Wednesday, January 14, 2009

How to remove SALITY

Sality is a virus that has backdoor capabilities and executes keylogger and may infect executable files by putting its code to host files. Once it is installed, Sality virus will infect local executable files and delete all files that are associated with anti-virus and anti-spyware applications, as well as firewalls. After this, Sality runs a keylogging module that gathers all system and network information, records passwords and login names, steals all sensitive information and sends all this collected data to a predefined email address.

In addition, Sality opens a backdoor that allows the remote attacker to get the full control over the infected computer and this places any financial or banking information stored on your computer in severe jeopardy and represents a serious security risk.

Also known as: W32/Sality (McAfee), Virus.Win32.Sality.aa (Kaspersky), W32.Sality.AE (Symantec), Virus:Win32/Sality.AM (MS OneCare), PE_SALITY.EM (Trend)

W32/Sality is a parasitic virus that infects Win32 PE executable files. It is a polymorphic virus that attempts to spread by file infection. It looks for Win32 PE executable files with .EXE or .SCR file extensions, and infects any such files found on the system by appending the virus body to the host file.

The virus also attempts to propagate by copying itself with a random filename to network drives, including all removable disk drives. Sality.AA also creates an "autorun.inf" file in these drives so that the virus executes when it is accessed.

Upon execution, it drops the following files into the Windows system directory:
  • %Windir%\System32\Hdaudprop.dll
  • %Windir%\System32\Hdaudpropres.dll
  • %Windir%\System32\Hdaudpropshortcut.exe
  • %Windir%\System32\drivers\Hdaudbus.sys
  • %Windir%\System32\drivers\Hdaudio.sys
  • %Windir%\System32\drivers\portcls.sys
Creates the following registry keys:
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WMI_MFC_TPSHOCKER_80
  • HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\IPFILTERDRIVER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline

and it downloads further malware from the following domains:
  • bpowqbvcfds677.info
  • aapowqbvcfds677.info
  • abpowqbvcfds677.info
  • d98dc9.bpowqbvcfds677.info
  • bmakemegood24.com
  • d99395.bmakemegood24.com
  • bbeakemegood24.com
  • bperfectchoice1.com
  • d998b6.bperfectchoice1.com
  • cbparfectchoice1.com
  • cbpbrfectchoice1.com
  • bcash-ddt.net
  • d9aab7.bcash-ddt.net
  • pzrk.ru
  • dbcabh-ddt.net
  • bddr-cash.net
  • ebddrbcash.net

It also modifies the following registry entries:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"

and this virus also deletes entries in the following registry subkeys:
  • HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

Sality.AA bypasses the system firewall by executing the command:
netsh firewall set opmode disable

It may also disable settings related to system security. It does this by adding the following registry entries:
  • HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusOverride = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallOverride = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\UpdatesDisableNotify = dword:00000001
  • HKLM\SOFTWARE\Microsoft\Security Center\Svc\UacDisableNotify = dword:00000001

The virus sets the following registry entry so that hidden folders and files are not displayed in Windows Explorer view:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden = 2

It also disables Registry Editor and Task Manager by adding these registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableTaskMgr = dword:00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableRegistryTools = dword:00000001

Sality.AA terminates all anti virus routine services running on the system, and prevent access to Websites that contain its names, like sality_remove, viruscan, sophos, mcafee, eset.com, kaspersky, onlinescan, and more...

The device driver is not dropped and installed onto the system unless there is an active internet connection.

The virus may prevent execution of applications that perform an integrity self-check as a result of them being infected.

So my dear friend the easiest way to tackle this virus is to Remove above mention Virus Entry Doors from registry and Delete those .DLL files from system.

Sality Manual Removal Instructions

Below is a list of Sality manual removal instructions and Sality components listed to help you remove Sality from your PC. Backup Reminder: Always be sure to back up your PC before making any changes.

Note: This manual removal process may be difficult and you run the risk of destroying your computer.

Step 1 : Use Windows File Search Tool to Find Sality Path

  • Go to Start > Search > All Files or Folders.
  • In the "All or part of the the file name" section, type in "Sality" file name(s).
  • To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
  • When Windows finishes your search, hover over the "In Folder" of "Sality", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete Sality in the following manual removal steps.

