The Malware Dictionary

The Latest Computer Adware, Spyware, and Virus Info!

How Do You Turn Norton Antivirus On and Off?

Tags: , , , , , , , ,

Norton Anti-virus is one of the most popular anti-virus programs for home computers. It is also a popular anti-virus program that is bundled with new computers sold by companies such as HP and Dell computing. Many computer users will want to be able to turn Norton off if they have a preferred anti-virus program or need to conduct computer downloads or game play that are not compatible with running Norton anti-virus. Regardless of the reason that you need to turn Norton on or off, it is relatively straightforward to accomplish once you have done it once.

How to Turn Norton Anti-Virus Off Using the Software Interface

The easiest way to turn Norton Anti-virus off is using the program’s interface to secure the application. In order to so:
1 – Double left click the Anti-virus center icon in the right corner of your toolbar. Then, choose the “status and Settings” toolbar option.
2 – Now, you’ll select the “Security” menu option and select the “off” option on the subsequent menu.

When you restart your computer, Norton Anti-virus will be off.

How to Manually Turn Off Norton Security

Alternatively, you can secure Norton Anti-virus manually through the Windows Task Manager. To secure Norton in this manner:
1 – Open your computer’s task manager by choosing the “Ctrl + Alt + Delete” keys simultaneously.
2 – Choose the “Processes” tab that’s at the top of your computer’s task manager. You can then sort the application names by clicking the “description” program heading.
3 – Find Norton Anti-virus on the program listing. Single left click the program name and choose the “End Process” menu option. Norton will now be manually turned off.

How to Manually Turn On Norton Security

If you need to turn Norton Security back on, you will need to open Norton from your computer’s start menu. Then,
1 – Choose the “Options” menu option in the main Norton window.
2 – Toggle the “Auto-Protect” option in the Norton Options window and check the check box next to the “Enable Auto-Protect” menu choice. Norton will now be enabeld on your computer.

How to Enable Norton LiveUpdate

Norton LiveUpdate can be set to have Norton Anti-Virus to check for software updates automatically on a set schedule. When LiveUpdate is set to automatic, it will check for updates on a four hour frequency. In order to enable LiveUpdate you will need to:

1 – Choose the “Options” menu in the main Norton Anti-virus window.
2 – Click the “Internet” option in the options menu and pick “LiveUpdate”
3 – Then, choose the “Enable Automatic LiveUpdate” check box on the next window.

W32.Allaple Computer Malware – Worm

Tags: , , , , , ,

W32.Allaple Computer Malware – Worm Description

w32 allaple is a malware that targets your network to scan and attempt to spread. It is classified as a low-medium risk worm, and will keep trying to spread as long as it is on your computer.

W32.Allaple Malware Installation

This malware worm installs itself in your registry. Most files of the worm come from downloads and spyware, which will then attempt to spread from your computer to another. It installs by “hacking” network passwords that are weak and easy to crack. It also takes advantage of exploits that may be present in your network. HTML files usually become infected with this malware code instead of executable programs. Like many worms and viruses, the w32 allaple puts itself into the registry, so every time you load your computer it starts up too.

W32.Allaple MalwarePayload

The payload is said to be severe and the risk is very high when it comes to getting the virus. Your computer slows down dramatically, and will frequently crash. The malware also downloads other potentially dangerous files without your consent, and continues to harvest information to upload to a remote website.

W32.Allaple Malware Processes and Files

There are a few different identifying files when looking for the allaple virus. It usually drops files that are 8 random lower case letters, and may look like this: uitlokgh.exe

It adds a specific registry that looks like this:

key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows

value: ImagePath

data: “”%System%\urdvxc.exe”/service

There are a number of different Allaple malware files that can tip you off to whether or not your computer is infected with the w32 allaple virus.

Basic Removal Steps

The W32.Allaple worm is complex and it is not recommended to attempt manual removal. Automatic removal using an updated anti-virus program is the recommended means for removal.

Click here for automatic removal instructions for removing the W32.AllapleWorm.

W32.Alemod Trojan Virus

Tags: , , , , , , ,

W32.Alemod Trojan Virus Description

W32 Alemod is a Trojan virus that works by downloading information and stealing your personal information, or any kind of information it can recover. Currently this is not a high risk threat, and it is easily controlled.

