<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Security Software &#187; Conficker</title>
	<atom:link href="http://www.antivirus-buyability.co.uk/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.antivirus-buyability.co.uk</link>
	<description>Internet Security &#38; Antivirus Reviews</description>
	<lastBuildDate>Mon, 05 Dec 2011 06:04:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Top Tracked Viruses</title>
		<link>http://www.antivirus-buyability.co.uk/top-tracked-viruses/</link>
		<comments>http://www.antivirus-buyability.co.uk/top-tracked-viruses/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 10:20:09 +0000</pubDate>
		<dc:creator>2020plus1</dc:creator>
				<category><![CDATA[My Viruses]]></category>
		<category><![CDATA[UpDates]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus detection]]></category>

		<guid isPermaLink="false">http://www.antivirus-buyability.co.uk/?p=1238</guid>
		<description><![CDATA[McAfee maintain a list of the current top tracked viruses and their characteristics. The current list of prime suspects is most illuminating. Most are trojans, but two are worms: Exploit-ObscuredHtml Exploit-MS06-006 Generic!atr HTML/FakeAV Exploit-PDF.b.gen Generic PWS.ak W32/Conficker.worm!inf W32/Rimecud Generic FakeAlert!cr Bredolab.gen.d. As to which are trojans and which are viruses, the clue is in the [...]]]></description>
			<content:encoded><![CDATA[<p>McAfee maintain a list of the current top tracked viruses and their  characteristics.</p>
<p>The current list of prime suspects is most illuminating. Most are  trojans, but two are worms:</p>
<ul>
<li>Exploit-ObscuredHtml</li>
<li>Exploit-MS06-006</li>
<li>Generic!atr</li>
<li>HTML/FakeAV</li>
<li>Exploit-PDF.b.gen</li>
<li>Generic PWS.ak</li>
<li>W32/Conficker.worm!inf</li>
<li>W32/Rimecud</li>
<li>Generic FakeAlert!cr</li>
<li>Bredolab.gen.d.</li>
</ul>
<p>As to which are trojans and which are viruses, the clue is in the  title of one, but it&rsquo;s not so easy in the other. The infamous  W32/Conficker.worm!inf is one and the other is W32/Rimecud.</p>
<p>But lets have a look at one of the trojans first.  Exploit-ObscuredHtml. To remind ourselves, this is a trojan  and it&rsquo;s  so-called because its takes it lesson from ancient Greece mythology.  They are spread inadvertently by people who think that they are  downloading, or swapping to someone else, a file which is of some use.  In reality, it&rsquo;s an illegal gateway to someone&rsquo;s computer. And because  unlike viruses they don&rsquo;t replicate, they rely on manual distribution  methods such as email, malicious, or hacked web pages, Internet Relay  Chat (IRC), or peer-to-peer networks.</p>
<p>Now Exploit-ObscuredHtml is an exploit by sub-type and it exists as  code in an email message, web page, or HTML document.</p>
<p>Interestingly, certain non-ascii characters are ignored by Microsoft  Internet Explorer, allowing an attacker to obfuscate malicious code. And  still have it rendered by Internet Explorer. But the detection of this  particular trojan covers HTML documents that have been crafted with the  intention of evading antivirus detection. And there are other documents  that mix HTML with non-ascii characters which could also trigger this  detection.</p>
<p>Now lets take a brief look at the W32/Conficker.worm!inf. The  Conficker caused virtual panic in the media earlier in 2009 and its was  dubbed the mother of all viruses. Actually it has been around for some  years, although this version was particular virulent. <br />
The sub-type is a worm and it is a file which is usually dropped onto  the root of all removable drivers and mapped drives in an attempt to  autorun an executable when the drive is accessed.</p>
<p>IT people can spot infection when they see the prescence of  autorun.inf files on the root of all removable drives or mapped network  drives containing specific information.</p>
<p><span style="color: rgb(153, 153, 153);">Guest Article by </span><strong><span style="color: rgb(153, 153, 153);">Neil Camp</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.antivirus-buyability.co.uk%2Ftop-tracked-viruses%2F&amp;title=Top%20Tracked%20Viruses"><img src="http://www.antivirus-buyability.co.uk/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-buyability.co.uk/top-tracked-viruses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BitDender’s Top  Malware for May</title>
