Showing posts with label Virus Solutions. Show all posts
Showing posts with label Virus Solutions. Show all posts

Thursday, 28 June 2012

What? A virus attack?


Viruses, Trojans and worms… computers too are vulnerable to infection and what’s alarming is it spreads fast. Geeta Padmanabhan on what protective measures can be taken
My system flashed several warnings. Then it locked up, went blank, started randomly, slowed down suddenly. One morning it crashed. Kaboom! Gone!
The mechanic started with a quiz. “Did you see strange error messages? Pop-up alerts about firewalls? Unsavoury pictures on the screen when you booted?” I nodded. He tickled the desktop a bit and announced, “Your system has a virus.” (Just one?) “Some people find new toolbars in the browser, new shortcuts on the desktop they didn't put there, new items in the system tray at the bottom of the screen.” (Note: new toolbars/shortcuts often come bundled with software you actually want; they may not be malicious — just annoying.)

DIFFERENT VIRUSES

 I needed computer wellness lessons. “Virus is a tiny program designed to infect a machine (files in the machine),” said an ethical hacker (EH).  “When the file is opened, it goes into memory, and infects all files opened. When an infected program is opened on another machine it infects all files in that machine also.” And yes, there are different virus types — those that infect only files, those that infect documents, excel files, boot record/partition and those smart hybrid ones which infect all the above. Classification is based on what they infect.
Then there are worms. These usually travel as a single file to infect machines, so the damage isn’t too much. (That’s kind!) The worm tags on to inbuilt communication mechanism (e-mail) to transmit itself using a weakness on a machine or through shares. Sometimes virus and worm marry. This couple is difficult to remove. Trojan (spyware) programs intercept private data — passwords, e-mails, files — it’s a Trojan war!
Most are innocent victims! “Ha, virus is created for fun by youngsters for bragging, to see it spread, it’s a high,” said EH. “Some are professional — to destroy rivals’ computers. Your computer is just a victim in this process.” What armoury do I have to fight it? “Invest in good antivirus software. It’s difficult to detect them manually.” He recommends Fprot and  Avast (avast.com). “You get a one-year home edition free once you register for Avast. Prevent Trojan (keylogger) from doing identity theft with keyscrambler personal edition (www.qfxsoftware.com)  along with antivirus software. This ensures safety of passwords of emails and net-banking.”
 Session II is with Samir Mody, Senior Manager — Threat Control Lab, K7 Computing. “A computer virus does covert actions such as stealing credit card information, sending spam,” he said. “Most computer viruses are developed for financial gain.” Great.

MALWARE AND SPYWARE

What are malware and spyware? “Malware is synonymous with computer virus. It is the superset of spyware which silently steals information like passwords, confidential data.” Watch out for any unusual behaviour — unknown process names, unusual network traffic — on the device, he said.
Giant companies fall victim to hackerazzi. An AP story tells us how international hackers ran an online advertising scam to take control of infected computers around the world. Hackers installed malicious software on the victim computers, which turned off antivirus updates. In an unusual move, FBI is encouraging users to visit http://www.dcwg.org   (till July 9) to check and fix the problem. According to a Russian anti-virus firm, more than half a million Apple computers have been infected with Flashback Trojan. It sent a unique ID to the intruder's control server to identify the infected machine. The criminals could then control the machine. Apple released its own “security update”.
F-Secure also posted instructions on how to confirm if a machine is infected and how to remove the Trojan. Apple isn’t safe?  “Anti-virus software, including K7 security products, will detect and clean up the infection automatically and without fuss,” Samir consoled. “This is not a plumbing, so don’t call local fix-it men. Maintain up-to-date anti-virus software to prevent malware infection in the first place. Be wary of and discard spam emails or social-networking messages (Facebook, Twitter) from unknown individuals or having dubious content. Refrain from clicking on links or opening attachments within such correspondence.”
 Don’t exchange memory-storage devices. Don’t use memory-storage devices on other computers. Avoid visiting websites of dubious repute. Avoid Internet Explorer as the default browser, Google Chrome and, to a lesser extent, Firefox are currently seen as less vulnerable to malware targeting. Operating systems like Linux (Ubuntu, Mint, etc.), due to their significantly smaller user base, are considered less likely to attract malware.
 My system is back in action. I scream “Virus!”  if it slows down one second.
 DEALING WITH VIRUSES
* On control panel, Security, if you can’t click/launch Windows Update, you probably have a virus.
* Many legitimate parts of Windows have virus-sounding names. Be careful when you do CTRL-ALT-DEL.
* Use multiple programs with multiple and varied virus definitions for better diagnosis.
* When you scan for viruses, be sure to turn off or disable any other security software. These programs can interfere with one another.
* Check out Safentrix.com.
* For Asian malware, read http://blog.k7computing.com/2011/11/malwasia-in-operation-since-1986-part-1/part-2/part-3 
Source : http://www.thehindu.com/ 27/06/2012

