Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Saturday, October 12, 2013

CryptoLocker Ransomware


CryptoLocker is one nasty piece of malware! 

To put it simply, CryptoLocker encrypts the files on the computer and holds them for ransom.  There is only one private key available to unencrypt the public key and it is stored on a secret server with a time bomb set to destroy the key if the ransom isn't paid by the deadline.  Depending on the version, the ransom is $100 to $300 with a deadline for payment of between ~72 to 100 hours.

Techies interested in "deep dive" information on CryptoLocker are encouraged to see the additional references below.

Update:  Grinler published a comprehensive CryptoLocker Guide and FAQ, added to the references below.  (15OCT2013)

Update 2:  Grinler's guide has been updated with new information. Of particular interest it the information about CryptoPrevent.

CryptoPrevent is a free utility by
FoolishIT LLC that automatically adds the suggested Software Restriction Policy Path Rules (listed in the guide) to your computer. The added Software Restriction Policies are to prevent CryptoLocker and Zbot from being executed in the first place.  (21OCT2013)

Cure

The trojan can be removed from the computer but, other than paying the ransom (not recommended), there is no known way of recovering access to the encrpted files.

The reason it is not recommended that the ransom be paid is that there have been reported instances of the ransom being paid but the decryption key did not work.

As pointed out by "Grinler" in his forum post in the Cryptolocker Hijack program discussion at Bleeping Computer, the only reliable recovery is System Restore or reliable backups.  In the unfortunate event your computer does get infected with CryptoLocker, Grinler's post includes instructions on "How to restore your encrypted files from Shadow Volume Copies"

Prevention

  • Keep your computer updated (antivirus software as well as both Microsoft security and third-party programs).  
  • Be extra cautious about email attachments.  
  • Review critical files and store backups of anything that cannot be replaced offline.  
  • If you are in a position to do so, purchase a Malwarebytes Anti-Malware PRO license for the malware execution prevention and blocking of malware sites and servers that it provides.  A license is currently a one-time fee of $24.95 for one computer.

Additional Information

Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Saturday, November 03, 2012

Report: Top Ten Vulnerabilities Exclude Microsoft Products

Yes, you read the title correctly.  Kaspersky released their 2012 third quarter report of the top ten vulnerabilities and no Microsoft product is on the list.  The data in the report is based on vulnerable programs and files detected on the computers of KSN users.  There was an average of eight different vulnerabilities on each affected computer.

Topping the list is Oracle Java, followed by Adobe products, particularly Adobe Flash Player.  Also included in the list are two Apple products, Quick Time and iTunes.  The list of vulnerabilities can be found on the Securelist, "IT Threat Evolution: Q3 2012", here.

The takeaway?
Don't be a statistic.  Stay safe and keep your computer updated.

If your computer does get infected or you need assistance determining if it is up to date, post the requested logs for review in the Analysis and Malware Removal forum at LandzDown or in the Security Arena at Sysnative.com.


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Friday, August 10, 2012

Gauss: Kaspersky Discovery, Analysis and Removal Tool

First came Stuxnet, Duqu and then Flame.  The latest is Gauss.  Although Gauss is less sophisticated than Flame, it is a data-stealing banking trojan having already obtained data from the Bank of Beirut, EBLF, BlomBank, ByblosBank, FransaBank and Credit Libanais. Citibank and PayPal users are also reported as being targeted.


As described on Securelist in  Gauss: Nation-state cyber-surveillance meets banking Trojan:
"In 140 chars or less, “Gauss is a nation state sponsored banking Trojan which carries a warhead of unknown designation”. Besides stealing various kinds of data from infected Windows machines, it also includes an unknown, encrypted payload which is activated on certain specific system configurations "

The majority of Kaspersky customers who have been found to be infected with Gauss are located in Lebanon. Others are in Israel and Palestine with a few in the U.S., UAE, Qatar, Jordan, Germany and Egypt.

A quick check to determine if your computer is infected with Gauss is available from CrySyS at http://gauss.crysys.hu. The free Kaspersky Virus Removal Tool can be used to remove Dauss from your computer.  


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Sunday, July 29, 2012

Get a Second Opinion from Virus Total

It is not uncommon that an antivirus or anti-malware software program has a f/p (false/positive) detection in a scan. In the event a file that has been on your computer for some time suddenly turns up during a scan, the first recommendation is quarantine rather than remove. If it is a f/p, the file can be restored from quarantine but not easily replaced if deleted, particularly if it is a critical system file.

How can you determine if the detection is a f/p? There are various vendors that provide free on-line computer scans but, in this case, we are looking at one particular file. Among the many services Virus Total provides is the ability to navigate to a specific file on the PC and send it to VirusTotal. As you can see by this example, not every service was detecting this Zbot variant when it was submitted.

