Tuesday, January 6, 2009

Torrent sites blocked by Trojan...

A trojan named Troj/Qhost-AC has been spotted on torrent sites labeled as a keygen for popular software. But in a strange surprise, the trojan would modify the users host file, rather than generating a key, changing popular torrent web sites like, The Pirate Bay, Suprbay (The Pirate Bay forum) and Mininova, the two most popular torrent sites on the internet to 127.0.0.1, making it impossible to visit these sites.

The Trojan caused pop-ups on users screens and played a sound file saying "downloading is wrong". The Trojan didn't install any other spyware or malware onto the victims PC, other than blocking the three web sites, something that many users thought was strange.


I know this is not so harmful trojan,but only if you know the technical details.For novoice users it can block their daily torrent spot.So,beware and very before you download torrents using vertor.com


Tuesday, December 16, 2008

ZoneAlarm 8.0.065.0


ZoneAlarm is an easy-to-use firewall that blocks hackers and other unknown threats.
  • Intrusion Blocking systematically identifies hackers and blocks access attempts.
  • Stealth Mode automatically makes your computer invisible to anyone on the Internet.
  • Automatic Program Configuration provides safety and simplicity by automatically configuring programs. Automatically decides whether to allow or deny Internet access to individual programs.
  • Expert Controls give savvy users precise control over security settings.
This free version is for non-commercial use only.

ZoneAlarm

Wednesday, February 20, 2008

Bugged by Virus??

So lately you suffered a computer crash and a headache of course due to a virus intrusion or a spyware. So people ask me what are the ways to avoid that. Here are some of the basic steps that everyone should follow to prevent such an intrusion.

1) Install a reputed antivirus software.

2) Upgrade your Internet Explorer to version 7

3) Use Firfox browser for increased security.

4) Regularly install windows update and keep it on.

5) Run liveupdate on your antivirus and put it on automatic update mode.

Read the complete article here: TechJunkies

(Sam is a Certified Ethical Hacker who blogs at TechJunkies)

Tuesday, October 2, 2007

OpenOffice bug hits multiple operating systems

Security experts have discovered vulnerabilities in OpenOffice.org that could allow attackers to remotely execute code on Linux, Windows or Apple Mac-based computers. OpenOffice version 2.0.4 and earlier versions are vulnerable to maliciously crafted TIFF files, which can be delivered in an e-mail attachment, published on a Web site or shared using peer-to-peer software. The next version of OpenOffice (version 2.3) arrived on September 17 and is not affected by the flaw. The vulnerability was discovered by researchers at iDefense, who claim that the OpenOffice TIFF parsing code is flawed.

"When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow," the iDefense team reported last Friday. TrustDefender co-founder Andreas Baumhof said: "This vulnerability allows someone to execute malicious code on your computer. It's an OpenOffice bug so it doesn't matter what type of operating system you run; it allows you to run malicious software with the same rights as the user who runs OpenOffice." "At this stage, it's only confirmed on Linux," Baumhof said. "But typically it would affect all operating systems. The only difference with Linux and Windows is that home users typically run Windows as the administrator."

Full Story

Saturday, September 29, 2007

Thumb Drive - self-destruct in 10 seconds

Thumb drives are a convenient and cool way to carry around your data, and with drive sizes in the gigabytes, you can store a ton of photos, files, music, and video in a very tiny space. Unfortunately, due to their small sizes, they are targets for information thieves.

Think about it - all that personal data - your resume, email, password-files, and pictures of your girlfriend can be picked up and copied and returned before you even noticed it was missing. You want to have this data handy, but handy for you and not for that scumbag down the hall with the sticky fingers.

Like you, the US Military wanted portable but secure storage, and the guys at IronKey stepped up. They've developed the perfect solution that's one-part thumb-drive, and two parts Mission: Impossible. Their thumb drives hold up to 4 Gigabytes of data, but includes a hardware encryption chip that scrambles the data so as to be completely unreadable without a password.


Passwords can be hacked, but not the IronKey. It's built to withstand attacks both virtual and physical. 10 incorrect password attempts, and the encryption chip self-destructs, making the contents of the flash drive totally unreadable. The contents of the drive are filled with epoxy, so if a hacker tries to physically access the chips, he'd more likely damage them instead. Even if he did get access to the memory chips, they'd be worthless without the encryption chip. Electron-shielded, even a scanning electron microscope can't get inside.

