Expert Virus Removal Services and Technical advice.

We are Providing Computer users with Expert Virus Removal Services and Technical Advice.

Threats and their Removal.

Do you need a quick solution to a technical problem? With our live remote-assistance tool, a member of our support team can view your desktop and share control of your mouse and keyboard to get you on your way to a solution.

Spywares and their Removal.

Are you worried that your computer might be nfected with Spywares? Then this is were you can find Support.

Advices for Protecting the Computer.

Expert Advices for Protecting your computer from attacks from all threats

Different Anti Virus Software and Tools.

Familiarizing different Anti Virus Software and removal Tools.

Showing posts with label Virus Removal. Show all posts
Showing posts with label Virus Removal. Show all posts

February 1, 2011

Removal Of WORM_STRATION.FA

As this comes in the form of an attachment it is easy to identify. All we have to do is to scan the attachment with a good anti-virus product. However the manual removal involves the following things when PC is already infected.

January 22, 2011

Symptoms Of Malware

Malware is the short form of malicious software, is a software designed to secretly access a computer system without the owner's consent or knowledge. Malware includes computer viruses, worms, trojan horses, spyware, dishonest adware, scareware, crimeware, most rootkits, and other malicious and unwanted software or program that will

January 21, 2011

20th Century's Most Dangerous Infections

Viruses saw light and managed to cause serious damages to unprepared users and their machines. Millions of users downloaded computer viruses without even knowing about it. Hackers used various ways of penetrating the systems of universities from around the world, even NASA, armed Forces and Government Sites.It shows the increased level of mastery in writing virus programs, malware or hacking methods.


Jerusalem
The virus was named Jerusalem because it was identified in a Hebrew university. For the first time it was discovered in 1987 on October 1, but in 1991 antivirus experts found that Italy is the country where the first traces of the computer virus were noticed. Initially the Jerusalem virus included a bug that led to a repeat infection of the files that continued until the size of the files overcome computer resources. In addition, each Friday 13 it deleted all programs in the infected system as a result of a malicious payload that set off on the respective day. Jerusalem considerably slowed down the machine. A person could identify the virus but noticing two lines on the monitor.

 


Morris or  Internet Worm:
We wrote about this computer worm, which is believed to be one of the first worms that spread over the Internet. The name of the virus comes from its developer Robert Tappan Morris, who was a student at Cornell University. The computer worm was set off on November 2, 1988 and after some time it managed to infect 6,000 to 9,000 machines. It overloaded the whole Internet, leading to the failure of a large number of servers. According to its developer, the goal was to discover just how far and fast a computer worm can spread all over the network. Robert Tappan Morris was found guilty and sentenced to 3 years of probation along with 400 hours of community service. In addition, he had to pay a $10,000 fine.

CIH or Chernobyl:

CIH virus that caused an estimated damage of $20 to $80 million around the globe, the computer virus managed to affect huge amounts of data stored on computers. Later it was discovered that the computer virus was launched in Taiwan. It has been recognized to be one of the most dangerous computer viruses in history that has infected Windows 95, 98, and ME executable files. In addition, CIH remained resident in the memory of the machine, being able to carry on infecting other executables. After being activated, the virus overwrote data on the HDD of the infected PC, making the latter inoperable. CIH could also overwrite the BIOS of the infected computer, thus preventing boot-up. The second name of the virus - Chernobyl - was given because some of the biggest damages occurred on the day when the nuclear reactor exploded.

Solar Sunrise :
It is the name of the situation that occurred in 1998 when a team of hackers managed to take control of more than 500 computer system of the army, government as well as private sector of the United States. The name Solar Sunrise comes after the well-known vulnerabilities in machines that run on the Sun Solaris OS. At first the attack was believed to have been organized by hackers from Iraq, but later it was discovered that the ones to blame were two American youngsters from California.


