Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Monday, March 15, 2010

What is Trojan horse?

Trojan horse
Trojan horse is not exactly a virus. It is a software application that will only perform its function after being executed by the user.

Sometimes, a Trojan horse hides itself as a folder while in fact, it's a .EXE file. This is to catch the eye of users so they will click and execute it.

Different kinds of Trojan horse are OSX.RSPlug Trojan of Mac operating system, Trojan horse downloader, Trojan horse Generic 9, Trojan horse downloader Adload, Trojan horse generic 6, Trojan horse spyware and Trojan horse Vundo.

After the user executes the file, it will open an alternative means for malicious software such as spyware and adware to infect your PC. After the execution of file the keyloggers will enter from back doors and will pollute files and folders. Keylogger is an explicit software code that has capability of calculating the keyboard stroke, such as username and password for misuse purpose.

Trojan horse infection comes from downloading the program themselves or its being downloaded into their system stealthily. For example, you are looking for some paid program on Google that converts into video format.

Trojan horse is a rouge application code that shut downs the performance of PC. Some of the hazardous affects of Trojan horse are-

• Repeated system reboot
• Slow work efficiency of system
• Uncertain system crash
• Unexpected termination of application programs
• Delay’s in program opening and close
• Sound disabilities in speakers

Trojan horse is a system deadly application code and has to be removed to prevent unnecessary changes in system performance. Consider the steps for removal of Trojan horse-

STEP 1: Disable System Restore feature on your PC. System Restore, if enabled will restore all deleted files containing Trojan horse. Go to “My computers”, click on performance and select File system and then, Disable System Restore.

STEP 2: Reboot your PC in safe mode by persistently pressing the F8 key.

STEP 3: Go to start, click on “Control panel” and then, click on ADD\REMOVE Programs. It will show you list of programs containing Spyware and adware. Select the Remove program option.

STEP 4: In Windows System Folder delete all the files that contains Trojan virus extension.
Trojan horse is an explicit source code that alters the efficiency of PC. To prevent your system from getting affected with Trojan horse install antivirus security program such as McAfee Premium.

Related Post:-

Friday, January 29, 2010

Free Trojan Horse Removal

Free Trojan Horse Removal
A Trojan virus is a piece of malicious computer software,.which enters into the victim computer without the consent of the computer administrator. It is cited as the most common type of malwares, which is known to infect maximum number of computer systems worldwide. This should not be a point of surprise, because almost every computer connected to Internet is affected by one or the other form of malicious software. The main difference between Trojan virus and other computer viruses is that the former are capable to destroy your computer system to the same extent which the latter can do.

Trojan virus makes use of several practices and methods to get into a PC without the consent of the computer user. Some websites offer free software applications and utilities to make your PC much faster and a good performer. The Trojan virus pretends to be similar to the free software utility, which might damage your computer system or they may look like a folder or an important link, which demands a user click for executing. Once a Trojan virus receives a click from the user, it starts its action there. It opens the door for other harmful and dangerous malicious codes such as worms, adwares, and spywares.

It is strongly recommended that you should carry out a research before downloading any freeware from Internet.

If you are looking for a free Trojan virus remover tool then you can find here a list of some of the best Trojan remover tools:

1. Trojan Remover
2. A-Squared Anti-Malware
3. MalwareBytes
4. XoftSpySE

There are several free version of Trojan virus removal tool available on Internet. You can try one which you find to be authentic. You don’t need to search for the type of Trojan virus installed on your computer or the registry affected by the Trojan virus. Just download the latest version of Trojan Remover software and scan your PC for the presence of any virus infection.

Friday, May 1, 2009

GameSpy Arcade spyware

GameSpy Arcade is a game program that is used to find players, maps and servers when playing many well-known multiplayer Internet games. It also secretly installs the spyware WebHancer, an executable program that tracks and records a user's actions across the web and reportedly overwrites some vital system files, especially where the user's Internet relation is concerned.
Recommendation for GameSpy Arcade :

It is highly recommended that you do a scan to remove the bundled spyware.

See Also
antivirus windows
malicious spyware removal

Friday, April 24, 2009

Top 10 Viruses Related to Microsoft Word

Back in the early nineties, 84% of virus attacks were aimed at Microsoft Word. This was all down to what are called macros, which are small computer programs that do flashy things like changing the way a display looks or performing calculations.

Microsoft Word allows macros within Word documents, which wasn't a poor idea to begin with but all went wrong when the virus makers discovered how easy it was to make macro viruses. Their macros do snazzy things too, like adding malicious files and editing other files that determine how your computer runs.

The problem has declined now because the latest versions of Word (2000 on) do a decent job of protecting against Word macro viruses. Older versions (Word 6 and earlier) are poor. Word 7 is somewhere in the middle.

If you run an old version of Word, you should certainly run a virus checker too. If you don't want to do this, then you must take a lot of precautions over which Word documents you open.
The safest thing to do is open any strange Word documents that you receive by email or on disk in WordPad first. They won't open properly and the first 30 or more lines will be code garbage, but in the middle you'll find most of the text of the file, enough to check whether it's a genuine file that you need to open the proper way.

