Showing posts with label Malware Infections. Show all posts
Showing posts with label Malware Infections. Show all posts

Friday, 27 November 2015

Microsoft Protects Companies From Unwanted Software


Microsoft has the business security of a new feature provided in order to protect businesses and organizations from potentially unwanted software. It involves, for example so-called software bundles containing adware, toolbars and other unwanted programs.

According to the software giant this program may increase the risk of getting infected corporate networks with malware or make it harder to identify malware infections. It would also burden the helpdesks and time consuming to remove the applications. To protect corporate users from this kind of software security solutions System Center Endpoint Protection (SCEP) and Forefront Endpoint Protection (FEP) with a new opt-in feature rich, so Microsoft through a blog posting disclosed.

The feature can detect potentially unwanted programs and stop, so they are not downloaded or installed. Microsoft claims that the blocking of such software should be an explicit choice, and companies are wise to do to set policy on here. Even end users should be alerted in this case, so they know that potentially unwanted programs are not allowed in the operating environment and will block the security products such software.

Wednesday, 7 October 2015

Apple: YiSpecter-Malware Only Works On Old iOS Versions


The YiSpecter malware that security company Palo Alto Networks warned only works on older iOS versions, and only if users themselves downloading malware from untrusted sources, says Apple. The malware is mainly active in China and Taiwan, but the number of infections is unknown.

To spread the malware uses different methods, but a user action is still required to download and install the malware. In a statement to The Loop, Apple says that the problem affects only users of older iOS versions of the malware itself from unreliable sources have downloaded. The specific problem could be resolved in iOS 8.4. This version was published on June 30 of this year.

In addition, Apple has the apps that were used to block the spread of malware. Apple recommends that iPhone owners to install the latest version of iOS apps only from trusted sources such as downloading the App Store. Also, users should be careful when they get warnings when downloading apps.

Monday, 5 October 2015

McAfee Receives Award For Research Into Botnet


Anti-virus company McAfee has at the Virus Bulletin conference in Prague received an award for research into a botnet which was in collaboration with the Dutch police shut. The botnet, which Beebone, VObfus or AAEH was called, was a polymorphic botnet.


The malware that caused computers part of the botnet had been active since 2009 and spread via infected USB sticks and social engineering. In early April of this year, the botnet was the High Tech Crime Team (THTC) of the Dutch police, the FBI, Europol and security Intel Security, Kaspersky Lab and Shadow Server taken off the air.

To disable the botnet domains were all registered and seized that used the malware to communicate with infected computers. Then the investigating authorities showed these areas to the servers of Internet providers and computer emergency response teams (CERTs) by pointing all over the world, a process also known as "sink holes" is mentioned.Research showed that the malware had infected 12 000 computers.

According to McAfee cooperation between law enforcement agencies and security companies was essential to make the botnet from the air. The anti-virus company wrote a technical report (pdf) on the malware and operation of the botnet.Previously received McAfee last week at the Virus Bulletin conference Peter Szor Award. An annual prize for the best security research named after the anti-virus pioneer deceased in 2013.

Szor began twenty years ago with the analysis of malware and in 2005 wrote the book "The Art of Computer Virus Research and Defense. He worked for Symantec and F-Secure, before he went to work in 2011 at McAfee. In 2013 died he unexpectedly. "This kind of research makes everyone safer, as did the survey conducted late Peter Szor," said Martijn Grooten of Virus Bulletin.

Saturday, 3 October 2015

Kaspersky Wins Test Malware Removal



Anti-virus software must be able to not only detect malware, including the removal of an infection is part of a good working virus scanner. The Austrian test lab AV-Comparatives therefore decided to test 16 security packages to consumers on malware removal.

In total, were used for the test 35 different malware instances that had to remove the packages. These criteria include being sought for leave of executable files, MBR or registry changes, custom host files and programs that were disabled by the malware and after disinfection is still not working, like Windows Task Manager and the Windows Registry Editor.

