myTribu::reb0rn Search Members Help Calendar
Welcome Guest .:: Log In :: Register ::. .:: Resend Validation Email  

Reply to this topicStart new topic

> Alerte Virus, Vous prévenir des nouveaux virus

Deather

CALLBACK
***************
Group: Administrateu(r|se)
Posts: 683
Member No.: 3
Joined: 28-December 03

Posted: Sep 9 2004, 23:16 PM   Quote Post 

Ça n'arrête pas :-p
t'façon faut vraiment être un boolay pour ouvrir une pièce jointe de qqun qu'on connais pas et dont le mail est douteux :-p

Y'a que les utilisateurs de Outlook pour faire ça mdr :-D

 PMEmail Poster  Top

DarkFantasy

CALLBACK
***************
Group: Administrateu(r|se)
Posts: 684
Member No.: 4
Joined: 21-June 04

Posted: Sep 9 2004, 23:39 PM   Quote Post 

Tritri vous informe du virus, je vous livre les sources Langue.gif c'est pas forcement la même version mais c'est assez instructif. Cophobe passez votre chemin ClinDOiel.gif
http://www.62nds.co.nz/62nds/documents/mydoom/

____________________
user posted imageuser posted image

 PMEmail PosterUsers WebsiteMSN  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Sep 15 2004, 12:12 PM   Quote Post 

" Alerte Virus 4/5 - I-Worm.Mydoom.y / Danger : moderate risk "

I-Worm.Mydoom.y
[ 09/15/2004 06:46, GMT +03:00, Moscow ]
Danger : moderate risk
ESAC : Virus propagation Speed 4/5
http://www.viruslist.com/eng/alert.html?id=2218228

( version francaise grace a Google http://nanolink.fr/Mydoom.y-Fr )

I-Worm.Mydoom.y spreads via the Internet and local networks as an attachment to
infected messages. It also spreads via file-sharing networks and through a
vulnerability in Microsoft Windows LSASS.

The worm is written in Microsoft Visual C++, and is compressed using UPX. The
packed file is 69932 bytes in size; the unpacked files is 193024 bytes in size.

This latest version of Mydoom has all the functionality of I-Worm.Plexus

A detailed description of I-Worm.Mydoom.y will be available in the Virus
Encylopaedia in the near future.

An urgent update to Kaspersky Anti-Virus databases protecting against
I-Worm.Mydoom.y has already been released.

Actions :

- Update AVBase

- Retrovirus against Kaspersky Products


____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Kei

PTR
***********
Group: ~ Tribu ~
Posts: 146
Member No.: 24
Joined: 23-July 04

Posted: Sep 15 2004, 20:16 PM   Quote Post 

tritri chasseur de virus professionnel ^^

____________________
user posted image
user posted image

 PMEmail PosterUsers WebsiteAOLYahooMSN  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Oct 17 2004, 11:01 AM   Quote Post 

Worm.Win32.Opasoft.s
[ 10/12/2004 16:18, GMT +03:00, Moscow ]
Danger : moderate risk
http://nanolink.fr/Alert.Worm.Win32.Opasoft.s

( version francaise grace a Google http://nanolink.fr/Worm.Win32.Opasoft.s-fr )

On 7th October 2004, Kaspersky Labs virus analysts detected a new version of
Opasoft, Worm.Win32.Opasoft.s.

The worm is now showing increased activity in Russia.

The worm uses accessible network resources to spread via local networks. It also
contacts the site of a Ukrainian mobile services provider in order to send sms
messages containing the IP addresses of victim machines.

A detailed description of Worm.Win32.Opasoft.s is available in the Virus
Encyclopaedia.

Protection against Opasoft.s was included in the updates to antivirus databases
the day the worm was detected.

________________________________________________________________
Eur'Net - Dept. Kaspersky Anti Virus ( ex. AVP )
( Sme Reseller of the Year 2002 - Kaspersky Lab )

Addresse :
4, route de la Fossery
F-27220 LA BOISSIERE
Telephone:
+33 (0) 232 366 364
Fax:
+33 (0) 232 366 367 / (0) 232 265 057
E-mail :
info@antivirus-france.com - Service Information
devis@antivirus-france.com - Service Commercial
support@antivirus-france.com - Support Technique
virus@antivirus-france.com - Laboratoire d'Analyse Viral
WWW:
http://antivirus-france.com - http://avp-france.com
NewsLetter:
http://antivirus-france.com/newletter.html
Telechargement:
http://antivirus-france.com/download.html
Scan en Ligne:
http://www.kaspersky.com/remoteviruschk.html
Communaute Ze_Kaspersky
http://www.kaspersky-info.com/ze_kaspersky.php


____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Deather

CALLBACK
***************
Group: Administrateu(r|se)
Posts: 683
Member No.: 3
Joined: 28-December 03

Posted: Oct 17 2004, 11:27 AM   Quote Post 

Dis si jamais tu entend parler d'un virus sous Linux tu me préviens que je me fasse pas infecter ? user posted image

Quoi on a pas le droit de troller de bon matin? :-p

 PMEmail Poster  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Oct 26 2004, 11:58 AM   Quote Post 

I-worm.Mydoom.ab
[ 10/25/2004 18:07, GMT +03:00, Moscow ]
Danger : moderate risk
http://nanolink.fr/Alert.I-worm.Mydoom.ab

( version francaise grace a Google http://nanolink.fr/I-worm.Mydoom.ab-fr )

The latest Mydoom variant, version Mydoom.ab was detected by Kaspersky Lab on
October 24, but a significant number of incoming samples has lead our analysts
to issue an alert.

Mydoom.ab is another Mydoom.a variant. It spreads as an attachment in an
infected email. The worm send copies of itself to all addresses in the local
address book.

