Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Friday, September 21, 2012

Beware - sneaky spy returns


Eset has published a list of threats, which in July this year. most infected users' computers around the globe. The top ten most active malware trojan returned Win32/Spy.Ursnif.A, which collects information about the user, such as monitoring traffic generated ICQ instant messenger and e-mail.
Spy.Ursnif.A is already known threat, which is a hybrid of spyware and Trojan horse. This malicious program showed no significant activity over the past few months. In July, however, the situation has changed. Malicious software usually gets into the computer through the same user who is social engineering tricks and downloads from the network, and then install on your machine infected file. After implantation in Spy.Ursnif.A system modifies the Windows registry so that you can activate as soon as you start your computer. The threat has also created a new user account system and adds an exception to the firewall, so that effectively masks its activity. As analysts point out threats to ESET's main task is to collect Spy.Ursnif.A user information, including the IP address and the data to the operating system and Web browser.
In addition, monitors threat to send and receive email messages, and captures passwords for various websites saved in Internet Explorer. Spy.Ursnif.A transmit collected data to a remote computer, using the HTTP protocol. As emphasized by analysts at ESET, particularly dangerous for the user may be able to run the so-called Spy.Ursnif.A. Remote Desktop through which cybercriminals can without the knowledge or consent of the user take control of the infected computer.
Spy.Ursnif.A infection can be avoided while maintaining common sense and applying the principle of limited trust files and links that users get from people in the news through the mail or IM. Each time before copying to your computer unknown file, it is worth checking it before using antivirus software or free online scanner.


Esetは7月、今年の脅威のリストを公開しています。世界中で最も感染したユーザーのコンピュータ。トップ10最もアクティブなマルウェアのトロイの木馬は、そのような生成されたトラフィックを監視するように、ユーザーに関する情報を収集しWin32/Spy.Ursnif.Aを返さICQのインスタントメッセンジャー、電子メール。
Spy.Ursnif.Aは、スパイウェアやトロイの木馬のハイブリッドで既に知られている脅威です。この悪意があるプログラムは、過去数ヶ月の間に有意な活性を示さなかった。 7月には、しかし、状況は変更されています。悪意のあるソフトウェアは、通常、ソーシャルエンジニアリングのトリックやネットワークからのダウンロードで、同じユーザを介してコンピュータに取得し、自分のマシンに感染したファイルをインストールします。あなたはできるだけ早くあなたがコンピュータを起動するように活性化することができるようにSpy.Ursnif.Aシステム内注入した後に、Windowsのレジストリを変更します。脅威はまた、新しいユーザー·アカウント·システムを作成し、その結果を効果的にマスク、その活動は、ファイアウォールに例外を追加しています。アナリストが指摘するようにESETのメインタスクへの脅威は、IPアドレス、オペレーティングシステムおよびWebブラウザへのデータを含むSpy.Ursnif.Aのユーザー情報を収集することです。
さらに、電子メールメッセージを送受信するための脅威を監視しており、Internet Explorerで保存した様々なウェブサイトのパスワードをキャプチャします。 Spy.Ursnif.Aは、HTTPプロトコルを使用して、リモートコンピュータに収集したデータを送信します。としてESETのアナリストで強調、ユーザにとって特に危険なのは、いわゆるSpy.Ursnif.Aを実行できる場合があります。サイバー犯罪者は、ユーザが気がつかずに感染したコンピュータの制御を取ることができるそれを通してリモートデスクトップ。
常識を維持し、ユーザーがメールやIMを通じてニュースの人々から得ることを制限された信頼のファイルとリンクの原理を応用しながらSpy.Ursnif.Aの感染を回避することができます。各時間は、お使いのコンピュータ未知のファイルにコピーする前に、それは、ウイルス対策ソフトウェアや無料のオンラインスキャナを使用する前にそれをチェックしてみる価値があります。


ESET的威胁,在今年7月公布的名单。世界各地的大多数被感染用户的计算机。十大最活跃的恶意软件木马返回Win32/Spy.Ursnif.A,收集有关用户的信息,如监控产生的流量ICQ即时通讯和电子邮件。
Spy.Ursnif.A是已知的威胁,这是一种混合的间谍软件和木马。在过去的几个月里,该恶意程序没有表现出显着的活动。在7月,然而,情况发生了变化。恶意软件通常会通过同一个用户是社会工程技巧和从网络上下载到计算机,然后安装在你的机器感染病毒的文件。 Spy.Ursnif.A系统植入后修改Windows注册表,只要你启动你的电脑,这样就可以激活。的威胁,也创造了一个新的用户帐户系统,并添加到防火墙的例外,这样就有效口罩的活动。分析人士指出,威胁,ESET的主要任务是,收集Spy.Ursnif.A用户的信息,包括操作系统和Web浏览器的IP地址和数据。
此外,监测发送和接收电子邮件的威胁,并捕捉各种网站的密码保存在Internet Explorer中。 Spy.Ursnif.A收集到的数据传送到远程计算机,使用HTTP协议。在ESET分析师强调,特别是危险的用户能够运行所以所谓的Spy.Ursnif.A的。远程桌面,网络罪犯可以通过控制被感染计算机的用户不知情的情况下或同意。
Spy.Ursnif.A感染可避免同时维护常识和应用的原则,信托文件和链接,用户得到的消息人士通过电子邮件或IM。每一次,然后再复制到您的计算机未知的文件,这是值得检查前使用防病毒软件或免费在线扫描。


