Recently in Antivirus Software Category

Storm Worm

| No Comments | No TrackBacks

also known as Trojan-Downloader.Win32.Small.dam, Trojan.Downloader-647, Trojan.DL.Tibs.Gen!Pac13, Email-Worm.Win32.Zhelatin.a (Kaspersky), Downloader-BAI (McAfee), Troj/Dorf-Fam (Sophos), Trojan.Peacomm (Symantec), TROJ_SMALL.EDW (Trend Micro), Win32/Nuwar.N@MM (Microsoft).

Type: Email worm, Trojan, Downloader
Discovered: January 19, 2007
Method of Propagation: The Storm worm spreads via email, using a variety of subject lines and message text that may masquerade as news articles or other current events. For example, subject lines in the Storm email may be named one of the following:

A killer at 11, he's free at 21 and kill again!
U.S. Secretary of State Condoleezza Rice has kicked German Chancellor
Angela Merkel
British Muslims Genocide
Naked teens attack home director.
230 dead as storm batters Europe.
Radical Muslim drinking enemies's blood.
Chinese missile shot down Russian satellite
Saddam Hussein alive!
Venezuelan leader: "Let's the War beginning".
Fidel Castro dead.

The attachment carried by the Storm worm may be named one of the following:

FullVideo.exe
Full Story.exe
Video.exe
Read More.exe
FullClip.exe
GreetingPostcard.exe
MoreHere.exe
FlashPostcard.exe
GreetingCard.exe
ClickHere.exe
ReadMore.exe
FlashPostcard.exe
FullNews.exe

Symptoms of Infection:

Note: There are dozens of variants of the Storm worm. The following technical details may not apply to each of them. To determine whether a Storm worm infection is present, scan your systems with up-to-date antivirus software.

System Impact:
The Storm email worm may drop the the file 'wincom32.exe' into the Windows system directory (typically, C:\Windows\System under Windows 95/98/ME, C:\Winnt\System32 under Windows NT/2000, and C:\Windows\System32 under Windows XP.

The Storm worm loads the dropped wincom32.exe as a device driver by modifying the registry as follows:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wincom32

This device driver injects a module into the services.exe process, sets up a peer-to-peer filesharing network on infected systems, and opens and listens for commands on UDP port 4000, 7871, and 11271.

The Storm worm then downloads files from various remote IP addresses and executes those files on the local system.

Removal Notes:
The Storm worm is rootkit enabled and may hide files and processes associated with it and other malware it downloads. To remove the worm and other installed malware, scan the system using up-to-date antivirus software.

F-Secure Anti-Virus 2009

| No Comments | No TrackBacks

An average of ten new viruses and spyware are found each day and the rate continues to grow. There is also a new breed of threats on the Internet, such as carefully planned targeted attacks that can pass through conventional security solutions unnoticed, possibly taking over your computer for illegal purposes.

F-Secure Anti-Virus 2009 comes with F-Secure DeepGuard™ 2.0, introducing network-based instant recognition of both safe and malicious software, which is able to protect you in 60 seconds from the first confirmation of a new threat. No other antivirus vendor has such "in-the-cloud" real-time protection network deployed globally.
With F-Secure® Anti-Virus 2009, you can open e-mail attachments and use your computer without any fear of virus infections, spyware intrusion or malicious programs that can take over your computer. In addition, F-Secure DeepGuard™ 2.0 provides instant protection against new threats with real-time protection network that shortcuts the hours it typically takes to send out database updates.