Mydoom.ab is a Windows PE EXE file and is about 32 KB - packed by UPX.
Installation

Upon installation Mydoom.ab creates a file named lsasrv.exe in the Windows
system registry and creates the following registry key:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"lsass" = "%System%\lsasrv.exe"

The worm also creates a file named version.ini in the Windows system folder.
Other

Mydoom.ab attempts to block the work of a number of firewalls.


____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Nov 1 2004, 14:22 PM   Quote Post 

I-Worm.Bagle.at / I-Worm.Bagle.au
[ 10.29.04 14:10, GMT +0400, Moscow ]
Danger : moderate risk

Vitesse de propagation des virus : 3/5

Action Urgente a faire :

Forcer les MAJ des bases AV.

#######################################################################
I-Worm.Bagle.at - http://nanolink.fr/Alert.I-Worm.Bagle.at
Kaspersky Lab has received multiple messages about a mass mailing of a new Bagle
variant. Bagle.at installs an email proxy server like most recent Bagle
variants.

A detailed description will be available soon. Kaspersky Anti-Virus databases
have been updated ealier today.

Traduction francaise faite grace a google :
- http://nanolink.fr/I-Worm.Bagle.at-fr
#######################################################################


#######################################################################
I-Worm.Bagle.au - http://nanolink.fr/Alert.I-Worm.Bagle.au
Kaspersky Lab has received messages with a second Bagle variant hard on the
heels of Bagle.at on October 29.

Users are urged to update their antivirus databases as soon as possible.

Traduction francaise faite grace a google :
- http://nanolink.fr/I-Worm.Bagle.au-fr
#######################################################################

____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Nov 24 2004, 22:40 PM   Quote Post 

Dsl du retard biggrin.gif

I-Worm.Sober.i

11.19.04 12:20, GMT +0300, Moscow

Status : moderate risk

Kaspersky Lab has detected a new variant of I-Worm.Sober version - Sober.i in
the wild. Sober.i is an email worm spreading as an infected attachment.

A detailed description will be available soon and Kaspersky Lab antivirus
databases have been updated with protection against Sober.i

- http://nanolink.info/I-Worm.Sober.i

Si vous souhaitez une version francaise merci d'utiliser Google :

- http://www.google.fr/language_tools?hl=fr


____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Deather

CALLBACK
***************
Group: Administrateu(r|se)
Posts: 683
Member No.: 3
Joined: 28-December 03

Posted: Nov 24 2004, 22:45 PM   Quote Post 

À quand le virus qui s'ajoute à tes contacts MSN et qui formatte ton PC? user posted image

 PMEmail Poster  Top

DarkFantasy

CALLBACK
***************
Group: Administrateu(r|se)
Posts: 684
Member No.: 4
Joined: 21-June 04

Posted: Nov 24 2004, 23:52 PM   Quote Post 

Ca existe, son addresse c'est darkfantasy_666@hotmail.com virez le !!user posted image

____________________
user posted imageuser posted image

 PMEmail PosterUsers WebsiteMSN  Top

Kei

PTR
***********
Group: ~ Tribu ~
Posts: 146
Member No.: 24
Joined: 23-July 04

Posted: Dec 1 2004, 13:12 PM   Quote Post 

W32.Salga.A@mm

W32.Salga.A@mm is a mass-mailing worm that uses Microsoft Outlook to send itself to all the email addresses that it finds in the Outlook Address Book. It also attempts to spread through mIRC, file-sharing networks, and network shares.

En French ca donne un truc comme :

W32.Salga.A@mm est un vers de type mailing en masse qui utilise M$ Outlook afin de se renvoyer à tout le carnet d'@ d'Outlook. Il se répends aussi par mIRC via des fichier partagés ou connexion partagés

Ce virus n'est pas très très dangeureux mais se répand assez rapidement.

PWSteal.Tarno.K

PWSteal.Tarno.K is a Trojan horse program that attempts to steal passwords and log information entered into Web forms.

En French ca donne un truc comme :

PWSteal.Tarno.K est un cheval de Troie qui tente de réupérer vos nomd'utilisateurs et vos mots de passe quand vous vous loggez à des site (comme par exemple si vous vous loggiez à ce forum ClinDOiel.gif)

Mise à part le vol des login & password ce cheval de Troie n'est pas tres dangeureux et sa diffusion n'est pas tres importante.

Sources : http://www.symantec.fr/

____________________
user posted image
user posted image

 PMEmail PosterUsers WebsiteAOLYahooMSN  Top

Tritri86

VOID
************
Group: ~ Tribu ~
Posts: 212
Member No.: 6
Joined: 13-July 04

Posted: Dec 1 2004, 18:18 PM   Quote Post 

Merci Kei de ton soutien biggrin.gif

____________________
user posted image

 PMEmail PosterUsers WebsiteAOLMSN  Top

Armenus

SHORT
*****
Group: T4C Joueu(r|se)
Posts: 49
Member No.: 33
Joined: 27-August 04

Posted: Dec 1 2004, 18:54 PM   Quote Post 

tritri tu devrai mettre la traduction directement sur le post sa encourage a lire (et ouais les ptit jeunes comme moi ils sont pas encore a fond dans l'anglais smile.gif )

____________________
user posted image

 PMEmail PosterMSN  Top

Kei

PTR
***********
Group: ~ Tribu ~
Posts: 146
Member No.: 24
Joined: 23-July 04

Posted: Dec 1 2004, 19:17 PM   Quote Post 

de rien Tritri ClinDOiel.gif et c'est surtout car je me faisé chier lol biggrin.gif

____________________
user posted image
user posted image

 PMEmail PosterUsers WebsiteAOLYahooMSN  Top

 0 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
0 Members:

Reply to this topicStart new topic

 


Top