Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Friday, November 09, 2007

Virus Alert

Some 30% of computers with a security solution installed scanned last week were infected with some kind of malware. In the case of computers without any kind of protection, the figure goes up to 44%. Source:http://www.infectedornot.com

Malware creators are trying to put a large number of threats in circulation and install them silently to prevent security companies from detecting them and generating the necessary vaccines.

Therefore, traditional security solutions must be complemented with other types of online solutions like BitDefender, which uses the ICSA Labs certified scanning engines, so you can feel secure about their virus protection.

As for the malicious code that has appeared in the past week, highlighted are the Bindo.A and Nuwar.HU worms.

Bindo.A aka autoply.exe is a worm designed to spread and infect as many computers as possible by copying itself under names like autoply.exe or MSshare.exe to the shared folders of any P2P programs that the targeted user might have installed.

It also creates a file called AUTORUN.INF in all drives it copies itself to, in order to be run every time that the drive is accessed It is very easy to detect the presence of this worm on the system, as it increases the number of shared files in the P2P shared folders on the computer.

Bindo.A also changes certain shortcuts in the desktop so that they have two execution paths: the original one and one that runs when the original program is launched.

BitDefender is a FREE online virus scanner, which takes a while to run and it is advisable to run this when you have no other programs using resources. When opened, you will have to click the ‘I Agree’ user license after which you will be taken to the Options page.

Click image for larger view.

The default setting is to scan all of your computer, which is the safest option. Under the ‘Settings’ the default option is for BitDefender to try and clean the infected files. There is a warning that if disinfection fails, the files will be deleted. You can change this option where it says ‘click here’ and a pop-up window opens (ensure you do not have pop-up blockers turned on).

Click image for larger view

Under the heading ‘Action options’ select ‘Prompt user for action’ and under ‘Second action’ again select ‘Prompt user for action’ then click OK, then click where it says ‘Click here to scan’. BitDefender will then load the anti-virus engine and virus signatures.

If it fails to update, select ‘Yes’ to continue and scanning will start.

Click image for larger view

When scanning, if an infection is found you will be prompted for an action and you will see the location of the infected file. You can select ignore, disinfect or delete. If disinfection fails however, the file will be deleted so use this with caution and ensure that it is not an important file.

Nuwar.HU is a new variant of the infamous “Storm Worm” which takes advantage of Halloween to spread. It ends processes of certain security tools that might be installed on the computer.

Nuwar.HU drops a rootkit called noskrnl.sys on the system and sets it as a service so that it is run automatically when the computer is started. Nuwar.HU spreads in email messages with subjects like “Have a Happy Halloween everyone” or “Party on this Halloween” among many others.

These messages include links to certain web pages that show a ‘dancing skeleton’ animation. If the user downloads and runs the animation offered on the website, the worms infects the computer and turns it into a zombie system at the service of a malicious user.

Rootkit detection

Methods to detect rootkits fall into two categories: Signature-based and heuristic/behavior-based detection.

There is an article about rootkits here and advice on searching your hard drive for the presence of rootkits and tools to remove them which you can get more information by clicking here.

Thursday, September 13, 2007

Instant Messaging - Reducing The Risks

The internet has revolutionised the way in which we communicate with email replacing snail mail and the introduction of real-time Instant Messaging (IM).

The most popular and widely used IM services are MSN Messenger, Yahoo Messenger, AOL AIM, and ICQ. Regardless of which of these you may use, they all provide an interface for one-to-one communication or group conversations.

These programs however have opened up a whole new area for spammers and hackers to target. Using IM you can obtain the latest weather reports, movie listing etc, but you are dealing with a ‘chat robot’, also known as a ‘bot’. Now the software behind this can in some instances fool you into believing that the responses are from a real person, especially the more sophisticated versions used by hackers.

These IM programs are free to use, but are also extremely vulnerable to exploitation. They allow you to transfer files quite freely, which may already be infected with a destructive virus, Trojan horses or worms, and to have unencrypted chat sessions, which to many hackers is an open door. Some IM clients also allow peer-to-peer file sharing which potentially means that other users have access to the hard discs of other users.

Protecting yourself is a simple combination of common sense, vigilance and a few essential security tools, such as a firewall and real time anti-virus program.

Because IM is real-time, malicious attacks spread very quickly and can do an enormous amount of damage in a very short period of time.