W32.Alemod Trojan Virus Malware Installation

The malware w32 alemod, or win32 alemod, infects your computer by downloading an infected program. This is not always the case, but usually it is. The malware will only activate once you execute, or attempt to execute an infected computer file. It’s hard to know if one of your programs is infected, unless you check every single file on a regular basis. They can be transferred to your computer by jump drives, USB drives, downloaded files, and transferred files.

W32.Alemod Trojan Virus MalwarePayload

The payload varies depending on how many files are infected and how badly your computer is hit. Usually important information is stolen, such as any social security numbers you may have stored, and uploaded to a website used to gather the information. This information that is obtained may be used for malicious purposes.

W32.Alemod Trojan Virus Malware Processes and Files

There are several identifying files that can let you know your computer has the w32 alemod virus. They are:

oleadm.dll

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
“AllowProtectedRenames” = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
“PendingFileRenameOperations” = \??\C:\windows\system32\oleadm32.dll
!\??\C:\windows\system32\wininet.dll

Wininet.dll is replaced with a dangerous file named oleadm32.dll.

This malware is also known as a few different names that include: Trojan-Downloader.Win32.Agent.ns, W32.Desktophijack, and win32.alemod.a

Basics on Removal of the W32.Alemod Trojan Virus

This virus can be easily removed by using an anti-virus program or hunting down the files and removing them. If you are experienced at virus removal, this removal is a cinch.

Automatic removal using an updated anti-virus program is the recommended means for removal.

Click here for automatic removal instructions for removing the W32.Alemod Trojan Virus.

Win32.Mawar – Computer Virus

Tags: , , , , , , , , , ,

Win32.Mawar Description

Win32.Mawar is labeled as a computer virus, but it is really just a script labeled as malware by most anti-virus companies. It is also known by the names JS_AUTORUN.ABE, Mawar.js, and AhPaw.js.

Win32.Mawar Symptoms
You will see the following indications if your computer is infected with Mawar:

- Your Windows Explorer and/or the Internet Explorer window title is changed to Mawar.js or AhPaw.js
- When you right-click any drive inside the My Computer section of your computer, the default option which is “Open” is not the first choice. It will be labeled “Op%n” or “Search” instead of the default, bolded “Open”.
- Double clicking a drive on your computer won’t open it. Instead it will perform another operating system function such as “Search”.
- You have to go to the address bar and select your drive from the small arrow icon to open it, instead of double-clicking the drive.

How to Remove Win32.Mawar

Manual Instructions – Conduct at your own risk! Use a anti-virus or anti-malware program if you have one available first!
1. Disable System Restore on your computer by doing the following:

- Right click the “My Computer” icon on your computer and select “Properties->System Restore” and check the “Turn Off System Restore” option.
(Right click My Computer –> Properties –> System Restore –> check at the Turn Off System Restore box –> OK

2. Restart your computer in Window Safe Mode

Reboot your computer normally, then push the “F8” key rapidly until you get the reboot menu. Then choose the “Safe Mode” rebooting option.
3. Login to your computer in administrator mode.
4. Unhide all Hidden Files and protected Operating System Files

- Open “My Computer” then select “Tools->Folder Options->View” and check the “Show hidden files and folders” radio button followed by unchecking the “Hide protected operating system files (Recommended) button.
- Click “OK” to apply the changes
5. Go to My Computer –> C:\ drive (or any additional/removable drive) find the following files through searching the drive and delete them: autorun.ini, VirusMwrdy.js, ahpaw.js.
6. Go to My Computer again, and right-click C:\ drive
- Click Properties –> Disk Cleanup –> More Options –> System Restore –> Cleanup.. –> click Yes when asked –> then choose the “Ok” menu option.
7. Remove Mawar Registry Entries
- Click Start — > Run –> input “regedit” and click the “enter” button on your keyboard.
- Search the registry for VirusMwrdy.js, ahpaw.js, and delete all keys found on the searches. For mawar, also enter mawar on a separate search and ahpaw for AhPaw.js.

8. To fix your windows and Internet Explorer title bars, delete this entry from your registry:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
9. Reboot your computer normally after finishing with the registry deletions.

© 2009 The Malware Dictionary. All Rights Reserved.

This blog is powered by Wordpress and Magatheme by Bryan Helmig.