Archive for the ‘Anti Virus Software’ Category

Beware Fake Swine Flue Alert Scam Email

Dramatically Improve The Performance Of Your Computer And Make It Run Like New Using FREE Tools

Hackers are using fake alerts using the Swine Flu as bait to snare unwary computers users into installing malware.

This latest malware scare uses the H1N1 virus with email messages offering information regarding the Swine Flu vaccination. These email messages contain links to fake disease control centre and prevention sites and prompt the user to create a user account, during which the user’s computer will be infected with malware.

Here is the CERT advisory with some examples or the email subject line.

The scam email lures users into believing they are part of a state wide H1N1 vaccination process and are required to create a vaccination profile on the Disease Control web site.

Within the scam email there is a link that takes you to a very convincing CDC web site where you are given an ID and link to your vaccination profile. This link is actually an executable file with a Trojan that once installed will create a security free gateway on the computer and will install malware without the users authorization or knowledge.

Panda Burning Incense worm due to make a dramatic return as China warns of mass Internet virus

Dramatically Improve The Performance Of Your Computer And Make It Run Like New Using FREE Tools

According to McAfee a new worm that China has warned internet users about is a new version of the Panda Burning Incense Worm that did the rounds 2006. This latest variant has a malicious payload that the original did not that makes it harder to detect.

This version contains a root kit which makes it far more difficult to detect and even to know that the system has been infected.

The first Panda worm became notorious for changing the icons of infected files to an image of a panda holding 2 incense sticks. This image would also flash across the screen, but the worm actually installed a Trojan that stole passwords. This worm infected millions of computers across the world.

The national virus response center in China has issued a warning about a new variant of this worm. The new variant of the Panda worm will block infected users from restoring infected files, will turn off the antivirus software on the pc and connect to web sites to download Trojans.

Another Worm Targeting the iPhone Has Been Discovered by Security Company F-Secure

Worm:iPhoneOS/Ikee.B

This worm is affecting users in a number of counties, and is financially motivated as it looks for financial information stored on the iPhone.  IPhones with the worm are being redirected to a lookalike site with a logon screen.

The worm only affects iPhone’s that have been modified by the user so they can run non apple applications, otherwise known as “jail broken”. The iPhone’s must also have SSH installed and be using the factory default SSH password of “alpine”. SSH is used so that services can connect to the iPhone remotely and is used by the worm to spread.  The worm will change the default SSH password to “ohshit”. The default password for SSH should be changed if you have this installed on your iPhone.

If your IPhone has not been “jail broken”, does not have SSH installed, or if the SSH default password has been changed if it is installed, will not be affected by this worm.

When the iPhone becomes infected it will connect to a server and further malware is installed. It then sends banking information stored in SMS messages on the iPhone to a control server and changes the SSH default password from “alpine” to “ohshit”.

For clarification to be vulnerable to this worm the iPhone must be “jail broken” and have SSH installed and have the default SSH password of “alpine”.

While the worm is active the infected iPhone will scan for other vulnerable handsets via WI-FI and 3G networks. When one is found it will infect that iPhone.

To disinfect an iPhone restore the handset firmware via Apple  iTunes.

What is a computer virus?

A computer virus is a piece for computer code that is able to replicate itself whilst carrying out another instruction. Computer viruses are not able to replicate on their own, they need to assistance of humans, i.e. computer user, to be able to perform their function.

Computer viruses will carry out any instruction the writer has programmed the virus to do. This can be harmful as in the Chernobyl virus, where it can destroy the contents of your hard drive and over write the computer BIOS making your computer completely unusable, or they can be programmed to find private details from your computer and send this back to the author.

This private information can be passwords to accounts, credit card information and banking details. The writers of viruses toady generally are after financial gain, but this was not always the case. Early viruses would merely put a message across your computer screen or perhaps make a noise when you typed.

As mentioned earlier, a virus must be unwittingly activated by computer user and they cannot do anything without human intervention. The virus is an executable file that runs its code when run by a computer user.

The virus is commonly sent via email and can look like a normal Word document for example. This is because the virus writer has added the Microsoft Word document extension on to the end of the file, this file would actually be in the format of ‘filename.exe.doc’, thus your email client and indeed Microsoft Windows would display the icon as a Microsoft Word document. However when the user clicks on the file Windows would run it as an executable file (.exe) and run the virus code on the computer.

The virus would then carry out its instructions and replicate itself by adding its code to documents in the now infected computer, or perhaps email itself automatically to all the contacts in the infected computers address book. The infected files would then be used by other users, and when they opened the document on their computer, the virus would run the code and also infect that computer.

Viruses can be stopped from running by using a good antivirus program on your computer that updates regularly. It is absolutely essential to use anti virus software as you will very soon be infected without one. There millions of infected computers on the internet today, make sure yours in not one of them.

Technorati Tags: , , , ,