August 1, 2009

Different Virus Description & Characteristic Part 2

Continuation...........

TROJANS

Unlike worms and viruses, trojan programs do not create copies of themselves. They sneak into a computer, for example, via e-mail or using a web browser when the user visits an "infected" website. Trojan programs are launched by the user and start performing their malicious actions as they run.

The behavior of different trojan programs in the infected computer may differ. The major functions of Trojans are blocking, modification and erasing of data, disruption of the operation of computers or computer networks. Besides, Trojan programs can receive and send files, run them, display messages, access web pages, download and install programs and restart the infected computer.

Types of trojan programs and their behavior are described in the table below.

Click to download table in PDF form

July 29, 2009

Different Virus Description & Characteristic

Everyday new viruses is being spread over the net and most of this viruses are difficult to neutralize in one's PC.So, I was thinking to run description summary in some of the characteristics of this malicious programs(viruses) for you to have better understanding.

Viruses are categorize into two, these are the Potentially Unwanted Programs and Malware Programs.I will focus more in the malware programs category since this is that bring most damage to one's PC.

Potentially Unwanted Programs-are created not intended solely to inflict damage. However they can be used to breach the computer's security, includes adware, pornware and other potentially unwanted programs.

Malware Programs
-are created with the purpose to damage a computer and its user, for example, to steal, block, modify or erase information, disrupt operation of a computer or a computer network.It is further divided into three subcategories: viruses and worms, Trojans programs and malware utilities.

1.Viruses and worms can create copies of themselves which are, in turn, capable of creating their own copies. Some of them run without user's knowledge or participation, others require actions on the user's part to be run. These programs perform their malicious actions when run.

2.Trojan programs do not create copies of themselves, unlike worms and viruses. They sneak into a computer, for example, via e-mail or using a web browser when the user visits an "infected" website. To be launched they require user's actions and start performing their malicious actions as they run.

3.Malware utilities are created specifically to inflict damage. However, unlike other malware programs, they do not perform malicious actions immediately as they are run and can be safely stored and run on the user's computer. Such programs have functions used to create viruses, worms and Trojan programs, arrange network attacks on remote servers, hacking computers or other malicious actions.

Viruses and Worms Sub-Category

A classic virus infiltrates into the system, it infects a file, activates in it, performs its malicious action and then adds copies of itself into other files.It reproduce only on the local resources of a certain computer, they cannot independently penetrate other computers. They can penetrate other computers only if it adds its copy into a file stored in a shared folder or on a CD or if the user forwards an e-mail messages with at infected attachment.

Code of a classic virus can penetrate various areas of a computer, operating system or application. Based on the environment, there is a distinction between file, boot, script and macro viruses.

Viruses can infect files using various methods. Overwriting viruses write their own code replacing the code of the file they infect and after they destroy the content of such file. The infected file stops working and cannot be disinfected. Parasitic viruses modify files leaving them fully or partially operating. Companion viruses do not modify files but create their duplicates. When such infected file is opened, its duplicate, that is the virus, will be run. There are also link viruses, (OBJ) viruses that infect object modules, viruses that infect compiler libraries (LIB), viruses that infect original text of programs, etc.

Worms - After it penetrates the system, the code of a network worm, similarly to the classic virus code, gets activated and performs its malicious action. The network worm received its name due to its ability to tunnel from one computer to another - without the user's knowledge - to send copies of itself through various information channels.

The major method of proliferation is the main attribute that differentiates various types of worms. The table below lists types of worms based on the method of their proliferation.

Click to download table in PDF form


To be continued...............

July 28, 2009

System takes time when opening the save path drop down list!


The unit is actually a Pentium Dual Core Processor with 1 GB DDR2 Memory, the system actually runs normally except when you try to save or save_as a file(particularly in Word and Excel), the saving path takes some time to appear(around 2 min) and that the user becomes impatient especially if he is in a hurry in his work.

I troubleshoot the problem, I tried everything from replacement of application program to virus check up, I even suggested that we will reformat it, but the user insist that reformatting should be the last option since they have a very important application that is difficult to restore.

I spent a little more time in troubleshooting the problem and I found out that the cause of it all is a non existing network drive,what happen is that application tries to locate the missing network drive causing it to stack for a while when you click the Save path drop down button as seen it the picture.I remove the non existing network drive in the system and everything backs to normal.

Next time you encounter same or similar problem make sure to check if there is a dead network drive mapped in your system, it may solve the problem.

God Bless!

July 25, 2009

Bad CMOS Battery may cause unusual Windows problem

The units are Pentium III and a Pentium IV, both units has drained CMOS battery. The problem I encountered is that Windows XP hangs up at start up if you just bypass the CMOS bad error by pressing F1 upon turned on.

It took me sometime to figure out what is the problem, I even mistaken it as a software problem, but later I discovered this thing happen if you bypass CMOS setup at startup without particularly setting up the date, I don’t really know exactly what cause it, maybe BIOS has problem interacting with Windows if date is not properly set.

I just love my work, it's full of surprises!