PCCare247.com Blog, PC Care 247 Tech Support Redefined
Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Monday, 5 March 2012

Beware!! For these processes have a Malicious Intent


Malware RemovalMalware – The term is so synonymous with everything that intends to shred the security of our PC into tatters. But then again, also on a flipside, in spite of the entire hullabaloo, not all malware is malicious in intent and is commonly referred to as spyware; malicious software truly hell bent on infiltrating computers every now and then.

A case wherein hackers end up refining the capabilities of malware, expanding the flux technologies in order to obscure the infrastructure and making it even harder to locate their servers. However, in the recent times recent variants have come out that are able to detect when someone is investigating an activity; in order to respond with a flooding attack against an investigator. In short, malware is becoming stickier on target machines and more difficult to shut down.

So, just in case to prepare PC users better, we ended up preparing a list of processes which need to be watched out for in order to take any malware threat head on. Starting with:

ISASS.EXE
A part of Optix.Pro virus, Isass.exe is also better known as the Optix.Pro Trojan that carries along with it a payload ability to disable firewalls, local security protections and the ability to open a backdoor capability for fairly unrestricted access into a PC. The Trojan was a brainchild of someone by the name of s13az3; who at the same instance also ended up being a part of the Evil Eye Software crew.

NVCPL.EXE
A component of W32.SpyBot.S Worm; Nvcpl.exe is a process that is registered as the W32.SpyBot.S worm (It at the same time is also associated with the Yanz.B worm which again is once again just another name). Taking advantage of the Windows LSASS vulnerability, the process creates a buffer overflow, forcing a PC to shut down. Although not necessarily considered to be a particularly destructive piece of malware, it is a nuisance since it continues to access an e-mail address books while at the same time sending spam to contacts.

CRSS.EXE
Crss.exe is a process-forming part of the W32.AGOBOT.GH worm. The spyware worm is distributed via the Internet through e-mail and acquires the form of an e-mail message, in the hope that a PC user would end up opening the hostile attachment. The worm has its own SMTP engine to gather E-mails from a local computer while at the same instance trying to re-distribute itself. Yet, at the same time in worst case circumstances, the worm also ends up allowing attackers to access a PC while stealing personal data and passwords.

SCVHOST.EXE
A part of the W32/Agobot-S virus family, the scvhost.exe file belongs to the Agobot (aka Gaobot) PC worm family. The Trojan ends up spreading itself via networks and allows attackers to access a PC from remote locations, steal their passwords and along with it all forms of Internet banking and personal data.

SVHOST.EXE
Svhost.exe is a process associated with the W32.Mydoom.I@mm worm. The worm is distributed as an e-mail message and requires a PC user to open a hostile attachment. Using the SMTP engine, the MyDoom worm is known to gather e-mails from a local computer in order to redistribute itself. Further, as it would go, the other payload carried by the process was a denial of service attack on the website of SCO Group. But that’s somehow not it, for the later versions of the worm have also been known to carry out denial of service attacks on other sites, and those popularly being Google and Lycos. http://www.pccare247.com/pc-security/malware-removal.html

Tuesday, 3 January 2012

Computers get a shiver down their spine with five deadliest viruses of all time


‘Nightmare on Elm Street’ has its own online ‘Avatar’ and this time around it is in the form of five deadly viruses PC users would have ever faced. Deadly, Menacing, Ominous as metaphors would also end up coming short in giving an account of mayhem these viruses have unleashed on hapless PC users.   

Death Knell for a PC comes in innumerous forms
PCCare247 Computer Support
Viruses have many forms, stretching from problematic worms spreading like wildfire to backdoor entrances caused by Trojan horse imposters, they are all geared up to break down every PC’s defense mechanism. But then again, discussing about all viruses is a farfetched scenario, so here I would at best enlighten you about only 5 computer viruses which have over time unleashed ‘hell’ on the web.

Well, what are you waiting for go ahead and fortify your PC’s defense mechanism for the going is certainly going to get ugly.

The Evil 5 

Klez
Released in the online world on October 2001, the Klez virus spreads via email sent from an infected recipient’s email address. To a large extent highly malicious in its intent, the Klez turned up the heat an extra notch. Klez was in fact one of the first viruses to spoof email addresses, replacing the address in the “From” field with any address it so pleased. In a way making detection a difficult prospect as users ended up getting infected via their email address books. Klez as a virus was instrumental in exploiting vulnerability in Internet Explorer’s Trident rendering agent (also used in Outlook and Outlook Express) to wreak its havoc.

SQL Slammer Or Sapphire
SQL Slammer or otherwise known as Sapphire targeted Microsoft’s SQL Server and Desktop Engine database software while at the same time initiating a Distributed Denial of Service (DDoS) attack on various targets. Within minutes of infecting the first server, Slammer began doubling its number of infected machines every few seconds. The ATM outlets of Bank of America ended up bearing the brunt of this virus. At the same time, the city of Seattle was unable to take 911 calls for a period and clients travelling via Continental Airlines ended up experiencing ticketing and check-in hassles. The total damages caused by the virus were estimated to the tune of nearly 1 billion dollars.

MyDoom
‘MyDoom’ started making an appearance in inboxes across the globe in January 2004 and soon became one of the fastest worms to spread across web. Email messages containing the worm were often masked as delivery failures, prompting many to open and investigate the message. On a subsequent click of the attached file the worm would send itself to email addresses found in the local address book while at the same time leaving its replicated version in KaZaa’s shared folder. The knock-out effect of the virus resulted in placing a severe load on services like Yahoo and Google, thus slowing down a PC user’s web search by a long way. Further, the worm ended up carrying two payloads – one was a backdoor entrance allowing an intruder to control the infected computer and another one was a DDoS attack on the SCO group.

Sasser and Netsky
Considered to be amongst one of the most famous outbreaks ever to come into news, Sasser and Netsky are famous not only for their astonishing effectiveness but have been traced back to a 17-year-old German teenager called Sven Jaschan. In spite of being separate viruses, the similarities in the code linked both the viruses to the same individual. Developer whose name was given up by a friend once Microsoft issued a $250,000 bounty. Tried as a minor Sven received a 21-month suspended sentence (and well of course a flurry of job offers from premier security firms).

Storm Worm
Distributed in email messages with a subject line, “230 dead as storm batters Europe”, the Storm Worm as a nasty Trojan horse infected a user’s machine with a malware as and when it became active. Over time, the virus has also been seen masquerading behind other news-inspired subject lines. During its nascent stage, the virus ended up spreading at an incredible rate, with one analyst pointing out the company had detected over 200,000 emails containing links to the virus over a period of just days. To know more about virus  or PC threads just visit here: http://www.pccare247.com/virus-removal.html

PCCare247.com Copyright © 2012-2013 by PCCare247 Solutions (P) Ltd.