Expert Virus Removal Services and Technical advice.

We are Providing Computer users with Expert Virus Removal Services and Technical Advice.

Threats and their Removal.

Do you need a quick solution to a technical problem? With our live remote-assistance tool, a member of our support team can view your desktop and share control of your mouse and keyboard to get you on your way to a solution.

Spywares and their Removal.

Are you worried that your computer might be nfected with Spywares? Then this is were you can find Support.

Advices for Protecting the Computer.

Expert Advices for Protecting your computer from attacks from all threats

Different Anti Virus Software and Tools.

Familiarizing different Anti Virus Software and removal Tools.

January 7, 2011

ADW_THREAT.C

Adware is software that displays advertising banners on Web browsers such as Internet Explorer and Mozilla. While not categorized as malware, many users consider adware invasive. Adware programs will display pop-ups on a system which are annoying popup ads and, in some instances, the degradation in either network connection or system performance where they will take over the network on the system. They are bundled with certain free software online as well. They are also often installed in tandem with spyware programs and both programs feed off of each other's functionalities - spyware programs profile users' Internet behavior, while adware programs display targeted ads that correspond to the gathered user profiles.
Pop-Ups of different Ads

Preventing DNS poisoning

DNS poisoning could lead to crime ware by Identity theft, purchasing a fake anti-virus, getting unwanted malware without knowledge. These could lead to severe consequences like taking the punishment for someone else's crime.

Preventing DNS poisoning:
The First thing we can do to prevent DNS poisoning is to make sure that we have the latest version of DNS. DNS based on BIND 9.3.x or Microsoft Windows Server 2003 is far more secure than DNS implemented with earlier versions.
Recursive queries should be limited to internal DNS servers. If Internet facing recursive queries are required, only queries from internal addresses should be accepted. This will help prevent outside systems from sending queries with malicious intent.


Many cache poisoning attacks can be prevented on DNS servers by trusting the information to a lesser extent passed to them by other DNS servers, and ignoring any DNS records passed back which are not directly relevant to the query. We can use cryptography help to help secure our DNS servers from being poisoned.

Adding additional security to the LAN with the encrypting technology like DNSSEC where it uses cryptographic electronic signatures signed with a trusted public key certificate to determine the authenticity of data. DNSSEC can counter cache poisoning. Clearing the cookies when we go to any particular suspicious site having a good firewall, Updating the Internet Security Definitions regularly will help mitigate the poisoning.
  • Use TSIG to digitally signed zone transfers and zone updates – one of the best ways to prevent poisoning is to force identification of the sending authoritative source
  •  Restrict dynamic DNS updates when possible
  • Hide the version of BIND being used on the DNS servers 
  • Remove unnecessary services running on the DNS servers and use dedicated appliances instead of multi-purpose servers that allow unauthenticated Server queries
  • Physically separate external and internal DNS servers
  • Restrict Zone transfers.

Consequences of Cache Poisoning

There are several risks that will result in DNS poisoning. Since the DNS server's cache is poisoned it will have many things attached to it. Pharming is the primary risk associated with cache poisoning which means it means a site will be redirected to a different site that has full access of Attacker.Four reasons why crackers employ pharming are identity theft, distribution of malware, dissemination of false information, and man-in-the-middle attacks.


January 6, 2011

DNS is abbreviation of Domain Named System which helps in changing the IP addresses to names given to their respective domain names. This avoids the task of remembering numerous IP addresses that are there in the world. Its poisoning means the compromise occurs when data is introduced into a DNS name server's cache database that did not originate from authorized DNS sources. It may be a deliberate attempt of a maliciously crafted attack on a named server.When a DNS server has received such non-authentic data and caches it for performance optimization, it is considered poisoned, supplying the non-authentic data to the clients of the server.Domain Named Server translates a domain name in to an IP address that Internet hosts use to  contact Internet Resources of that particular domain.If a DNS server is poisoned, it may return an incorrect IP address, diverting traffic to another computer.

SCADA systems under attack by STUXNET

Stuxnet, a multi- component infection that has a worm, a worm assisting file and a rootkit that assists the worm in implementing the routines has infected SCADA systems in a typical way. The nature of Stuxnet itself reveals that it is not intended to affect home users or common domestic users. Worm_Stuxnet.A has looks for legitimate dll file S7OTBXDX.DLL which is used by Siemens WinCC systems in windows systems folder and renames it to S7OTBXSX.DLL then drops its copies in it and replaces the original file.

Stuxnet.A and propagation

Idt is basically a malware that finds the vulnerabilities in Microsoft windows and executes its routines that spreads through networks and removable drives. It has different names WORM_STUXNET.A, LNK_STUXNET.A, RTKT_STUXNET.A. It is programmed to target specific infrastructures which has raised many people's interest in this Particular malware.

WORM_DOWNAD.AD

This is yet another worm that affects removable drives by dropping copies of itself in its way of propagation. It affects the computers by locating the vulnerabilities and propagates through networks and further making it available for users on network. The main job of it is to hide file processes and registry entries on the computer that it affects.

Related Posts Plugin for WordPress, Blogger...

Search This Blog

Followers

Categories

Twitter Delicious Facebook Digg Stumbleupon Favorites More