<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jhong Medina&#039;s Qlick Blog &#187; Antivirus</title>
	<atom:link href="http://www.qlickcafe.com/blogs/tag/antivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.qlickcafe.com/blogs</link>
	<description>Qlick Solutions, Web Design, IT News &#38; Events and  Internet Cafe Games Updates</description>
	<lastBuildDate>Tue, 11 May 2010 07:51:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How to protect your PC from Trojans, Viruses, and Worms Threat.</title>
		<link>http://www.qlickcafe.com/blogs/it-journal/how-to-protect-yourself-from-trojan-virus-and-worms-attacks/</link>
		<comments>http://www.qlickcafe.com/blogs/it-journal/how-to-protect-yourself-from-trojan-virus-and-worms-attacks/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 05:06:55 +0000</pubDate>
		<dc:creator>Jhong Medina</dc:creator>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Qlick Tips and Tricks]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.qlickcafe.com/blogs/?p=546</guid>
		<description><![CDATA[
What are Trojans, Viruses and Worms?

Viruses, Trojans, Worms and other cyber threats are now a part of daily life. Malware spreading throughout the Internet, hackers stealing confidential data and mailboxes flooded with spam are the price we pay for computing convenience. Any unprotected computer or network is vulnerable.

 

A computer virus is a computer program [...]]]></description>
			<content:encoded><![CDATA[<div id="qlicksolution">
<h1>What are Trojans, Viruses and Worms?</h1>
</div>
<p>Viruses, Trojans, Worms and other cyber threats are now a part of daily life. Malware spreading throughout the Internet, hackers stealing confidential data and mailboxes flooded with spam are the price we pay for computing convenience. Any unprotected computer or network is vulnerable.<br />
<span id="more-546"></span></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-6253842080202367";
/* 468x60, created 1/13/09 */
google_ad_slot = "9323334255";
google_ad_width = 468;
google_ad_height = 60;
// --></script> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p>
<p><img class="alignleft" style="margin-left: 10px; margin-right: 10px;" src="http://www.qlickcafe.com/imageblogs/trojan-horse.jpg" alt="" width="180" height="226" /></p>
<p><strong>A computer virus </strong>is a computer program that can copy itself and infect a computer without the permission or knowledge of the user. The term &#8220;virus&#8221; is also commonly but erroneously used to refer to other types of malware, adware and spyware programs that do not have the reproductive ability.  </p>
<p>The name &#8220;<strong>Trojan</strong>&#8221; came from The Greek Methology &#8220;Trojan Wars&#8221;. in the context of computing and software, describes a class of computer threats (malware) that appears to perform a desirable function but in fact performs undisclosed malicious functions that allow unauthorized access to the host machine, giving them the ability to save their files on the user&#8217;s computer or even watch the user&#8217;s screen and control the computer.  </p>
<p><strong>A computer worm </strong>is a self-replicating computer program. It uses a network to send copies of itself to other nodes (computers on the network) and it may do so without any user intervention. Unlike a virus, it does not need to attach itself to an existing program. Worms almost always cause at least some harm to the network, if only by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer.  </p>
<p><!-- You will NOT be able to see the ad on your site! This unit is hidden on your page, and will only display to your search engine traffic (from US and CA). To preview, paste the code up on your site, then add #chitikatest=mortgage to the end of your URL in your browser's address bar.  Example:  www.yourwebsite.com#chitikatest=mortgage. This will show you what the ad would look like to a user who is interested in "mortgages." --> <script type="text/javascript"><!--
ch_client = "jhongmed";
ch_type = "mpu";
ch_width = 550;
ch_height = 120;
ch_color_bg = "333333";
ch_color_border = "333333";
ch_color_title = "FF9B00";
ch_color_site_link = "FF9B00";
ch_color_text = "FFFFFF";
ch_non_contextual = 4;