Applications built right onto the IronKey help keep your personal data safe. For example, the password manager keeps your passwords safe. How? Your passwords are securely stored in a hidden hardware-encrypted area inside the device (and not in the drive's file system), being first locally encrypted with 256-bit AES, using randomly generated keys encrypted with a SHA-256 hash of your device password. All of this data is then doubly encrypted with 128-bit AES hardware encryption. Hack that.

A secure copy of Firefox included with your IronKey encrypts your browsing session through a VPN tunnel to IronKey's Secure Sessions Service. It works by tunneling your entire web browsing communications through the Tor-based Secure Sessions proxy on your IronKey. The Secure Sessions tunnel connects over an encrypted connection to their network routing servers, which in turn route your traffic between a number of servers, and then eventually out to your destination website. This approach protects your identity and your confidentiality, encrypting and anonymizing your Web surfing on almost any network or VPN (virtual private network).

These drives have already seen duty in Afghanistan, keeping US Military secrets safe from unsavory people. They're certainly good enough even for your most sensitive data.

All this goodness is demoed here. Go check it out!
* Fast 30MBPS Read, 20MBPS Write
* Drive contents encrypted with AES CBC-Mode Encryption
* Onboard IronKey Password-manager keeps all your internet passwords safe
* Secure version of Firefox included that encrypts all your web-surfing traffic
* Encased in a potted metal case, not plastic, making it one of the strongest USB keys around
* Exceeds MIL-STD-810F military waterproofing standards
* The encryption chip self-destructs if an invasive attack is detected
* If your Ironkey is lost, you can restore from a secure backup to a new Ironkey in minutes
* Dual channel SLC NAND Flash for high-quality and read/write speeds
* Windows XP and Windows Vista only, but Mac and Linux drivers are in development

Wednesday, September 26, 2007

Outpost Security Suite Pro 2008 – public beta 3

Agnitum has reached a significant milestone with the release of the first public beta of Outpost Security Suite Pro 2008 (OSS 2008 ). Building on the solid foundation of the initial version of the suite, this latest product delivers a long list of additional threat protections and enhancements for users of Microsoft Vista.

Download: Outpost Security Suite Pro 2008 – public beta 3

Friday, September 14, 2007

PC Tools ThreatFire 3.0.7.0

ThreatFire is an easy-to-use application designed to protect your computer against malware such as trojans, spyware, rootkits, keyloggers, and buffer overflows by intelligently detecting and blocking behavior consistent with that of malware. ThreatFire does this by constantly monitoring your system, and analyzing programs and process activity. Whenever ThreatFire detects any unusual process or activity, it will display an alert with further information on the threat. If it is a known threat, then ThreatFire will automatically quarantine the malware and no further action is required on your part. If the threat is unknown, or new, then ThreatFire will display an alert and prompt you to Allow or Quarantine the process. All alerts provide detailed information to help you make an informed decision.

New features:

- Cyberhawk is now named ThreatFire, which has a new look and feel and is branded as a PC Tools product. The basic product layout and functions are similar to the older version, so hopefully it will be easy to make the switch to ThreatFire.
- Certain features previously found only in Cyberhawk Pro are now available in the new free product: ThreatFire Free Edition. These features include malware quarantine and removal, advanced custom rules, the rootkit scanner, and the built-in search on ThreatFire alerts which allows you to find out additional information on a threat.
- The “potentially malicious”alerts (yellow alerts) now give the option to Allow or Quarantine, instead of Allow or Deny. This is because ThreatFire is now able toquarantine any threats it detects, not just threats that wereclassified as “known” malware.
- The newPro versionincludes theon-demand scanning piece of PC Tools AntiVirusso that you can scan your system for dormant threats that may not becaught by ThreatFire’s real-time behavior-based protection. This AVscanner greatly increases the overall protection offered by ThreatFireand offers protection from a full spectrum of both known and unknownthreats.
- Greatly improved the overall protective capability of ThreatFire since the Cyberhawk v. 2.04 release.
- Fewer false positives.
- Miscellaneous other program fixes.

