Digniin:
Virus halis ah oo aad ugu dhexfaafaya Kunbuyuutarada.
Ismail Said Aw-Musse
ismail.awmusse@jeegaan.com
Helsinki - Finland
Updated: Aug 21, 2003
Helsinki 20.09.03 Viruskan cusub oo
lagu magacaabo Sobig.F ayaa maantey si lixaadleh ugu dhexfaafaya kunbuyuutarada
caalamka khaasatan wadamada loo yaqaan Nordic (Sweden, Denmark, Norway Iceland
iyo Finland) Viruskan (Sobig.F) markii u horaysey waxaa la arkey 19.08.2003
isaga oo radarka shirkada F-secure ka galay lanbarka kowaad.
Sobig.F waxa uu ka dhexdirayaa kunbuyuutarkaaga emailo aad u faro badan
isaga oo raacinaya lifaaq xanbaarsan viruska.
Culayska emailka xanbaarsan viruskan ay dhan 70KB
waxana uu wataa Server u shaqeynaaya sida SMTP oo ah server loo isticmaalo in
la diri karo email waxaana loo soo gaabiyaa (Simple Mail Transfer Protocol )
kadib waxa uu si toos ah ugu xirmanayaa oo codsanayaa Network Time Protocol.
Viruskan ayaa sidoo kale iskiis isu update gareynaaya
isaga oo wata hab shuroodo ah taas oo u sahlaysaa in uu aad u faafo, waxana uu
ku programgaraysan yahay ilaa iyo 10.09.2003 in uu sii faafo.
Viruskan (Sobig.F) iskiis ayuu isu rakibaya marka uu soo dhexgalo
kunbuyuutarkaaga isaga oo ka kacaaya fileka ah
%windir%\winppr32.exe
kadib waxa uu dhexgelayaa registeriga kunbuyuutarkaaga ka eega maabkan
[HKEY_CURRENT_USER\ SOFTWARE\Microsoft\Windows\ CurrentVersion\Run] "TrayX"
= %windir%\winppr32.exe /sinc
Arintaasi waxa ay sahlaysaa in markasta oo aad shido kunbuyuutarkaaga uu la
soo kaco filekii waxyeelaysaan ama xanbaarsanaa viruska.
Inta badan cinwaanka dirayaa waa mid caadi ah ah oo xanbaarsan magaca
internetka sida admin@internet.com ama kunbuyuutarkasta oo uu
waxyeelo gaarsiiyey
Viruskan ayaa xanbaarsan cinwaano kala gedisan sida:
Re: Thank you!
Thank you!
Your details
Re: Details
Re: Re: My details
Re: Approved
Re: Your application
Re: Wicked screensaver
Re: That movie
Qoraalka ku dhexqoran emailka sida viruska ayaa ah sidan:
See the attached file for details
Please see the attached file for details.
Laakiin fileka xanbaarsan viruska laf ahaantiisa ee
lifaaqa la socda ayaa qudhiisu wataa magacyo kala gedisan sida:
your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif
Sidee uga hortagaysaa Viruskan:
1- Ka dhexbaar kunbuyuutarkaaga filekan winppr32.exe , meelaha aad ka
baarayso ha u horeyso Regsiteriga sida aad ku arki karto registeryga waa adoo
taabta Start kadibna Run kadib ku dhexqor regedit waxaa
kuu soo baxaya registeryga (Digniin: haddii aadan aqoon u lahayn ha isuku
taaban registeryga maxaa yeelay waa meel dhaawac aad gaarsiin kartid
kunbuyuutarkuna fariisan karo).
2-
Hadii uu galay computerka viruska loo yaqaan
Sobig.F waxaad soo gashataa aalada ama (Tools-ka) loogu tala galay saaridiisa:
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.zip
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.txt
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.exe
Kadibna ku Run gareey kunbuyuutarkaaga adiga oo raacaya habka ku sharaxan
fileka qoraalka la socda si sahal ah ayey kaaga baxayaa.
3- Soo gasho Antivirus isla markaasna update gareey marka uu u baahdo.
Ha u ogolaan filesha lifaaqa wata in lifaaqu ama attechmentigu furmo adiga
oo aan ogolaan waxaadna mari habkan. haddii aad isticmaalayso Outlook Exprees
taabo Tools kadibna Option waxaa kuu soo baxaya sawirkan.
Sida kuu muuqata waxaad taaban SECURITY kadib waxaa kuu soo
bixi sawirkan:
Kadib waxaad dooran meesha casaanka ku calamaadsan tahay ee ay ku qoran
tahay "Do not allow attechments to be saved or opened.."
Waa meel muhim ah waxaadse ogaataa filekasta oo lifaaq wataa makuu furmanaayo
ilaa aad mar labaad bedesho optionkan.
4. Hadii uu ku aafeeyay Viruskan fadlan bedel date ama taariikhda
computerkaaga oo dooro taariikh ka danbeysa 10.09.2003 taas oo sahlaysa inaan
worm ku amavirusku aanu kicin kadibna ku dadaal intaa kadib in aad saarto.
Cinwaano muhim ah oo aad ka helayso macluumaad dheeraad ah:
http://www.symantec.com/
http://www.f-secure.com/
http://us.mcafee.com/root/package.asp?pkgid=100
Ismail Said Aw-Musse
ismail.awmusse@jeegaan.com
Helsinki - Finland
Faafin: SomaliTalk.com | Aug 20, 2003 |
Updated: Aug 21, 2003
»
DIGNIIN VIRUS CUSUB: Computerka oo Xogta Laga Xadayo
....
Copyright
& Islaamku wuxuu ka qabo.... Akhri
Kulaabo bogga hore ee
www.somalitalk.com
Afeef: Aragtida qoraalkan waxaa leh qoraaga ku saxiixan
|