Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Thursday, April 19, 2012

5 Online Web Page Scanners for

I want to know whether...
  • I trust this site before I visit the website?
  • my website is hosting malware and viruses, or poor reputation?
Here is the list of site you can try!

1. F-Secure Browsing Protection - Once you enter the URL it will scan it for suspicious behavior.


2. ScanURL is another website you can used to scan a URL. It checks Google safe browsing, PhishTank and WebTrust services and give you a overall view of the website.

3. Stop badware is database keeps track of all the badware URLs. This service been used by Google for Google Chrome browser, fireFox, Paypal and Verizon.

4. Siteinspector is another site and it will give some inside information about the IP addresses and domain information as well.


5. AVG Online Web Page Scanner is a trustworthy scanner that can be used to scan your website or websites before visiting them.

What do you think? Do you have any secret tool that you used to check your website or website you are trying to visit is hosting malware or black listed. If you are a webmaster then it is always good practice to have Google webmaster account to keep track of your website. 

Monday, August 9, 2010

Why You Must Run MalwareByte Now

Malware (Virus, Spyware, AdWare, Trojan Horses, Worms, rootkits) are getting smarter everyday. I have noticed that one antivirus program could not handle all the malicious software coming to your computer as friendly software. Even though you are running the number one Antivirus software you must check your computer with another Malware removing software.

My Test

I have tested more than ten computers which are already protected with AVG, Norton and Kaspersky.
All the computers looks normal but actually they are not. I installed MalwareByte and update for the latest Malware definition file. Free version is quite enough for this. I did a full scan and found out that six out of ten computers are infected with some kind of Malware.


Non of the Antivirus programs are perfect. Each Program use different methods to detect Malware. Always try another Malware cleaner other than the one you are using.

Four Reasons Why I use Malwarebyte

It is free to scan and clean the malware
I can install while other antivirus programs run in the background.
It takes couple of minutes to install and update.
It has been working for me in number of cases to remove malware.

Download MalwareByte and run a full scan Today!

Important
If your Malware scanner (Including Malwarebyte) did not detect any malwares dose not mean that your computer is not infected.

Monday, March 1, 2010

Why internet keeps on disconnecting and extremely slow

Recently I noticed extremely slow internet connection and it keeps on disconnecting regularly. If you are experiencing such symptoms in your work or home network, you need to act fast.

Let us see the symptoms in details

• Internet speed is considerably slow
• Internet keeps on dropping and coming back
• When you visit a new website most of the time it says page cannot be found
• Web pages load without images and styles.
• Sometimes you might have to restart the router in order to get the internet back.
• Ping command will take longer and frequent timeouts.

If you are experiencing any of these problems with your internet connection, please go through the following checklist.

First, check with your internet service provider whether there is a problem with the internet connection. You might able to check if there is any scheduled system maintenance going on with the service provider website or by calling them. If there is nothing wrong at their end, you have to move to the next step.

Check all the computers connected to the internet whether any of the machines using peer to peer, or torrent downloading programs as these programs can kill the connection speed.

If that is not the case, you might have to check each machine for send and receive packets. In windows machines you can simply check that in Local Area connection. Alternatively, you can use this command in command prompt to check both sent and receive bytes and packets.

If you notice large numbers in send and receive packets without internet activity then there might be virus or Trojan infection. In our case, couple of computers were infected with Trojans that killed the local area network.

You can use softwares like etherboy or wireshark to check the network statistics to understand which machines are sending more packets. However, if it is a small network you can simply remove one computer at time from the router and check the internet connection status-using ping command.

Anyway I would recommend to install Malwarebyte which is free for all your computers and scan them out.

Wednesday, October 28, 2009

not a virus then what?

Recent couple of days I have come cross this not-a-virus: Malware. Most of the anti virus programs dose not block, clean or detect this Malware. Kaspersky able to detect and remove not a virus malware. If it is not a virus then what it is? How can it be harmful to you?


According to the definition of this Malware it is not a virus but there are so many types of it. Amazingly these type of malware can be find in many small softwares that can be download for free.

What is not-a-virus?

That can be anything but not a virus. That can be backdoor programs, RemoteAdmin programs, Fraud Tools and etc. These are not harmful like normal viruses. But these can cause many security vulnerabilities. Opening your computer for attackers. Therefore even if you download any of these programs you will not notice any symptoms immediately.

On the other hand these can be something that software are used for its functions. For example not-a-virus:Client-IRC.Win32.mIRC.603 is an IRC chat client nternet Relay Chat is a dedicated network used for real-time communication. However, Kaspersky included this in their extended database because its functionality may be used maliciously. mIRC functionality is often used by virus writers to create backdoors. Users should therefore exercise caution when using this program.

