Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Thursday, July 2, 2009

Michael Jackson spam virus in concerts a round a world



Michael Jackson spam virus screenshot. Credit: UAB.

A Cyber criminals who are exploiting public interest in his death with spam messages that infect computers with a virus able to steal bank account numbers and passwords, according to Gary Warner, University of Alabama at Birmingham (UAB) director of research in computer forensics. Warner and the other researchers at the UAB Spam Data Mine began tracking the celebrity-focused spam early on Tuesday, June 30.

This virus been tracking the cyber criminals behind this spam and the associated virus for many weeks, but it is just today that they have shifted their strategy by embedding their virus into an e-mail that claims to link you to a Web site that will reveal Michael Jackson’s killer.

The spam related to this virus has taken many forms, including e-cards, shipment tracking links and, most recently, a fake update to Microsoft Outlook, but with the high interest in Michael Jackson’s death the cyber criminals decided to change their delivery method to capitalize on that

Google also, has confirmed that the surge of Michael Jackson-related searches on Google News Thursday was first interpreted as an attack on its service.

Google News was inaccessible for some people Thursday afternoon right as rumors of Jackson's death began to circulate, replaced by an error message reading "We're sorry, but your query looks similar to automated requests from a computer virus or spyware application. To protect our users, we can't process your request right now."

Of course, those queries were quite legitimate, as millions around the world searched for accurate information regarding Jackson following reports that he had suffered cardiac arrest. The spike in queries began at about 2:45 p.m. PDT Thursday, and Google thought the traffic was an attack for about 25 minutes before realizing what was going on.

Google also noted that it saw a huge spike in mobile searches. Yahoo's data backed up Google's; it set a record for unique visitors in a single day with 16.4 million visitors, and its lead story on Jackson's death was the most highly-visited story in its history.

A mass-mailing worm is using Jackson's death as bait, computer security company Symantec has discovered.

The worm sends out spam emails with the subject "Remembering Michael Jackson" and an attachment named "Michael songs and pictures.zip."

The .zip file contains another file called "MichaelJacksonsongsandpictures.doc.exe" which is a copy of the worm.

When opened, the worm automatically downloads onto the user's machine, then spreads through its email program and also onto removable drives such as USB sticks.

For people looking for news, videos, pictures or any information regarding Michael Jackson and his life, Symantec recommends that they only visit sites they are familiar with and trust," Symantec Australia and New Zealand managing director Craig Scroggie said.

"Also, don't click on every link related to this story and make sure that your security solutions are up-to-date........

More intechclan...

Wednesday, October 29, 2008

I Can't click my drive...!!!!


Not able to open drives on hard disk by double click...?

Sometimes it happens in windows XP, that you are not able to open drives on your hard disk. When you double clicking on the drives icons or right click on the drive/explore in My computer , the drive does not open.But don’t worry this is not a big trouble it can be fixed easily.

This problem is generally caused by most of the viruses which infect windows XP system. They block or restrict your access to any of the drives.A lot of virus, creates an autorun.inf, file at the root of your local drives and USB flash drive. The reason for this is when you open My Computer and tries to access a drive, it will run the virus to infect your computer. Very often anti-virus is able to remove executable virus from system but not autorun.inf. This is because autorun.inf that’s located at the root of your drive is only an instruction file that tells Windows what to automatically run when you access the drive from My Computer.

So even after the virus being cleaned, you’ll find that you’re unable to access your C drive from My Computer. Some people double click C drive, a search window will appear. For some, it’d say that it cannot find the script or file to run. Most common of all, when double click C drive, it gives you an option to choose a program to open.

For computer experts, one look and they’ll know they had to remove the autorun.inf file from C drive. Usually the autorun.inf cannot be easily deleted because it has system, read-only, and hidden file attribute. You can go to command prompt to remove the file attributes and then delete it. Sounds easy for an advance computer user but might be tough for a novice.

Normally when a virus infects a windows system which causes a drive opening problem, it automatically creates a file named autorun.inf in the root directory of each drive.This autorun.inf file is a read only ,hidden and a system file and the folder option is also disabled by the virus. This is deliberately done by the virus in order to protect itself. autorun.inf initiates all the activities that the virus performs when you try to open any drive. You have to just delete this file and restart your system to correct this problem.

