Who Writes Malicious Programs and Why?

posted under by nandu reddy
Who Writes Malicious Programs and Why?
Virus writers: four general types
Virus writers belong to one of four broad groups: cyber-vandals, who can be divided into two categories, and more serious programmers, who can again be split into two groups.
Cyber vandalism - stage 1
In the past, most malware was written by young programmers: kids who just had learned to program who wanted to test their skills. Fortunately most of these programs did not spread widely - the majority of such malware died when disks were reformatted or upgraded. Viruses like these were not written with a concrete aim or a definite target, but simply for the writers to assert themselves.
Cyber vandalism - stage 2
The second largest group of contributors to malware coding were young people, usually students. They were still learning programming, but had already made a conscious decision to devote their skills to virus writing. These were people who had chosen to disrupt the computing community by committing acts of cyber hooliganism and cyber vandalism. Viruses authored by members of this group were usually extremely primitive and the code contained a large number of errors.
However, the development of the Internet provided space and new opportunities for these would-be virus writers.Numerous sites, chat rooms and other resources sprang up where anyone could learn about virus writing: by talking to experienced authors and downloading everything from tools for constructing and concealing malware to malicious program source code.
Professional virus writers
And then these 'script kiddies' grew up. Unfortunately, some of them did not grow out of virus writing. Instead, they looked for commercial applications for their dubious talents. This group remains the most secretive and dangerous section of the computer underground: they have created a network of professional and talented programmers who are very serious about writing and spreading viruses.
Professional virus writers often write innovative code designed to penetrate computers and networks; they research software and hardware vulnerabilities and use social engineering in original ways to ensure that their malicious creations will not only survive, but also spread widely.
Virus researchers: the 'proof-of-concept' malware authors
The fourth and smallest group of virus writers is rather unusual. These virus writers call themselves researchers, and they are often talented programmers who devote their skills to developing new methods for penetrating and infecting systems, fooling antivirus programs and so forth. They are usually among the first to penetrate new operating systems and hardware. Nevertheless, these virus writers are not writing viruses for money, but for research purposes. They usually do not spread the source code of their 'proof of concept viruses', but do actively discuss their innovations on Internet resources devoted to virus writing.
All of this may sound innocent or even beneficial. However, a virus remains a virus and research into new threats should be conducted by people devoted to curing the disease, not by amateurs who take no responsibility for the results of their research. Many proof of concept viruses can turn into serious threats once the professional virus writers gain access to them, since virus writing is a source of income for this group.
Why write viruses?
Fraud
The computer underground has realised that paid for Internet services, such as Internet access, email and web hosting, provides new opportunities for illegal activity with the additional satisfaction of getting something for nothing. Virus writers have authored a range of Trojans which steal login information and passwords to gain free access to other users' Internet resources.
The first password stealing Trojans appeared in 1997: the aim was to gain access to AOL. By 1998 similar Trojans appeared for all other major Internet service providers. Trojans stealing log in data for dial-up ISPs, AOL and other Internet services are usually written by people with limited means to support their Internet habit, or by people who do not accept that Internet resources are a commercial service just like any other, and must therefore be paid for.
For a long time, this group of Trojans constituted a significant portion of the daily 'catch' for antivirus companies worldwide. Today, the numbers are decreasing in proportion to the decreasing cost of Internet access.
Computer games and software license keys are another target for cyber fraud. Once again, Trojans providing free access to these resources are written by and for people with limited financial resources. Some hacking and cracking utilities are also written by so-called 'freedom fighters', who proclaim that all infomration should be shared freely throughout the computing community. However, fraud remains a crime, no matter how noble the aim is made out to be.
Organised cyber crime
The most dangerous virus writers are individuals and groups who have turned professional. These people either extract money directly from end users (either by theft or by fraud) or use zombie machines to earn money in other ways, such as creating and selling a spamming platform, or organizing DoS attacks, with the aim here being blackmail.
Most of today's serious outbreaks are caused by professional virus writers who organize the blanket installations of Trojans to victim machines. This may be done by using worms, links to infected sites or other Trojans.
Bot networks
Currently, virus writers either work for particular spammers or sell their wares to the highest bidder. Today, one standard procedure is for virus writers to create bot networks, i.e. networks of zombie computer infected with identical malicious code. In the case of networks used as spamming platforms, a Trojan proxy server will penetrate the victim machines. These networks number from a thousand to tens of thousands of infected machines. The virus writers then sell these networks to the highest bidder in the computer underground.
Such networks are generally used as spamming platforms. Hacker utilities can be used to ensure that these networks run efficiently; malicious software is installed without the knowledge or consent of the user, adware programs can be camoflaged to prevent detection and deletion, and antivirus software may be attacked.
Financial gain
Apart from servicing spam and adware, professional virus writers also create Tojan spies which they use to steal money from e-wallets, Pay Pal accounts and/or directly from Internet bank accounts. These Trojans harvest banking and payment information from local machines or even corporate servers and then forward it to the master.
Cyber extortion
The third major form of contemporary cyber crime is extortion or Internet rackets. Usually, virus writers create a network of zombie machines capable of conducting an organized DoS attack. Then they blackmail companies by threatening to conduct a DoS attack against the corporate website. Popular targets include estores, banking and gambling sites, i.e. companies whose revenues are generated directly by their on-line presence.
Other malware
Virus writers and hackers also ensure that adware, dialers, utilities that redirect browsers to pay-to-view sites and other types of unwanted software function efficiently. Such programs can generate profits for the computer underground, so it's in the interests of virus writers and hackers to make sure that these programs are not detected and are regularly updated.
In spite of the media attention given to young virus writers who manage to cause a global epidemic, approximately 90% of malicious code is written by the professionals. Although all of four groups of virus writers challenge computer security, the group which poses a serious, and growing threat is the community of professional virus writers who sell their services.


