DailyExposition

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label malware encyclopedia. Show all posts
Showing posts with label malware encyclopedia. Show all posts

Wednesday, May 29, 2013

Trojan.Zbot!gen44

Posted on 10:11 PM by Unknown
This malware since our last update has had 3 different variations with a few changes and still has a low threat rate. However let us jump into this malware and see what the major changes were, and what they could mean for you. Now please keep in mind that this family is known as the Zeus Bot which was a big threat "back in the day".



Effects
This malware was designed to specifically go after important bank information and goes through a number of ways to get it. The trojan will even try to go through your saved files and passwords on internet explorer to retrieve important passwords.  While this malware is hard to deal with if you don't have Antivirus it is actually a very low level threat as far as malware goes. While the malware may pose a threat to infected computers there are not a lot of infections. According to Symantec there could be as few as 1,000 (at the time of this post) worth of infected computers. Now if you believe you are one of these few then be careful and try to remove the malware as fast as possible. This malware is controlled by the creator or a bot program and it can be commanded to:  shutdown the computer, reboot the computer, delete files, and delete important system files which requires you to reinstall the operating system. However, you need to keep in mind that these threats are not as bad as other malware because you still have full access to your computer and you remove the malware with a simple secondary scanner that are in the lists below.

Detection
While this malware is not the easiest to detect, there are some obvious signs. The first one being strange or unscheduled shutdowns/restarts. This is generally the sign of malware or some sort of malware issue. You might also (hopefully not) get a warning from one of your accounts, whether it is Google, Paypal or anything else please read these if you know they are from the real company. Your computer will also start to slowdown from the malware which is typical. 

Please Follow My Removal and Protection Guide


Removal 
You can remove the malware by using the secondary scanners below, and they will detect the malware. However,you need to realize that if one of them says that your computer is safe there is still a chance that the computer is infected with some sort of malware. So make sure to use two or three of the scanners below. I recommend that you use Malwarebytes and HitmanPro because they are the most powerful secondary scanners on the market. With this malware we also recommend that you change any and all passwords that could have been compromised from this attack, because if you don't the person that sent you the malware might be able to access your accounts and change the log in information.

Protection
If you want to protect against the malware you will want an up to date antivirus and firewall. I recommend that you use Ad Aware Antivirus or Avast Free Antivirus because these two have always found malware that someone else has missed. But make sure that you only use one of the above antivirus products because we want to avoid confliction between them. For your firewall I recommend that you use Comodo free firewall which offers the best HIPS protection in the industry, and it contains a ton of extra features like the Sandbox and the Comodo Kiosk.


Secondary Malware Scanners
 HitmanPro: http://www.surfright.nl/en/hitmanpro/
Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
Malwarebytes: http://www.malwarebytes.org/
Super AntiSpyware: http://www.superantispyware.com/
Bitdefender Quick Scan: http://quickscan.bitdefender.com/
Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
Read More
Posted in malware encyclopedia | No comments

Saturday, May 25, 2013

Infostealer!gen4

Posted on 11:15 AM by Unknown
This malware was first identified by Symantec, and this is the signature for a family fo Trojans which as you can guess from the name is meant to steal passwords and user information. This malware is actually not very common, and it is actually a low threat, but the malware does have some unique characteristics that make it difficult for an antivirus product to detect it. Now since the malware is such a low threat there is a good chance that your antivirus product already has the signatures in its database or heuristics engine never the less lets jump in.





Effects
This malware will get onto your computer and try to use an encryption method from the program/file, and it tries to slip by the antivirus program that you are using. It will then try to get private information from your browsers saved passwords form, and it will try to gather information from email clients that might be on the computer. This malware is also hard to detect because of the encryption method that it is using but with all malware there is a sign that your computer might be infected.

Detection
If you believe that your computer is infected with this malware then there are some hints that you can use to try and diagnose the computer. The first thing is that your computer will be slower, and this is generally associated with all malware so you can tell that something is wrong with your computer. You might also notice account warnings from Google or another company warning about someone attempting an unauthorized access to your account. There is a chance you can't access your email client or other online accounts.

Removal
You can remove the malware by using the secondary scanners below, and they will detect the malware. However you need to realize that if one of them says that your computer is safe there is still a chance that the computer is infected with some sort of malware. So make sure to use two or three of the scanners below. I recommend that you use Malwarebytes and HitmanPro because they are the most powerful secondary scanners on the market. With this malware we also recommend that you change any and all passwords that could have been compromised from this attack, because if you don't the person that sent you the malware might be able to access your accounts and change the log in information.

Protection
If you want to protect against the malware you will want an up to date antivirus and firewall. I recommend that you use Ad Aware Antivirus or Avast Free Antivirus because these two have always found malware that someone else has missed. But make sure that you only use one of the above antivirus products because we want to avoid confliction between them. For your firewall I recommend that you use Comodo free firewall which offers the best HIPS protection in the industry, and it contains a ton of extra features like the Sandbox and the Comodo Kiosk.

Secondary Malware Scanners 
HitmanPro: http://www.surfright.nl/en/hitmanpro/
Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
Malwarebytes: http://www.malwarebytes.org/
Super AntiSpyware: http://www.superantispyware.com/
Bitdefender Quick Scan: http://quickscan.bitdefender.com/
Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
Read More
Posted in malware encyclopedia | No comments

Wednesday, May 22, 2013

Trojan.Blackrev

Posted on 7:39 PM by Unknown
This malware was first analyzed by Symantec go visit them why don't you?
This malware is was first discovered by the Symantec corporation, and they found this to be a low level threat I am going to disagree with that statement, and I will explain why.



What Does It Do?

This malware infects the computer by downloading some sort of rogue software, and it is meant to turn the computer into a zombie. They then use this new "zombie" computer to send out DDOS attacks to the websites of the creators choice. This malware once installed onto the computer will change its name so that it is not noticeable to you. The most common name is explorer.exe which would be the windows explorer name so you would not think anything of the program. Something that you must keep in mind is about how much has the program spread. Now the malware is very well contained, and there is not any large breakouts as of now so we are in the clear for now, but the only way to prevent the malware is for you to learn and protect your self from it.