FIX 1

1. Open Start>>Run and type cmd and press enter. This will open a command prompt window. On this command prompt window type the following steps.

2. type cd\

3. type attrib -r -h -s autorun.inf

4. type del autorun.inf

5. now type d: and press enter for d: drive partition. Now repeat steps 3 and 4. Similarly repeat step 5 for all your hard disk partition.

Restart your system and your trouble will be fixed.


FIX 2

Or you can do this simple guide.....(actually im used more, for this method... ;-) )

1. Open you notepad.
2. Save a notepad as a autorun.inf
3. copy or send that file to a problem drive.
4. Restart your system and your trouble will be fixed.

FIX 3

Used a free Disk Heal software. Disk Heal is a useful tool that restores the condition of your storage device after being infected by a virus. Disk Heal is a useful tool that performs many functions. Initially it was a program which fixed disk problems that occur after a virus has been removed with a few additional features like changing the icon of a drive. Currently it performs various other tweaks as well.

Fix double click c drive problem

To fix your C drive problem, download, install and run Disk Heal. Make sure you have administrator privileges. Click the Fix button, type the drive letter and click Fix.

Other Disk Heal Functions

Other than fixing a drive not opening problem, Disk Heal also can restore a folder options, task manager, and registry editor. Besides fixing a problems that virus creates, it also has a bunch of other useful security, appearance, Internet Explorer and Control Panel tweaks as per below :

Security Tweaks:

-Enable/Disable Task Manager
-Enable/Disable Folder options
-Enable/Disable the registry editor
-Lock the location of ‘My Documents’
-Enable/Disable Display Properties
-Enable/Disable ‘Search’
-Enable/Disable ‘Run’
-Enable/Disable Control Panel
-Enable/Disable Shutdown
-Enable/Disable CPU Beep
-Enable/Disable CD Auto-run
-Hide/Unhide Start->(All) Programs menu
-Enable/Disable the Context menu in My Computer & Desktop
-Enable/Disable My Computer
-Hide/Show ‘Pinned’ items from the Start menu
-Remove ‘Manage’ in My Computer Context Menu

Appearance Tweaks:

-Change drive icon
-Enable/Disable Clear-Type (Also known as ‘Font smoothing’ Fonts)
-Enable/Disable smooth scrolling
-Hide/Show the left panel from My Computer
-Hide/Show the current user in the Start menu
-Hide/Show the windows version on the Desktop
-Hide/Show windows error messages on startup

Internet Explorer Tweaks:

-Enable/Disable Auto-complete
-Check if Default Browser
-Lock current home page
-Increase simultaneous downloads to 10

Control Panel Tweaks

-Hide/Show Accessibility Options
-Hide/Show Add or Remove programs
-Hide/Show Console Options
-Hide/Show Date and Time Options
-Hide/Show Display Options
-Hide/Show Fax Options
-Hide/Show Hardware Wizard
-Hide/Show IR Port Options
-Hide/Show Regional Options
-Hide/Show Internet Settings
-Hide/Show Joystick Options
-Hide/Show licensing programs
-Hide/Show Keyboard and Mouse Options
-Hide/Show Mail Options
-Hide/Show sound Options
-Hide/Show dial-up Options
-Hide/Show network & connectivity Wizard
-Hide/Show modem Options
-Hide/Show Netware client Options
-Hide/Show ODBC options
-Hide/Show PC card Options
-Hide/Show port Options
-Hide/Show power Options
-Hide/Show scanner and camera Options
-Hide/Show server manager Wizard
-Hide/Show speech Options
-Hide/Show System Properties
-Hide/Show Telephone Properties
-Hide/Show TweakUI Properties
-Hide/Show User Manager Properties

Disk Heal is FREE and portable that works on Windows NT, 2000, XP and Vista. After installing Disk Heal, go to C:\Program Files\Disk Heal\Disk Heal v1.47 and copy the Disk Heal.exe to your USB flash drive. Great and useful tool.

[ Download Disk Heal ]

More intechclan...

Saturday, February 2, 2008

My C Drive, give me options.



I has formatted my pc, after the virus attack, but the virus is still there. Another big problem that arises is when I double click at C drive, it gives you an option to choose a program to open. I will try to run my antivirus but so even after the virus being cleaned, I' ll find that I'm still unable to access my C drive from My Computer. So I know, now my computer have been infected by autorun.inf created by virus.

