FYI…

- http://www.viruslist.com/en/analysis?pubid=182974451
Apr 03 2006
"This report provides statistical information and comment on significant events of the past year. It also examines the continuing growth in the market for malicious code, and includes an analysis of the current situation. The report is aimed at security professionals who have an interest in malicious programs. Users with an interest in computer viruses may also find it of use.
…Since virus writers have started intensively targeting new users, the antivirus industry's speed of response has become key. Unfortunately, most users (both total beginners and slightly more experienced users) fail to appreciate the gravity of the situation… The poll results show that only 24% of users update their solution at least once a day. Given the rate at which new malicious programs appear…, it's easy to estimate the number of detections for malicious programs which are added in each hourly update. Consequently, it's also easy to estimate the number of malicious programs which could potentially infect the 76% of users who do not update their solutions daily… Unfortunately, security does not only depend on the speed at which antivirus vendors respond to new threats. Users need to take a multifaceted approach and install patches that rectify vulnerabilities in the operating system and other software they use… Data shows that the mass mailing of a malicious program to several million addresses using a botnet (a network of infected machines) takes about two hours. Therefore, every additional minute translates into thousands, even tens of thousands, potential new victims, making the speed at which antivirus companies respond crucial…"

(Other highlights of the report:
- Rootkits
- Business-malware
- Blackmail
…and more)

User Recommendations
Although this article covers a variety of security issues, there are a number of simple recommendations which will help users avoid or combat most cyberthreats.
* Do not open attachments or click links in messages which you were not expecting. This applies to emails and messages received via any other network client (e.g., ICQ). Moreover, the rule applies both to messages from unknown senders and from those in your contact list; there are lots of malicious programs that infect computers and then send messages to all contacts found. The attachment or link is usually accompanied by a plausible-sounding text encouraging the recipient to activate it. If you weren't expecting a message, check with the sender whether the attachment or link is genuine.
* Update your antivirus solution regularly.
* Update your operating system and other software regularly.
* Back up your data regularly. This will enable you to restore data if your system crashes or data is rendered unusable by malicious programs.
* Do not use the administrator account unless necessary.
* Use a firewall.
Conclusion
…The results of 2005 shows that cybercriminals are likely to continue to focus on mobile devices and the financial sector. However, rootkits, botnets, cyber-blackmail and other criminal activities are likely to remain popular. Although law enforcement bodies have stepped up their efforts in relation to tracking and convicting cybercriminals, the threats still outweigh the countermeasures taken. It is therefore essential that users take steps to help ensure their own cyber safety."

* http://www.viruslist.com/en/analysis?pubid=178949694

.