Tuesday, June 10, 2008

Top Ten excuses why people don't want to secure their computer


1. I don't have anything valuable on my computer anyway, so I don't need to worry about someone taking it over.

Actually, you have something very valuable on your computer, especially if you are on a fast internet connection. You have bandwidth. A lot of malware is designed to take over your computer and use it as a server to attack other computer, distribute SPAM or even deliver more malware. It will also steal your data, passwords and account numbers, so the criminals can steal your identity and everything you own. Even if you only use your computer for gaming, there are people now stealing passwords for some computer games so they can steal any reserves you have built up online.

2. The antivirus companies are the ones who put out all those viruses so they can sell their programs anyway. If I install their program, it will install their viruses.


This is mostly one of the silliest myths on the web. It is true that there are rogues that try to trick people into buying their programs by claiming your computer is infected:

List of Rogue Programs

However, the legit companies wouldn't even consider risking their reputations to make a few extra dollars. If they are recommended by reputable sources, they are going to be safe and useful. You need to be sure the source is reputable though. The people that create viruses and other malware are criminals and many are now part of organized crime gangs that make millions by stealing from people like you.

3. Running a firewall slows down my games.

Most firewalls have settings to allow you to play games without removing that protection. Even a few minutes online without your firewall can leave you infected.

4. The programs are too complicated.

Most programs have simple modes that can be set to update automatically and protect you without you having to do much more than renew a subscription or download a major update about once a year.

5. I don't have any money and the programs are all expensive.

You can assemble a very effective set of security programs for free. Even if you pay a bit for a program, it is a lot less than what you will pay to get your computer fixed and possibly deal with having your accounts cleared out by criminals.

6. I have heard that WinXP Service Pack 2 and 3 will cause problems on computers and I don't want to risk it.

That is sort of like saying I will jump off of the cliff because I don't want to risk slipping on the rocks climbing down. SP2 is probably the most important security update that MicroSoft has released for any version of Windows to date. It is true that it caused problems in the first few months, but it has been out for more than 2 years and it is quite stable now. If you don't have it, you also don't have any number of other security updates and you are almost certain to get infected.

7. I have an illegal copy of WinXP and MS won't let me update it. It isn't fair because they make so much money anyway.

If you are running an illegal copy of Windows, do the rest of us a favor - buy a legal copy. When you get infected, you can become a zombie server for the criminals, distributing malware, SPAM and scams all over the web. If all the zombie systems were shut down today, the quantity of SPAM would slow from a tidal wave to a trickle. Don't contribute to the flood. If you don't believe you can afford a legal copy of WinXP, use a free install of Linux. There is no good reason to put yourself and the rest of us at risk.

8. I have never used security programs and I have never been infected.

Maybe, maybe not. Some of the most effective infections today are essentially invisible on your computer. They don't slow it down in a noticeable way, they don't popup ads and they don't do anything to attract your attention. They do quietly send your personal information to the criminals, they do use your computer as a zombie server and they do own your computer more than you do. The truth is, malware is getting more aggressive, harder to detect, harder to kill and almost unavoidable if you go online at all. If you are not armored, you are probably already infected or you will be.

9. It is my computer and it is only my problem if I get infected, so leave me alone!

Well, not really. It is your computer and it is mainly your problem if you get infected. However, if your computer becomes a server that sprays malware, SPAM and attacks against the rest of us, it becomes our problem too. As soon as you go online, you are part of a community and the decisions you make effect everyone in that community. If you don't mind people messing around with your personal information and possibly using it to steal all that you have, please at least consider the harm you may be doing to the rest of us.

10. I plan to install security programs, I just haven't had time yet.

If you are reading this, you are already online. If you are online, you are already at risk. I once fixed a problem with my firewall and had it uninstalled for a while. I went online for about 10 minutes to download a fresh copy and while I was online, my system was infected with the Welchia worm. TEN minutes I was online, only 10 minutes!! How long have you been running without security??


Copied/pasted with permission - Credit goes to Budfred (SWI Admin) - original article. For more similar articles/news/tips, subscribe to the SWI Newsletter.