To scan an individual file at VirusTotal, just go to https://www.virustotal.com/. Navigate to the location of the file on your computer. After the file is uploaded, click the Scan it! button.

There is more to VirusTotal than scanning individual files. With so many malicious websites, there are occasions when you may want to check whether a site is safe before visiting. VirusTotal also includes the ability to scan URLs. In addition to the Malware Domain Blocklist being integrated in VirusTotal's URL scanning engine, it also includes hpHosts.

hpHosts is maintained by my friend and fellow Microsoft Consumer Security MVP, Steve Burn. The activities that result in domains being included by hpHosts are described at VirusTotal as follows:

  • "Domains being used for advert or tracking purposes.
  • Domains engaged in the distribution of malware (e.g. adware, spyware, trojans and viruses etc).
  • Sites engaged in or alleged to be engaged in the exploitation of browser and OS vulnerabilities as well as the exploitation of gray-matter.
  • Sites engaged in the selling or distribution of bogus or fraudulent applications.
  • Sites engaged in astroturfing otherwise known as grass roots marketing.
  • Persons caught spamming the hpHosts forums.
  • Sites engaged in browser hijacking or other forms of hijacking (OS services, bandwidth, DNS, etc.).
  • Sites engaged in the use of misleading marketing tactics.
  • Sites engaged in Phishing.
  • Sites engaged in the selling, distribution or provision of warez (including but not limited to keygens, serials etc), where such provisions do not contain malware."


The next time you are unsure of the safety of a website, go to VirusTotal and Scan it!



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Saturday, July 07, 2012

Is Your Internet Connection in Jeopardy?

There have been warnings for months about the impending take-down of the temporary DNS servers that the FBI put into place to provide Internet connections to the thousands of computers that were hijacked by the DNS Changer malware.

The take-down of the FBI servers will occur on Monday, July 9, 2012.  In the event your computer was infected with this malware, you will lose your Internet connection when the servers are taken offline.

What to do


If you have not checked your computer yet to find out if it is infected with the DNS Changer trojan, it is important to visit http://www.dcwg.org/detect/.  DCWG has a list of links to security organizations that are maintaining detection sites in local languages.  Each site has instructions on the next steps to clean up possible infections.

Background information is available from the FBI website at FBI — International Cyber Ring That Infected Millions of Computers Dismantled.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Monday, May 28, 2012

Flame, aka Flamer or sKyWIper

Flame, aka Flamer or sKyWIper, has been dubbed more complex than Duqu and Stuxnet.  In fact, it has been described as "the most sophisticated malware we encountered during our practice; arguably, it is the most complex malware ever found." 

As described in The Flame: Questions and Answers - Securelist:
"What exactly is Flame? A worm? A backdoor? What does it do?

Flame is a sophisticated attack toolkit, which is a lot more complex than Duqu. It is a backdoor, a Trojan, and it has worm-like features, allowing it to replicate in a local network and on removable media if it is commanded so by its master.

The initial point of entry of Flame is unknown - we suspect it is deployed through targeted attacks; however, we haven’t seen the original vector of how it spreads. We have some suspicions about possible use of the MS10-033 vulnerability, but we cannot confirm this now.

Once a system is infected, Flame begins a complex set of operations, including sniffing the network traffic, taking screenshots, recording audio conversations, intercepting the keyboard, and so on. All this data is available to the operators through the link to Flame’s command-and-control servers.

Later, the operators can choose to upload further modules, which expand Flame’s functionality. There are about 20 modules in total and the purpose of most of them is still being investigated."
The map below, compiled by Kaspersky, shows the top seven countries affected by Flame:


The following quote by Professor Alan Woodward Department of Computing, University of Surrey, was included in the BBC article, Flame: Massive cyber-attack discovered, researchers say:
"This is an extremely advanced attack. It is more like a toolkit for compiling different code based weapons than a single tool. It can steal everything from the keys you are pressing to what is on your screen to what is being said near the machine.

It also has some very unusual data stealing features including reaching out to any Bluetooth enabled device nearby to see what it can steal.

Just like Stuxnet, this malware can spread by USB stick, i.e. it doesn't need to be connected to a network, although it has that capability as well.

This wasn't written by some spotty teenager in his/her bedroom. It is large, complicated and dedicated to stealing data whilst remaining hidden for a long time."
In other words, it appears that this is just the tip of the iceberg.

Update:  A search of the Malware Protection Center Portal for Win32/Flame shows the addition to detection by Microsoft Security products, Published: May 29, 2012 , Alert level: Severe:

Additional References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Monday, April 09, 2012

OSX/Flashback Trojan

Last week security company, Dr.Web, reported findings of a massive bot net infection impacting Macintosh computers. The Dr.Web report met with a fair amount of skepticism until confirmed by Kaspersky researchers.