Home Page

Monday, July 23, 2007

Security : BitTorrent flaw hits Opera

A 'highly critical' vulnerability has been found in the Opera web browser which could be exploited to remotely compromise a user's system. The flaw is caused when Opera uses already freed memory to parse BitTorrent headers, and can lead to an invalid object pointer being de-referenced.

This can be exploited to execute arbitrary code if the user is tricked into clicking on a specially-crafted BitTorrent file and then removes it from the download pane by right-clicking. The vulnerability is reported in version 9.21 of Opera on Windows, but security monitoring website Secunia, which rated the flaw 'highly critical', said that other versions may also be affected. The problem can be fixed by upgrading to Opera 9.22.

But what i suggest is, do not use Opera for torrents. You can use uTorrent, BitComet etc... There are many freeware/Open Source torrent clients available.

Wednesday, June 20, 2007

F-Secure BlackLight 2.2.1064 Beta

F-Secure BlackLight Rootkit Elimination Technology detects objects that are hidden from users and security tools and offers the user an option to remove them. The main purpose is to fight rootkits and all kinds of malware that use rootkits. The F-Secure BlackLight Rootkit Elimination Technology works by examining the system at a deep level. This enables BlackLight to detect objects that are hidden from the user and security software.

* F-Secure BlackLight can detect and eliminate active rootkits from the computer. Traditional antivirus scanners can't detect active rootkits.

* On a normal system F-Secure BlackLight does not confront the user with a long list of suspected objects. This makes F-Secure BlackLight useful even for non-technical users.

* F-Secure BlackLight Rootkit Elimination Technology can be used in the background during normal system operation. Other available scanners require a reboot during scan or may produce false positives if the system is used during scanning.

F-Secure Home Page

Windows Live Bug - Door for Scammers

Microsoft Corporation has fixed a bug in its Windows Live ID registration that let users deceptively register a false e-mail address. The false e-mail address could then be used as an ID for Microsoft's Live Messenger program, which could trick a user into thinking they are chatting with someone who is not whom they appear to be. Erik Duindam, a Web developer in Leiderdorp, the Netherlands, reported the problem to Microsoft on Monday. Microsoft acknowledged it had fixed the bug but did not have further information on the flaw's impact.

It's unclear how long the flaw may have existed or how many accounts with deceptive instant messenger IDs could have been created. If a user attempts to create a Windows Live ID, Microsoft sends a confirmation e-mail to the e-mail address entered by the user. Without confirmation, Microsoft includes a warning with future messages sent by instant message, which appear as: fake@emailaddress (E-mail Address Not Verified).

However, accounts created over the weekend with fake e-mail addresses were still active as of Tuesday and carried no such warning. Microsoft should try to shut down the fake accounts as soon as possible but it could be difficult, especially if Microsoft was not aware of the flaw and can't track the spoofed accounts. An attacker could use the flaw as part of a social-engineering ploy, where users are tricked into doing something that puts their machine at risk. Users could be tricked into thinking they are talking to someone they trust.

PC World

Thursday, June 14, 2007

Belarc Advisor 7.2.20.0

The Belarc Advisor builds a detailed profile of your installed software and hardware, missing Microsoft hotfixes, anti-virus status, CIS (Center for Internet Security) benchmarks, and displays the results in your Web browser. All of your PC profile information is kept private on your PC and is not sent to any web server. The information includes Local Drive Volumes, memory Modules, printer information, Installed Licenses, Installed software, Multimedia information and a lot more.

* Operating Systems: Runs on Windows Vista, 2003, XP, 2000, NT 4, Me, 98, and 95.
* Browsers: Requires IE 3 or Netscape 3, and higher versions. Also runs on Opera, Mozilla, and Firefox.

Belarc Home Page

Monday, June 11, 2007

Red Hat - bundle with Symantec

Red Hat last week continued its appliance assault via a partnership with Symantec.

The companies have crafted a pair of software bundles meant to give Linux customers easier access to high-end security features. Customers can pick from pre-tested packages that included Red Hat Enterprise Linux or the Red Hat Application Stack with Symantec Critical System Protection. As you might expect, the packages are aimed at small- to mid-sized business that could use some help securing their data centers with relative ease.

