Stealth Virus

Posted: Kamis, 29 April 2010 by VIruS Of WinDoWS in Label:
0

Spotting the Stealth Virus

By nature, a computer virus must modify something in the host system in order for it to become active. This may be a specific file, a boot sector, or a partition sector, more commonly known as a MBR (Master Boot Record). Regardless of what it is, it must be modified in some type of way. Unless the infection takes control of portions in the system to manage accesses to modifications that have been made, the changes will typically become visible, leaving the virus exposed. This very nature has led writers to design malicious codes that are for more elusive.

Understand the Stealth Virus

A stealth virus is one that conceals the changes it makes. This is done by taking control of system functions that interpret files or system sectors. When other applications request data from portions of the system modified by the virus, the infection reports back the accurate, unchanged data, instead of the malicious code. In order for this to occur, the virus must be actively present in the memory.

An example of a stealth infection is Brain, the very fist DOS virus. Brain is a system infector that begins by monitoring physical disks. It then redirects all attempts to read an infected sector to sections on the disk where the original, uninfected boot sector is located. Other viruses to follow this trend were Frodo and the Number of the Beast, two viruses classified as file infectors.

How the Stealth Virus Works

It is important to know that many viruses not only hide, but encrypt the original data they have infected. Some victims may use traditional DOS commands such as FDISK/MBR or SYS to fix the problem, an instance that could make things much worse. If the virus is overwritten with FDISK/MBR, the hard drive will have no way to recognize what's in the partition table and cannot access the encrypted data without aid of the virus. For this reason, anti-virus software is recommended to eradicate a stealth virus rather than self maintenance.

Virus coders mainly use the stealth approach to elude virus scanners. Those that have not been designed to do so, because the malicious code is fairly new or the user's anti-virus software isn't up to date, are often described as stealth viruses as well. The stealth technique is a contributing factor to why most anti-virus programs function best when the system is booted from a clean CD or floppy disk. By doing this, the infection is not able to seize control of the system and the changes it makes can be exposed and immediately dealt with.

In general, a stealth virus will hide itself in system memory every time a program scanner is run. It employs various techniques to hide any changes so that when the scanner looks for altered sections, the virus redirects it to any area that contains the clean, uninfected data. A more advanced anti-virus program can detect a stealth virus by searching for evidence of changes within system sectors along with areas that are more susceptible to attack, regardless of how it is booted.

Stealth Virus

Posted: by VIruS Of WinDoWS in
0

Spotting the Stealth Virus

By nature, a computer virus must modify something in the host system in order for it to become active. This may be a specific file, a boot sector, or a partition sector, more commonly known as a MBR (Master Boot Record). Regardless of what it is, it must be modified in some type of way. Unless the infection takes control of portions in the system to manage accesses to modifications that have been made, the changes will typically become visible, leaving the virus exposed. This very nature has led writers to design malicious codes that are for more elusive.

Understand the Stealth Virus

A stealth virus is one that conceals the changes it makes. This is done by taking control of system functions that interpret files or system sectors. When other applications request data from portions of the system modified by the virus, the infection reports back the accurate, unchanged data, instead of the malicious code. In order for this to occur, the virus must be actively present in the memory.

An example of a stealth infection is Brain, the very fist DOS virus. Brain is a system infector that begins by monitoring physical disks. It then redirects all attempts to read an infected sector to sections on the disk where the original, uninfected boot sector is located. Other viruses to follow this trend were Frodo and the Number of the Beast, two viruses classified as file infectors.

How the Stealth Virus Works

It is important to know that many viruses not only hide, but encrypt the original data they have infected. Some victims may use traditional DOS commands such as FDISK/MBR or SYS to fix the problem, an instance that could make things much worse. If the virus is overwritten with FDISK/MBR, the hard drive will have no way to recognize what's in the partition table and cannot access the encrypted data without aid of the virus. For this reason, anti-virus software is recommended to eradicate a stealth virus rather than self maintenance.