A lot batch of virus creates an autorun.inf drives files at the root of your local drive and USB flash. The reason for this is, when you open or double click "My Computer" and sort to access has drive, it will run the repugnant virus to your computer. Very often antivirus is whitebait to remove executable virus from system goal not autorun.inf. This is because autorun.inf that's located at the root of your drive is only year instruction spins that tells Windows what to automatically run when you access the drive from My Computer.

For computer experts, one look and they' ll know they had to remove the autorun.inf drive file from C. Usually the autorun.inf cannot be easily deleted because it has a system, read-only, and hidden file attribute. Sounds easy for an advance computer user but might be tough for a begginers.

Here's, I'll show you, simple way to heal this problem, download "Disk Heal". "Disk Heal" as has useful tool that restores the condition of your storage device after being infected by has virus. "Disk Heal" is has useful tool that performs many functions. Initially it was has program which fixed disk problems that occur after has virus has been removed with has few additional features like changing the icon of has drive. Currently it performs various other tweaks have well. Drive More will Be added soon. But very important thing is, "Disk Heal" is FREE and portable that works on Windows NT, 2000, XP and Vista.

To fix your C problem, download, install and run Disk Heal. Sour Make you cuts administrator privileges. Click the Fix short prop, the type drive letter and click Fix. Other than fixing problems that virus creates, it also has a bunch of other useful security, appearance, Internet Explorer and Control Panel tweaks.




Get your's "Disk Heal" now and protected your PC

[ Download Disk Heal]

More intechclan...

Sunday, September 23, 2007

JambanMu.Com virus...!!!!!!!



Lately, a lot of my friends' computer has been infected by JambanMu.Com virus (virus by trojan.win32.vb.ayo also known as flash.10.exe) and my computer now has been infected by this virus…!. This virus is quit annoying because it messing up with your registry. Your computer may become slow because this virus will load your registry with unnecessary entry that they created. This Virus is created by using VB Basic v5 .

What the virus did to your system you've been infected :-

1) Disable Task Manager
2) Disable Folder Option
3) Disable Regedit
4) Disable "cmd"
5) JambanMu.com run everytime you start your computer(at startup)
6) This virus also will create a few folders and files like flash.10.exe, msconfig.com, cmd.com, jambanmu.com, ping.com, regedit.com, aweks.pikz, msn.msn and many more.
7) Disable “Search” option
8) Slow the Computer
9) Slow the Internet Connection
10) Corrupted the Exlorer
11) Slow your shutdown time




My zonealarm has detacted this virus but cannot remove it, the Zonealarm just keep it on quarantine. But after I google to search any kind of removal for this virus, i'm founded this program. You just download this program, after that click at the icon, then wait the message prompt “Restart your computer “. Now my computer is free from this virus. Don’t worry, this program been tested by me. It is 100% working. ( If download not work please email me, I will send you the copy or try this link).

More intechclan...

Sunday, September 2, 2007

Malware Gyaan



Malware is the collective term to describe malicious programs, incuding viruses, trojans, spyware, adware,rootkits, nerbots, backdoors, keyloogers, fraudulent dialers, the list is endless. Some of the other threats include phising and pharming.

VIRUS: It is a program that can replicate itself and affect normal operation of a computer without the permission or knowledge of the user.

POLMORPHiC VIRUS: This type of a virus keeps changing its signature every time it replicates and infects a new file.

WORM: Unlike a virus, a worm is a program that is capable of replicating and spreading to various other systems without the need of a host file.

TROJAN: It is a program that contains or installs a malicious program though it appears to be a genuine one.

SPYWARE: Such type of software collects personal information about the users without their informed consent.

ADWARE: These software are capable of playing, displaying, or downloading advertising material automatically to a computer after it is installed on it.

BACKDOOR: It is a program that can bypass normal authentication to gain remote access to a computer and remain hidden from cursory inspection.

BOTNET: It is a network of computers controlled by a Bot developer.

ROOTKIT: These software tools hide some malicious running processes, files or system data from the operating system.

KEY-LOGGER: It is a program that is used to capture the user's keystrokes.

