And the Oscar goes to . . . Not these guys!
Comments OffSans Internet Storm is reporting on Anti-virus Scareware tactic. I’ll quote from them:
ISC reader Gary wrote in to let us know that searching for “oscar presenters” and “oscar winners” with Google brings up a prominently ranked result on a web server in Poland, on a subdomain of “beepl”, which – surprise, surprise – includes a malicious JavaScript. The end result currently seems to reside on stabilitytraceweb com, and is yet another incarnation of the “Fake Anti-Virus Program” malware that we have covered repeatedly. Watch out, the EXE has a meager 6/39 on Virustotal.
[Via Sans]
I did my own research and it is true they are at least 3 sites with the .pl Domain that are used to send you to these fake sites. You should consider checking your system for possible viruses if you been to these sites and are worried. You should also report any site like this to Phishtank to fight this type of scare tactics. Please remember if you are worried about your system this is the best time to install software to prevent these types of scare tactics. Remember you don’t always have to buy software to be safe. There are free anti-virus and Firewall solutions at your fingertips, use them well. It is also a good idea to make sure you have the latest updates from Microsoft while your at it.
You won’t make money from W32:Sality.ao
Comments OffPeople should be cautious of the making money because there is a variant out there trying to leverage the users into thinking they can make money.
McAfee Says “W32/Sality.ao is a parasitic virus that infects Win32 PE executable files. It infects files (*.exe and *.scr files) on the local, network and removable drives by overwriting code in the entry point of the original file and saving the overwritten code in its virus body. It then appends the virus body to the host file.”
Aliases for this Virus is:
- PE_SALITY.JER (Trend Micro)
- Virus.Win32.Sality.aa (Kaspersky)
- Virus.Win32.Sality.y (Ikarus)
- Virus:Win32/Sality.AM (Microsoft)
- W32.Sality.AE (Symantec)
- W32/Sality-AM (Sophos)
- W32/Sality.AE (Norman)
- W32/Sality.AH (Panda)
- W32/Sality.AK (F-Prot)
- Win32.KUKU.a (Rising)
- Win32.Sality.OG (BitDefender)
- Win32/Sality.AA (VET)
These links should help people understand it it. You can visit my Malware Resources to help remove this virus. Something to consider before removing this is to disable your restore points.
Remember there’s no easy to make money, the only real way is to work hard. According to my research the Anti-virus companies have ways to remove this virus and as long as you update your database.
PolyMorphic Win32:Vitro Most Viraulent Virus
This seems to be an virus that is getting some people hit hard. I wanted to blog about this because of the nature of Virus and Trojans. I have read reports that this might be from Online Movies, and I have to say this is one reason why you must stay away from certain online movies. I am going to take a guess that this virus requires a special CODEC, and you downloaded it and installed it. It Could also be the update the Adobe Flash player idea to but still results in getting the Virus.
As I said before you take a risk when you go to sites you don’t trust or know anything about. You also should know that if you need a “SPECIAL” codec, you should just go on to another site. These sites that claim they need this special codec means only one thing they want to install something without your Knowledge.
So what is this Virus:
The Virut family of viruses uses polymorphism to hide from all anti-virus protection, it infects executable files. File infection makes it very hard to repair a system that has been infected. W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.
Tech Journalist breaks the silence — Journalist got Pwned!!
Comments OffIt was another ordinary day for this tech journalist. He had just waken up from his lovely dreams and hadn’t realized that he was being baited with Phish. Yes that is correct he actually gave out his password to an Phish site and didn’t know it.
I have to admit that he didn’t hide it, in fact he decided to post about how he got Pwned and what happened.
[Click Picture to see the full story]
Internet Security Companies Warn about Patch Tuesday and Valentines Day.
Comments OffWith Tomorrow being released some very highly rated Remote Code Execution to become Zero day in very short time. Some researchers are speculating about more viruses will be released in conjunction to Valentines day. According to this one post it will be likely to be E-cards being sent to try to lure you into downloading Malware.