Thursday, 9 February 2012

Generic Host process for win32 services solution


Many of us suffer from the following problem:

Soon after connection following error message is displayed

Generic Host Process for Win32 Services
Generic Host Process for Win32 Services has
encountered a problem and needs to close. ....
To see what data this error report contains, click here.:

When clicked on ‘click here’, following screen is displayed:

Error signature
szAppName: svchost.exe szAppVer: 5.1.2600.2180 szModName: svchost.exe
szModVer: 5.1.2600.2180 offset: 00001361

:thumbsup:The solution 100% working:thumbsup:

Symptoms:•You are surfing the internet or are engaged any type of Internet activity when suddenly all your Network activity goes to hault. You can still see the Internet connected icon in the tray but you cannot surf, browse or do anything.
•You get an error message something like "Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience."
•Error message reporting about faulting netapi32.dll and svchost.exe.
•You try to disconnect your Internet because of no activity observed but the Internet icon wont disappear.


Solution:Follow these two simple steps and your problem will be solved

STEP 1:Close Port 445:
1. Click Start menu, and then click Run .
2. In the small box that Opens, type: regedit then click the OK button.
3. Registry Editor will open.
4. Locate the following key in the registry:
HKEY_LOCAL_MACHINE->System->CurrentControlSet->Services->NetBT->Parameters
In the right-hand side of the window find an option called TransportBindName.
Double click that value, and then delete the default value, thus giving it a blank value.

STEP 2:Close Port 135:
1.Then go to the following registry key:
HKEY_LOCAL_MACHINE->Software->Microsoft->OLE
2. You will see there is a String Value called: EnableDCOM
Set the value to: N (it should currently be Y)
3. Close the Registry Editor. Shutdown and Restart your computer.

And the PROBLEM is gone


Wednesday, 9 November 2011

Computer Security Threats


This page provides basic information on computer security threats. The computer security threats covered here are:

Viruses
Macro Viruses
Trojan Horses
Worms
Zombies
Phishing
Internet Based Attacks
Viral Web Sites
Spyware, Adware and Advertising Trojans
Virus Hoaxes
Unsecured Wireless Access Point
Bluesnarfing
Social Engineering
Microsoft Office Document Metadata

Viruses

A software virus is a parasitic program written intentionally to alter the way your computer operates without your permission or knowledge.
A virus attaches copies of itself to other files such as program files or documents and is inactive until you run an infected program or open an infected document. When activated, a virus may damage or delete files, cause erratic system behaviour, display messages or even erase your hard disk.
A virus may spread through email and instant messenger attachments, through infected files on floppy disks or CD-ROMs, or by exploiting a security flaw in Microsoft Windows.

Macro Viruses

Macros are simple programs that can be written to automate repetitive tasks in a document or make calculations in a spreadsheet. Macros can be written in documents created by Microsoft Word, in spreadsheets created by Microsoft Excel and in many other kinds of documents.
Macro viruses are malicious macro programs that are designed to replicate themselves from file to file and can cause damage to the files on your computer. They spread whenever you open an infected file.

Trojan Horses

Trojan horses are programs that appear to serve some useful purpose or provide entertainment, which encourages you to run them. But these programs also serve a covert purpose, which may be to damage files, to place a virus on your computer or to allow a hacker to gain access to your machine. More commonly these days, you can be enticed into running a Trojan by clicking a link on a viral web site or in an email.
Trojans that allow a hacker to gain access to your machine, called Remote Access Trojans (RATs), are particularly prevalent at the moment. Over 50% of all spam (unsolicited email) is sent from home or work computers that have been compromised by RATs.
A Trojan horse is not a virus because it does not replicate and spread like a virus.

Worms

Worms are programs that replicate and spread, often opening a back door to allow hackers to gain access to the computers that they infect.
Worms can spread over the Internet by expoiting security flaws in the software of computers that are connected to the Internet. Worms can also spread by copying themselves from disk to disk or by email.

