This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Friday, May 22, 2009

How Profits Motivates Virus Creators

The motivation behind hackers has evolved noticeably over the last couple of years. Developing harmful viruses is less about “bragging rights” or satisfying the creator’s ego and is becoming more and more about generating profit or commercial return.

The destruction of data on your computer or corruption of programs you use is a common side effect and what people have traditionally associated with a computer virus. The reformatting of your computer “c: drive”, especially at work, and the loss of valuable data used to be an incredibly painful experience.

The widespread deployment of data back up solutions within companies to comply with legislation and other factors means less and less valuable data is now stored on your computer’s local hard drive. More importantly for the virus writer this attack does not generate much tangible profit so there is not much motivation to develop more sophisticated programs to counter improved anti virus applications and corporate network security.

However, there is profit for the virus writer in turning your computer into a spam distribution machine. “Spam” is email sent without the permission of the person receiving the message. Hackers gain control of your computer through a Trojan Horse which gives them the same access rights as the user. Once your computer is controlled by the hacker it becomes known as a “Zombie.” A group of zombie machines is known as a “botnet.”

By controlling a botnet a hacker can generate profit in a number of ways. The botnet can be used to exhort a ransom from a company by threatening launch a damaging “Distributed Denial of Service” (DDoS) attack against its web site. The botnet can also be hired out to other hackers.

The most common way of profiting from a botnet is to use it to send out spam email. According to the security software company Sophos over 50% of all spam email now originates from botnets. Hackers use spam email to drive traffic to pay per click advertising sites or distribute virus programs further. Using a zombie computer helps cover their tracks.

The drive for generating profit is clearly evident in a new form of virus dubbed “Ransomware” by security experts which started to appear in 2005. Ransomware, as the name suggests, holds data on your computer “hostage.” Files on your hard drive are encrypted with a password. The user is then contacted and asked to pay a ransom to release the file.

Here are some simple tips and strategies to help prevent your computer turning into a “Zombie.”

• Keep your computer up to date with the latest software patches for Windows and other Microsoft programs. Most viruses and other malware exploit vulnerabilities in widely used programs.
• Install a reputable anti virus program. Keep the definitions up to date and scan your computer regularly.
• Install a personal firewall or buy a router with a hardware firewall. Ideally you need a firewall solution which filters both incoming and outgoing traffic from your computer to the internet.
• Never open spam email or associated email attachments which is frequently used to distribute virus programs. Use a spam filter to help reduce the amount of spam you receive.

Sunday, April 19, 2009

Top 10 Virus on January 2009

Here are the top 10 Virus/Trojan on January 2008

1. Windx-Maxtrox

Display your desktop wallpaper after modified by the virus Windx-Maxtrox.Virus created with Visual Basic has a body the size of the original around 77Kb, without in-pack. The virus is suspected to originate from the strong North Sulawesi has an executable file infection capabilities. Precisely, it will infected program in the Program Files directory. Technical infection canny enough to avoid implementing it detection heuristic antivirus engine. Characteristics that can be recognized on the infected computer is changing the image of the desktop wallpaper images into animation.

2. Autoit variants

Most variants use Autoit folder icon in the typical virus impersonation.Ciri this one is made using a scripting automation. That if the compile into a executable file, which is also in-pack using UPX. And nearly 90% of all viruses and their variants autoit that we have, using similar folder icon in impersonation. This virus will also create an autorun.inf file at the time of the disk drive or flash drive.

3. Malingsi

The virus attacks the other virus Malingsi fat.Virus well with the size of 705,312 bytes is created using Visual Basic in the pack-use PECompact. It seems this virus is intended to attack another virus, this is seen from the message in the body. This virus breed and spread using intermediaries Personalization, which acts as a bot.

4. Recycler variants

File viruses hiding behind the false Recycle .Whom become typical of this virus is a technique, how it spread. Of all the variants that we have, how that is done the same, namely masquerade as Recycle Bin. For example the virus attacks the flash disk. In the flash disk of the victim will be the folder with the name of Recycler in which there is a folder using the name of alpha numeric example “S-1-5-21-1482476501-1644491937-682003330-1013″ with the icon is similar to the Recycle Bin icon. If this folder, click on or accessed from the Explorer, the file the virus will not be visible. To view them, you can go to command prompt with the command “dir / a”.