Modern versions of Word will inform you that a document contains a macro and offer you the option "Disable Macros" before opening. Always choose this option without fail. You can always open the document a second time, with macros enabled, once you've established that it's a genuine document and you need the macros to run.


Microsoft Word Viruses
Cap
Concept
Niceday
Wazzu
Colors
MDMA
Npad

See Also
computer virus removal
Twitter Under Attack Once Again
Windows Live One Care Help You
windows firewall security
Online Computer Support

Thursday, April 23, 2009

Twitter Under Attack Once Again

"Late Sunday night and into the wee hours of Monday we fought off a fourth attack," said Biiz Stone, co-founder of Twitter, in an update to a blog post he originally published Sunday. "Once again, we secured the compromised accounts and deleted any material that would further propagate the worm."

The latest attack -- which followed a pair of worms Saturday and a third Sunday -- originated from a just-registered account labeled "cleaning Up Mikeey," said F-Secure Corp.'s chief research officer,
Mikko Hyppfonen. Today's copycat worm infected account profiles of people who clicked on the sender's name or image in tweets like, "How TO remove new Mikeayy worm! RT!! http://bit.ly/yCL1S."

"A message like this is particularly nasty, as there were plenty of re-tweets of this malicious message sent by genuine users," Hypponen said in a blog post just minutes after Monday's attack began. "The bit.ly link got redirected back to Twitter, to user reberbrerber's profile & which would infect Twitter users who viewed it."

Twitter has since deleted the cleaningUpMikey account and the tweets it and other infected accounts spawned.

Also on Monday, Twitter again emphasized that while the worm attacks have been a nuisance, they haven't stolen any user account information. "No passwords, phone numbers, or other sensitive information were compromised as part of this renewed attack," the service's status page said early this morning.

Twitter has not responded to questions posed Sunday about the attacks, specifically about whether it had, or would, contact law enforcement officials. According to some reports, and his own Web site, teenager Michael "Mikeyy" Mooney took responsibility for the worms that circulated on Twitter over the weekend.

In his updated blog today, Stone hinted that the company would take legal action against the worms' creators. "The worm introduced to Twitter this weekend was similar to the famous Samy worm, which spread across the popular MySpace social-networking site a while back," Stone wrote. "At that time, MySpace filed a lawsuit against the virus creator, which resulted in a felony charge and sentencing. Twitter takes security very seriously and we will be following up on all fronts."

In 2005, Samy Kadmkar exploited a bug in MySpace to add as a "friend" anyone who viewed his account profile. He then copied a snippet of JavaScript to that user's profile to continue the hack. Within 24 hours, he had accumulated over a million friends.

MySpace sued, and in January 2007 Kadmkar pleaded guilty to a single felony count. He was sentenced to three years probation and 90 days of community service.

See Also
spyware removal software
how to remove cipav spyware
malicious spyware removal
remote virus scan
windows 7

Wednesday, April 22, 2009

Claria Spyware

Upon installing the program, the installation wizard states that Claria will show advertisements based on the sites a user visits on the internet. The wizard does not state that it will monitor every site a user visits and report that data back to the vendor's database as long as the software is functioning. However, this information is clarified in a detailed End User License Agreement , which is read by very few users. The End User License Agreement gives Claria the right to track and report back information regarding all of the programs on your computer, along with the first four digits of your credit card number, allowing them to know what institution you bank at.

Another huge concern of the public was the fact that the users were prohibited to remove Claria software with anti-virus or anti-spyware software. According to the End User License Agreement, the only way a user was permitted to remove the program was by using the "Add/Remove Programs" utility in the Microsoft Windows operating system.

Additionally, the End User License Agreement does not fully disclose as to what data the Claria Corporation actually collects. Many users were outraged that the program captured sensitive data that could be potentially used to commit internet crimes. Scott Eadgle, the company's Chief Marketing Officer, claims that the only information Claria collects now is behavior of "commercial intent" - referring to product research and shopping online. Eagle went on to claim that the data is filed by an anonymous computer identification number and does not collect email addresses, usernames, zipcodes or complete credit card numbers.

Removal of Claria spyware
Like several types of spyware and adware, the Claria software doesn't completely uninstall after using the "Add/Remove programs" utility. It leaves behind various files and programs such as GAIN, that lead back to the company's server, along with several fragments that can only be cleaned up by a registry cleaning application. Scoott Eadgle states that GAIN is a separate add-delivery program that only collects non-personal user data and automatically uninstalls itself after all traces 0f Claria are completely removed.

See also
remote virus scan
antivirus spyware removal
malicious spyware removal
how to remove cipav spyware
optimize your web browser

Thursday, April 16, 2009

Types of Spyware in your computer

Spyware is any software that collects information from a PC without the user’s knowledge. There are many different types of spyware operating on the Internet but you can generally group them into two categories: Domestic Spyware and Commercial Spyware.

Domestic Spyware is software that is usually purchased and installed by computer owners to watch the Internet behavior on their computer networks. Employers use this software to monitor employee online activities; some family members use domestic spyware to monitor other family members (such as reviewing the content of children’s chat room sessions).

