Category: Malware/Trojans

  • W32 Vb Fp and Externalvxd

    w32.vb.fp is a trojan and externalvxd.exe is a virus. 
    W32.vb.fp is a virus affecting Windows 32 systems (Window 2000/XP/Vista) written in Visual Basic.

    Remove W32/vb.fp and externalvxd.exe

  • Monster.com Hacked?

    Yesterday, we analyzed a sample of a new Trojan, called Infostealer.Monstres, which was attempting to access the online recruitment Web site, Monster.com. It was also uploading data to a remote server. When we accessed this remote server, we found over 1.6 million entries with personal information belonging to several hundred thousand people. We were very surprised that this low profile Trojan could have attacked so many people, so we decided to investigate how the data could have been obtained.

    — More at Symantec

  • Prevent Computer Viruses

    In the last three years or so I haven’t had a single computer virus on my main system unless I put it there on purpose.  I use a very simple method to prevent computer viruses and malware from ever getting on my system. 

    check it out here: http://elamb.org/hacked/how-to-prevent-computer-virus.htm

     

  • How to get Malware/Virus/Trojans on your Home Windows computer:

    1) Use Window 9x/2000/XP out of the box DO NOT bother to reconfigure it
      

    Don't create any login accounts with strong passwords
    Do all work from the adminstrator account (Windows does this out automatically  so   don't do anything)
    Do not bother with patches no matter how critical (Windows will prompt you to update, just ignore it)
    Don't disable the guest account
    Don't change the name of default administrator account
    Enable as many network protocols as you can

     

    2) Use Internet Explorer

    If you want your system to get infected with all kinds of malware DO NOT use Firefox or anytype of pop up blockers
    When you use IE, don't increase the security under: Tools | Internet Options | Security tab, just leave it as is
    Ensure all Java and ASP scripting languages are enabled, allowing other computers to load software on your computer remotely
    Never patch Internet Explorer

    3) Connect directly to the Internet

    Do not use any kind of firewall 
    Do not use Network Adress Translation (which will hide your IP adress)
    Do not load SP2 for Window XP
      

    4) Surf the deadliest sites with no protection

    Surf Serial/Crack/Warez sites and always completely trust their sites
    Porn sites with no protection
    Screen Saver sites
    “hacker sites”  not all hackers sites just “black hats” and script kiddie type sites
    Find dark IRCs
      

    5) Behavior that will help you get your system infected.

    Download Screen Savers from site you are not sure about
    Open emails from people you don't know
    If you get a Security Warning that says “Do you want to download XXXXPROCUT NAMEXXX..” Don't even bother reading the rest just click yes.
      

    6) Software that is more than likely infected

    Tools bars that automatically download without your permission
    Kazaa and some other free P2P tools

     

    List of Tools for faster Infection:

    Internet Explorer  (Firefox can affectively block malware)
    Broadband/DSL (use of a firewall using Network Adress Translation will hide you system)
    Windows 9.x/2k/XP (open source OSes such as Linux are less likely to be hacked)

     

  • Trojan Virus Encrypts your files, holds password ransom for $300

    A new Trojan identified as CryZip infects files on a computer by encrypting them, then demands a $300 ransom for the password to unlock the files.

    More and more reasons to have redundant back-ups of all important data.  I currently have my data on two different computers and a seperate server.  But what I'd like to do is get a good external storage device or (even better IMO) a DVD burner.  NO I don't have one yet.

    Even though it seems like it would be more time consumning to use DVDs to burn all my important files every month or so, it would be better than the alternative (external storage) since I keep hearing horror stories about them breaking down.

    read more | digg story

  • How to get rid of SpySheriff:

    “I have a malware infection on my laptop, i go into safe mode and look into
    the files and the virus file comes up as spysheriff with an icon.”

    How do i get rid of it?
    Is it easy to get rid of?
    How did i come accross it?

    *******************************************************

    How to get rid of it?