Zombies

A Zombie is a dormant program that lies inactive on a computer. It can be activated remotely to aid a collective attack on another computer. Zombies don’t normally damage the computer on which they reside but can damage other computers.
Zombies often arrive as email attachments and when the attachment is opened they install themselves secretly and then wait to be activated.

Phishing

A Phishing attack is when you are are sent an email that asks you to click on a link and re-enter your bank or credit card details. These emails can pretend to be from banks, Internet service providers, on-line stores and so on, and both the email and the web site it links to appear genuine. When you enter your bank or credit card details they are then used fraudulently.

Internet Based Attacks

While your computer is connected to the Internet it can be subject to attack through your network communications. Some of the most common attacks include:
  • Bonk – An attack on the Microsoft TCP/IP stack that can crash the attacked computer.
  • RDS_Shell – A method of exploiting the Remote Data Services component of the Microsoft Data Access Components that lets a remote attacker run commands with system privileges.
  • WinNuke – An exploit that can use NetBIOS to crash older Windows computers.

Viral Web Sites

Users can be enticed, often by email messages, to visit web sites that contain viruses or Trojans. These sites are known as viral web sites and are often made to look like well known web sites and can have similar web addresses to the sites they are imitating.
Users who visit these sites often inadvertently download and run a virus or Trojan and can then become infected or the subject of hacker attacks.

Spyware, Adware and Advertising Trojans

Spyware, Adware and Advertising Trojans are often installed with other programs, usually without your knowledge. They record your behaviour on the Internet, display targeted ads to you and can even download other malicious software on to your computer. They are often included within programs that you can download free from the Internet or that are on CDs given away free by magazines.
Spyware doesn’t usually carry viruses but it can use your system resources and slow down your Internet connection with the display of ads. If the Spyware contains bugs (faults) it can make your computer unstable but the main concern is your privacy. These programs record every step that you take on the Internet and forward it to an Ad Management Centre which reviews your searches and downloads to determine your shopping preferences. The Ad Management Centre will build up a detailed profile of you, without your knowledge, and can pass this on to third parties, again without your knowledge. Some Spyware can download more serious threats on to your computer, such as Trojan Horses.

Virus Hoaxes

Virus hoaxes are messages, usually sent by email, that amount to little more than chain letters. They pretend to alert you to the latest "undetectable" virus and simply waste your time and Internet bandwidth. The best course of action is to delete these hoaxes - they can cause genuine fear and alarm in the disabled, elderly and other vulnerable groups.

Unsecured Wireless Access Points

If a wireless access point, e.g. an ADSL (Broadband) Router, hasn't been secured then anyone with a wireless device (laptop, PDA, etc) will be able to connect to it and thereby access the Internet and all the other computers on the wireless network.

Bluesnarfing

The act of stealing personal data, specifically calendar and contact information, from a Bluetooth enabled device.

Social Engineering

Tricking computer users into revealing computer security or private information, e.g. passwords, email addresses, etc, by exploiting the natural tendency of a person to trust and/or by exploiting a person's emotional response.
Example 1: Spammers send out an email about victims of child abuse and provide a link to click in the email for further information or to help the victims. When the link is clicked the spammers know the email address is "live" and add it to their live list which they then use to target their spam.
Example 2: A company computer user is tricked into revealing the network password by someone on the telephone who is impersonating the voice of an employee in authority and who has a story of distress.

Microsoft Office Document Metadata

The average Microsoft Word, Excel, etc document includes hidden metadata with details of who created it, who has worked on it, when it has been amended and quite possibly the text of all those changes as well. Viewing a Word document in a text editor can reveal the metadata in plain text at the start and finish of the document.

Friday, 28 October 2011

How to Remove Norton Anti Virus from my PC completely?

It's not so easy to remove Norton by using the Windows utility. You need to carefully remove from Registry also. It's little tricky and long process. Please do the cleaning with care.