Commercial Spyware (also known as adware) is software that companies use to track your Internet browsing activities. Companies that track your online habits often sell this information to marketers who then hit you with targeted advertising—ads that match your browsing interests and would most likely appeal to you.

Advertisers are delighted when they acquire such valuable marketing information so easily; in the past marketers had to bribe you to learn your preferences through contests, registration surveys and the like. Those methods of gaining your personal information still exist, but in those cases you have the power to read the fine print to learn the fate of your data and so could choose to consent or refuse. Gaining your preferences by stealth using software spies is far easier and offers a much more complete picture for the marketing industry; as a result, spyware is everywhere. For more information on how and when spyware attaches itself to your computer, read

How Did Spyware End Up on My Computer?
At the very least, spyware is a nuisance—slowing down your computer, filling your hard drive with useless gunk and marking you as a target for enterprising advertisers. Beyond intruding on your privacy, spyware can be used as a tool to perpetuate crimes, such as identify fraud. Below is a list detailing different types of spyware and the purposes for each.

Internet URL loggers & screen recorders
URL loggers track websites and pages visited online; screen recorders can take a small grayscale snapshot image of your screen every time it changes and can store or transmit these without notifying you. These methods are common to Domestic spyware.

Keyloggers & password recorders Keyloggers & password recorders
When you bank online with this software on your hard drive someone is looking over your shoulder. Password recorders do just that—track typed passwords. Keylogger software records all of your keystrokes, not just passwords.

Web bugs
Web bugs are also known as advertiser spyware or adware. When you have adware on your computer you receive targeted, popup ads after you perform some action, such as typing something into a search engine. This advertising can even appear on your screen even when you are not online. If you are pummeled with new advertising screens constantly, you most likely have web bug spyware installed on your computer.

Browser hijacking
Browser hijackers place Internet shortcuts on your Favorites Folder without prompting you. This shortcut will lead many accidental viewers to their website so that they may artificially inflate their website\'s traffic stats; this enables them to receive higher advertising revenues at the expense of your time. You may be able to get rid of these false favorites by changing your Internet options, but occasionally the only way to get rid of these annoying shortcuts is to go into your registry and delete them. However, some spyware installs a safety net for itself that resets the spyware on your registry each time you reboot. Your only option to kill this aggressive type of spyware is to reformat your hard drive or to utilize an excellent anti-spyware program.

Modem hijacking
If you use a telephone modem for your Internet connection, an unscrupulous person may be able to install an online dialer on your computer to establish a new Internet connection that uses pricy 900-type long-distance phone numbers—quite a shock when you get your next telephone bill. These dialer spyware programs often piggy-back on spam and porn emails; simply opening the email can inadvertently initiate the dialer installation. The hard-to-track villain banks on the fact that you’ll pay your phone bill in full before you take time to figure out what happened.

PC hijacking
Some borrow your computer system for their own use—spyware users can hijack your connection to send their spam through your ISP. This means that a parasitical spammer can send thousands of spam emails through your computer connection and your ISP address. High-volume, high speed Internet access lines are targeted by users of this spyware. Often victims don’t realize that their good name has been muddied until their ISP cuts them off due to spam complaints.

Trojans & viruses
Like the wooden Trojan horse that the Greeks used to enter Troy, this spyware masquerades as a something harmless yet can compromise your computer—your data may be copied, distributed or destroyed. A virus is similar but has the additional power to replicate itself, causing damage to multiple computers. Both of these vicious pieces of software fall under the definition of spyware because the user is unaware of and would not condone their true purpose.

Related Search
morris worm removal
spyware adware removal software
Password-Manipulating Virus Spreading
How To Secure Yourself Against Conficker Worm

Tuesday, April 14, 2009

17-year-old Attacked Twitter With Worm

The nettlesome program, known as a worm, targeted Twitter's network with four different attacks starting early Saturday and ending early Monday, according to Twitter co-founder.
The worm was set up to promote a Twitter knockoff, StalkDaily.com. It displayed unwanted messages on infected Twitter accounts, urging people to visit the Web site.

The worm was designed to automatically reproduce itself once its links were clicked on, but it didn't filch any personal information from the more than 6.1 million people with Twitter accounts, Stone wrote in a posting about the incident. Nearly 10,000.00 Twitter messages, known as "tweets," had to be deleted to contain the potential damage.
"We are still reviewing all the details, cleaning up and we remain alert," Stone reassured Twitter's audience.

Michael "Mikeyy" Mooney, a 17-year-old high school student who created StalkDaily, acknowledged unleashing the worm in a Monday interview with The Associated Press. Besides wanting to promote his Web site, Mooney said he wanted to expose Twitter's weaknesses.
"I really didn't think it was going to get that much attention, but then I started to see all these stories about it and thought, 'Oh my God,' " said Mooney, who lives in Brooklyn, N.Y. He first confessed his responsibility for the worm .

Mooney began having second thoughts about what he had done after reading a part of Stone's posting indicating that Twitter might pursue legal action against its tormenter. In a Monday e-mail sent to the AP, Stone said he didn't know whether Twitter will go after Mooney.
"If I get hit with a lawsuit, I am going to have major regrets and a big brick on my back," Moooney said. "I am backing off now. Twitter ignored its vulnerability (to worms) so I am hoping they can just ignore me now."

