Showing posts with label anti malware. Show all posts
Showing posts with label anti malware. Show all posts

Friday, June 6, 2014

A Big Problem: Cryptolocker the Ransomware


Cryptolocker is back in the headlines, thanks to a coordinated effort to take down the computers and criminals that run the notorious "ransomware". But what is it? And how can you fight it?

Cryptolocker is ransomware: malicious software which holds your files to ransom

The software is typically spread through infected attachments to emails, or as a secondary infection on computers which are already affected by viruses which offer a back door for further attacks.
When a computer is infected, it contacts a central server for the information it needs to activate, and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message asking for payment to decrypt the files – and threatens to destroy the information if it doesn't get paid.

The authorities have won users a two-week window of safety
The National Crime Agency (NCA) announced yesterday that the UK public has got a "unique, two-week opportunity to rid and safeguard" themselves from Cryptolocker. The agency didn't go into more detail, but it seems likely that at least one of the central servers which Cryptolocker speaks to before encrypting files has been taken down.
The NCA has also taken down the control system for a related piece of software, known as GameOver Zeus, which provides criminals with a backdoor into users' computers. That back door is one of the ways a computer can be infected with Cryptolocker in the first place.
What that means is, until the window is closed – and the virus cycles to new servers – users who are infected with Cryptolocker won't lose their files to encryption. As a result, these users have the chance to remove the virus before it destroys data, using conventional anti-virus software. In other words, there has never been a better time to update the protection on your computer. 
But watch out – while the servers that control Cryptolocker are out of action, it's possible to be infected with it and not know. If you don't keep your computer clean, then at the end of the two-week period, you could be in for a nasty surprise.

Cryptolocker only infects PCs, but there are other types of ransomware
Cryptolocker is the name of one particular virus, which only infects Windows PCs, running XP, Vista, Windows 7 or Windows 8. So if you use an Apple computer, it can't affect you. Similarly, smartphones are safe from cryptolocker. 
Although it is the most famous example of ransomware, it's not the only one. Even in the two-week window, PC users may be infected with other types of ransomware, and Android and Mac OS users should carry on with their normal security precautions. Being safe from one type of malware doesn't mean you're safe from all of them.

If you've been infected by Cryptolocker, your files really are gone unless you have a backup
 
Some ransomware is little more than a confidence trickster, presenting a message asking for payment without having done anything to the user's files. Cryptolocker isn't like that: the software really does encrypt your files, to a strength which renders it unbreakable even by the fastest computers in the world – even if they had the entire lifetime of the universe to work on it.
 
That means you'll have to rely on any backups of your data to get it back. But it's important that you don't try and restore your data before you clear your computer of the infection, otherwise you could lose your backup, too.

Sometimes paying the ransom will work, sometimes it won't
Except, of course, there is another possibility. Some users hit with Cryptolocker report that they really did get their data back after paying the ransom – which is typically around £300. But there's no guarantee it will work, because cybercriminals aren't exactly the most trustworthy group of people. 
What's more, if the NCA really is bringing down the command and control servers, then the criminals may not be able to return the data, even if the ransom has been paid. There's also a whole load of viruses which go out of their way to look like Cryptolocker, and which won't hand back the data if victims pay. Plus, there's the ethical issue: paying the ransom funds more crime.

This article was originally posted on:

Wednesday, December 26, 2012

Scareware - Yes it is that Scary

Scareware aka smitfraud or rogue security software, is a type of software that is defined as malware. These types of malware not only try to disrupt your computer, but also try to trick you into conducting a transaction with your credit card.

These types of malware appear to users in the form of pop-ups that resemble Windows system messages, usually masquerading as an antivirus or antispyware software, a firewall application or a registry cleaner. 
The message displayed by this malware informs the user that the PC in use is in trouble and contains many security issues and a large number of virus infections.  The Popup claims that the software it is marketing will be able to remove all the infections, speed up your PC and optimize its performance.

Naive enough some people do fall for this lame trick, and they follow the pop-up instructions and submit their personal data along with credit card number to buy this rogue software that pretends to save their PCs.
These scareware are well known for their ability to lock or limit the usage of control panel, disable registry editor, and prevent the user from visiting legitimate valid antivirus websites.

Some of the scareware I have encountered and seen on different systems are: Antivirus 2007, 2008 and 2009, XP Antivirus 2010, WinFixer, DriveCleaner, and Malware Cleaner.

If you face a suspicious pop-up, you should carefully close it by right-clicking on the item in the task bar and select "Close" or by manually exit the browser by using the task manager (Ctrl-Alt-Delete). To protect your system from future attempts, install a good pop-up blocker and configure it to prevent pop-ups from sites that you haven’t allowed.

Don’t automatically click download when prompted, don’t follow suspicious links even if received from your known friends (they might be infected and unknowingly spreading the infection).