Sunday, June 8, 2008

Increase of malware found on legitimate websites

According to ScanSafe, 68% of the Malware is found on legitimate websites nowadays. These sites were hacked as a result of SQL injection attacks or via stolen FTP credentials.
Malicious scripts and (hidden) iframes are added in order to infect the visitor with trojans, backdoors and password-stealing malware.
That's why you should always be cautious, because even known legitimate sites can't be trusted anymore.

Also read: A May 2007 / May 2008 State of the Web Comparative

If you're on Vista, make sure UAC is enabled, so Internet Explorer runs under Protected Mode.
If you're on XP - you can read some tips here: How to Surf More Securely by gizmo.richards
In case you're using Firefox as your default browser, install the NoScript extension.

The Neverending Story


It's already more than 4 years that I clean severly infected computers.
In most of the cases, when I review the logs, I see more malware present than anything else.
Also, in most cases, many don't even have an Antivirus Scanner + Firewall installed and their Windows hasn't been updated for years.
Hence, they don't even know why the updates are needed for. Also, many of them don't have a genuine version of Windows installed anyway.
Some don't even know what an Antivirus Scanner or Firewall is.
For example, yesterday, I analysed a log from a severly infected computer and asked the guy why he didn't have an Antivirus and Firewall installed.

He: "Huh? I have an Antivirus and Firewall installed though"
Me: "Ok, can you tell me which one, because I can't see an Antivirus and Firewall present in your log"
He: "I have mailwasher!"

Mailwasher is a spam filter software - so not sure where he has read it was an Antivirus/Firewall.

And that's why we should "teach" these people about security. Why they need an Antivirus and Firewall and how to prevent malware. This is my main goal here... teach about prevention, how to keep their computer(s) clean/secure.

Unfortunately, many do know how to prevent malware, how to keep their computer(s) secure, but they just won't listen, mainly because they just don't care.
They also know how they got infected in the first place.. because they were warned many times before. But still, they just can't resist the use of illegal software/cracks/hacks whatever, even though they know that 80% of it is bundled with malware.
One single click on one of these "popular" crack sites may already download and install a huge malware bundle... and yes, they are also aware of this.
Oh well, not a big deal for them - They just post their problem at one of the forums/sites where they receive help for free. Once their system is "clean", they can hunt for more cracks/keygens again.
Yes! I've seen it too many times before.

"Hi, I visited a cracksite, downloaded and installed a crack - can you check if my computer is still clean?"
"Help! I downloaded and installed a crack from a torrent/P2P again and now my computer is acting weird.... again"
"I need help asap!! Keygen infected my computer again!"

Yes, in 80% of the cases, people get infected because of the use of illegal software/cracks/keygens/hacks... etc.
So I clean their computers and most important part, I tell them that they should stay away from illegal software, cracks, keygens etc, because they will get reinfected anyway if they don't change their surfing habits.
I also explain that there are many free alternatives and give them extra prevention tips.
I'm glad that many learn a lesson here, listen to my advise and make sure this won't happen again.

However, there are still a lot of others who don't listen and proceed with what they were doing before, even though they were warned.
Result.. 2 weeks later, they are back, asking for help to get rid of another infection, because they installed another crack which downloaded/installed malware again. Then they receive free help once again and one month later, they are back again. And this goes on and on and on...
I'm sorry, but I gave up on them. It's a waste of my time.
If they don't want to listen, they should take care of their own problems. In such cases, I recommend that they format and reinstall Windows (even though the malware can be cleaned easily).
Or I ask them to go to the local computer shop to get it fixed. It will cost them a lot of money and in most cases, they will just format and reinstall Windows anyway.
Maybe that will learn them since they have to pay for it - or since they have to start from scratch again.

"Was it really worth it??"
"Wanna use cracks/keygens again and go through the same scenario again?"
"Are you sure??"
- If there was an "Yes" button here, I'm sure some would click it - Ooh, they love to click Yes!

What I hear many times is:

"It's my computer - if I want to visit illegal sites/use cracks etc, it's my problem if I get infected."

Ok, so why are you asking for help in the first place? If it's your problem, you should take care of it.
And it isn't your problem ALONE. Your computer is responsible for infecting A LOT of other computers as well (depends on what malware is present).

"I blame my Antivirus because it didn't detect the malware".



You are the only one to blame!!!

Also, all their passwords and other sensitive data may be known... But do they really care???