Wednesday, September 19, 2012

Shamoon - the first criminal modeled on the Stuxnet trojan and Flame


Similar to the Stuxnet and Flame Shamoon program is being used by criminals - makes data theft and blocks the victim's computer - told Computerworld.
Analysts with the firm Seculert computer security, who first described a new Trojan horse that affects the state on both computers on the corporate network, as well as belonging to individual users. The analysis, however, shows the code that is specifically targeted to attack some people and companies. In this latter case, the target company's energy sector.
Shamoon in the first phase of the attack takes control of the systems connected to the Internet and spread on all the PCs with Windows operating system - regardless of version - working in the victim's network. Then copies the data from the compromised computer, using the acquired company's system and then forward them to the server management and control (C & C servers). Analysts working for both companies Seculert as well as for other companies in the same industry Symantec and Kaspersky Lab has not agreed so far, exactly what type of data looking for Shamoon. In the second phase of the attack, after downloading all the data relevant to the Trojan is activated mechanism of destruction - the system files are overwritten in the boot sectors of computers acquired (MBR = Master Boot Record). The result is that the operating system can no longer run.
MBR Overwriting files relates in particular to the computer from which Shamoon communicate with their C & C servers, which, according to Aviva Raffa, analyst and co-founder of Seculert aims to seize evidence, leading to the C & C server List overwritten because the file is passed to the C & C server, probably to check whether the cover-up procedure was successful.
How Symantec analysts note attack directed at specific targets, with destructive procedures are rare and hardly used since 2005. Trojans and malware work "in silence" and their creators to not depend on the seized computers attracted unnecessary attention.
Despite the similarities between Shamoon, a known malware such as Stuxent, Flame or Gauss - in the case of these last two so-called active element. Head also had a destructive process - analysts do not believe that a new Trojan, and those already known malware, created the same group of developers.
Kaspersky Lab released a list of significant differences between the Stuxnet code and Flame and Shamoonem that they think it clear that these programs have created two different groups of developers. Shamoon their opinion is "very successful ribbon" Stuxnet and the Flame, the first created by the criminal group. This is confirmed by analysts Seculert, considering that hackers can offer Shamoon data acquired by the affected party competition, or try to sell them on the black market.


トロイの木馬の新しいタイプを発見しました。 Stuxnetのと炎Shamoonプログラムと同様に、犯罪者によって使用されている - データが盗難やブロック、被害者のコンピュータを作る - Computerworld誌に語った。
第一企業ネットワーク上の両方のコンピュータ上の状態に影響を及ぼす新たなトロイの木馬を説明事務所Seculertコンピュータセキュリティ、とアナリストだけでなく、個々の利用者に属するように。分析は、しかし、具体的に何人かの人々や企業を攻撃するために対象とされるコードを示しています。この後者の場合には、対象会社のエネルギー部門。
バージョンに関係なく - - 被害者のネットワークで作業をして攻撃の最初の段階でShamoonは、Windowsオペレーティングシステムとすべてのパソコンでインターネットと普及に接続されたシステムの制御を取得します。その後、買収した企業のシステムを使用して、侵入先のコンピュータからデータをコピーしてから、サーバーの管理と制御(C&Cサーバ)に転送する。両社のために働いて、アナリストはSeculertだけでなく、同​​じ業界の他の会社のためにSymantecとKaspersky Labは、正確にどのようなタイプのShamoon探しのデータは、これまでのところ同意していない。攻撃の第二段階では、トロイの木馬に関連するすべてのデータをダウンロードした後に、破壊のメカニズムを活性化される - システムファイル(MBR =マスターブートレコード)を取得するコンピュータのブートセクタで上書きされます。結果は、オペレーティングシステムが実行されなくできることです。
MBRのファイルの上書きアビバRaffaによると、Seculertのアナリスト兼共同創設者は、C&Cサーバにつながる証拠をつかむことを目指し、それらのC&CサーバとからShamoon通信するコンピュータに特に関係する上書きリストファイルは、C&Cサーバに渡されるためには、おそらく、カバーアップの手順が成功したかどうかをチェックします。
破壊的な手順で、具体的な目標に向けどのようにシマンテックのアナリストノート攻撃はまれであり、ほとんど2005年以降使用されていません。押収されたコンピューターに依存しないように、トロイの木馬、 "沈黙の"マルウェアの仕事と、そのクリエイターは、不要な注目を集めました。
これら最後の二つのいわゆるアクティブ素子の場合 - Shamoon、そのようなStuxent、炎やガウスのような既知のマルウェアとの類似点にもかかわらず。ヘッドはまた、破壊的なプロセスを持っていた - アナリストが新しいトロイの木馬、およびそれらの既に知られているマルウェアは、開発者の同じグループを作成したことを信じていない。
Kaspersky Labは、Stuxnetのコードと炎、そして、彼らはそれを明確に、これらのプログラムは、開発者が2つの異なるグループを作成していることを考えることShamoonem間の有意差のリストを発表した。 Shamoon彼らの意見は、犯人グループによって作成された最初の、 "非常に成功したリボン" Stuxnetのと炎です。これは、ハッカーが影響を受けた当事者の競争によって取得Shamoonデータを提供したり、闇市場にそれらを販売することを試みることができることを考えると、アナリストSeculertにより確認されている。


发现了一种新的木马。类似的Stuxnet和火焰Shamoon程序正在被犯罪分子利用 - 使数据被窃取,并阻止受害者的电脑 - 告诉计算机。
分析师Seculert公司的电脑安全,他首先介绍了一个新的木马,影响企业网​​络上的两台计算机上,以及属于个人用户的状态。然而,分析,显示的代码是专门针对攻击一些个人和公司。在后一种情况下,目标公司的能源部门。
Shamoon在第一阶段的攻击进行控制的系统连接到互联网,在所有的Windows操作系统的PC传播 - 不论版本 - 在受害者的网络。从受感染的计算机上,然后复制数据,利用被收购公司的系统,然后将它们转发到服务器的管理和控制(C&C服务器)。分析师对两家公司Seculert以及其他公司在同行业中赛门铁克和卡巴斯基实验室不同意,到目前为止,究竟是什么类型的数据寻找Shamoon。在第二阶段的攻击,下载后所有有关的数据,该木马被激活机制的破坏 - 系统文件被覆盖在收购的计算机的引导扇区(MBR主引导记录)。其结果是,该操作系统将不能再运行。
MBR覆盖文件,特别是涉及从C&C服务器,Shamoon沟通,根据英杰华Raffa,分析师和共同创始人的Seculert的目的是抓住证据,导致C&C服务器的计算机清单覆盖,因为该文件传递到C&C服务器,可能检查,是否掩盖程序是成功的。
赛门铁克分析师指出,攻击破坏性程序的具体目标,是罕见的,自2005年以来,很少使用。木马和恶意软件的工作“沉默”及其创作者的不依赖于检获的电脑吸引不必要的注意。
尽管相似,之间Shamoon,一个已知的恶意软件,如Stuxent,火焰或高斯 - 的情况下,最后两个所谓的有源元件。头也有一个破坏性的过程 - 分析师并不认为,一个新的木马,那些已知的恶意软件的开发,创造了同一组。
卡巴斯基实验室发布了一个名单Stuxnet的代码和火焰和Shamoonem的,他们认为,这些方案已经创建了两个不同的团队开发的显着差异。 Shamoon他们的意见是“非常成功丝带”Stuxnet蠕虫和火焰,创建的第一个犯罪集团。这也证实了分析师Seculert,考虑到黑客可以提供Shamoon受影响的一方竞争获得的数据,或尝试他们在黑市上出售。