Symptoms

Your computer will restart at random times for no apparent reason, this can be used as a way for the malware to through you off or to prevent you from uninstalling it. This is generally a clear cut sign that there is a form of malware on the computer or that your computer is facing hardware issues. You can also notice computer slowdown because all malware does tend a tool on your computer especially one that has been "zombified". You will also notice your computer acting strangely whether it is random applications opening or you are visiting random websites without actually doing anything. When this happens it means that the malware creator has already taken control of the computer.

Threat Level Medium

The reason that I classify this malware as a medium level threat is because of the goal and the use of the malware. Now while the malware is not common it is still a threat if you had the malware, and this is something that you don't want to have. Now it is not classified as High, Severe, or Critical is because it is easily stopped such as turning the computer off and using the AVG rescue CD to remove it. It is higher than a level of Low, or Very Low is because the malware does some serious damage and could do more if more people had the malware.

Removal

You can remove the malware by using the secondary scanners below, and they will detect the malware. However you need to realize that if one of them says that your computer is safe there is still a chance that the computer is infected with some sort of malware. So make sure to use two or three of the scanners below. I recommend that you use Malwarebytes and HitmanPro because they are the most powerful secondary scanners on the market. If you are having a hard time accessing the internet then you should use the AVG Rescue CD which can be found here.

Protection


If you want to protect against the malware you will want an up to date antivirus and firewall. I recommend that you use Ad Aware Antivirus or Avast Free Antivirus because these two have always found malware that someone else has missed. But make sure that you only use one of the above antivirus products because we want to avoid confliction between them. For your firewall I recommend that you use Comodo free firewall which offers the best HIPS protection in the industry, and it contains a ton of extra features like the Sandbox and the Comodo Kiosk.

Second Opinion Malware Scanners!

  • HitmanPro- http://www.surfright.nl/en/hitmanpro/
  • Panda Active Scan- http://www.pandasecurity.com/homeusers/solutions/activescan/
  • Malwarebytes- http://www.malwarebytes.org/
  • Super AntiSpyware- http://www.superantispyware.com/
  • Bitdefender Quick Scan- http://quickscan.bitdefender.com/
  • Norton Power Eraser- http://security.symantec.com/nbrt/npe.aspx
  • Kaspersky TDSSKiller- http://kaspersky-tdsskiller.en.softonic.com/
  • McAfee Stinger- http://www.mcafee.com/us/downloads/free-tools/stinger.aspx
  • Trend Micro House Call- http://housecall.trendmicro.com/
  • Eset Onlne Scanner- http://www.eset.com/us/online-scanner/
  • Dr.Web CureIt! - http://www.freedrweb.com/cureit/
  • Read More
    Posted in malware, malware encyclopedia | No comments

    Saturday, May 18, 2013

    Trojan.Zbot!gen41

    Posted on 8:42 AM by Unknown

    Today we will be discussing a new form of malware that was released 5/16/2013 and that is the
    Trojan.Zbot!gen41 this particular variation of trojan has very specific directions on what to target but at the same time it was poorly written and it is easy to detect. So lets dive into this new malware sample, and by the end of this you will know how to avoid the trojan and remove the program the program from your computer.



    Effects

    This malware was designed to specifically go after important bank information and goes through a number of ways to get it. The trojan will even try going through your saved files and passwords on internet explorer to retrieve important passwords. The Zeus trojan also goes through any programs such as Thunderbird which it will try to gather any passwords for the email accounts that are being used. So as you can tell the point of this program is to gather any and all passwords that it can get it's hands on. Now after the malware has gotten onto the computer it will try to download a worm which was identified by Symantec as the W32.Waledac. After the computer gets these malicious items on it the creator can feed the trojan commands and tell it to do various commands such as: shutdown the computer, reboot the computer, delete files, and delete important system files which requires you to reinstall the operating system.

    Signs Of Infection

    The computer will be running slower however this is commonly shared with all forms of malware. There are other main signs such as the computer randomly shutting down or rebooting which should not be happening but this is generally a clear cut sign of malware, or some form of a driver issue. Which might also lead to random shutdowns, but you want to check all possibilities before trying to fix the issue. So please go down to the secondary scanners and run any combination of them to see if your computer is infected.

    Removal

    You can remove the malware by using the secondary scanners below, and they will detect the malware. However you need to realize that if one of them says that your computer is safe there is still a chance that the computer is infected with some sort of malware. So make sure to use two or three of the scanners below. I recommend that you use Malwarebytes and HitmanPro because they are the most powerful secondary scanners on the market.


    Protection

    If you want to protect against the malware you will want an up to date antivirus and firewall. I recommend that you use Ad Aware Antivirus or Avast Free Antivirus because these two have always found malware that someone else has missed. But make sure that you only use one of the above antivirus products because we want to avoid confliction between them. For your firewall I recommend that you use Comodo free firewall which offers the best HIPS protection in the industry, and it contains a ton of extra features like the Sandbox and the Comodo Kiosk.

    Secondary Malware Scanners 

    1. HitmanPro- http://www.surfright.nl/en/hitmanpro/
    2. Panda Active Scan- http://www.pandasecurity.com/homeusers/solutions/activescan/
    3. Malwarebytes- http://www.malwarebytes.org/
    4. Super AntiSpyware- http://www.superantispyware.com/
    5. Bitdefender Quick Scan- http://quickscan.bitdefender.com/
    6. Norton Power Eraser- http://security.symantec.com/nbrt/npe.aspx
    7. Kaspersky TDSSKiller- http://kaspersky-tdsskiller.en.softonic.com/
    8. McAfee Stinger- http://www.mcafee.com/us/downloads/free-tools/stinger.aspx
    9. Trend Micro House Call- http://housecall.trendmicro.com/
    10. Eset Onlne Scanner- http://www.eset.com/us/online-scanner/
    11. Dr.Web CureIt! - http://www.freedrweb.com/cureit/
    Read More
    Posted in malware, malware encyclopedia | No comments

    Thursday, May 16, 2013

    Skype Bitcoin Malware

    Posted on 8:02 PM by Unknown

    The skype related malware is still going around, and it has turned thousands or even millions of computers into zombie computers that are meant to farm Bitcoins. This Bitcoin related malware has only made it more difficult for the currency to be taken seriously. However this is one threat that you don't want to have, but it is fairly easy to remove.