Symantec's Critical System Protection handles a wide variety of tasks, including protection against zero day exploits and buffer overflow and memory-based attacks. It also automates some security policy procedures.

Since Critical System Protection covers both server and application protection, the companies will sell their new bundles as Secure Server Host and Secure Server Host for Applications. The server bundle, which will run on two-socket systems, covers intrusion protection and detection, while the application bundle, also aimed at two-socket x86 gear, focuses on security policy and compliance.

Read More...

Thursday, June 7, 2007

XPY 0.9.9

XPY is a small tool which disables the default threats of a Windows XP installation. Besides disabling Windows and some of its components to communicate with Microsoft servers, XPY improves privacy settings and your system’s security.

Features:
* Disable questionable services
* Disarm Internet Explorer
* Disarm Windows Media Player
* Remove Windows Messenger
* Improve privacy and security
* Improve performance

Though xpy is smaller than 60 kilobytes, it can close serious threats (i.e. DCOM) on long distance, where large service-packs can only protect you until a new security hole has been found.

XPY Home Page

Bugs Discovered In Yahoo Messenger!

Yahoo is working on a patch for critical Yahoo Messenger vulnerabilities that could enable a remote hacker to take control of a user's system. eEye Digital Security's researchers found the bugs within the last few weeks and reported them to Yahoo on Wednesday, according to Marc Maiffret, co-founder and CTO of the security company. eEye's researchers say there actually are multiple flaws in Version 8 of Yahoo's instant messenger client software. Maiffret was careful not to give out too much information about the flaw until Yahoo can issue a patch for it.

InformationWeek

Tuesday, June 5, 2007

AVG Anti-Spyware Free 7.5.1.36

AVG Anti-Spyware Free is a free anti-spyware protection tool developed by GRISOFT for home use. Anti-Virus programs offer insufficient protection against urgently growing threats like Trojans, Worms, Dialers, Hijackers, Spyware and Keyloggers. That's where the protection of AVG Anti-Spyware begins and supplements existing security applications to create a complete security system - because only a complete security system works effectively.

Features of AVG Anti-Spyware

- NEW Completely renewed user interface
- NEW Possibility to create exceptions
- NEW Shredder for secure file deletion
- NEW XP Antispy
- NEW BHO Viewer
- NEW LSP Viewer
- Heuristics to detect unknown threats
- Scanning and cleaning of the Windows registry
- Support for NTFS-ADS scanning
- Daily database updates
- Patch proof by using strong signatures
- Analysis tools (startup, connections and processes)
- Intelligent online-update
- Scan inside archives
- Secure detection and deletion of DLL-Trojans
- Generic crypter detection through emulation
- Generic binder detection
- Free E-Mail Support
- Automatic Clean Engine
- Quarantine for suspicious files
- Multilingual User Interface

Note: This setup contains the free as well as the paid version of AVG Anti-Spyware Free. After the installation, a free 30-day trial version containing all the extensions of the full version will be activated. At the end of the trial, these extensions will be deactivated and the program will turn into a feature-limited freeware version. The purchased license code can be entered at any time.

Home Page

PeerGuardian 2.0 RC1

PeerGuardian is a tiny firewall program especially designed for P2P software users, but also to anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections. It uses an online IP database for the blocking, but IP ranges can also be configured manually.

Home Page

Total Privacy 5.30

Total Privacy is a safe and easy-to-use to use privacy protection tool that stops all those pesky snoopers such as Cookies, history, index.dat, competitors and even your boss! from finding the trail of your computer use that modern internet browsers and many other programs leave behind. All this can be accomplished with a single click on the mouse, or even automatically!

Total Privacy Features:

** Extensive Areas **
Remove all traces and history of your recent Windows activity. Total Privacy 5 supports dozens of Microsoft Windows locations so that you can control what information stays on your computer.

** Browser Activity **
Keep your browsers clean and running smoothly. Total Privacy 5.0 now supports cleaning and washing for all the major and most common internet browsers (Internet Explorer, Netscape, FireFox, Mozilla, America Online and Opera).

** Instant Messengers Activity **
Cleanand Wash away the stored history of all of your private IMconversations and file transfers kept by all of your Instant Messagingprograms. Total Privacy 5.0 supports MSN Messenger, AOL IM, ICQ andYahoo! IM.