By it self these programs are not a threat but can be used for a attack later. So it is all up to you to download the softwares that are infected with not-a-virus. If you are downloading it from a trusted software company it might be safe otherwise it is pretty hard say what that can be used for.

Most of the Anti virus softwares dose not detect these programs. Kaspersky is one of the programs that detects these and block them and clean the files that are infected with not-a-virus. If you want to check your machine you can always download the Kaspersky trial version and check your machine and clean if there is any not-a-virus infections.

Personally I will not download such programs in to my main computer. But I do not mind in my test machines. But always better to be in safe side.

Monday, June 22, 2009

How twitter can kill your computer

Malware Threat is one of the trending topics in twitter search. What is it all about? It is basically about some malware links start to use twitter trending topics. Pretty much a new way to catch large number of twitter users.

how it works? According to mashable.com it malware links comes with normal tweets and and only affect you if you click on any of these links.

Beware “Twitterbest” and “Zasaden” in Twitter Search

Do not click on any of the linkes with these keywords.

If you click it will take you to a page that prompt you to upgrade the flash plug in and if you agree to download it the software install it self and then a error message saying there is a virus in your computer and need to download a Antivirus called "Fast-anti-virus-2009" for $89. (Goal of the malware)

Do not click on any of the links with these keywords “Twitterbest” and “Zasaden”.

Do not install any software or upgrade any drivers that pop up from any of the links.

It will be a really hard hard task to track the links as liks can be hidden using tools that use to shorten the urls (commonly use in twitter).

Also twitter shows the real time trending topics and that allows the attackers to target the most number of users at that time. Imagine if Google started to display real time trending search will create a big mess.

Wednesday, April 8, 2009

What is Conflicker Worm


Simplest definition is it is a computer worm that can harm your computer and recently most of the anti virus companies warn about Conflicker worm. Before going in to more details you should download the simple Conflicker Worm removal tool from Symentic website and run a scan to check whether your machine is infected with the virus.

Three simple steps you should take to prevent any attack from Conflicker Worm.

1. Install a proper antivirus and anti-spyware software.
2. Update your antivirus and anti-spyware definition files to the latest available.
3. Update your Windows to the latest security patch.

Not only to prevent Conflicker worm but to prevent from any virus or worm these three steps will be a great practice.

Sunday, February 1, 2009

Google Hacked??? - This is crazzy

Google Error - Google May Harm Malware Warning


I am tried searching for few things on google and all the results i got back said this site may harm your computer with a Malware Warning.

I thought it was problem related to my search query BUT

then I search for Google website from google and I got the same result. Here are the screenshot.

I tried restarting my computer, using firefox browser, chrome browser - everything returned the same. even tried google.com.au, google.com etc

Any one else experienced this problem??

Either the Google search Index is corrupted or Google is Hacked!

UPDATE: Google is BACK! :) We will have to wait for an official announcement from Google on the situation. I hope no private data stored on Gmail were compromised

Update: Google uses Stopbadware.org as its Malware partner and it had outsourced the malware check to it. Stopbadware.org is Down that brought down

Update: Spam emails spluring out into Inbox in Gmail after the Google May Harm situation. Hope this will be resolved soon

Update: Here's a official word from Google on the incident. I thought the Internet was coming to an end. I am Proud to have witnessed this event myself on the 31st of January 2009 :)

The company today blamed the mistake on human error and apologised to users and site owners whose pages were incorrectly labelled.

The glitch occurred between 1.30am and 2.25am, Google Inc said in an explanation on its company blog.

Anyone who did a Google search during that time likely saw the message "This site may harm your computer" accompanying every search result, the company said.

Google said it routinely flags any search results with that message if the site is known to install malicious software in the background or otherwise surreptitiously, a practice aimed at protecting its users.

It gets its list of suspicious sites from StopBadware.org, a non-profit project headed by legal scholars at Harvard and Oxford universities who research consumer complaints.

Today's error happened when the latest update to the list was received from StopBadware but was checked in such a way that the warning would apply to all URLs, the company said in a statement.

The glitch was caught by on-call staff and the file was quickly fixed, Google said.

Since the updates are applied in a staggered and rolling fashion, the errors began appearing at 1.27am and disappeared no later than 2.25am, with the duration for any particular user approximately 40 minutes, it said.

"We will carefully investigate this incident and put more robust file checks in to prevent it from happening again," said Marissa Mayer, vice-president of search products and user experience, in the statement.

