Showing posts with label computer viruses. Show all posts
Showing posts with label computer viruses. Show all posts

“Hey You! Your PC is scrap”

Trojan Whizz.A : Back to the future – Part 2

London, UK, March 2009: System error reports and collaborating computers: That the are the attacks of the old days. With the “warning” “Hey You! Your PC is scrap”, or whatever in the appropriate language the Trojan Whizz.A draws attention to itself and to the fact that it is present on the machine in question. This is a traditional piece of malware, which is based on a very old kind.

Like Panda Security had predicted for 2009 online criminals are using old variants of malware again. Beats me why but so it seems to be.

With the Trojan Whizz.A we are seeing, for the second time in this first quarter of 2009 such an example. It appears to be a definite case of “Back to the Future” going on here.

In the same ways as in days gone by Whizz.A reduces the usability of the PC in that it slows it down. An infection is therefore immediately noted. First of all the Trojan lets users know his presence with a message like the one mentioned in the header – or variants, depending on the language – and the user thus immediately has been alerted to the fact that he has become the victim of an attack. This is then followed by an audio alarm emanating from the PC speakers.

The cursor too no longer remains stationary by is all over the show and the keyboards becomes basically unusable.

The Trojan also opens the CD/DVD player and the monitor is filled slowly in steps with red bars until nothing is visible anymore. In addition to that the PC can no longer be started up in the safe mode.

More information as to how to find and remove this virus you can find here: http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=sol&idvirus=206552&sitepanda=particulares

As said above, I have no idea as to why the cyber-criminals are resorting, once again, to attacks with malware such as this Trojan as they cannot, in effect, use it to achieve anything. With the exception, that is, of causing havoc, and maybe it is that what they are trying too do.

© M Smith (Veshengro), 2009
<>

Facebook we have a problem

Koobface, and other worms target Facebook Friends

by Michael Smith

London, March 7, 2009: As Facebook works to make itself more relevant and timely for its growing member base with a profile page makeover, attackers seem to be working overtime to steal the identities of the friends, fans and brands that connect though the social-networking site.

Indeed, Facebook has seen five different security threats in the past week alone. According to Trend Micro, four new hoax applications are attempting to trick members into divulging their usernames and passwords. Also, a new variant of the Koobface worm is running wild on the site, installing malware on the computers of victims who click on a link to a fake YouTube video.

The Koobface worm very is dangerous. It can be dropped by other malware and downloaded unknowingly by a user when visiting malicious Web sites, Trend Micro reports. When attackers execute the malware, it searches for cookies created by online social networks. The latest variant is targeting Facebook, but earlier variants have also plagued MySpace.

Once Koobface finds the social-networking cookies, it makes a DNS query to check IP addresses that correspond to remote domains. Trend Micro explains that those servers can send and receive information about the affected machine. Once connected, the malicious user can remotely perform commands on the victim's machine.

According to Trend Micro once cookies related to the monitored social-networking Web sites are located, it connects to these Web sites using the user log-in session stored in the cookies. It then navigates through pages to search for the user's friends. If a friend has been located, it sends an HTTP POST request to the server.

Ultimately, the worm's agenda is to transform the victim's computer into a zombie and form botnets for malicious purposes. Koobface attempts to do this by composing a message and sending it to the user's friends. The message contains a link to a Web site where a copy of the worm can be downloaded by unsuspecting friends. And the cycle repeats itself.

Malware authors are investing more energy in Facebook and other social-networking sites because that effort pays off, according to Michael Argast, a security analyst at Sophos. Facebook alone has more than 175 million users, which makes it an attractive target.

"Many computer users have been conditioned not to open an attachment from an e-mail or click a link found within, but won't think twice about checking out a supposedly hot new video linked to by a trusted friend on Facebook," Argast said.

Argast called the Koobface worm a mix of something old and something new. The new is using social networks as a method to spread malware. The old is using fake codec Trojans linked to a saucy video to induce the user to install the malware.

Argast said people can protect themselves by running up-to-date antivirus software, restricting which Facebook applications they install, thinking twice before clicking on links from friends and never, never installing a codec from some random Web site in the hopes of catching some celebrity in a compromised situation.