Barrotes - 1993:
This is believed to be the first popular computer virus developed in Spain. As soon as it infected the system, it would remain there until January the 5th, when it would set off showing a series of bars on the screen. It infected .COM, .EXE and overlay files. The Barrotes computer virus represents a resident virus - it becomes a resident of the computer memory each time the machine starts up. Due to a series of vertical lines that appear on the monitor, it was easy to identify the virus. It could also overwrite the Master Boot Record of the HDD, thus making it impossible for the uses to access the hard disk.

There are many more viruses that are dangerous and damages the system very badly. We need to get a good anti-virus that has good search engine and which updates regularly and protects our computer.

January 20, 2011

Dangerous Things On Web

There are list of topics that will download viruses without our knowledge.There are list of threats or dangerous places by going where you may download unwanted infections.

WORM_DOWNAD.KK

This is the latest variant of Worm_Downad.It exploits software vulnerabilities to propagate to other computers across a network. This Worm may be downloaded by other malware/grayware/spyware from remote sites. It may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites.

January 17, 2011

New Tax Scams

Phishers have gotten pretty sophisticated in their ability to create convincingly authoritative-looking web sites and email communications and lookout for phony emails warning you that your tax credit, tax refund, or other tax-related treat is in dire peril unless you go to a web site and divulge all your personal information. If you're ever tempted to respond to such an email, just remember that the IRS does not send out tax-related communications by email. Here's a new phishing scam to look out for—and a good way to recognize any phishing email.


A recent scam targets taxpayers who use the Electronic Federal Tax Payment System, or EFTPS, to make federal tax payments online. It follows a known format which tell victims that a payment can't or won't be processed until they provide additional information about themselves, please don't respond to those mails. EFTPS won't send any such information in the middle if you have already started paying them. It needs details in the beginning but not in any time after you have already started paying the tax. However, many scammers reside overseas and still haven't mastered English.Their misspellings, Poor grammar, or strange phrases are usually a means for a scam.

Many Anti-Virus companies warned users of a spam campaign that targeted U.S. taxpayers with Foreign Bank and Financial accounts. The spammed message includes the subject, "Notice of Under reported Income," and lures users to click the link that supposedly contains the tax statement. Users who click the URL are re-directed to a site where they get infected by various ZBOT variants, notorious for stealing information.

Please be careful and make your money safe and help governments to safegaurd you from those fraudsters and spammers stealing your money, attacking your computers and stealing your personal information.

Summary:
  • You will get an email from a look alike site of Electronic Federal tax Payment System stating that there is some information you need to fill to pay the tax. 
  • Don't click on those links, they will bring severe threats on to your computer that will steal your personal information and many things that you won't even expect.



<!--fad9b86e6c234aaf905f232cfd7e289c-->

January 15, 2011

Back Door

A backdoor in a compurwe system is a method of bypassing normal authentication, securing remote access to a computer, obtaining access to plaintext, and so on, while attempting to remain undetected. The backdoor may take the form of an installed program or may subvert the system through a rootkit.


WHAT IS BACKDOOR?
A backdoor is a malicious computer program or particular means that provide the attacker with unauthorized remote access to a compromised system exploiting vulnerabilities of installed software and bypassing normal authentication. A backdoor works in background and hides from the user. It is very similar to a virus and therefore is quite difficult to detect and completely disable. A backdoor is one of the most dangerous parasite types, as it allows a malicious person to perform any possible actions on a compromised computer. The attacker can use a backdoor to spy on a user, manage files, install additional software or dangerous threats, control the entire system including any present applications or hardware devices, shutdown or reboot a computer or attack other hosts. Often a backdoor has additional harmful capabilities like keystroke logging, screenshot capture, file infection, even total system destruction or other payload. Such parasite is a combination of different privacy and security threats, which works on its own and doesn’t require to be controlled at all.