Thursday, September 13, 2012

Gauss - another spy Trojan


Kaspersky Lab announces the discovery of "Gaussian", attacking members of the new cyber threat in the Middle East. Gauss is a complex, financed by the Government of a set of tools designed to steal confidential information, especially passwords in the browser, the credentials associated with online banking, cookies, and specific configuration of infected machines.
The banking Trojan identified in the Gaussian is a unique feature not found in any previously known cyber weapons. Gauss was detected during an ongoing initiative launched by the International Telecommunication Union (ITU) after detecting Flame'a. Its aim is to reduce the risk from cyber weapons, which is a key element of efforts to achieve the overarching goal of the global cyber room.
ITU, supported by the knowledge and experience of Kaspersky Lab, is taking significant steps to increase the global cyber security through active cooperation with all relevant players, such as governments, private sector, international organizations and the public, as well as their key partners in the initiative, ITU-IMPACT.
Kaspersky Lab has detected a Gaussian by identifying common characteristics of this malicious program from previously identified cyber weapon Flame. These include similarities in architecture, the structure of modules, code, and how to communicate with the servers used by cybercriminals to control these risks.
Key facts:
- The analysis shows that Gauss has been operating since September 2011
- It was first detected in June 2012 on the basis of information obtained as a result of in-depth analysis and research on pest Flame.
- This discovery was made possible by the clear similarities and relationships between Flame and Gauss.
- Infrastructure servers that control the Gaussian was closed in July 2012, shortly after it is detected. Currently, this malware is dormant, waiting for the servers to become active again.
- From the end of May 2012, based on the cloud security system, Kaspersky Lab recorded over 2 500 infections, and the total number of victims is estimated to be Gaussian tens of thousands. This number is lower than the Stuxnet but relatively higher than the Flame'a and Duqu.
- Gauss steals detailed information on the infected PCs, including browser history, cookies, passwords and system configurations. He can also steal credentials to access different online banking systems and payment methods.
- An analysis of the Gaussian that the worm was designed to steal data from several Lebanese banks, including Bank of Beirut, EBLF, BlomBank, ByblosBank, FransaBank and Credit Libanais. In addition, users also affects Citibank and PayPal.
Gauss was detected by Kaspersky Lab experts in June 2012, his main module is called by unknown artists from the name of the German mathematician Carl Friedrich Gauss Johann. Other components also are named after famous mathematicians, for example, Joseph-Louis Lagrange and Kurt Gödel. The study showed that the first incident involving the Gauss took place in September 2011, in July 2012, Gauss control servers stopped working.
Numerous modules are Gaussian to collect information from the browser, including the history of websites visited and passwords. To the attackers also sent details of the infected machine, including data on network interfaces, drivers, computer, and information about the BIOS. Gauss module can also steal customer data, several Lebanese banks, including Bank of Beirut, EBLF, BlomBank, ByblosBank, FransaBank and Credit Libanais. Attacks also Citibank and PayPal users.
Another major feature is the ability to infect Gaussian USB devices through the same vulnerability that Stuxnet exploited previously and Flame. The infecting USB devices, however, a more "intelligent". Gauss can "cure" such a device in certain circumstances and using removable media to store the collected information in a hidden file. Another action is to install a trojan on your system a special font called "Palidano Narrow", but the purpose of this action is still not known.
While Gauss Flame'a like in terms of design, the geographical distribution of the infection has been markedly different. The largest number of computers infected by Flame'a was recorded in Iran, and most of the victims were in a Gaussian Lebanon. Number of infections is also different. Based on telemetry Kaspersky Security Network (KSN), experts from Kaspersky Lab found that Gauss infected about 2 500 machines. For comparison, Flame infected much less, because nearly 700 machines.


