thank you everyone who supported the blog. but I am officially closed. I hope these posts will continue to interest people and I wish you all the best of luck.
The Bowery Presents
let's talk about Bridgerton tea, my ask is open

Discoholic đŞŠ
occasionally subtle
taylor price

gracie abrams
đŞź
trying on a metaphor

romaâ
tumblr dot com
Xuebing Du
Lint Roller? I Barely Know Her

Origami Around
Jules of Nature
I'd rather be in outer space đ¸
Sweet Seals For You, Always

seen from Colombia

seen from Germany
seen from Kazakhstan

seen from Netherlands
seen from Brazil
seen from United States
seen from Russia
seen from United States

seen from United States
seen from United States
seen from United States

seen from United States
seen from United States
seen from United States

seen from United States

seen from United States
seen from United States

seen from United States

seen from United States
seen from United States
@nimda01-blog
thank you everyone who supported the blog. but I am officially closed. I hope these posts will continue to interest people and I wish you all the best of luck.

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
Michael Aranda explains five of the worst computer viruses that have hit the net!
Zeus
Zeus, also known as Zbot, is a Trojan horse malware package made to infect computers running Microsoft Windows, so to perform various criminal tasks on its own. The most common of these tasks are usually man-in-the-browser keylogging and form grabbing. It is also used to install the CryptoLocker ransomware. The majority of computers were infected either through drive-by downloads or phishing scams. First identified in July 2007 when it was used to steal information from the United States Department of Transportation, it became more widespread in March 2009, when it managed to compromise over 74,000 FTP accounts and computers from large multinational corporations and banks, such as Amazon, Oracle, Bank of America, Cisco, etc. Controllers of the Zeus botnet used it to steal the login credentials of social network, email, and banking accounts.
In the US alone, it was estimated that more than 1 million computers were infected. The entire operation was sophisticated, involving people from around the world to act as money mules to smuggle and transfer cash to the ringleaders in Eastern Europe. About $70 million was stolen and in possession of the ring. 100 people were arrested in connection of the operation.
Zeus is very difficult to detect, even with up-to-date antivirus and other security software, as it hides itself using stealth techniques. This is considered the primary reason why the Zeus malware has become the largest botnet on the Internet: Damballa estimated that the malware infected 3.6 million PCs in the U.S. in 2009.
In late 2010, the creator of Zeus announced his retirement, and had given the source code and rights to sell Zeus to his biggest competitor, the creator of the SpyEye trojan, but many experts believe this to be false. Â
nVIR
nVIR is an obsolete computer virus which can replicate on Macintosh (Mac) computers running any System version from 4.1 to OS 8. The source code to the original nVIR has been made widely available, and so numerous variants exist. Each variant causes somewhat different symptoms, such as: application crashes, printing errors on laser printers, slow system response time, or unpredictable system crashes. nVIR spreads through any nVIR-infected program, but due to the long period of time nVIR lies basically dormant in a host system, nVIR generally finds its way into system backups and is not detected until the first overt symptoms appear. For example, if a disk used in an infected Macintosh is removed and inserted in a second Macintosh, the other machine will become infected if any application on that disk is executed in the second machine. Further, any method used to transfer programs between Macintoshes will spread nVIR, including file transfer over a network. However, nVIR cannot spread via a print network's hardware.
nVIR carries an additional code resource, CODE 256 (though some variants carry CODE 255), and patches the jump table to point to it. The original application's entry point is saved in the nVIR 2 resource. nVIR introduces to the System file the INIT 32 resource which is executed at startup, at which time nVIR patches the TEInit trap. Any application subsequently calling this trap will be infected. The nVIR 3 (or nVIR 5) resource is a copy of INIT 32. An nVIR 10 resource in the System file will prevent nVIR infection. If an application calls OpenResFile prior to TEInit, that application will be damaged.
nVIR 0 resource holds a counter that is set to 1000 on the first infection of the system. Each reboot decrements the counter by 1. Each application launch decrements it by 2. When the counter reaches 0, nVIR will beep 1 out of 8 reboots and 1 of 4 infected application launches. If MacinTalk is installed in the machine's System folder, the machine may occasionally say "Don't Panic". Otherwise, it may beep unexpectedly.
nVIR has been known to 'hybridize' with different variants of nVIR on the same machine.
Brain
Brain is the industry standard name for a computer virus that was released in its first form in January 1986, and is considered to be the first computer virus for MS-DOS. It infects the boot sector of storage media formatted with the DOS File Allocation Table (FAT) file system. Brain was written by two brothers, Basit Farooq Alvi and Amjad Farooq Alvi, from Lahore, Punjab, Pakistan. Brain affects the IBM PC computer by replacing the boot sector of a floppy disk with a copy of the virus. The real boot sector is moved to another sector and marked as bad. Infected disks usually have five kilobytes of bad sectors. The disk label is changed to ŠBrain, and the following text can be seen in infected boot sectors:
ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ (ď˝)  ď˝ď˝ď˝ď˝ď˝ & ď˝ď˝ď˝ď˝ď˝ď˝ (ď˝ď˝ď˝) ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝_ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ ď˝. ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ ď˝ď˝ ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ ď˝ď˝ď˝ ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ ď˝ ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ - ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝!! ď˝ď˝ ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ ď˝ ď˝..ď˝ď˝ď˝ď˝ď˝ : ď˝ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ď˝ď˝ ď˝ď˝ď˝ď˝ ď˝ ď˝ď˝ď˝ ď˝ď˝ ď˝ď˝ ď˝ď˝ď˝ď˝ď˝ ď˝....$#@%$@!!
In 2011, 25 years after Brain was released, Mikko HyppÜnen of F-Secure traveled to Pakistan to interview Amjad for a documentary. Being inspired by this documentary and its wide spread, a group of Pakistani bloggers interviewed Amjad, under the banner of Bloggerine.
Ashar is an older version of Brain. There are six variants, each with a different message.