FRAUDULENT DIALERS: It is a program that that installs a malicious program.

PHISHING: It is a fake website appearing to be a genuine one in orderto extract personal details from users.

PHARMING: Pharming is aimed to redirect website's traffic to another phoney website.

More intechclan...

Monday, August 20, 2007

The Virus



Most viruses are written with a malicious intent, so that they can cause damage to programs and data in addition to spreading themselves. Viruses infect existing programs to alter the behavior of programs, actively destroy data, and perform actions on storage devices that render their stored data inaccessible.

Computer viruses attack the software of a computer such as operating systems, data files, application software, and e-mails. However, viruses do not affect the computer hardware.

Viruses infect computers and spread themselves using various methods. Some viruses attach themselves to a common program such as a popular game or word processor. When a person downloads the infected game and runs it, the attached virus program gets executed. The virus then loads itself into memory and searches for any other program on the disk. If the virus finds any program, it modifies the program by adding the malicious code to the program. The next time this program gets executed, it infects other programs, and the cycle continues thereafter.

There are many types of computer viruses such as a boot-sector virus, macro virus, e-mail virus, etc.

A boot-sector virus infects the boot record on hard disks and floppy disks, which is used to start the computer. When the computer is turned on or restarted, the virus is automatically executed. An infected boot disk may stop the computer from starting up.

A macro virus is a macro or script that attaches itself to a file or template. When the file is loaded, the instructions of the macro or script are executed.

An e-mail virus moves around in e-mail messages, and usually replicates itself by automatically mailing itself to many people in the their e-mail address book.

Some other types of programs are also harmful to computers, which are not viruses such as a Trojan horse.

The main difference between a virus and a Trojan horse program is that a Trojan horse program does not replicate itself. A Trojan horse only destroys information on the hard disk. A Trojan horse program disguises itself as a legitimate program such as a game or utility. It often looks and initially acts in the same way as a legitimate program, but when it is executed, it destroys or corrupts data. A Trojan horse program can contain viruses, but it is not a virus itself.

A Worm uses computer networks and security holes to replicate itself. A Worm scans the network for another computer that has a specific security hole. It copies itself to the new computer using the security hole, and then starts replicating from there as well. A virus can have both virus and worm characteristics.

There are several anti-virus software that can detect, identify, and remove these viruses. As a precaution against viruses, we should take the following actions:
An anti-virus software that can detect, identify, and remove viruses should be installed on the computer.

All information downloaded from the Internet or some unknown resource must be immediately scanned for viruses by using an anti-virus software. Any e-mail attachment that comes from unknown sources should never be opened.

More intechclan...

Thursday, August 2, 2007

Downloader the latest nemesis.




Did you received suspicious email with the attachments such as bill from Amazon or eBay. Do you know the attachments files like this are very dangerous. Many online attacks are beginning to employ such tactics. The similarities of such attacks donate from the executable downloader which arrive in mail attachment such as “Zip” or “PDF” file.

A Double click on the does not run Winzip or Adobe reader, but executes a downloading process. This is how possible malware such as Trojans, Worms or Spyware sneaks into the PC.

Normally the anti-virus should have sounded the alarm, but the problem is that downloading a supposedly harmless file will not trigger anything. Its not damage the computer while modifying system files. It only does what is command to download the file from the internet.

The Anti-virus company, at present finding difficult to develop a solution. This because what the downloader downloads is basically yet another slightly modified downloader. The most insidious part about this is that even if the antivirus can be hard coded to ban a specific downloader, it will not recognized the second, third and following programs as they all unique.

When the downloader goes into action, disaster will start to unfold. Your are lucky if, it will only download spyware to your computer. But it more dangerous, if it install the botnet software to your computer. Your computer wrongly to gain unauthorized control by the hackers. The hackers then uses this computer as a distributor machine to spamming and may even resend that malicious email to your address book contacts.

Now the antivirus companies are working hard at finding the solutions. The Symantec, suggested the firewall of good security suites to block the downloader. However, it may not be able to capture all of them. Trend Micro is dealing with the issue by blacklisting popular websites which host malware. But the basic rules to dealing with this issue are “Please, never to open file attachments of suspicious mails….”

More intechclan...

Blog Widget by LinkWithin

Label Cloud