Wednesday, September 17, 2008

Perfect Virus Scanner

Last time I end up one of my post with a question; “Can we trust an Antivirus?” I found a good example that can help me to find an answer. That is virusscan.jotti.org.


What is so special about virusscan.jotti.org?

Jotti is an online virus scanner powered by nineteen virus scanners and gives each result. So if you scan a file through Jotti, nineteen individual virus scanners will scan the file for viruses.

We cannot blame any of the antivirus software, because each one is base on their own logic to identify viruses. There are good points and bad points. Jotti’s logic is simple use as many as recognized virus scanners possible.

Virus scanners used by Jotti

A-Squared

AntiVir

ArcaVir

Avast

AVG Antivirus

BitDefender

ClamAV

CPsecure

Dr.Web

F-Prot Antivirus

F-Secure Anti-Virus

Ikarus

Kaspersky Anti-Virus

NOD32

Norman Virus Control

Panda Antivirus

Sophos Antivirus

VirusBuster

VBA32


You can see the last scanned positive result.


Scanner Malware name
A-Squared MalwareScope.Trojan-PWS.Pinch.1
AntiVir SPR/Agent.Z.1
ArcaVir Riskware.Hacktool.Agent.Z
Avast Win32:Agent-KIW
AVG Antivirus HackTool.BND
BitDefender Trojan.Hacktool.Agent.Z
ClamAV X
CPsecure HackTool.W32.Agent.z
Dr.Web X
F-Prot Antivirus W32/EmailWorm.GWV
F-Secure Anti-Virus HackTool.Win32.Agent.z
Ikarus MalwareScope.Trojan-PWS.Pinch.1
Kaspersky Anti-Virus HackTool.Win32.Agent.z
NOD32 probably a variant of Win32/Hacktool.Agent
Norman Virus Control X
Panda Antivirus Trj/Downloader.MDW
Sophos Antivirus X
VirusBuster I-Worm.Agent.BNDW
VBA32 X


If you look closely on this example you a see different viruses were found by different virus scanners. May be they identified the same virus with a different name. Some scanners failed to detect any virus at all.

Limitations I see in Jotti is that you can scan only one file at a time. You will not be able to download each and every virus scanner on your machine.

Conclusion is we cannot trust a single virus scanner. It might say it’s cleared but the file might be infected.

Wednesday, July 9, 2008

How to: Remove Trojan.Pakes

Trojan.Pakes is one of the latest viruses out break recently. This is how to remove Trojan.Pakes.

1. Start PC in Safe mode.
2. Delete Registry Entry:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Office

if you cannot find it in this location search for "msoff" and "Trojan.Pakes" in registry and it will give you the results that matches. This is really important as if you have more than one users it might affected on them.

3. Delete file 'msoff.exe'
4. Scan your PC in safe Mode with a free antivirus program. I would recomend AVG free antivirus. Also, you can down load Norton trail version.

Friday, June 20, 2008

How to: Remove Braviax.exe manually



I don’t trust all the free scanners I find when I Google “Remove Braviax.exe” or “Braviax.exe”. Most of them are another adware or spywae. Otherwise it will only scan your computer for free and ask money to remove them. Therefore I always trust couple of good antivirus and spyware programs like Norton (Not free but you can use the trial for 90 days) AVG (100% free and cool).

Then always there is a manual removal for each spy ware, virus or antivirus. You need go back and remove the registry and couple of files and folders from your computer.

Braviax.exe is another Trojan horse that can affect any version of windows (Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003 or Windows 2000).

If your computer is infected with Bravia.exe it will pop up windows warning style message saying

“Your computer is infected!
Windows has detected spyware infection!It is recomended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you.Click here to protect your computer from spyware!”


Removal Instructions

Update your antivirus program and do a full scan. If you don’t have any you can download AVG Antivirus and spy ware removal for free.

Then clean every threat found by your antivirus and get ready for a manual removal.

Go to windows file search and do a search for “Braviax” and do a full search and delete all the files you find. Braviax.exe in windows\system32 folder and figaro.sys are few of common file I found

Then go to registry edit (start> run> type “regedit” > enter) and do search (ctrl + f or go to “Edit” and the select Find) then search for “braviax” delete all the registry key found under that name. (Take a backup in any case if something goes wrong but remembers it is infected)

This is one of the common records in registry you can navigate to this location and remove it. However I have found couple of extra records in the registry when I have couple of users in my computer and if those accounts are infected. I think search for braviax and delete record is more effective.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"braviax" = "%System%\braviax.exe"

Restart your computer and everything should be fine.
Blog Widget by LinkWithin