Estimates are that around 1 percent of all Macs worldwide have been infected with the Flashback trojan, with the largest majority in the U.S. and Canada.

Detection and Removal


If you or a friend has a Mac, there are a couple of simple methods for Mac users to check to see if their computer is infected with Flashback:
  1. via Forbes, An Easy Way To Check Your Mac For The Flashback Malware 
  2. via DrWeb, Dr.Web C&C Botnet HW-UUID checker

F-Secure provided removal instructions at Threat Description: Trojan-Downloader:OSX/Flashback.K. Because the OSX/Flashback Trojan uses a flaw in Oracle’s Java, F-Secure also provided instructions for Mac users to Update, Disable or Remove Your Java.

So, do Mac or Windows users really need Java? Following are reasons why someone may need Oracle Sun Java installed on their computer:

  • Playing on-line games generally requires Java.
  • With OpenOffice, Java is needed for the items listed here .
  • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
  • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
If the above does not apply to you, consider uninstalling Java. In the event you discover that it is needed, you can always download the most recent version.

Protect Your Mac


With Windows operating systems being the majority, they have long been the the target of malware writers. As a result, it is seldom that I see a Windows OS without an antivirus software installed. The same is not the case for Mac users, although perhaps now they will see the light. Most antivirus vendors now provide licensed software specifically designed for Macs. There are also a few free programs available:

Free A/V for Macintosh:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, December 06, 2011

Windows Defender Offline Beta, formerly Standalone System Sweeper

Although the Microsoft Standalone System Sweeper is currently still available at Connect, it can now also be found as Windows Defender Offline Beta on the Microsoft Help & How-to web pages.

Windows Defender Offline Beta Information


Related Articles





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Friday, November 25, 2011

No, it isn't the Blaster Worm

There has been a rash of posts in help forums by people reporting their computer is infected with the Blaster Worm, w32blaster/worm.  It is not the Blaster Worm that has infected these computers but rather a fake/rogue antispyware program called "Spyware Protection".

Those who have attempted self-help fixes are reporting that they are unable to boot the computer in any mode.  If you are getting notices that your computer is infected with  the w32blaster/worm, follow the following steps:

1. Please restart the computer in Safe Mode with Networking. (To do this, turn your computer off and then back on.  Immediately when you see anything on the screen, start tapping the F8 key on your keyboard. Using the arrow keys on your keyboard, select Safe Mode with Networking and press Enter on your keyboard. Windows will now boot into safe mode with networking and prompt you to login as a user.)
Note:  If you are unable to connect to the Internet, it will be necessary to go to an uninfected computer and download both RKill and Malwarebytes and transport the files to the infected computer via CD/DVD or memory stick.
2. Please download RKill from one of the following links at Bleeping Computer and save to your Desktop:

One, Two,Three or Four

  • Double-click RKill to run.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave RKkill on the Desktop until otherwise advised.
  • Do NOT restart your computer after running rkill as the malware program(s) will start again.
Note: If you you receive security warnings about RKill, please ignore and allow the download to continue.

3. Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, be sure Quick scan is selected, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, EXCEPT items in System Restore as shown in this sample:


  • Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See the Note below)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
** Note **

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

After completing the above steps, take the additional time to update the third-party software on your computer, particularly Adobe products and Java.  Also, double-check that any old, vulnerable versions of Java have been uninstalled.

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you are still having problems with your computer after completing the above instructions, assistance is available from trained analysts trained in malware removal at the sites listed in Malware Removal Help Sites.  As each site has different requirements, please follow the instructions provided at the site.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Sunday, October 09, 2011

How Windows PCs Get Infected with Malware

CSIS Security Group in Denmark conducted a study of almost three months where they collected real-time data from various so-called exploit kits that Danish users were exposed to.  As described by Peter Kruse, Partner and Security Specialist at CSIS:
"An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits."

How PCs Get Infected

The CSIS study revealed that as much as 99.8 % of all virus/malware infections were a direct result of not updating five specific software packages.  Aside from missing Microsoft security updates, the study revealed the following out of date programs as being the most used by malware:  Java JRE (37%), Adobe Reader and Adobe Acrobat (32%), Adobe Flash (16%) and Microsoft Internet Explorer (10%).

Third-Party Software

Setting aside browser and operating system for the moment, what is notable from the CSIS study is the impact of third-party software, notably Java JRE, Adobe Reader and Adobe Acrobat and Adobe Flash.