    How You Got It
    This malware is meant to spam onto skype and possibly other social networks such as Facebook. It has been reported that the most common message includes something about a picture of the person that they are referring to and when you click on the link you will download the malware. This might even take control of the account and use it for more spam links, but this was not confirmed. It is meant to infect the machine and farm the virtual currency the Bitcoin which has had a growing controversy over the years. However, they are becoming more valuable and are trading at a price equivalent to $100 +.

    What It Looks Like
    According to Kaspersky this malware is running under the process name of bitcoin-miner.exe -a 60 -l no -o http://suppp.cantvenlinea.biz:1942/ -u XXXXXX0000001@gmail.com -p XXXXXXXX according to Kaspersky. They also censored out the important information with XXXXX's so that no one would be harmed from this information. The process will farm them and send the information to the specified "wallet". This malware will not cause major damage to the machine, but it is best to change account information and to clean the computer with the secondary scanners below. So you can tell if you have this malware if you go into your task manager and go to the process' tab and if you have something with the above process name then you do have the malware. Your computer might also be running very poorly because the farming is meant to use as much CPU power so that the creator gets the most amount of coins.

    Removal
    You can use the secondary scanners below to remove the malware but you should also delete the original file first and then scan with the scanners below. The best thing is that the computer's internet will not be affected meaning that you can easily download one of the scanners below. Then go into your Microsoft account and change the password to Skype because that is one common mistake with a malware infection and that is people don't change their login information which means that you can still be sending out the spam.
    Goal Of The Malware
    This malware was made strictly for farming Bitcoins so that someone could make money and you were the computer power. Now the way that the malware was created and how well it grew is some what scary to Security Experts but at the same time you have to give the creator credit for being able to infect the thousands maybe millions of computers.

    Secondary Malware Scanners
    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
    Read More
    Posted in malware encyclopedia, Microsoft | No comments

    Sunday, May 12, 2013

    W32.Phopifas!gen2

    Posted on 8:23 PM by Unknown

    This family of malware is known as the Phopifas family. This is another family of worms that has done some major damage in the past. Just last year alone Phopifas!gen1 was responsible for 2.5 million infections. This was a wide spread malware at the time, and it started with the rise of Skype. Now while it is not as well known today this malware is a smaller threat to companies such as Symantec and Bitdefender who have labeled this threat as Low Level Risk. The reason for this was the malware is not widely spread, and the malware has already been identified once.


    Origin 
    The origin of this malware was first found via a Skype link were there was a message along the lines of Were did you get this picture? Or is this picture really of you? Or even i cant believe that you would do that. These messages want the user to click the link to see what the image is unfortunately they don't know they are headed to a malicious site. This malware has been transferred in many other forms of social networks including Facebook. After they go to the download page they download the image in a ZIP file which strikes many people as odd but they continue with it anyways. The malware is in the folder and is apparently the second downloaded item.

    Effects
    This malware has in some cases contained some other forms of malware such as trojans. However since the malware has been used by many other people it is hard to tell what the exact type of malware was being spread. The purpose of the worm is to spread its self to other users by using the same social media source that it originated from. So one person get the worm then their skype account sends out the same message that they received to spread the malware even more. Now the other malware that the ZIP file contains has mostly been isolated to trojans, however some cases have been reported to contain viruses, rootkits, and others. As with any worm be sure to avoid using a USB drive or connecting to your internet or there is a risk that this malware will spread to other users on the same network.

    Removal
    The removal process is quiet simple you will want to delete the zip file that you downloaded and use one of the secondary scanners below. After that I recommend that you change your Skype password because it might have been compromised during the infection. Now if your antivirus is not detecting or removing the malware then you can try booting into safe mode and deleting the file that way to wipe it out for good.

    Protection
    As always have some sort of antivirus and firewall installed on your computer and make sure that they are being updated daily. Even if you have these installed to click on any suspicious links that you may come across on skype or Facebook. The reason is if the malware is new and the company does not have it in their signatures or database then you will be in trouble because the antivirus program cant help you. So just because your system is protected don't be daring and try to download the file.

    Secondary Malware Scanners 
    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
    Read More
    Posted in malware, malware encyclopedia, worm | No comments

    Friday, May 10, 2013

    Packed.Generic.410

    Posted on 10:22 PM by Unknown
    Symantec | United States
    Pay our friends over there at Symantec a visit why don't you?

    Symantec corporation has identified a newly released threat which they have labeled as a Packed.Generic.410 please remember that just because another company labels it something different it does not mean that it is different. This particular piece of malware which I believe is a trojan based off of its actions. While this variation of trojan is not a major threat to you please keep your computer safe by downloading safe programs from trusted websites. Now lets break this malware down.

    Simple Name Break Down
    Packed = This means that it is a packer. A packer is a program that has been packed with some sort of security. Whether it was a password or a special algorithm, they are generally weak and not a serious threat.
    Generic = This just means that it is another common variation of a packer.

    Effects
    The thing to keep in mind with these packers is that they are very weak, and are generally a low level threat to the user. Now since it is a trojan you should still take it as a threat to your bank information and other account information. These "packer trojans" generally get onto the computer and are released when extracted UNLESS they are self extracting which is a possibility. These trojans are generally downloaded from an infected computer. They can be downloaded from emails but as email systems are becoming more and more secure these are slowly being weaned out. So always download safe programs from safe and well trusted websites and these packers wont be an issue.

    Removal
    As always run a scan with an antivirus program from my secondary scanner list at the bottom of the post. You will also want to delete the source whether you downloaded a zip file or it was an exe file. It is also recommended to delete your internet files and cookies because we don't know what other modifications that it made to your computer. After you use the scanners and delete the cookies you should not have to worry about them, but if you feel that the trojan still remains post a comment below.