"I would expect to see more attacks on Facebook," Argast said. "As long as this is a successful propagation method, the bad guys will double down and invest more. They are entirely motivated by financial gain. If it pays, they'll continue to romp in your social playgrounds."

This advice is the same and the rules should be the same as to the emails that arrive claiming that here or there one can have a look at this or that celebrity or whatever in compromised positions or such.

I personally must say that I never understand why people have this desire to believe that there are such videos about even and that they are worth taking a look at.

However, as we all know, people being people they have this strange drive and they will do just that and that is what the malware writers exploit.

As Michael Argast from Sophos says, have proper up-to-date anti-virus – and remember that you protection is only as good as your latest update, whenever that may have been – and also, and this is my advice, run other good protection software such as PC Tools ThreatFire and such like.

None of such protection has to cost you anything as for the private personal user you can get most of the stuff free. So there is no excuse not to have a fully protected PC or Laptop.

One note, on the side: those worms and Trojans and viruses are dangerous and some more dangerous than others; Koobface worm is very dangerous but not because, as some people might believe, it destroys hard drives or such – those viruses are (mostly) gone nowadays – but because it is a piece of code that ultimately turns the infected PC into a zombie on a botnet.

© M Smith (Veshengro), 2009
<>

November 24 could be 'Black Monday' for computer viruses

by Michael Smith

The Internet security company PC Tools has warned that next Monday could be the worst day of the year for computer attacks.

The spread of viruses and malicious software is expected to peak on Novem 24, along with attempts by hackers to seize control of computers, according to PC Tools.

PC Tools, by the way, is the “maker” of ThreatFire, amongst other items of software, and ThreatFire, which I have reviewed in the pages of this journal and used for a considerable time by now, I am certain, has done the bulk of work in preventing my system, while other have been infected, from staying free of problems.

The company has analysed information on more than 500,000 computers worldwide, and looked at data from the same period last year, which appears to suggest the Monday before Thanksgiving in the US is a prime time for security attacks.

PC Tools believes that this could probably be because of the increased online activity at this time of the year, as people starting shopping online for Holiday gifts, and for details of bargains they might be able to pick up on Black Friday, the day after Thanksgiving, when many US stores hold huge sales.

Online shoppers are a tempting target for hackers and fraudsters, many of whom will try and trick consumers into clicking links in emails and websites that will download software onto their computers that allows malicious attackers to take remote control of the system and/or to gain control of their passwords and other sensitive information.

With such software on board hackers will then be able to log keystrokes in order to access banking login details and passwords for online shopping sites, and more dangerously even, credit card numbers, PayPal account details and such like.

Web users must be especially vigilant in the run-up to the Holidays and they really must keep their wits about them. While in the real world they would shield their PIN for their Credit or Debit cards they must do similar things as regards to protecting their online identity and credentials.

People who plan to do their gift shopping on the Internet should ensure their anti-virus software and firewall security is up to date, that they don't open emails and files from unfamiliar people, and that they ensure they only enter credit or debit card information on secure web pages.

Secure web pages are denoted by the appearance of a padlock symbol somewhere around the border of the webpage or in the address bar, and the "http://" prefix for the website changing to "https://" to show it is a secure link.

As to opening emails let me add that even emails that are sent from friends may not actually be from them. Their details could have been cloned in the same way as your own details can be cloned – even my own. So let the user beware and if in doubt contact the sender of an email, if he is a known associate, as to whether he or she has, in fact sent you and email with this or that title. If so then it is, more than likely, safe to open.

I have received emails even from my own email addresses – supposedly – that never were from my own addresses. However, the address had been cloned and could have, maybe, confused people.

So, as I always say; let's be careful out there.

© M Smith (Veshengro), November 2008
<>

Most web malware found on legitimate websites

by Michael Smith (Veshengro)

More than two thirds of web-based malware is now found on legitimate web sites, according to a report by security supplier Scansafe. This represents an increase of 407% in comparison with May of last year, that is to say May 2007.

According to a senior security researcher at Scansafe hackers have moved away from direct attacks like social engineering to focus on indirect attacks that use trusted brand names.

Just because you are accessing a well-known site you definitely and absolutely cannot and should not assume that that site if safe. At this presently moment thousands of legitimate web sites are being compromised on a daily basis.