ch_vertical ="premium";
ch_font_title = "Comic Sans MS";
ch_font_text = "Comic Sans MS";
ch_sid = "Chitika Premium";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
// --></script><br />
<script src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></p>
<h2>How can I protect my computer from these attacks?</h2>
<p>Although these threats can&#8217;t be avoided, you can still protect your computer systems by doing the following:</p>
<h3>1. Install an Anti-virus Software.</h3>
<p>Make sure that you have an anti-virus software installed in your PC. There are lot of Free Antivirus Software that you can download from the web. Here&#8217;s are some:</p>
<p><a href="http://free.avg.com/download-avg-anti-virus-free-edition"><strong>AVG Free  Edition</strong></a> &#8211; Protection against viruses, spyware, adware and trojans.<br />
<strong><a href="http://www.kaspersky.com/virusscanner">Kaspersky</a> </strong>- scans your computer for malicious code and offers the same<br />
exceptional detection rates as other Kaspersky Lab products<br />
<strong><a href="http://www.free-av.com/en/download/index.html">Avira AntiVir Personal</a> </strong> &#8211; from Avira GmbH protects you computer against viruses,<br />
malware, adware and spyware, unwanted programs and other dangers. This manual<br />
deals with viruses and software in brief.</p>
<h3>2. Security Updates.</h3>
<p>Your operating systems offers you a free security updates on regular basis. Just make sure that you download it and install it to your system.</p>
<p><a href="http://www.microsoft.com/security/default.mspx">Microsoft Security Updates</a></p>
<p><a href="http://support.apple.com/kb/HT1222">Apple Security Updates</a></p>
<p><a href="http://www.redhat.com/security/updates/">Red Hat Security Updates</a></p>
<h3>3. Don&#8217;t open or download software from an unreliable sources.</h3>
<p>Usually, you can get Trojan Horses from unsolicited emails with file attachment. Always make sure that you only open attachment from a reliable source. Avoid opening any executable file from emails or downloading it using P2P applications such as limewire or bearshare. Here&#8217;s are some extension name you should avoid downloading:</p>
<p>exe, com, bat, vbs, js, and inf file extensions</p>
<p>Note:</p>
<p>If you are using removable drives such as USB Flash drives&#8230; Make sure that you scan it first and avoid opening it from auto run or auto play.</p>
<h3>4. Use An Anti-Spyware software if your connected to the internet.</h3>
<p>Lastly, use an Anti-Spyware software to protect you when accessing the internet.</p>
<p>Here are some example:</p>
<p><strong>Windows Defender -</strong> It&#8217;s free for Microsoft Genuine Windows User.</p>
<p><strong>AVG Internet Security </strong>- It&#8217;s <span class="price">USD                         54.99 but a complete and reliable solution.<br />
</span></p>
<p><strong>Norton 360 </strong>- <strong>Protects your PC, online activities and your identity 24/7</strong> – Delivers award-winning protection against viruses, spyware, worms, phishing, hackers, and more in one complete, fully automated solution.  USD $79.<span>99</span></p>
<div class="linkwithin_hook" id="http://www.qlickcafe.com/blogs/it-journal/how-to-protect-yourself-from-trojan-virus-and-worms-attacks/"></div>]]></content:encoded>
			<wfw:commentRss>http://www.qlickcafe.com/blogs/it-journal/how-to-protect-yourself-from-trojan-virus-and-worms-attacks/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>How to Remove W32.Downadup.B Virus?</title>
		<link>http://www.qlickcafe.com/blogs/it-journal/how-to-remove-w32downadupb-virus/</link>
		<comments>http://www.qlickcafe.com/blogs/it-journal/how-to-remove-w32downadupb-virus/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 10:19:41 +0000</pubDate>
		<dc:creator>Jhong Medina</dc:creator>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Qlick Solutions]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.qlickcafe.com/blogs/?p=513</guid>
		<description><![CDATA[W32.Downadup.B Virus was discovered by Symantec last December 30, 2008, and was announce to public January 9, 2009. Now it widely spreading all over the world and it floodings network connections.