    Protection
    Download any of the free antivirus products below and update them. If you have an antivirus program please remember to update it daily. If you don't know whether your product is safe or a trusted program ask in the comments below or consult this short list. Again just because it is not on the list does not mean that it is not a trusting program.
    Avg- http://free.avg.com/us-en/homepage
    Avast- http://www.avast.com/en-us/index
    Bitdefender- http://www.bitdefender.com/
    Ad Aware- http://www.lavasoft.com/
    Avira- http://www.avira.com/en/avira-free-antivirus
    Panda- http://free.pandasecurity.com/
    Comodo- http://www.comodo.com/
    Microsoft Security Essentials- http://windows.microsoft.com/en-us/windows/security-essentials-download
    Windows Defender- Installed on all windows 8 machines

    Secondary Scanners

    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
    Read More
    Posted in malware, malware encyclopedia | No comments

    Thursday, May 9, 2013

    Malware: WN32.Changeup!gen41

    Posted on 5:45 PM by Unknown

    A new string of the Changeup family of malware was detected and categorized by Symantec today. This malware is quite strange because it a low level worm. Generally when someone writes a worm it is meant to be very difficult to remove however Symantec marks it as a low level threat. Lets explore this family of malware and explain what it is meant to do to your computer.

    Possible Infection Routes

    You will contract a worm generally by downloading some sort of unsafe program. However they are also commonly shared by USB drives and the USB was infected for downloading the unsafe program and either it replicated its self onto the USB, or it was installed onto it. Since it is a worm we also know that it was possibly spread through the network from another infected machine. This is one of the reason any Network Manager or IT professional hates to deal with worms.

    Effects

    This malware is very similar in its effects compared to any form of worm. It will set its self to autorun so that it will always run with the computer on start up. This is so common with malware that it is almost not worth mentioning. The worm is meant for two main things. The first thing being that a worm spreads to other users through any means necessary. The second main thing is to download more malware onto the computer. This malware is generally trojans that will steal information from your computer. Now think about this the worm spreads to as many computers as it can. It will then try to download trojans and more malware onto the computer. This technique is meant to steal as much information (credit card, banking, etc..) so the author can make money. There is also a thought that these worms are part of an affiliate scheme to were the author says if you pay me (insert dollar amount here) then I will get this many downloads.

    Removal

    Scan your computer with any secondary scanners at the bottom of this post. You should also check anyone else that was on your network or if you used a flash drive. While you might get malware from the flash drive your antivirus product will detect it if it was already updated. You will want to disconnect your self from the internet if you feel like your computer does have the malware after you downloaded a scanner. The reason for this is you want to reduce any chances of getting the malware onto another computer or it makes removing it that much more difficult.

    Protection

    Don't download any programs if you cant prove that they are safe or if they are from a trusted partner of the owners. For instance I could download Microsoft word but if I got it from some random site then even though the product is safe they might have added malware to that package. You should also keep an updated antivirus product on your computer to protect it in case you do run into the malware.

    Secondary Scanners

    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx
    Read More
    Posted in malware, malware encyclopedia | No comments

    Tuesday, May 7, 2013

    Malware: Trojan:Win32/Urausy.D

    Posted on 5:35 PM by Unknown

    A new piece of Ransomware that is running around that was classified by Microsoft as Trojan:Win32/Urausy.D. This family of malware is Win32/Urausy which is a family of Ransomware that takes over your computer by displaying some form of false FBI or local Polic Department message saying that your computer is locked. Down so what do we do with this form of malware? This family of Trojans has been growing more and more common in recent times only because it has proven to be successful for the people who are making it. Some would disagree with the term industry however this is a multi million dollar industry. Which is why they keep making it all because people do not know about these fake programs and they don't protect their computers. The sad fact is that the USA which is one of the most advanced countries we are also the most heavily infected country in the world. You take 1 look at any statistic or malware map, and the US has the largest amount of infected computers. So lets just jump into the effects of this Trojan on your computer.

    Effects?

    This form of malware does do some strange things to the computer however it is what you would expect from any form of Ransomware. The program practically takes control of your computer by displaying this fake message and says you must pay, or your computer will lose internet access. As we know though this is a fake message and you should not pay them or it will continue the cycle. This program is disguises its self as Skype through the form of Skype.(filename) and it fools the user into thinking that this is a trust worthy program.

    Now the program is meant to pop-up on launch and will do it when trying to access the internet so removing it can be a pain. However it will not be that hard to remove it if you use another computer to download some sort of tools. Just remember that you should never pay for the program because this will just end up taking money away from you and the problem will still exist. You shouldn't bother contacting your ISP because this is on your side and they cant help you when it comes to removing the malware.

    Removal
    1.Get a USB drive.
    2. Download the AVG Rescue CD
    3. Follow the steps that are given on the site.
    4. Run the tool on the infected machine.
    5. Let it clean any files that it detects.

    After That
    1. Delete the AVG Rescue CD from your USB.
    2. Download HitmanPro Kickstart
    3. Follow the steps given on the website.
    4. Run the tool on the infected machine.
    5. Let it clean any files that it detects.

    After that your machine should be fine. Make sure that you download some sort of antivirus software, and to keep your computer protected from further infections follow my guide on securing your computer.
    The article can be found here!
    Read More
    Posted in malware, malware encyclopedia | No comments

    Sunday, May 5, 2013

    What Is A Trojan:JS/Seedabutor.B

    Posted on 9:38 PM by Unknown


    This piece of malware has grown very quickly and is becoming a very troubling form of malware for home users. This piece of malware was first classified by Microsoft on January 11th of this year. They were able to patch their program to detect this malware, yet it has become a growing threat because of out dated or just the lack of antivirus. So if you want to remove the malware skip to the bottom of the post and follow the very simple removal guide.


    What Is It?