Some will never learn, so this is a neverending story and unfortunately I can't help them anymore.
Oh well... maybe they will learn some day (when it's too late).

Monday, June 2, 2008

Virut is back again - sigh

Virut (PE_VIRUT.XZ in this case) is back again.

This one "spreads" via email with subject: "Important update from Microsoft Windows XP/2003 Professional Service Pack 2(KB946026)" or "Critical Security Update for Microsoft Windows (KB946026)".
From: Micrisoft Corporation 2008 ©
The link to the supposed WINDOWS-KB946026-X86-ENU download from Microsoft for the fix goes to this address:

URL=hxxp://xxxxx.net/upload/WINDOWS-KB946026-X86-ENU.EXE.exe



Note: This is NOT the legitimate download from Microsoft here. The legitimate WINDOWS-KB946026-x86-ENU.EXE does NOT have above "Windows icon", but has the default exe file icon instead.
The file from the link in the mail doesn't install any updates, but installs Virut, a polymorphic appending file infector.

This one attempts to infect any accessed .exe or .scr files by appending itself to the executable. It contains an IRC-based backdoor that provides unauthorized access to infected computers.

Luckily, since this is an older variant - most Antivirus Scanners *should detect and delete it immediately. That's why it's really important that your Antivirus Scanner is up to date!

In case you are someone who just loves to click links in mails - even though your Antivirus Scanner alerts you - or you have an Antivirus where the trial already expired for a couple of months - or don't even have an Antivirus installed... Well, I can assure you, you'll really regret it if you open/run the file. Mainly because this is a file infector which infects legitimate exe and scr files, so these files may not be deleted, but disinfected instead. And a common problem I see with Virut is that in some cases (some variants), it contains a bug in the code and as a result it may misinfect a proportion of executable files. And because of that, an Antivirus Scanner cannot disinfect it properly either > result > a corrupted file.

That's why, if I guide someone with Virut present and their Antivirus cannot properly disinfect it, then I recommend a format and reinstall. Unless the person knows what files are corrupted and knows how to replace them with a clean one. But then again, it's no guarantee that everything will work properly again and Virut is gone.
A format and reinstall in this case is still the fastest and especially the safest solution.

So once again, make sure your Antivirus is always up to date!

Source.

Google Alerts - You should try it!



I'm actually suprised that many people never heard of Google Alerts. I'm using this Google feature for a couple of weeks now and, for me, it's very useful!

I have used a lot of other programs in the past, such as Copernic Search, which uses several different searchengines, but Google is still my fav searchengine since others don't display as many results. So that's why I switched to Google Alerts instead. No more programs to install since it's an "online tool".
For the Google Alerts, you just have to enter your search term and create an alert for it. It then notifies you by e-mail with the new results.

It offers six types of alert searches: "News", "Blogs", "Web", "Comprehensive", "Video" and "Groups".
You can also specify if you want the email with the results "Daily", "Weekly" or "As it happens". The "As it happens" doesn't work - although, not for me. That's why I've set it to daily.

A nice extra feature would be a "website watcher" included in Google Alerts (this for pages that don't provide Atom or RSS feeds) - where you have to enter the URL of a website, specify a filter (what changes to ignore) and Google notifies you of the changes being made on that page since your last visit. I already use another program for that, but it would be nice if this feature is also included in Google Alerts.

Sunday, June 1, 2008

Woopra - new real-time Web tracking and analysis application



Most people who run a website or have a blog have a Web tracking and analysis application present. Always useful to see how much visitors your Website/Blog has, where your visitors come from, what posts are popular etc etc...

I used to have SiteMeter "installed" - but I replaced it with W3Counter since it has more options, statistics etc. However, there's still something I'm missing - until I found Woopra. It really has all the options/statistics I want! I'm sure you're going to like the several features it offers. You can run it from the desktop and it even includes Real Time notifications.

Anyway... for me, It looks pretty neat. :)

I signed up today and I'm currently waiting for my approval. This may take a while according to their blog.
So I can't tell yet what to expect - but I'll update this blogpost with my thoughts/view once woopra is up and running.
And if I like it - then I'll replace my current w3counter with it.