First Step

  • Remove Norton using Windows utility
  • Start --> Control Panel --> Add/Remove Programs.
  • Select Norton application
  • Click Change --> Remove All.
  • You will be asked to restart your PC. Without fail Restart
Second Step
  • Start --> My Computer --> Program Files.
  • Right click on each Symantec folder
  • Select Delete.
  • Go to the Common Files folder at or near the top of the Program Files window.
  • Delete every Symantec folders.
  • Again restart your PC.
Third Step
  • Go to Start --> Search --> All Files and Folders --> More Advanced Options.
  • Check each option except for "Case sensitive"
  • Type 'Norton' and Search
  • Delete each Norton folder from the search results (Again, right click, choose "Delete").
  • For the third time, restart your PC.
Fourth Step
  • Go to Start --> Search --> All Files and Folders --> More Advanced Options.
  • Check each option except for "Case sensitive"
  • Type 'Symantec' and Search
  • Delete each Norton folder from the search results (Again, right click, choose "Delete").
  • For the third time, restart your PC.
Fifth Step
The is very very tricky. Do it with care :

  • Start --> Run
  • Type in "regedit"
  • Go to the top of the Regedit window.
  • Click (+) next to HKEY_CURRENT_USER.
  • Go down the thread until you see Software.
  • Click on Software
  • Scroll down the thread until you see Symantec.
  • Right click on Symantec and choose "Delete".
  • From there go down to HKEY_LOCAL_MACHINE
  • Go down the thread until you see Software.
  • Click on Software
  • Scroll down the thread until you see Symantec.
  • Right click on Symantec and choose "Delete".
  • Restart your PC.
Sixth Step
  • Start --> Run
  • Type in "regedit"
  • Go to the top of the Regedit window.
  • Click (+) next to HKEY_LOCAL_MACHINE
  • Click (+) next to Software
  • Click (+) next to Microsoft, Click (+) next to Windows
  • Click (+) next to CurrentVersion.
  • Select the Run folder
  • Right-click and delete each Symantec entry you see (if present).
  • Restart your PC.
I believe these steps can clean your system without Norton Antivirus programs

Sunday, 16 October 2011

Best Antivirus Suggested by MR-Support




Most of us spend money to buy Anti-Virus for personal computers and laptops. If you’re spending money on buying, renewing Anti-virus licenses, note that Microsoft itself provides an Anti-virus, completely free. MSE (Microsoft Security Essentials) is just more than enough, to run it, all you need is genuine Windows. Best of all, it’s light with very less memory foot print.





Download Microsoft Security Essentials

Friday, 16 September 2011

Uninstall Symantec Anti Virus without a password



When removing Symantec antivirus you often need to supply a password for the uninstall to run. This can be a very big pain if you've forgotten the password or if the original install was done by an administrator that has long since left. As usual, there is a work around. Here's how to remove SAV without supplying a password:

- Press Windows Key + R (This brings up the run dialog box)

- Type regedit and press Enter (This will open the Registry editor)
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\AdministratorOnly\Security

- Look for a DWORD value called UseVPUninstallPassword. Once you find it, double click it.
- Change the value of UseVPUninstallPassword to 0 (zero) and click OK[See pic below]


Tuesday, 21 June 2011

USB Disk Security 6 for Windows



Award-winning protection to secure your PC against threats from USB drive.

To download and install USB Disk Security please follow these instructions.

1. Download USB Disk Security 6 from the links below:

Download Link 

2. Save the installer

When the File Download dialog box appears click the "Save" button and download it onto your computer.

3. Run the installer

Please run the installer and follow the Setup Wizard to complete the installation.

Monday, 13 June 2011

3 Simple Things To Do To Avoid Virus Infection On Windows Computer

         Viruses are malicious programs that can run down your entire system and leak your private data into the wrong hands. What about you system’s performance after been infected by viruses? How right can a computer perform in the presence of viruses? Your computer cannot be as right as it ought to be when there are viruses in your computer. The performance of your computer will deteriorate as soon as it is infected with viruses and by this time you fall on the brink of losing the entire documents and files on your computer.


Many people have been hacked and have loosed their paypal and email accounts to hackers due to the presence of viruses and spywares on their computer. Some viruses that seem to look harmless are the most dangerous; some viruses pose as antivirus and upon installing them on your computer you then begin to experience difficulties with your computer: such as applications mysteriously ending while in use, your browser directing you to harmful sites etcetera, etcetera. I shall be explaining some few tips on how to protect your computer against virus attack.
Install an up to date antivirus

Antivirus programs are developed to protect your system against virus attacks of all forms. Antivirus programs neutralizes any virus or spyware that gets into your computer; an antivirus can clean your computer if there are viruses on it and also disarm those that come along with files that are copied from flash drives and attachments from your email box. When you are installing an antivirus, you should make sure the antivirus you are installing is a well trusted and widely used by many computer users. You can easily purchase an antivirus program in the market while you can also get it for free if you care to use the free ones.