		<link>http://www.antivirus-buyability.co.uk/bitdender%e2%80%99s-top-malware-for-may/</link>
		<comments>http://www.antivirus-buyability.co.uk/bitdender%e2%80%99s-top-malware-for-may/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 11:30:47 +0000</pubDate>
		<dc:creator>Neil Camp</dc:creator>
				<category><![CDATA[My Viruses]]></category>
		<category><![CDATA[UpDates]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.antivirus-buyability.co.uk/?p=1199</guid>
		<description><![CDATA[Top malware in May according to computer security company BitDefender is an Autorun trojan. May&#8217;s top malware goes by the name of Trojan.AutorunInf.Gen and represents just over 13% of all global malware. It&#8217;s designed to use external hard drives, memory cards and flash drives to spread malware. And although Microsoft may have discarded its Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Top <strong>malware</strong> in May according to computer security company <strong>BitDefender</strong>  is an Autorun trojan.</p>
<p>May&rsquo;s top malware goes by the name of Trojan.AutorunInf.Gen and  represents just over 13% of all global malware. It&rsquo;s designed to use external hard drives, memory cards and flash drives to spread malware. And although Microsoft may have discarded its Windows Autorun feature from its latest operating systems and from Vista SP2, early versions are still vulnerable.</p>
<p>Next on the top malware list for May is the infamous Kido, or Conficker, which goes by the tag of Win32.Worm.Downadup. This nasty virus takes a bow for around 6% of global infections and attacks a Windows vulnerability. It spreads via local network computers and stops users trying to access Windows updates and security companies web pages. Latest versions of Windows has removed the vulnerability, but people using older operating systems should ensure that they have updated their operating systems and anti-virus applications.</p>
<p>In third place and close behind the Conficker on the top malware list is another Trojan which accounts for some 5% of all infections. It&rsquo;s official name is Trojan.FakeAV.KUE and it&rsquo;s based on JavaScript code. It creates anti-virus scams and the malware gets hosted either on sites that unknowingly carry the virus, or malicious sites.  Once people download this type of malware, it triggers various fake alerts offering rogue antivirus software.</p>
<p>Coming fourth is the May top malware list is Win32.Sality.OG. It&rsquo;s the only file infector virus in the top ten and it&rsquo;s a device which appends its encrypted code to executable files (.exe and .scr binaries). It does this by deploying a rootkit which kills any antivirus applications on the computer. This means that it remains undetected and unable to carry out its malicious tasks.</p>
<p>In the fifth place is a new one to the top malware charts. It&rsquo;s a Trojan and is responsible for a tad over 2% of infections. Called the Trojan.Swizzor.2, it acts as a pathfinder for a number of other pieces of malicious software.</p>
<p>BitDefender&rsquo;s top malware chart for May includes:</p>
<ol>
<li>Trojan.AutorunINF.Gen 		13,24%</li>
<li>Win32.Worm.Downadup.Gen	5,84%</li>
<li>Trojan.FakeAV.KUE 		5,11%</li>
<li>Win32.Sality.OG 			2,68%</li>
<li>Gen:Variant.Swizzor.2 		2,12%</li>
<li>Trojan.Autorun.AET 		2,02%</li>
<li>Gen:Heur.Krypt.24 		2,01%</li>
<li>Worm.Autorun.VHG 		1,97%</li>
<li>Gen:Variant.Rimecud.2 		1,91%</li>
<li>Exploit.PDF-JS.Gen 		1,76%</li>
</ol>
<p>One things is for sure, try to avoid any of the top malware for May.</p>
<p><span style="color: rgb(153, 153, 153);">Guest Article by </span><strong><span style="color: rgb(153, 153, 153);">Neil Camp</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.antivirus-buyability.co.uk%2Fbitdender%25e2%2580%2599s-top-malware-for-may%2F&amp;title=BitDender%E2%80%99s%20Top%20%20Malware%20for%20May"><img src="http://www.antivirus-buyability.co.uk/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-buyability.co.uk/bitdender%e2%80%99s-top-malware-for-may/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BitDefender’s March e-Threat Report</title>
