Tuesday, March 24, 2009

Be Aware of 'iehelper.dll' and Don’t Lose your Data!

Each day brings me something new, interesting or amazing. And one of unknown things I come with lately is iehelper.dll being recognized as pwsteal.tarno.k trojan iehelper. I have discovered that my computer has a dll file called 'iehelper.dll' on it which points to the fact that my PC has a trojan.
iehelper.dll is a security risk alongside it is pwsteal.tarno.k trojan is said to be a Trojan.In this case I cannot delay the removal of iehelper.dll as it may result in serious damage to my system causing a number of difficulties such as loss of data, loss of control or leaking private information.
Bearing in mind that malware masks themselves to be iehelper.dll I need to check the iehelper.dll process on my computer to find out if it is an infection with the help of Security Task Manager.

Monday, March 23, 2009

A Mass-Mailing Worm: Mytob!

Did you know as I didn't that W32.Mytob.PI@mm being a mass-mailing worm uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.The worm tries to open a back door and lower security settings.
I also found that this worm opens certain ports, decreases security settings on affected systems and blocks security websites. It has the ability to stop the Windows task manager opening, prevent IT admins from checking and terminating the viral processes.
And it affects systems such as Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP.

Friday, March 20, 2009

What is Trojan.Brisv.A?

Trojan.Brisv.A is a Trojan horse that I am now aware of and which infects media files causing Windows Media Player to access a malicious URL.
The Trojan horse attempts to search the compromised computer for .asf, .mp2, .mp3, .wma and .wmv files, which it then corrupts. Also, I am careful as when opened in Windows Media Player the infected files make the program to connect to a malicious URL that may end in more malware being downloaded on to the compromised computer. Apart from that I found that infected media files may be downloaded on to the computer through file-sharing programs.
To avoid this happening I have both a firewall and real time antivirus protection running regularly.

Thursday, March 19, 2009

An Injurious Computer Worm - W32.Netsky.D@mm

To continue the topic of computer infections like viruses, spyware or worms I want you to pay attention to W32/Netsky.D-mm , a mass-mailing worm.
Netsky.D spreads through e-mail only with spoofed "from" addresses. Altogether, it transmits copies of itself to addresses gathered from an infected machine's local and mapped (C: through Z:) network drives.
In order to avoid this kind of threat I do not open or execute email attachments and keep my antivirus up to date.

Wednesday, March 18, 2009

Win32/Conhook: Malware Continues to Multiply

As malware and other computer threats are rising each month I want to introduce Win32/Conhook, a family of Trojans that installs themselves as Browser Helper Objects (BHOs), and are able to connect to the Internet without user acceptance . Altogether, they determine specific security services, and download additional malware to the computer.
I discovered that this Trojan injects its code into winlogon.exe and explorer.exe running processes creating remote threads in each. Then, Win32/Conhook listens for connections on UDP port 3012.
To prevent this threat I have to enable a firewall on my computer, get the latest computer updates, use up-to-date antivirus software and use caution with attachments and file transfers.

Monday, March 16, 2009

Warning: A NTOSKRNL-HOOK!

This time I found a NTOSKRNL-HOOK, a virus hooked into the kernel of the operating system, also it is recognized as a "rootkit".
However, nothing I do with the actual operating system on the hard drive will make it to be fully erased. Being a technique hooking changes or improves the behavior of an operating system or application, without having access to its source code.
Hooking is being used for various reasons, such as debugging and extending functionality. Alongside, it can be used to by potentially malicious code, like rootkits.

Friday, March 13, 2009

Is Limewire Considered to be Secure?

I don’t want my PC to be occupied by malware, viruses and other dangers. Therefore, I am very accurate while choosing various software programs.
Lately, I have come across Limewire and it is believed to be a reliable, fast, easy-to-use file sharing program with no spyware, adware or other bundled software. But, some computer users think that it is unsafe and may cause damage to my PC. Still, if I am completely sure of my actions, the usage of P2P software can be safe.
But, on the safe side I better have a good virus and spyware scanner installed and in this way I hope to avoid unwanted malware.

Thursday, March 12, 2009

Conficker Worm is Spreading

Conficker worm, spreading since last November and coming in two variants, has already infected about 12 million computer systems. The initial variant of the worm, Conficker A, used Microsoft Windows vulnerability to spread itself to vulnerable computers. The fact that this variant of the malware did not affect computers that use Ukrainian keyboard layout raised a suspicion that the malware itself was created in Ukraine. The worm basically spreads itself infecting computers across networks, allowing for remote code execution when file sharing is in use. The second variant of this threat – Conficker B – has the ability to spread via network shares as well as USB drives. When executed on a computer, both variants of Conficker disable a number of system services, including Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. This malware also prevents system from downloading any new security software or receiving any updates for current security software and opens infected computers to receive additional programs from the evil author.
In case you are experiencing any of the above mentioned problems, your computer has most probably caught the Conficker worm. But there is a way out of this problem. There is a possibility to remove Conficker manually. However, as this is a rather long and complicated task I would recommend you to use a special Conficker removal tool. One of such programs is offered for free by Enigma Software Group, Inc. and is available to be downloaded from http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/ . When run on the system, the Conficker removal tool initiates a four-step Conficker removal process that will completely eliminate the threat from infected machines.

Wednesday, March 4, 2009

Do you Know what Backdoor Trojan is?

I have a phobia of computer viruses, trojans and other malware. In this particular case I refer to a backdoor Trojan, a program which allows other computer users to gain access to my computer across the internet. Backdoors are said to be the most dangerous kind of Trojans and the most extensive on a user’s computer nowadays. Very often I am not able to see the backdoor in the log of active programs. Apart from that I found out that backdoors are used for the following purposes like to detect and download confidential information, execute malicious code, destroy data, include the machine in bot network. So to get rid of backdoor trojan I have to wipe the drive clean, reformat and reinstall the OS.