Oracle Java JRE
When it comes to Oracle Java JRE, you may have it installed on your computer but might not even need it.  Following are reasons why someone may need Oracle Sun Java installed on their computer:
  • Playing on-line games generally requires Java.
  • With OpenOffice, Java is needed for the items listed  here . 
  • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
  • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
If the above does not apply to you, consider uninstalling Java.  In the event you discover that it is needed, you can always download the most recent version.

Adobe Products
Regular readers of this blog are familiar with my postings of critical updates for Adobe products.  You may not realize, however, that there have been over a dozen critical updates of Adobe products just this year between February and September.  Combined, out-dated Adobe products were the direct result of 48% of the infections in the analysis.

Although I will continue providing updates for these products, it is advisable that you check that you have the most recent versions of Adobe products.  Personally, I switched to an alternate PDF reader some time ago.  There are a number of open source readers available from http://pdfreaders.org/.  Others include Nitro Reader and Sumatra PDF.

Internet Explorer

Although Internet Explorer is listed as shown in the CSIS analysis as the most affected browser, the report falls short in not breaking down the statistics by browser version.  According to the IE6 Countdown, at the end of September, 2011, 9% of the world is still using IE6.

It is not very likely that 66% of  reported thousands of users in the analysis who had been exposed to drive-by attacks were using IE9.  Nonetheless, Denmark should be commended with only 0.7% of the users still on IE6.  The percentage still using IE7 is unknown.  Considering the high percentage of affected Windows XP computers, it would not be surprising to learn that the majority have not updated to IE8.

References

CSIS: This is how Windows get infected with malware
IE6 Countdown
Microsoft Download Center - Windows Internet Explorer 8 for Windows XP


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Wednesday, August 03, 2011

Solve Microsoft Standalone System Sweeper Errors

Edit Note: *The Microsoft Standalone System Sweeper Beta has been renamed to "Windows Defender Offline Beta".

There is a lot of interest in the Microsoft Standalone System Sweeper Beta, a recovery tool currently available from Microsoft Connect.  Most people using the tool have not had any problems.  However, as is inevitable, there are several error codes that some people have experienced.

Below is a summary of the common error codes and suggested trouble-shooting steps.

Items of note

  1. At least 1 GB RAM is required in order to run the Standalone System Sweeper.
  2. A minimum of at least 250 MB of free space on the selected media (CD, DVD or USB drive) is required.
  3. The correct version of the tool (32- or 64-bit) is required for the infected operating system where the tool will be used.
  4. The System Sweeper will not be able to scan if there are no definitions.
  5. An Internet connection is needed in order to update the definitions.

Error Code 0x8004cc04


Error Code 0x8004cc04 relates to missing definitions. 

Recommendation:  Run the tool again and select the USB drive option.  The USB drive will be reformatted and a Standalone System Sweeper will be installed on the USB drive.  This will convert the USB to a bootable USB drive.  Be sure to click Yes, download the latest definitions.  You must be connected to the Internet to complete this process.

Error Code 0x8004cc05

UpdateError Code 0x8004cc05 has also occurred in situations where no floppy drive is enabled.  In those cases, a solution that has worked is to boot without the network cable. After the Microsoft Standalone System Sweeper launches, reconnect the network cable and download the current definitions.
(Added 12SEP2011)

Error Code 0x8004cc05 appears to be more common on systems with an AMD processor. I also found that Error Code 0x8004cc05 is also more likely on systems with a 3.5" floppy drive. Disabling the floppy drive either via Device Manager or BIOS appears to solve the problem.

  1. To Disable the Floppy Drive in Device Manager:  Go to Device Manager. (Accept any UAC Prompt in Windows Vista or Windows 7).  Locate and  Expand FloppyDiskdrives. Right-click on the FloppyDiskDrive and select Disable.  Close Device Manager and restart the computer.
  2. To Disable the Floppy Drive in BIOS: On most computers you can access the BIOS by tapping the Delete key when restarting the Computer, although some use the F2, F10 or ESC key.  In CMOS Setup, click the device associated with the drive, generally Floppy Drive A and select Disabled.  Press F10 to save and select Yes to confirm your changes and restart the computer.
Reverse the process to re-enable the floppy drive.

Error Code 0x8050800c

There are a couple of issues that may result in Error Code 0x8050800c.

  1. At least 1 GB RAM is needed in order to run the Standalone System Sweeper
  2. The ISO created may be defective.  Try creating a new ISO, allowing it to download the newest definitions (Note:  You will not be able to scan if there are no definitions.)
  3. Run chkdsk /r on the drive and see if system sweeper will work correctly

Additional Help


For additional assistance, see the problems listed below addressed in Microsoft Standalone System Sweeper Beta Help & How-To


Related Topics



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, June 02, 2011

Setting Up the Microsoft Standalone System Sweeper Beta, Now Windows Defender Offline

Edit Note: The Microsoft Standalone System Sweeper Beta has been renamed to "Windows Defender Offline".  The instructions below have been edited accordingly.