    Check out my site:

    http://elamb.blogharbor.com/hacked/removespysheriff.htm

    If you have already, try this:

    http://www.bleepingcomputer.com/forums/How_to_remove_SpySheriff_Winstallexe_Spysheriffexe-t22402.html

    The Easiest Way to get rid of it:
    Another way you may be able to remove it is to do a system restore:

    http://www.elamb.org/hacked/systemerror384.htm

    This is what I had to do because I had stuff going on even in Safe Mode.

    How did I get it?
    I was surfing some serial/crack/warez sites.  They are absolutely
    INFESTED with malware. Some porn sites are bad, but warez sites seem to
    be the worst.

    On way to Prevent it is to use FireFox:
    See top of this blog.


  • Detected Spyware! System error #384

    detected spyware system error #384

    This is a bogus error screen that replaces your browser's home page. The message Reads:

    Detected Spyware! System error #384

    Your IP address is XX.XXX.XX.XX. Using this address a remote computer has gained access to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help of install the software for deleting secret information about the sites you visited.

    You computer is full of evidences!

    More than likely, this message is just the tip of the iceberg. Using simple intrusion detection tools you will see that your system has scores of viruses, trojans, worms and other malware installed on it. The message is trying to get you to purchase some scamware.

     

    How to remove the “Detected Spyware! System error #384” message and all the malware on your system?

    There are actually a few relatively easy ways for removing this malware:

    USE FREE (LEGITIMATE) ANTI-SPYWARE

    PERFORM A SYSTEM RESTORE

    COMPLETELY RE-INSTALL WINDOWS (self explanatory, and complete overkill unless you have rootkit on your system or something crazy like that.)

    READ MORE HERE…

  • "Windows has detected spyware infection!"

    Want to know how to get rid of the “Windows has detected spyware infection!

     

    “Your computer is infected! [tag]Windows has detected spyware infection[/tag]!
    It is recommended to use special antispyware tools to prevent data loss Windows
    will now download the most up to date antispyware for you.
    Click here to protect your computer from [tag]spyware[/tag]!”

    Here is how to delete that annoying “computer is infected” message.

    If your seeing this message your system really is infected with some [tag]malware[/tag] (virus, trojan, spyware) and that message you see is a part of the malware. This type of malware typically is trying to get you to purchase a product to clean your system. When you click on the link they provide, it takes you to the very source of the malware on your system. It is supposed to look like some of the Window system messages you can get about updates. DON’T fall for it.

    DO NOT GIVE THESE PEOPLE YOUR CREDIT CARD INFORMATION!

    This page will give your more information on what it is and how to get rid of it.

  • Spy Sheriff Removal

    I was doing some testing on my Windows XP system surfing about some
    sites of “ill repute” with IE6 and got hit with something called Spy
    Sheriff
    .

    Spy Sheriff is like a watered down version of PS Guard or Smithfaud.  Like PS
    Guard
    , Spy Sheriff claims to want to remove all the malware it infects
    you system with.  Both of these horrible bits of malicious code
    are what I like to call scareware.  The get loaded on to your
    system along with about 100 other viruses, worms and trojans and take
    over you desktop with a message like “Spyware Infection”.  The
    application then “scans” your system.  And tells you that you must
    activate the Spy Sheriff or PS Guard in order to clean your
    system.  When attempt to remove Spy Sheriff using Add/Remove programs, it simply adds itself again once you reboot.

    In the background, all the malware they loaded on your system are
    collecting data and send status report to a parts of the world. 
    The scareware will usually make sure you know this to convince you to
    buy their product.  DO NOT GIVE THEM YOUR CREDIT CARD INFO!

    Here is how to remove Spy Sheriff.

  • Trojan Pretends to be Skype Update

    Another attempt to hijack systems with bait software.  P2P file share programs has lots of these bastards running around (the older free ones anyway).  I'll look into this and put together a manual on how to remove it… gotta find the bad Skype first.

    The Trojan horse, a variant of IRCbot, arrives in an e-mail purporting to be an update to Skype, the popular Internet telephony application. Once opened the malicious software displays a phony installation error message. It then blocks access to security updates and installs a back door on computers, MessageLabs said in a statement.

    read more | digg story