SOURCE:- http://www.viruslist.com/en/viruses/encyclopedia?chapter=153280553

what is an antivirus??

posted under by nandu reddy
Antivirus software are computer programs that attempt to identify, neutralize or eliminate malicious software. The term "antivirus" is used because the earliest examples were designed exclusively to combat computer viruses; however most modern antivirus software is now designed to combat a wide range of threats, including worms, phishing attacks, rootkits, trojan horses and other malware. Antivirus software typically uses two different approaches to accomplish this:
examining (scanning) files to look for known viruses matching definitions in a virus dictionary, and
identifying suspicious behavior from any computer program which might indicate infection.
The second approach is called heuristic analysis. Such analysis may include data captures, port monitoring and other methods.
Most commercial antivirus software uses both of these approaches, with an emphasis on the virus dictionary approach. Some people consider network firewalls to be a type of antivirus software, however this is not correct.


source :- http://en.wikipedia.org/wiki/Antivirus_software

India tackles cyber crime BBC NEWS

posted under by nandu reddy
Sunday, 23 July, 2000, 16:45 GMT 17:45 UK

India's top police officials and information technology experts are meeting in Delhi to discuss ways of countering cyber crime.
The one-day "Cyber law and police" seminar has been organised by India's leading crime-fighting agency, the Central Bureau of Investigation (CBI).
Information and Technology Minister, Pramod Mahajan told the gathering that computer crime would soon be the biggest challenge for the police and lawmakers.
Mr Mahajan said the authorities need to wake up now, or face becoming mere spectators as criminal IT use increases.
Computer crimes mainly involve unauthorised access, data alteration and destruction and theft of intellectual property.
"Crimes like fraud, pornography, illegal sales can all be done by computers," Mr Mahajan said.
He also warned that cyber crimes could take on a far more serious dimension in the near future.
New breed
Experts believe a new breed of criminals could damage telecommunications or rail links, disrupt power supplies and harm other important parts of India's infrastructure.
The CBI has invited senior police officials from across India, and IT and law experts to work out effective ways of fighting cyber offences.
The CBI chief, R K Raghavan, said they had sought help from several foreign agencies, including the US Federal Bureau of Investigation, in tackling the recent boom in cyber crimes.
Last year, FBI experts visited India and trained policemen in dealing with such offences. The CBI has now set up its own special cyber crime unit.
The Indian parliament recently passed a law dealing with computer crimes, but experts say police and security agencies need to be more pro-active in dealing with the growing threat.