In the mean time, Mooney is retooling StalkDaily.com to accommodate more users. He has temporarily closed the site after getting swamped by the traffic triggered by his worm.
The trouble with Mooney represents another rite of passage for San Francisco-based Twitter, which has emerged a popular way to communicate on the Web and mobile phones since its debut three years ago.

Twitter's system, which limits messages to 140 characters, is used to broadcast both mundane and tantalizing information by a diverse group of users that include teenagers, celebrities, news agencies, politicians, police departments and companies.

Twitter's broadening reach makes it an inviting target for mischief makers and scam artists. Two of the Internet's biggest online hangouts, Facebook and MySpace, both have had to grapple with similar threats.

The widening usage also occasionally overwhelms the free service, whose 30 employees have been subsisting on about $55 million in venture capital until Stone and fellow co-founder Evan Williams come up with a way to generate revenue.

Although it doesn't break down as frequently as it did in its early days, Twitter periodically remains inaccessible because its computer servers can't handle all the traffic.
Such challenges have spurred speculation that Twitter eventually will be sold to a larger Internet company. Twitter already spurned a $500.00 million buyout offer from Facebook Inc. There also have been unsubstantiated reports that Internet search leader Google Inc. is eyeing a possible bid for Twitter.

Both Williams and Stone have said they intend to build Twitter into a profitable, independent company.

Related Search
virus removal software
Password-Manipulating Virus Spreading
How To Secure Yourself Against Conficker Worm

Monday, April 13, 2009

Conficker also installs fake antivirus software

Programmers have discovered another characteristic of the Conficker worm that provides an additional clue about the intent of the creators--the worm installs malware that masquerades as antivirus software.

The worm, which has infected millions of Windows-based computers on the Internet, is downloading a program called Spyware Protect 2009 and displaying warning messages saying that the computer is infected and offering to clean it up for US$49.9500, according to the Trend Micro blog.

The infection alerts repeatedly appear and experts are worried that people may be clicking on them and paying for the software just to be rid of the annoying messages, thereby handing thieves their credit card information.

The fake antivirus program also attempts to install a Trojan downloader that is programmed to download new versions of Spyware Protect 2009, according to Kasperky Lab's blog. However, the domain the Trojan downloader was being accessed from has been shut down, the blog said.
The fake antivirus feature further bolsters the speculation that the motivation behind the worm is to make money and not a desire to disrupt computer or network operations.
Researchers were still analyzing new component code of the worm that began being spread via peer-to-peer and being downloaded off domains that host the Waledec worm on Wednesday but were finding the task difficult because the instructions are encrypted.

The worm spreads via a hole in Windows that Microsoft patched in October, as well as through removable storage devices and network shares with weak passwords. The worm disables security software and blocks access to security Web sites.

Despite all the news the worm has made, many computers still remain unpatched, Sophos said. Of the number of people who have used Sophos' free endpoint assessment test to check the security risk of a network since the beginning of the year, 11.00 percent did not have the Microsoft patch installed, according to Graham Cluley's blog at Sophos.
For the month of March, 10 percent of all of the people who used the Sophos assessment tool were missing the patch, he said. The company did not divulge exactly how many people had used the tool and Cluley said the statistics cannot be extrapolated to represent the number of unpatched systems on the Internet.

In an indication of infection rates, IBM's Internet Security Systems group released statistics that show that the number of unique IPs infected with Conficker.C is increasing slightly.
Based on infections seen through monitoring devices in its IBM ISS' Managed Security Services, the number has grown from just over 64,000 on April 2 to more than 71,000 on April 8, according to the unit's Frequency X blog.

"We've seen around 11 percent more unique IPs in the past few days in comparison to a week ago," the blog said, also adding that the number doesn't necessarily indicate the scope of worldwide Conficker infection.

Nearly 60.00 percent of the infections monitored by IBM ISS are in Asia, followed by 18 percent each in Europe and South America, and 4 percent in North America, the statistics show. By country, China leads with 16.6 percent, followed by Brazil at 10.800 percent, Russia at 10.200 percent and Korea at 4.600 percent, according to ISS.

Related Search

Wednesday, April 8, 2009

Security Experts: Conficker still a threat

THE threat posed by network worm Conficker is not over - instead it's a question of "what's next''.

About 11 million computers worldwide have been infected by the tenacious and mysterious worm, but the expected trigger date, April one, passed without harm.


"Most of the security communities - those who aren't caught up in the hype - are maintaining a watch on Conficker to see where it goes next.''

Concerns surround the advanced capabilities of the worm, which incorporates lessons learned from pioneering peer-to-peer worms .

"Normally with botnets, we try to find the command and control centre, because if you chop off its head the botnet dies,'' Mr Iram said. "With P2P worms, each of the peers is potentially the command and control centre and they simply pass the function among themselves.

"Their communications are encrypted - and these are good encryptions, not something that just anyone can break into - so we don't know what the infected machines are instructed to do.

"And because the drones don't need to phone home to a central controller, it becomes very difficult to find the injection point into the network, and it's very much harder to stop.''

