns7777triippersxyx.com <--- copyy this to your broowser to see me geting nakked for you on myCam !!

OH ????????? listen , after u copy paste it to your browwser you MUST delete the 7777 or else it wont work uugc05 7x04pl 4ao 7u76025 gff
Last message received on 7/11 at 9:32 AM



solution? pretty simple though... block the source... but the problem is they have multiple links and they seem to update it every now and then.

Also what if unsuspected brother/sister/cousins etc gets to curiously check the link and boom! virus infiltration

Here is simple steps on how to determine if a website you just received is a virus link.

1. Always use proxy websites to browse websites. So that you can avoid infection from them. My suggestion is using www.ktunnel.com then check no scripts and no cookies so that no infromation will be attached or downloaded.

2. Use proper blocking of websites. In this case it can't be helped to block the website but instead cut the source. To know the IP address of these sick twisted freaks just type this website http://www.selfseo.com/find_ip_address_of_a_website.php then type that suspicious link there. It will populate an IP address and that is where those virus links are coming from. Block that instead of the website since they have a way of tunneling and grabbing enormous URL links that still route to the same Main web page.

3. Once the IP address is located. For example this guy's IP is The IP address 62.219.250.70 is assigned to Israel use that IP address to block all his mirror websites that get routed to the same main page.

NOTE: DO NOT TYPE IN THAT IP ADDRESS ON YOUR INTERNET BROWSER! YOU WILL BE SEVERLY INFECTED IF YOU DO!

Block that IP using your handy dandy website blocking tools. I would recommend the Admuncher trial

here is a link where you can download a copy
http://coldfire01.110mb.com/Ad%20Muncher%20v4.7.27105.1383.zip

just unzip it... oh yah it only runs on windows xp or higher ... unfortunately not in mac....

4. Block the website IP that you found using the software of your choice. On Ad Muncher, once it is installed, right click on the icon on the bottom right of your window. It is near the clock so you can't miss it. Click on Configure then click on My filters Tab. Click on New on the right then type the IP address on the entry. Choose the drop down menu Block Retrieval of URL to block the website.


If you have any other harmful websites to block. Feel free to post it here so that others can update their own Adblock to avoid any dangerous Websites like these.

Also be aware that the IP address that you are blocking can change in time. Hackers and virus programmers are using Fake proxies to hide thier identity against Internet Police and FBI.

I have to admit i have a Somalian Mountain IP address whenever i am doing something nasty hehe .....just kidding.

Share this info to your friends so that we can have the internet a safe place to be in again.


Note: There will be a problem on Yahoo or MSN if you use adblock. Please add the websites or IP addresses on safe websites and Choose drop down list as "NO filtering on URL" to let them in. Other than that it is an effective program.

zevlag21
07-10-2009, 08:13 PM
no worry i am a MAC user

tonyu56
07-10-2009, 09:53 PM
i still like windows better.... and if u do get a virus just run AVAST! boot scan it gets like everything

coldfire01
07-11-2009, 10:11 AM
i still like windows better.... and if u do get a virus just run AVAST! boot scan it gets like everything

Latest viruses cant be detected by Avast!... That is a known fact since they are just a few programmers who are working on anti virus definitions.


it is best practice that you make your own personal precautions. By being proactively blocking, removing, providing other people and users information about these threats that you help contribute a better environment for everyone.

Even though they are talented hackers/virus programmers. They still cannot overpower the entire community who are against them if we all worked together to improve our systems.

It is up to you guys to decide what to do. I am just sharing my best practices as a fellow programmer.

solidoxygen
07-11-2009, 10:31 AM
Another tip about suspicious pop-ups is that you should close them (end process) with the task manager if you want to be on the safe side.
Not all pop-ups are required to be closed this way though; since sometimes they are just real advertisements.
You can never be quite sure about those pr0n pop-ups.
Sometimes what appears to be the close button (x) is not what it appears to be.

Saw this tip on a CNN video a while ago.

coldfire01
07-12-2009, 10:11 AM
Another tip about suspicious pop-ups is that you should close them (end process) with the task manager if you want to be on the safe side.
Not all pop-ups are required to be closed this way though; since sometimes they are just real advertisements.
You can never be quite sure about those pr0n pop-ups.
Sometimes what appears to be the close button (x) is not what it appears to be.

Saw this tip on a CNN video a while ago.