Keep your antivirus updated regularly

After installing an antivirus on your system, your system might still be visited by viruses if the antivirus you are using is not regularly updated. For your antivirus program to perform well for you, you have to update it regularly and frequently run a system scan. The fact that an antivirus is installed on your computer does not mean a virus can’t find its way into your computer, you can only assume that you are fully protected when you antivirus program is kept updated regularly.

Download from trustworthy sites

When downloading files and applications from the internet to your computer system make sure the sites you are downloading from are trustworthy sites. If you want to know the rank or the quality of websites you are downloading from you can install alexa toolbar on your web browser by visiting

Tuesday, 7 June 2011

New Folder.exe Virus Removal Tool


Virus also known as- IT University Sohanad W32.HLLW.Ssdx newfolder.exe
If this virus infected in you computer, It will Disable the following …
Task Manager, Registry Editor, Folder Options, Run in start menu
And it will create exes like the icon of folders. If this virus is running it will use more than 50 % of your processor
Manually remove it (new folder.exe Fix)
Delete File named svichossst.exe
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Yahoo Messengger”=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Shell”=”Explorer.exe “

Internet Explorer - Lord rahul cool removal Procedure


Delete this values into registry

1— Start>>Allprograms>>RUN
2—- and type REGEDIT into run window
3—– goto this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\

delete the key value
********************

Window Title : LORD RAHUL COOL ”’delete this value or change it to any name.

Sunday, 5 June 2011

How to Remove AutoRun Virus ?


AutoRun is a traditional feature in windows operating systems that enables media like the CD ROMs, USB Devices, Memory Sticks, DVDs, etc. to automatically launch the programs stored in them. This happens through an autorun.inf file present in the root directory of the USB Device or CD ROM and it contains a list of commands that get executed as soon as the media is inserted into the appropriates drives of the PC. You will typically find autorun.inf on installation CDs and DVDs.
AutoRun is often confused with AutoPlay, a feature introduced in Windows XP. Though Microsoft intended it to be a useful feature, there are several viruses and malware that abuse the autorun.inf to spread itself.


How to delete AutoRun Virus?

  • First disable System Restore on all drives. To do this go to Control Panel -> System and choose the System Restore tab. Check the option “Turn Off system Restore on all Drives
  • Clear all temporary internet files in your browser
  • Do a Disk Cleanup of all the drives on your PC. To do this, navigate to Start ->All Program ->Accessories ->System Tool ->Disk cleanup, choose the drive that you want to clean up and click OK.Once the drive is cleaned, proceed to cleanup the remaining drives
AutoRun Viruses spread themselves through removable media like USB drive, etc. They contain three executable files namely “autorun.inf“, “kavo.exe” and “ntdelect.com“. These are hidden files and they usually disable theShow hidden files and folders option, so that you can never see them.The only way to find these files is through the DOS command prompt.

Delete autorun.inf and ntdelect.com :

  • Click Start, enter cmd and press Enter
  • Check all the drives for the above three files.For eg: to check the files in C:, type dir c:\ /a/w in cmd prompt and press Enter. This will list all the system and exe files. Look out for autorun.inf and ntdelect.com files.Disable ‘hidden’, ‘system’ and ‘read only’ attributes for these files by typing
attrib -s -h -r c:\autorun.inf
attrib -s -h -r c:\ntdelect.com
  • Then delete the files by typing
del c:\autorun.inf
del c:\ntdelect.com
  • Make sure that you delete ntdelect.com and not ntdetect.com which is a system file
  • Repeat from step 2 for all other drives

Delete kavo.exe :

  • Search for kavo.exe in C:\windows\system32\
  • If you find it, type
attrib -s -h -r c:\windows\system32\kavo.exe 
  • to disable ‘hidden’,'system’ and ‘read only’ attributes
  • Delete kavo.exe by entering the command
del c:\windows\system32\kavo.exe 
  • Click Start, type regedit and press Enter. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \CurrentVersion\Run,and
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows \CurrentVersion\Run. Delete kavo and c:\windows\system32\kavo.exe value.

Enable ‘Show hidden files and folders’ option:

Open Notepad,copy and paste the following and save it as a “showhidden.reg” file.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"
"Text"="@shell32.dll,-30500"
"Type"="radio"
"CheckedValue"=dword:00000001
"ValueName"="Hidden"
"DefaultValue"=dword:00000002
"HKeyRoot"=dword:80000001
"HelpID"="shell.hlp#51105"
Double click on the saved file to modify the registry.
That is all! You have now cleaned up autorun virus on your PC. But isn’t prevention better than cure?