I love to test new "goodies" - so what's next? :)

Update
My blog was approved today (june 4), so Woopra is currently up and running.
I'm really impressed with all the options it contains. I even scared some visitors today with the chat feature :P (Don't worry, I won't use this feature often :D)
There are still some bugs present - but then again, this is also still a beta.
Can't wait for the final release. This is a keeper, that's for sure.

Wednesday, May 28, 2008

New Comments System installed

I previously had Haloscan installed as my Comments System, however, I've noticed that there were a lot of problems with Haloscan lately. Posts were lost, debug errors in the comments system, and other errors which caused my blog to crawl.

So, I decided to remove Haloscan.. and replaced it with Intense Debate instead.
It's a free service that provides more functionality and allows greater control of the comments.
It also automatically adjusts itself to the layout of your blog and there are a lot of extra settings and widgets you can use with it.
Thanks to this great tutorial, I could "install" it without any problems.

Too bad that removing Haloscan deleted all my previous comments - but oh well, there weren't that many comments posted anyway.

Tuesday, May 27, 2008

VIRUS ALERT! in clock and how to restore it

Most people recognise the words VIRUS ALERT! beside the System clock after being infected with one of the Zlob-Media Codec infections.



It's also displayed under the ProductID in your System Properties > General:



In the Registry, the following values are affected and replaced with VIRUS ALERT!

[HKEY_CURRENT_USER\Control Panel\International]
"sTimeFormat"="h:mm: VIRUS ALERT!"


Which explains the VIRUS ALERT! words in the clock.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion]
"ProductId"="VIRUS ALERT!"


Which explains the VIRUS ALERT! in the System Properties.

In both cases, on every computer, above default values are different, because for the clock settings, it depends what the Regional Settings are.
To restore the VIRUS ALERT! in the clock settings, Go to start > run and type: intl.cpl
Hit enter
This opens the Regional Settings properties.
Under the tab Regional Options > standards and formats, from the dropdown list, re-select your region again.

In my case it is set to English (United States), but in your case, it may be different ofcourse.
By default the correct region should already be displayed there, but you have to re-select it, or select another Region first and then select your Region again > click apply and OK. This will reset the default data in the Registry for the sTimeFormat, so the VIRUS ALERT! should be gone.
(in some cases, you need to log off in order to make the changes)
(Extra note: In case you're having problems with above instructions, see the latest part of this post how to restore the policies first.)

For the ProductID - this is somewhat more advanced since every ProductID is different.
You need to restore that value in the Registry again with your ProductID. The ProductID will be a 20 long string of numbers and is used when you call Microsoft for support. It may also affect Windows XP Validation, an error in System tray with "Unable to complete genuine Windows validation" and/or you *may receive the error: "0x80080201 Cannot detect product ID (PID)"

The ProductID that was modified here is under the:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion]
"ProductId"="XXXX-XXX-XXXXXXX-XXXXX"


Note, this is not your Product Key used to install Windows!

To retrieve your Product ID and restore it for above key/value, you can find it under next value in the registry as well:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
"ProductId"="XXXX-XXX-XXXXXXX-XXXXX"


If you're not familiar with the registry, I suggest you use the Microsoft Genuine Advantage Diagnostic (MGADIAG) tool instead to retrieve your Product ID.

Run MGADiag.exe, click Continue and you'll find your Product ID under the Windows Tab.



There you can find your Product ID.
Now you have to restore that value in the registry again.
To do this, go to start > run and type: regedit
This will open your Registry Editor.
(Extra note: In case you're having problems with above instructions, see the latest part of this post how to restore the policies first.)

Now browse to the following key by expanding the folders (keys)
HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows NT > CurrentVersion
On the right, you should find: ProductId
In your case, you'll see VIRUS ALERT! next to it.
Doubleclick the value to open it and edit the string as you see in the screenshot below:



Where you see VIRUS ALERT! in the "edit string Window", delete the VIRUS ALERT! in there and replace it with your Product ID key you retrieved previously: XXXX-XXX-XXXXXXX-XXXXX
The X stands for random numbers/letters
Click the OK button after you edited the ProductID value in the Edit string Window to apply the changes.