Kaspersky Labは、中東での新たなサイバー脅威のメンバーを攻撃し、 "ガウス"の発見を発表しました。ガウスは、ブラウザで、特に機密情報、パスワードを盗むために設計されたツールのセットの政府が融資する、複雑で、オンラインバンキング、クッキー、および感染したマシンの特定の構成に関連付けられた資格です。
ガウシアンで同定銀行トロイの木馬は、以前に知られているサイバー兵器では見られないユニークな機能です。ガウスはFlame'aを検出した後、国際電気通信連合(ITU)が立ち上げた継続的なイニシアティブの間に検出されました。その目的は、グローバルサイバー部屋の包括的な目標を達成するための努力の重要な要素であるサイバー兵器からリスクを減らすことである。
Kaspersky Labの知識と経験でサポートされているITUは、イニシアチブは、ITU-IMPACTでそのような政府、民間部門、国際機関や公共だけでなく、彼らの重要なパートナーとして、関連するすべてのプレーヤーとの積極的な協力を通じて、グローバルサイバーセキュリティを高めるための重要な措置を講じている。
Kaspersky Labは、以前に同定されたサイバー兵器炎からこの悪意あるプログラムの共通の特性を識別することによって、ガウスを検出しました。これらは、アーキテクチャの類似性、モジュール、コード、そしてどのようにこれらのリスクを制御するためにサイバー犯罪者が使用するサーバーと通信するための構造を含んでいる。
重要な事実:
- 分析は、ガウスは2011年9月以来活動を続けていることを示しています
- これは、最初の害虫炎に関する詳細な分析と研究の結果として得られた情報に基づいて2012年6月に検出された。
- この発見は炎とガウスの間に明確な類似点との関係によって可能となった。
- ガウス分布を制御する基幹サーバは、それが検出された直後、2012年7月に閉鎖された。現在、このマルウェアは、サーバが再びアクティブになるのを待って、休止している。
- 2012年5月の終わりから、クラウド·セキュリティ·システムに基づいて、Kaspersky Labは、2 500感染にわたって記録し、犠牲者の総数は数千のガウス万と推定されています。この数値は、Stuxnetのより低いがFlame'aとDuquに比べて相対的に高くなっています。
- ガウスは、ブラウザの履歴、クッキー、パスワード、およびシステム構成など、感染したパソコンに関する詳細な情報を盗みます。彼はまた、別のオンライン·バンキング·システムおよび支払い方法にアクセスするための認証情報を盗むことができます。
- ワームはベイルート、EBLF、BlomBank、ByblosBank、FransaBankとクレジットLibanais銀行を含むいくつかのレバノンの銀行からデータを盗むように設計されたというガウスの解析。また、ユーザーはまた、シティバンクとPayPalに影響を与えます。
ガウスは、彼の主なモジュールはドイツの数学者カール·フリードリヒ·ガウスヨハンの名前から未知の芸術家によって呼ばれ、2012年6月にKaspersky Labのエキスパートによって検出された。他の成分もジョゼフ=ルイ·ラグランジュ、クルト·ゲーデル、例えば、有名な数学者の名にちなんで名付けられる。研究では、ガウスを含む第一事件は、2012年7月に、2011年9月に行われたことを示した、ガウス制御サーバは動作を停止しました。
多数のモジュールでは、アクセスしたウェブサイトとパスワードの履歴を含めて、ブラウザから情報を収集することがガウシアンである。攻撃者にも、ネットワークインターフェイス、ドライバ、コン​​ピュータ、およびBIOSに関する情報に関するデータを含む感染したマシンの詳細を送った。ガウスモジュールはまた、ベイルート、EBLF、BlomBank、ByblosBank、FransaBankとクレジットLibanais銀行を含む顧客データは、いくつかのレバノン銀行を盗むことができます。また、シティバンクとのPayPalユーザーを侵す。
もう一つの大きな特徴は、Stuxnetのは、以前と炎が​​悪用したのと同じ脆弱性を利用してガウスのUSB機器に感染する能力です。感染したUSBデバイス、しかし、より多くの "インテリジェント"。ガウスは、特定の状況下でこのようなデバイスを "治す"と隠しファイルに収集された情報を格納するリムーバブルメディアを使用することができます。別のアクションは、ご使用のシステム "狭Palidano"と呼ばれる特殊なフォントにトロイの木馬をインストールすることですが、この行動の目的は、まだ知られていない。
ガウスFlame'aはデザインの面で希望しながら、感染の地理的分布は著しく異なっている。 Flame'aに感染したコンピュータの最大数は、イランに記録され、犠牲者のほとんどは、ガウスレバノンであった。感染者数も異なっています。テレメトリカスペルスキーセキュリティネットワーク(KSN)に基づいて、カスペルスキーの専門家は、ガウスが500の約2マシンを感染させたことがわかった。約700機あるため、比較のために、炎は、はるかに少ない感染。


卡巴斯基实验室宣布发现了“高斯”,在中东的新的网络威胁攻击的成员。高斯是一个复杂的一组工具,窃取机密信息,特别是在浏览器中的密码,凭证与网上银行,cookies和受感染的机器的具体配置,由政府提供资金。
在高斯标识的银行木马是一个独特的功能,没有发现任何已知的网络武器。高斯过程中检测到正在进行的倡议,由国际电讯联盟(ITU)后检测Flame'a。其目的是从网络武器,这是一个关键要素,努力实现全球网络空间的总体目标,以减少风险。
ITU,支持的知识和经验的卡巴斯基实验室,是采取显著的步骤,以提高在全球网络安全性,通过积极的合作与所有相关的参与者,如政府,私营部门,国际组织和公众,以及他们的关键合作伙伴的主动权,ITU-IMPACT。
通过识别恶意程序的共同特点,这从先前确定的网络武器火焰,卡巴斯基实验室已经检测到一个高斯。这些措施包括相似的架构,结构模块,代码,以及如何进行通信的服务器被网络罪犯用来控制这些风险。
重要事实:
- 分析表明,高斯已自2011年9月
- 这是首次发现于2012年6月的基础上,作为害虫火焰深入的分析和研究的结果,获得的信息。
- 这一发现可以通过明确的相似性和火焰和高斯之间的关系的。
- 基础设施服务器,控制高斯在2012年7月被关闭后不久,它被检测到。目前,该恶意软件处于休眠状态,等待的服务器变得活跃起来。
- 从2012年5月底,云安全系统的基础上,卡巴斯基实验室录得超过2 500感染,和受害者总数估计为高斯数以万计的。这个数字是低于Stuxnet的,但相对高于的Flame'a和Duqu。
- 高斯抢断在受感染的电脑,包括浏览器的历史记录,饼干,密码和系统配置的详细信息。他也可以窃取凭据来访问不同的网上银行系统和支付方法。
- 高斯分析,该蠕虫的目的是要窃取数据的黎巴嫩银行,包括贝鲁特,常绿阔叶林,BlomBank,ByblosBank,FransaBank和信用Libanais银行。此外,用户还影响到花​​旗银行和PayPal。
高斯检测卡巴斯基实验室的专家在2012年6月,他被称为主模块的名称未知艺术家的德国数学家卡尔·弗里德里希·高斯约翰。其他组件也被命名后,著名的数学家,例如,约瑟夫·路易斯·拉格朗日和哥德尔。研究表明,涉及高斯的第一个事件发生在2011年9月,2012年7月,高斯控制服务器停止工作。
许多模块是高斯的浏览器,包括历史的网站收集信息的访问和密码。攻击者发送受感染的计算机,网络接口,驱动程序,计算机的BIOS的信息,包括数据的详细信息。高斯模块还可以窃取客户数据,有几个的黎巴嫩银行,包括贝鲁特,常绿阔叶林,BlomBank,ByblosBank,FransaBank和信用Libanais银行。攻击也花旗银行和PayPal的用户。
另一个主要功能是通过相同的漏洞Stuxnet蠕虫利用和火焰感染高斯USB设备的能力。感染的USB设备,但是,更多的“智能”。高斯可以“治愈”这样的设备在某些情况下,使用可移动介质存储在一个隐藏的文件中收集到的信息。另一个动作是一个木马安装在您的系统称为“Palidano窄”的特殊字体,但仍然不知道这一行动的目的。
高斯Flame'a喜欢在设计方面,已经有了显着的不同地理分布的感染。在伊朗录得最大数量的电脑,感染的Flame'a的,大多数受害者是在高斯黎巴嫩。感染数量也是不同的。基于遥测卡巴斯基安全网络(KSN),来自卡巴斯基实验室的专家发现,高斯约2 500台机器感染。为了便于比较,火焰感染要少得多,因为近700​​台机器。