** Profiles and Automatic Cleaning Cycles **
Cleanand wash what you want, when you want with Total Privacy's Profiles.Profiles can be scheduled to Wash and Clean Automatically (ProfileAutomation) or run at a specified event (Browser closing, Windowsstarting up or shutting down).

** Custom Items **
Over 465 plugins(custom items) are included with Total Privacy 5 to clean and wash thefiles, folders, registry entries and other evidence of your activityleft behind by these programs.

Total Privacy Home Page

Monday, June 4, 2007

A-Squared Free 3.0.0.311 Beta

Security must not be a privilege. Under this motto, Emsi Software provides the Malware scanner a-squared Free completely free of charge for private use. But it is not a very limited version, it is a full tool to clean your computer from Malware. Not only Spywares, as detected by classic Anti-Spyware programs, but also especially Trojans, Backdoors, Worms, Dialers, Keyloggers and a lot of other destructive pests, which makes it dangerous to surf the web.

A-squared removes reliably:

* Trojans, Backdoors, Keyloggers, Rootkits
* Worms, Bots
* Dialers
* Spyware, Adware

The advantages to you:

- Frees your PC from Malware
Use the a-squared Free Scanner to scan your hard disk, remove all infections and restore your PC to maximum performance.

- Quarantine for emergency
Sometimes it is possible that the system may be unstable after removing Malwares because it already manipulated too much. Therefore it is recommended to place detected Malwares always in Quarantine first before removing it permanently.

- Daily updates for the best protection
Don't forget to run an online update before you scan your computer with a-squared Free. Note: The automatic update feature is only available in a-squared Anti-Malware.

- Exceptionally easy to use
Regardless of whether you are a computer expert or a beginner, you will quickly become familiar with a-squared Free. You do not have to be a specialist to free yourself from Malware.

Home Page

Thursday, May 31, 2007

Cyberhawk 2.0.4.34

Cyberhawk is patent-pending, security software for your computer. Cyberhawk protects you by intelligently blocking behavior consistent with that of malware such as viruses, worms, trojans, spyware, adware, rootkits, keyloggers, and buffer overflows. Cyberhawk vigilantly monitors any activity that might compromise the security of your computer. Technological advances allow Cyberhawk to monitor your computer at very low levels to seek out even deeply hidden threats. When you install Cyberhawk, it is already fully configured and no additional set up is required. Cyberhawk will automatically block any known malicious threats. For indeterminate threats, or threats that might be a virus, it will immediately suspend the suspicious process and present you with the choice to “Allow” or “Deny” the process. You can always undo any actions you decide to take. Information about the type of threat, a description of what it does, and the risk level associated with that type of threat, are always provided so that the program is intuitive and easy-to-use.

What's New in Cyberhawk 2.0.4.34

* Addressed Internet Explorer slow down and performance issues experienced by some users
* Improved malware cleanup and quarantine for more effective cleaning
* Added incremental install capability so that going forward updates can be delivered through patches instead of requiring a full uninstall followed by reinstall
* Fixed rootkit scanner hang issue when scanning directories with large numbers of files
* Rootkit scan dialog now includes a ‘Select All’ option and abilitiy to ignore or remember certain hidden objects in future scan results
* General improvements to overall protective capability
* Fewer false positives
* Miscellaneous other program fixes

Novatix Home Page

Friday, May 18, 2007

Symantec sues 8 firms for $55M

Anti-virus and computer security software-maker Symantec Corporation has announced it is suing eight companies, for a total of $55 million USD. Symantec alleges in filings in U.S. District Court in California that the businesses are guilty of trademark infringement, copyright infringement, fraud, unfair competition, trafficking in counterfeit labels and documentation, as well as false advertising. The software company is seeking between $4 million US and $10 million in damages in individual claims from the following companies: Acortech (California), mPlus (California), Logical Plus (New York), SoftwareOutlets.com (Florida), Rowcal Distribution (California), Global Impact, Inc. (Florida), Directron.com (Texas) and eDirect Software (Canada). Symantec is also seeking a permanent injunction in each of the lawsuits to block the companies named from selling "unauthorized Symantec products" and to surrender all alleged counterfeits of Symantec goods.

CBC News