    Well to take it from the name classification you will notice that it is a trojan, but there is more to it. This particular trojan was meant to be transmitted through Javascript which is what all website include. Well most of them do there are some who try to accommodate to those who don't use Java. This particular trojan is put into your temporary internet files and will start to redirect your browser to other sites. Now the sites seem to have been random in order but they were put there for someone to make money. The trojan is easily removable, and anyone can do it with a very simple tool or by going into their browser and deleting the temporary internet files. Something I found interesting is when the trojan activated some of the servers it sent were not available which meant that the trojan probably was from some sort of hacked website that was repaired.

    Interesting though that this became such a large threat so quickly. This issue while not very large in the public did get the attention of security experts quickly.

    Removal

    Very simple removal process by deleting your temporary internet files.
    Download Ccleaner- Then the process should be self explanatory. http://www.piriform.com/ccleaner
    Afterwards, you can uninstall or keep the software it is free so it is up to you.

    Now I recommend that you use a form of secondary scanner such as Hitman pro. This will scan for any remnants of the malware if there are any. It will also scan for other forms of malware that you may have contracted from the infected links. If you want some powerful secondary scanners then check out my post here were I give you a very quick list about secondary scanners.

    List Here

    After Removal

    Alright after you removed the malware the next thing that you must do is update or in some cases install some sort of antivirus software. If you need to update your program just launch it and look around for the update. It might be under some sort of tab such as maintenance, settings, update etc..

    If you are looking for some sort of antivirus software then try one of the free programs below. Please remember not to download both only use 1 of them. Also make sure that you don't have any other form of antivirus software on your computer while you download these or there can be possible conflicts. 

    Ad Aware- http://www.lavasoft.com/products/ad_aware_free.php
    Avast- http://www.avast.com/index

    Read More
    Posted in Computer Support, malware, malware encyclopedia | No comments

    Monday, April 29, 2013

    What Is Adware

    Posted on 6:00 PM by Unknown

    Adware one of the most commonly misunderstood form of malware right next to the common virus. The issue with Adware is people try to assume that they know what it is but the thing to keep in mind with Adware is it rarely comes alone. When it comes to malware Adware is one of the most common types but it is generally coupled with a form of malware such as a Trojan or spyware. None of these will break the computer, but they are annoying and can get some information about you if you are not careful.

    What Is Adware


    Adware is a form of malware that as it title says is meant to get revenue for the creator in the form of ads. Now they are generally harmless depending on the ad agency that they used but many of them can get your private information. Most forms of adware come in the form of a toolbar. This is because they can easily integrate into your web browser making it really easy to display the ads. They are generally shown from some sort of java code so turning off java should end the ads but we want to get rid of them permanently.

    Removal

    This is very dependent on the type of malware that you have on your computer. If it is a toolbar then that is very simple to remove and I have explained that in an article which is located here. But what if this is not a toolbar and is a file. This is where it gets to be annoying, because we either have to find the file its self or use a variety of malware scanners. Since it would be to difficult to diagnose every type of adware that there is and where it is located we will use scanners to do the work for us. But you must first ask yourself have I downloaded anything recently? If so what was it. Generally adware is contracted through some sort of download so first look at every program that you have downloaded. If it is not from a trusted company such as Microsoft or adobe then LOOK THEM UP. Chances are that is where the malware is coming from.

    Now let's say that your malware is some form of file and not a program. I am not going to force you to look through folders and thousands of files. That would take hours, and it is just unnecessary. So we will be using scanners to do all of the real work for us. Scroll down to the bottom of this post for the links to the scanners. Use HitmanPro first this will probably find all of the malware first and it does not require you to install it.

    Protection

    As always you should have antivirus and a functioning firewall for your computer. I have written a guide on protecting your computer from malware. The guide is located here and gives you free recommendations to protect your computer.

    Scanners


    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/

    Use This One At Your Own Risk. The power eraser is very sensitive.
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx

    Read More
    Posted in malware, malware encyclopedia | No comments

    Thursday, April 25, 2013

    What Is Scareware

    Posted on 7:14 AM by Unknown
    Scareware is a form of malware that is meant to scare the user to think that their machine is infected with malware. This is a large distributor of malware because so many fall for its trick. So below I will cover all you need to know about this form of malware and what to do if you come in contact with scareware. As always you should never download anything that it tells you to or your computer will be infected. Scareware was very popular a couple years back but it has slowed in recent times.


    What Does It Do

    Scareware is generally seen in the browser or it will pop up on the screen. It will say something like windows is running a virus scan and it spits out a menu telling you to download some software. This software comes with a trojan and some sort of ransomware. This why it got the name of scareware while they themselves don't contain malware they do encourage the download of it. Generally it is in the form of trojans and ransomware.

    How Do I Detect It

    You will be able to detect them fairly quickly but the trick is to not fall for what it says. For instance you might get a pop up saying windows is scanning for viruses  The first issue is nothing in windows will tell you that it is scanning for viruses. Many programs do however windows its self cant. Another thing is after the scan it prompts you to download a program. Now the real issue if windows could scan for viruses then why cant it remove them without this other software. That is because this is a malicious download. You will not be able to tell before hand unless you have a tool that tells you whether a site is safe or not before you go to it.

    Protection?

    There are not a lot of ways to protect yourself other than to not download the software that it tells you. You should also avoid popups and ads that tell you that there is something wrong with your machine. These are generally a bad sign unless you are using something such as the bit defender quick scan.

    Summary

    While these are generally harmless the best thing for you to do when online is never to download the program that they tell you to. You should also try making your browser more secure by adding extensions such as WOT or read my article about Securing Google Chrome.
    Read More
    Posted in malware, malware encyclopedia | No comments

    Wednesday, April 24, 2013

    What Is Ransomware

    Posted on 8:40 AM by Unknown
    Ransomware is another form of malware that is one of the hardest forms of malware to remove. One of the worst things about ransomware is that it can come with other forms of malware such as viruses, trojans, and many other forms of malware. The main thing that you must keep in mind with ransomware is that antivirus software has a hard time detecting it. That and you will have a hard time removing it, so below I will go into ransomeware into great detail. I will also give you some tricks that you can do to try and remove it.


