<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jembelisme Media &#187; analisis virus</title>
	<atom:link href="http://jembelisme.com/tag/analisis-virus/feed" rel="self" type="application/rss+xml" />
	<link>http://jembelisme.com</link>
	<description>News, Opinion, Monetize, Link Exchange, Web Technology and Internet</description>
	<lastBuildDate>Sat, 19 May 2012 08:12:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>New Variant Virus Edd.exe</title>
		<link>http://jembelisme.com/new-variant-virus-edd-exe.html</link>
		<comments>http://jembelisme.com/new-variant-virus-edd-exe.html#comments</comments>
		<pubDate>Thu, 04 Feb 2010 01:07:42 +0000</pubDate>
		<dc:creator>Anas</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[My Stories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[analisis virus]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[new variant]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus baru]]></category>

		<guid isPermaLink="false">http://jembelisme.com/?p=928</guid>
		<description><![CDATA[Tadi malam saat Anas lagi ngecek file mencurigakan di startup file komputer, Anas menemukan 1 file yang mencurigakan namanya Edd.exe kemudian Anas cek dari mana asalnya, ternyata berasal dari C:\Documents and Settings\Admin\Local Settings\Temp . Pikirku kok aneh ya ada program yang dijalanin dari subdirectory tersebut. Kemudian Anas scan dengan Smadav 8.0 dan McAfee Enterprise 8.7i [...]]]></description>
			<content:encoded><![CDATA[<p>Tadi malam saat Anas lagi ngecek file mencurigakan di startup file komputer, Anas menemukan 1 file yang mencurigakan namanya <strong>Edd.exe</strong> kemudian Anas cek dari mana asalnya, ternyata berasal dari <strong>C:\Documents and Settings\Admin\Local Settings\Temp</strong> .</p>
<div id="attachment_929" class="wp-caption aligncenter" style="width: 212px"><img class="size-full wp-image-929" title="edd" src="http://jembelisme.com/wp-content/uploads/2010/02/edd.jpg" alt="" width="202" height="66" /><p class="wp-caption-text">file yang dicurigai</p></div>
<p>Pikirku kok aneh ya ada program yang dijalanin dari subdirectory tersebut. Kemudian Anas scan dengan Smadav 8.0 dan McAfee Enterprise 8.7i (versi 5878) hasilnya nihil, tidak terdeteksi virus. Analisa saya lanjutkan dengan mencari informasi di google dengan keyword &#8220;Edd.exe&#8221; hasilnya pun negatif (artinya tidak mengindikasikan virus).</p>
<p>Rasa penasaranku makin kencang, kemudian Anas buka situs <strong>www.virustotal.com</strong> dan mengupload file tersebut dan hasilnya Taaaaraaaaaaaaaaaa&#8230;<br />
<span id="more-928"></span></p>
<blockquote><p>File Edd.exe received on 2010.02.03 22:07:36 (UTC)</p>
<table id="tableado" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td>
</tr>
<tr>
<td>a-squared</td>
<td>4.5.0.50</td>
<td>2010.02.03</td>
<td>Trojan.Win32.FakeAV!IK</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>5.0.0.2</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.9.1.158</td>
<td>2010.02.03</td>
<td>TR/Agent.AN.104</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>2.0.3.7</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Authentium</td>
<td>5.2.0.5</td>
<td>2010.02.03</td>
<td>W32/FraudLoad.A!Generic</td>
</tr>
<tr>
<td>Avast</td>
<td>4.8.1351.0</td>
<td>2010.02.02</td>
<td>-</td>
</tr>
<tr>
<td>AVG</td>
<td>9.0.0.730</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>10.00</td>
<td>2010.02.03</td>
<td>(Suspicious)   &#8211; DNAScan</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.96.0.0-git</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Comodo</td>
<td>3809</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>DrWeb</td>
<td>5.0.1.12222</td>
<td>2010.02.03</td>
<td>Trojan.Fakealert.10737</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>35.2.7278</td>
<td>2010.02.03</td>
<td>Win32/FakeCodec!generic</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.5.1.85</td>
<td>2010.02.03</td>
<td>W32/FraudLoad.A!Generic</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.0.15370.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Fortinet</td>
<td>4.0.14.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>GData</td>
<td>19</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.80.0</td>
<td>2010.02.03</td>
<td>Trojan.Win32.FakeAV</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>13.0.900</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>7.10.966</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2010.02.03</td>
<td>Packed.Win32.Krap.an</td>
</tr>
<tr>
<td>McAfee</td>
<td>5881</td>
<td>2010.02.03</td>
<td>New  Malware.kd</td>
</tr>
<tr>
<td>McAfee+Artemis</td>
<td>5881</td>
<td>2010.02.03</td>
<td>Suspect-D!DEB5E58E1119</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>6.8.5</td>
<td>2010.02.03</td>
<td>Heuristic.LooksLike.Trojan.FakeAler.H</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.5406</td>
<td>2010.02.03</td>
<td>TrojanDownloader:Win32/Renos.KF</td>
</tr>
<tr>
<td>NOD32</td>
<td>4832</td>
<td>2010.02.03</td>
<td>a  variant of Win32/Kryptik.CDK</td>
</tr>
<tr>
<td>Norman</td>
<td>6.04.03</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>nProtect</td>
<td>2009.1.8.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>10.0.2.2</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>PCTools</td>
<td>7.0.3.5</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Prevx</td>
<td>3.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>22.33.02.04</td>
<td>2010.02.03</td>
<td>Trojan.Win32.Generic.51F8D7B1</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.50.0</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>3.2.1858.2</td>
<td>2010.02.03</td>
<td>Trojan-Downloader.Tibs.gen   (v)</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.5.1.0.179</td>
<td>2010.02.03</td>
<td>Trojan/Krap.an</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>9.120.0.1004</td>
<td>2010.02.03</td>
<td>TROJ_FAKEAL.SMDP</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.12.1</td>
<td>2010.02.03</td>
<td>Malware-Cryptor.Win32.Palka</td>
</tr>
<tr>
<td>ViRobot</td>
<td>2010.2.3.2170</td>
<td>2010.02.03</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>5.0.21.0</td>
<td>2010.02.03</td>
<td>Trojan.Codecpack.Gen</td>
</tr>
</tbody>
</table>
</blockquote>
<p>Memang file tersebut adalah <strong>virus</strong>. Sayangnya McAfee Enterprise yang Anas pakai versi lama jadi tidak terdeteksi. Untuk mengatasi virus ini Anas harus mengupdate Engine McAfee Enterprise ke versi 5881. Alhasil virus tersebut lenyap. Nah, sebagai saran aja buat para pembaca <a href="http://jembelisme.com">Jembelisme Media</a> jangan lupa update antivirus dengan versi terbaru.</p>
]]></content:encoded>
			<wfw:commentRss>http://jembelisme.com/new-variant-virus-edd-exe.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