Virus coders mainly use the stealth approach to elude virus scanners. Those that have not been designed to do so, because the malicious code is fairly new or the user's anti-virus software isn't up to date, are often described as stealth viruses as well. The stealth technique is a contributing factor to why most anti-virus programs function best when the system is booted from a clean CD or floppy disk. By doing this, the infection is not able to seize control of the system and the changes it makes can be exposed and immediately dealt with.

In general, a stealth virus will hide itself in system memory every time a program scanner is run. It employs various techniques to hide any changes so that when the scanner looks for altered sections, the virus redirects it to any area that contains the clean, uninfected data. A more advanced anti-virus program can detect a stealth virus by searching for evidence of changes within system sectors along with areas that are more susceptible to attack, regardless of how it is booted.

Military Viruses

Posted: by VIruS Of WinDoWS in Label:
0

Military Viruses

Viruses can wreak havoc on any computer and they are most likely to strike computers which are connected to the internet. No computer is safe and this means that all computer users need to spend a large amount of their time securing their computer against these viruses.

Virus

Viruses are particularly nasty pieces of software which are written for malicious purposes. Some viruses are pretty harmless but others will cause your PC a serious amount of harm. Many of these will also compromise the security of your computer which will make it easier for hackers to steal your identity.

Corporate Viruses

It's not just individuals that suffer from viruses. Large businesses also still find themselves affected by these horrible programs. Corporate viruses are on the rise thanks to networks and a worm is able to easily spread throughout the entire network without any intervention.

As everyone is connected to the internet the spread of viruses and worms is made very easy. It's possible for these viruses to spread throughout the world in days compared to the months it use to take before the popularity of the internet.

Military Viruses

Even the military is at risk of computer viruses. Obviously they will take the threat of viruses much more seriously than most computer users. Military computers are privileged with lots of top secret and sensitive information.

Many of these computers also have the ability to control weapons. Needless to say it's vital that security of these computers isn't compromised. The military must be very careful with their data and will do everything they can to secure their network.

Even so, there have been a number of examples of viruses hitting military computers. The military won't own up to all of them but most of the rumors are certainly true.

One of the most revealing is the naked wife virus. This spreads by sending emails to contacts telling them that they have a picture of their naked wife. People are so intrigued that they open the email and try to view the picture.

This just goes to show that a computer is only as secure and honest as the person using it. If someone can be tricked into opening a file then it's very easy for a file to be installed, even if it is on military computers.

Protecting Computers

To protect your computer you don't need to use the same systems as the military. Instead you can use a reliable antivirus scanner, firewall and security suite. These utilities can be run regularly to ensure you are fully protected. The firewall will also help you avoid any future problems by blocking access to your computer for hackers.

Guarding From Network Virus

Posted: by VIruS Of WinDoWS in Label:
0


Guarding against Network Virus

While the primary intent of anti-virus software is to prevent worms and viruses from infiltrating an organization's network, some programs fail to detect more complex infections, thus enabling an outbreak to start. This issue primarily arouse from the widespread use of laptop computers and mobile computing in general. Since many users tend to operate mobile devices with no security implementation at all, an entire network becomes susceptible to infection. Once a virus establishes a strong hold within the network, removal often becomes difficult for the most advanced anti-virus software. Additionally, intrusion detection systems and firewall components have a difficult time preventing the network virus from propagating to other files and devices.

A network worm or virus has the ability quickly degrade the performance of a network, totally disabling critical devices, programs and network connections. Once the infection spreads, fully eradicating it often becomes difficult. Reinfection typically occurs which prompts a spiraling support effort and inflating cost when attempting to recover from the initial outbreak.

The Answer

The best solution for defending an interconnected organization is to implement a program equipped with a network-based firewall. This type of software can be configured to automatically repair infected network devices and more importantly, prevent the virus from occurring.

A network-based firewall uses a combination of techniques to detect, contain and eliminate viruses known to plague a network. Here are some of the common features you'll find:

Outbreak Monitoring - Keeps track of changes in traffic flow, connections made to and from a particular client and sudden increased traffic through ports and protocols such as TCP, UDP, IGMP, and ICMP. The system administrator is immediately notified of any infectious host computers that are detected.