		<link>http://www.antivirus-buyability.co.uk/bitdefender%e2%80%99s-march-e-threat-report/</link>
		<comments>http://www.antivirus-buyability.co.uk/bitdefender%e2%80%99s-march-e-threat-report/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 10:28:52 +0000</pubDate>
		<dc:creator>Neil Camp</dc:creator>
				<category><![CDATA[My Viruses]]></category>
		<category><![CDATA[UpDates]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.antivirus-buyability.co.uk/?p=1050</guid>
		<description><![CDATA[The latest threat report from BitDefender shows that top of the nasty parade for March was a USB Trojan. Known by the tag Trojan.Autoruninf.Gen, it accounted, says BitDefender, for 13% of total global malware in March. Trojan.Autoruninf.Gen is a mechanism of a generic nature which is designed to spread via removable drives. It exploits an [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>latest threat report from BitDefender</strong> shows that top of the nasty parade for March was a USB Trojan.</p>
<p>Known by the tag Trojan.Autoruninf.Gen, it accounted, says BitDefender, for 13% of total global malware in March. Trojan.Autoruninf.Gen is a mechanism of a generic nature which is designed to spread via removable drives. It exploits an established vulnerability when people swap files using physical devices such as memory sticks.</p>
<p>Number two in March was that old favourite the Conficker, or Kido as its otherwise known. Although at 6% of total global malware in March less than half the threat posed by Trojan.Autoruninf.Gen, it is still being a nuisance and hanging around. Its trick is to exploit a Microsoft Windows vulnerability and to get rid of it, users have to update their operating system and ensure that their anti virus software is up to date.</p>
<p>In third is another old favourite, one which gets hold of Adobe&rsquo;s PDF Reader&rsquo;s JavaScript engine and uses it to piggy back malicious code into a computer. It&rsquo;s known as Exploit.PDF-JS.Gen and it&rsquo;s a nasty piece of work which uses a very commonly used application.</p>
<p>But talking of nasties, in fourth is one that takes the biscuit. It&rsquo;s a file infector known as Win32.Sality.OG. What&rsquo;s makes this family of infectors so bad, is that it&rsquo;s protected by a polymorphic code, which makes it extremely difficult to firstly detect and then remove. What&rsquo;s more, the rootkit part of the virus does its best to disable antivirus applications on the computer its attacking. One to be avoided at all costs.</p>
<p>In at number five this is the Trojan.JS.Downloader.BIO. Inserted into legimate webpages via SQL injection methods and tactics, this is actually JavaScript. It only targets those websites built with ASP. Another characteristic of Trojan.JS.Downloader.BIO. is that is forms cookies from bits of information about a victim&rsquo;s browsing habits which are then sent to a website based in China.</p>
<p>That&rsquo;s the top five, but here&rsquo;s the complete <a href="http://shop.antivirus-buyability.co.uk/manufacturer/BitDefender,b.html"><strong>BitDefender</strong></a> run for March:</p>
<ol>
<li>Trojan.AutorunINF.Gen 13,40</li>
<li>Win32.Worm.Downadup.Gen 6,19</li>
<li>Exploit.PDF-JS.Gen 5,30</li>
<li>Win32.Sality.OG 2,58</li>
<li>Trojan.JS.Downloader.BIO 2,13</li>
<li>Trojan.Autorun.AET 1,95</li>
<li>Gen:Heur.Krypt.21 1,921</li>
<li>Worm.Autorun.VHG 1,78</li>
<li>Exploit.PDF-Payload.Gen 1,67</li>
<li>Trojan.Wimad.Gen.1 1,42.</li>
</ol>
<p><span style="color: rgb(153, 153, 153);">Guest Article by </span><strong><span style="color: rgb(153, 153, 153);">Neil Camp</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.antivirus-buyability.co.uk%2Fbitdefender%25e2%2580%2599s-march-e-threat-report%2F&amp;title=BitDefender%E2%80%99s%20March%20e-Threat%20Report"><img src="http://www.antivirus-buyability.co.uk/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-buyability.co.uk/bitdefender%e2%80%99s-march-e-threat-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojans March On</title>
		<link>http://www.antivirus-buyability.co.uk/trojans-march-on/</link>
		<comments>http://www.antivirus-buyability.co.uk/trojans-march-on/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 12:20:33 +0000</pubDate>
