Saturday, September 11, 2010

All About Computer Viruses



Your computer is as slow as molasses. Your mouse freezes every 15 minutes, and that Microsoft Word program just won’t seem to open.

You might have a virus.



Just what exactly is a virus? What kind is in your computer? How did it get there? How is it spreading and wreaking such havoc? And why is it bothering with your computer anyway?



Viruses are pieces of programming code that make copies of themselves, or replicate, inside your computer without asking your explicit written permission to do so. Forget getting your permission down on paper. Viruses don’t bother to seek your permission at all! Very invasive.



In comparison, there are pieces of code that might replicate inside your computer, say something your IT guy thinks you need. But the code spreads, perhaps throughout your office network, with your consent (or at least your IT guy’s consent). These types of replicating code are called agents, said Jimmy Kuo, a research fellow with McAfee AVERT, a research arm of anti-virus software-maker McAfee Inc.

In this article, though, we’re not talking about the good guys, or the agents. We’ll be talking about the bad guys, the viruses.

A long, long time ago in computer years, like five, most viruses were comprised of a similar breed. They entered your computer perhaps through an email attachment or a floppy disk (remember those?). Then they attached themselves to one of your files, say your Microsoft Word program.



When you opened your Microsoft Word program, the virus replicated and attached itself to other files. These could be other random files on your hard drive, the files furthest away from your Microsoft Word program, or other files, depending on how the virus writer wanted the virus to behave.



This virus code could contain hundreds or thousands of instructions. When it replicates it inserts those instructions, into the files it infects, said Carey Nachenberg, Chief Architect at Symantec Research Labs, an arm of anti-virus software-maker Symantec. Corp.

Because so many other types of viruses exist now, the kind just described is called a classic virus. Classic viruses still exist but they’re not quite as prevalent as they used to be. (Perhaps we could put classic viruses on the shelf with Hemingway and Dickens.)

These days, in the modern era, viruses are known to spread through vulnerabilities in web browsers, files shared over the internet, emails themselves, and computer networks.



As far as web browsers are concerned, Microsoft’s Internet Explorer takes most of the heat for spreading viruses because it’s used by more people for web surfing than any other browser.



Nevertheless, “Any web browser potentially has vulnerabilities,” Nachenberg said.

For instance, let’s say you go to a website in IE you have every reason to think is safe, Nachenberg said.

But unfortunately it isn’t. It has virus code hidden in its background that IE isn’t protecting you from. While you’re looking at the site, the virus is downloaded onto your computer, he said. That’s one way of catching a nasty virus.



During the past two years, another prevalent way to catch a virus has been through downloads computer users share with one another, mostly on music sharing sites, Kuo said. On Limewire or Kazaa, for instance, teenagers or other music enthusiasts might think they’re downloading that latest Justin Timberlake song, when in reality they’re downloading a virus straight into their computer. It’s easy for a virus writer to put a download with a virus on one of these sites because everyone’s sharing with everyone else anyway.



Here’s one you might not have thought of. If you use Outlook or Outlook Express to send and receive email, do you have a preview pane below your list of emails that shows the contents of the email you have highlighted? If so, you may be putting yourself at risk.

Some viruses, though a small percentage according to Nachenberg, are inserted straight into emails themselves.



Forget opening the attachment. All you have to do is view the email to potentially get a virus, Kuo added. For instance, have you ever opened or viewed an email that states it’s “loading”? Well, once everything is “loaded,” a virus in the email might just load onto your computer.



So if I were you, I’d click on View on the toolbar in your Outlook or Outlook Express and close the preview pane. (You have to click on View and then Layout in Outlook Express.)



On a network at work? You could get a virus that way. Worms are viruses that come into your computer via networks, Kuo said. They travel from machine to machine and, unlike, the classic viruses, they attack the machine itself rather than individual files.


Worms sit in your working memory, or RAM,

Nachenberg said.




OK, so we’ve talked about how the viruses get into a computer. How do they cause so much damage once they’re there?

Let’s say you’ve caught a classic virus, one that replicates and attacks various files on your computer. Let’s go back to the example of the virus that initially infects your Microsoft Word program.



Well, it might eventually cause that program to crash, Nachenberg said. It also might cause damage to your computer as it looks for new targets to infect.



This process of infecting targets and looking for new ones could eventually use up your computer’s ability to function, he said.

Often the destruction a virus causes is pegged to a certain event or date and time, called a trigger. For instance, a virus could be programmed to lay dormant until January 28. When that date rolls around, though, it may be programmed to do something as innocuous but annoying as splash popups on your screen, or something as severe as reformat your computer’s hard drive, Nachenberg said.

There are other potential reasons, though, for a virus to cause your computer to be acting slow or in weird ways. And that leads us to a new segment – the reason virus writers would want to waste their time creating viruses in the first place.



The majority of viruses are still written by teenagers looking for some notoriety, Nachenberg said. But a growing segment of the virus-writing population has other intentions in mind.



For these other intentions, we first need to explain the “backdoor” concept.



