Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Tuesday, May 3, 2011

Bin Laden's death leads to surge in cybercrimes, Internet scams

Security experts are warning Web-surfing consumers about a rise in cybercrime and scams related to Osama bin Laden's death.

Major news events are often accompanied by an uptick in cybercrime, as perpetrators seek to take advantage of Web searches for content such as pictures and videos.

"I suppose this was just inevitable," Dave Marcus, director of security research for McAfee Labs, wrote in a blog post. "The reported death of Osama Bin Laden is just too good a lure for cybercriminals and scammers to pass up."

Marcus said e-mails are circulating with links purporting to lead to photos of bin Laden's corpse. One message teases to a video showing bin Laden disproving his death by holding a newspaper with Monday's date. Clicking on the links generally opens files that install malware on the user's computer. In other cases, cybercriminals have poisoned Google Images results.

Facebook is also a fertile breeding ground for these scams, with malicious links being circulated on posts and messages within the social networking site. Researchers at Kaspersky Labs said they noticed scam ads on Facebook promising free merchandise in celebration of bin Laden's death. Users that click on the ads will be redirected multiple times, with each layer asking for more detailed personal information, Kaspersky Labs said.

Experts at Websense said cybercriminals compromised the website of Sohaib Athar, the Pakistani information technology consultant living in Abbottabad who provided a real-time account of the U.S. operation via his Twitter feed. In a blog post, Websense said a malicious code was embedded into the site that installs malware on a computer. The malware installs fake software that looks like a security tool, and prompts users to enter their credit card information to purchase a premium version of this software.

Security experts said consumers should be careful searching for information on the Web, visiting only websites of credible news sources, and be wary of links in e-mails. Making sure anti-virus and firewall software is updated is also helpful, as these kinds of attacks are increasingly common.

"We believe the hackers laid the criminal groundwork in advance, waiting for the right news trigger," said Rony Moshkovich, malware researcher at PC Tools.

Source: http://www.chicagobreakingnews.com/news/local/chibrkbus-bin-ladens-death-leads-to-surge-in-cybercrimes-internet-scams-20110503,0,101828.story

Tuesday, March 31, 2009

Last-minute Conficker survival guide

Tomorrow -- April 1 -- is D-Day for Conficker, as whatever nasty payload it's packing is currently set to activate. What happens come midnight is a mystery: Will it turn the millions of infected computers into spam-sending zombie robots? Or will it start capturing everything you type -- passwords, credit card numbers, etc. -- and send that information back to its masters?

No one knows, but we'll probably find out soon.

Or not. As Slate notes, Conficker is scheduled to go "live" on April 1, but whoever's controlling it could choose not to wreak havoc but instead do absolutely nothing, waiting for a time when there's less heat. They can do this because the way Conficker is designed is extremely clever: Rather than containing a list of specific, static instructions, Conficker reaches out to the web to receive updated marching orders via a huge list of websites it creates. Conficker.C -- the latest bad boy -- will start checking 50,000 different semi-randomly-generated sites a day looking for instructions, so there's no way to shut down all of them. If just one of those sites goes live with legitimate instructions, Conficker keeps on trucking.

Conficker's a nasty little worm that takes serious efforts to bypass your security defenses, but you aren't without some tools in your arsenal to protect yourself.

Your first step should be the tools you already have: Windows Update, to make sure your computer is fully patched, and your current antivirus software, to make sure anything that slips through the cracks is caught.

But if Conficker's already on your machine, it may bypass certain subsystems and updating Windows and your antivirus at this point may not work. If you are worried about anything being amiss -- try booting into Safe Mode, which Conficker prevents, to check -- you should run a specialized tool to get rid of Conficker.

Microsoft offers a web-based scanner (note that some users have reported it crashed their machines; I had no trouble with it), so you might try one of these downloadable options instead: Symantec's Conficker (aka Downadup) tool, Trend Micro's Cleanup Engine, or Malwarebytes. Conficker may prevent your machine from accessing any of these websites, so you may have to download these tools from a known non-infected computer if you need them. Follow the instructions given on each site to run them successfully. (Also note: None of these tools should harm your computer if you don't have Conficker.)

As a final safety note, all users -- whether they're worried about an infection or know for sure they're clean -- are also wise to make a full data backup today.

What won't work? Turning your PC off tonight and back on on April 2 will not protect you from the worm (sorry to the dozens of people who wrote me asking if this would do the trick). Temporarily disconnecting your computer from the web won't help if the malware is already on your machine -- it will simply activate once you connect again. Changing the date on your PC will likely have no helpful effect, either. And yes, Macs are immune this time out. Follow the above instructions to detect and remove the worm.

Source: http://tech.yahoo.com/blogs/null/132464

Wednesday, January 21, 2009

Downandup/Conficker worm infects 9 million PCs

Judging from the complaints and questions filling my inbox, Windows security looks like it's already on track for its worst year this decade. The latest attack is a worm called Downandup, Downadup, Kido!, or Conficker (all the same thing), and it primarily seems to be being delivered via infected USB drives.


How's it work? By tricking you into running the virus by modifying the way "autorun" works when you plug in a drive. Look closely at the screenshot above and you'll see two entries for "Open folder to view files." The one at the top is a phony entry that actually installs the virus on your machine... but of course it's the default selection that pops up when you plug in a drive. Once installed, the virus spreads like crazy via a separate flaw in Windows networking system (now patched, so be sure to run Windows Update if you haven't lately) and can quickly infect a whole office. F-Secure has more analysis on the clever way it tricks you into installing the malware yourself.

How bad has it gotten? Estimates range from 3.5 million infected in the first four days after it bean spreading to 9 million impacted... and gettng worse. By now I figure the numbers could top 15 or 20 million.

From an antivirus standpoint, fixing Downandup isn't easy. The worm is particularly problematic because of the tricky way it involves the user in installing the software, bypassing auto-installation safeguards, plus its sophisticated way of avoiding detection, as it morphs its code constantly (using randomized elements) to make traditional, signature-based detection almost impossible.

Your best strategy for avoiding Downandup? Turn off AutoPlay/AutoRun on your computer (with Windows XP, TweakUI is the easiest way to do it). If you do see an AutoPlay dialog box like the one above, just close it and eject the disc or thumbdrive; browsing the drive manually for individual files should keep you uninfected, but you're best off not using the drive at all. And of course, make sure your system is fully patched via Windows Update.

What if you already have Downandup infecting your machine? Try your standard antivirus utility as a fix. If that doesn't work, F-Secure has a removal tool that should get rid of it. Good luck out there.

Source: http://tech.yahoo.com/blogs/null/116396