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
AIDS
AIDS is a computer virus written in Turbo Pascal 3.01a which overwrites .com files. AIDS is the first virus known to exploit the MS-DOSÂ "corresponding file" vulnerability. In MS-DOS, if both foo.com and foo.exe exist, then foo.com will always be overwritten first.
When the AIDS virus activates, it shows a message that reads:
ATTENTION I have been elected to inform you that throughout your process of collecting and executing files, you have accdientally œHĂ¢KÎŁâş [PHUCKED] yourself over: again, that's PHUCKED yourself over. No, it cannot be; YES, it CAN be, a âĂŹĎĂťs [virus] has infected your system. Now what do you have to say about that? HAHAHAHAHA. Have ÂśHĂĂ [PHUN] with this one and remember, there is NO cure for AIDSÂ
In the message above, the word "AIDS" covers about half of the screen. The system then freezes, and must be powered down manually.
The AIDS virus overwrites the first 13,952 bytes of a .com file. Overwritten files must be deleted and replaced with clean copies in order to remove the virus. It is not possible to recover the overwritten portion of the program.
The AIDS II virus appears a more elegant revision of AIDS. AIDS II also employs the corresponding file technique to execute infected code.
Bomber
Also known as Commander Bomber, Bomber is a DOS polymorphic memory resident computer virus, known for its technique of "patchy infection". This method of infection is very similar to the one utilized by the OneHalf computer virus.
Contrary to the usual method of infecting executables (which is to append virus body to the executable  and to change the entry point), it inserts several fragments ("patches") of its code in random places inside the file. These fragments transfer control to each other using various mechanisms.
The method of infection makes the detection of the virus difficult by anti-virus programs, and it means that they would have to scan the file in its entirety in order to detect the virus.
The size of the Bomber executable is approximately 4096 bytes and contains the following text:Â
ďźďźďźĄďźŽďź¤ďźĽďź˛ ďź˘ďźŻďźďź˘ďźĽďź˛ ďźˇďźĄďźł 
[ďźďźĽ] [ďźďźĽ]
Blaster
The Blaster Worm (also known as Lovsan, Lovesan or MSBlast) was a computer worm that spread on computers running the Microsoft operating systems Windows XP and Windows 2000, during August 2003. The virus worked like this: once a network (such as a company or university) was infected, it spread faster within the network because firewalls typically did not prevent internal machines from using a certain port. Filtering by ISPs and widespread publicity about the worm curbed the spread of Blaster.
The worm was programmed to start a SYN flood against port 80 of windowsupdate.com if the system date is after August 15 and before December 31st and after the 15th day of other months, thereby creating a DDoS against the site. The damage to Microsoft was minimal as the site targeted was windowsupdate.com, rather than windowsupdate.microsoft.com to which the former was redirected. Microsoft temporarily shut down the targeted site to minimize potential effects from the worm.
The worm's executable, MSBlast.exe, contains two messages. The first reads  âI just want to say LOVE YOU SAN!!â This message gave the worm the alternative name of Lovesan. The second reads âbilly gates why do you make this possible ? Stop making money and fix your software!!â This is a message to Bill Gates, the co-founder of Microsoft and the target of the worm.
The worm also creates the following registry entry so that it is launched every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ windows auto update=msblast.exe
On August 29, 2003, Jeffrey Lee Parson, an 18-year-old from Hopkins, Minnesota, was arrested for creating the B variant of the Blaster worm; he admitted responsibility and was sentenced to an 18-month prison term in January 2005.