The sole purpose of some viruses is to create a vulnerability in your computer. Once it creates this hole of sorts, or backdoor, it signals home to mama or dada virus writer (kind of like in E.T.). Once the virus writer receives the signal, they can use and abuse your computer to their own likings.



Trojans are sometimes used to open backdoors. In fact that is usually their sole purpose, Kuo said.

Trojans are pieces of code you might download onto your computer, say, from a newsgroup. As in the Trojan War they are named after, they are usually disguised as innocuous pieces of code. But Trojans aren’t considered viruses because they don’t replicate.



Now back to the real viruses. Let’s say we have Joe Shmo virus writer. He sends out a virus that ends up infecting a thousand machines. But he doesn’t want the feds on his case. So he instructs the viruses on the various machines to send their signals, not of course to his computer, but to a place that can’t be traced. Hotmail email happens to be an example of one such place, Kuo said.

OK, so the virus writers now control these computers. What will they use them for?



One use is to send spam. Once that backdoor is open, they bounce spam off of those computers and send it to other machines, Nachenberg said.



That’s right. Some spam you have in your email right now may have been originally sent to other innocent computers before it came to yours so that it could remain in disguise. If the authorities could track down the original senders of spam, they could crack down on spam itself. Spam senders don’t want that.



Ever heard of phishing emails? Those are the ones that purport to be from your internet service provider or bank. They typically request some information from you, like your credit card number. The problem is, they’re NOT from your internet service provider or your bank. They’re from evil people after your credit card number! Well, these emails are often sent the same way spam is sent, by sending them via innocent computers.



Of course makers of anti-virus software use a variety of methods to combat the onslaught of viruses. Norton, for instance, uses signature scanning, Nachenberg said.



Signature scanning is similar to the process of looking for DNA fingerprints, he said. Norton examines programming code to find what viruses are made of. It adds those bad instructions it finds to its large database of other bad code. Then it uses this vast database to seek out and match the code in it with similar code in your computer. When it finds such virus code, it lets you know!

©2004 by Kara Glover



Feel Free to reprint this article in newsletters and on websites, with resource box included. If you use this article, please send a brief message to let me know where it appeared: kara333@earthlink.net



Kara Glover is a Computer Tutor and Troubleshooter. You can find her articles and tutorials on topics such as Microsoft Word®, Excel®, and PowerPoint® on her website: http://www.karathecomputertutor.com/

kara333@earthlink.net



Sunday, June 20, 2010

Google updates IE plug-in Chrome Frame


Open source plug-in works in Microsoft IE6, IE7 and IE8


By Gregg Keizer | Computerworld US
Published: 12:34 GMT, 09 June 10

Google updated Chrome Frame, a plug-in that embeds the company's Chrome browser engine into rival Microsoft's Internet Explorer, to a beta version.

Chrome Frame debuted last September, prompting rivals Microsoft and Mozilla to blast the move. The open source plug-in can be used with Internet Explorer 6, IE7 and IE8.

The beta is powered by the current beta version of Chrome for Windows, 5.0.375.62, but will be updated as Chrome is refreshed. Additionally, the "dev channel" edition of Chrome Frame was revamped today to keep it in sync with that build of Google's browser.

Google fixes bug in Calendar

As it did last year, Google cast Chrome Frame today as a way for IE users to instantly boost the notoriously slow JavaScript speed of their browser and let them access sites and Web applications that rely on standards that IE doesn't support, primarily HTML5.

"Chrome Frame is an attempt to move the Web forward," Alex Russell, an engineer on the Chrome Frame development team, told Computerworld. "We're excited that it's ready for broader use and want to get it out there to target [users] who aren't able to use HTML5."

HTML5, the still-under-construction next generation of the Web's foundation language, has become a flashpoint -- and buzzword -- in the increasingly competitive browser market as makers rush to support the standard, especially its video tag that lets Web site designers embed video.

Apple, for example, has been aggressively promoting HTML5 as a substitute for Adobe's Flash, which Apple has banned from its iPhone and iPad.

Meanwhile, Microsoft has been trumpeting the support for HTML5 it's baking into IE9, which has no firm release date and is now at a rough developer preview stage.

Google has been promoting HTML5 just as hard. Last month, for example, Google debuted a new royalty-free video codec that will compete with the H.264 codec that Apple's backing for HTML5.

"We'd like to keep everyone bunched toward the front of the [standards] compatibility edge," said Russell as he further explained why Google is pushing Chrome Frame.

Even though Microsoft is working on IE9, and promising that its next browser will support HTML 5, the problem is that users often stick with outdated versions of IE for years, added Russell.

"And the fact that Microsoft's chosen not to support IE9 for older versions of Windows, like Windows XP, means that IE8 is the end of the road for [XP users]. They'll be in the same situation [in the future] as IE6 users are [now]," he said.

Microsoft may be pushing to end IE6's reign, but it's not conceding anything to Google. Last week, Ryan Gavin, Microsoft's director of platform strategies and the executive in charge of driving down the aged browser's market share, claimed that IE8 was gaining more ground that Google's Chrome in the U.S.

"We're already seeing Chrome in retreat," Gavin said.

Contrary to fears expressed by Mozilla executives last year when Chrome Frame debuted, Google has no intention of releasing a similar plug-in for Firefox, Russell said.