  • Quicker where it matters
    NEW! Quick and easy installation, faster boot-up times and faster scanning and cleaning of files.
  • Protects your computer against viruses, worms and unknown attacks
    With daily automatically updated virus protection from world-renowned F-Secure Data Security Laboratory and F-Secure DeepGuard 2.0 technology that instantly protects you against zero-day attacks and other future threats, you can safely use your computer, now and tomorrow.
  • Detects and removes spyware from your computer
    F-Secure Anti-Virus detects and removes secretly installed software from your computer better than ever before, ensuring that your system is running smoothly and clean of spyware.
  • Fastest Protection
    F-Secure is one of the leading antivirus vendors when it comes to reaction times and update delivery times during virus outbreaks.
  •  

    F-Secure Anti-Virus 2009

    Advanced Virus Protection for Your Online Life
    With F-Secure® Anti-Virus™ 2009, you can use your computer without any
    fear of virus infections, spyware intrusion or malicious programs that can take
    over your computer. F-Secure Anti-Virus has been designed to automate all key
    tasks required to keep your computer and data safe from viruses. It's so easy
    all you have to do is install and forget it.
    DeepGuard 2.0 - Protect Yourself Against the Unknown
    Fast-spreading hidden attacks designed by money-driven online criminals are a
    major problem on the Internet. F-Secure Anti-Virus 2009 comes with updated
    DeepGuard 2.0 technology that automatically protects you against anything
    that might be a sign of danger in your computer. The new version also
    introduces instant recognition of both safe and potentially bad software which
    makes the technology virtually unnoticeable and more accurate than ever.
    Protect your Privacy with Antispyware
    Spyware can secretly track your surfing habits and profile your shopping
    preferences. It can even hijack your web browser or abuse your Internet
    connection by sending data to a third party. F-Secure Anti-Virus protects your
    privacy by detecting and removing such software from your computer.
    The Fastest Protection with Automatic Updates
    Antivirus software is only as good as the capability of antivirus software
    manufacturer to provide a timely cure for new virus outbreaks. F-Secure
    Anti-Virus Research Team updates virus definition databases several times a
    day to ensure that customers have 24-hour protection against new,
    fast-spreading viruses. This is why F-Secure products constantly rank at the top
    when compared with competing products.

    Protects your computer against
    viruses, worms and other attacks
    With daily automatically updated
    virus protection from the
    world-renowned F-Secure Data
    Security Laboratory and F-Secure
    DeepGuard technology that
    protects you against zero-day
    attacks and other future threats, you
    can safely use your computer, now
    and tomorrow.
    Detects and removes spyware from
    your computer
    F-Secure Anti-Virus removes secretly
    installed software from your
    computer, ensuring that your system
    is running smoothly and clean of
    spyware.
    Fastest Protection
    F-Secure is one of the leading
    antivirus vendors when it comes to
    reaction times and update delivery
    times during virus outbreaks.

    Protection Against Unknown Threats and Rootkits
    Modern malware can break into your computer even if you have
    up-to-date security components installed. F-Secure DeepGuard™ detects
    and prevents any suspicious activity that might indicate a danger in
    your computer. Rootkits are also detected and removed.
    Scans E-mail and Web Traffic
    POP3, IMAP and SMTP traffic are scanned for viruses so that you do
    not have to worry about infected e-mails. Web Traffic Scanning
    protects you against web sites that can infect your computer even if you
    do not download anything from them.
    Easy to Install and Use
    F-Secure Anti-Virus is extremely easy to install and use. As the software
    is highly automated, you do not have to understand the complexities of
    data security.
    The Fastest Protection Against Virus Outbreaks
    Immediate reaction times and fast cures during new and emerging
    threats ensured by F-Secure Research Team working 24 hours a day.
    Security News
    Get information about new viruses and their behavior immediately, as
    well as the instructions on how to avoid the infection and a confirmation
    whether your computer is already protected against the latest threat.
    Multiple Scanning Engines
    F-Secure Anti-Virus uses multiple scanning engines, bringing you the very
    best in detection and disinfection. Each scanning engine specializes in
    detecting a different type of malware. It is like having several antivirus
    products running in your computer at the same time!
    Software in your Language
    F-Secure Anti-Virus has a clear user interface, including an easily
    accessible electronic manual. Both the software and electronic manual
    are available in your language.

    F-Secure Anti-Virus is a great product that offers many of the standard functions associated with antivirus software, but also goes above and beyond the bar set by others with efforts by F-Secure to educate the people that use F-Secure Anti-Virus on general security practices as well as specific threats.