Friday, August 31, 2012

The most annoying things on the Internet



We love the internet. We need him. But I also hate it sometimes. For these things and much more ...
First Lazy activism. On the Internet, people are divided maniacally appeals for help, not cruelty to animals, the appellants did not sign online petitions, join the noble groups and so on, and so on, and then put the sense of a job well done, but it really did not do anything .
Second Captcha. There is no doubt annoying contraption. There is only one problem. A matter of fact he is not being replaced.
3rd Self-activating ads with sound. That is why we created adblocki. In order not to get a heart attack when from out of the blue we hear the voice of Michael Zebrowski laudatory last minute holiday in Tunisia in a resort for opossums. Apart from the fact that its advertising is "weigh" by which everything is loaded two times slower. Slightly, but only slightly less annoying are self-activating videos.
4th Overloaded websites. Flash-based animations, videos, various gadgets, bells and whistles and graphic explosions are cool, but a little casus beer and soda. The beer is great, the juice, but the beer and soda have not. The same combination of all these ornaments on one site makes it not quite that difficult to navigate after it is loaded, it still light-years, while bringing users crazy.
5th "The video is not available in your country". A person might think that the internet was precisely to transcend artificial boundaries established.
6th Pokemoniaste letter. Ie the use of alternating large and small letters. Are you sure you know what's going on, you've seen it many times. And in case not: Pokémon letter. ie the use of alternating upper and lower case. Also called "neurosis Shift". I do not know what it's for, what was created, or how anyone wants to write it, because it takes much more time than writing in a normal human way. However, this is sometimes inscrutable world.
7th Viruses, worms, trojans, and all the other stuff that runs out to the Internet. Through this daily web browsing like fight to the death. Death and life of our device connected to the Internet.
8th No privacy. Unfortunately, the Internet has its advantages, but you have to pay for them. Not only corporations are viewing our correspondence, suck as much data about us as much as you can, and then do with them what they want, but we do not have complete influence on what about us summarize other people. Yes it is, we're not on the Internet and will never be identified. The sooner you come to terms with that, the better for us.
9th Easy to destroy people. It's that simple. And you, cut out the pictures on the class in which you are doing a silly face, you could be the next internet meme face. Do you think anyone will care that you have a really interesting interior and personality, and the expression on his face was just for a laugh? Not a chance. People will start to recognize you on the street, but in contrast to other types of popularity - it can not be pleasant for you. I can not let go of this for a long time.
10th Internet users. Yes, the internet would be a really beautiful place, if not for its users, at least that part of them worse.


我々は、インターネットが大好きです。我々は彼を必要としています。しかし、私はまた、時々それを嫌う。これらのものとはるかにために...
最初の怠惰な行動。インターネット上では、人々が熱狂的にヘルプではなく、動物虐待のためのアピールを分割され、控訴人は、オンライン嘆願書に署名貴族のグループに参加するというように、というようにしてから、うまくいった仕事の感覚を入れて、それは本当に何もしなかったしなかった。
2番目のキャプチャ。疑い迷惑な仕掛けはありません。つだけ問題があります。実際のところ、彼は、交換されていません。
第三音声付きの自己活性化広告。我々はadblockiを作成した理由です。青の外から私たちはオポッサムのためのリゾートでマイケルゼブロウスキー賛美チュニジアの直前の休日の声を聞くとき、心臓発作を取得しないために。離れて、その広告はすべてが2倍遅いロードされていることによって "重さ"であるという事実から。少しだけ、わずかに迷惑な自己活性化動画です。
第四オーバーロードのウェブサイト。 Flashベースのアニ​​メーション、ビデオ、さまざまなガジェット、添えものとグラフィック爆発はクールですが、少しcasusビールとソーダ。ビール、ジュース素晴らしいですが、ビールやソーダはそうではありません。 1サイト上のすべてのこれらの装飾品の同じ組み合わせは、それがない非常にそれが読み込まれた後にナビゲートすることが困難になり、それはまだ光年、ユーザーが狂っせながら。
第五"ビデオは、あなたの国では利用できません"。人は、インターネットでは、人工の境界が確立された超越した正確だったと思うかもしれません。
第六手紙をPokemoniaste。大小の文字を交互に使用すること、すなわち。あなたは何が起こっているか知っている確信している、あなたはそれを何回も見てきました。としない場合は、次のようにポケモンの手紙。大文字と小文字を交互に使用すること、すなわち。また、 "神経症シフト"と呼ばれる。私はそれが正常な人間のように書くよりもはるかに時間がかかるので、誰もが、それを書きたいどのように作成、またはされたもの、それはのためだかわからない。しかし、これは時々不可解な世界です。
第七ウイルス、ワーム、トロイの木馬、およびインターネットに不足し他のすべてのもの。死への戦いのように、この毎日のWebブラウジングを通じ。我々のデバイスの死と生とは、インターネットに接続されています。
第八プライバシーなしません。残念ながら、インターネットは、その利点を持っていますが、あなたは彼らのために支払う必要があります。企業が私たちの対応を見ているだけでなく、できるだけ多くすることができますように私達についてのできるだけ多くのデータを吸うし、彼らが望むものを一緒に行うが、私たちは私たちの他の人々をまとめた内容に完全に影響力を持っていない。はい、そうです、我々はインターネットに接続していないしていると識別されることはありません。早くあなたは私たちのためにより良い、それとの折り合いをつける。
第九人々を破壊するのは簡単。それは簡単です。そして、あなたは、あなたが愚かな顔をしているされているクラスの画像を切り取るには、次のインターネットミームの顔である可能性があります。あなたは誰があなたが本当に面白いインテリアと個性を持っており、彼の顔の表情は笑いのためだけだったこと気になると思いますか?偶然ではない。人々は路上であなたを認識するために開始しますが、人気は他のタイプとは対照的に - それはあなたのための気持が良いことはできません。私は長い間、これを手放すことはできません。
第十インターネットユーザー。そのユーザーのためではない場合は、[はい、インターネットでは、それらの少なくともその一部悪化本当に美しい場所でしょう。