Although such a plug-in is possible, he said, "We didn't release it [and] it's not something that we expect to use."

And Russell dismissed Microsoft's complaints of last year, when IE's maker argued that Google Frame would effectively double users' security problems because they would have to keep two browser platforms up to date.

"The real problem is that Web developers have to target the lowest-common denominator," Russell said, citing the example of the nearly-nine-year-old IE6.

Sunday, May 23, 2010

Microsoft's alleged click fraud launderers maintain innocence

Beta customers named in two click fraud lawsuits Microsoft filed this week maintain their innocence, and both say they assisted the software giant in investigating the source of the problem.




On Wednesday, Microsoft held a press conference featuring its general counsel, senior attorney of its digital crimes unit, an independent consultant, a Harvard professor and an executive from an advertising industry group. The Microsoft executives detailed what they said is a new kind of click fraud, "click laundering," and said the company had filed two lawsuits against people employing the technique.

Microsoft alleges that defendants used botnets and other techniques to drive traffic to their own servers, where they scraped out the traffic-referring information and replaced it with code that made it look like the traffic came directly to their sites.


While the company HelloMetro was not named as a defendant in either of the suits, it was cited as the publisher of sites receiving inordinate numbers of clicks.

"During the brief 4 weeks last year we participated in Microsoft's Beta, we volunteered information to Microsoft to help locate some suspected sites and companies," said Clark Scott, CEO of HelloMetro, in a statement. "That is why we are not listed as a Defendant here. We may be asked to submit what we have found to pursue those John Does."

Microsoft named 20 John Does as defendants in the suit, meaning it doesn't know who is responsible for the fraud.

But RedOrbit says it also helped Microsoft investigate the fraud. "We turned over log files" and other details that Microsoft requested as it sought to discover the source of a dramatic spike in clicks to RedOrbit, said Eric Ralls, RedOrbit's president, who is also named as a defendant in the suit.

Microsoft executives pointed their fingers at RedOrbit because "we feel confident that the person who would profit is RedOrbit," said Richard Boscovich, senior attorney of Microsoft's digital crimes unit. It's unclear why Microsoft didn't name HelloMetro as a defendant for similar reasons.

Yet, RedOrbit didn't profit, Ralls said. "They had paid us no money. We didn't get a dime from those clicks. We have not profited in any way from this at all," he said.

Ralls said that his lawyer, retained this week after news of the lawsuits surfaced, has instructed him to say little more. "We do not, nor have we ever, engaged, assisted in, or condoned click fraud," Ralls said in a statement. "We are disappointed that Microsoft has made these completely baseless allegations, and intend to defend against them vigorously."

Both RedOrbit and HelloMetro were beta customers of Microsoft's AdCenter program. AdCenter is Microsoft's answer to Google's AdSense, the market-leading advertising platform.

There are some curious aspects of the case, said Richard Sim, vice president, product management and marketing at Anchor Intelligence. For instance, Microsoft said that the average clicks per day on RedOrbit's site grew from 75 to 10,000 in a matter of weeks.

"When I saw that, to me it signaled that the person behind this scheme was very unsophisticated because that's a sure sign that something's going wrong," Sim said. "That did surprise me, that if this was perpetrated by one individual that they'd use such a rudimentary approach." Most ad platforms would suspect fraud after such a dramatic spike in traffic.

Yet Microsoft characterized this kind of fraud as sophisticated. "There's been lots of talk about whether this is technically possible," said Boscovich. It's the first time Microsoft has seen this kind of fraud, which it previously thought was impossible to do, he said.

It's possible, though rare, that such spikes happen without the involvement of the site owner. For instance, a competitor might maliciously send huge volumes of traffic to another site as a way to try to get the site blacklisted by its ad platform, Sim said.

Microsoft is the underdog in this market and seemed to be using the lawsuits as a way to paint itself as the most honest of the ad platform providers.

"We and every other company in the industry has to recognize that we have a choice. We can either take aggressive steps to stop this fraud or look the other way and make money from it. We don't think looking the other way should be an option," said Brad Smith, general counsel at Microsoft, during Wednesday's event.
Login | Register Follow us on Twitter Get Widget
Subscribe to Techworld newsletters

Microsoft noted that it has filed three click fraud suits. The experts around the table said that they were aware of one Google suit that was quickly dropped and zero Yahoo suits.

But Microsoft has a history of using lawsuits to fight fraud and has often done so successfully, Sim said. "I think the approach Microsoft took to fighting spam is similar to what they're doing in click fraud," he said. Microsoft used technology tools, industry collaboration and civil lawsuits to combat spam, Sim said. "That was effective because for the industry as a whole it sent the message that they are willing to invest and enforce violations against spam policies. They send a message to the perpetrators that they can't get away with this," he said.

That's exactly what Microsoft said it is trying to do. "We're sending a clear message here and that's that we don't tolerate this," said Boscovich.

It is very early in Microsoft's ad platform and so it may be trying to ensure from the very beginning that fraud isn't a problem. "For them, click fraud hasn't been a big pain point to date," Sim said.