Windows Defender Offline

Windows Defender Offline is a recovery tool currently available from Microsoft.  The tool is not a general, all-purpose scanner and is not a replacement for an updated antivirus program.  Rather, it is to help start an infected PC and perform an offline scan to identify and remove rootkits and other advanced malware.

Windows Defender Offline can also be used in situations where an antivirus software fails to install or the program that is installed is unable to detect or remove malware from the computer.

The original "Microsoft Standalone System Sweeper" tool had long been a part of the Microsoft Diagnostics and Recovery Toolset (DaRT) for Microsoft Enterprise customers.

~   ~   ~   ~   ~   ~   ~   ~   ~   ~   ~

With USB sticks so readily available, the instructions that follow are for that media.  However, a blank CD or DVD can also be used.


Requirements When Creating Windows Defender Offline Media

When creating the bootable media, it is important to consider the following information and requirements:
  • A minimum of at least 250 MB of free space on the selected media (CD, DVD or USB drive) is required.
  • If you elect to prepare an ISO for future use, keep in mind that the definitions will not be up-to-date.
  • Installing Windows Defender Offline on a USB drive will reformat the USB drive, resulting in the loss of all data stored on the USB drive.  (See Note below*)
  • Regardless of the operating system used to create the file, it is essential to select the correct version of the tool, either 32- or 64-bit, for the infected operating system where the tool will be used.
  • An Internet connection is required for installation and download of the latest virus and spyware definitions for Windows Defender Offline.
  • Internet Browser: Windows Internet Explorer 6.0 or higher or Mozilla Firefox 2.0 or higher.


Installing on USB Drive

The download file is located at Microsoft Help and Support.  Again, it does not matter what the operating system is that you use to download and create the bootable media.  However, it is critical to select the correct version for the computer where the tool will be used.

After downloading the file, select the correct version.  If you need assistance determining whether the infected computer is 32- or 64-bit, see the Microsoft Help and Support article for instructions.


Launching the installer, will take you to the "Welcome" screen:



Clicking Next is when you select the media where the tool will be created:



The files for the selected version (32- or 64-bit) will download and install on the media:



After the process has been completed, the bootable USB drive is ready for use.



When you click "Computer" to eject the USB drive, note that the name includes the version of the tool that was created.


Updating the Definitions

After starting the infected computer with Windows Defender Offline, do the following to insure that the most recent definitions are installed:
  1. Click on the Help drop down arrow menu.
  2. Click on Check for updates.
  3. Click on Download.

In the event the infected computer does not have an Internet connection, the updates can be manually transported to the infected machine.  The definitions are the same for Windows Defender Offline as used with Microsoft Security Essentials.
  1. Download the latest definitions from the Malware Protection Center Portal, selecting the correct version for the infected computer: 
    -- mpam-fe.exe is for the 32-bit version   
    -- mpam-fex64.exe is for the 64-bit version
  2. Transport the saved definitions to the infected computer, selecting the Browse button to navigate to the location of the saved definitions.  (See Note below*)


*Note regarding reformatting the USB Drive 

If the following conditions are met, when running the tool again, the USB drive will not be reformatted.  In addition, after creating the tool on your USB, you can copy other tools, "rescue data" as well as the latest definitions. 
  1. The files on the USB drive are not damaged or missing (the tool will verify that the files are not damaged).
  2. The same USB drive is used.
  3. The version of the Windows Defender Offline used to create the bootable USB drive is the same as the version of the tool being re-run or updated.  The tool will detect the already installed product and will only update the definitions without reformatting or altering your data.

System Requirements for Infected Computer

Important Note:  BitLocker must be disabled on the infected computer to use Windows Defender Offline.
  • Operating system:  Windows XP Service Pack 3; Windows Vista (RTM, Service Pack 1, or Service Pack 2, or higher); Windows 7 (RTM, Service Pack 1, or higher).
  • Required processor: 
    Windows XP: 500 MHz or higher1.0 GHz or higher
    Windows Vista and Windows 7: 1.0 GHz or higher
  • Required memory:
    Windows XP: 768 MB RAM or higher
    Windows Vista and Windows 7: 1 GB RAM or higher
  • Required video card: 800 × 600 or higher
  • Available hard disk space: 500 MB 

Download and Additional Information



Related Articles




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, May 26, 2011

Mac Rogue Remover Tool

The creators of rogue (fake) antivirus programs that have been plaguing Windows users for many years have now migrated to the Mac platform. 