Yes that is also a good idea. It is best that you take precautions by also installing pop up blockers and also Advertisement blocks to ensure that all (even safe ones like google) will be blocked.


i still like windows better.... and if u do get a virus just run AVAST! boot scan it gets like everything

I dont think that is recommended being reliant on antivirus alone. Some high level viruses attach themselves to windows/system32 files. In my previous experience, i had to reformat a pc after being hit by a nasty virus that attached himself in one of the boot dll's I scheduled my Avast! antivirus on a boot time sector scan and set it on delete all (i was a noob back then sorry). When i deleted all the infections, the pc doesnt boot anymore for it is already missing several dlls and causing it to turn into the blue screen of death.

Also another drawback is the time consumed. When you are in boot time schedule scan, and you have insanely huge HDD. You find yourself scanning waiting for hours (mine is actually 4-6 hours). Not all have the luxury of time to wait that long for your PC to be like that. It would be fun if you are downloading gigabytes of data or uploading some but with Boot scan you can't.

Best choice is to avoid threats by being proactive at latest threats and share best practices.

avich
07-13-2009, 06:14 AM
• If you want to browse safely, install WOT add-on in Firefox, it checks the links for you to see whether it is safe.

• If you have more knowledge on web scripting, you can install NoScript. It blocks all scripts by default. This is annoying if you don't know what scripting is about and you have little patience. But adding NoScript definitely makes browsing safer.

• If you are using McAfee 8 enterprise, then you can add restrictions on your computer. Disable adding/modifying system files on your C, etc...

• It is advisable that you have a separate anti-virus and anti-spyware running together. If you use S & D, make sure all of its components are running, especially TeaTimer. This scans your registry for unusual behaviors. If you can, schedule auto-update of your anti-virus and anti-spyware during times when you don't use the computer (i.e. 3:00am) and automatically scan your system once a week. If you schedule it right, it won't bother you.

• It is recommended to disable auto-run with any kind of removable devices.(Even NASA just realized this recently.)

• It is good practice to put all your downloads on one folder destination. Scan the downloaded file before running. If it double compressed, scan it once before extracting and scan again after extracting.

• Use Deep Freeze if you are paranoid and dont really know about computer security(no offense). DF to me is strictly for public computers, like internet cafe, libraries, school computer laboratory,..etc.

RogerDodger
07-13-2009, 06:38 AM
ohh avich's post is much helpful

coldfire01
07-14-2009, 07:22 PM
ohh avich's post is much helpful

Yah i forgot that. That reminds me that not all viruses are from the the internet.

Another thing is the network you are in if you shared connection with your neighbor and via USB..

About what Avich suggested. The script disabling that is also another good tip.

How to disable network sharing on your files if you are in a network.

Right click on any of your share files. To see then click on Start>My network Places>
You will see all the folders there. Right click on them then click on sharing then uncheck sharing.

You can also set your computer to disable all script enabling protocols. They also sometimes come hand in hand with the Autorun function with your USB port.

to disable script is to go to Start>Control Panel>Folder Options>
Click on File types tab

Select these extensions one at a time

JS Jscript file
JSE Jscript Script File
VBE VBscript Encoded Script file
VBS VBscript Script file
WSF Windows Script file

click on Advance
Click on Edit
Click on Set Default
Click OK

Once you finished with all extensions. you are now blocked with Script encoding Viruses that also manipulate your registry. Most viruses comes in Script form that is why antiviruses can't detect them. They just recognize them as safe script programs however they alter your Operating System.

Also be warned. If you use disable scripting, you might have problems uninstalling/installing programs since they are off. Turn them on again so that you won't have problems and turn it off again.

mikko0
07-15-2009, 02:27 AM
Linux for the win

ranmachua
07-15-2009, 11:06 PM
I've got them too but I usually close them & never open the links coz I know that my friends won't send my such a message.

coldfire01
08-15-2009, 07:54 PM
I've got them too but I usually close them & never open the links coz I know that my friends won't send my such a message.

if your friends are sending you suspicious links then that means their pc is infected already.

YOu need to help them girl so that you wont receive them anymore.

shah6287
09-04-2009, 04:41 AM
thanks for the post..it really help me.

sectionsix
09-24-2009, 12:34 AM
It's also a good idea to run all of your internet facing apps in a sand boxing program like sandboxie.

I run all my browsers and IM clients in it.

http://www.sandboxie.com/

emer333
01-03-2010, 04:46 AM
wow guys you give helpful tips.. there are many things in the internet that can harm the PC huh? :)

dand963
05-18-2011, 06:53 AM
i still like windows better.... and if u do get a virus just run AVAST! boot scan it gets like everything
umm... avast is one hell of a noisy antivirus.