    F-Secure Anti-Virus is one of the most effective antivirus programs on the market. Its heuristic scanner is considered by many to be one of the fastest and most complete on the market.

    We did have some problems with its on-access scanner though. The test system we used is a pretty fast system. Intel Pentium D 2.8GHz with 1GB of RAM. The on-access scanner would sometimes bring this system to a halt when opening programs or moving files.

    F-Secure Anti-Virus comes with the standard protection you would expect from any modern antivirus suite. Both on-access and on-demand scanners are included as well as a spyware scanner that runs with both. An email scanner is also included for those of us using local email clients like Outlook or Thunderbird.

    One feature we especially liked about F-Secure Anti-Virus was the integrated news on the home menu. The Security News section is full of useful information about which new security threats are out and whether you are protected from each threat.

    AVG Anti-Virus 8 & Anti-Spyware

    | No Comments | No TrackBacks

    Antivirus and antispyware protection for Windows from the world's most trusted security company. Use the Internet with confidence in your home or small office.

  • Easy to download, install and use
  • Protection against viruses, spyware, adware, worms and trojans
  • Real-time security while you surf and chat online
  • Top-quality protection that does not slow your system down
  • Free support and service around the clock and across the globe
  • Compatible with Windows Vista and Windows XP
  •  

    Integrated protection

    • Anti-Virus: protection against viruses, worms and trojans
    • Anti-Spyware: protection against spyware, adware and identity-theft
    • Anti-Rootkit: protection against hidden threats (rootkits)
    • Web Shield & LinkScanner: protection against malicious websites

    Easy-to-use, automated protection

    Real-time protection, automatic updates, low-impact background scanning for on-line threats, and instant quarantining or removal of infected files ensures maximum protection. Every interaction between your computer and the Internet is monitored, so nothing can get onto your system without your knowledge. AVG scans in real time:

    • All files including documents, pictures and applications
    • E-mails (all major email clients supported)
    • Instant messaging and P2P communications
    • File downloads and online transactions such as shopping and banking
    • Search results and any other links you click on

    Internet use with peace of mind

    The new web shield checks every web page at the moment you click on the link to ensure you're not hit by a stealthy drive-by download or any other exploits. All links on search results pages in Google, Yahoo, and MSN are analyzed and their current threat level is reported in real time before you click on the link and visit the site.

    The best Windows protection - trusted by millions of users

    AVG's award-winning antivirus technology protects millions of users and is certified by major antivirus testing organizations (VB100%, ICSA, West Coast Labs Checkmark).

    No hidden costs

    When you purchase an AVG product, everything you need is included in the price for the full license duration - technical support, virus updates, and new program versions. All users of paid AVG products also qualify for generous discounts on subscription renewals and product upgrades.

    Flexible licensing

    • AVG Anti-Virus can be purchased online in license packs for 1-10 computers.
    • One or two year subscriptions available.

     

    BitDefender Antivirus 2009

    | No Comments | No TrackBacks

    Superior Proactive Protection from Viruses, Spyware, and other e-Threats...that won't slow you down!

     

    Confidently download, share and open files from friends, family, co-workers - and even total strangers!

    • Improved: Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time
    • Proactively protects against new virus outbreaks using advanced heuristics



    Protect your identity: shop, bank, listen, watch privately and securely

    • Blocks attempted identity theft (phishing)
    • Improved: Prevents personal information from leaking via e-mail, web or instant messaging



    Guard your conversations with top-of-the line encryption

    • NEWInstant Messaging Encryption



    Play safe, play seamlessly!

    • Improved: Reduces the system load and avoids requesting user interaction during games



    Get fine-tuned performance from your computer !

    • Uses few system resources
    • NEWLaptop mode prolongs battery life
    • Improved: Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time
    • Proactively protects against new virus outbreaks using advanced heuristics

    Features and Benefits

     

    Family network protection
    Manage the security of your home network from a single location. BitDefender software from other computers in the network can be remotely configured, while tasks such as scans, backups tune-ups and updates can be run on-demand or scheduled to run during off-hours.

