Expert Virus Removal Services and Technical advice.

We are Providing Computer users with Expert Virus Removal Services and Technical Advice.

Threats and their Removal.

Do you need a quick solution to a technical problem? With our live remote-assistance tool, a member of our support team can view your desktop and share control of your mouse and keyboard to get you on your way to a solution.

Spywares and their Removal.

Are you worried that your computer might be nfected with Spywares? Then this is were you can find Support.

Advices for Protecting the Computer.

Expert Advices for Protecting your computer from attacks from all threats

Different Anti Virus Software and Tools.

Familiarizing different Anti Virus Software and removal Tools.

Showing posts with label Trojans. Show all posts
Showing posts with label Trojans. Show all posts

March 24, 2011

MBR Viruses.



MBR is master boot record, the first sector of a data storage device. It is used for partition tables or OS loading programs such as LILO or Grub.

March 8, 2011

FixTDSS Tool.


FixTDSS is designed to remove the infections of Backdoor.Tidserv and Tidserv variants.

January 28, 2011

Types of Botnet Attacks

Bot net is a like a robot that sends some codes to remote user as requested by him. It first scans the computer or network for different vulnerabilities and it will use different types of attack . And we have seen what


  • Denial-of-service attacks where multiple systems autonomously access a single Internet system or service in a way that appears legitimate, but much more frequently than normal use and cause the system to become busy.
  • Adware exists to advertise some commercial entity actively and without the user's permission or awareness, for example by replacing banner ads on web pages with those of another content provider.
  • Spyware is software which sends information to its creators about a user's activities – typically passwords, credit card numbers and other information that can be sold on the black market. Compromised machines that are located within a corporate network can be worth more to the bot herder, as they can often gain access to confidential information held within that company. There have been several targeted attacks on large corporations with the aim of stealing sensitive information, one such example is the Aurora botnet.
  • E-mail spam are e-mail messages disguised as messages from people, but are either advertising, annoying, or malicious in nature.
  • Click fraud is the user's computer visiting websites without the user's awareness to create false web traffic for the purpose of personal or commercial gain.
  • Access number replacements are where the botnet operator replaces the access numbers of a group of dial-up bots to that of a victim's phone number. Given enough bots partake in this attack, the victim is consistently bombarded with phone calls attempting to connect to the internet. Having very little to defend against this attack, most are forced into changing their phone numbers.
  • Fast flux is a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies.
Measures to prevent it:


  • The most serious preventive measures utilize rate-based intrusion prevention systems implemented with specialized hardware.
  • Removing services that provide reference points to botnets can cripple an entire botnet.
  • Updating the Operating system that will avoid or fill all the vulnerabilities will also prevent botnets.
  • You may go to opt for products like Norton Anti-Bot and other products given by different anti-virus companies will help in removing the botnets.


January 25, 2011

Removal of NETSKY


This is a Email virus that comes in email attachments and just opening the email will affect the system.We have to find the malware program first. There are many automatic cleaner programs from Trend Micro, Symantec, or Kaspersky etc but preferably manual removal will give us a better cleaning of the file.

January 15, 2011

Back Door

A backdoor in a compurwe system is a method of bypassing normal authentication, securing remote access to a computer, obtaining access to plaintext, and so on, while attempting to remain undetected. The backdoor may take the form of an installed program or may subvert the system through a rootkit.


WHAT IS BACKDOOR?
A backdoor is a malicious computer program or particular means that provide the attacker with unauthorized remote access to a compromised system exploiting vulnerabilities of installed software and bypassing normal authentication. A backdoor works in background and hides from the user. It is very similar to a virus and therefore is quite difficult to detect and completely disable. A backdoor is one of the most dangerous parasite types, as it allows a malicious person to perform any possible actions on a compromised computer. The attacker can use a backdoor to spy on a user, manage files, install additional software or dangerous threats, control the entire system including any present applications or hardware devices, shutdown or reboot a computer or attack other hosts. Often a backdoor has additional harmful capabilities like keystroke logging, screenshot capture, file infection, even total system destruction or other payload. Such parasite is a combination of different privacy and security threats, which works on its own and doesn’t require to be controlled at all.

Most backdoors are autonomic malicious programs that must be somehow installed to a computer. Some parasites do not require the installation, as their parts are already integrated into particular software running on a remote host. Programmers sometimes left such backdoors in their software for diagnostics and troubleshooting purposes. Hackers often discover these undocumented features and use them to break into the system.

Generally speaking, backdoors are specific trojans, viruses, keyloggers, spyware and remote administration tools. They work in the same manner as mentioned viral applications do. However, their functions and payload are much more complex and dangerous, so they are grouped into one special category.



WAYS OF INFECTION
Only few backdoors are able to propagate themselves and infect the system without user knowledge. Most parasites must be manually installed as any other software with or without user consent. There are four major ways unsolicited threats can get into the system.

