Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts

Friday, November 09, 2007

Virus Alert

Some 30% of computers with a security solution installed scanned last week were infected with some kind of malware. In the case of computers without any kind of protection, the figure goes up to 44%. Source:http://www.infectedornot.com

Malware creators are trying to put a large number of threats in circulation and install them silently to prevent security companies from detecting them and generating the necessary vaccines.

Therefore, traditional security solutions must be complemented with other types of online solutions like BitDefender, which uses the ICSA Labs certified scanning engines, so you can feel secure about their virus protection.

As for the malicious code that has appeared in the past week, highlighted are the Bindo.A and Nuwar.HU worms.

Bindo.A aka autoply.exe is a worm designed to spread and infect as many computers as possible by copying itself under names like autoply.exe or MSshare.exe to the shared folders of any P2P programs that the targeted user might have installed.

It also creates a file called AUTORUN.INF in all drives it copies itself to, in order to be run every time that the drive is accessed It is very easy to detect the presence of this worm on the system, as it increases the number of shared files in the P2P shared folders on the computer.

Bindo.A also changes certain shortcuts in the desktop so that they have two execution paths: the original one and one that runs when the original program is launched.

BitDefender is a FREE online virus scanner, which takes a while to run and it is advisable to run this when you have no other programs using resources. When opened, you will have to click the ‘I Agree’ user license after which you will be taken to the Options page.

Click image for larger view.

The default setting is to scan all of your computer, which is the safest option. Under the ‘Settings’ the default option is for BitDefender to try and clean the infected files. There is a warning that if disinfection fails, the files will be deleted. You can change this option where it says ‘click here’ and a pop-up window opens (ensure you do not have pop-up blockers turned on).

Click image for larger view

Under the heading ‘Action options’ select ‘Prompt user for action’ and under ‘Second action’ again select ‘Prompt user for action’ then click OK, then click where it says ‘Click here to scan’. BitDefender will then load the anti-virus engine and virus signatures.

If it fails to update, select ‘Yes’ to continue and scanning will start.

Click image for larger view

When scanning, if an infection is found you will be prompted for an action and you will see the location of the infected file. You can select ignore, disinfect or delete. If disinfection fails however, the file will be deleted so use this with caution and ensure that it is not an important file.

Nuwar.HU is a new variant of the infamous “Storm Worm” which takes advantage of Halloween to spread. It ends processes of certain security tools that might be installed on the computer.

Nuwar.HU drops a rootkit called noskrnl.sys on the system and sets it as a service so that it is run automatically when the computer is started. Nuwar.HU spreads in email messages with subjects like “Have a Happy Halloween everyone” or “Party on this Halloween” among many others.

These messages include links to certain web pages that show a ‘dancing skeleton’ animation. If the user downloads and runs the animation offered on the website, the worms infects the computer and turns it into a zombie system at the service of a malicious user.

Rootkit detection

Methods to detect rootkits fall into two categories: Signature-based and heuristic/behavior-based detection.

There is an article about rootkits here and advice on searching your hard drive for the presence of rootkits and tools to remove them which you can get more information by clicking here.

Thursday, September 13, 2007

Skype Targeted With Worm

Skype, the VoIP (Voice over Internet Protocol) is considerably less secure than traditional telephone lines. Many people have switched to using Skype because of the savings they can make, and many have abandoned their traditional telephone lines altogether.

Skype was founded in 2002 and was bought by ebay in 2005 for US$2.5 billion. It has seen a steady rise in the number of subscribers to its service.

However, it still has many pitfalls, including the latest Worm called ‘W32/Ramex.A’.

It spreads through the peer-to-peer instant chat utility and is activated when a user clicks on a link within an instant message asking recipients to download a file.

It is very cleverly disguised within a jpeg image of soap bubbles, one of Windows default built-in wallpapers which has been embedded with a malicious executable code.

This code installs Spyware that can easily steal passwords and other personal information. It may also block users from visiting certain websites and stop programs from running or responding. It also connects to a remote server to download additional malicious code.

It is often titled ‘really funny’ or ‘look at this crazy photo sent to me’ with a clickable link. Once clicked, users who continue to download the file then have the risk of their machine becoming infected, and it then uses Skype’s application program to access files on the infected machine. The worm then attempts to replicate itself and then send out messages to recipients on the users contact list.

Ensure your anti-virus is up-to-date, windows updates are downloaded and installed, especially The Windows Malicious Software Removal Tool, which was last updated September 11th 2007. To remove the worm and its variants go to the link below and Download the file, save it to your Desktop (or location where you store downloaded files) and once the download is complete, select Run and the program will install.

You then have the option of a Quick Scan, Full Scan or Customized Scan.

Select Quick Scan and if any Malicious Software is found you will be prompted to run a Full Scan which may take several hours depending on your machines hard drive capacity but it’s worth it for the safety and security of your PC.

Download Here