5. Fdshield

The name used by Fdshield time spread.Virus made using Delphi language using this icon that resembles the Internet Explorer. Has a file size of 553,472 bytes, without in-pack. One thing the light of this virus is of the name used when spread, labeled “17 + + & Confidential Sexs Women artists Indonesia (foto2_kamera tersembunyi_liputan). Exe”. For users who do not careful - careful, will take the file is an HTML file. If you see in the directory C: \ Windows \ System32, the mother found a file with the name “rundl32.exe”. Do not be deceived again! That is not part of the Windows files, but it really is a file virus. Note the letter “L” is just one. And now see in the Schedule Task, have a new job with the name “Windows FD Shield” which will execute the virus file at the time that he has set.

6. Purwo variant

Message delivered creator.One more new variants, Purwo.C, still created using Visual Basic, with the body size of about 56KB, without the pure-pack. This virus uses Word document icon similar property MsOffice to deceive potential victims. When he infected create a folder with the name “Purwokerto Under Cover” of the hidden attributes, and contain a file called “KoruptorPurwokerto.exe” on each drive that he find. In the folder C: \ Windows \ System32 \ file system also have windowss.exe, and in the C: \ Windows \ javaa \ service.exe. At the time it will show a black screen that contains the text of the message from the author. And be careful, this virus will also remove some of the files belong to you that he met.

7.Formalin

File properties Formalin.Icon virus that is used by this virus resembles the withdrawal folder, and it is created using Visual Basic. On Formalin.D, the file size of 18,432 bytes, with the condition of the pack using UPX. The virus creates a folder “disguise” with names such as seepage problems UAN and UAS, My Completed Downloads, Picture Wallpaper, Crack Program, don’t opened !,Ensurt Data (dont’ removed), and others. At the infected computer, Internet Explorer in the caption will be changed to “Your computer has been infected Formalin virus.” He also tries to disable “safe-mode” with how to remove some registry related. And in the file properties of the virus, the property description in the version information will have any posts such as “Kasian dch loe”.

8. Raider.vbs variant

Raider habits virus body has up-to-encryption.Virus if this type of VBScript, its file opened with Notepad, not a lot of strings that can be read as in most encryption. This has become a habit in every variant. Typically, the Registry, it will provide a key to making the new HKLM \ Software with the same name as the name on the computer name, with its contents as a string value is the name of the virus, Raider, and the date the first time the computer is infected.

9. Autorunme variant

Virus Autorunme hide the Recycle Bin folder that is not a production dibuatnya.Virus local programmers use this pack PECompact. He does not have the icon, only the icon from the standard Windows applications. infected time, he tried to embed the file on the parent directory C: \ Windows \ System with the name and msvc32s.exe with hidden and system attributes, and create new autorun in registry with the name “Windows msvc Control Centers.” The virus can spread through the data storage media such as flash disks can also be spread through Instant Messaging application. In the flash disk, it will make the Recycle Bin folder imitation that contains files with the name autorunme.exe, and direct autorun.inf file to run the virus. So when a user plug and play their flash disk drive and access is, the virus will be active.

10. Rieysha variant

Sma-Virus Found Rieysha variants of Rieysha again, this time with the name Rieysha-high school. Like previous variants, it is still possible to use Visual Basic. This time around the size of 104KB, with the icon that resembles a file Real Media Player. Menginfeksi time, it will create a duplicate file exe, mp3, doc, and replaced with a 3gp himself. In addition, there are at least 2 pieces of virus files on the root drive, with the name “sma3gp.exe” and “CeritaSeru.vbs”.