Various security vendors, including CA Inc, MX Logic Inc., Trend Micro Inc., and Panda Security, have issued alerts about new Valentine’s Day-themed spam campaigns that try to dupe users into installing the Waledec bot.Researchers note that many websites which are affiliated to Waledac e-card scam have been recently updated with content based on the Valentine’s Day theme.
Web sites distribute Trojan files which are commonly named love.exe; onlyyou.exe; you.exe; youandme.exe; and meandyou.exe and the list is not exhaustive.
[Via Express Buzz]
Scams about Stimulus Checks
Comments OffIt’s that time of year where people are hearing about the Stimulus Checks and some Phishing people are still trying to get people’s information for your bank account and steal your identity. One such one is sending out email for the 2008 Stimulus Program this email account looks to be “stumulusref@i-r-s.com”. As you can see this is a .com email address and not a .gov address.
What is a Virus and Why do I have one
After seeing more and more the updates coming from the net. I wanted to talk about what a Computer Virus or Trojan is and how you get it. So how did you could of gotten a Virus in the first place. So here are some information to consider:
The vulnerability of operating systems to viruses
So what does that mean to you? Most of the times when you get a virus you have a vulnerability in some place in your Operating system and it is either something that has not be known by Microsoft, Apple, and Linux or is know as a Zero-day Exploit.
A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit unknown, undisclosed or patchfree computer application vulnerabilities. The term Zero Day is also used to describe unknown or Zero day viruses.
[Via Wikipedia]
This is one of the most used because if it is an unknown exploit by the Operating System creators then they have a longer to us the exploit. Most of the time hackers like to use this because that means there is a possibility of finding even more vectors to infect other systems. You see if they can get on one system they can then find ways to get on other systems.
Are you patched, Secunia Says NO
Comments Off
Think you’ve got nothing to worry about, according to Secunia 98% of computers are not fully patched and are vulnerable to some kinda of attack.
If you have a system that is off of the Net you could use the Clone of Autopatcher Program to do it for you. You also need to update all your secondary programs such as Audacity, Open Office, and other programs that you use weekly.
Apple’s Immunity, Botnet sanctuary.
Comments OffBut is Apple projecting a false sense of security just to save face? Many experts repeatedly warn that all operating systems are susceptible to viruses, and as the Mac becomes more popular OS X will inevitably become a bigger target for malicious attacks.
[via Pcworld]
Having said that I feel the notion that Apple is trying to keep there reputation as a virus free system. I can only hope that they stay that way. Which as much as I know, Apple will most like start to be the main source for botnets, because of the lack of security.
Spying on Spyware.ISpynow!!
Comments OffSpyware.ISpyNow monitors files, network traffic, and keystrokes. This Spyware gives the person who installed it a Web-based interface with summaries of logged information on the host computer.
[Via Symantec]
- Avg detected Trojan Horse Generic 12.htc? – This has a great article on how to use HiJackthis program and how to make sure you no longer have the virus.
- Some Important programs to prevent yourself from having viruses and Malware!! — This article gives you some other programs to use other than Symantec. You have a wide variety of choices on Anti-virus programs and Firewall Choices. You also have some choices on Spyware removal programs.
Not so, Antivirus2008
Comments OffOK, so let’s say the user (by some stroke of luckless chance, or courtesy of a trojan downloader) ends up with the demo installer of Rogue:W32/VirusRemover2008.C on their hands and it runs
[via F-Secure]
According to them, they have many different version of this rogue antispyware. They have de, dk, es, fr, it, no, nl, and no, which are all attempting for you to buy this no so Virusremover2008 software. They talk about how it tells you have a 9 infected viruses and that you need to remove them, but in truth, they use a text file to create this lie. Check out all the details for further information.
Microsoft kills a fake antivirus tool from 994,061 computers!