Most backdoors are autonomic malicious programs that must be somehow installed to a computer. Some parasites do not require the installation, as their parts are already integrated into particular software running on a remote host. Programmers sometimes left such backdoors in their software for diagnostics and troubleshooting purposes. Hackers often discover these undocumented features and use them to break into the system.

Generally speaking, backdoors are specific trojans, viruses, keyloggers, spyware and remote administration tools. They work in the same manner as mentioned viral applications do. However, their functions and payload are much more complex and dangerous, so they are grouped into one special category.



WAYS OF INFECTION
Only few backdoors are able to propagate themselves and infect the system without user knowledge. Most parasites must be manually installed as any other software with or without user consent. There are four major ways unsolicited threats can get into the system.

1. Typical backdoors can be accidentally installed by incautious and unaware users. Some backdoors come attached to e-mail messages or are downloaded from the Internet using filesharing programs. Their authors give them unsuspicious names and trick users into opening or executing such files.
2. Backdoors often are installed by other parasites like viruses, trojans or even spyware. They get into the system without user knowledge and consent and affect everybody who uses a compromised computer. Some threats can be manually installed by malicious local users who have sufficient privileges for the software installation. Few backdoors are able to spread by exploiting remote systems with certain security vulnerabilities.
3. Several backdoors are already integrated into particular applications. Even legitimate programs may have undocumented remote access features. The attacker needs to contact a computer with such software installed in order to instantly get full unauthorized access to the system or take over control over certain software.
4. Some backdoors infect a computer by exploiting certain software vulnerabilities. They work similarly to worms and automatically spread without user knowledge. The user cannot notice anything suspicious, as such threats do not display any setup wizards, dialogs or warnings.

Widely spread backdoors affect mostly computers running Microsoft Windows operating system. However, lots of less prevalent parasites are designed to work under different environments

WHAT A BACKDOOR DOES?
- Allows the intruder to create, delete, rename, copy or edit any file, execute various commands, change any system settings, alter the Windows registry, run, control and terminate applications, install arbitrary software and parasites.
- Allows the attacker to control computer hardware devices, modify related settings, shutdown or restart a computer without asking for user permission.
- Steals sensitive personal information, valuable documents, passwords, login names, identity details, logs user activity and tracks web browsing habits.
- Records keystrokes a user types on a computer’s keyboard and captures screenshots.
- Sends all gathered data to a predefined e-mail address, uploads it to a predetermined FTP server or transfers it through a background Internet connection to a remote host.
- Infects files, corrupts installed applications and damages the entire system.
- Distributes infected files to remote computers with certain security vulnerabilities, performs attacks against hacker defined remote hosts.
- Installs hidden FTP server that can be used by malicious persons for various illegal purposes.
- Degrades Internet connection speed and overall system performance, decreases system security and causes software instability. Some parasites are badly programmed, they waste too much computer resources and conflict with installed applications.
- Provides no uninstall feature, hides processes, files and other objects in order to complicate its removal as much as possible.


EXAMPLES OF BACKDOORS
There are lots of different backdoors. The following examples illustrate how functional and extremely dangerous these parasites can be.

Litebot is a backdoor that allows the remote attacker to download and execute arbitrary files from the Internet. The parasite decreases overall system security by changing default Windows firewall settings. Litebot main files have random names, so it is quite difficult to detect and get rid of. The backdoor automatically runs on every Windows startup.

Remote connection, also known as RedNeck, is a dangerous backdoor that gives the intruder full access to a compromised system. The parasite can shutdown or restart a computer, manage files, record user keystrokes, install and run various programs, take screenshots and perform other malicious actions.

Tixanbot is an extremely dangerous backdoor that gives the remote attacker full unauthorized access to a compromised computer. The intruder can manage the entire system and files, download and install arbitrary applications, update the backdoor, change Internet Explorer default home page, attack remote hosts and obtain system information. Tixanbot terminates running essential system services and security-related processes, closes active spyware removers and deletes registry entries related with firewalls, antivirus and anti-spyware software in order to prevent them from running on Windows startup. The parasite also blocks access to reputable security-related web resources. Tixanbot can spread. It sends messages with certain links to all MSN contacts. Clicking on such a link downloads and installs the backdoor.

