Showing posts with label Exploit Windows. Show all posts
Showing posts with label Exploit Windows. Show all posts

Tuesday, December 1, 2009

Microsoft Security Essentials

Microsoft Security Essentials provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software.

Microsoft Security Essentials is a free* download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. It’s easy to tell if your PC is secure — when you’re green, you’re good. It’s that simple.

Thursday, November 19, 2009

W32/Conficker.worm Infection Cycle

The W32/Conficker.worm can infect systems via three infection vectors, via exploit MS08-067, an Autorun mechanism or by exploiting weak passwords. In addition the worm has an auto update routine to update previously infected systems .

These Infections are all multi stage processes. Involving the initial compromise,
copy files and then executing the malware.

Exploit Vector
Local network is scanned for susceptible computers. Once a susceptible computer is located the exploit is then attempted against the machine. If successful the process is hijacked and malware is copied from remote attacking machines HTTP server (random port # is used) to the localhost. At this point the machine is compromised.

Fake Antivirus Remover, Use to Clean Fake Antivirus

We have more and more antivirus, free antivirus can we download on the Internet. But with so many free antivirus presence we need to be aware, many anti-virus which was spreading a virus or trojan.

Remove fake Antivirus is a simple tool that serves to remove the antivirus, fake antivirus that may have infected your computer.

Here's a list of fake antivirus that can be detected by Fake Antivirus Remove:
1. Cyber Security
2. Alpha Antivirus
3. Braviax
4. Windows Police Pro
5. Antivirus Pro 2010
6. PC Antispyware 2010

Sunday, November 15, 2009

Download Free McAfee VirusScan Enterprise

McAfee VirusScan Enterprise protects your desktop and file servers from a wide range of threats, including viruses, worms, Trojan horses, and potentially unwanted code and programs.

This version provides these new or improved features:
- Support for 64-bit operating systems.
These features or products are not supported on
64-bit operating systems:

- Buffer Overflow Protection.
- Scanning of Lotus Notes databases.
- Alert Manager 4.7.1.

Monday, November 9, 2009

Slow Start-up Windows XP When Using Norton Internet Security

If you are using Norton Internet Security, and are experiencing slow start-up of XP, (i.e. you can see the desktop with icons etc. but it takes 30-60sec before you can start using the computer), this fix might help:

· Click on Start button.
· Select Control Panel.
· Open "Network Connections".
· Under "LAN and High-Speed Internet", right-click on your "Local Area Connection" and select "Properties".

Sunday, November 8, 2009

Windows Defender in Windows Vista

Windows Defender is Microsoft’s anti-spyware program, which it purchased from Giant and re-badged. An examination of the effectiveness of this product is beyond the scope of this article. One excellent feature, however, is that WD (who else wishes they had called it Windows Malware Defender – WMD?) does tell the user in good
detail every time a program (even a legitimate one) takes certain actions, such as writing to the registry. For the informed user, this is useful information.

What is most interesting, though, is that despite all of the other measures taken in Vista to preserve system integrity and reduce the attack surface for malicious exploiters, there is still a need for a standalone (albeit bundled) application
which is dedicated exclusively to dealing with undesirable programs. This, more than any other indication, is tantamount to an admission that Microsoft does not believe
that the new security controls in Vista are going to solve ‘the virus problem’.

Friday, October 30, 2009

Disable the Avira AntiVir avnotify nag screen

Windows 2000:
Click Start,
1. and then click Run
2. In the Open box, type gpedit.msc, and then click OK
3. Expand User Configuration, expand Administrative Templates, and then expand System
4. In the right pane, double-click Don't run specified Windows applications
5. Click Enabled, and then click Show
6. Click Add, and then type the executable file name of the program (avnotify.exe) that you want to restrict users from running.
7.Click OK, click OK, and then click OK (NOTE: If domain-level policy settings are defined, they may override this local policy setting.)
8. Quit Group Policy Object Editor
9. Restart the computer


Tuesday, October 27, 2009

Virus - Exploit.PDF-JS.Gen

There are no obvious symptoms until the malware manages to infiltrate the system. This can happen when opening a crafted PDF file and the javascript code inside the file is executed.

Exploit:Win32/Pidief.D; Exploit:W32/AdobeReader.QQ

This is a generic detection for specially crafted PDF files which exploit different vulnerabilities found in Adobe PDF Reader's Javascript engine in order to execute malicious code on user's computer. The exploitation mainly involves the following two functions:
util.printf() - if an attacker sends a string long enough to generate a
stack-based buffer overflow he will then be able to
execute arbitrary code on user's computer with the
same level privileges as the user who opened the PDF
file
Collab.colectEmailInfo() - a stack-based buffer overflow can be
caused by passing a string long enough (at least 44952
characters) as a parameter in the msg field of this
function.

Friday, October 23, 2009

Types of Malicious Code

Malicious code can be defined as code that has been developed to perform various harmful activities on a normal computer. Examples of such harmful activity can be actions such as stealing the end users data or personal information, infecting other ma-chines on a network or sending spam through infected machines. There are several categories of malicious code which include but are not limited to viruses, worms, trojan horses and bots. Each of these categories has differing characteristics according to their intended purpose. As we move forward, our aim is to discuss the various techniques we can use for effectively analyzing such malicious code.

Let us discuss the basic definitions of some different types of malicious code:

Tuesday, October 20, 2009

Virus - Sasser (2004)

Another worm to exploit a Windows flaw, 'Sasser' led to several computers crashing and rebooting themselves. 

Sasser spread by exploiting the system through a vulnerable network port. The virus, which infected several million computers around the world, caused infected machines to restart continuously every time a user attempted to connect to the Internet. The worm also severely impaired the infected computer's performance. 

The first version of worm struck on April 30, 2004. The worm’s three modified versions have followed it since then, known as Sasser.B, Sasser.C and Sasser.D. The companies affected by the worm included the Agence France-Presse (AFP), Delta Air Lines, Nordic insurance company If and their Finnish owners Sampo Bank. 

Virus - Brain (1986)

`Brain' was the first virus to hit computers running Microsoft's then popular operating system DOS. The virus was written by two Pakistani brothers, Basit Farooq Alvi and his brother Amjad Farooq Alvi and left the phone number of their computer repair shop. 

A boot-sector virus, Brain infected the boot records of 360K floppy disks. The virus would fill unused space on the floppy disk so that it could not be used. The first "stealth" virus, it hid itself from any detection by disguising the infected space on the disk. Due to its partial non-destructiveness, Brain often went undetected as many times users paid little attention to the slow speed of floppy disk access.

The virus was also known as Lahore, Pakistani and Pakistani Brain. BusinessWeek magazine called the virus the Pakistani flu. The brothers told TIME magazine they had written it to protect their medical software from piracy and it was supposed to target copyright infringers only.