Labels

Search This Blog

Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Monday, April 16, 2012

Computer worm


Computer worm

From Wikipedia, the free encyclopedia
Morris Worm source code disk at theComputer History Museum.
Spread of Conficker worm.
A computer worm is a standalone malware computer program that replicates itself in order to spread to other computers. Often, it uses a computer network to spread itself. This is due to security shortcomings on the target computer. Unlike a computer virus, it does not need to attach itself to an existing program. Worms almost always cause at least some harm to the network, even if only by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer.


Many
 worms that have been created are designed only to spread, and don't attempt to alter the systems they pass through. However, as the Morris worm and Mydoom showed, even these "payload free" worms can cause major disruption by increasing network traffic and other unintended effects. A "payload" is code in the worm designed to do more than spread the worm–it might delete files on a host system (e.g., the ExploreZip worm), encrypt files in acryptoviral extortion attack, or send documents via e-mail. A very common payload for worms is to install a backdoor in the infected computer to allow the creation of a "zombie" computer under control of the worm author. Networks of such machines are often referred to as botnets and are very commonly used by spam senders for sending junk email or to cloak their website's address. Spammers are therefore thought to be a source of funding for the creation of such worms, and the worm writers have been caught selling lists of IP addresses of infected machines.Others try to blackmail companies with threatened DoS attacks.
Payloads

Backdoors can be exploited by other malware, including worms. Examples include Doomjuice, which spreads better using the backdoor opened by Mydoom, and at least one instance of malware taking advantage of the rootkit and backdoor installed by the Sony/BMG DRM software utilized by millions of music CDs prior to late 2005.


Worms with good intent

Beginning with the very first research into worms at Xerox PARC, there have been attempts to create useful worms. The Nachi family of worms, for example, tried to download and install patches from Microsoft's website to fix vulnerabilities in the host system–by exploiting those same vulnerabilities. In practice, although this may have made these systems more secure, it generated considerable network traffic, rebooted the machine in the course of patching it, and did its work without the consent of the computer's owner or user.
Some worms, such as XSS worms, have been written for research to determine the factors of how worms spread, such as social activity and change in user behavior, while other worms are little more than a prank, such as one that sends the popular image macro of an owl with the phrase "O RLY?" to a print queue in the infected computer. Another research proposed what seems to be the first computer worm that operates on the second layer of the OSI model (Data link Layer), it utilizes topology information such as Content-addressable memory (CAM) tables and Spanning Tree information stored in switches to propagate and probe for vulnerable nodes until the enterprise network is covered.
Most security experts regard all worms as malware, whatever their payload or their writers' intentions.


Protecting against dangerous computer worms

Worms spread by exploiting vulnerabilities in operating systems. Vendors with security problems supply regular security updates (see "Patch Tuesday"), and if these are installed to a machine then the majority of worms are unable to spread to it. If a vulnerability is disclosed before the security patch released by the vendor, a zero-day attack is possible.
Users need to be wary of opening unexpected email, and should not run attached files or programs, or visit web sites that are linked to such emails. However, as with the ILOVEYOU worm, and with the increased growth and efficiency of phishing attacks, it remains possible to trick the end-user into running a malicious code.
Anti-virus and anti-spyware software are helpful, but must be kept up-to-date with new pattern files at least every few days. The use of a firewall is also recommended.
In the April–June, 2008, issue of IEEE Transactions on Dependable and Secure Computing, computer scientists describe a potential new way to combat internet worms. The researchers discovered how to contain the kind of worm that scans the Internet randomly, looking for vulnerable hosts to infect. They found that the key is for software to monitor the number of scans that machines on a network sends out. When a machine starts sending out too many scans, it is a sign that it has been infected, allowing administrators to take it off line and check it for viruses. In addition, machine learning techniques can be used to detect new worms, by analyzing the behavior of the suspected computer.

Adware


Adware


Adware, or advertising-supported software, is any software package which automatically renders advertisements. These advertisements can be in the form of apop-up. They may also be in the user interface of the software or on a screen presented to the user during the installation process. The object of the Adware is to generate revenue for its author. Adware, by itself, is harmless; however, some adware may come with integrated spyware such as keyloggers and other privacy-invasive software.