Want to see computer viruses, trojans, and worms in action? This is the YouTube channel for you. From digital mischief to outright destruction, I try to sample a bit of everything that made older malware (malicious software) unique from its modern day counterparts.
I donât distribute malware, so donât ask. If you post links to malware in the comments, itâll most likely be filtered and eventually removed. Repeat offenders will be blocked from posting new comments.
FAQ:
Q: Whatâs your keyboard?
A: IBM Model M 1391401
Q: What PCs do you use for videos?
A:If you see a video captured with a screen recorder, the video was made using a virtual machine. I use Virtual PC 2007 for these videos, and Camtasia Studio 7 to record the footage.
If the video is captured with a camera pointed at an MS-DOS computer, this is most likely my Packard Bell Legend 316SX, running a 386SX processor with two megabytes of RAM.
Special thanks to unjinz for the channel art.
https://www.youtube.com/user/danooct1/featured
Ransomware
Much more recent, Ransomware is a type of malware which restricts access to the computer system that it infects, and demands a ransom paid to the creator(s) of the malware in order for the restriction to be removed. Some forms of ransomware encrypt files on the system's hard drive (cryptoviral extortion, a threat originally envisioned by Adam Young and Moti Yung), while some may simply lock the system and display messages intended to coax the user into paying.While initially popular in Russia, the use of ransomware scams has grown internationally; in June 2013, security software vendor McAfee released data showing that it had collected over 250,000 unique samples of ransomware in the first quarter of 2013âmore than double the number it had obtained in the first quarter of 2012. CryptoLocker, a ransomware worm that surfaced in late-2013, had procured an estimated $3 million USD before it was taken down by authorities.
Ransomware typically propagates as a conventional computer worm, entering a system through, for example, a downloaded file or a vulnerability in a network service. The program will then run a payload: such as one that will begin to encrypt personal files on the hard drive. More sophisticated ransomware may hybrid-encrypt the victim's plaintext with a random symmetric key and a fixed public key. The malware author is the only party that knows the needed private decryption key. Some ransomware payloads do not use encryption. In these cases, the payload is simply an application designed to restrict interaction with the system, typically by setting the Windows Shell to itself, or even modifying the master boot record and/or partition table (which prevents the operating system from booting at all until it is repaired).
Ransomware payloads utilize elements of scareware to extort money from the system's user. The payload may, for example, display notices purportedly issued by companies or law enforcement agencies which falsely claim that the system had been used for illegal activities, or contains illegal content such as pornography and pirated software or media. Some ransomware payloads imitate Windows XP's product activation notices, falsely claiming that their computer's Windows installation is counterfeit or requires re-activation.These tactics coax the user into paying the malware's author to remove the ransomware, either by supplying a program which can decrypt the files, or by sending an unlock code that undoes the changes the payload has made. These payments are often delivered using either a wire transfer, premium-rate text messages, through an online payment voucher service such as Ukash or Paysafecard, or most recently, the digital currency Bitcoin.