我们热爱互联网。我们需要他。但我有时也恨它。对于这些事情,更...
第一懒惰的积极性。在互联网上,人们划分疯狂上诉的帮助,不虐待动物,上诉人没有签署网上请愿,加入了高贵的团体和等,及依此类推,和然后把所做的出色工作的感觉,但它确实也没有做什么。
第二验证码。毫无疑问,恼人的玩意儿。是只有一个问题。事实上,他是不会被取代。
第3自激活广告的声音。这是为什么我们创建adblocki。为了得到一个心脏攻击的时候出蓝色的,我们听到的声音,迈克尔·热布罗夫斯基的美称最后一分钟在突尼斯度假的度假胜地,负鼠。除了一个事实,即它的广告是“权衡”,这一切都被加载慢两倍。略有下降,但仅略低于恼人的是自发的影片。
第4重载的网站。基于Flash的动画,视频,各种小工具,钟声和口哨声和图形爆炸的是很酷,但一点点的理由,啤酒和苏打水。的啤酒是伟大的,果汁,啤酒和苏打水没有。在一个网站上,相同的组合,所有这些饰品没有想象中的那么困难的浏览加载后,它仍然光年,而用户带来了疯狂的。
第5 “视频是不是在您的国家”。一个人可能会认为,互联网恰恰是超越人为的边界建立。
第6 Pokemoniaste信。 IE浏览器的使用大,小写字母交替。你确定你知道发生了什么事,你已经看到了很多次。的情况下:神奇宝贝的信。即交替使用上部和下部壳体。也称为“神经官能症移”。我不知道是什么,什么,或怎么会有人想要写它,因为它需要更多的时间比写在一个正常的人的方式。然而,这有时是难以理解的世界。
第7病毒,蠕虫,木马,和所有其他的东西,运行到Internet。通过这个每天的网页浏览一样战斗到死。我们的设备连接到Internet的生死。
第8毫无隐私可言。不幸的是,互联网有它的优势,但你必须为他们支付。不仅企业正在查看我们的信件,吸关于我们尽可能多的数据,你可以尽可能多的,然后做他们想要的东西,但我们并没有完整的关于我们总结别人的影响。的确是这样,我们还没有在互联网上,将永远不会被识别。你越早达成协议,更好地为我们的。
9日容易破坏人。就这么简单。而你,切出的照片上的课堂上,你正在做的一个愚蠢的脸,你可能是下一个互联网米姆面。你认为任何人会关心你有一个非常有趣的内饰和个性,他脸上的表情只是笑吗?不是一个机会。人们会开始认识到你在大街上,但在其他类型的流行 - 它不能为您愉快。我不能放过这个很长一段时间。
第10互联网用户。是的,互联网将是一个非常美丽的地方,如果不是因为它的用户,差至少是其中的一部分。



Tuesday, August 28, 2012

The most dangerous viruses in the world


The list, published on Thursday, the 15 most significant in the history of the virus, Kaspersky Lab lists include viruses attacking Iran's nuclear facilities. Cyberwarfare is not a screenplay, and the reality - says the analyst of the Polish branch of the company.
The most significant so far in 2012 the authors of the virus recognized statement of Flame (also known as Flamer, sKyWIper and Skywiper) - a malicious program that is actively used as cyberbroń in attacks on objects in different countries, especially the Arab world. Once infected machine can record audio Flame (eg, instant messaging conversations), take screenshots and record keystrokes on the keyboard.
In contrast to the famous Stuxnetu (used among others to attack Iran's nuclear facilities - destroy centrifuges used to enrich uranium, misleading supervisor working speed devices) - Flame by experts, was created primarily for the purpose of espionage, as well as an outdoor year Duqu virus earlier.
- If I had to choose three "worst" of the threat presented by our list, it would be the three most recent. All showed the whole world that it is no longer Cyberwarfare Hollywood production scenario and the reality - said Maciej Ziarek, malware analyst at Kaspersky Lab Poland. - Despite the fact that these three are not exploited by malicious programs infecting innovative technology, it was ground-breaking in terms of the objectives that have chosen cybercriminals. They were strictly selected organizations or strategic objects, and the complexity indicates that the creation of programs involved many experts and a lot of money. We had to deal with cyberbronią aimed at specific targets.
The top fifteen most important by the company in the history of computer threats was also Brain - one of the first computer viruses infecting diagnosed IBM PC computers. Discovered in 1986 and writes its code in the boot sector of floppy virus within a few months of the uprising has spread around the world. The program itself is not destroyed a data disk only the name has changed. Considered virus writers, programmers Pakistani Basit Farooq Alvi and Amjad explained later that with the help of Brain wanted to measure the level of software piracy in the country.