Advertising functions are integrated into or bundled with the software, which is often designed to note what Internet sites the user visits and to present advertising pertinent to the types of goods or services featured there. Adware is usually seen by the developer as a way to recover development costs, and in some cases it may allow the software to be provided to the user free of charge or at a reduced price. The income derived from presenting advertisements to the user may allow or motivate the developer to continue to develop, maintain and upgrade the software product. Conversely, the advertisements may be seen by the user as interruptions or annoyances, or as distractions from the task at hand.
Application

Some adware is also shareware, and so the word may be used as term of distinction to differentiate between types of shareware software. What differentiates adware from other shareware is that it is primarily advertising-supported. Users may also be given the option to pay for a "registered" or "licensed" copy to do away with the advertisements. The Eudora e-mail client is an example of an adware "mode" in a program. After a trial period during which all program features are available, the user is offered a choice: free of charge with limited functionality, a mode with full functionality which displays advertisements for Eudora, or a paid mode that enables all features and turns off the ads.


Malware

Some adware can also be classified as spyware, a type of malware (malicious software) which steals information.


Prevention and detection

Programs have been developed to detect, quarantine, and remove spyware, including Ad-Aware, Malwarebytes' Anti-Malware, Spyware Doctor and Spybot - Search & Destroy. In addition, almost all commercial antivirus software currently detect adware and spyware, or offer a separate spyware detection package
The reluctance to add adware and spyware detection to commercial antivirus products was fueled by a fear of lawsuits.[citation needed] Kaspersky, for example, was sued by Zango for blocking the installation of their products. Zango software and components are almost universally detected as adware nowadays.[citation needed]


  • 180SearchAssistant
  • Ask.com Toolbar
  • Bonzi Buddy
  • ClipGenie
  • Comet Cursor
  • Cydoor
  • DollarRevenue
  • FlashGet
  • Gator
  • Isearch
  • Mirar Toolbar
  • MyWay Searchbar
  • Viewpoint Media Player
  • WhenU SaveNow
  • Zango products
  • Zwinky
  • HotBar
  • Tencent QQ
  • Play Pickle

Get to know about the Trojans and stay safe



Do you think you are safe with all the latest technology and outstanding anti-malwares? Unfortunately, majority of antivirus software cannot deal with all the viruses and spywares. Trojans virus is mutating day by day, and it’s not an easy task for researchers and developers to develop new software over night to battle against it. It’s an ongoing war between good guys and bad guys.

Like Worms, spywares and other kind of viruses, Trojan viruses are also infecting computers on a very large scale. From domestic users to big networks of computers, everywhere, people are facing the same problem.

Trojan or a new face of online terror

I. What it’s all about?

A Trojan is a very common virus threat, which is also known as Trojan horse. It is basically the software, which is designed to steal data or damage your PC. Trojan is a very lethal virus and can provide a hacker with very safe intrusion. Through this virus, a hacker can have remote access to your computer. Unfortunately, Trojan infection is on the rise and more than 83% of global computer users complain about this software. It can work very well with other Worms and can spread easily with them on the wide surface of global internet communication.

II. How Trojans ruins your system?

By keystroke logging
  • Through deletion of files
  • Via monitoring user’s screen
  • By computer crash
  • Via internet viewing
  • Through uploading or Downloading files on PC

Don’t get infected

It can easily spread to a big network of computers through internet. It is one the most dangerous executable programs. Mostly, Trojan viruses have risky and suspicious file extensions. To avoid such risks, it is recommended that you should completely unhide file extensions.
The easiest way for a Trojan horse to infect your PC is through free games, free movies, free songs and other “FREE” stuff. Mostly, dumb people use to download files from different free sites (mostly FTB or WWW) and let the Trojan invade their PCs. Similarly, opening suspicious mails, instant messaging and using IRC can ruin your PC.

How you come to know?

Early signs of a Trojan infection can be as other PC users complain about your system of spreading a “Trojan virus disease”. It’s proven that whenever a computer user carelessly handles e-mails and downloads files from suspicious sites, the chances of infection gets higher.

Master of  disguise

Trojans are just like normal software and if you are not a computer geek, then it’s hard to make a difference. Usually, it takes a refuge into your PC by some other application or software, which you may conceive as some antivirus or some useful virus detector. Trojan horses are not able to replicate or make copies of them, but still, they are dangerous as they can provide a hacker the backdoor or secret entry into your so-called safe computer.

A good coalition partner

Trojan horse virus is able enough to make a good coalition with other worms and viruses. Initially, a Trojan horse virus shows itself as very useful software, but soon it starts damaging your system. Mostly, people get trapped by this software, as in the beginning, it is just like useful software, which they consider should be downloaded for better performance of your PC, but sooner or later such Trojan horses take control of your system without your consent.