Outbreak Prevention - Prevents the spread of viruses over WANs (wide area networks) by using file, IP address, port and protocol filtering. These processes may be automated or configured manually to give the user greater flexibility and control.

Scanning and Detection - This type of program uses virus scanning technology to detect the latest network threats, dropping the infected packets before they have a chance to be executed.

Security Enforcement - The enforcement of strict security polices greatly reduces the threat of worms, viruses and other infections, setting guidelines that ensure the protection of a network. Some of the actions it may enforce typically include the detection of other anti-virus software that create conflict or automatically downloading virus definitions and scanning technology from an online database. It will also check for compliance of these policies among authorized users who access the network. Those found not to be in compliance can then be directed to comprehensive instructions that detail how the application is to be updated and receive training on any other areas that correspond to the network's security policies.

Where to Find Them

Network-based firewalls have been implemented by a number of security vendors. Some examples include Symantec's Endpoint Security, Norton's 360 and TrendMicro's Virus Firewall. When the integrity of your organization is on the line, it's important to protect it with the best security available.

Email Virus

Posted: by VIruS Of WinDoWS in Label:
0


You've Got Email Virus

Viruses have been around for sometime in the world of computing. They have become much more prevalent in today's society thanks to modern technologies such as the internet. Malicious code writers essentially changed the environment of computing with the creation of email viruses. Take Melissa for example. Released in 1999, this infection is known as one of the most devastating viruses of all time. Melissa distributed itself through Microsoft Word documents distributed via email. Here is how it functioned:

The Email Virus Origin

The virus was originally created as a Word document and was then uploaded via email to an internet newsgroup. Any recipient who opened the email, downloaded the document and opened it on their computer, unknowingly triggered Melissa's payload. From there, the virus sent itself as a document to the first 50 contacts in the victim's address book. The email was attached with a friendly note which included the recipient's name. This was done to make the virus appear harmless and trick them into opening it. It then created 50 new infected documents from that victim's machine. At this continuous rate, Melissa quickly became the fastest spreading virus seen by anyone at the time. The virus was so severe that it resulted in a number of large commercial companies disabling their email systems.

Melissa was so powerful because it capitalized on a vulnerability found in the Microsoft Word programming language known as VBA (Visual Basic for Applications). VBA is a complete language that can be programmed to perform actions such as modifying files and distributing emails. It also includes a rather useful yet dangerous function known as "auto-execute". The Melissa virus was programmed by inserting malicious code into a document, enabling it to be executed whenever someone opened it.

The ILOVEYOU virus, which was first detected in May of 2000, was much more simple than Melissa. The malicious code it contained came in the form of an attachment. Any recipient who clicked on the attachment unknowingly executed the code. This email virus then distributed copies of itself to contacts in the user's address book, enabling the infection to spread at a rapid rate. Because ILOVEYOU was also known to unload different types of infections, some experts have labeled it a Trojan rather than a virus.

Fueling Email Viruses

Since they are known to exploit common vulnerabilities in word processing applications, email viruses fall under the classification of macro viruses. Because of their wide spread nature, most Microsoft applications are equipped with a feature known as Macro Virus Protection, which helps to prevent ths type of infection. When this feature is enabled, a dialog box is displayed to warn the user of any document attempting to execute a malicious code. Unfortunately, many users have limited knowledge on macros or macro viruses, causing them to ignore the warning and unknowingly allow the infection to launch.

This type of feature would be useless against the ILOVE virus which was entirely human powered. Overall, the infection was fueled by the willingness of a human recipient to click on the virus and initiate it's execution.

Self-Defense from virus

Posted: by VIruS Of WinDoWS in Label:
0

Self-Defense: Virus Protection

If you frequently surf the internet, you are sure to be encountered by a computer virus at one time or another. It may be introduced via email, within a program you attempt to download, or a website you visit. The best defense against a virus begins with awareness and ends with prevention. The purpose of this article is to educate you more about these nasty infections and a few ways they can be easily avoided.