Although Apple is planning a Mac OS X software update that is expected to automatically find and remove Mac Defender malware and its known variants, affected Mac users do not need to wait for the update.  In the meantime, Mac users are advised to consider the following:
  1. For Safari users, uncheck the default setting "Open safe files after downloading" on your Mac.
  2. In the event you fell for the scam and purchased the fake program, contact your credit card company.
  3. Watch for the promised update to be issued by Apple.
  4. Install an antivirus software.  (Sophos offers a free antivirus software for Mac home users.)
In the unfortunate event your computer has been infected with one of the rogues, Bleeping Computer to the rescue!  Site owner, Microsoft MVP Lawrence Abrams, has created a tool and removal guides to assist in the removal of many of the known variants of the recently released rogues.  As other variants become available, expect that additional removal guides will be made available. 

For background information on the Mac Removal Tool, see Introducing the BleepingComputer Mac Rogue Remover Tool.


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Sunday, April 17, 2011

How to Use the New Microsoft Safety Scanner

The newly released Microsoft Safety Scanner is a replacement for the Windows Live OneCare Scanner.  The Windows Live OneCare Scanner was eliminated when support ended for Windows Live OneCare. 

If you think your computer has a virus that your current antivirus software missed or is unable to remove, the Security Scanner helps remove viruses, spyware, and other malicious software. The Microsoft Security Scanner will work with your existing antivirus software but it is not a replacement for a resident antivirus software program. There is no charge to use the Microsoft Safety Scanner.


Note

The Microsoft Safety Scanner expires ten (10) days after being downloaded. In order to scan after that time, download the Microsoft Safety Scanner again in order to get the latest anti-malware definitions.

As illustrated by the following images, the scanner is easy to use.  You can download the Microsoft Safety Scanner for running on your own computer or to removable media (i.e., a thumb drive) and transport it to another computer that is infected.

Download


Clicking the "Download" button, provides a prompt to select the 32-bit or 64-bit version. 

If you are downloading the scanner for use on a different computer, be sure you know the correct operating system (32- or 64-bit)



Save the file to a convenient location.  When launching, Windows 7 and Windows Vista users will be asked to approve a UAC prompt.




After launching, you are presented with an end user license agreement.  The terms must be accepted in order to run the scan.

Scanning

One more Next click to get to the point of selecting the type of scan you want the scanner run.







Knowing my computer is not infected, I selected a Quick scan. 

To provide "breathing space" on an infected computer, run a Quick Scan first and then follow with a Full scan.  If you have a lot of files, the scan may take up to several hours to complete.  Allow plenty of time for the scan to run to completion. 





The Quick Scan was indeed fast and only took a few minutes to complete.












After the scan has completed click Finish to close the program.



Remember, the Microsoft Safety Scanner is not a substitute for a resident antivirus software program.  It expires ten (10) days after being downloaded. In order to scan after that time, download the Microsoft Safety Scanner again in order to get the latest anti-malware definitions.

Should you need to re-examine the log, it is located at C:\Windows\Debug\msert.log.  If errors were found during the scan see Microsoft Safety Scanner Troubleshooting.

DownloadMicrosoft Safety Scanner

If you are confused about the difference between the Microsoft Security Scanner and the other anti-malware tools provided by Microsoft, my follow-up article, Understanding Microsoft Anti-Malware Software, should  help clear up the confusion.

Updated Information at Understanding Microsoft Anti-Malware Software 2012.


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, March 31, 2011

Samsung Laptops Secure -- No Keylogger!

The media feeding frenzy over the possibility of a repeat of the Sony BMG rootkit scandal in Samsung laptops was dispelled when reported that it was a false/positive.

As explained by Alex Eckelberry, General Manager, GFI Security:

"The detection was based off of a rarely-used and aggressive VIPRE detection method, using folder paths as a heuristic.  I want to emphasize “rarely”, as these types of detections are seldom used, and when they are, they are subject to an extensive peer review and QA process.  (It’s not common knowledge, but folder path detections are actually used by a good number of antimalware products, but are generally frowned upon as a folder that looks clearly like one for malware has the potential of generating just this kind of result — a false positive.)"

VIPRE has been updated to remove the false/positive detection.

Additional information is available in Samsung Laptops do not have a keylogger (and it was our fault).







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, December 30, 2010

How to Block the New Fast Flux Botnet

The folks at Shadowserver have reported on a new spam campaign that, at first looked like the holiday e-card scams that have been around for many years.  After closer inspection of the details, it appears that it could be the next generation of Storm Worm or Waledac.