Comments Off
According to Arstechnica and I’ll quote:Win32/FakeSecSen has gone by various names, including Micro Antivirus 2009, MS Antivirus, Spyware Preventer, Vista Antivirus 2008, Advanced Antivirus, System Antivirus 2008, Ultimate Antivirus 2008, Windows Antivirus, XPert Antivirus, Power Antivirus, and Ultra Antivirus 2009. Furthermore, it is skinnable, so each of these variants has a different GUI, although the basic functionality is the same: bother users with warnings of malware until they pay up.The Microsoft Malware Protection Center recently released some data on how the removal tool performed this month: FakeSecSen was removed from 994,061 machines. That number isn’t the highest Microsoft has recorded before, and the number of removals depends on which malware Microsoft adds each month and how widespread it is.
[via Arstechnica]
This seemed to of happened this month with the usual Windows update. If you haven’t updated your system just yet you should. This troublesome fake virus seems to have been killed from several systems. This could effectively make it harder for these guys who ever designed this program to make money. I hope microsoft does even more virus removals in next month. If you still want to try to get rid of these viruses don’t forget to check out my tips on Virus removal.
You have an undelivered UPS/FEDEX Package. (Virus)
Comments OffFrom what I’ve seen so far. There seems to be a new rash of email going around with the heading that makes it look and feel like either UPS or Fedex. Saying that you have an undelivered package from them and to either print the order confirmation or to click a link. I will say this once, if you get this delete it. Fedex and UPS will never hide the link and tell you have an package waiting in the email. They will leave a note your door. You must ask yourself how Fedex/UPS found out your email address to tell you have a package waiting? They don’t and they won’t, just a fact.
TROJ_DLOADR.GG and TSPY_ZBOT.NM Trojan, which will Monitor and try to steal your data. The other one is a ZBot and will try to steal you data also. If you need help removing this virus, I’d suggest checking out my other virus article Avg detected Trojan Horse Generic 12.htc?. There are a lot of ways to remove this virus but the first step is never click on any links in your emails. I also wrote about Some Important programs to prevent yourself from having viruses and Malware!! This will help prevent and fix the common virus problems you might have.
Sites that you need not Visit:
Comments Off- hxxp://movieportal2008q.com/freemovie/Movie/xxxx/x/ — this site usually tries to send you the “Trojan.HTML.Zlob.AG” Virus.
- hxxp://porntubedot.com/xxxxxxxx/WatchFreeMovie.php –This site usually tries to send you the “Trojan.Dropper.SMN” Virus.
- hxxp://handballfondi.it/xxxxxx1.php — This site is one of the new Malware sites that looks like Youtube, When you go to this site they say you need a special to play a video clip. Most of the time when you get something like this, it is going to try to install Malware. A good broad set of Codecs that you may want to download is called Klite Mega Codec, which if you us that you should never need to download any other codec to play a movie clip from any site online.
What’s with Google trends?
Comments OffHaving been going to the Google Trends and keeping watching. I am starting to wonder something? Take a look at this and you tell me?
Very Simple, they’d watch what is trending and post accordingly. Now you as a reader would click on the website expecting to see what you want to see but instead it would popup with advertisements and maybe malware? Check these links to better understand it:
- Skype isn’t always safe!
- Some Important programs to prevent yourself from having viruses and Malware!!
Now even though these are just a few. You can see how someone might want to abuse it and get there site up on Google trends and be able to infect several to even millions of computers before Google sees that or stops. You could in theory take over a website high in Google rankings and do exactly that.
Fixing the Adobe Problem!!
Comments OffIf your have been having problems with Flash Players stoping after 2 seconds of playing. I have a few ideas to try to get rid of the problem. It used to happen all the time with Vista in the early days. Here’s what I did to occasionally get the flash player to work:
-
Cleaning out the Prefetch Directory! — Having seen this from time to time. If you have programs startup that might need to be refreshed this will refresh them so that they run like new. You occasionally can get programs that will load in a odd way and this will fix that also.
-
You want to be more anonymous? — Cleaning out your cache on your browser can sometimes fix the problem. It’s like anything else it can sometimes be corrupted.
-
Some Important programs to prevent yourself from having viruses and Malware!! — Having seen this with my own two eyes, if you have a viruses or malware on your system that too can cause problems with playback of flash media. So just double check making sure you don’t have any viruses.