		<dc:creator>Neil Camp</dc:creator>
				<category><![CDATA[My Viruses]]></category>
		<category><![CDATA[UpDates]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security software]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.antivirus-buyability.co.uk/trojans-march-on/</guid>
		<description><![CDATA[Trojans dominated the top ten e&#8211;threats for September according to a top security software company. BitDefender, creator of one of the industry&#8217;s fastest and most effective lines of internationally certified security software, produce a table of malware that represents the biggest threat on a month to month basis. And in number one spot for September [...]]]></description>
			<content:encoded><![CDATA[<p>Trojans dominated the top ten e&ndash;threats for September according to a top security software company.</p>
<p>BitDefender, creator of one of the industry&#8217;s fastest and most effective lines of internationally certified security software, produce a table of malware that represents the biggest threat on a month to month basis.</p>
<p>And in number one spot for September is the Trojan.Clicker.CM. The reason for this, ponder BitDefender, may be due to Tojan.Clicker&rsquo;s popularity as a weapon of choice amongst purveyors of &quot;warez.&quot; This a term used by malware developers to describe compromised software.</p>
<p>In second place is Trojan.AutorunINF.Gen and this is a generic detection for Trojans that use Autorun. Number three spot in this line-up of nasties goes to the Trojan.Wimad.Gen.1.</p>
<p>The infamous Conficker is never far away from any malware list and in this particular chart it occupies the fourth slot. BitDefender labels Conficker, in all its various guises, as Win32.Worm.Downadup.Gen.</p>
<p>At number five is an exploit which uses a vulnerability in the way some versions of the Adobe PDF reader parse embedded JavaScript is gaining popularity again. Exploit.PDF-JS.Gen is one to be careful of.</p>
<p>Trojan.Exploit.JS.Y slots into the number six position. It&rsquo;s a malicious piece of JavaScript, usually found on compromised or malicious websites.</p>
<p>In the number seven spot, down from number five, and a long-time star of the BitDefender&#8217;s Top 10 E-Threat is Win32.Sality.OG. It&rsquo;s an encrypted, polymorphic file infector and appears set for a very long cybercrime &quot;career&quot;.</p>
<p>In the eight and nine slots are two threats which use the Autorun security loophole found in older versions of Windows. BitDefender point out that the lower-spreading of the two threats is actually a downloader component used to spread the ever-present Conficker, or Kido worm (aka Downadup).</p>
<p>Bringing up the rear in tenth is Trojan.Skintrim.HTML.A, a type of HTML page usually found associated with adware programs such as Navipromo.</p>
<p>BitDefender&#8217;s September 2009 Top 10 E-Threat list is made up of:</p>
<ol>
<li>Trojan.Clicker.CM 			10.98%</li>
<li>Trojan.AutorunINF.Gen 		9.58%</li>
<li>Trojan.Wimad.Gen.1 			5.52%</li>
<li>Win32.Worm.Downadup.Gen 	4.68%</li>
<li>Exploit.PDF-JS.Gen 			4.09%</li>
<li>Trojan.Exploit.JS.Y 			3.44%</li>
<li>Win32.Sality.OG 			2.75%</li>
<li>Trojan.Autorun.AET 			2.27%</li>
<li>Worm.Autorun.VHG 			1.78%</li>
<li>Trojan.Skintrim.HTML.A 		1.49%</li>
<li>Others					53.41%</li>
</ol>
<p><span style="color: rgb(153, 153, 153);">Guest Article by </span><strong><span style="color: rgb(153, 153, 153);">Neil Camp</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.antivirus-buyability.co.uk%2Ftrojans-march-on%2F&amp;title=Trojans%20March%20On"><img src="http://www.antivirus-buyability.co.uk/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-buyability.co.uk/trojans-march-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee Says Spam, Botnets at an All Time High</title>
		<link>http://www.antivirus-buyability.co.uk/mcafee-says-spam-botnets-at-an-all-time-high/</link>
		<comments>http://www.antivirus-buyability.co.uk/mcafee-says-spam-botnets-at-an-all-time-high/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 13:37:38 +0000</pubDate>
		<dc:creator>Neil Camp</dc:creator>
				<category><![CDATA[My Viruses]]></category>