Source: bibeh.com

Monday, March 23, 2009

Background of Password cracking

Passwords to access computer systems are usually stored, in some form, in a database in order for the system to perform password verification. To enhance the privacy of passwords, the stored password verification data is generally produced by applying a one-way function to the password, possibly in combination with other available data. For simplicity of this discussion, when the one-way function does not incorporate a secret key, other than the password, we refer to the one way function employed as a hash and its output as a hashed password. Even though functions that create hashed passwords may be cryptographically secure, possession of a hashed password provides a quick way to verify guesses for the password by applying the function to each guess, and comparing the result to the verification data. The most commonly used hash functions can be computed rapidly and the attacker can do this repeatedly with different guesses until a valid match is found, meaning the plaintext password has been recovered.

The term password cracking is typically limited to recovery of one or more plaintext passwords from hashed passwords. Password cracking requires that an attacker can gain access to a hashed password, either by reading the password verification database or intercepting a hashed password sent over an open network, or has some other way to rapidly and without limit test if a guessed password is correct. Without the hashed password, the attacker can still attempt access to the computer system in question with guessed passwords. However well designed systems limit the number of failed access attempts and can alert administrators to trace the source of the attack if that quota is exceeded. With the hashed password, the attacker can work undetected, and if the attacker has obtained several hashed passwords, the chances for cracking at least one is quite high. There are also many other ways of obtaining passwords illicitly, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, timing attack, etc.. However, cracking usually designates a guessing attack.

Cracking may be combined with other techniques. For example, use of a hash-based challenge-response authentication method for password verification may provide a hashed password to an eavesdropper, who can then crack the password. A number of stronger cryptographic protocols exist that do not expose hashed-passwords during verification over a network, either by protecting them in transmission using a high-grade key, or by using a zero-knowledge password proof.

Sunday, March 22, 2009

How to Protect Your Files From a Computer Virus

How safe is your computer? Could you be in danger of getting a virus on your system? Just how real is the danger? What steps should you take if any?

While visiting with a one of my students, I became aware that her anti-virus software was over seventeen months old and had never been updated. Upon informing her that she should update her anti-virus software regularly, she was totally surprised. Furthermore she had no concept how essential this was to ensure her system's safety. Therefore I thought it wise to write about some of the precautions you should take to avoid becoming infected with a computer virus.

While there are many 'virus' hoaxes, and please do not pass any of these hoaxes on as these may actually contain viruses, computer viruses do pose a very real danger. Therefore I've listed a few preventative measures that you should take to ensure computer safety.

1. Do install an anti-virus software program and update it often as there are new viruses discovered everyday. I update my anti-virus database daily. At least weekly should be a goal. If you are not updating perpetually, it is like having an insurance policy and never paying the premiums. In no time at all it would be worthless.

2. Be wary of email from strangers. Never open an email with an attachment from a source that is unknown or suspicious. Virus containing emails can be very persuasive in the subject line. Do not let your curiosity be aroused.

I prefer an anti-virus program that has the ability to check all email sent and received. If you update it often, this should keep you safe, although nothing is 100% secure. There are good programs that offer a free version for personal use. These programs generally allow continual updates. Some may require that you register again at the end of year, but the software and updates will still be free.

Two such programs are:

AVG anti-virus, Free edition
http://grisoft.com

Free avast! 4 Home Edition
http://www.avast.com/eng/avast_4_home.html

Free Firewall & Antivirus
www.personalfirewall.comodo.com
For more options and reviews on programs you can do a search on google for free anti-virus.

3. Do exercise caution when downloading files from the Internet. Be sure to download from well known and reputable sources. Ascertain that your anti-virus software is set to scan files while you are downloading. I have that feature enabled in my anti-virus program and it scans all files when I am in the process of downloading, and it has on occasion prevented me from downloading a file that was infected or posed a potential danger. These programs work so take advantage of the security your anti-virus will provide by using all of the safety features.

4. New viruses creep upon a daily basis. It is important to back up your important files regularly. CD’s and DVD’s hold a large amount of information. Take advantage of this and store your valuable information and computer programs on these removable disks. In the event that a virus should ever invade your system and your files become corrupted you will be able to replace them with your backup copies.