1. Typical backdoors can be accidentally installed by incautious and unaware users. Some backdoors come attached to e-mail messages or are downloaded from the Internet using filesharing programs. Their authors give them unsuspicious names and trick users into opening or executing such files.
2. Backdoors often are installed by other parasites like viruses, trojans or even spyware. They get into the system without user knowledge and consent and affect everybody who uses a compromised computer. Some threats can be manually installed by malicious local users who have sufficient privileges for the software installation. Few backdoors are able to spread by exploiting remote systems with certain security vulnerabilities.
3. Several backdoors are already integrated into particular applications. Even legitimate programs may have undocumented remote access features. The attacker needs to contact a computer with such software installed in order to instantly get full unauthorized access to the system or take over control over certain software.
4. Some backdoors infect a computer by exploiting certain software vulnerabilities. They work similarly to worms and automatically spread without user knowledge. The user cannot notice anything suspicious, as such threats do not display any setup wizards, dialogs or warnings.

Widely spread backdoors affect mostly computers running Microsoft Windows operating system. However, lots of less prevalent parasites are designed to work under different environments

WHAT A BACKDOOR DOES?
- Allows the intruder to create, delete, rename, copy or edit any file, execute various commands, change any system settings, alter the Windows registry, run, control and terminate applications, install arbitrary software and parasites.
- Allows the attacker to control computer hardware devices, modify related settings, shutdown or restart a computer without asking for user permission.
- Steals sensitive personal information, valuable documents, passwords, login names, identity details, logs user activity and tracks web browsing habits.
- Records keystrokes a user types on a computer’s keyboard and captures screenshots.
- Sends all gathered data to a predefined e-mail address, uploads it to a predetermined FTP server or transfers it through a background Internet connection to a remote host.
- Infects files, corrupts installed applications and damages the entire system.
- Distributes infected files to remote computers with certain security vulnerabilities, performs attacks against hacker defined remote hosts.
- Installs hidden FTP server that can be used by malicious persons for various illegal purposes.
- Degrades Internet connection speed and overall system performance, decreases system security and causes software instability. Some parasites are badly programmed, they waste too much computer resources and conflict with installed applications.
- Provides no uninstall feature, hides processes, files and other objects in order to complicate its removal as much as possible.


EXAMPLES OF BACKDOORS
There are lots of different backdoors. The following examples illustrate how functional and extremely dangerous these parasites can be.

Litebot is a backdoor that allows the remote attacker to download and execute arbitrary files from the Internet. The parasite decreases overall system security by changing default Windows firewall settings. Litebot main files have random names, so it is quite difficult to detect and get rid of. The backdoor automatically runs on every Windows startup.

Remote connection, also known as RedNeck, is a dangerous backdoor that gives the intruder full access to a compromised system. The parasite can shutdown or restart a computer, manage files, record user keystrokes, install and run various programs, take screenshots and perform other malicious actions.

Tixanbot is an extremely dangerous backdoor that gives the remote attacker full unauthorized access to a compromised computer. The intruder can manage the entire system and files, download and install arbitrary applications, update the backdoor, change Internet Explorer default home page, attack remote hosts and obtain system information. Tixanbot terminates running essential system services and security-related processes, closes active spyware removers and deletes registry entries related with firewalls, antivirus and anti-spyware software in order to prevent them from running on Windows startup. The parasite also blocks access to reputable security-related web resources. Tixanbot can spread. It sends messages with certain links to all MSN contacts. Clicking on such a link downloads and installs the backdoor.

Resoil FTP is a backdoor that gives the hacker remote unauthorized access to an infected computer. This parasite runs a hidden FTP server, which can be used to download, upload and run malicious software. Resoil FTP activity may result in noticeable computer performance loss and user privacy violation.

CONSEQUENCES OF A BACKDOOR INFECTION
A backdoor allows the attacker to work with an infected computer as with its own PC and use it for various malicious purposes or even criminal offences. The responsibility for such activity is usually assumed by guiltless users on which systems backdoors were installed, as in most cases it is really hard to find out who was controlling a parasite.

Practically all backdoors are very difficult to detect. They can violate user privacy for months and even years until the user will notice them. The malicious person can use a backdoor to find out everything about the user, obtain and disclose priceless information like user’s passwords, login names, credit card numbers, exact bank account details, valuable personal documents, contacts, interests, web browsing habits and much more.

Backdoors can be used for destructive purposes. If the hacker was unable to obtain any valuable and useful information from an infected computer or have already stole it, he eventually may destroy the entire system in order to wipe out his tracks. This means that all hard disks would be formatted and all the files on them would be unrecoverably erased.