Saturday, 4 June 2011

Google Image Poisoning


Google is doing a relatively good job removing (or at least marking) links leading to malware in normal searches, however, Google’s image search seem to be plagued with malicious links. So how do attackers do this?

The activities behind the scenes to poison Google’s image search are actually (and unfortunately) relatively simple. This is what the attackers do:

1.The attackers compromise a number of legitimate web sites. They usually attack Wordpress installations, but any widely spread software that has known vulnerabilities can be exploited.

2.Once the source (legitimate) web sites have been exploited, the attackers plant their PHP scripts, These scripts vary from simple to very advanced scripts that can automatically monitor Google trend queries and create artificial web pages containing information that is currently interested. That is actually how they generate new content – if you ever wondered how they had those web sites about Bin Laden up quickly it is because they automatically monitor the latest query trends and generate web pages with artificial content.


3.These web sites contain not only text, but also images that are acquired from various web sites. Again, their scripts use various search engines to locate these pictures. They embed links to pictures which are really related to the topic so the automatically generated web page contains real looking content.

4.Google now crawls through these web sites. The scripts that the attackers put will detect Google’s bots (either by their IP address or the User Agent) and will deliver special pages back containing automatically generated content. Google will also parse links to images and, if appropriate, populate the image search database.


5.Now, when a user searches for something through the Google image search function, thumbnails of pictures are displayed. Depending on the automatically generated content in step 3), number of links to the web page and other parameters known to Google, the attacker’s page will be shown at a certain position in the results web page. The exploit happens when a user clicks on the thumbnail.

6.Google now shows a special page that shows the thumbnail in the center of the page, links to the original image (no matter where it is located) on the right and the original web site (the one that contained the image) in the background. This is where the “vulnerability” is.

7.The user’s browser will automatically send a request to the bad page which runs the attacker’s script (the one set in step 1). This script checks that the request’s referrer field and if it contains Google (meaning this was a click on the results page in Google), the script displays a small JavaScript script.

This causes the browser to be redirected to another site that is serving FakeAV.

As we can see, the whole story behind this is relatively simple (for the attackers). There is a number of things to do here to protect against this attack, depending if we are looking at servers or clients. For a standard user, the best protection besides not clicking on images is to install a Mozilla Firefox addon such as NoScript. Google could step up a bit as well, especially since this has been going on for more than a month already and there are numerous complaints on Google’s forums about this. Since there are so many poisoned images they could maybe modify the screen that displays the results so it does not include the iframe – that will help in first step only, since if the user lands on the malicious web page there is nothing Google can do really.

Courtesy: Bojan,http://www.infigo.hr/en

Cartoon by: srputtur

Saturday, 9 April 2011

How To Remove Norton Antivirus 2011 & Internet Security Completely


         
       Norton removal tool will help you Uninstall Norton Internet security and Norton Antivirus completely from your pc when you encounter uninstallation errors with windows. Norton Removal Tool will also help you uninstall other latest Norton products too.

     The tool is small in size and will support the removal of following Norton 2011 products.
*Norton AntiSpam 2004/2005
* Norton AntiVirus 2003 through 2007.2
* Ghost 2003, Ghost Version 9.0 and 10.0
* Norton GoBack 3.1 through 4.2
* Norton Internet Security 2003 through 2007.2
* Norton Password Manager
* Norton Personal Firewall 2003 through 2006
* Norton SystemWorks 2003 through 2007
* Norton Confidential Online 2007
* Norton Internet Security Add-on Pack
* Norton Save and Restore 1.0
* Norton 360
Note : Before using the norton uninstall tool makes sure you have copied down your norton product key as you might need to enter the product key again when you are reinstalling norton 2011.
Norton removal tool is supported by windows versions and should be run only if you have problems uninstalling norton 2011 products normally via windows


Saturday, 19 March 2011

Websites To Scan For Viruses Online Free....


 Top 10 Websites To Scan For Viruses Online Free
Here is the  list of Top 10 Websites that can scan for viruses online for free.


1) VirusTotal Online Virus Scanner
2) VirusChief Online Virus Scanner
3) Jotti’s Online Malware Scan
4) Kaspersky Online Virus Scanner
5)  BitDefender Online Virus Scanner
6) ESET Nod32 Online Antivirus Scanner
7) F-Secure Online Virus Scanner
8) McAfee Free Online Virus Scanner
9)Windows Live OneCare online scanner
10) Panda Antivirus ActiveScan 2.0

Monday, 28 February 2011

Norton Power Eraser


If you have become the victim of crimeware that regular virus scans can't detect, use the Norton Power Eraser to target and eliminate them.
Norton Power Eraser : Eliminates deeply embedded and difficult to remove crimeware that traditional virus scanning doesn't always detect.