According to the report there has also been a 220% increase in the different kinds of web-based malware in the past year.

According to Scansafe authentication-bypass and password stealing malware has grown the fastest with an 855% increase, which puts sensitive corporate data at serious risk.

Since October last year there have been hundreds of thousands of mainly China-based attacks, in which hackers passed malicious code to visitors on completely legitimate websites.

The computers of visitors to those sites are infected when they are redirected to malicious servers using a code injection method based on the database query language SQL.

A number of legitimate websites have thus been attacked in the USA and the United Kingdom, amongst them the Wal-Mart's website in the USA, as well as the websites of the Royal Statistical Society, National Media Museum, Skills for Care, and a number of businesses in the UK.

Unlike in the past, so it would appear, a much larger number malicious networks and servers were used in those recent attacks. Whether this means that the attacker or attackers has or have changed tactics or whether we are seeing a copycat is still not clear at this moment, it would seem.

The one thing this might point to though is a government sponsored attack, maybe. Rumor has it, though that is rumor from serious professionals, that many of the attacks from China are in fact coming from security services and military in that country. Maybe we are seeing an attempt to find out weaknesses in the systems in order to attack much more sensitive places next.

© M Smith (Veshengro), June 2008

Variant of blackmailing virus spreading on Internet

Another blackmailing virus. Oh, how lovely - NOT

by Michael Smith (Veshengro)

Security software firm Kaspersky Lab has reported a new and dangerous blackmailing virus and is alerting computer users everywhere about a new variant of Gpcode, a dangerous encryptor virus.

The Virus.Win32.Gpcode.ak malware encrypts users' files with various extensions, including .doc, .txt, .pdf, .xls, .jpg, .png, .cpp, .h and more, using an RSA encryption algorithm with a 1024-bit key, and that is a lot.

Kaspersky Lab itself added a virus signature to block Virus.Win32.Gpcode.ak in early June 2008.

Kaspersky Lab says it has succeeded in thwarting previous variants of Gpcode by cracking the private key held by the attackers.

However, the author of the new Gpcode variant has taken two years to improve the virus and previous errors have been fixed and the key has been lengthened to 1024 bits instead of the original 660, which was crackable.

So far, it would appear that Kaspersky have been unable to decrypt files encrypted by Gpcode.ak since the key is 1024 bits long and so far no errors have been found in the implementation. That means, according to Kaspersky, the only way to decrypt the encrypted files, presently, is to use the private key which, unfortunately, only the author of that virus has.

After Gpcode.ak encrypts files on the victim's machine, it changes the extension of these files to ._CRYPT, and places a text file named !_READ_ME_!.txt in the same folder.

In the text file the criminal tells the victims that the file has been encrypted and offers to sell them a decryptor: "Your files are encrypted with RSA-1024 algorithm. To recovery your files you need to buy our decryptor. To buy decrypting tool contact us at: ********@yahoo.com"

Kaspersky Lab is still working on a way to recover data that has been encrypted without having to use the criminal's decryptor. Let's hope that they will do so and in addition to that that those criminals get caught.

In addition to that, what can one do? Even the best anti-virus software is and will be always one step behind the virus writers and criminals.

While personal vigilance as to where one goes and what email one opens is important, and more often than not it is the bad email protocol of users that bring them those lovely viruses and Trojans. However, Trojans sometimes come packaged in different ways even where the user would not suspect them to be.

See my article “Viruses and Trojans in Trusted Downloads” on how easy it is to have such things reach your computer.

© M Smith (Veshengro), June 2008

Viruses and Trojans in Trusted Downloads

by Michael Smith (Veshengro)

Recently – though I never gave it a thought before and I did not have any anti-virus program check it – Bitdefender v10 FREE found in an ISO image help on my external hard drive a Trojan.

The ISO was for the OPEN CD 7.04 (both ISO and cut CD have now been destroyed) and came via a direct download from the official website.

This could only mean one of two things, I believe, and that is that either there is, or has been, at time of my download, infection on the site or two that there is a Trojan, according to BitDefender, embedded in the CD, in one of the programs.

Although few of us will ever think this necessary I would suggest – and I shall be one to follow my own advice this time for a change – that everyone always save any download to desktop and then check anything for hidden dangers and pitfalls prior to actually installing anything on the PC. Anything that cannot be saved to disk but wants to force install should be considered suspect, even if from a supposedly reputable source, and left well alone.