The default security settings in IM programs are very low to make it easier to use, but this also leaves you more open to attacks. There’s also a new breed of IM worms. To your friends it appears as though they’re receiving a message from you, but the truth is the message is generated by a worm, and may contain a link to a Web site that automatically downloads another bit of malicious code.

IM is a prime target for online scams, identity theft and other predatory behavior.

These tips will help to make IM more secure:

Use a strong password and change it frequently.

Regularly update your IM software, operating system and security programs.

Do NOT enter any personal information.

Do NOT open any attachments or click on any web links sent to you by an unknown person.

If you know the identity of the person who sent you a link, hover your cursor over it to check that it is a legitimate link.

Be very careful of if a person on your allowed list starts sending odd messages, best advice is to shut down your IM program immediately.

Spim is spam sent over IM containing offensive language or links to web sites which cam also trigger an avalanche of pop-up ads, Spyware and Trojans.

There are ways to limit this, but the settings that enable you to do this mean that anyone not on your ‘buddy’ list will be blocked. This is a good thing, it protects you.

MSN Messenger: Once you’re logged in, click on Tools then Options, and select Privacy. Check mark the ‘Only people on my Allow List can see my status and send me messages’ box. The Privacy tab also allows you to add or remove people on the Allow List, as well as allowing you to see which other MSN users have added you to their contact list.

Yahoo Messenger: Click the Login menu and select Preferences. Select Privacy in the left pane of the Yahoo Messenger Preferences window, and tick the ‘Ignore anyone who is not on my Friend list’. To prevent spim through Yahoo, choose the ‘Do not allow users to see me online and contact me in the ‘When people see my ID on Yahoo Web sites’ section.

AOL Instant Messenger: Click My AIM, Edit Options, Edit Preferences to open the preferences window. Select Privacy in the left pane, and then tick the ‘Allow only users on my buddy list’ option under the ‘Who Can Contact Me’.

ICQ: Click the Main button, select Security and Privacy Permissions. Click Communication Events in the left pane, and then fill in the radio buttons under either the yellow check mark icon (this will limit these actions to users on your contact list) or the red X icon (which will prevent anyone from sending you these things). Click Spam Control in the left pane, fill in all the check boxes in the right pane, and select ‘All users’ next to the item labeled ‘Do not accept Multi Recipient Messages from’.

Friday, September 07, 2007

More Email Dangers

The email Trojans are back in full swing.

Many of these will be titled ‘Office Antics’, ‘It Takes Guts to Say Jesus’, ‘Free Web Tools’ and many other eye catching subjects.

DO NOT open these emails as they contain a Trojan Downloader and if the link contained in the body is clicked a new window will open and you will be prompted to download a file.

Only trust emails from trusted sources, but also ensure that you have real-time anti-virus running. Even trusted sources can innocently pass on trojans and malicious code.

Virus Name: JS/Psyme also known as HTML/Mht@exp

Spreads through Web Browsing, Downloads Code from the internet, Exploits your system and/or Software vulnerabilities, and in extreme cases it can wipe your hard drive of all data.

Ensure your anti-virus is up-to-date. I recommend AVG Anti-Virus (freeware) which catches these Trojans and opens a ‘Threat Detected’ window.

If you are infected with this update your virus definitions file and reboot into Safe Mode, scan with anti-virus and also scan with ad-aware.

Email will read similar to this, with some variations:

Welcome Member,

We are so happy you joined ************

Member Number: 6257277682314
Your Temp. Login ID: user3795
Your Password ID: eq708

Please Change your login and change your Login Information.

Use this link to change your Login info: ******** (link removed)

Welcome,
***********
***********

These emails all follow the same format with a clickable link…….DO NOT click.

Monday, September 03, 2007

Email Danger - Free Web Tools

Hot on the heels of the ‘Postcard From A Friend’, there is a new trend starting.

Below is a copy of an email I received - several copies of it too.

DO NOT open this email as it contains a Trojan Downloader, just Delete it
Virus Name: JS/Psyme also known as HTML/Mht@exp

Spreads through Web Browsing, Downloads Code from the internet, Exploits your system and/or Software vulnerabilities.

Ensure your anti-virus is up-to-date. I recommend AVG Anti-Virus (freeware)which catches these Trojans and opens a ‘Threat Detected’ window.

