Showing posts with label adware. Show all posts
Showing posts with label adware. Show all posts

Sunday, 20 March 2011

73,000 malware strains created daily in 2011

The number of threats in circulation has risen in comparison to last year. In the first three months of 2011, PandaLabs identified an average of 73,000 new malware strains, most of which were Trojans. Moreover, there was a 26 percent increase of new threats compared to the same period last year.



While PandaLabs observed a quarter-over-quarter increase of new malware in 2010, the rise was not nearly as notable as the one experienced over the last several quarters.

Trojans remain the most popular type of threat to computer systems, and now account for 70 percent of all new malware. This is unsurprising considering it can be incredibly lucrative for cybercriminals to commit fraud or steal money from Internet users through the online banking channel.


“The proliferation of online tools that enable non-technical people to create Trojans in minutes and quickly set up illegal business – especially when it can provide access to banking details - is responsible for Trojans’ impressive growth”, said Luis Corrons, technical director of PandaLabs.

Not all kind of Trojans grow at the same pace. Taking a look further at the subtypes of malware, PandaLabs found that Banker Trojans have decreased, bots have remained steady, and fake anti-virus or rogueware has descreased in popularity. However, the number of “downloaders” has increased significantly.

Downloaders are a subtype of Trojan that, once it has infected a user's computer, connect through the Internet to download additional malware. Hackers often use this method because the downloader is lightweight – only containing a few lines of code - and can go completely unnoticed unlike other Trojans.

[Net-Security]

Saturday, 5 March 2011

Seven Hints to Stay Safe Online

There have been a number of attacks recently against high-profile social networking accounts--French President Sarkozy, teen pop star Selena Gomez, and even social network wunderkind and Facebook founder Mark Zuckerberg have all fallen prey. Web surfing and social networking are here to stay, so the trick is figuring out how to protect your computer and your personal information while you're online.
Similar Articles:

A McAfee spokesperson e-mailed me a list of online security practices recommended by McAfee. Here is an overview of seven steps you can take to secure your online activities:


Attackers are relentless in seeking your personal data, so you have to be diligent about protecting it.

1. Update your browser. Newer browsers have better security controls and protection than older browsers. Make sure you are using the latest version of your Web browser of choice to take advantage of features like phishing filters that can protect you from attacks.

2. Do it in private. Public Wi-Fi hotspots like those at McDonald's or Starbucks are very convenient, but they are also--in a nutshell--insecure. There is typically no security or encryption enabled which means that anyone within range of your wireless connection can potentially intercept your data, including any account numbers or passwords you might type in.
In general, you should stick to reading the news and weather at public hotspots, and avoid ever typing any username, password, or other account data that should be kept private. If you absolutely must log in to Facebook, at least use the new security setting that uses HTTPS to set up a secure, encrypted connection with the social networking site.

3. Keep 'em guessing. Your username and password should be different for each site. Yes, that is more tedious and cumbersome for you to try and remember what your credentials are for each site, but it means that an attacker who compromises your Twitter account will only compromise your Twitter account, rather than having the master key that grants access to every site and service you use on the Web.

4. Double-check the domain. Before you start typing in sensitive information like your password or account number, take a peek at the address bar just to make sure that the site you are logging into is the legitimate site, hosted from the correct domain.
While you might think you are logging in to facebook.com, attackers will often create a realistic-looking malicious spoof site with a domain like facebook.hacker.com, or facebook_login.hacker.com. The bottom line is that the end is the only part that matters. If it says facebook.twitter.google.hacker.org, the real domain is simply "hacker.org" and the rest are simply subdomains created to distract and confuse you.

5. Suspicious messages are suspicious for a reason. Have you ever received an e-mail, or a private Facebook message from someone you know--but who almost never contacts you? Did it seem odd that after months or years or no communication, this person sent you a message out of the blue simply saying "Is this you in this video? LOL.", accompanied by a URL-shortened link to some unknown destination? Did it seem suspicious and make you think twice about clicking the link? It should have. If it seems suspicious--at all--assume that it is malicious and just delete it. If you are concerned that it might be important, then contact the alleged sender directly to make sure it is legitimate.

6. Clear history and log out. If you use a public PC, like at a library or a hotel lobby, to do any Web surfing, make sure you erase your tracks before you leave. You should use the anonymous or private browsing mode of the browser if there is one available. When you are done, you should go into the properties for the Web browser and erase the history and cache to remove traces of your Web-surfing activities.
You also need to make sure you manually log out of sites you log into. Just because you shut down the browser window doesn't necessarily mean you are logged out of the site. Whether intentional or pure accident, the next user of that same PC may find that your account is still actively logged in, granting complete access to a stranger.

7. Protect your PC. It wouldn't be a list of recommended security best practices without a reminder to properly protect the PC. You should have some sort of security suite, or collection of tools, providing personal firewall security and protection against viruses, spyware, phishing attacks, and other malware. As important as installing the protection is, it is more important to make sure the tools are frequently updated. Security software is typically only as secure as its last update. As new threats emerge, security software may be unable to detect or defend against them without the current update data.
There you have it. None of it is rocket science. In fact, most of it is simple, common sense. The dirty secret about PC and online security is that it is 90 percent common sense and healthy skepticism. The security software just helps guard against the other 10 percent.

[PCWorld]

Friday, 4 March 2011

Simple protection steps from credit card fraud

Every year, cybercriminals steal billions of dollars from unsuspecting computer users and companies by committing credit card fraud.



Although this activity was once relegated to pick-pocketers and mailbox thieves, today roughly half of all credit card fraud starts with online attacks ranging from phishing and email scams to spyware programs such as adware, keyloggers, Trojans, system monitors, browser hijackers, and dialers.

Fortunately, if you know what to watch for – and have good online protection – you can avoid becoming a victim of these fraudsters and keep your personal information safe.

The first step to ensuring that you're able to catch any form of credit card fraud (online or otherwise) early is to closely monitor your credit card activity. You can do this the old-fashioned way via your credit card company's official website, or you can find a security program that monitors your credit cards for you and alerts you to suspicious activity.

Here are a few additional tips from Webroot to help you safeguard your personal information online:
  • Use varied and complex passwords for all your accounts, including online shopping accounts, bank accounts, social networking sites, etc. (You may want to try using a security software program with a password manager to help you keep them straight.)
  • Only provide personal information on secure sites. (Look for "https" in the web address or the lock icon at the bottom of the browser.)
  • Do not respond to unsolicited requests for personal information – they are often a sign of phishing.
  • Avoid questionable Web sites, such as adult sites and file sharing sites.
  • Only download software from sites you trust.
  • Practice safe email protocol by not opening messages from unknown senders. Immediately delete messages you suspect to be spam.
Some signs and symptoms that your PC may be infected and require cleanup (as well as updated spyware and virus protection) include:
  • Sluggish performance
  • Increased number of pop-ups
  • New toolbars you can't delete
  • Unexplained changes to homepage settings
  • Puzzling search results
  • Frequent computer crashes.