Another important program that Kaspersky Lab analysts earned a place in the top fifteen is Conficker, also known as Downup, Downadup or Kido. Exploiting vulnerabilities in Windows, it was infecting computers private and corporate, where protective systems shut down, install additional malware and steal personal information. Its characteristic feature is that it automatically downloads its new, updated by cybercriminals copies. In 2009, Microsoft has set 250 thousand. U.S. dollar prize to anyone who will contribute significantly to the recognition of Conficker creator. Unfortunately, to this day do not know who was behind the creation of this program.
However, the greatest threat to individual users and businesses recognize Maciej Ziarek Trojan horses, programs that pretend useful tools perform malicious acts. - Nowadays, information is more valuable than ever before, so the cyber criminals use Trojans to steal any data that can later be sold on the black market or used to blackmail users or companies. There are also banking Trojans that "specialize" in the theft of information related to online banking - added Ziarek.
Kaspersky Lab has released a list of the occasion of the 15th anniversary of its founding.
Top 15 most important virus in chronological order:
- 1986 - Brain appears, the first computer virus. Brain spread by writing your code in the boot sector of floppy disks.
- 1988 - Morris worm infects about 10% of computers connected to the Internet (about 6 000 machines).
- 1992 - Michelangelo appears - the first virus that causes widespread media interest.
- 1995 - appears Concept - the first macro virus that infects Microsoft Word documents.
- 1999 - Melissa begins the era of mass mailing malware responsible for the massive global epidemics.
- 2003 - appears Slammer worm bezplikowy responsible for massive worldwide epidemic.
- 2004 - Cabir appears: the first worm a "Proof-of-Concept" for Symbian, Cabir infects mobile phones through Bluetooth.
- 2006 - Leap appears, the first virus for Mac OS X.
- 2007 - Storm worm (also known as Zhelatin) initiates the use of distributed servers through which the cybercriminals controlling malicious programs.
- 2008 - there is Koobface, the first malicious program that attacks Facebook.
- 2008 - appears Conficker, the worm that caused one of the biggest epidemics in history, attacking corporate networks, consumers and governments in more than 200 countries.
- 2010 - appears FakePlayer, pink SMS Trojan for Android.
- 2010 - there is Stuxnet, which is used to carry out targeted attacks on SCADA systems (Supervisory Control and Data Acquisition), signaling the arrival of cyberwars.
- 2011 - appears Duqu, a sophisticated Trojan that collects information about its carefully selected targets.
- 2012 - Flame appears highly sophisticated malicious software that is actively used as cyberbroń in attacks on objects in different countries.


カスペルスキーのリストが含まれて木曜日に発行されるリストは、ウイルスの歴史の中で最も重要な15日イランの核施設を攻撃するウイルス。サイバー戦争は、脚本、そして現実ではない - 会社のポーランド支店のアナリストは述べています。
特に積極的に様々な国、アラブ世界内のオブジェクトへの攻撃にcyberbrońとして使用された悪意のあるプログラム - 最も重要なのは、これまでのところ、2012年にはウイルスの作者は、炎の文(もFLAMER、sKyWIperとSkywiperとしても知られる)を認識した。一度感染するとマシンは、(例えば、インスタントメッセージングの会話)オーディオ炎を記録するキーボード上のスクリーンショットと、レコードのキーストロークを取ることができます。
有名Stuxnetu( - 高速デバイスをワーキングウラン、誤解を招くようなスーパーバイザーを豊かにするために使用される遠心分離機を破壊するイランの核施設を攻撃するためにとりわけ使用される) - とは対照的に、専門家による炎、主にスパイの目的だけでなく、屋外の年間のために作成されました以前Duquウイルス。
- 私は私たちのリストが提示した脅威の3 "最悪"を選択しなければならないとしたら、それは最新の3つであろう。すべては、それがもはやサイバー戦争ハリウッド製作のシナリオと現実でないことを全世界に示した - マチェイZiarek、カスペルスキーでマルウェアのアナリストは述べています。 - これらの3つの革新的な技術を感染させる悪意のあるプログラムによって悪用されていないという事実にもかかわらず、それはサイバー犯罪者を選択した目標の観点から画期的だった。彼らは、厳選された組織や戦略的なオブジェクトであった、と複雑さは、プログラムの作成は、多くの専門家や多くのお金が関与していることを示します。我々は、具体的な目標に向けたcyberbroniąに対処しなければならなかった。
診断されたIBM PCのコンピュータを感染させる最初のコンピュータウイルスの1 - コンピュータの脅威の歴史の中で会社でトップ15で最も重要なのは、脳であった。 1986年に発見され、反乱の数ヶ月以内にフロッピーウイルスのブートセクタに自身のコードを書き込むには、世界中に広がっています。プログラム自体は名前だけが変更されたデータディスクが破壊されていません。ウイルス作成者と見なされ、プログラマーパキスタンBasitファルークAlviと民放は、脳の助けを借りて国にソフトウェア著作権侵害のレベルを測定したいと思ったことを後で説明した。

Kaspersky Labのアナリストは、トップ15内に地位を獲得したもう1つの重要なプログラムはまたDownup、Downadupや木戸として知られているConfickerのです。 Windowsの脆弱性を悪用し、それは、保護システムがシャットダウンする個人や企業のコンピュータを感染させる追加のマルウェアをインストールし、個人情報を盗みました。その特徴は、それが自動的にその新しい、サイバー犯罪のコピーによって更新がダウンロードされていることです。 2009年、マイクロソフトは250万人を設定しています。 Confickerワーム作成者の認識に大きく貢献します誰にも米国ドルの賞金。残念なことに、この日にこのプログラムの作成の背後にいたのか分からない。
ただし、個々のユーザーや企業への最大の脅威はマチェイZiarekトロイの木馬、便利なツールが悪質な行為を行うふりをするプログラムを認識しています。 - 今日では、情報がかつてないほど貴重なものですので、サイバー犯罪者は、後で闇市場で売られたり、ユーザーや企業を脅迫するために使用できる任意のデータを盗むトロイの木馬を使用しています。 Ziarekを追加しました - それはオンラインバンキングに関連する情報の窃盗に "特化"銀行のトロイの木馬もあります。
Kaspersky Labは、創立15周年の機会のリストを公表した。
年代順にトップ15最も重要なウイルス:
- 1986 - 脳は、最初のコンピュータウイルスが表示されます。脳はフロッピーディスクのブートセクターにあなたのコードを記述することによって広がる。
- 1988 - モリスワームは、インターネット(約6 000機)に接続されたコンピュータの約10%に感染します。
- 1992年 - ミケランジェロが表示されます - 広範囲のメディアの関心を引き起こした最初のウイルスを。
- 1995 - Microsoft Word文書に感染する最初のマクロウイルス - コンセプトが表示されます。
- 1999 - メリッサは、大規模な世界的流行を担うマスメーリングマルウェアの時代が始まります。
- 2003 - 大規模な世界的流行にbezplikowy責任Slammerワームが表示されます。
- 2004 - Cabirはが表示されます:最初のワームSymbian向けの "プルーフ·オブ·コンセプト"、CabirはBluetooth経由で携帯電話に感染する。
- 2006 - リープが表示され、Mac OS X用の最初のウイルス
- 2007 - Stormワーム(またZhelatinとして知られている)、サイバー犯罪者は、悪意のあるプログラムを制御しているを通じて配布サーバの使用を開始します。
- 2008 - Koobfaceは、Facebookを利用して攻撃する第一の悪意のあるプログラムがある。
- 2008 - Confickerを、200カ国以上で企業ネットワーク、消費者、政府を攻撃し、史上最大の流行の一つの原因となったワームが表示されます。
- 2010 - FakePlayer、Android用のピンクのSMSトロイの木馬が表示されます。
- 2010 - cyberwarsの到着を合図に、SCADAシステム(監視制御およびデータ収集)に標的型攻撃を実行するために使用されるStuxnetは、があります。
- 2011 - Duqu、その厳選されたターゲットに関する情報を収集し、洗練されたトロイの木馬が表示されます。
- 2012 - 炎は積極的に様々な国のオブジェクトへの攻撃にcyberbrońとして使用され、高度に洗練された悪意のあるソフトウェアが表示されます。