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
Sobig.
Sobig was a computer worm that infected millions of Internet-connected, Microsoft Windows computers in August 2003. Although there were indications that tests of the worm were carried out as early as August 2002, Sobig.A was first released to the public in January 2003. Sobig.B was released in May 2003, though first called Palyh. It was renamed after anti-virus experts discovered it was a variant of Sobig. Sobig.C was released May 31; it fixed the timing bug in Sobig.B. Sobig.D came a couple of weeks later followed by Sobig.E. On August 19, Sobig.F became known and set a record in sheer volume of e-mails. The worm was most widespread in its "Sobig.F" variant.
Sobig is not only a computer worm in the sense that it replicates by itself, but also a Trojan horse in that it masquerades as something other than malware. The e-mail contained the text: "See the attached file for details" or "Please see the attached file for details." and contains either a .pif or .scr file. When the file is installed, the virus will replicate by using its own SMTP agent engine. E-mail addresses that will be targeted by the virus are gathered from files on the host computer.
The Sobig.F variant was programmed to contact 20 IP addresses on UDP port 8998 on August 26, 2003 to install some program or update itself. It is unclear what this program was, but earlier versions of the virus had installed the WinGate proxy server softwareâa legitimate productâin a configuration allowing it to be used as a backdoor for spammers to distribute unsolicited e-mail. The virus was written using Microsoft Visual C++ compiler, and was compressed using a program called tElock.
The Sobig.F worm deactivated itself on September 10, 2003. On November 5 the same year, Microsoft announced that they will pay $250,000 for information leading to the arrest of the creator of the Sobig worm. To date, the perpetrator has not been caught.
i love how much work you put into your virus posts its so nice to read something like that!
i honestly love writing them! itâs sort of an obsession i have with viruses, pretty weird, right? i think theyâre super cool and iâve always wanted to show other people them so maybe i wonât feel so weird about the whole thing lol. iâm glad you think so though!
Storm Worm
The Storm Worm (dubbed so by the Finnish company F-Secure) is a backdoor Trojan horse that affects computers using Microsoft operating systems, discovered in January of 2007. The worm is also known as:
Small.dam or Trojan-Downloader.Win32.Small.dam (F-Secure)
CME-711 (MITRE)
W32/Nuwar@MM and Downloader-BAI (specific variant) (McAfee)
Troj/Dorf and Mal/Dorf (Sophos)
Trojan.DL.Tibs.Gen!Pac13
Trojan.Downloader-647
Trojan.Peacomm (Symantec)
TROJ_SMALL.EDW (Trend Micro)
Win32/Nuwar (ESET)
Win32/Nuwar.N@MM!CME-711 (Windows Live OneCare)
W32/Zhelatin (F-Secure and Kaspersky)
Trojan.Peed, Trojan.Tibs (BitDefender)
Storm Worm began infecting thousands of (mostly private) computers in Europe and the United States, using an e-mail message with a subject line about a recent weather disaster, "230 dead as storm batters Europe". During the weekend there were six subsequent waves of the attack. As of January 22, 2007, the Storm Worm accounted for 8% of all malware infections globally.
There is evidence, according to PCWorld, that the Storm Worm was of Russian origin, possibly traceable to the Russian Business Network. According to Joe Stewart, director of malware research for SecureWorks, Storm remains amazingly resilient, in part because the Trojan horse it uses to infect systems changes its packing code every 10 minutes, and, once installed, the bot uses fast flux (a DNS technique used by botnets to hide phishing and malware delivery sites) to change the IP addresses for its command and control servers.
Mydoom
First sighted in January of 2004, Mydoom, also known as W32.MyDoom@mm, Novarg, Mimail.R and Shimgapi is a computer worm affecting Microsoft Windows. It became the fastest-spreading e-mail worm ever (as of January 2004), exceeding previous records set by the Sobig worm and ILOVEYOU.
Mydoom appears to have been commissioned by e-mail spammers so as to send junk e-mail through infected computers. The worm contains the text message "andy; I'm just doing my job, nothing personal, sorry," leading many to believe that the worm's creator was paid. Early on, several security firms expressed their belief that the worm originated from a programmer in Russia. The actual author of the worm is unknown.
Speculative early coverage held that the sole purpose of the worm was to attack the SCO Group with a DDoS. 25 percent of Mydoom.A-infected hosts targeted www.sco.com with a flood of traffic. Trade press conjecture, spurred on by SCO Group's own claims, held that this meant the worm was created by a Linux or open source supporter in retaliation for SCO Group's controversial legal actions and public statements against Linux. This theory was rejected immediately by security researchers.Â
Initial analysis of Mydoom suggested that it was a variant of the Mimail wormâhence the alternate name Mimail.Râprompting speculation that the same people were responsible for both worms. Later analyses were less conclusive as to the link between the two worms.
Mydoom was named by Craig Schmugar, an employee of computer security firm McAfee and one of the earliest discoverers of the worm. Schmugar chose the name after noticing the text "mydom" within a line of the program's code. He noted: "It was evident early on that this would be very big. I thought having 'doom' in the name would be appropriate."
Conficker
First detected in 2008, Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system. It uses flaws in Windows OS software and dictionary attacks on administrator passwords to propagate while forming a botnet, and has been unusually difficult to counter because of its combined use of many advanced malware techniques.The Conficker worm infected millions of computers including government, business and home computers in over 200 countries, making it the largest known computer worm infection since 2003.
Although almost all of the advanced malware techniques used by Conficker have seen past use or are well known to researchers, the virus' combined use of so many has made it unusually difficult to eradicate. The virus' unknown authors are also believed to be tracking anti-malware efforts from network operators and law enforcement and have regularly released new variants to close the virus' own vulnerabilities.Five variants of the Conficker virus are known and have been dubbed Conficker A, B, C, D and E (go here to read about the variants).

