<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hackstacks &#187; Virus</title>
	<atom:link href="http://www.hackstacks.com/tag/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.hackstacks.com</link>
	<description>My Digital Life</description>
	<lastBuildDate>Fri, 03 Feb 2012 12:42:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Fake Anti-Virus called Security Shield is spreading in Twitter</title>
		<link>http://www.hackstacks.com/a-fake-anti-virus-called-security-shield-is-spreading-in-twitter/2392</link>
		<comments>http://www.hackstacks.com/a-fake-anti-virus-called-security-shield-is-spreading-in-twitter/2392#comments</comments>
		<pubDate>Sun, 23 Jan 2011 15:48:02 +0000</pubDate>
		<dc:creator>Renjith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.hackstacks.com/?p=2392</guid>
		<description><![CDATA[Be careful when you click on a re-tweeted tweet on twitter because it can be... <a class="meta-more" href="http://www.hackstacks.com/a-fake-anti-virus-called-security-shield-is-spreading-in-twitter/2392">more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-2393 alignleft" style="border: 0pt none;" title="Twitter_worm" src="http://www.hackstacks.com/wp-content/uploads/2011/01/Twitter_worm.gif" alt="" width="180" height="144" /></p>
<p>Be careful when you click on a re-tweeted tweet on twitter because it can be a twitter worm. The new threat is spreading in the form of tweets. You will not be able to recognize it by the URL as it short linked using the Google’s (goo.gl) URL shortening service. So, on the first glance it will look genuine.</p>
<p>But once you have clicked on the link it will redirect you to a Fake Antivirus called “Security Shield” after couple of domain re direction you will reach in a Ukrainian top level domain but that’s not the end ! Again you are re directed to an IP address and that will take you to the rogue anti-virus’s website.</p>
<p>After landing on the rogue AV website you are prompted with a warning saying that your machine is running malicious and you are exhilarated to run a free scan. If you say YES you are busted! The rouge antivirus named Security Shield will be loaded on your computer and start to scan. Finally it will show you a fake list of infected files, once you plan to go ahead with cleanup process it will prompt for a credit card purchase of the Fake Anti-virus.</p>
<p>The Fake Anti-virus uses RSA technology for code obfuscation. The RSA technology is widely used to deploy this type of threats.</p>
<p><em><strong>How to secure your computer from these threats?</strong></em></p>
<p>•	Update your Anti-virus with latest patches available. (Use live-updates)<br />
•	Update windows with latest patches available.<br />
•	Try to use industry standard Anti-virus rather than going for free ones. (Because paid ones will have better support against new threats)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackstacks.com/a-fake-anti-virus-called-security-shield-is-spreading-in-twitter/2392/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Simple Tweak to Speed-Up the Internet Explorer Response Time</title>
		<link>http://www.hackstacks.com/a-simple-tweak-to-speed-up-the-internet-explorer-response-time/1179</link>
		<comments>http://www.hackstacks.com/a-simple-tweak-to-speed-up-the-internet-explorer-response-time/1179#comments</comments>
		<pubDate>Tue, 17 Aug 2010 12:02:43 +0000</pubDate>
		<dc:creator>Renjith</dc:creator>
				<category><![CDATA[Quick Tip]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.hackstacks.com/?p=1179</guid>
		<description><![CDATA[I could see people are in love with Mozilla Firefox than the Internet Explorer when... <a class="meta-more" href="http://www.hackstacks.com/a-simple-tweak-to-speed-up-the-internet-explorer-response-time/1179">more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1180" style="border: 0px;" title="Internet-Explorer-Speed-up" src="http://www.hackstacks.com/wp-content/uploads/2010/08/Internet-Explorer-Speed-up.gif" alt="" width="347" height="276" /></p>
<p style="text-align: justify;">I could see people are in love with Mozilla Firefox than the Internet Explorer when I did a plain analysis on the web browser usage. Firefox was taking the first place while Internet Explorer moved to second place followed by Google Chrome on third and Safari on fourth. Faster response and useful Add-On features made the Firefox most favorite but still in many corporate companies are still forced to use the Internet Explorer because of some internal applications compatibility. It is a known problem that after using the internet explorer for a few months the browser will start slowing down and take longer time to load the applications. The reason behind this can be installing many internet explorer toolbar, installing unwanted application which adds BHO( Browser Helper Objects) to the internet explorer.<strong> </strong><a href="http://www.hackstacks.com/system-lookup-to-find-legitimate-programs-or-files/209" target="_blank"><strong>In my previous post I have written about BHO’s</strong></a><strong>.</strong></p>