5. Lastly apply the little rule, 'When in doubt do without'. If you are uncertain, whether it is with an unknown source in your email or a web site that offers a download, then best not to take a chance. No email message or free software is worth the damage to your computer files and the time and expense of repairing your PC. Do not be fooled, computer viruses do affect everyone.

The Internet offers us an array of software, services, entertainment and education that is beneficial. There is no reason to fear the web, it can be safe and secure. Yet it would be unrealistic to assume that there is no danger of computer viruses. There are unscrupulous persons who desire to do you harm. By observing these few guidelines you can minimize any threat of a virus attacking your computer.

14 Household Ways To Protect Your Computer From Viruses

Computer viruses are deadly. They often spread without any apparent contact and can be a nuisance, or even worse, fatal to your computer. Individuals who create these viruses, estimated at 10-15 new ones a day, are the electronic version of terrorists. Their goal is to inflict havoc and destruction on as many people as possible by disabling, stealing, damaging, or destroying computer and information resources. Often, they have no specific target in mind, so no one is safe. If you access the internet, share files or your computer with others, or load anything from diskettes, CDs, or DVDs onto your computer, you are vulnerable to viruses.

Fortunately, there are good guys working just as hard as the hackers to develop cures for viruses as quickly as they send them off into cyberspace. And there are many things you can do to keep your computer from catching viruses in the first place.

Defining Viruses:

A virus is a small computer program that can copy and spread itself from one computer to another, with or without the help of the user. However, viruses typically do more than just be fruitful and multiply, which is bad enough in itself because it hogs system resources. Anything else viruses are programmed to do, from displaying annoying messages to destroying files, is called their payload. Often, they cannot deliver their payload until an unsuspecting user does something to make the virus execute its programmed function. This could be as simple as clicking on an innocent looking file attachment with the .exe (executable) extension.

Catching a Virus:

Most viruses are spread through e-mail attachments because it's the easiest way to do it. Although Macintosh, Unix, and Linux systems can catch viruses, hackers are particularly keen on exploiting the security weaknesses in anything Microsoft, particularly Microsoft Outlook and Outlook Express. Because of the popularity of this software, hackers get maximum bang for their buck, and they probably get some satisfaction from continually reminding Microsoft that being big doesn't mean you're perfect.

Solution 1: Anti-virus Software

Your first line of defense is to install anti-virus software. To be extra safe, also install firewall software, which is now included in some anti-virus packages. This software can scan all of your drives for viruses and neutralize them. Here are some features to consider when evaluating anti-virus software.

- Compatibility with your operating system - Make sure the software works with your system, particularly if you are using an older operating system like Windows 98.

- Firewall software - If it's not included, find out if it's available. If you must, buy it from another vendor.

- Automatic background protection - This means your software will constantly scan behind the scenes for infections and neutralize them as they appear. This provides some peace of mind.

- Automatic, frequent updates - Because new viruses appear every day, you'll want regular updates. It's even better if they occur automatically when you connect to the internet. If automatic updating isn't included, you'll have to check the vendor's website and download updates yourself. This is vitally important, because you will not be protected from new viruses if your software is out of date.

- Disaster recovery - Software with a recovery utility to help you get your system back to normal after a virus attack is always good to have.

- ICSA certification - The International Computer Security Associatioin has standards for the detection rates of anti-virus software. Make sure your software has the ICSA certification.

- Technical support - It's a good idea to select a package that offers free technical support, either online or through a toll-free number. If you're ever felled by a virus, you may need it. Some anti-virus software vendors are Symantec Corporation (Norton AntiVirus), McAfee Corporation (McAfee VirusScan), Trend Micro Inc. (PC-cillin), and Zone Labs Inc. (Zone Alarm Suite).

Solution 2: The Virus Scan

If you receive a particularly juicy attachment that you're dying to open, save it on your Windows desktop and run your anti-virus software on it first. To do this, click once gently on the file on your desktop ... don't actually open it ... then right click and choose Scan with (Name of Anti-Virus Software) to activate a virus scan.