When the Storm worm was released, it "was incredibly advanced over anything we'd seen'' at the time, Mr Ingyram said.

"They had a lot of machines that were well controlled and security people had a limited capability to disrupt or mitigate it.''

In the end, the Storm botnet was broken down and borrowed out to spammers, "which is annoying but not earth-shattering'', he said.

"But much of that experience has gone into Conficker, and even if they don't get it right this time, it's another step on the road towards better malware, and that's very concerning.''

Related Search
Computer Virus Removal
Remote Virus Scan and Removal
How To Catch A Computer Virus

Tuesday, April 7, 2009

How To Protect Yourself from Phishing and Internet Fraud

Phishy Emails. The most common form of phishing is emails pretending to be from a, bank, organization, or government agency. The sender asks to "confirm" your personal information for some reason: an order for something has been placed in your name, or your information has been vanished because of a computer problem. Another method phishers use is to say they''re from the fraud departments of well-known companies and ask to verify your information because they suspect you may be a victim of identity theft! In one case, a phisher claimed to be from a state lottery commission and requested people''s banking information to deposit their "winnings" in their accounts.

links within emails that ask for your personal information. Fraudsters use these links to attract people to phony Web sites that looks just like the real sites of the company, organization, or agency they''re impersonating. If you follow the instructions and enter your personal information on the Web site, you''ll deliver it directly into the hands of identity thieves. To check whether the message is really from the company or agency, call it directly or go to its Web site (use a search engine to find it).

Pharming: In this latest version of online ID theft, a virus or malicious program is secretly planted in your computer and hijacks your Web browser. When you type in the address of a legitimate Web site, you''re taken to a fake copy of the site without realizing it. Any personal information you provide at the phony site, such as your password or account number, can be stolen and fraudulently used.

pop-up screen. Sometimes a phisher will direct you to a real company''s, organization''s, or agency''s Web site, but then an unauthorized pop-up screen created by the scammer will appear, with blanks in which to provide your personal information. If you fill it in, your information will go to the phisher. Legitimate companies, agencies and organizations don''t ask for personal information via pop-up screens. Install pop-up blocking software to help prevent this type of phishing attack.

Use anti-virus and anti-spyware software, and a firewall, and keep them up to date. A spam filter can help reduce the number of phishing emails you get. Anti-virus software, which scans incoming messages for troublesome files, and anti-spyware software, which looks for programs that have been installed on your computer and track your online activities without your knowledge, can protect you against pharming and other techniques that phishers use. Firewalls prevent hackers and unauthorized communications from entering your computer - which is especially important if you have a broadband connection because your computer is open to the Internet whenever it''s turned on. Look for programs that offer automatic updates and take advantage of free patches that manufacturers offer to fix newly discovered problems. Go to www.onguardonline.gov and www.staysafeonline.org to learn more about how to keep your computer secure.

Beware of email attachments if you''re expecting them and know what they contain. Even if the messages look like they came from people you know, they could be from scammers and contain programs that will steal your personal information.

Act immediately if you''ve been hooked by a phisher. If you provided account numbers, PINS, or passwords to a phisher, notify the companies with whom you have the accounts right away. For information about how to put a "fraud alert" on your files at the credit reporting bureaus and other advice for ID theft victims, contact the Federal Trade Commission''s ID Theft Clearinghouse, www.consumer.gov/idtheft or 877-438-4337, TDD 202-326-2501.

Report phishing, whether you''re a victim or not. Tell the company or agency that the phisher was impersonating. You can also report the problem to law enforcement agencies through NCL''s Fraud Center, www.fraud.org. The information you provide helps to stop identity theft.

Related Search
spyware removal

Monday, April 6, 2009

A virus alert might infect your computer

Yesterday my computer kept giving me a message that it had detected spyware. The window looked like a genuine Microsoft window.

The message kept popping up from a Microsoft looking icon on my toolbar, so of course, I thought it was a Microsoft popup. It looks like when your computer pops up that little window that says, "Your computer is searching for automatic updates." Windows automatically does this if you have that feature enabled.

After investigating the issue, I found that the message was false and it was trying to get me to download some antispyware software that is actually spyware.
The software is called Anti-Virus Number one and it's actually spyware.

Yesterday, I reported that my son was excited to revisit a Pokemoon Craiter site. We did register with this site within the past 24 hours, so I'm not sure if this spyware was connected to that in any way. Perhaps it's not, but that site was running awfully slow and not doing what we were trying to get it to do. So who knows?

I removed my blog post about the game and I'm personally never going to that site again. A pity because my kids liked that game. Oh well. We certainly have enough other computer and video games.

Always be wary of anything that urges you to download something from the internet with the threat of something horrible happening to you and your computer if you don't. If it says, "your computer will blow up if you don't download this right away!" then it's probably a fraud.

Related Search
virus removal
Computer Virus Removal
Remote Virus Scan and Removal
How To Catch A Computer Virus

Friday, March 27, 2009

New Malware & Viruses

According to ESET, a computer security firm, the most recent virus and other malware attacks are sophisticated and insidious as they rely on socially engineered tactics that lure probable victims into downloading malicious code on their systems. The statement came as a warning that ESET raised during a briefing to the press in Makati City (Philippines).

