Posts Tagged ‘antivirus’

Unable to connect to any antivirus site

Wednesday, August 27th, 2008

Just yesterday my computer got infected by nasty virus/spyware, the virus hijack my browser when going to any AV site or known support forum. The virus is preventing me to access those site and instead it redirected me to my localhost/127.0.0.1 . I am using windows XP Pro and was using AVG Free.

I tried to scan using AVG but it does not find anything either. I noticed that the virus definition was not updated, and keep failing to update. The virus is preventing me to access the updates, so what I did is used web proxy to visit the AVG site and luckily I got in and download the updates manually. I scan again and still no virus was found.

So then I went and tried all other free antivirus softwares out there: BitDefender, Avira Antivir, Spybot, and still no luck to find any virus/spyware.

I also tried to checked my HOSTS file and it looked normal. I keep on looking/searching on the net until I found the solution on a cnet forum.
(more...)

Remove Win32/Glenwiry.P virus

Wednesday, June 18th, 2008

Win32/glenwiry.p is a new virus which affects computer especially from USA. Win32/glenwiry.p is a dangerous virus that spreads through security holes and infects network computers. After Win32/glenwiry.p will infect your computer it may download additional malware (trojan horses, spyware, adware, hijackers and keyloggers). Moreover, Win32/glenwiry.p can change system settings and slow your PC.

From Yahoo Answers

CA a/v reported wextract.exe infected with WIn32/Glenwiry.P in 3 locations (all \windows folders, from \system32 through \servicepack1 and \servicepackfiles\i386). First 2 quarantined and the 3rd just listed as infected. XPSP2 popped up a hard request (no redirect to a folder name) for the SP2 disk, which I don't have either, being updated/upgraded via MS Update all along.

I searched the CA support and av center site and got ZERO results on either the filename or the glenwiry name, really surprising! Did a quick update check and my CA AV is fully up to date.

I'm not doing anything until I find out some more information. Going to check the MS site and run another full scan...

Update from CA Antivirus....

This from CA:
Thank you for using CA Security Advisor.

This is to notify you of the results of your submission, issue number 1386780. Please keep this issue number for future reference.

With regards to the file "wextract.exe" submitted by you on 13 Jun
16:58:23 (Australian Eastern Standard Time), we have updated our signature files to resolve the false positive problem.

The Windows PE (I386,EXE) file "wextract.exe" has been determined to be clean. Our researchers have analyzed the file and found nothing suspicious.

So if you are using CA anti-virus and detected the wextract.exe as Win32/Glenwiry.P virus you should update you signature files to resolved the false positive problem.

If you have been infected Win32/Glenwiry.P, here is a software that may help you remove it from your computer. Download NOD32 trial Anti virus form this website: http://www.softpedia.com/get/Antivirus/NOD.shtml .

Make sure to update the virus definition before using it :D

Free Online Virus Scanner

Thursday, May 29th, 2008

Looking for the best free virus removal tool to help cure your computer system of infections? Now look no more, here's the list of free online scanner you can use.

Trend Micro HouseCall
Offers a free online virus and spyware scan. This is the service you'll most likely see recommended in first place on many PC security related forums. It is indeed that popular! TrendMicro scan goes far beyond bare virus detection, supports Windows and Mac based computers, Mozilla and Internet Explorer browsers. Important: you can choose from either ActiveX engine or Java engine. These set of options make this online scan very versatile. Currently there's a new version available for testing .

Go to Trend Micro Housecall.

BitDefender Online Scan
BitDefender Online Scanner is an on-demand virus scanner which incorporates the award-winning BitDefender scanning engines. You can use it to scan your system's memory, all files and drives' boot sectors, and to automatically clean infected files. As to cons, it requires IE 4.0+.

http://www.bitdefender.com/scan8/ie.html

McAfee FreeScan
Offers a browser window with real-time statistics - number of files scanned, infections, name of detected virus. The scanning service is solid as everything produced by the brand, the drawback is that it supports IE browser only.

Go to http://us.mcafee.com/root/mfs/default.asp

F-Secure Online Scan
F-Secure Online Virus Scanner (version 3.3) is a free service. Use it to find out if your computer is infected, and disinfect your computer if needed. The product will automatically download the necessary components and virus definition databases as it is started. As to cons, it requires IE 6.0+ and works with ActiveX controls only. If ActiveX is disabled, than you can't use the service. Javscript need to be enable.