If it's infected, your anti-virus software may neutralize it, or at least tell you the attachment is too dangerous to open. On the other hand, don't feel guilty if the very thought of saving a potentially damaging file anywhere on your system is enough to quell your eagerness to open it and make you delete it immediately.

Solution 3: Delete first, ask questions later.

When in doubt about the origin of an e-mail, the best thing to do is delete it without previewing or opening it. However, some viruses, such as Klez, propagate by fishing in people's address books and sending themselves from any contact they find to another random contact. You can spread a virus just by having people in your address book, even if you don't actually e-mail them anything. They'll receive it from someone else in your address book, which really makes life confusing. Because of the proliferation of porn on the internet, e-mail viruses often tempt victims by using sexual filenames, such as nudes.exe. Don't fall for it.

Solution 4: Beware of virus hoaxes

E-mails warning you about viruses are almost always hoaxes. You may be tempted to believe them because you typically receive them from well-meaning friends, who received them from friends, etc. These e-mails themselves usually aren't viruses, but some have actually fallen into the hands of hackers who loaded them with viruses and forwarded them merrily on their way as a sick joke.

The proliferation of e-mails about virus hoaxes can become nearly as bad as a real virus. Think about it, if you obey an e-mail that tells you to forward it to everyone in your address book, and they THEY do it, and this goes on long enough, you could bring the internet to its knees. If you ever want to verify a virus warning, your anti-virus vendor may have a list of hoaxes on it website. It's in the business of providing the fixes, so it will know which viruses are real.

Solution 5: Beware of filename extensions

The extension of a filename is the three characters that come after the dot. Windows now defaults to hiding filename extensions, but it isn't a good idea. Just being able to see a suspicious extension and deleting the file before opening it can save you from a virus infection.

To see filename extensions in all your directory listings, on the Windows XP desktop, click Start button | Control Panels | Folder Options | View Tab. Clear the check box for Hide extensions of known file types. Click Apply | OK. System files will still be hidden, but you'll be able to see extensions for all the files you need to be concerned with. Viruses often live on files with these extensions - .vbs, .shs, .pif, .Ink - and they are almost never legitimately used for attachments.

Solution 6: Disable the .shs extension

One dangerous extension you can easily disable is .shs. Windows won't recognize it and will alert you before attempting to open an .shs file. The extension is usually just used for "scrap object" files created in Word and Excell when you highlight text and drag it to the desktop for pasting into other documents. If this isn't something you ever do, or you have Word and Excell 2000 or later, which allow you to have 12 items on the Clipboard, click the Start button | Control Panel | Folder Options | File Types tab. Under Registered file types, scroll down and highlight the SHS extension. Click Delete | Yes | Apply | OK.

Solution 7: Dealing with double extensions

When you turn on your extensions in Windows, you'll be able to detect viruses that piggy-back themselves onto innocent looking files with a double extension, such as happybirthday.doc.exe. NEVER trust a file with a double extension - it goes against Nature.

Solution 8: Beware of unknown .exe files

A virus is a program that must be executed to do its dirty work, so it may have an .exe extension. Unfortunately, this is the same extension used by legitimate program files. So, don't panic if you find files named Word.exe or Excel.exe on your system - they're your Microsoft software. Just don't EVER open any file with an .exe extension if you don't know what the file's purpose is.

Solution 9: Watch out for icons

Viruses in attachment files have been known to assume the shape of familiar looking icons of text or picture files, like the wolf in the hen house. If you recieve an unexpected attachment, don't open it without first running it through your anti-virus software.

Solution 10: Don't download from public newgroups

What better place for a hacker to lurk and stick his virus than in the middle of a crowd? Sooner or later, someone's bound to download it and get the virus going. Don't download files and programs from newsgroups or bulletin boards, or open attachments sent from strangers in chatrooms ("Let's exchange pictures!") without first scanning with your anti-virus software.

Solution 11: Avoid bootleg software

This may seem like a no brainer, but sometimes that tiny price tag on a popular but expensive package can be too good to resist. Resist it! Likewise, be careful about accepting application software from others. You don't know where it's been, and what may have started out as a perfectly clean package could have become infected during installation on someone else's infected computer.