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
SQL Slammer
In January of 2003, Â the SQL Slammer worm caused a DDoS in some Internet hosts and dramatically slowed down general Internet traffic. It spread rapidly, infecting most of its 75,000 victims within ten minutes. Slammer was first brought to the attention of the public by Michael Bacarella. Although titled âSQL slammer wormâ, the program did not use the SQL language; it exploited a buffer overflow bug in Microsoftâs flagship SQL Server and Desktop Engine database products, for which a patch had been released six months earlier in MS02-039. Other names include W32.SQLExp.Worm, DDOS.SQLP1434.A, the Sapphire Worm, SQL_HEL, W32/SQLSlammer and Helkern.
The worm was based on proof of concept code demonstrated at the Black Hat Briefings by David Litchfield, who had initially discovered the buffer overflow vulnerability that the worm exploited. It is a small piece of code that does little other than generate random IP addresses and send itself out to those addresses. If a selected address happens to belong to a host that is running an unpatched copy of Microsoft SQL Server Resolution Service, the host immediately becomes infected and begins spraying the Internet with more copies of the worm program.Â
The worm was made possible by a software security vulnerability in SQL Server first reported by Microsoft on July 24, 2002. A patch had been available from Microsoft for six months prior to the wormâs launch, but many installations had not been patched â including many at Microsoft.
CIH
First emerging in 1998, CIH, also known as Chernobyl or Spacefiller, was a Windows 9x virus, considered one of the most damaging viruses to ever exist. It would overwrite critical information on infected system drives, destroying the systems BIOS. The total cost of damage was an estimated  $1 billion USD.
The virus was written by Chen Ing-hau, who was a student at Tatung University in Taiwan. Chen claims to have written the virus to challenge antivirus efficiency. He was never charged with spreading the virus because the original spread occurred at his university, he claimed he never meant for it to spread and quickly developed an antivirus to remove the virus from systems infected.
The name âChernobylâ came from the coincidence that a variant of CIH had a payload that went into effect on April 26th, the anniversary date of the Ukrainian Chernobyl nuclear incident. The name "Spacefiller" was introduced because most viruses write their code to the end of the infected file, however CIH looks for gaps in the existing program code where it writes its own code. This does not increase the file size and in that way helps the virus avoid detection.