 
This virus monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network [...]]]></description>
			<content:encoded><![CDATA[<p>W32.Downadup.B Virus was discovered by Symantec last December 30, 2008, and was announce to public January 9, 2009. Now it widely spreading all over the world and it floodings network connections.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-6253842080202367";
/* 468x60, created 1/13/09 */
google_ad_slot = "9323334255";
google_ad_width = 468;
google_ad_height = 60;
// --></script> <script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p>
<p>This virus monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network request timed out.  We (my MIS Team) discovered W32.Downadup.B Virus from our quarantine logs and we found out that it was introduce to the network using a USB drive activated by autorun.inf.</p>
<p><img class="alignnone" src="http://www.qlickcafe.com/imageblogs/w32virus.jpg" alt="" width="358" height="341" /></p>
<p><!-- You will NOT be able to see the ad on your site! This unit is hidden on your page, and will only display to your search engine traffic (from US and CA). To preview, paste the code up on your site, then add #chitikatest=mortgage to the end of your URL in your browser's address bar.  Example:  www.yourwebsite.com#chitikatest=mortgage. This will show you what the ad would look like to a user who is interested in "mortgages." --> <script type="text/javascript"><!--
ch_client = "jhongmed";
ch_type = "mpu";
ch_width = 550;
ch_height = 120;
ch_color_bg = "333333";
ch_color_border = "333333";
ch_color_title = "FF9B00";
ch_color_site_link = "FF9B00";
ch_color_text = "FFFFFF";
ch_non_contextual = 4;
ch_vertical ="premium";
ch_font_title = "Comic Sans MS";
ch_font_text = "Comic Sans MS";
ch_sid = "Chitika Premium";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
// --></script><br />
<script src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></p>
<p>W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed. The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible.<br />
<span id="more-513"></span><br />
You won&#8217;t be able to detect it using the command prompt because it run by using the RPC Handling Remote Code Execution. How to remove the virus just follow the steps below:</p>
<h2><strong>Follow these Steps:</strong></h2>
<p><strong></strong></p>
<p>1. Download the removal tool from <a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/D.exe">Symantec website</a> and place it on your desktop.</p>
<p>2. Download the Security patch from microsoft website. ( Choose the file support with your OS).</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0D5F9B6E-9265-44B9-A376-2067B73D6A03&amp;displaylang=en"> for Windows XP (KB958644)</a></p>
<p>3. Temporarily Disable System Restore (Windows Me/XP).</p>
<p>4. ​​​Update the virus definitions (If your using Symantec).</p>
<p>5. Reboot your computer in SafeMode.</p>
<p>6. Run the FixDownadup.exe that you have just downloaded and let it scan until it found a viruses.</p>
<p>7. Run the Security Patch.</p>
<p>8. Reboot your system in normal mode and run the Full System Scan to make sure that no virus present on  your computer.</p>
<p>9. As preventive measure We disabled autorun in the registry and disable USB Port access to all workstation.</p>
<p>Below are stats from Symantec regarding this virus.</p>
<h2>Threat Assessment</h2>
<p><strong>Wild</strong></p>
<p>* Wild Level: Medium</p>
<p>* Number of Infections: 1000+</p>
<p>* Number of Sites: 10+</p>
<p>* Geographical Distribution: Medium</p>
<p>* Threat Containment: Moderate</p>
<p>* Removal: Moderate</p>
<p><strong>Damage</strong></p>
<p>* Damage Level: Medium</p>
<p>* Modifies Files: Modifies the tcpip.sys file.</p>
<p><strong>Distribution</strong></p>
<p>* Distribution Level: Medium</p>
<p>* Shared Drives: Attempts to spread to network shares protected by weak passwords.</p>
<p>* Target of Infection: Spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (BID 31874)</p>
<div class="linkwithin_hook" id="http://www.qlickcafe.com/blogs/it-journal/how-to-remove-w32downadupb-virus/"></div>]]></content:encoded>
			<wfw:commentRss>http://www.qlickcafe.com/blogs/it-journal/how-to-remove-w32downadupb-virus/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>