    What Is Ransomware

    Ransomware is a form of malware that is disguised as a legitimate program such as an antivirus program. This is why a lot of people tend to fall for these programs but what makes them worse is that they bring more malware with them to put your system in danger. You could say ransomware is some form of double agent that gets into your computer and looks like a friend but is really working for the enemy. It is pretty easy to notice ransoware once it is on the computer and it is infected but it may not be so easy when you are searching around on the web. The big hit for your computer is some weird fine or cost to use the program or in the case of the money pack scam  a way to unlock the computer.

    What Is It Meant To Do

    Ransomware is meant to steal credit card information and to take your money. This is a form of scam that people have been making millions of dollars from. The above example is what is known as the money pack scam which is where the person gets that message and it blocks them from connecting to the internet. The worst part is even if someone does "pay to unlock their computer" it will still be locked.

    What To Do If I Have Ransomware Removal Guide

    If you suspect that you have a ransomware program then you will need to determine your situation. Can I connect to the internet? Can I use a system restore? Generally your best bet is to try a system restore and if that does not work then you will need to try some other tools.
    1. Use the AVG rescue CD. This nice tool is very nice for detecting malware and removing malware that is preventing your computer from starting up. It can be downloaded here. Download from another computer and burn it to a dvd like they show on the site.
    2. After you have run the tool and you launch your computer determine the situation. Can you connect to the internet? If so then continue with the steps with the letter A marked. If not then follow the numbers with the letter B attached to it.
    3A. So now you can connect to the internet you will need to go to another site and scan your computer for malware I recommend using Hit Man Pro which can be downloaded here.
    3B. So you can't connect to the internet which means that you still have malware attached to your computer. So instead of you trying to go into the registry right away lets try to use another tool to remove the malware. I recommend that you try the Kaspersky Rescue Disk to try and remove more malware. You can use a Disk or a USB for this scanner. This disk can be downloaded here.  
    4A. After you have removed any remnants of the malware I recommend that you download some sort of antivirus. I have created a guide on securing your computer which you can see here.
    4B. Alright now that you have used both of those rescue disks your computer should be able to connect to the computer but lets just say that it does not below I will give you some more tips.
    5A. After you have selected your choice of antivirus and firewall then you should be good just remember to not download anything that seems suspicious unless you are in a testing environment.
    5B. You can try one last rescue tool and if that does not work we will need to find the files manually. The last tool that I recommend using is the Hitman Pro Kick-start which will scan everything on boot up and remove it. The best thing is that this tool can remove the money pack scam. You can download that here.
    6A. You have concluded this part of the removal and protection process.
    6B. After all of that you should be able to boot up the computer and log into the internet. After that follow my guide on protecting your computer from malware and you should be safe. That guide can be found here.
    **If that does not work still then please try getting a friend to help you remove the files by hand**
    Read More
    Posted in Computer Support, general, malware, malware encyclopedia | No comments

    Tuesday, April 9, 2013

    What Is A Keylogger?

    Posted on 9:43 PM by Unknown

    A keylogger is another form of malware that is specifically created to steal your passwords for malicious intent. There are a lot of keyloggers, and they are also one of the easiest forms of malware to create and they are very easy to spread. Now they are generally able to hide themselves from your detection, and this is why they are such a threat to you and your security. If you think that you have a keylogger please go to the bottom of this post and use the malware scanners and see if they find it.



    In the video above I give you the basic over view of a keylogger and common ways to detect this form of malware. There are a lot of easy ways to prevent key loggers, and you can easily avoid them if you stick to sites that you know are safe, and you don't download any unknown programs. At the bottom of this post I will give you common software that you can use to scan and detect for malware. You can use any of them for free, and they are only a secondary scanner if you are looking for a free antivirus software. Go here to download Ad Aware Free Antivirus +

    What Does It Do?

    The name really gives it away, but a Keylogger is able to log the keys that you hit and the application that it is used in. They are used for stealing passwords or used to help remember passwords. Now you will be wondering what do you mean "helps remember passwords" this is very simple anyone can create their own keylogger, and they can use it monitor their own passwords so they do not need to rely on the browser or risk the chance of forgetting them.

    The worst part about Keyloggers are that they are generally un detectable by the task manager and that makes it very hard to catch them. The longer you can find it the more passwords that the person mining this information has. Now you might be able to configure your firewall or see were the information is being sent but that is a big if and the general users will not be able to find or block the connection.

    How To Prevent It

    You can prevent this by downloading an antivirus software and by only using trusted website that you know are safe or by using a website scanner. How ever it is hard to tell the difference between safe software and unsafe software. To make it simple don't download any unsafe software and these programs can be usually found if the program is not from a safe or well trusted company.

    Scanners

    HitmanPro: http://www.surfright.nl/en/hitmanpro/
    Panda Active Scan: http://www.pandasecurity.com/homeusers/solutions/activescan/
    Malwarebytes: http://www.malwarebytes.org/
    Super AntiSpyware: http://www.superantispyware.com/
    Bitdefender Quick Scan: http://quickscan.bitdefender.com/
    Norton Power Eraser: http://security.symantec.com/nbrt/npe.aspx

    When you use the Norton Power Eraser please be careful so that you don't delete any important files that are necessary for your computer.
    Read More
    Posted in Computer Support, general, malware, malware encyclopedia | No comments

    Wednesday, March 13, 2013

    What Is A Worm Malware Talk

    Posted on 2:56 PM by Unknown

    A worm is a piece of malicious code that is meant to enter computers through security exploits so that it can either gather information or even delete certain files. When it comes to network security this is the one piece of malware every security expert fears. The reason is if the computer is infected and the antivirus program or firewall did not stop it then it can easily copy its self and send those copies over the network to infect other computer and mess them up.

    How Do I Prevent Worms?

    There are many ways to prevent worms many of them are obvious, but some might not be so obvious. The easiest way to prevent worms is to keep an updated antivirus program running on your computer and to change the settings so that it can be at its top specs. The options will vary from the antivirus product to another however I can show you what do for avast. You can check that out by going to the url at the bottom of this post. 
    The other way to prevent worms from getting into your computer is to keep a firewall that is setup with necessary protection by blocking incoming and outbound connection. This way you can stop the worm from trying to get into the network its self. Unfortunately, this will most likely not prevent it, but it can still help with the general protection of your computer. You should also have your network firewall running to prevent the worm from spreading to other users on the same network as you.