If you are infected with this update your virus definitions file and reboot into Safe Mode, scan with anti-virus and also scan with ad-aware.

Email will read similar to this, with some variations:

Welcome Member,
We are so happy you joined Free Web Tools.

Member Number: 6257277682314
Your Temp. Login ID: user3795
Your Password ID: eq708

Please Change your login and change your Login Information.

Use this link to change your Login info: Free Web Tools

Welcome,
Internet Support
Free Web Tools

eCards and Postcards from Friends

From: BlueMountain.Com ufp@btconnect.com

Subject: You’ve received a postcard from a School mate!

Hi. School mate has sent you a postcard.
See your card as often as you wish during the next 15 days.

SEEING YOUR CARD

If your email software creates links to Web pages, click on your
card’s direct www address below while you are connected to the Internet:

http://**.***.***.**/?e3ca036e47840d8e117868911e6c3

Or copy and paste it into your browser’s “Location” box (where Internet
addresses go).

We hope you enjoy your awesome card.

Wishing you the best,
Webmaster,

BlueMountain.Com

At present there are millions of these being mass mailed on a daily basis, from ’schoolmates’, ‘friends’, ‘family members’, ‘your mate’ and many more.

Ensure that your Anti-Virus is up to date, and all system security patches have been downloaded.

NO Greeting Card company will ever ask you to DOWNLOAD anything, ecards are viewed online through a link in an email, but the links contained in these ‘cards’ prompt you to download.

In this particular case, if you click the link you are PROMPTED to DOWNLOAD or informed that your DOWNLOAD will start shortly.

It is important that you just delete these mails, many contain a Trojan Script…..but they will not zero your drive or boot sector as the rumours are saying.

As with all emails, if you don’t know the sender DELETE it.

How to ruin your PC

Fighting off Viruses

Thursday, June 07, 2007

Virus Protection from AVG - Tutorial included

Protecting your computer from a virus is getting harder and harder each day. While it may border on the paranoid, it goes without saying that you can’t leave your guard down for one second. Even corporate giant Microsoft has found its own systems compromised on more than one occasion.

Because new viruses erupt daily, it is important that you regularly update your antivirus software. Become familiar with the software’s real-time scan feature.

Make it a habit to always scan all new programs or files no matter from where they originate.
Perform regular backups in case your system is corrupted. It may be the only way to recover your data if infected.

I suspect a lot of people get virus infections because they download random files off the internet. Kazaa/eMule and other peer-to-peer are great places to download infected items. It is important that if you use such programs that you have one dedicated folder to download too, and before opening or running anything scan it first with an anti-virus program. I recommend that people who want to exchange files over the internet (including entire folders of files) do so using encrypted solutions (and only with friends or people they know). A great new application is GigaTribe, it encrypts all exchanges, no files size limits, and is free from any spyware/adware.
Their website is http://www.gigatribe.com

AVG Anti-Virus Free Edition is a free downloadable antivirus program that has received high marks for its reliability. In the past, free downloadable antivirus programs have been viewed skeptically because of issues relating to its reliability.

However, AVG from Grisoft, remains one of the best-known free anti-virus programs available. While AVG cannot be installed on a server operating system and there is no technical support, it still makes a good choice for many home computer users.The best part is that it is free for both Windows and Linux and it checks for updates on a regular basis.

I have been using AVG free Anti-Virus for many years and install it as first choice on other peoples machines.

Get yours here:http://free.grisoft.com/doc/avg-anti-virus-free/lng/us/tpl/v5

Save the program to a folder which is easily accessible, I created one on my desktop and renamed it Downloads, this is where I download all of my utilities etc. so I have them in one easily accessible location.

Once installed AVG loads at startup and sits in your system tray.It will carry out a complete scan on a daily basis, but you can schedule it to do this at a time convenient to you. When it has completed its scan a small window will pop up with the results.

You also have the added benefit of real-time scanning as it runs in the backgound and will warn you if something you are downloading is infected.

You can also left click any folder or an item within a folder and scan it with AVG.

Important: Do NOT use more than one Anti-Virus programas it will give you false readings.

http://free.grisoft.com/doc/avg-anti-virus-free/lng/us/tpl/v5

Windows Media Player Tutorial - Click Here