This infection also adds a lot of policies (taskmanager disabled, registry editor disabled etc..) and also made some modifications in the startmenu as you see in the screenshot below:


To fix this, download this zipfile to your desktop.
Unzip it. Then RIGHTCLICK the VArestorepolicies.inf and select to Install from the Context menu.

Then, log off or reboot to apply the changes.

Note: Above will set the display in the Startmenu to Windows default. This in case you have modified this previously and already "disabled" some StartMenu items there.
It will also delete some policies which you *may have set yourself previously.

Note2: Above instructions only remove the VIRUS ALERT! in the clock and System properties and the restrictive policies+registry modifications being set. This doesn't clean the infection itself if still present. As long as the infection is still present and active, it will replace above values (with VIRUS ALERT!)+policies again.
To receive help to remove the infection (if still present), register at one of the forums present on the right, or register at my personal forum here. It's a dutch forum but I also give english support.

Monday, May 26, 2008

Popups - annoying... but funny... sometimes

Once in a while, I install some random malware to analyze what it exactly does. And some popups the malware generates are just amazing.
So here are few of my "funny popups collection" :







Too bad there's no Yes button there... :(

Stay tuned for new ones...

Saturday, May 17, 2008

Vundo goes WGA!

Vundo aka Virtumonde aka Win32.Monder aka somanyotherdescriptions is a common infection nowadays. It creates several different loading points to keep the infection alive.
Some loading points are:

* HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\randomkeyname
"DllName"="badfile"


* HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bad CLSID}

* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
"{bad CLSID}"=""


* HKLM\SYSTEM\CurrentControlSet\Control\Lsa
"Authentication Packages"="default value + bad value inserted"


* and some more

We have also seen some other variants where a file infector was recreating above files/keys+values again.
An example of this one is W32/Trats.

I have already cleaned A LOT of computers with above ones present. After a while it's a piece of cake if you know where to look and what to delete.
However - I had a hard time with this one.
I just couldn't figure out why it was respawning everytime again. Everytime we tried to remove the files and related keys, after reboot, a new DLL was dropped again, which then downloaded/installed more files again.

The user had McAfee installed and in some other threads, I've noticed that McAfee was interfering with some removaltools after reboot. After I asked to temporary uninstall McAfee (since disabling doesn't make a difference because it will run again after reboot anyway) worked in most of the cases.. so the tools could finish their job and remove the infection properly.
However, in this case, it didn't make a difference. New files were created again after reboot.
Then I asked the user to disconnect from the internet, leave it disconnected and transfer the logs via another computer. This variant also downloads more files everytime again if connected with the internet so it would be a neverending story.
And if disconnected, it's easier to troubleshoot/figure out where these files come from, if they are downloaded or if a file already present is recreating/installing them.

The user disconnected the infected computer from the internet...
I really thought we could finally nail it now, because I assumed that the active files were responsible for downloading and installing new files again immediately after one was deleted.

I was wrong - because even after the user disconnected, after reboot, a new random DLL was present there again.
The other random files didn't appear there anymore, so this DLL couldn't download more files since the computer was disconnected from the internet. So we made progress in a way...
We tried once again, deleted the DLL and related keys - rebooted - and again, a new random DLL was created. Grrrrrr...

So, there should be a loader still present in the system - something I overlooked...
And yes, I overlooked some entries in the Kaspersky log that was posted previously. The log was posted with html tags which made it harder to read, because the forum doesn't support posts in html.
So I created the html file and had a better look....

And there it was..... the loader/installer!!

C:\WINDOWS\system32\WgaTray.exe/data0000.cab/is201779.exe Infected: Trojan.Win32.Monder.gen

The WgaTray.exe is a legitimate file and runs in the background to validate your Genuine Windows XP software. In this case, the WgaTray.exe was an infected version.
Since WgaTray.exe runs in combination with WgaLogon.dll and LegitCheckControl.dll, I had to check if WgaLogon.dll and LegitCheckControl.dll were also infected or not. The WgaLogon.dll was indeed modified recently, but appeared to be clean. The same was for LegitCheckControl.dll.
Only the WgaTray.exe was infected.

After removing the WgaTray.exe, the issue was resolved and no more files were installed again.

So what happened here was...
This user wanted to patch the WgaTray.exe in order to avoid the Genuine validation check, patched it with malware instead and All hell broke loose!

Another lesson learned I hope...