The security company states that amidst all Internet threats, fake anti-malware programs pose the greatest danger. According to it, a pop-up box would usually emerge saying that there is a spyware or malware on the user's system; therefore, the user needs to click on link to get free anti-spyware or anti-malware software.

The spyware or malware, while taking gain of the genuine software, continues to stay on the user's system despite the free protection solution.
Other variations of similarly socially engineered malicious software also exist like false codecs that generate pop-up boxes informing possible sufferers that there is need to download some specific software to run and watch video files. Apart from spreading via the Internet, spyware, viruses and other malicious programs are transmitted by modern methods of "sneakernet" like being carried on USB (universal bus) storage devices such as multimedia cards and flash disks rather than floppy disks.

Another threat spreading like this is the Downadup or Conficker computer worm that has come up recently. This virus creeps into systems and makes its own copies on other computers. This implies that if any single computer is infected within a network of computers, the infection will disseminate across the whole network.

For instance, if one school computer is infected with the Conficker virus and it does not have the appropriate antivirus, then the malware could spread across the entire network of the school, potentially corrupting other PCs.

Related Search
virus removal
Remote Virus Scan and Removal
How To Catch A Computer Virus
Facebook profiles targeted by hackers

Wednesday, March 25, 2009

Conficker Virus How It Works

Conficker, also known as Kido, is a computer worm that started in October 2008 and targets the Windows operating system.

How it works
The Conficker worm spreads itself primarily through a buffer overflow weakness in the Server Service 0n Windows computers. The worm uses a specially crafted RPC request to execute code 0n the target computer.

When runs on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center.

It receives further instructions by connecting to a server. The instructions it receives may include to propagate, gather personal information and to download and install extra malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe.

The worm seems to implement some of the ideas presented by Fucs, Paes de Barros e Pereira at the Blackhat Briefings Europe 2007, specifically: digitally signed additional payload, use of PRNG for communication and P2P communication.


Related Search
virus removal software
Computer Virus Removal
Remote Virus Scan and Removal
How To Catch A Computer Virus
Facebook profiles targeted by hackers

Tuesday, March 24, 2009

“Botnet” spyware creator gets four-year prison sentence

John Schiefer, the creator of the malicious "botnet" computer program, was sentenced by a federal court on Wednesday, for four years for infecting as many as 250,001 computers. Schiefer was computer security consultant from Los Angeles and employee of Santa Monica, California based search engine startup Mahalo.

28-years-old Schiefer was found guilty of using botnet spyware programs to infect and access thousands of computers to steal the identities of the owners of the computers. Schiefer admitted using "botnets" to turn the computers into "zombies" to thieve the identities of victims nationwide by illegally picking information from their PCs and wiretapping their communications.

Commenting on Schaefer’s conduct, the U. S. District Judge A. Howard Matz said, "This kind of conduct is actually far more devastating than assaulting a prison officer." Schiefer was arrested in 2007 under a large U. S. FBI enforcement action against botnet makers, called Operation Bot Roast 2. Schiefer was previously found guilty to hacking, fraud and wiretapping charges. Schiefer created his botnet army while he was a consultant at 3.5G Communications, a small Los Angeles telecommunications company.

The Judge said that Schiefer was employed "to protect people from this kind of conduct, yet he engaged in this kind of conduct."

According to the U. S. Attorney's Office, Schiefer applied the malware, which he called a "spybot," to wiretap electronic communications being sent online from the zombie computers to PayPal and other Web sites. Thus, Judge Matz also ordered Schiefer to pay restitution of $19,000 to PayPal and other companies Judge Matz said, "There's a pathology that society has to deal with. There are people who want to display their prowess in Internet technology -- but they screw up big time."

Mahalo top executives stated that they didn't know about Schiefer's criminal activities when they hired him. In a blog posting, Mahalo founder Jason Calacanis said that still he stands by his employee. Calacanis said, "I consider myself a fairly decent judge of character, and after spending months with John, I'm convinced he was an angry stupid kid when he launched his botnet attack (which did .0000000001% of the damage it could have). Now he's an adult who just wants to make a decent living, spend time with his significant other and breathe the clean air off the Pacific Ocean by our offices in Santa Monica. When he comes out, I hope to be able to offer him a job and that we can work together again."

Related Search
spyware removal

Friday, March 20, 2009

Online Internet Infections: 4 Simple Tips

59% of Online Businesses have been sufferers of hackers, every time you access the Internet it is almost certain that some form of intrusive software is attempting to infiltrate your computer, even your existing Operating System can cause major problems.

The following article will provide four tips which whilst is not definitive, can dramatically reduce the risk of becoming subject to such problems.

The first advice is to install virus removal Software. A virus can completely weaken your computer and potentially cause the entire loss of all information. This can be prevented by installing Anti-Virus Software which will scan your machine to detect any pre-existing viruses and also prevent any new viruses from attacking your computer. However it is crucial that the Software which you adopt is regularly kept up to date.