Go to http://support.f-secure.com/enu/home/ols.shtml

ESET NOD32 Online Antivirus Scanner
ESET's Online Antivirus Scanner uses its patented ThreatSense technology which is featured in company's desktop and server products. Initial download of antivirus signature database takes under a minute if you're on a broadband. ESET offers to remove the detected infections - for this you need to check the proper boxes (see screenshots below). Spyware is removed as well! NOD32 Scanner works only with ActiveX so it requires Internet Explorer.

Go to http://www.eset.com/onlinescan/

Kaspersky Online Scanner
Kaspersky claims its Online Scanner to have the highest detection rate. To some extent, it is true. It's antivirus database is updated hourly which may be considered to be the fastest response to emerging online threats. It uses Microsoft ActiveX technologies to scan your computer for malicious code and offers the same exceptional detection rates as other Kaspersky Lab products.

NOTE: The online virus scanner will not remove the malware from your machine if it finds it - installing Kaspersky software is required to do this. You can try our antivirus software (full product) for FREE by downloading and installing a free trial.

Go to http://www.kaspersky.com/kos/english/kavwebscan.html

Panda ActiveScan with TruPrevent
Panda security vendor offers anyone to try out its TruPrevent technology. With a database of 185,000 threats its online scan can not only detect, but also remove the infections. Additionally scans for spyware modules (like dialers, jokes, rootkits, etc). Panda claims to be able to desinfect the known spyware, and thanks to its heuristic engine, it detects even unknown types of malware.

Go to http://www.pandasecurity.com/homeusers/solutions/activescan/

Avast! Online Scanner
Online virus scanner gives the possibility to check your files quickly and free of charge. All you need to do is just browse for the target file on your PC, enter the captcha and press 'Scan' button and it will begi scanning.

Go to http://onlinescan.avast.com/

DrWeb Online Scan
DrWeb is another PC security product from Russia. Dr.Web scanner successfully detects Win32.Ntldrbot (aka Rustock.C) and cures system files infected by the rootkit. Currently no other anti-virus can detect this malicious program. It offers to scan single files - the webpage is as simple as possible, there's nothing on it except the "browse" button to specify the path to the target file.

Go to http://online.drweb.com/

VirusTotal
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines.

Virus Total receiced a PC World Magazine Award in 2007 as one of 100 best products of the year

VirusTotal is not substitute any antivirus software installed in a PC, as it only scans individual files on demand. It does not offer permanent protection for the user's system either.

http://www.virustotal.com/

What are the best firewalls to use for your PC?

Tuesday, May 20th, 2008

Hackers seem to be everywhere and they cause threats to every PC owners like you. To keep yourself protected, you would need an excellent firewall to prevent those malicious hackers from wrecking havoc to your PC. If you use paypal and other internet-based banking, you have to be careful as your password and username may be copied through spywares and you’d end up losing valuable money from malicious withdrawal.

Linux and Mac users are not affected by this but the majority, the Windows users, are constantly being threatened by these spywares, identity and data theft.

There are paid and free spyware removal software available to choose from but it doesn’t really matter if you’d get a free software as long as it does its job well. Why pay more for something you can get for free anyway?

The 5 best firewalls you may want to try are the Comodo Firewall Pro 3.0.21.329, Online Armor Personal Firewall 2.1.0.119, ProSecurity 1.43, Outpost Firewall Pro 2008 6.0.2302.264.0490 and Kaspersky Internet Security 7.0.1.325. The Comodo Firewall Pro and the Online Armor Personal Firewall are free software but they are actually the best type of firewall available. Finding the best firewall for you is a debatable topic as each PC are different and people’s preference also vary. You may try both free firewall software to check for yourself which one suits you best. Only Comodo supports Windows Vista as Online Armor does not. Online Armor has an easy interface so you don’t need to be an expert to know what to do and how to go around it. The Comodo has many settings and people with the right know-how would appreciate this software more. Either way you choose, or perhaps you may choose the 3 other firewalls software stated above, you are still protected from those malicious hacking.

Just make sure that you only use 1 firewall protection software at a time. If you’re not happy with your chosen software, uninstall it and install a new one and use that.