Step 2 : Use Windows Command Prompt to Unregister Sality DLL Files
  • To open the Windows Command Prompt, go to Start > Run > type cmd and then click the "OK" button.
  • Type "cd" in order to change the current directory, press the "space" button, enter the full path to where you believe the Sality DLL file is located and press the "Enter" button on your keyboard. If you don't know where Sality DLL file is located, use the "dir" command to display the directory's contents.
  • To unregister "Sality" DLL file, type in the exact directory path + "regsvr32 /u" + [DLL_NAME] (for example, :C\Spyware-folder\> regsvr32 /u Sality.dll) and press the "Enter" button. A message will pop up that says you successfully unregistered the file.
  • Search and unregister "Sality" DLL files: syslib32.dll, sysdll.dll, oledsp32.dll

Step 3 : Detect and Delete Other Sality Files
  • To open the Windows Command Prompt, go to Start > Run > type cmd and then press the "OK" button.
  • Type in "dir /A name_of_the_folder" (for example, C:\Spyware-folder), which will display the folder's content even the hidden files.
  • To change directory, type in "cd name_of_the_folder".
  • Once you have the file you're looking for type in "del name_of_the_file".
  • To delete a file in folder, type in "del name_of_the_file".
  • To delete the entire folder, type in "rmdir /S name_of_the_folder".
  • Select the "Sality" process and click on the "End Process" button to kill it.
  • Remove the "Sality" processes files: syslib32.dll, sysdll.dll, oledsp32.dll, oledsp32.dll, sysdll.dll, syslib32.dll
source: (viruscontra)

The best tool to remove sality variants is the kaspersky removal tool.
Plug your infected to another PC (slave) and rrin the tool.

Thursday, December 4, 2008

Windows 7 Ultimate Milestone 2 (M2) Build 6589.1




INFO:

Windows 7 Milestone 2 Ultimate Edition is alive, kicking and as real as they get! Although it's but one year away from the moment Windows Vista hit the shelves, and despite being in the final stages of development of Windows Vista Service Pack 1 and Windows XP Service Pack 3, Microsoft is also building Windows 7.At this point in time,Windows 7 is being dogfooded inhouse by Microsoft. However, the successor of Windows Vista was also shipped in an early stage to a select pool of the Redmond company's key partners.

On January 24, you were able to feast your eyes on the first ever leaked screenshots from Windows 7 Ultimate Edition version 6.1
(Build 6519.1.x86fre.winmain.071220-1525), courtesy of ThinkNext.

Because of numerous accusations that the images had been tampered with, and were fake, the Chinese blog posted the video embedded at the bottom of this article. Yes, this is Windows 7

"I was about to share something interesting about Windows 7 in my last post,Windows 7: The Real Thing. The ISO image, bootable, installation, evaluation and the screenshots are all real. I mean there is no Photoshop or anything like that involved,"reads a fragment from ThinkNext."I'm not a person who makes himself complacent by faking something hot, neither will I be unhappy if someone denies the real information I posted. I don't mean to draw much attention, especially from those suckers.

Users that are running Windows Media Center under Vista Home Premium and Ultimate SKUs will undoubtedly notice differences when it comes to the WMC running in the Ultimate edition of Windows 7. While the interface is approximately the same, the text size has changed, and so has the number of categories.

In fact,Windows 7 M2 is nothing more than an artificially customized image of Windows Vista Service Pack 1, masquerading as the next version of Windows. Even more, there has been no official confirmation of Windows 7 Milestone 2 from Microsoft or from other sources. In this context, M2 is as good as inexistent.

Windows 7 M2 comes, as all software under development from Microsoft."I don't think there is anything wrong, disappointing or weird that Windows 7 Milestone 2 isn't greatly different from Vista. It's only Milestone 2 so lots of code may be reused. Besides, even we can't see much visual changes, that doesn't mean Win7 internals don't change greatly. Here from the release notes, I read: 'the software will stop running on June 2008. You may not receive any other notice. You may not be able to access data used with the software when it stops running'," added ThinkNext.



Screens & Features


The Real Windows 7 Ultimate Milestone 2 (M2) Build 6589.1






Bootable On ISO Format




Support About 90 Languages



Activated And Genuine Windows



Working Firewall And Updates




Milestone 2 Ultimate Edition 6589.1.

Try: Post your comment for the download link.

Wednesday, November 26, 2008

Flash Disinfector

Flash Disinfector was designed to remove unwanted files including autorun.inf on removable USB drives, flash drives and memory sticks. Use flash disinfector if you cannot access your USB drives, flash drives and memory stick due to modifications done by autorun Worms.

Author: sUBs

Operating System: Windows 2000/XP/Vista

Download Here:
Flash Disinfector

Threat Removal Procedure:
1. Download Flash_Disinfector and save it ot your Desktop.2
2. After downloading, double-click on Flash_Disinfector to run it.
3. Just follow the prompts and continue until it begin scanning.
4. If asked to insert your flash drive or any removable device including USB Pen Drive and Memory Stick, please do so.
5. It will scan removable drives, wait for the scan to finish. Done.