Viruses can also be avoided by being extra vigilant with regards to what you download and what e-mail attachments you view. It is best to assume that anything could be infected and only access it if you are certain of its authenticity.

The second tip is to install Anti-Spyware Software. Spyware is software that is placed on your computer to secretly gather information about the user. This information could be browsing patterns which is passed on to advertisers or can even log each key pressed by the user in order to obtain details such as passwords and bank details etcetera. It can slow your computer down, alter your home page and produce numerous unwanted links to websites.
This software must too be kept up to date and can be obtained free through various different websites.
The third tip is to install Firewall Software. A Firewall is a piece of Software designed to shield your computer from unauthorised access and unwanted Internet activity. This is particularly important in the business environment. Firewall should be set to work on both incoming activity and outgoing so that you can control both what leaves and enters your computer.

The final tip is with regard to the Operating System issue as mentioned in the introduction. Some Operating Systems develop problems with time which were not anticipated at the point of installation. These problems can be remedied via an update known as a patch. These can be obtained through the supplier’s website. Those users which have Windows XP can activate an internal automatic update facility which is a built in tool to keep Windows up to date.
The Software mentioned above is vital in trying to beat Internet crime as well as protecting your computer against software which can severely damage its operation.

Thursday, March 19, 2009

Top 10 worst computer viruses

Malicious software’s and computer viruses are on the raise, say security experts, as hackers, spammers and identity thieves seek new ways to steal information that can be used to empty bank accounts or spread electronic mayhem. Here, we present a look back at the 10 worst computer viruses of ever made(virus removal)

The Morris worm

In 1998 Robert Morris, a university student, unleashed a worm which affected 10 per cent of all the computers connected to the internet (at the time the net was estimated to consist of 60,001 computers), slowing them down to a halt. Morris is now an associate professor at MIT.

The Concept virus
The Concept virus, accidentally shipped on a CD-R0M supplied by Microsoft in 1995, was the first virus to infect Microsoft Word documents. Within days it became the most widespread virus the world had ever seen, taking advantage of the fact that computer users shared documents via email.

CIH
The Chernobyl virus (also known as CIH) triggers on April 27 each year, the anniversary of the Chernobyl nuclear disaster. It overwrites a chip inside PCs effectively paralysing the entire computer. Its author, Chen Ing Hau, was caught by the authorities in Taiwan.

Anna Kournikova worm
The Anna Kournikoova worm posed as a photo of the tennis player, but was in fact a virus written by Jan de Wit, an obsessed admirer from the Netherlands. He ended up receiving a community service sentence.

I LOVEYOU
The Love Bug flooded internet users with ILOVEYOU messages in May 2000, forwarding itself to everybody in the user's address book. It was designed to steal internet access passwords for its Filipino creator.

Melissa virus
The Melissa virus, written by David L Smith in homage to a Florida stripper, was the first successful email-aware virus and inserted a quote from The Simpsons in to Word documents. Smith was later sentenced to jail for causing over $80 million worth of damage.

The Blaster Worm
The Blaster worm launched a denial of service attack against Microsoft's website in 2003, and infected millions of computers around the world by exploiting a security hole in Microsoft's software. Its author has never been found.

Netsky and Sasser
Sven Jaschan, a German teenager, was found guilty of writing the Netsky and Sasser worms. Jaschan was found to be responsible for 70 per cent of all the malware seen spreading over the internet at the time, but escaped prison and was eventually hired by a security company as an "ethical hacker".

OSX/RSPlug Trojan
In November 07, the first example of financially-motivated malware for Apple Macs was discovered in the wild. The launch of the OSX/RSPlug Trojan increased fears that Apple's platform may be targeted more by hackers in the future.

Storm worm
The Storm worm, originally posing as breaking news of bad weather hitting Europe, infected computers around the world in 07. Millions of infected PCs were taken over by hackers and used to spread spam and steal identities.

Related Search
Computer Virus Removal
Remote Virus Scan and Removal
How To Catch A Computer Virus
Facebook profiles targeted by hackers

Thursday, March 12, 2009

How To Protect Your Computer From Online Attacks

Keeping your computer secure from nastier on the web is often overlooked, but taking a few simple steps can minimize the risks from viruses, Trojans, worms, spyware and all other forms of infections.

Protection is the best way to protect a computer from being attacked by malicious software, also known as malware. Users can avoid malware infecting their computers by using a firewall. But if a PC has already been infected by malware, the cause of the infection could be eliminated by using anti-virus or spyware removal software. So what is a "firewall" exactly? And what do we mean by virus removal software.

What is Firewall

A firewall will try and prevent infection in the first place, and acts as a first line of defense against the web's more unpleasant elements. It monitors inbound and outbound web traffic on a computer, searching and blocking behavior consistent with malware. Whichever operating system you use, check that your firewall is already switched on. This happens as standard with Windows Vista and later versions of Windows XP but not with Mac OS X.

Check if your machine's firewall is on by opening the control panel and selecting firewall settings. Then look at the check box to see if Microsoft's firewall is switched on or off. That said, commercial alternatives can provide a more comprehensive level of protection. There are many tried and tested third-party firewalls available. Some less-known but perfectly adequate pieces of software, are available as a free download.