    Hassle - Free Hourly Updates
    Hourly updates ensure that you are protected against the latest threats without pushing a button. Lost program files are not a problem either. In the rare event of file damage due to PC problems, BitDefender automatically repairs and updates itself.

    For those seeking the best antivirus software for the money AND an "install and forget" proposition, BitDefender is the right choice. Not only does it protect your computer and files, but BitDefender is easy to use, light on your computer and, maybe most importantly, light on your pocketbook.

    No matter how technically capable any piece of software may be, the productivity enhancement it offers is only effective if people use it. This is especially true in antivirus software. The primary reasons people fail to protect their computers from a variety of malware are the cost and the 'burden' of installing and maintaining antivirus software. The best protection in the world is worthless if people find it cumbersome and distracting to use.

    The same holds true for price. This is the beauty of BitDefender: It provides comprehensive protection, takes up little space on your computer, costs less and requires little maintenance.

    You might think antivirus software that's this easy to use and this inexpensive might not be as effective as products with bigger brand names and bigger price tags, but you would be wrong. AV-Test.org is among the most prestigious, independent research laboratories in the world for testing antivirus software. In recent tests, BitDefender received their highest rating for having removed 98% of all viruses and spyware in their rigorous tests. In addition, BitDefender has received the highest ratings for effectiveness by Virus Bulletin (VB100%) and AV Comparatives.org, and was certified by ICSA, Checkvir.com and West Coast Labs for its ability to detect viruses and virus replication while minimizing false positives (detecting viruses that are not there).

    One of the key features BitDefender has developed is a virtual machine that runs invisibly in the background on your computer where it tests suspicious code, which is code that looks like a virus but doesn't currently match any of the known virus signatures. In this way, BitDefender can protect your computer from viruses no one has reported yet. In the same tests by AV-Test.org, BitDefender scored higher than Kaspersky, Norton, Computer Associates (CA) and McAfee on its proactive detection of viruses and other malware with this heuristic approach. BitDefender scans somewhat slower than some of its competitors, due (we believe) to this virtual machine running. Naturally, there's going to be a price for this type of protection, but other products like ESET's NOD32 have done a better job at minimizing it.

    Although BitDefender is great at removing viruses and spyware, it excels at protecting your system from incoming viruses. The new BitDefender can actually strip viruses from your incoming HTML stream before the virus makes it to your browser. We think every new computer should be outfitted with this kind of protection.

    In the spirit of "install and forget" software, BitDefender doesn't go in for the blinking red and green lights to notify you of its activity. Instead, a tiny red and black icon appears in the lower-right corner of your desktop, just above the system tray. This unobtrusive icon is the scan activity monitor. A green line indicates when files are being scanned for viruses and spyware. You can remove the monitor by going into the configuration settings.

    The antispyware section of BitDefender includes Privacy Protection. This feature is disabled by default, but turning this feature ON is recommended. In the Advanced Setting link, you can enter your credit card numbers or other private information, and if any Windows application attempts to send these over the Internet, it stops and requires your active permission. Otherwise, BitDefender will refuse any program that attempts to send your personal information over the Internet.

    BitDefender is the only antivirus software reviewed with a gamer mode. With gamer mode enabled, online gamers are protected without sacrificing much performance. Since online gamers are notorious for disabling firewalls and other protection to optimize performance, this could be a lifesaver for the family computer used for online gaming by members of your household.

    Kaspersky Anti-Virus 2009

    | No Comments | No TrackBacks

    Kaspersky Anti-Virus 2009 provides the basic tools needed to protect your PC. Installation of a separate firewall and anti-spam filter is recommended.