Download Instructions:
  1. Click on the "Download Norton Power Eraser" button above
  2. A dialog will appear, click on the "Save File"
  3. Select the location where you want to save the file, and click "save".
  4. Go to the location you saved the file and run the file you downloaded
  5. You may get a prompt asking you to confirm that you want to run the file. Please confirm and continue with the download process.

Because the Norton Power Eraser uses aggressive methods to detect these threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully, and only after you have exhausted other options.


Download 

Friday, 28 January 2011

How to Fix Generic Host For Win32 and Svchost.exe Error


          What are Generic Host For Win32 and Svchost.exe Error and how to conferm that your pc infected by this malicious?When your pc infected you will see couple of symptom like these: In time of surfing internet suddenly you will see your internet activites become hault but you are still connected through your network and network icon of taskbar is showing ok.As you can not surf, you try to disconnect your connection but network icon will not removed.Some time you will see different type of message like below:


1."Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience."

2."svchost.exe -- application error the instruction at "0x745f2780" reference memory at "0x00000000". the memory could not be 'read'"

Some error message will report you about faulting netapi32.dll and svchost.exe. or your pc has recoverd from a serious problem.

So these are the common symptom of this problem.



Now we discuss actually what is it

What is an Generic Host Process for Win32 Services and svchost.exe?

Generic Host Process for Win32 Services or svchost.exe is a legal and essential component of Windows which is used to host services which run from dynamic-link libraries (DLLs). Multiple instances of Svchost.exe can run at the same time. So it is not a problem in most cases if you see five or six or even more copies of svchost.exe running in your services because they host different groups of DLLs. However, there are several known spyware anâ trojans that pretend to be legal svchost.exe. They usually have the same name or one of the following names: svchost.exe, svchosts.exe (which often causes svchosts.exe page faults), Generic.exe, svcchost.exe and several others. Please note that legal svchost.exe should reside in Windows\System32 folder and should not appear in startup list.

Now we will see how to remove this evil problem.

There are lots of easy way to remove this problem, I mentioned couple of them below:
Solution 1:

Follow these simple steps and your Windows will be fully cured of this malicious

Close Port 445:

1. Start Registry Editor (Regedit.exe) by clicking Start menu, and then click the Run icon.
2. In the small box that Opens, type: regedit then click the OK button. The Registry Editor will now have opened.
3. Locate the following key in the registry:
HKEY_LOCAL_MACHINESystemCurrentControlSetServicesNetBTParameters
In the right-hand side of the window find an option called TransportBindName.
Double click that value, and then delete the default value, thus giving it a blank value.

Close Port 135:

1. Then you must now navigate to the following registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftOLE
2. You will see there is a String Value called: EnableDCOM
Set the value to: N (it should currently be Y)
3. Close the Registry Editor. Shutdown and Restart your computer.

Now you will see your problem is solved.

Solution 2:

This is another way to fix Generic Host For Win32 Error in Windows:

1. 'Run' and open 'Regedit' and
Navigate to:
HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Services > Browser > Parameters
2.Find the Key
Name: IsDomainMaster
and set
Data: False
3.Restart Your PC
Solution 3:

1.Go to 'Run' and open 'cmd'
2.Type 'netsh' in command console then press enter
3.Then type 'winsock' and press enter and then type reset
4.Restart Your PC

These are some easy ways to solve Generic Host For Win32 Error and Svchost.exe Error
without using any third party software or spyware removing tools.If you want to use any tool or software to remove Generic Host For Win32 and Svchost.exe Error you can us these free tools from some website


Thursday, 27 January 2011

What is Computer Virus?. How to Protect Yourself from Virus?


Basic types of viruses
File viruses
File viruses, also known as parasitic or executable viruses, are pieces of code that attach themselves to executable files, driver files or compressed files, and are activated when the host program is run. After activation, the virus may spread itself by attaching itself to other programs in the system, and also carry out the malevolent activity for which it was programmed.
Most file viruses spread by loading themselves in system memory and looking for any other programs located on the drive. If it finds one, it modifies the program’s code so that it contains and activates the virus the next time it’s run.
 It keeps doing this over and over until it spreads across the system, and possibly to other systems that the infected program may be shared with. Besides spreading themselves, these viruses also carry some type of destructive constituent that can be activated immediately or by a particular ‘trigger’. The trigger could be a specific date, or the number of times the virus has been replicated, or anything equally trivial. Some examples of file viruses are Randex, Meve and Mr Klunky.