Many of the free packages also have grown-up fully featured paid-for alternatives. If you decide to plump for a third party firewall, you may need to switch the Microsoft firewall off. Often MS firewall will conflict with third party firewalls.

What is ANTI-VIRUS

While a firewall is the first line of defence, it should also be used in conjunction with good anti-virus and anti-spyware software.

These pieces of software should hunt down and eliminate malicious software lurking on a machine. But make sure only one piece of anti-virus software is installed at a time.
If you purchase or download new anti-virus software, uninstall any previous protective software that may be running on your machine.

Like the firewall, running multiple anti-virus suites can cause software conflicts and create major computer performance issues.

There are also paid-for and free versions of anti-virus and anti-spyware software available.
Many of the free options have fewer and more basic features than the full price alternatives.
In addition, it is important to make sure that anti-virus software and the operating system is updated regularly.

New threats are being released onto the web all the time, so anti-virus and operating system updates are required to combat these threats.

For less experienced users, many of these updates can be performed automatically, by instructing both the operating system and anti-virus to auto-update.

Related Topic
Spyware Master Sentenced
Computer Virus Removal
How To Catch A Computer Virus

Tuesday, March 10, 2009

How To Catch A Computer Virus

There are immense amounts of viruses today all over the Internet and computer world. Computer security experts are working around the clock in order to try and stop these viruses. Virus writers on the other hand are working around the clock in order to find vulnerabilities and work their way around computer security software. The most alarming facet with regard to computer viruses is that they spread. Some spyware can really cause extreme harm to your life and your computer, while others may be more innocent and a bit easier to get rid of. It all depends 0n various things and it is extremely important to be aware of the ways that a virus can be caught. There are many ways that you can catch a virus, although some are more popular methods than others.

The most popular way of detecting a virus is from the Internet. Viruses can be anywhere on the Internet and you usually only find out where they are when it is too late. It is very common for a virus to be attached to a file on the Internet. These files are usually files that people download. They are placed there in very clever ways and when a person clicks on and downloads the particular file, your system will then become infected with a virus. It is vital for everyone to admit the factor that each time that you download and install a file; you are actually placing yourself at risk of catching a virus.

Another common way that a virus is caught in today's day and age is through Email. Viruses are placed in Emails in very clever ways and the Email receipt has completely no idea that anything is wrong until the damages have been done. Viruses usually travel through Email attachments. This is why computer security experts are continuously warning the public to be careful when they open and click on and download Email attachments. It is important to know that you need to actually open the attachment before the virus is able to infect your system. If an Email appears suspicious in any way, then it is in your best interest to not even consider opening the Email message 0r downloading the attachment.

Another popular way of catching a virus is from a computer network. The server and networks of computers are constantly sharing information. All it takes is one file for every single computer on the network to become infected by a virus. If a particular file is infected with a virus and this file is used by several other network users, they will all become infected with this particular type of virus. The virus may spread extremely fast and before you even know it, the entire network becomes infected with the virus.

It is very important to devote in good virus removal software. It is also very important to make sure that you update this software on a regular basis in order to keep yourself safe. You should also be scanning your computer on a regular basis; you can do so with antivirus software. There are always reports of new viruses so it may be in your best interest to stay abreast of the latest threats through security news sources. You also need to back up your files on a regular basis, no matter how time consuming it is, because it may be your last defense when you are faced with a serious virus infection.

Related Search
Remote Virus Scan and Removal
Free anti-spyware
Computer Virus Removal

Tuesday, March 3, 2009

Facebook profiles targeted by hackers

Facebook , the world’s largest online social networking site, has been the victim of five separate security problems over the last week, including a virus and four malicious applications.

Rascal application invites
The spiteful applications often work by posing as invites from friends asking Facebook users to sign up to an application. An example given is of an attempt to trick Facebook users by claiming that their friends were having trouble looking at their profile, and that they needed to add the application to solve the problem.

If the application is added it spams itself to every Facebook friend that a member of the site has in an attempt to steal saleable information from the profiles of those who open it up.

The BBC report gives comments from online security expert Rik Ferguson, senior security advisor at online security retailer Trend Micro. Mr Ferguson said that the way that Facebook is built can make it tricky for members to spot malicious or rogue applications, and that it was time for Facebook to review its policy of approving applications. Currently, it only vets them after they are offered to members and have been reported as causing problems.

Koobface virus
Facebook users have also been targeted in the last few days by a computer virus known as the Koobface virus, which originally hit MySpace and Facebook users in December 2008.
The latest version of the Koobface computer virus sends a Facebook message that appears to be from a friend to a Facebook user's profile. The message directs them to visit a webpage appearing to be on the YouTube website, where they are asked to download a piece of software or play a video.

The apparent YouTube web page is fake. If online users play the video or download the software, their computer becomes infected with a computer virus which searches for cookies on the victim's computer and uses the details it finds to enter other social networks the user is signed up to. The virus then searches for an infected computer user’s friends, who are then sent messages containing a link where a copy of the virus is downloaded.

Related Search
virus removal software
Computer Virus Removal
Some Basic Pc Maintenance Tips
Online Bank Accounts Under Virus Attack