Resoil FTP is a backdoor that gives the hacker remote unauthorized access to an infected computer. This parasite runs a hidden FTP server, which can be used to download, upload and run malicious software. Resoil FTP activity may result in noticeable computer performance loss and user privacy violation.

CONSEQUENCES OF A BACKDOOR INFECTION
A backdoor allows the attacker to work with an infected computer as with its own PC and use it for various malicious purposes or even criminal offences. The responsibility for such activity is usually assumed by guiltless users on which systems backdoors were installed, as in most cases it is really hard to find out who was controlling a parasite.

Practically all backdoors are very difficult to detect. They can violate user privacy for months and even years until the user will notice them. The malicious person can use a backdoor to find out everything about the user, obtain and disclose priceless information like user’s passwords, login names, credit card numbers, exact bank account details, valuable personal documents, contacts, interests, web browsing habits and much more.

Backdoors can be used for destructive purposes. If the hacker was unable to obtain any valuable and useful information from an infected computer or have already stole it, he eventually may destroy the entire system in order to wipe out his tracks. This means that all hard disks would be formatted and all the files on them would be unrecoverably erased.

HOW TO REMOVE A BACKDOOR?
Backdoors work in the same manner as the computer viruses and therefore can be found and removed with the help of effective antivirus products like Symantec Norton AntiVirus, Kaspersky Anti-Virus, McAfee VirusScan, eTrust EZ Antivirus, Panda Titanium Antivirus, AVG Anti-Virus. Some advanced spyware removers, which are able to scan the system in a similar way antivirus software does and have extensive parasite signature databases can also detect and remove certain backdoors and related components. Powerful anti-spyware solutions such as Spyware Doctor and Microsoft AntiSpyware Betaare known for quite fair backdoor detection and removal capabilities.

In some cases even an antivirus or spyware remover can fail to get rid of a particular backdoor. That is why there are Internet resources such as 2-Spyware.com, which provide manual malware removal instructions. These instructions allow the user to manually delete all the files, directories, registry entries and other objects that belong to a parasite. However, manual removal requires fair system knowledge and therefore can be a quite difficult and tedious task for novices.

January 14, 2011

Manual Removal of Security Tool

Security tool which is a rogue anti-virus program that automatically scans the computer and will show fake security alerts, and induces users in to purchasing a fake anti-virus. It will disable all the windows legitimate programs and shows them as infected which actually are not.

Removal Instructions:

  • The first and foremost thing we need to do is go to safe mode with networking.
  • Kill the processes that are running in the background using MS-config or download Rkill.exe from the site www.bleepingcomputer.com or Process explorer.exe and run it. It will kill all the processes. Don't restart the computer.
  • Open Run and type  %user profile%\desktop which will open desktop and click on Iexplore.exe
  • Download the Malware Bytes and rename it as Explorer.exe while saving  which is safe and does not give any code 2 error while execution as Security tool thinks it as a Windows Process.
  • Run the tool and perform a full system scan on it. It will complete and show results like this.
Malware bytes displaying the results of Security Tool
As this infection also changes your Windows HOSTS file, we want to replace this file with the default version for your operating system. In order to protect itself, Security Tool changes the permissions of the HOSTS file so you can't edit or delete it. To fix these permissions please download the file hosts-perm.bat file and save it to your desktop.When the file has finished downloading, double-click on the hosts-perm.bat file and click Ok. We now need to delete the C:\Windows\System32\Drivers\etc\HOSTS file. Once it is deleted, download the HOSTS file that corresponds to your version of Windows and save it in the C:\Windows\System32\Drivers\etc folder and delete the Explorer.exe program from your desktop.