    Keep your operating system up to date this is kind of a no brain er. Many people surprisingly don't have their computers set to update windows automatically and this is a major issue because Microsoft if releasing updates to improve the safety of your computer and you are not downloading them. So you should be downloading all of the important updates AND the optional updates because they can also be important but are not necessary. 
    Keep your web programs up to date. Now you will be wondering what is a web program and how do i update it. I say a web program is anything that your browsers uses to display or use web pages. These programs can be Java Microsoft Silver light, Flash Player, Basically anything that you use to display images in your browser. The reason is these programs have been known to have security exploits and are a common source of infection.

    How Do I Know If I Have A Worm?

    Your computer will be running slower and some files could be disappearing, The easiest way to check if you have a worm is to go into your computer's task manage and see if there are any unknown process running. If you are unsure what the process is do not end it look it up first generally the more common ones will be answered. But you will find a post saying that is a worm. Unfortunately, many programmers will make the process hidden so that you can not find it in the task manager. Leaving the only other way to find it is to scan for it using a variety of scanners that can be found at the end of this post.
    Summary
    A worm is a piece of malicious code that is meant to take and delete information from your computer and anyone else that is using your network. The only way to protect yourself is use optimal security settings with your firewall and antivirus. Make sure to have your network firewall updated as well so that you are protecting your friends from the threat to.

    Scanners

    http://www.surfright.nl/en
    http://www.malwarebytes.org/
    http://www.superantispyware.com/
    Read More
    Posted in malware, malware encyclopedia | No comments

    Tuesday, March 12, 2013

    What Is A Trojan 32 Generic?

    Posted on 9:56 PM by Unknown


    I got a question from someone asking what a trojan generic 32 is and I am going to explain what it is you should do to remove it and what it is. You will get all of the necessary download tools at the bottom to determine whether, or not it is a false positive. If it is follow the steps below to remove it.




    What Is A Trojan Generic 32?

    This is a trojan that is made for a 32 bit operating system. Now do not panic it is actually very easy to remove these depending on the situation. I am going to assume that since you have internet access to comment that you can download programs onto your computer. You said that you were getting it when ever opening Visual Basic. Now this is a false positive or the antivirus that you are using is saying that there is a trojan attached to the program it's self. Now there are some tools to check at the bottom of the post to determine if the program is infected or not. Please remove the software if it found to be malicious.

    What If It Is A False Positive?

    Well I do not know what kind of antivirus program you are using however you should be able to blacklist or whitelist the program so that it is not counted as a trojan any more. However do not do this until after you scan with the programs below. There is a possibility that the antivirus is ringing up the program as malicious probably through some sort of script shield that is in the product. But if you do not want to deal with these false positives you might want to consider using another form of antivirus such as Avast!

    What If It Is Malicious?

    If the scanners below do say that this is a trojan then all you have to do is remove the program by uninstalling it and go to the Microsoft website and download the most recent version of visual basic and fill out the free version. Other than that your system should be fine. As always I recommend you checking as many other sources as possible to detect malware so use at least 2 of the below scanners. That way you can determine that it truly is a trojan and not a false positive.

    Scanners

    http://www.superantispyware.com/
    http://www.malwarebytes.org/
    http://www.surfright.nl/en/hitmanpro/

    Visual Basic / Studio
    http://www.microsoft.com/visualstudio/eng/office-dev-tools-for-visual-studio
    Read More
    Posted in malware, malware encyclopedia | No comments

    Thursday, February 21, 2013

    What Is A Trojan?

    Posted on 6:42 PM by Unknown
    In this post I will be answering what a Trojan is what it does and how to protect yourself from it. There above video will allow you to listen and read or do one or the other they are truly for your own entertainment and they will both get the message across.



    What Is A Trojan? What do they do?
     A Trojan is a type of malware that is created to steal personal information from the person that has it. They were created for this exact purpose not to mention the fact they are the most common type of malware. They will search through the files on your computer and attach its self to one and hide its self so that you won't be able to delete it unless you are handy with computers. They will then leech off of the file along with other process' on the computer and take the information that it needs. The worst part is it can do this without you knowing that it is doing it and if it gets into a file that you use to save your bank information you are in serious trouble.

     How do I tell if I have one?
    There are many signs that can range, but you will generally be able to tell by going into your task manager and seeing an unknown process or you will see an unusual slow down with your computer. These are the 2 most common ways to identify that your computer has been infected by malware. Other signs that could be too late is strange and unknown changes of your account information this is a bad sign. If they get access to your bank accounts, contact your bank immediately. If it was a credit card put a fraud alert on it, this way they have to show ID if using it. If an account such as your gmail account was hacked follow through the support that the website has to retrieve and try and contact customer support.

    How Do I Remove A Trojan?
    Well removing a Trojan can be tricky because you will generally have other forms of malware on your computer that can stop you from removing it. The best way is to download an antivirus program such as Avast! or run a scan with either of these two programs. Hitman pro and Malwarebytes if non of these will download then you are being blocked by another form of malware then get on another computer and download the Avg rescue disk and then either burn a disk or put it on a flash drive. This will remove any of the programs that are making it impossible to download an antivirus software.

    How Do I Prevent An Infection?
    There are many things you will need an antivirus program as i have said if it is free then role with Avast. If you are going to pay for an antivirus I recommend Bitdefender Total Security. You can also use a secure browser such as Google Chrome which from my own testing is the most secure browser at the moment followed by IE 10 and then Mozzila firefox. The last thing you can do is for your browser is get a tool such as Bitdefeder Traffic Light or avast web rep. This will tell you if a site is safe or not before you enter it.
    Read More
    Posted in antivirus, malware, malware encyclopedia, security | No comments

    Wednesday, February 20, 2013

    What Is Malware?