周四公布的名单,15个最重要的在历史上的病毒,卡巴斯基实验室列表病毒攻击伊朗的核设施。网络战是不是一个电影剧本,而现实 - 波兰的分支公司的分析师说。
最重要的,到目前为止,在2012年确认的病毒作者声明火焰(也称为火焰喷射器,sKyWIper和Skywiper的) - 是一种恶意程序,积极作为cyberbroń的攻击对象在不同的​​国家,特别是阿拉伯世界。一旦感染的机器可以录制音频火焰(如即时消息对话),键盘上的截图,记录键击。
相反的,著名Stuxnetu(以及其他攻击伊朗的核设施 - 摧毁离心机进行铀浓缩活动,误导性导师工作的测速设备使用) - 火焰由专家,间谍活动的目的,主要是为创建,以及一个室外的一年Duqu病毒。
- 如果我不得不选择三个“最差”的威胁,提出了我们的名单,这将是最近三个。都表现出了整个世界,它不再是网络战的好莱坞生产场景和现实 - 马切伊Ziarek说,波兰卡巴斯基实验室的恶意软件分析师。 - 尽管这三者都无法利用恶意程序感染的创新技术,突破性的选择了网络罪犯的目标。他们是经过严格挑选的组织或战略的对象,并创建程序的复杂性表明,涉及许多专家和大量的资金。我们要处理的具体目标,旨在与cyberbronią。
前15个最重要的公司在历史上对计算机的威胁也是脑 - 感染诊断的IBM PC计算机的计算机病毒之一。 1986年发现的,其代码病毒的软盘的引导扇区写入的起义在短短几个月内已传播到世界各地。这个程序本身不被破坏的数据磁盘的名称发生了变化。考虑病毒作家,程序员巴基斯坦的巴西特法鲁克ALVI和Amjad解释的帮助下,脑想的盗版软件在国内的高低来衡量。

另一项重要的程序,卡巴斯基实验室的分析师顶部15赢得了一个地方是Conficker的,也称为Downup的,Downadup或Kido。利用Windows的漏洞,它被感染计算机的私人和企业,保护系统关闭,安装额外的恶意软件,窃取个人信息。它的特征是,它会自动下载新的,更新的网络犯罪分子的副本。在2009年,微软已经设置为250000。美元奖金,任何人都将有助于显着的Conficker创造者的认可。不幸的是,这一天不知道谁是背后的创造这一计划。
然而,最大的威胁为个人用户和企业认识到的马切伊Ziarek特洛伊木马,伪装成有用的工具,执行恶意行为的程序。 - 现在比以往任何时候都更有价值,因此网络罪犯使用的木马程序窃取,以后可以在黑市上销售或使用要挟用户或公司的任何数据。也有银行木马“专门”的盗窃网上银行的相关信息 - Ziarek。
卡巴斯基实验室已经发布了其成立15周年之际列表。
15个最重要的病毒按时间顺序排列:
- 1986 - 大脑出现的第一个计算机病毒。脑软盘的引导扇区写代码的传播。
- 1988年 - 莫里斯蠕虫感染的电脑连接到互联网(约000台)的10%左右。
- 1992年 - 米开朗基罗出现了 - 第一个病毒,引起了媒体的广泛关注。
- 1995 - 出现的概念 - 第一个宏病毒感染Microsoft Word文档。
- 1999 - 梅丽莎开始群发邮件恶意软件负责大规模的全球流行病的时代。
- 2003 - 出现Slammer蠕虫病毒bezplikowy负责的为大规模的全球性流行病。
- 2004 - Cabir蠕虫病毒出现:“证明概念”为Symbian的首个蠕虫病毒,Cabir蠕虫病毒感染的手机通过蓝牙。
- 2006 - 飞跃出现​​的第一个病毒的Mac OS X
- 2007 - 风暴蠕虫病毒(也称为Zhelatin)发起使用分布式服务器通过网络罪犯控制的恶意程序。
- 2008 - Koobface的恶意程序,第一攻击Facebook的。
- 2008 - 出现Conficker蠕虫,该蠕虫造成攻击企业网络,在超过200个国家和地区的消费者和政府在历史上,最大的流行病之一。
- 2010 - 出现FakePlayer的,粉红色的Andr​​oid短信木马。
- 2010 - Stuxnet的,它是用来进行有针对性的攻击SCADA系统(监控和数据采集系统),信号cyberwars的到来。
- 2011 - 出现Duqu,一个复杂的木马程序,收集信息,其精心挑选的目标。
- 2012 - 火焰高度复杂的恶意软件积极作为cyberbroń的攻击对象在不同的​​国家出现。