Below you'll find a list of subjects in the spam campaign reported by Stephen Adair in New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0?.  The e-mails are coming from all over the Internet with spoofed sender addresses.
Greeting for you!
 Greeting you with heartiest New Year wishes
 Greetings to You
 Happy New Year greetings e-card is waiting for you
 Happy New Year greetings for you
 Happy New Year greetings from your friend
 Have a happy and colorful New Year!
 l want to share Greeting with you (Shadowserver note: the first letter is an L)
 New Year 2011 greetings for you
 You have a greeting card
 You have a New Year Greeting!
 You have received a greetings card
 You've got a Happy New Year Greeting Card!
The email contains a link to a compromised website.  Clicking the link results in a redirect to one of the new malicious domains being used by the botnet.  As explained in the report, "these are fast flux domains that will frequently return a new IP address each time they are resolved."


From New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0?, the currently known domains hosting the botnet, whose purpose is to install malware, are listed below with the appropriate entry to add to your HOSTS file if you wish to block the domains.

If you use WinPatrol, it is easy to edit the HOSTS File, regardless of whether you are running Windows XP, Windows Vista or Windows 7,

  • Right-click on Scotty in the system tray to launch WinPatrol, selecting "Options".
  • Windows Vista and Windows 7 Users: Accept any UAC Prompts
  • Click "View HOSTS file", which will launch in Notepad
  • In Notepad copy/paste the following entries:

    127.0.0.1  bethira.com

    127.0.0.1  bitagede.com
    127.0.0.1  cifici.com
    127.0.0.1  darlev.com
    127.0.0.1  elberer.com
    127.0.0.1  envoyee.com
    127.0.0.1  leolati.com
    127.0.0.1  makonicu.com
    127.0.0.1  nurealla.com
    127.0.0.1  scypap.com
    127.0.0.1  suedev.com
    127.0.0.1  teddamp.com
    127.0.0.1  eplarine.com

  • Click File > Save
  • Close Notepad
  • Close WinPatrol


If you do not use WinPatrol (you should!), you can manually edit the HOSTS file.  It just takes a bit more effort.

With default Windows installations, the HOSTS file is located at C:\Windows\System32\drivers\etc.  If you use Windows 7, it is necessary to first click on Start, type in Notepad and then right-click on Notepad and choose Run as Administrator.  Then, for all systems (Windows XP, Windows Vista and Windows 7), right-click hosts and select to open with Notepad. 


This is an example of what you will see when Notepad launches the HOSTS File:

# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

# localhost name resolution is handled within DNS itself.
#    127.0.0.1       localhost
#    ::1             localhost

After the last line in the HOSTS file, paste the entries below
127.0.0.1  bethira.com
127.0.0.1  bitagede.com
127.0.0.1  cifici.com
127.0.0.1  darlev.com
127.0.0.1  elberer.com
127.0.0.1  envoyee.com
127.0.0.1  leolati.com
127.0.0.1  makonicu.com
127.0.0.1  nurealla.com
127.0.0.1  scypap.com
127.0.0.1  suedev.com
127.0.0.1  teddamp.com
127.0.0.1  eplarine.com

Save and close Notepad. 

Your HOSTS file has been updated and those malware domains have been blocked.

Clubhouse Tags: Clubhouse, Security, Privacy, How-To, Information, Tutorial, Family Safety, Windows Vista, Windows 7, Windows XP,


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, September 09, 2010

Waledac Botnet: R.I.P. b49

A botnet is a network of computers hijacked by bot-herders to spread malware, send spam and commit other forms of cyber crime, such as click fraud and DDoS (Distributed Denial of Service) attacks on websites.  In the case of the Waledac botnet, the network comprised tens of thousands of hijacked computers.


Waledac botnet background described by USA Today:

"The Waledac botnet was a major source of spam and PC infections, at its peak in 2009 delivering 1.5 billion spam messages daily. Microsoft added detection and filtering for Waledac infections to its free malicious software removal tool. But cleaning infected PCs one by one did not stop the command PCs.

By December, Microsoft Hotmail accounts were getting swamped with more than 650 million e-mail spam messages sent out by Waledac. That helped motivate the company to pursue a court order to shut down the command domains.

Even after the botnet's command center got knocked out, tens of thousands of infected PCs continued trying to phone home for instructions."
Waledac botnet take down:

Through the efforts of Microsoft’s Digital Crimes Unit, in partnership with Microsoft’s Trustworthy Computing team and the Microsoft Malware Protection Center, Microsoft undertook a combination of technical measures and previously untried legal techniques to disrupt and control the Waledac botnet, referenced by Microsoft as Operation b49,

The result of this effort takes us from this:
to this:  


Additional background information is available in my earlier post, Waledac Botnet Takedown.

Clean-up:

The exciting news is that the legal action by Microsoft to permanently shut down the botnet was successful.  As a result, Microsoft is now in a position to work with Internet Service Providers (ISPs) and CERTS to help customers remove the Waledac infection from their computers. 

Although communications with the Waledac botnet remain dead, there are still If you believe  your computer is infected by Waledac, free help is available at the Microsoft Virus and Security Solution Center.