SOURCE:- http://cybercrime.planetindia.net/indiatackle_cybercrime.htm

download the best antivirus and internet security suite

posted under by nandu reddy
zone labs is the best ! download at :-


http://download.zonealarm.com/bin/free/1043_zl/zasuiteSetup_en.exe

remove pen drive virus without using antivirus !!

posted under by nandu reddy
here is a simple method to remove funny ust scandal virs without formatting windows
Download and install TaskKiller (326 KB freeware). We’re doing this because we need to remove a few tasks running, and Windows Task Manager (Alt + Ctrl + Del) gets killed by the virus
Run Task Killer, and a red skull icon will appear on the system tray
Left click it, and click Processes
Select to kill these processes -
killer.exe
lsass.exe
smss.exe
Now open up Command Prompt (Start>Run>command). Type each command and press Enter to run it -
cd\
attrib -h -s smss.exe
attrib -h -s autorun.inf [NOTE : Type each command exactly as its given here]
Open My Computer and go to C:\ or whichever partition in which you’ve installed Windows.
Delete the following files -
smss.exe
autorun.inf
Funny UST Scandal.avi.exe
Go to Command Prompt again. Run this command -
attrib -h -s smss.exe
Go to C:\Windows or wherever else you’ve installed Windows, and delete the file smss.exe.
Now, go to C:\Documents and Settings\All users\Startmenu\Programs\Startup and delete the file lsass.exe.
Open Registry Editor (Start>Run>regedit)
Delete the key HKEY_LOCAL_MACHINE\Software\ Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe
Delete the key HKEY_CURRENT_USER\Software\ Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)
You’re done!

google is the best

posted under by nandu reddy
google is the best search engine as we all know. we cant imagine even a day without google...

back up registry first !!!

posted under by nandu reddy
Backing up the Windows registry
Before editing the registry via the Registry Editor, you should back up the registry.
You can create a backup using Windows XP's Backup Utility by selecting the System State option. Many third-party backup applications will also back up the Windows registry along with your data files. Furthermore, you can also use the Console Registry Tool for Windows (enter reg /? At a command prompt for more information) or create a Restore Point.
To back up an individual key before making changes to the values it contains, select the key in the Registry Editor, pull down the File menu, choose the Export command, give the file a name, select a save location, and click save. The end result is a REG file that you can use to easily undo your changes—just locate and double-click the file.

How the Windows registry is organized ???

posted under by nandu reddy
How the Windows registry is organized ???
The Registry Editor presents the registry in a folder tree structure that should be familiar to most Windows users. Although the registry doesn't contain actual folders, this display format allows us to easily navigate and manipulate registry.
Each folder is called a key and each key can contain other keys and values. The keys provide the organization structure and the values contain the actual configuration data. Keys appear in the Registry Editor's left pane and values appear in the right pane.
The registry contains five main, or root, keys. Each key contains specific types of information.
• HKEY_CLASSES_ROOT contains information about file types.
• HKEY_CURRENT_USER contains copies of data stored in HKEY_USERS about the user that is currently logged on.
• HKEY_LOCAL_MACHINE contains information about all the hardware and software installed on the computer.
• HKEY_USERS contains information about all the system's user accounts.
• HKEY_CURRENT_CONFIG contains copies of the information from all the other root keys that pertain to the currently running session.

registry !!!

posted under by nandu reddy

What the Windows registry is ???
The registry is essentially a database of Windows' configuration settings. It contains information on each user with an account on the local system, on all internal and external hardware, on installed programs, and on property settings. Windows continually references the registry during operation. When you change Windows configuration setting, the registry stores those changes. For example, most changes you make through the Control Panel or local Group Policy Editor (Gpedit.msc) are stored in the registry.
You manually view and modify the registry via the Registry Editor. To launch the Registry Editor click Start Run, type Regedit in the Open text box, and click OK. Windows NT and Windows 2000 provide two different registry editing tools Regedit and Regedt32. Windows XP and Server 2003 provide a version of Regedit which has the functionality of both tools.