    Posted on 5:30 PM by Unknown

    Above is a video that I recommend watching before you go and read the entire post because this can do a summary of it and it will also give you the option to listen as well as read, so you can retain the information.
    Read my full in depth post after the jump!

    What Is Malware?

    This is the very basic question that I am going to be answering. The answer is simple malware is short for Malicious Software. Many people will try to tell you that is a virus the answer is NO malware is the starting point viruses are a branch of malware. Don't get the 2 confused not to mention viruses are actually becoming less and less common and are being replaced by Trojans which I will explain in a later post. Trojans are already  the most common type of malware that you will encounter online. You will be thinking okay well then what is a virus? Hold on that will have to be a whole separate post it's self since these things are not black and white some forms of malware fit under the gray area.

    What Is Malicious Software?

    Malicious Software is the direct definition, but this is not a 100% true definition because for something to be classified as malware it does not have to be a program it can even an internet cookie of which some can be classified as malware. So you will be thinking that is great and all but how is something determined as malware. The answer to that is simple malware is basically any form of file/program/cookie anything that you can find that causes damage to your computer or data. You can look at it like this if you have downloaded a program from an unknown website and your computer start's slowing down or it downloads other programs without your consent that is malware. It is difficult to give a good analogy for it so if the above analogy does not make any sense disregard it.

    How Do I Prevent Malware From Getting On My Computer? Free version

    The most security you will ever get for free will have a set up like this.
    Go here and download avast antivirus
    Go here and download Comodo firewall
    Optional Can conflict with bad updates.
    Antispyware

    These three programs if set up properly will give your computer the best security (according to testing and features) for free. Between these you have an award winning free antivirus a firewall that is known to be the best free one on the market and an antispyware that has had years of experience.

    How Do I Prevent Malware From Getting On My Computer? Paid Version

    Bitdefender Total Security 100% detection rate on av-test.org (this is not 100% safe these were the results of 2 tests)
    Firewall: This is included in the total security suite.
    Antispyware: Included with the package you can go to the above link if you want an on demand scanner,
    Read More
    Posted in 2013, malware, malware encyclopedia, security, technology | No comments
    Older Posts Home
    Subscribe to: Posts (Atom)

    Popular Posts

    • Which Internet Browser Should I Use
      Most people have heard of the big 3 or 5 internet browsers . However many of you don't know of the many other internet browsers out ther...
    • What Is Quick Scoping
      Many people in call of duty say that they are good at quick scoping, and many people don't know what this is. So in this article I will ...
    • Is Internet Explorer Safe?
      There are 3 main browsers used in the world today Microsoft's Internet Explorer. Mozilla's Firefox and Google's Google Chrome. N...
    • What Is A Black Hole
      A black hole is a theoretical concept in astrophysics that is the remains of a start after it has gone through a super nova. These are thoug...
    • Iobit Random Password Generator Review
      If you are like me and need to remember a lot of different passwords but also want them to be secure but don't know who to trust well he...
    • SpyBot Search And Destroy Review
      There are a lot of dedicated users of Spybot search and destroy, and that is because this is the only program that offers very powerful real...
    • What Is A Trojan 32 Generic?
      I got a question from someone asking what a trojan generic 32 is and I am going to explain what it is you should do to remove it and what it...
    • Securing Your Computer For Free Complete Guide
      As we all know our computers contain all sorts of important information and a lot of us can lose it all if we are not careful. You bank, sho...
    • Internet Browser Test Results
      From my last post on this issue someone pointed out that it looked like I was favoring Google Chrome. Now while I like its UI the best it sc...
    • What Is A Worm Malware Talk
      A worm is a piece of malicious code that is meant to enter computers through security exploits so that it can either gather information or e...

    Categories

    • 2013
    • 2013 Total Security
    • Android
    • Anti-Virus
    • antivirus
    • Apple
    • Asynchrony
    • Bitdefender
    • Bitdefender Wallet
    • Blackberry
    • Car dealership
    • cloud storage
    • CNET
    • Computer Support
    • computers
    • coupons
    • CX
    • Data loss
    • Direct selling
    • Download
    • Editor's Choice
    • forums
    • free software
    • Gamer
    • gaming
    • general
    • Google
    • HTML
    • internet
    • Internet access
    • ios 6 jailbreak
    • iOS 6.1 Jailbreak Tweaks
    • Jumpshot
    • LeBron James
    • Linux
    • Loader (computing)
    • loading
    • malware
    • malware encyclopedia
    • Miami Heat
    • Microsoft
    • Mobile security
    • Nokia
    • PageSpeed
    • Personal computer
    • Play Station 4
    • Product Reviews
    • Program
    • Programming
    • science
    • Searching
    • security
    • Servers
    • Shareware
    • SONY
    • technology
    • Tesla
    • Tesla Motors
    • top 5 ios
    • top 5 ios 6 cydia tweaks
    • Trade
    • videogames
    • Web page
    • Website
    • White House
    • Windows
    • Windows 8
    • Windows Update
    • worm
    • Xbox
    • Xbox 360
    • Xbox One
    • Yahoo
    • Youtube

    Blog Archive

    • ▼  2013 (170)
      • ▼  September (15)
        • CEO Steve Ballmer Goes Out With A Song
        • Youtube Comments Block List
        • Why Are Apple fans So Devoted?
        • Should Blackberry Sell?
        • Microsoft Joins Other Tech Companies With Buybacks
        • Can Creating Your Own Encryption Keys Prevent NSA ...
        • Google To Ditch Cookies For Advertising
        • Microsoft To Buy Nokia's Phone Division
        • Google Street View Car In Three Seperate Accidents
        • Advanced Systemcare 7 Beta
        • Nokia Android Phone Was Real
        • Google Passwords Are Dead
        • Google To Be Sued Over Privacy Issues
        • Microsoft And Google To Sue The NSA
        • Google Watches Employee Snack Habit
      • ►  August (13)
      • ►  July (13)
      • ►  June (16)
      • ►  May (29)
      • ►  April (28)
      • ►  March (30)
      • ►  February (22)
      • ►  January (4)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile