Tuesday, September 2, 2008

Virus Protection - Malware, Spyware, Worms and different type of Viruses

In the year of 1983, one Mr. Fred Cohen explianed the name and defenition of “computer virus”, a virus was "a program that can 'infect' other programs by multiplying them to include a possibly evolved copy of itself.”



Mr. Cohen expanded his definition a year later in his 1984 paper, “A Computer Virus”, noting that “a virus can spread throughout a computer system or network using the authorizations of every user using it to infect their programs. Every program that gets infected may also act as a virus and thus the infection grows.”

Using that explanation, we can see that viruses infect program files. However, viruses can also infect certain types of data files, specifically those types of data files that support executable content, for example, files created in Microsoft Office programs that rely on macros. Compounding the definition difficulty, viruses also exist that demonstrate a similar ability to infect data files that don't typically support executable content - for example, Adobe PDF files, widely used for document sharing, and .JPG image files. However, in both cases, the respective virus has a dependency on an outside executable and thus neither virus can be considered more than a simple ‘proof of concept’. In other cases, the data files themselves may not be infectable, but can allow for the introduction of viral code. Specifically, vulnerabilities in certain products can allow data files to be manipulated in such a way that it will cause the host program to become unstable, after which malicious code can be introduced to the system. These examples are given simply to note that viruses no longer relegate themselves to simply infecting program files, as was the case when Mr. Cohen first defined the term. Thus, to simplify and modernize, it can be safely stated that a virus infects other files, whether program or data.








The terms 'VIRUS is bifurcated as per its nature of execution on different location of the Computer and it is devided in to: -

a) File infected Viruses - This type of Viruses that infect program files. These viruses normally infect executable files that buileded with innumerable codes such as .com and .exe files. This type of virus afftected only when we run an infected programme or files from LAN network, floppy disk, hard disk or from the internet. Most of these viruses are memory affected virus. once this viruses afftected the Memory that means it will automatically affect all the executable files that runs in the future.

b) Macro Viruses:- These types of viruses infect data files. They are the most common and have cost corporations the most money and time trying to repair. With the advent of Visual Basic in Microsoft's Office 97, a macro virus can be written that not only infects data files, but also can infect other files as well. Macro viruses infect Microsoft Office Word, Excel, PowerPoint and Access files. Newer strains are now turning up in other programs as well. All of these viruses use another program's internal programming language, which was created to allow users to automate certain tasks within that program. Because of the ease with which these viruses can be created, there are now thousands of them in circulation. Examples of macro viruses include W97M.Melissa, WM.NiceDay and W97M.Groov.

c) Boot sector viruses:- infect the system area of a disk; that is, the boot record on floppy disks and hard disks. All floppy disks and hard disks (including disks containing only data) contain a small program in the boot record that is run when the computer starts up. Boot sector viruses attach themselves to this part of the disk and activate when the user attempts to start up from the infected disk. These viruses are always memory resident in nature. Most were written for DOS, but, all PCs, regardless of the operating system, are potential targets of this type of virus. All that is required to become infected is to attempt to start up your computer with an infected floppy disk Thereafter, while the virus remains in memory, all floppy disks that are not write protected will become infected when the floppy disk is accessed. Examples of boot sector viruses are Form, Disk Killer, Michelangelo, and Stoned.





Symptoms of an infected PC

The following examples may be indications that a computer has been infected with a virus. Although these problems can be caused by a non-virus problem, they are the most reported symptoms of an infection.




  1. Programs take longer to load than normal.


  2. Computer's hard drive constantly runs out of free space.


  3. The floppy disk drive or hard drive runs when you are not using it.


  4. New files keep appearing on the system and you don't know where they came from.


  5. Strange sounds or beeping noises come from the computer or keyboard.


  6. Strange graphics are displayed on your computer monitor.


  7. Files have strange names you don't recognize.


  8. Unable to access the hard drive when booting from the floppy drive.


  9. Program sizes keep changing.


  10. In Windows, 32-bit errors keep occurring or Windows refuses to use 32-bit file or disk access.


  11. Conventional memory is less than it used to be and you can't explain it.


  12. Programs act erratically.


When you suspect that you PC is infected by a virus, the things you should do are, update your antivirus software and run a thorough scan of all hardrives. If it's infected, list the name of the virus(es). Try to clean or delete the infected file(s).


THERE IS DIFFERENT TYPES OF ATTACKS THAT CAN HAPPEN WITH YOUR COMPUTERS, NETWORKS, NETWORK CONNECTED PHERIPHERALA INCLUDING MEDIA PLAYER, PLAYSTATION, MOBILE ETC.. TO AVOID THE SAME WE HAVE TO TAKE CARE OF MANY THINGS THAT IS DIRECTLY OR INDIRECTLY ENTERING IN YOUR ELECTRONIC DEVICES THROUGH INTERNET, BUETOOTH, WIRED OR WIRELESS LAN OR INFRARED.


The attack of viruses can happen in different modes. In normal way the viruses attacks the main . exe files as explained above. But nowadays the way of functioning of virus programms are changed and the authors are very much care about writing the same that nobody can break the codes of the same. presently the virus attacks in a different way like malware, spyware, worms and many other different names. Once theses type of softwares downloaded when you are downloading your favourite programme or software, it will work as a agent between the virus software and your electronic media ( computer ). So i want to explain you waht is malware and spyware, trojen etc.


a) Malware : -


Malware, is a virus attack which we can explain as a software which is designed to damage a computer system or entire network without the consent of the ownner of the software. This software mostly downloaded at the time when you entering in a particular site to download different software then automatically these type of malicious software will be downloaded and affects the entire system. There is many types of malware activities which includes a malware which downloaded once in your pc and whenever you surf in the internet it will automatically updated and starting to download the malicious software. This will change the code of your web browser that is ie or netscape. For example you have seen that the webaddress will changed without our knowledge and website were trying to open in some of other address.

More recently, the greater share of malware programs have been written with a financial or profit motive in mind. This activities done through a malware authores, they will work for a particular client and there products. They want to increase there business aftre approaching a malware software author and generate a huge revenue for them.


Please follow the link which will will display latest Malware / Worm and Virues and how you can find out what action will be taken by the Firewall when an attempt of attack happens in the Pcs.http://www.privacyware.com/


b) Spyware and Trojen

Trojans and spyware perform similar functions, gathering and forwarding personal information from the user's computer, but Trojans activate without a user's permission.

Trojans are the first stage of an attack and their primary purpose is to stay hidden while downloading and installing a stronger threat such as a bot. Unlike viruses and worms, Trojan horses cannot spread by themselves. They are often delivered to a victim through an email message where it masquerades as an image or joke, or by a malicious website, which installs the Trojan horse on a computer through vulnerabilities in web browser software such as Microsoft Internet Explorer.


After it is installed, the Trojan horse lurks silently on the infected machine, invisibly carrying out its misdeeds, such as downloading spyware, while the victim continues on with their normal activities.

Spyware is a general term used for programs that covertly monitor your activity on your computer, gathering personal information, such as usernames, passwords, account numbers, files, and even driver’s license or social security numbers. Some spyware focuses on monitoring a person’s Internet behavior; this type of spyware often tracks the places you visit and things you do on the web, the emails you write and receive, as well as your Instant Messaging (IM) conversations. After gathering this information, the spyware then transmits that information to another computer, usually for advertising purposes

How you can protect your machines and other net connected electronics items from theses viruses is only you have to use a better software that can provide you a protection from these all malware and spyware that is trying to capture your personal informations and codes etc.

The best way to protect from cybercrime and other threats of virus attached visit the link below:-



http://www.symantec.com/norton/cybercrime/prevention.jsp


VIRUS PROTECTION SOFTWARES


There is a lot of software available in the Market but many are less affective or many of the viruses that are more complicated by the anti virus manufactures to sort out the issues generated in the coded software languages generated by well experienced software engineers. But still there is lot of softwares in the Market that can perfectly solve 99% of virus affected issuess and perfectlyt protect your valuable PCs, Servers, Laptop, Mobile, MP3, player etc.which is directly connected to www or downloading files, photoes or songs etc. through bluetooth, wi-fi, infrared etc. Here is some of the best software available in the Market with perfect touch of protection of virus, malware, trojen and different type of activities of virus.

Antivirus Softwares are available in Licensed Verion and Evaluation version also some companies providing the same for Business proimotion on Free basis but available only for single user license. some of the common Anti virus programmes that helps to protect from laware, Spyware, Trojens, Worms etc.

a) Symantech Corporation - Norton - http://www.symantec.com/index.htm

b ) Mcafee - http://www.mcafee.com/us/

c) Kapersky - http://www.kaspersky.com/

But one of the best service provider supporting only single user on Free Service basis is AVG.com = http://free.avg.com/

**************************************************************************


Different Types of Virus Attackes and solutions to prevent the same:-


Viruses can be devided in to two categories in which one category of viruses are not so harmful and some are very much harful for th entire network. As per study Globally, about 64% of companies were hit by at least one virus in the past 12 months, up from 53% the year before. In the United States, viruses stung 69% of companies. Those figures are about four times as high as the next highest category of security breaches: unauthorized network entry.



Most other forms of security problems declined or remained flat in the past year, with reports of information loss dropping from 15% of respondents to 11%; data and system integrity losses falling from 14% to 11%; and denial of service declining from 13% to 11% (see chart, below).
The only category of security problem other than viruses to show an increase this year is Trojan horses, which mimic familiar programs to trick users' into divulging passwords and other key information. The number of companies reporting Trojan horses jumped from 3% to 8%.


a) E-mail Virus Attack:-


E-mail message downloading, which is the latest security breach in the information technology, which provides a Vulnerable chance to the hackers to capture the entire secret of electronic message system. Also such e-mail leads the latest attack like worm.arrives as an attachment. When executed, the worm emails to everyone in your Microsoft Outlook address book. These types of viruses aren't intensely dangerous to your system, but they overload email servers and cost you and your firm lost productivity.


The Only Solution to prevent such e-mail virus attack is to:-




  • Regularly download and update all the current virus updates.


  • use the reputed companies anti virus which is updated daily with latest technology.


  • Do not open any attachments unless you know exactly what it is and who sent it to you.


  • Don't open attachments with your email client, open the mail itself in the server and don't try to download.


  • Save the file to your hard drive and run a virus check on it before opening the file."

Viruses can infect several components of a computer's operating and file system including:


System Sectors/Boot Records - Viruses can infect the parts of the system that are used to run programs and perform functions such as start up and shut down.



Microsoft Office Files or any Executive Files - Viruses can infect program files. These viruses stick to program files such as .com, .exe, .sys, etc. Some viruses hide in the memory of the computer at first, while others simply attack a specific software program, such as Microsoft Word. The Memmory resident virus attacks when a particular programme starts for its functioning.


Companion Files - Viruses can create companion files that are a special type of file that adds files that run on the hard disk.


Macros - Viruses can infect macro or data files.



Disk Clusters - Viruses can infect files through the disk directory.



Batch Files - Viruses can use batch files to infect a computer.


Source Code - Viruses can be in additional code that is added to actual program source code.



Visual Basic Worms - These worms use the Visual Basic programming language to control a computer and perform tasks.


Types of Computer Viruses



Viruses are categorized by how they infect computers. Some viruses fall into more than one of these categories.
Types of viruses include:


Polymorphic Viruses - Polymorphic viruses change characteristics as they infect a computer.



Stealth Viruses - Stealth viruses actively try to hide themselves from anti-virus and system software.



Fast and Slow Infectors - Fast and Slow viruses infect a computer in a particular way to try to avoid being detected by anti-virus software.


Sparse Infectors - Sparse Infectors don't infect very often.



Armored Viruses - Armored viruses are programmed to make eradication difficult.



Multipartite Viruses - Multipartite Viruses are viruses that may fall into more than one of these categories.


Cavity (Spacefiller) Viruses - Cavity (Spacefiller) viruses attempt to maintain a constant file size when infecting a computer in order to try to avoid detection.


Tunneling Viruses - Tunneling viruses try to "tunnel" under anti-virus software while infecting.



Camouflage Viruses - Camouflage viruses attempt to appear as a benign program.



Virus Droppers - Virus Droppers are a special category of programs that place viruses on computers but are not by themselves an actual virus.



Ways to Catch a Computer Virus


There are several ways to catch a computer virus:



From Floppy Disks - Be very careful about loading a floppy disk that has been in another computer in your computer, even if it is from a trusted source.



From the Internet - Viruses can be attached to various types of Internet files, such as graphics and program files that people download from the Internet. Just browsing the Internet does not put your computer at risk. You have to download and install a file for a virus to be able to infect a computer. Also e-mail which is downloaded in your computers can be vermy much dangerous to attract the viruses.



From E-Mail - Viruses often travel via e-mail attachments. E-mail messages by themselves do not carry viruses. Only .exe, .com or other types of executable files can carry a virus.


From a Computer Network - Computer Networks are groups of computers linked together by a large computer called a server. The server and these computers constantly share information. If one file that is used by several network users becomes infected with a virus, the virus will quickly spread to the other users.


Latest Attckes as per BBC Reported:-


http://news.bbc.co.uk/2/hi/technology/2693925.stm