Prevention:

The standard advice applies:
  1. Keep a software firewall turned on at all times.
  2. Update not only your computer operating system but third-party software (i.e., Adobe products, Quick-Time and Java, as well.
  3. Maintain up-to-date antivirus and anti-malware software.

The future of botnets from the Microsoft Blog:
"The Waledac takedown is the first undertaking in a larger Microsoft-led initiative called Project MARS (Microsoft Active Response for Security), which is a joint effort between Microsoft’s Digital Crimes Unit, the Microsoft Malware Protection Center (MMPC), Microsoft Support and the Trustworthy Computing team to annihilate botnets and help make the Internet safer for everyone.  We believe the Waledac takedown will be the first of many successful endeavors for Project MARS and we’re already working to apply the lessons we learned from this operation to future initiatives.  
We’re also seeing other members of the security industry and law enforcement taking proactive action to both study and dismantle other botnets, such as the recent actions against Mariposa and Pushdo/Cutwail.  While the approaches to these actions have differed somewhat from the Waledac takedown, all of these efforts demonstrate that the industry is beginning to take a more aggressive stance against botnets."

References:


Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Vulnerabilities, Information


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, August 22, 2010

Beware: Fake Microsoft Security Essentials Rogue

Further substantiation of the increasing popularity of Microsoft Security Essentials (MSE) is evidenced by the new five-in-one rogue reported by Microsoft MVP, Lawrence Abrams of Bleeping Computer. As illustrated by the image capture by Bleeping Computer, this rogue disguises itself as an alert from MSE.

Image and Description by Bleeping Computer:



Description:

"The fake Microsoft Security Essentials Alert is a Trojan that attempts to trick you into thinking you are infected so that you will then install and purchase one of 5 rogue anti-virus programs that it is distributing. When the Trojan is run it will masquerade as an alert from the legitimate Windows Microsoft Security Essentials Program anti-virus program. This alert will be titled Microsoft Security Essentials Alert and states that a Trojan was detected on your computer. It will list this Trojan as Unknown Win32/Trojan and state that it is a severe infection. It will then prompt you to clean your computer using the program in order to remove it. When you click on the Clean Computer or Apply actions button, it will state that it was unable to remove it and then prompt you to scan online. If you click on the Scan Online button it will list 35 different anti-virus programs, 30 of which are legitimate anti-virus programs and 5 that are rogues that the Trojan is distributing. These five rogue programs are:

  • Red Cross Antivirus
  • Peak Protection 2010
  • Pest Detector 4.1
  • Major Defense Kit
  • AntiSpySafeguard or AntiSpy Safeguard

During this fake online scan only the 5 fake anti-virus programs listed above will state that this supposed Trojan is an infection. It does this to scare you into clicking the Free Install button next to them that will install the rogue program onto your computer and then reboot your computer. It should be noted that Red Cross Antivirus, Peak Protection 2010, Pest Detector 4.1, Major Defense Kit, AntiSpySafeguard, and AntiSpy Safeguard that this Trojan is distributing are exactly the same."

In the event you or someone you know is fooled by this rogue trojan, detailed removal instructions are available at Remove the Fake Microsoft Security Essentials Alert Trojan.

Follow-up Actions:
  • If additional assistance is needed to clean the computer, follow the posting instructions at one of these sites that provide Malware Removal Help.
  • Review the 4 Steps to Protect Your Computer and check that third-party programs such as Adobe Flash, Adobe Reader and Java are up-to-date.

, Rogue, Fraud



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, April 08, 2010

Fake Security Programs -- Rogues

Malware disguised as security programs; that is, rogues, have been plaguing internet surfers for the past five years. As time passes, the rogues have become more sophisticated, having the ability to disable Windows Update, firewall, antivirus and anti-malware software, cause web search re-directs and change file associations.

I follow a number of resources to stay up-to-date on the latest rogues. Often times two or three new rogues can be reported in any given day. These sources include sites such as Malwarebytes blog, updates by S!Ri on his blog, Bleeping Computer reports such as "Script kiddies making rogues for fame and not profit", SunbeltBLOG and others.

Security Garden readers may not have much interest in following those sites. However, it is important that you understand what a rogue is and what it can do. Even more importantly, understand how to check for and remove a rogue if your computer becomes infected. Just like the realistic phishing e-mails you may occasionally receive in your mailbox, the rogues are very realistic appearing.

The brief videos linked below were created by Microsoft to provide general information and help about rogue software. Take a few minutes now to add to your personal knowledge base so you will know not only what to do but, most importantly, how to prevent your computer from being infected.

What is rogue software?




How to check for rogue software?



How to defend your computer against rogue software?



Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Safety, Information,



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...