Solution 12: Protect macros in MS Word, Excel, and Powerpoint

A common type of virus uses macros. Macros are sets of stored commands that users can save as shortcuts to perform long functions in just a few keystrokes. A macro virus may perform such mischief as changing file types from text files or spreadsheets into templates, locking up keyboards, and deleting files. Word, Excel, and PowerPoint come with macro virus protection. To make sure yours is activated, open each application, then click Tools menu | Macro | Security. On the Security Level tab, make sure Medium or High is selected. Clcik OK. If you are already infected with a macro virus, you may find that the steps of this procedure are unavailable becasue the virus has disabled them. In that event, run a virus scan on your system to see if your anti-virus software can kill the virus.

Solution 13: Use passwords

If you share your computer, it's a good idea to assign everyone a password. Passwords should be a combination of letters and numbers no less than eight characters long, and preferably nonsensical. Never write passwords and stick them anywhere near the computer. To assign passwords in Windows XP, click the Start button | Control Panel | User Accounts. Follow the prompts to assign/change passwords.

Solution 14: Update application software

Microsoft constantly issues patches for the security holes in its operating system and applications software. however, don't be lulled into complacency if you have Windows Update automatically checking things for you. Update checks for patches to repair bugs in the operating system, not for security problems.

To get the latest security hotfixes (as Microsoft calls them), visit www.microsoft.com and look for hotfixes for all your Microsoft software, particularly Outlook and Outlook Express.

Microsoft also has a free downloadable package called Microsoft Baseline Security Analyzer (MBSA) that scans your system for missing hotfixes. It works with Windows 2000 and XP Home and Professional only. It doesn't support Windows 95, 98, or ME.

To download the MBSA, go to the TechNet section of the Microsoft Website. Be warned that the information is written in techie language, so you may find it daunting.

Last Words:

Now that you know some ways for avoiding and dealing with viruses, let's wrap things up with some solution you've probably heard before but have ignored.

- Back up your files regularly - If a virus crashes your sytem, you'll feel much better if you've got backup copies of all your important files. Make the backup copies on a media that's separate from the computer, such as on diskettes, CDs, or zip disks. Scan them for viruses before you put them away to make sure they aren't infected. If they are, they'll do you no good if you ever have to use them because they will just transmit the virus right back onto your computer.

- Make a boot disk - Create an emergency boot diskette before you have a problem so you can start your computer after a serious security problem To make a boot diskette with Windows XP, put a blank floppy disk in the drive. Open My Computer, then right click the floppy drive. Click Format. Under Format options, click Create an MS-DOS startup disk. Click Start. Keep the disk in a safe place. With luck, you'll never need to use it.

- Turn off you computer - DSL and cable connections that are "always on" may be convenient, but you should always turn off your computer when its not in use. Hackers can't get to a machine that's powered off.



You are free to reprint this article in its entirety as long as the clickable URLs remain in the "Resource Box" section.

Thursday, March 5, 2009

Protecting your personal information

Avoiding the phishers


"The vandals are becoming fraudsters and electronic pickpockets."
Identity thieves are using more sophisticated methods to get consumers to divulge their personal and confidential information.

Bill Rosenkrantz, group product manager for internet security firm Symantec, says that in the last seven years, the internet has gone from an information source to an ATM: "Thirty-five to 40 per cent in the U.S. use the internet for financial transactions."

"Historically, hackers and virus writers would attack systems for ego's sake. But now it's financial," according to Rosenkrantz. "The vandals are becoming fraudsters and electronic pickpockets."

How to avoid getting "phished" in

  • Don't respond to e-mails requesting your personal information.

  • Don't click on links inside e-mails-

  • If you're uncertain about a website address that appears in an e-mail, go to your browser and enter the legitimate address manually.

  • Protect your computer -Use updated anti-virus software,.


  • Report suspicious e-mails

  • Notify the legitimate company if you receive any e-mails that you think might be fraudulent.

    More information at http://www.cbc.ca