Showing posts with label anti virus. Show all posts
Showing posts with label anti virus. Show all posts

Friday, June 6, 2014

A Big Problem: Cryptolocker the Ransomware


Cryptolocker is back in the headlines, thanks to a coordinated effort to take down the computers and criminals that run the notorious "ransomware". But what is it? And how can you fight it?

Cryptolocker is ransomware: malicious software which holds your files to ransom

The software is typically spread through infected attachments to emails, or as a secondary infection on computers which are already affected by viruses which offer a back door for further attacks.
When a computer is infected, it contacts a central server for the information it needs to activate, and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message asking for payment to decrypt the files – and threatens to destroy the information if it doesn't get paid.

The authorities have won users a two-week window of safety
The National Crime Agency (NCA) announced yesterday that the UK public has got a "unique, two-week opportunity to rid and safeguard" themselves from Cryptolocker. The agency didn't go into more detail, but it seems likely that at least one of the central servers which Cryptolocker speaks to before encrypting files has been taken down.
The NCA has also taken down the control system for a related piece of software, known as GameOver Zeus, which provides criminals with a backdoor into users' computers. That back door is one of the ways a computer can be infected with Cryptolocker in the first place.
What that means is, until the window is closed – and the virus cycles to new servers – users who are infected with Cryptolocker won't lose their files to encryption. As a result, these users have the chance to remove the virus before it destroys data, using conventional anti-virus software. In other words, there has never been a better time to update the protection on your computer. 
But watch out – while the servers that control Cryptolocker are out of action, it's possible to be infected with it and not know. If you don't keep your computer clean, then at the end of the two-week period, you could be in for a nasty surprise.

Cryptolocker only infects PCs, but there are other types of ransomware
Cryptolocker is the name of one particular virus, which only infects Windows PCs, running XP, Vista, Windows 7 or Windows 8. So if you use an Apple computer, it can't affect you. Similarly, smartphones are safe from cryptolocker. 
Although it is the most famous example of ransomware, it's not the only one. Even in the two-week window, PC users may be infected with other types of ransomware, and Android and Mac OS users should carry on with their normal security precautions. Being safe from one type of malware doesn't mean you're safe from all of them.

If you've been infected by Cryptolocker, your files really are gone unless you have a backup
 
Some ransomware is little more than a confidence trickster, presenting a message asking for payment without having done anything to the user's files. Cryptolocker isn't like that: the software really does encrypt your files, to a strength which renders it unbreakable even by the fastest computers in the world – even if they had the entire lifetime of the universe to work on it.
 
That means you'll have to rely on any backups of your data to get it back. But it's important that you don't try and restore your data before you clear your computer of the infection, otherwise you could lose your backup, too.

Sometimes paying the ransom will work, sometimes it won't
Except, of course, there is another possibility. Some users hit with Cryptolocker report that they really did get their data back after paying the ransom – which is typically around £300. But there's no guarantee it will work, because cybercriminals aren't exactly the most trustworthy group of people. 
What's more, if the NCA really is bringing down the command and control servers, then the criminals may not be able to return the data, even if the ransom has been paid. There's also a whole load of viruses which go out of their way to look like Cryptolocker, and which won't hand back the data if victims pay. Plus, there's the ethical issue: paying the ransom funds more crime.

This article was originally posted on:

Saturday, January 14, 2012

Internet Security Threats: Anti-Malware

Many of my friends ask me: which antivirus should I choose? What is the name of best antivirus? Shall I pay for an antivirus or use a free one? Is this particular antivirus going to slow the performance of my pc? Is it necessary that I update my antivirus program each day?
Too many questions, with no correct answer!
Have you ever asked yourself how does the Antivirus software detect and catch Viruses?


Anti-Malware
Anti-Malware software or as people call it Antivirus Program (AVP) is a protective software designed to prevent, detect, and remove MALWARE. There are two methods to detect viruses: specific and generic.

Specific Detection Method:
In the specific (traditional) method detection, the antivirus is required to have some predefined information about some viruses (virus database). Only then, the AVP searches the scanned files for the presence of certain strings and known patterns of data similar to the ones it has in its database. If there is a match then a virus is found. (This type of scanning is called: Signature Based Scanning)
Suppose a new virus is born, in older days there was an average delay of 14 days before vendors were able to update their database with a new virus signature to be able to detect and clean the new virus. Nowadays because vendors have introduced the "File Submission Process" where people allow their AVP to submit suspicious files to vendors for further analysis, it takes a maximum of 2 days for virus database signatures update to cover this new virus.
That is why updating the antivirus definitions is very crucial In order to decrease the chances of getting a malware infection. However, it is possible for a computer to be infected with new malware for which no signature is yet developed.

Generic Detection Method:
Generic detection method is based on the standard and common characteristics of the virus, so theoretically they are able to detect all viruses, including the new and unknown ones. And since it doesn't depend on previous knowledge of the virus signatures, it requires no signature update. Examples of this method include: Heuristic Based Scan, Artificial Intelligence (Behavioral Antivirus Programs), Threat Sense Technology,

In generic detection method the AVP searches instructions or commands within a file that are not found in typical good application programs. As a result, a heuristic engine is able to detect potentially malicious files and report them as viruses.


When a file is being analyzed by an AVP that uses generic detection method, a flag is created for each suspected ability (Suspicious file access, Suspicious Memory Allocation, Memory resident code, Wrong name extension, Disk write access, Contains a routine to search for executable, Incorrect timestamp etc….) The more flags that are triggered by a file, the more likely it is that the file is infected by a virus.

The only problem with scanners that use this method is that they sometimes blame innocent programs for being contaminated by a virus. This is called a "False Positive" or "False Alarm". For example, a legitimate Disk Format Utility is flagged by a generic "Heuristic Based Scan" as having: Memory Resident Codes, Disk Write Access, Overwriting Abilities, and thus your AVP screams: VIRUS!

The Cleaning Process:
The Virus is a program by itself, this program adds itself to the programs it aims to infect, so as a result the size of the infected program increases duo to the addition of the viral code. When the program is executed, the viral code is also executed and the infection continues to grow. (while infecting a new file some of the original file bytes are overwritten by bytes from the virus code itself, but these old bytes are stored within the virus code since the virus have to keep the original file executable).
In the cleaning process the AVP cleaner searches for the original file bytes from within the viral code and returns them to its original location, removes the viral code, and then truncates the file to it's original size. That being said: To clean an infected file, the AVP whether using the Specific or the Generic detection method has to know the virus in order to remove it. If the AVP removes bytes that should not be removed, the integrity of the file will be lost, and it the file might function incorrectly or even stops functioning at all.

In conclusion, there is nothing such as the Best Antivirus; the good AVP is one that uses the generic detection method along with a signature base scanner. You are to chose what suites your needs, and always keep in mind that utilizing an AVP and keeping it updated is the best way of decreasing and not eliminating the chances of getting a malware infection.
My next post will address wireless routers: Security and safety measures.