		<category><![CDATA[UpDates]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.antivirus-buyability.co.uk/?p=660</guid>
		<description><![CDATA[The second quarter threat report from McAfee has some bad news for all computer users out there. The main finding is that Spam volumes have increased by 141% since March, 2009, continuing the longest streak of increasing spam volumes ever. But that&#8217;s not all, as there has been a dramatic expansion of botnets and auto-run [...]]]></description>
			<content:encoded><![CDATA[<p>The second quarter threat report from McAfee has some bad news for all computer users out there. The main finding is that Spam volumes have increased by 141% since March, 2009, continuing the longest streak of increasing spam volumes ever. But that&rsquo;s not all, as there has been a dramatic expansion of botnets and auto-run malware.</p>
<p>The report highlighted the fact that 14 million computers have been enslaved by cybercriminal botnets, a 16% increase over last quarter.</p>
<p>Auto-run is becoming an increasing problem and over a test period of 30 days, it was discovered to have infected over 27 million files. Auto-Run malware, which exploits Windows Auto-Run capabilities, does not require any user clicks to activate. It is most often spread through portable USB and storage devices. Depressingly, the rate of detection surpasses the infamous Conficker worm by 400%, making it the number one piece of malware detected around the world.</p>
<p>Mike Gallagher, Senior Vice President and Chief Technology Officer of McAfee Avert Labs, said:<br />
&ldquo;The jump in bot and spam activity we saw in the last three months is alarming, and the threat from Auto-Run malware continues to grow. The expansion of these infections is a grave reminder of the potential harm that can be caused by unprotected computers in homes and businesses.&rdquo;</p>
<p>McAfee also provides some background showing the a generally worsening computer security situation.</p>
<p>It is noted that fourteen million additional computers have been turned into botnets this quarter. This equates to more than 150,000 computers infected every day, or 20% of the personal computers bought daily.</p>
<p>It also said that South Korea accounted for the largest boost in bot activity. The country saw a 45% increase in new infected computers over the last quarter. And such botnets were used to execute the recent DDoS cyber attacks against the White House, the New York Stock Exchange and South Korean government Web sites.</p>
<p>But although South Korea has its problems, it only accounts for less than four percent of the world&rsquo;s new bots. And its the U.S. which tops the list with 15% of the new zombie computers.</p>
<p>And its this bot expansion that is behind the increasing volume of spam, which is now 92% of all email. Spam volumes have now exceeded the highest volume on record by 20%, increasing at a steady rate of roughly 33% each month. This equates to spam volumes growing by over 117 billion emails every day.</p>
<p>What&rsquo;s most disturbing, is that as the number of bots continues to grow, malware writers have begun to offer malicious software as a service to those who control botnets. By exchanging, or selling resources, cybercriminals distribute new malware to wider audiences instantaneously. And the creation of and management of malware is becoming even easier, thanks to programmes like Zeus.</p>
<p>Programs like Zeus &#8211; an easy-to-use Trojan creation tool &#8211; continue to make the creation and management of malware even easier.</p>
<p>And cyber criminals are increasingly turning their attention to the popular social networking sites, including Twitter, Facebook and MySpace.</p>
<p><span style="color: rgb(153, 153, 153);">Guest Article by </span><strong><span style="color: rgb(153, 153, 153);">Neil Camp</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.antivirus-buyability.co.uk%2Fmcafee-says-spam-botnets-at-an-all-time-high%2F&amp;title=McAfee%20Says%20Spam%2C%20Botnets%20at%20an%20All%20Time%20High"><img src="http://www.antivirus-buyability.co.uk/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-buyability.co.uk/mcafee-says-spam-botnets-at-an-all-time-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