I am glad to say that I never actually installed anything from that particular OPEN CD – though I love OPEN CD in general – and therefore never actually had the Trojan let loose on my system.

Let the user beware!

© M Smith (Veshengro), June 2008

Users' Bad Habits Invite Malware

Some estimates suggest spyware problems in the U.S. are decreasing, but writers of all kinds of malware are prevailing – partly because of computer user behavior, antispyware experts have stated.

Computer users far too often run outdated antivirus software, operating systems and browsers that have not been updated or patched since time immemorial because they're scared of change, said Janie "CalamityJane" Whitty, administrator of security software vendor Lavasoft's online support forums.

Whitty sees people running a 2003 version of antivirus software, she said during an Anti-Spyware Coalition conference in Washington, D.C. "The nature of malware has changed since 2003," she added.

In addition to problems caused by users, there's a healthy underground market for the kinds of data compromised by spyware and other malware, said Stefan Savage, director of the Collaborative Center for Internet Epidemiology and Defenses at the University of California in San Diego. The center monitored a popular malware-trading IRC forum for about six months in 2006 and found the advertised value of compromised bank accounts offered there was US$54 million.

While some estimates show the spyware problem shrinking, U.S. companies and consumers are losing the battle against malware in general, Savage said. Antivirus vendors, in unguarded moments, will say they're able to catch less and less malware as criminals become more sophisticated, he said.

The chances of an Internet fraudster getting caught are "virtually zero," he added.

"By any objective measure... this is something we end up losing on," Savage said. "The more money these guys make, the more money they can invest to get better."

The panel on consumer behavior kicked off a day-long session on fighting spyware, during which many experts said they continue to have major concerns about spyware and other malware. Those concerns remain despite Consumer Reports' annual estimate of spyware that suggests the problem is declining. The magazine estimated that 850,000 U.S. households had to replace computers in the first half of 2007, with the cost of fighting spyware at $1.7 billion for the year. In 2006, spyware cost U.S. individuals and businesses an estimated $2.6 billion, the magazine said.

Part of the problem is that people hang on to outdated operating systems and browsers, even though newer ones have better security controls, because they don't want to learn how to operate the new software, Whitty said. "The malware changes," she said. "If we don't change with it, they're going to win."

Computer users seem to be of two minds when it comes to giving up personal information, added Susannah Fox, associate director at the Pew Internet and American Life Project, a research organization. Many young computer users will refuse to disclose personal information to e-commerce sites, she said. "But yet this is the same group that is putting their whole lives" on social-networking sites, she said. One private detective has told Fox that social-networking sites make it significantly easier to track down details about people, Fox said.

No one hast to have outdated antivirus and anti-spyware and anti-malware software. There are great programs out there to be had for FREE that will do the job properly and often better than the paid-for bits of software and on the other hand there are also operating systems out there available for free that are not even susceptible to any such threats. However, for the Windows PC user rather than the Linux PC user antivirus and other protection software, as well as all the patches, is a must and programs like AVG from Grisoft.com will give great anti-virus protection for FREE, and then there is Spyware Search & Distroy, Spyware Blaster, and AdAware. All are free to the home user. All people must do is (1) download and install then, (2) regularly, ideally daily, update them and (3) run regular checks.

A protected Windows PC is a happy PC. Otherwise get a Linux PC; that is an even happier PC.

Michael Smith (Veshengro), February 2008

Employees' USB sticks 'could risk security'

Workers who bring USB sticks and iPods into their place work and connect them to its computer system are a potential threat to their own organisations, according to information security solutions firm Kaspersky.

David Emm, senior technology consultant at the company, explains that employees are not experts in this field and as such they may not be fully aware of the risks.

Giving small business technology advice, he states that if and when workers bring USB sticks and iPods into work they should scan the peripherals before they integrate them into the computer system.

This allows a "layer of confidence" to be established in the firm, Mr Emm adds.

"It's really a question of giving sensible advice to your staff," he concludes.

Meanwhile, research by Websense suggests that 90 per cent of businesses have suffered a hacker attack in the last 12 months and 45 per cent have had their IT systems infected by a computer virus.