Security Tool

This is a very frustrating Fake Anti-virus program that keeps on showing you fake threats on the computer and asks to purhcase. Security tool is a rogue anti-spyware program from the same family as System Security which is promoted through the use of Trojans and web pop-ups.

January 13, 2011

WinCE.PmCryptic.A on Windows Smart Phone

A polymorphic Virus that changes its forms with different actions has been found recently. It is a file infector Virus that could spread by storage cards by generating new polymorphic copies of itself each time, and can cause a severe nuisance on a compromised phone including unwanted phone calls to toll numbers.

January 11, 2011

Stop Conficker from spreading by using Group Policy

 This procedure does not remove the Conficker malware from the system. This procedure only stops the spread of the malware.

Create a new policy that applies to all computers in a specific organizational unit (OU), site, or domain, as required in your environment.

Norton Power Eraser

Is your computer infected with Scareware or rogueware or Scamware which tricks users to buy their anti-virus or security products by showing false warnings and these products makes your system unstable and shows scary warnings which user may never dreamt of, Norton Power Eraser portable tool from Symantec identifies and removes these Scareware from your Computer.

December 28, 2010

Sality Virus

Sality is a family of file infecting viruses that spread by infecting executable files, it runs an autorun worm component that allows it to spread to any removable or discoverable drive. In addition, Sality includes a downloader trojan component that installs additional malware via the Web. So it is a combination of many infections bundled to damage the computer software.  

It will infect executable files on local, removable and remote shared drives. The virus also creates a peer-to-peer (P2P) botnet and receives URLs of additional files to download. It then attempts to disable security software on the computer. It also has key logging functionality . Sality generally drops a .cmd, .pif, and .exe to the root of discoverable drives or removable drives, along with an autorun.inf file which contains instructions to load the dropped file(s) when the drive is accessed. Updates to the malware that is dropped by it are fed via decentralized lists of HTTP URLs.


Removing Sality Virus: 

  • Take a registry back up and create a restore point to be on safe side.
  • Unregister the file using the command in command prompt Unregsvr32 vcmgcd32.dll
  • Remove the file vcmgcd32.dll by searching it using the search option.
  • Remove the "Virus.Sality.U" components:
  • BwUnin-6.1.4.36-8876480L.exe, syslib32.dll, sysdll.dll, oledsp32.dll and all the files those are associated with that file.

This will remove the virus Virus.Sality.U from the virus.

December 25, 2010

SYMPTOMS OF SALITY VIRUS

 
Sality virus is one of its kind; very dangerous and infective. It attacks all the system file components like windows task manager and registry. It is the most important part where we need to take care of as registry values are like wheels of a vehicle, if they get corrupted we may not be able to use the computer as similarly as we cannot use the vehicle if the tires go flat. 

"Here you have" Virus

''Here You Have'' is one of the widely spread viruses on the internet these days. It comes as an email to inbox and states like  as the subject  "Subject: Here you have or Just for you". It is also called

W32/VBMania@MM  


December 24, 2010

REMOVING VIRUS FROM PENDRIVES




Preventing the virus from entering the PC:
There are some common things that we need to take note of while using a pen drive/ Flash Drive/ Thumb Drive. People use Flash drives for copying data, often the date would be documents or executable files or movies and so on.
 
  • One can copy the files directly to prevent the virus that attacks folders mostly in a portable drive. That is the first important thing we need to keep in mind.
  • Secondly while opening the PD (portable drive) we should not use the autorun to open it directly. We first need to scan the PD using any good anti- virus before opening it.
  • If we find any infections we can fix them. If not fixed if they are skipped or avoided from scanning then we cannot open the PD as usual.


REMOVING IT:

Command prompt can be used for removing virus from pen drive with some familiar and basic CMD commands.