HOW TO REMOVE A BACKDOOR?
Backdoors work in the same manner as the computer viruses and therefore can be found and removed with the help of effective antivirus products like Symantec Norton AntiVirus, Kaspersky Anti-Virus, McAfee VirusScan, eTrust EZ Antivirus, Panda Titanium Antivirus, AVG Anti-Virus. Some advanced spyware removers, which are able to scan the system in a similar way antivirus software does and have extensive parasite signature databases can also detect and remove certain backdoors and related components. Powerful anti-spyware solutions such as Spyware Doctor and Microsoft AntiSpyware Betaare known for quite fair backdoor detection and removal capabilities.

In some cases even an antivirus or spyware remover can fail to get rid of a particular backdoor. That is why there are Internet resources such as 2-Spyware.com, which provide manual malware removal instructions. These instructions allow the user to manually delete all the files, directories, registry entries and other objects that belong to a parasite. However, manual removal requires fair system knowledge and therefore can be a quite difficult and tedious task for novices.

January 8, 2011

Backdoor.Tidserv Removal Tool

Backdoor.Tidserv is a trojan virus that sneaks onto your PC through security exploits and allows remote unauthorized access to your computer by creating a backdoor port. Backdoor.Tidserv may also modify various Windows system tools in order to prevent you from removing the threat and running virus checks. The tool is designed to remove the infections of Backdoor.Tidserv 
How to download and run the removal tool: 
You must have administrative rights to run this tool on Windows XP, Windows Vista, or Windows 7.


  1. Download the FixTDSS.exe file from: http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixTDSS.exe 

     
Save the file to a convenient location, such as your Windows desktop.
Close all running programs.
If you are running Windows XP, turn off System Restore.
Locate the file that you just downloaded.
Double-click the FixTDSS.exe file to start the removal tool.
Click Run to begin the process, and then allow the tool to run. 

Restart the computer when prompted by the tool by clicking on proceed.


After the computer has started, the tool will inform you of the state of infection.
If you are running Windows XP, re-enable System Restore.
Run LiveUpdate to make sure that you are using the most current virus definitions
When the tool has finished running, you will see a message indicating whether the threat has infected the computer.
You can kill the infection by clicking the "repair" option.

What the tool does
The Removal Tool does the following:
  • Terminates the associated processes of infection.
  • Deletes the associated files of infection.
  • Removes hidden partition unconditionally if detection occurs.

January 5, 2011

How to Remove TSPY_ZBOT.XMAS Malware Manually

For removing these type of malware we need to follow certain procedure which will be common for this family of infections. First and foremost thing is to disable system restore and do a full system scan.Then we need to remove the files dropped by the virus HTML_IFRAME.SMAX. It will be in Application Data folder. When we scan using any anti-virus program it will download


Identify and delete files detected as TSPY_ZBOT.XMAS using either the Recovery Console which needs to have a startup disc. Press R when it shows at the boot time. Go to the directory by using the command Cd "C:" (taken as an example. Go to the folder that has the infected files by using the same command. Delete the files using the command Del "filename ".

Restore the modified registry value:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

  • From: Userinit = %System%\userinit.exe,%System%\sdra64.exe, To: Userinit = %System%\userinit.exe, 
Delete  the following registry values:
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
  • EnableFirewall = 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network
  • UID = {computer name}_{23645898} 
 In HKEY_USERS\.DEFAULT\Software\Microsoft
    • Protected Storage System Provider
  • In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
    • {43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
  • In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
    • {19127AD2-394B-70F5-C650-B97867BAA1F7}
Next step is to delete the files from the system files in system folder by typing %System%\lowsec in search box.After this we need to delete the host files that are below the local host file. After all these steps do a full system scan using good Anti-Viruses like Trend Micro, Norton etc. This will completely remove the virus.

December 29, 2010

Email-Worm.Zhelatin

Anti-Virus8 is a typical rogue anti virus that installs itself on the computer and shows itself as not genuine and asks to purchase showing that there are many threats on your computer.It looks similar to AVG anti-virus and that is the reason why many people are getting to know the threat.

October 12, 2010

Threat Types

Threats to your computer system, data, and identity come in many different forms, a few of the most common are listed as follows:
Viruses:
A virus is a self-replicating program that is designed to damage or degrade the performance of a computer. A virus is replicated by being copied or by initiating its copying to another program, computer boot sector or document. Viruses can be classified into four different categories as follows:

File Infector
A File infector virus when executed on a system will seek out other files and insert its code into them. The programs with .EXE and .COM extensions are the most commonly targeted, but a file infector virus can target any executable file.
This infection is most commonly distributed via compromised networks, over the web via drive-by, or from a corrupted media (CDRW, flash media).

Related Posts Plugin for WordPress, Blogger...

Search This Blog

Followers

Categories

Twitter Delicious Facebook Digg Stumbleupon Favorites More