<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Tech Blogs &#187; Virus</title>
	<atom:link href="http://www.precisesecurity.com/blogs/category/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<lastBuildDate>Thu, 09 Feb 2012 00:49:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>~dulla@204 Virus</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus</link>
		<comments>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comments</comments>
		<pubDate>Wed, 10 Dec 2008 12:00:14 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>~dulla@204 is a harmful virus that can stop operation of document applications such as Microsoft Word, Excel, Powerpoint and Adobe Acrobat. ~dulla@204 also modifies Windows Registry and adds its own key to run itself when Windows starts. When attempting to open a document file, it will display “~dulla@204”. Category: Virus Risk Level: High Technical Details Characteristics: Once executed, this virus will drop several files under Windows directory. These files bears random name like ~jmkiteyd~.exe, which is around 43kb (44032 bytes) in size. To run ~dulla@204 on [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>~dulla@204 is a harmful virus that can stop operation of document applications such as Microsoft Word, Excel, Powerpoint and Adobe Acrobat. ~dulla@204 also modifies Windows Registry and adds its own key to run itself when Windows starts. When attempting to open a document file, it will display “~dulla@204”.<span id="more-2019"></span></p>
<p><strong>Category: </strong>Virus</p>
<p><strong>Risk Level: </strong>High</p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong></p>
<p>Once executed, this virus will drop several files under Windows directory. These files bears random name like ~jmkiteyd~.exe, which is around 43kb (44032 bytes) in size.</p>
<p>To run ~dulla@204 on every Windows start-up, it will add the following registry entries:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services =”~dulla@204”</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services =”~dulla@204”</li>
<li>HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run “~jmkiteyd~.exe”</li>
</ul>
<p>When loaded, ~dulla@204 virus may infect executable files on the compromised computer as a method to propagate. The same process is applied on a network to distribute a copy of itself. Once running on the computer, ~dulla@204 will corrupt all document files by altering part of the header, which makes it irrecoverable.</p>
<p><strong>Distribution Method:</strong><br />
Computer users may acquire ~dulla@204 from malicious web sites or legitimate site that are compromised with a Trojan. Visiting these sites may download and execute ~dulla@204 without visitors notice. Once on the system, this virus will infect .EXE files. It will also look for connected computers and do the same on network-shared drives.</p>
<h2>Recommended ~dulla@204 Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definition of your antivirus program.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Use antivirus program to run a full system scan and clean/delete all infected file.<br />
To manually delete associated files, please browse Windows directory and look for files similar to ~jmkiteyd~.exe (43kb). When found, delete carefully one at a time.</p>
<p>5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services =”~dulla@204”</em><br />
<em> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services =”~dulla@204”</em><br />
<em> HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run “~jmkiteyd~.exe”</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
<p>8. Addition removal tool can be found on this web site : http://www.insa.gov.et/INSA/faces/downloads/downloads.jsp</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/feed</wfw:commentRss>
		<slash:comments>227</slash:comments>
		</item>
	</channel>
</rss>