    Virus Essential Protection

    • Protects from viruses, Trojans and worms
    • Blocks spyware and adware
    • Scans files in real time (on access) and on demand
    • Scans email messages (regardless of email client)
    • Scans Internet traffic (regardless of browser)
    • Protects instant messengers (ICQ, MSN)
    • Provides proactive protection from unknown threats
    • Scans Java and Visual Basic scripts

    Preventive Protection from Viruses

    • Scans operating system and installed applications for vulnerabilities
    • Analyzes and closes Internet Explorer vulnerabilities
    • Disables links to malware sites
    • Detects viruses based on the packers used to compress code
    • Global threat monitoring (Kaspersky Security Network)

    Advanced Protection & Recovery

    • The program can be installed on infected computers
    • Self-protection from being disabled or stopped
    • Restores correct system settings after removing malicious software
    • Tools for creating a rescue disk

    Data & Identity Theft Protection

    • Disables links to fake (phishing) websites
    • Blocks all types of keyloggers

    Usability

    • Automatic configuration during installation
    • Wizards for common tasks
    • Visual reports with charts and diagrams
    • Alerts provide all the information necessary for informed user decisions
    • Automatic or interactive mode
    • Round-the-clock technical support
    • Automatic database updates

    Kaspersky Labs has been one of the best antivirus software developers in the world for over a decade and now Kaspersky Anti-Virus 2009 only strengthens that reputation. Founded by Natalia and Eugene Kaspersky in 1997, this Russian company is often the first to find and identify new viruses. Long used in Russia and Europe, Kaspersky is now making inroads in the North American market. Kaspersky Anti-Virus 2009 is one of the most effective antivirus packages in the world today and boasts a great interface with easy to use and intuitive controls.

    Kaspersky Labs has always been known for its ability to effectively detect and remove viruses as well as or better than any software program on the market. Like BitDefender, Kaspersky was able to remove over 98% of all viruses it encountered in the most recent  objective tests of AV-test.org. Kaspersky is also certified by all of the major virus/malware testing laboratories. Tests confirm Kaspersky's effectiveness. It found every virus on the test computer.

    Although Kaspersky is excellent at detecting viruses and malware, it could use some work in the detection of spyware. Independent tests by AV-test.org showed that Kaspersky allowed 8% of adware/spyware to go undetected. Furthermore, Kaspersky's proactive/heuristic engine failed to meet the high standards set by BitDefender, NOD32, F-Secure, Panda and some others.

    Like other software with proactive/heuristic engines to detect malware before their signatures are available, Kaspersky's scan is relatively slow. The time and resources demanded by these proactive/heuristic engines slows these scans, and relatively slow scans may be the price we pay for this level of protection. Of the antivirus software packages reviewed, only NOD32 scored high on both proactive detection and scan speed. 

    Kaspersky's feature set is one of its strongest assets. While BitDefender's interface is primarily an enable/disable feature set, Kaspersky is the software-tweakers dream with controls for nearly all of its features. Like most of the antivirus packages in our review, Kaspersky protects your computer from spyware as well as viruses. Scanning for both viruses and spyware simultaneously is far more efficient in terms of time and resources than stopping to do both separately. Kaspersky scans email and port 80 traffic (port 80 is the port that receives web traffic and must be open while browsing the web) so that this excellent software can detect and block online viruses, Trojans, and various other malware before they can cause you trouble.

    Kaspersky also has a proactive defense for your computer. Kaspersky watches for unwanted adware, dialers, rootkits, remote access utilities and locks specific registry keys that malicious code may target to damage your computer. Furthermore, Kaspersky now includes protection from viruses while using IM and ICQ.

    Kaspersky, in its ever-vigilance against viruses and other malware, now helps you create a rescue disc in the case that your computer is hit by some malicious code that makes your system unbootable. Although this effort to prepare users for the computer equivalent of Armageddon is commendable, the process is tedious and difficult. If you downloaded your operating system or the system disc is lost or unavailable, this feature will be unavailable to you.

    About this Archive

    This page is an archive of recent entries in the Antivirus Software category.

    Computer Viruses is the next category.

    Find recent content on the main index or look in the archives to find all content.