May 15

INF/Conficker Worm Description:

INF/Conficker is a computer infection whose basic objective is to propagate the notorious Conficker worm via Autorun.inf files. In other words, INF/Conficker is responsible for transmitting Conficker infection from one computer to another and does this by injecting itself into removable drives or adjacent drives and networks. INF/Conficker is also known to be capable of disabling security software installed on the compromised computer. INF/Conficker may block access to websites providing downloadable PC security solutions. In addition, INF/Conficker uses rootkit techniques to hide its presence on the infected machine, so in complex with disabled antivirus software, this feature of INF/Conficker makes this worm pretty much undetectable. Therefore, it’s the most complicated thing to expose INF/Conficker on one’s computer or on removable drives.

May 13

I-Worm.Trojan.b Worm Description:

If you are getting alerts that say you have I-Worm.Trojan.b, it doesn’t necessarily mean your computer is actually infected with that virus. The reason for triggering those alerts is the malicious activity of trojans and a browser hijacker inside your system. The most common way for the malware to manifest itself is through browser redirection to a certain strange website when you are trying to look something up on the internet. Once you get diverted, you will view a pathetic imitation of Windows Security Center alert that says: “Virus (I-Worm.Trojan.b) was found on your computer! Click OK to install System Security Antivirus”. Consequently, it looks like the whole hijacker and pop-up story aims to make you install and purchase the promoted program, i.e. System Security 2009 (aka System Security Antivirus or System Security). FYI: System Security 2009 is a fake spyware remover that uses tactics of scaring its victims into installing its licensed software.

Mar 26

Conficker.C Description:

Conficker.C (also known as Conficker C or W32/Conficker.C) is a computer infection representing the infamous family of Conficker (aka Downadup) worms. According to some experts’ estimates, the active launch of Conficker.C invasive campaign is planned around April.1 but the preliminary attacks are being observed during the last few weeks. Conficker.C is not expressly aggressive and usually remains hidden until you detect its presence in your system using reliable PC security utilities. However, Conficker.C is extremely dangerous in terms of its latent impact on the user’s privacy and computer security. Conficker.C is known to disable the vital protective functions of the compromised machine by disabling the antivirus software updates and preventing the victims from visiting security web resources offering anti-malware solutions. Conficker.C is capable of tracking the victims’ computer activities and even records keystrokes subsequently sending these harvested confidential data to scammers who sell them to interested third parties having malicious purposes.

Mar 24

Worm.AutoIt Description:

Worm.AutoIt is a primitive yet very dangerous malware application. Worm.AutoIt infiltrates target systems using misleading tactics of attaching itself to the content you download online. Another known method of Worm.AutoIt intrusion is via firewall backdoors and security software exploits spotted by this worm. Once inside the target computer, Worm.AutoIt will embed itself into multiple system processes to eventually affect general PC performance, open insecure network connections and compromise the victim’s privacy. When running in the host system, Worm.AutoIt will try to replicate itself throughout the entire network and all of its nodes, thus endangering the overall network functionality. Being capable of self-mutating, Worm.AutoIt is hard to detect and remove using some security utilities, not to mention the manual removal methods.

Mar 18

U.Z.A. Operating System Wallpaper and Affiliated Malware Description:

If your default desktop wallpaper suddenly turns black and displays an inscription reading “U.Z.A. Operating System”, it means your computer has been attacked by a dangerous PC worm known as U.Z.A. O/S Eliminator. U.Z.A. O/S Eliminator worm poses a risk to the compromised computer in a number of ways. First of all, this worm propagates mostly through removable drives to which it gets from the infected computers this drive was plugged into. Technically speaking, U.Z.A. O/S Eliminator drops and executable file into a latently created folder called My Personal Data on the infected drive. Along with the described method of propagation, U.Z.A. O/S Eliminator worm also replicates itself to computers referring to the same network.

Feb 17

W32.Downadup.B Description:

W32.Downadup.B is a worm that tends to replicate itself through networks infecting all the subsidiary nodes and causing severe system trouble for each of the network units. W32.Downadup.B is known to contaminate target systems by exploiting Windows Server Service vulnerability. W32.Downadup.B has an enormous propagation scope – starting from December 2008 up till now, it has infected up to 10 million computers all over the planet. When operating, W32.Downadup.B disables the access to some domains and concurrently triggers the “Network request timed out” alert or some other similar one. W32.Downadup.B also creates a file in all the drives called ‘autorun.inf’, and each time this drive is queried, this file is automatically executed. Once launched, autorun.inf will attempt to spot other machines connected to the infected one, in order to access them illicitly as well.

Jan 24

Downadup (Conficker) Worm Description:

Downadup (AKA Conficker) is a severe cyber infection classified as a computer worm. The basic traits of Downadup is its propagating itself throughout networks and disabling the use of PC security utilities and software updates. Downadup is an extremely widespread contaminant, around 9 million machines are known to be infected worldwide. Being a worm by its technical essence, Downadup will copy itself to your System32 directory as a .dll file with random name, subsequently configuring the operating system to load this .dll while running. Having Downadup infection on board, you will be unable to follow some URLs of security software vendors, thus preventing you from downloading malware removal tools and getting antivirus updates. Downadup will typically disable the System Restore option in order to keep you from getting your system to operate the way it did before getting infected.

Dec 24

Fujacks.e Worm Description:

Fujacks.e is a worm that propagates through networks that have vulnerable authentication parameters. Fujacks.e contaminates all executable files on the infected machine so that the system gets disrupted and its performance deteriorated. By its essence, Fujacks.e worm is a malicious application that encroaches on security utilities to consequently weaken the host system and make it exposed to outer hazards. Fujacks.e is known to disable most antivirus software and can go even as far as to affect your firewall. One of the most hazardous traits of Fujacks.e worm is the fact that it may remain resident in your machine and network without you knowing it – it’s only a system scan implemented with the trusted removal tool that can unmask the intruder. If Fujacks.e stays inside for

Dec 15

Netsky.Q Description:

Netsky.Q (AKA Win32.Netsky.Q or I-Worm.NetSky.q) is a digital ‘scarecrow’ used by some rogue anti-spywares to manipulate computer users into thinking their machines are infected with malware. Netsky.Q is labelled as a worm that may replicate itself and thus spread throughout a computer system and network harming it badly. In fact, though, Netsky.Q turns out to be an imaginary parasite reported by fake system scans and popup alerts, or a real but harmless worm brought in by the rogue anti-spywares that are implementing their malicious plan inside a new host system. You can view the Netsky.Q denomination in some security center alerts and fake system scans that report it as a malware of high severity. If you encounter Netsky.Q in the structure of