<p style="text-align: justify;">I have seen this Google Toolbar in many computers and user does n’t has no idea about it. Once simple response from a user when I asked about Google Toolbar! “<em>It came up when I open the Google</em>”! Google toolbar is an example but there are thousands of toolbars available. Most of these will come up with certain application but you are provided option to uncheck if you do not want to install.</p>
<p style="text-align: justify;">Deleting or disabling these BHO will give better performance improvement in Internet Explorer. When you install many toolbars it is also adding corresponding BHO entries to the Internet Explorer, so when ever you try to load the Internet Explorer it will become unresponsive and unusable. Certain BHO’s will get removed when you uninstall the application or toolbar. But in some cases we will require the applications (ITunes, Google, Adobe etc) but does not require the BHO.</p>
<p style="text-align: justify;">In that situations we can make use of third party applications such as <a href="http://download.softpedia.com/dl/af0e48ac1a7eedb23d8c9b839c022ceb/4c6a705e/100130528/software/security/SpyBHORemover.zip">Spy BHO Remover</a> to delete BHO entries in internet explorer. Spy BHO Remover is capable of detecting good and bad entries. It gives option to either Delete the BHO or Disable the BHO if you find the BHOs in red go ahead and delete it.</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://www.hackstacks.com/a-simple-tweak-to-speed-up-the-internet-explorer-response-time/1179/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple QuickTime Triggers Malware!!</title>
		<link>http://www.hackstacks.com/apple-quicktime-triggers-malware/868</link>
		<comments>http://www.hackstacks.com/apple-quicktime-triggers-malware/868#comments</comments>
		<pubDate>Sun, 01 Aug 2010 17:19:54 +0000</pubDate>
		<dc:creator>Sudeep</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.hackstacks.com/?p=868</guid>
		<description><![CDATA[Trend Micro lab reports that Apple Quicktime’s  specifically crafted .mov files trigger the download of... <a class="meta-more" href="http://www.hackstacks.com/apple-quicktime-triggers-malware/868">more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><img class="alignnone size-full wp-image-882" style="border: 0pt none;" title="apple-quick-time" src="http://www.hackstacks.com/wp-content/uploads/2010/08/apple-quick-time2.jpg" alt="" width="347" height="276" /></p>
<p style="text-align: justify;">Trend Micro lab reports that Apple Quicktime’s  specifically crafted <em>.mov</em> files trigger the download of malware masquerading as a codec update and an installation file for another player when run in the latest (7.6.6) version of QuickTime Player.</p>
<p style="text-align: justify;">Researcher Marco Dela Vega says that both files pretend containing Salt, the latest Angelina Jolie movie, but that his suspicion was aroused by the unusually small size of the files &#8211; small when compared to regular movie files, that is.Upon running the movie files in QuickTime, the &#8220;movie&#8221; does not start and the download windows for the malware pop up, asking you to save/run the codec update or the installation file.</p>
<p>Trend Micro is still investigating the matter and it&#8217;s not yet known if this attack is possible due to a vulnerability or feature of QuickTime. Apple has, of course, been notified of the occurrence.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackstacks.com/apple-quicktime-triggers-malware/868/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Abundant With Malware</title>
		<link>http://www.hackstacks.com/google-abundant-with-malware/778</link>
		<comments>http://www.hackstacks.com/google-abundant-with-malware/778#comments</comments>
		<pubDate>Thu, 29 Jul 2010 17:18:43 +0000</pubDate>
		<dc:creator>Sudeep</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[Bing]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.hackstacks.com/?p=778</guid>
		<description><![CDATA[Barracuda security labs have conducted study across Bing,Google,Twitter and yahoo and yet another reveals shocking... <a class="meta-more" href="http://www.hackstacks.com/google-abundant-with-malware/778">more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify"><img class="alignnone size-full wp-image-785" style="border: 0pt none" src="http://www.hackstacks.com/wp-content/uploads/2010/07/Baracudda-labs.gif" alt="" width="347" height="276" /></p>
<p style="text-align: justify">Barracuda security labs have conducted study across Bing,Google,Twitter and yahoo and yet another reveals shocking news. They conducted a 2 month study over these search engines; the analysis reviews more than 25,000 trending topics and nearly 5.5 million search results. The purpose of the study was to analyze trending topics on popular search engines to understand the scope of the problem and to identify the types of topics used by malware distributors.</p>