Keep all your software applications up to date, that includes: Java, Adobe Reader, Flash Player, Windows and certainly your Antivirus.
Remember: Scammers and Hackers will keep on finding new technical and non technical means to exploit systems and PCs. It is your job to avoid their traps.

Thursday, August 30, 2012

Watch out for the Facebook Scam!


Many Facebook users receive notifications by email when they are tagged in pictures, or if someone had written something on their wall and so on. This is not a really a good idea because of a newly discovered malware by the security firm "Sophos". Why isn't it a good idea? Basically, because this malware sends a fake email notification masquerading "Facebook Notification Emails" informing you that "one of your friends has tagged you in a picture". Once you click on the link provided in the email, a file that is able to infect your Windows-operated computer will be downloaded automatically, allowing hackers to gain control and access to your PC. 

This is how the email looks like:

How identify this Malware?
Usually, when Facebook sends you an email notification, it identifies the user that tagged you in a photo, wrote on your wall or sent you a message by displaying the Name or Alias. Notice that in the above picture, this email does not specify who tagged you, it just states that "one of your friends". So whenever you see "one of your friends" in the email notifications, do not open that email, just delete it and mark it as junk mail.

Another way to protect yourself from this scam is to stop email notifications in general. Who wants a bulk of email notifications in their inbox? It just causes your inbox to be congested and that will discourage you from checking your email more often. I advice you to stop these email notifications. So whenever you receive an email notification from Facebook, it will probably be a scam since you already stopped all email notifications. You can always check your Facebook notifications on the Facebook site itself. It is simple, easy and most importantly safe.

Always remember to keep your antivirus up to date, that will also help in identifying new malware.

Thursday, August 2, 2012

Software Updates, why should I bother?


Why Update
Usually Software updates are released for four reasons:
  1. Patch a security vulnerability; 
  2. Fix bugs;
  3. Add new features;
  4. Pure marketing purposes.
Staying away from the fourth reason, I believe that the most important aspect to apply a software update is to patch security vulnerabilities. Hackers do exploit these security vulnerabilities in order to gain access to your workstation and ultimately compromise your confidential data (passwords, emails, bank accounts).
Usually, when any software is being created it goes through series of phases within its development life cycle (SDLC). Two important parts of this life cycle are quality assurance and user acceptance testing. Yet the best testing any software could get is the Wild Testing.
Wild testing is done when vendors release their software un-officially (leaks, test or evaluation versions) to be tested and reviewed by enthusiastic users.
When these users submit their feedback directly to the vendor or share their experience using social networking media such as Facebook and twitter or even write a detailed review on Cnet they are able to draw the software vendor / developer attention. The developer consequently fixes the problems reported. And therefore a bug free update is released.
Sometimes, the term software update is used instead of software upgrade, this happens when the developer company releases a new version of their software with added features that is didn’t exist in the previous release.  
Most software nowadays, given the proper permission from their operator, has the ability to periodically and automatically check for updates. Moreover you as an operator can configure this software to download and install updated seamlessly and on recurrent basis, without any further more intervention from your part.

Four Software updates that shouldn’t be missed:

1. Operating Systems
Operating systems provide a software platform on top of which other programs, called application programs, can run, examples of operating systems include windows 7, windows XP, ubentu, fedora, snow leopard, Lion, and most recently mountain lion released by apple a week ago.
Vulnerabilities are discovered within an operating system on daily basis, the vendor of that operating system tries to mitigate these vulnerabilities by releasing patches. Since these patches should be able to save the day, you should install updates as soon as you see a prompt to do so, or set the computer to install them automatically.

2. Web Browsers and Supporting Software
Since the internet service and browsing experience is always evolving the ability to keep your data secure becomes a greater challenge. Microsoft’s Internet Explorer and Apple ‘s Safari are updated the same way an operating system is updated, while Google’s Chrome and Mozilla Firefox are updated automatically. 
For an ultimate user experience, web browsers need supporting packages like Adobe Flash, Adobe Reader, Sun Java and Microsoft Silverlight. And therefore due to their popularity, they are often the target of malicious attackers. It is extremely essential to update these type of software as soon as you see an alert.

3. End User Applications
Every now and then applications downloaded from the internet inform their user than a newer software update is released and ready to be downloaded and installed. These software updates are there either to fix bugs within the application or to offer brand new feature: perhaps a new graphical user interface or even better processing speed. Keep in mind that although these updates may not be mandatory, but sometimes these updates fix undisclosed security vulnerabilities within the application. So whenever an application prompts you for an update. Go ahead and do it.


4. Anti-Virus/Anti-Malware Software
New threats are introduced to the information technology field every day. And so, in order immune your PC against these threats you should keep your Anti-Virus/Anti-Malware updated. Usually these protection software update themselves seamlessly without any user intervention. 





Finally, keeping all the software installed on your PC updated can sometimes be hectic, but if you consider the risks you are mitigating, it is definitely worth the hassle