  •  Go to Command prompt by clicking on Start Run or by pressing windows logo button + R.   Type the drive letter of the pen drive with a colon following it
  •  Then type DIR/A. Check all the files and folders displayed in the list especially for AUTORUN,           RECYCLER and any .exe files which you don't expect in it.
  • Type ATTRIB *.* -S -R -H to unhide all hidden and system files.
  • Then delete the suspected files one by one using the command DEL FILENAME.EXT. This will delete the files from the drive.
  •  Repeat this process for all the folders in that drive.

This will remove the virus from the pen drive for sure.

Note: Never open the files in the pen drive when you have downloaded the files from Internet Cafe directly from windows explorer, cause they are the most important and dangerous places from where we get the infections.

Uninstalling an Anti-virus using removal tools:

REMOVAL TOOLS:

Any anti-virus has got some settings and files installed on different folders in computer. So today we will learn how to uninstall an anti-virus using different uninstalling utilities for different companies. Before we look into it we will need to know why we need to use the utilities to uninstall them using utilities.
Reason why we need to uninstall Anti-virus using tools is to make sure that there are no left over files in registry which cause some problems when we install another anti-virus. If there are more than one anti-virus on the system they will give raise to conflicts among themselves and none of them work.
So to protect our PC from infections and to have a clean one and only one security application we need to use the removal tools to uninstall them.

Names of few tools to uninstall different security programs:

  • Norton removal tool
  • McAfee consumer product removal tool
  • Avast uninstall utility
  • Removal tool for Kaspersky products
  • Avg remover
  • Bit defender uninstall tool

These removal tools will help us in removing the anti-virus that we have installed completely from the computer that will help in installing any other anti-virus programs without any problem.


These are operating system independent. That means they work in XP, vista as well as in win7. Sometimes we need to remove the toolbars that we get along with these full programs. For eg. Panda Anti-Virus Firewall 2010 uninstall tool. Norton Online family, Norton online back and so on these have to be uninstalled separately from either add or remove programs or using concerned removal tools.

Virus in RFID

VIRUS THAT HAS INFECTED MAN:

There has been a recent attack on a RFID chip implanted into Dr Mark Gasson’s left wrist by a virus. He gave an interview to BBC world news about the same and its effects.
There are many things we can do with a RFID chip. We can communicate with our mobile phone, we can gain access to our organization we work for and so on. If the chip we use to get access to the machines gets infected there are chances that the machines we show the RFID chip will get infected as well like mainstream computers.

An RFID chip means Radio Frequency Identity which will be embedded into human body to access like it is being done to animals. It is going to be a revolution in future; everyone will be having a RFID chip with all their personal details fed in to it. It may replace SSID to have advanced tracking system.

The virus that has infected the chip that Dr Mark Gasson has implanted into his hand is infecting all the machines that he is accessing using that. BBC news asked how well they infect the devices or computers that he accesses. Medical implants are prone to viruses as the implanting technology has developed to a point where they are capable of communicating, storing, and manipulating data. So technology has to keep pace with the new viruses that are being invented daily and should secure themselves from viruses.

December 23, 2010

Bom Samado Worm

Are you having GOOD SATURDAY WORM:

Is your orkut safe? Did your friends complain about scraps that are being sent to them with a name Bom Sabado, which means GOOD SATURDAY in Portuguese, that they are receiving regularly from your account? If you are experiencing this issue this means your Orkut account is being infected with this severe virus/worm. It has attacked the cross site scripting of the orkut site and has spread its presence.

ANDROID FAKE PLAYER-VIRUS

Android Fake Player:

A new virus was found with the phones using Android operating system, that is called Trojan SMS . This virus works by sending a premium SMS, which is very dangerous, once received corrupts the entire phone. Application of this virus is about 13 KB and will be active when the user is running the media player application. When running this file users will be approved or not activated when the Trojans has just started to attack.

Related Posts Plugin for WordPress, Blogger...

Search This Blog

Followers

Categories

Twitter Delicious Facebook Digg Stumbleupon Favorites More