The Truth about Viruses

Most internet threats including viruses, worms and Trojans spread themselves via email. A good way to keep these infections away from your computer is to keep your preferred email application current with updates. Contrary to popular belief, you CANNOT be infected by a virus just by opening or reading an email message. The hoax claiming that infections spread by opening an email with a virus-indicating subject field is not true. This misconception has been going around for years and has struck fear in many users. To put it in more simple terms, a virus cannot free itself from your inbox and infect your computer.

In order for a computer virus to be effective, some type of explicit action is required on the user's part. What makes this possible is the fact that many emails contain attachments. An attachment may be a word document, or an audio or video file. An attachment may also be a virus in disguise. By opening the attachment sent with an unsolicited email, you're taking a great risk. When that document is downloaded to your computer and opened, the payload of that virus is unleashed and immediately looks for ways to spread the infection.

Protecting Yourself

Keeping email-born viruses from your system is fairly easy. Since there is no standard method of distinguishing genuine attachments from infected ones, the best advice is to never open those sent in an unsolicited message. Regardless of how tempting it seems, knowing that your computer and everything on it could be at risk should be enough incentive to fight temptation. Caution should be practiced even if the attachment is sent from a friend or known source. Email viruses such as ILOVEYOU and Melissa infect a user's address book and propagates itself in the victim's name. In this instance, you may want to give the sender a call to make sure the email and it's contents are safe.

Software is the recommended solution for keeping viruses away from your system and eradicating them as well. Reliable products from McAfee, Symantec, Kapersky and many other vendors have established reputations for creating some of the best anti-virus software. These programs include sophisticated scanners that will run a quick and thorough search of your entire system, capable of detecting an array of malicious content from viruses to spyware.

Viruses pose a great problem to the modern computing environment. At the same time, exposure to these common threats isn't something you have to deal with. Your chances of contracting a virus can be greatly reduced by taking a few basic security precautions and locking your computer down with quality software.

Avoid Computer Worms

Posted: by VIruS Of WinDoWS in Label:
0

How to Avoid Computer Worms

From updating your security software to being aware of the emails in your inbox, there are many steps you can take to protect yourself and your computer from worms and viruses. One of the most important and simplest ways to protect yourself from computer worms is by being careful and aware of what kind of emails and attachments you receive, what you open and whom it is from. There is a lot of junk and spam email with viruses and worms that ends up directly in your inbox. So, you have to be careful who sends them to you and think twice before opening them.

If you are not expecting an email or do not recognize the person, then the best idea would be to delete it right away and forget about it. If you realize later that you do know the person, do not panic. Chances are they will write back to you again. Also, be aware of attachments and emails you receive from your own family and friends. Most of the time, people receive viruses and worms from individuals they know. Your friends may not realize that they are sending you a virus. So, your job is to inform them and fix the problem before it causes more damage.

Another step you can take to protect your computer is to regularly update your anti-virus software . Make sure that you are using the most up-to-date and enhanced version of your software, so it can catch all those new viruses and worms out there. Also, make sure to check if your software is installed correctly. Sometimes, people do not install the software properly and realize this only when their computer is attacked with a virus or worm. If you don't know how to install the software, have some who knows how to, to install it for you. Also, have him or her explain the steps and procedures to you so next time you need to update or install your software, you can do it yourself.

Finally, when you use email programs, use the ones that have built in spam filters , for instance, Outlook Express, Windows Hotmail and so on. This way, not only will the email be tracked and filtered for viruses, but you will also feel secure that your computer is free from worms and viruses.

In 2003, more than 10 million Americans fell victim to identity theft.

Identity theft costs business and individuals $53 billion dollars annually

In 2003, Americans spent 300 million hours resolving issues related to identity theft.

70% of all identity theft cases are perpetrated by a co-worker or employee of an affiliated business.