Boot sector viruses
A boot sector virus affects the boot sector of a hard disk, which is a very crucial part. The boot sector is where all information about the drive is stored, along with a program that makes it possible for the operating system to boot up. By inserting its code into the boot sector, a virus guarantees that it loads into memory during every boot sequence. A boot virus does not affect files; instead, it affects the disks that contain them. Perhaps this is the reason for their downfall. During the days when programs were carried around on floppies, the boot sector viruses used to spread like wildfire. However, with the CD-ROM revolution, it became impossible to infect pre-written data on a CD, which eventually stopped such viruses from spreading. Though boot viruses still exist, they are rare compared to new-age malicious software. Another reason why they’re not so prevalent is that operating systems today protect the boot sector, which makes it difficult for them to thrive. Examples of boot viruses are Polyboot.B and AntiEXE.
Multipartite viruses
Multipartite viruses are a combination of boot sector viruses and file viruses. These viruses come in through infected media and reside in memory. They then move on to the boot sector of the hard drive. From there, the virus infects executable files on the hard drive and spreads across the system. There aren’t too many multipartite viruses in existence today, but in their heyday, they accounted for some major problems due to their capacity to combine different infection techniques. A well-known multipartite virus is Ywinz.
Macro viruses
Macro viruses infect files that are created using certain applications or programs that contain macros. These include Microsoft Office documents such as Word documents, Excel spreadsheets, PowerPoint presentations, Access databases and other similar application files such as Corel Draw, AmiPro etc. Since macro viruses are written in the language of the application and not in that of the operating system, they are known to be platform-independent—they can spread between Windows, Mac and any other system, so long as they are running the required application. With the ever-increasing capabilities of macro languages in applications, and the possibility of infections spreading over networks, these viruses are major threats. The first macro virus was written for Microsoft Word and was discovered back in August 1995. Today, there are thousands of macro viruses in existence—some examples are Relax and Bablas.
Network viruses
This kind of virus is proficient in quickly spreading across a Local Area Network (LAN) or even over the Internet. Usually, it propagates through shared resources, such as shared drives and folders. Once it infects a new system, it searches for potential targets by searching the network for other vulnerable systems. Once a new vulnerable system is found, the network virus infects the other system, and thus spreads over the network.Some of the most notorious network viruses are Nimda.
Email Viruses
An email virus could be a form of a macro virus that spreads itself to all the contacts located in the host’s email address book. If any of the email recipients open the attachment of the infected mail, the virus spreads to the new host’s address book contacts, and then proceeds to send itself to all those contacts as well. Email viruses can infect hosts even by previewing the infected email in a mail client.

How to Protect Yourself from Virus?
Virus Protection
virus may or may not present itself. Viruses attempt to spread before activating whatever malicious activity they may have been programmed to deliver. So, viruses will often try to hide themselves. Sometimes there are symptoms that can be observed by a trained casual observer who knows what to look for (but, don't count on it).
Virus authors often place a wide variety of indicators into their viruses (e.g., messages, music, graphic displays). These, however, typically only show up when the virus payload activates. With DOS systems, the unaccounted for reduction of the amount of RAM known to be in the computer is an important indicator resident viruses have a hard time getting around. But, under Windows, there is no clear indicator like that. The bottom line is that one must use anti-virus software to detect (and fix) most viruses once they are on your system.
Your main defense is to detect and identify specific virus attacks to your computer. There are three methods in general use. Each has pros and cons and are discussed via these links. Often, a given anti-virus software program will use some combination of the three techniques for maximum possibility of detection.
With dangerous viruses on the network, what can computer users do to protect their systems?Here are just a few hints:
• Be sure to install an anti-virus software program (see the next section) to guard against virus attacks. Also, be sure you turn on the scanning features. It can't protect you if it's not enabled.
Practice caution when working with files from unknown or questionable sources.
• Do not open e-mail attachments if you do not recognize the sender (though you may also receive viruses from people you know). Scan the attachments with anti-virus software before opening them.
Download files only from reputable Internet sites, and be wary when exchanging diskettes or other media with friends.
• Scan your hard drive for viruses monthly.
Even with these precautions, new viruses may find ways to enter your computer system.