<p style="text-align: justify"><strong>Results included:</strong></p>
<ul style="text-align: justify">
<li>Google tops when when it comes to Malware distribution with its share of shocking 69%  as much as twice as Bing ,Yahoo,Twitter combined don’t match with Google.Yahoo has 18% ,Bing has 12.5 % and twitter 1 %.</li>
<li>A vulnerable topic appearing in Google takes nearly 1.2 days,Bing 4.3 days and Yahoo 4.8 days.</li>
<li>Timespan found with maximum exposure is 4.00 am and 10.00 am GMT (Means main business hours in different geo locations).</li>
</ul>
<ul style="text-align: justify">
<li>The      top 10 terms used by malware distributors include the name of a NFL      player, three actresses, a Playboy Playmate and a college student who      faked his way into Harvard.</li>
</ul>
<p style="text-align: justify"><strong>Twitter threat!</strong></p>
<p style="text-align: justify"><strong> </strong></p>
<p style="text-align: justify">Barracuda labs also analyzed more than 25 million Twitter accounts (Malicious and Legitimate)</p>
<p style="text-align: justify">Some not so good results:</p>
<ul style="text-align: justify">
<li>People gets more attracted to twitter accounts, activity increases, tweets increases thus malicious activity increases.</li>
<li>Another revealing is only 29% of Twitter accounts are true Twitter users.(Barracuda stats)</li>
<li>Exclusive crime rate of Twitter was for the first half of 2010 was 1.67 %</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.hackstacks.com/google-abundant-with-malware/778/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Lookup to find legitimate programs or files</title>
		<link>http://www.hackstacks.com/system-lookup-to-find-legitimate-programs-or-files/209</link>
		<comments>http://www.hackstacks.com/system-lookup-to-find-legitimate-programs-or-files/209#comments</comments>
		<pubDate>Sat, 05 Dec 2009 09:32:02 +0000</pubDate>
		<dc:creator>Renjith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.hackstacks.com/?p=209</guid>
		<description><![CDATA[What is System Lookup? Are you doubtful about a file or program which came in... <a class="meta-more" href="http://www.hackstacks.com/system-lookup-to-find-legitimate-programs-or-files/209">more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone size-full wp-image-211" title="System Lookup" src="http://www.hackstacks.com/wp-content/uploads/2009/12/systemlookup.jpg" alt="System Lookup" width="450" height="183" /></p>
<p><strong>What is System Lookup?</strong></p>
<p>Are you doubtful about a file or program which came in to your computer as uninvited? System lookup is a database provides information about legitimate files and programs which we call it as Malwares or Spywares! Currently System Lookup claims they have added over 85,000 items in their database. It is sustained by the great members of various forums.</p>
<p><span id="more-209"></span></p>
<p><em><span style="text-decoration: underline;">It is maintained a data base of the below list.</span></em></p>
<p><strong>CLSID</strong> &#8211; Browser Helper Objects (BHOs), Toolbars (TBs), SearchHooks (SHs), Explorer Bars (EBs).</p>
<p><strong>Extra Internet Explorer Buttons</strong> &#8211; It can be extra buttons on the Internet explorer toolbar, or extra items in the &#8216;Tools&#8217; menu.</p>
<p><strong>Layered Service Providers</strong> – It is a DLL that use Winsock APIs to insert itself into the TCP/IP stack. It can capture and alter the Internet traffic.</p>
<p><strong>ActiveX installers </strong></p>
<p><strong>Extra protocols and protocol hijackers</strong> – For hijacking various protocols.</p>
<p><strong>AppInit_DLLs and Winlogon Notify</strong> &#8211; These are used by Trojans and Hijackers.</p>
<p><strong>ShellServiceObjectDelayLoad</strong> &#8211; Unnecessary programs to start with Windows.</p>
<p><strong>SharedTaskScheduler</strong> &#8211; This is only applied in NT/2000/XP.</p>
<p><strong>Windows NT Services</strong></p>
<p><strong><em>So what happens when you find such bad files in your computer?</em></strong></p>
<p>You can very much follow the manual deletion steps which are provided in various Antivirus provider websites. Symantec and McAfee like companies will provide you removal tools for such infections.</p>
<p style="text-align: center;"><img class="size-full wp-image-212 aligncenter" title="Search Info" src="http://www.hackstacks.com/wp-content/uploads/2009/12/fileinfo.jpg" alt="Search Info" width="604" height="143" /></p>
<p style="text-align: center;"><em>Search Info for Iehelper.dll file</em></p>
<p>System Lookup is providing you an option to contribute, if you find a file which is good or bad and not listed in their data base.</p>
<p style="text-align: left;">Official Website : <a href="http://www.systemlookup.com/">http://www.systemlookup.com</a></p>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://www.hackstacks.com/system-lookup-to-find-legitimate-programs-or-files/209/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