Wednesday, October 22, 2008

Microsoft Windows SHORTCUT Keys

Internet Explorer Shortcuts:


CTRL+A - Select all items on the current page
CTRL+D - Add the current page to your Favorites
CTRL+E - Open the Search bar
CTRL+F - Find on this page
CTRL+H - Open the History bar
CTRL+I - Open the Favorites bar
CTRL+N - Open a new window
CTRL+O - Go to a new location
CTRL+P - Print the current page or active frame
CTRL+S - Save the current page
CTRL+W - Close current browser window
CTRL+ENTER - Adds the http://www. (url) .com
SHIFT+CLICK - Open link in new window
BACKSPACE - Go to the previous page
ALT+HOME - Go to your Home page
HOME - Move to the beginning of a document
TAB - Move forward through items on a page
END - Move to the end of a document
ESC - Stop downloading a page
F11 - Toggle full-screen view
F5 - Refresh the current page
F4 - Display list of typed addresses
F6 - Change Address bar and page focus
ALT+RIGHT ARROW - Go to the next page
SHIFT+CTRL+TAB - Move back between frames
SHIFT+F10 - Display a shortcut menu for a link
SHIFT+TAB - Move back through the items on a page
CTRL+TAB - Move forward between frames
CTRL+C - Copy selected items to the clipboard
CTRL+V - Insert contents of the clipboard
ENTER - Activate a selected link
HOME - Move to the beginning of a document
END - Move to the end of a document
F1 - Display Internet Explorer Help


Windows Explorer Shortcuts:


ALT+SPACEBAR - Display the current window’s system menu
SHIFT+F10 - Display the item's context menu
CTRL+ESC - Display the Start menu
ALT+TAB - Switch to the window you last used
ALT+F4 - Close the current window or quit
CTRL+A - Select all items
CTRL+X - Cut selected item(s)
CTRL+C - Copy selected item(s)
CTRL+V - Paste item(s)
CTRL+Z - Undo last action
CTRL+(+) - Automatically resize the columns in the right hand pane
TAB - Move forward through options
ALT+RIGHT ARROW - Move forward to a previous view
ALT+LEFT ARROW - Move backward to a previous view
SHIFT+DELETE - Delete an item immediately
BACKSPACE - View the folder one level up
ALT+ENTER - View an item’s properties
F10 - Activate the menu bar in programs
F6 - Switch between left and right panes
F5 - Refresh window contents
F3 - Display Find application
F2 - Rename selected item


Windows XP Shortcut:


ALT+- (ALT+hyphen) Displays the Multiple Document Interface (MDI) child window's System menu
ALT+ENTER View properties for the selected item
ALT+ESC Cycle through items in the order they were opened
ALT+F4 Close the active item, or quit the active program
ALT+SPACEBAR Display the System menu for the active window
ALT+TAB Switch between open items
ALT+Underlined letter Display the corresponding menu
BACKSPACE View the folder one level up in My Computer or Windows Explorer
CTRL+A Select all
CTRL+B Bold
CTRL+C Copy
CTRL+I Italics
CTRL+O Open an item
CTRL+U Underline
CTRL+V Paste
CTRL+X Cut
CTRL+Z Undo
CTRL+F4 Close the active document
CTRL while dragging Copy selected item
CTRL+SHIFT while dragging Create shortcut to selected iteM
CTRL+RIGHT ARROW Move the insertion point to the beginning of the next word
CTRL+LEFT ARROW Move the insertion point to the beginning of the previous word
CTRL+DOWN ARROW Move the insertion point to the beginning of the next paragraph
CTRL+UP ARROW Move the insertion point to the beginning of the previous paragraph
SHIFT+DELETE Delete selected item permanently without placing the item in the Recycle Bin
ESC Cancel the current task
F1 Displays Help
F2 Rename selected item
F3 Search for a file or folder
F4 Display the Address bar list in My Computer or Windows Explorer
F5 Refresh the active window
F6 Cycle through screen elements in a window or on the desktop
F10 Activate the menu bar in the active program
SHIFT+F10 Display the shortcut menu for the selected item
CTRL+ESC Display the Start menu
SHIFT+CTRL+ESC Launches Task Manager
SHIFT when you insert a CD Prevent the CD from automatically playing
WIN Display or hide the Start menu
WIN+BREAK Display the System Properties dialog box
WIN+D Minimizes all Windows and shows the Desktop
WIN+E Open Windows Explorer
WIN+F Search for a file or folder
WIN+F+CTRL Search for computers
WIN+L Locks the desktop
WIN+M Minimize or restore all windows
WIN+R Open the Run dialog box
WIN+TAB Switch between open items

src:markiee.com