The packages were evaluated for the simplicity with which the malware was removed, like removing normal mode, safe mode, using a rescue disk or calling the help desk to remedy the infection. Eventually, the virus could score up to 100 points. Kaspersky Lab sets with 93 points, the highest score down just before Avast (89) and Bitdefender (89). Sophos (72) and Threat Track Viper (65) put the lowest score down. Microsoft Windows Defender ends up with 80 points in the middle.

Thursday, 1 October 2015

Microsoft Received 175 000 Complaints About Telephone Scammers



Since May last year, Microsoft has more than 175,000 complaints received telephone scammers. It is in this case to telephone scammers posing as Microsoft employees. The scammers call people and say that there are problems with the computer, such as a malware infection.

It then attempts to get the victim to install a program that allows the scammer can take over your computer. Ultimately have to pay the victim for the correction of non-existent problems, which can amount to hundreds of euros. According to Microsoft this year will be an estimated 3.3 million people in the United States more than $ 1.5 billion to pay scammers. It is not clear whether this just about telephone scammers. In order for people to warn the scam Microsoft is working now with the American Association of Retired Persons (AARP). There is an information leaflet developed (pdf) and workshops are organized.

Thursday, 30 April 2015

Malware Infects Thousands Of Linux And BSD Servers


Researchers from the Slovak anti-virus company ESET have discovered thousands of Linux and BSD servers that are infected with malware and used to send large numbers of spam messages. Hard mumble, as the malware is called, would have been active since 2009.

It mainly involves Web servers that most likely through leaks in the popular content management systems Joomla and WordPress were hacked. Then the attackers Mumble Hard installed on the systems. In addition, the malware could also have spread via pirated versions of a program called Direct Mailer. The software normally costs $ 240, but on the Internet pirated versions were found with Mumble Hard backdoor.

Yell Soft

Direct Mailer is developed by the software company Yell Soft. Yell Soft sells software like Hard Mumble is written in the Perl programming language and is used to send bulk mail. Researchers from ESET suspect Yell Soft may be involved in the malware. It appears that the IP address of the C & C server that the infected Linux and BSD machines controls is in the same range as the Web server yellsoft.net .

The second link which the researchers point to the existence of the illegal versions of Direct Mailer where Mumble Hard backdoor hidden in. The first version of Mumble Hard dates from 2009. Yell Soft exists since 2004. "It is unclear whether they were involved between 2004 and 2009 in malicious activity," as the researchers in their report ( pdf ) about the malware.

Infections

Hard mumble was discovered after an administrator had complained that his server was ended because of a spam blacklist.During the research conducted ESET researchers knew to "sink holes" botnet server, where the movement of infected machines ran to a server of the anti-virus company. In this way, the researchers saw a period of seven months, nearly 8900 unique IP addresses passing by who were infected. Administrators who want to know if their server is compromised are advised to search for unsolicited cron jobs for all users.

Thursday, 23 April 2015

Adobe Distributes Emergency Patch Attacked Flash Leak



A comprehensive attack on users of Adobe Flash Player remained hidden for two months before it was discovered by security researchers. Before the attack, the attackers were using an unknown vulnerability in Adobe Flash Player which on February 4 this year came with an update. Anti-virus company Malwarebytes, however, that the leak since December 10, 2014 was attacked.

Unlike many zero days, vulnerabilities for which an update is missing, it was not a question of targeted attacks against specific organizations or institutions. Just ad networks were used to attack ordinary Internet users and infect with ransomware and click fraud malware. Once an infected ad was shown a Flash Player user's computer could be infected with the malware.

For the spread of infectious ads used the attackers an ad network that reaches more than 500 million users in their own words. To prevent the attack would stand each visitor got infected ad only see once and were users with a VPN or proxy not infected. According Malwarebytes attackers tried in this way to hide the attack for security researchers and security.

Furthermore discovered the virus fighter that the attackers simply paid for the ads and there was no hacked ad networks. 0.75 cents was paid for 1,000 impressions, but this figure fell to 0.06 cents at less busy times. The ads appeared on separate popular websites, Malwarebytes states that, judging by the use of a zero-day and the execution of the attack, we were dealing with a professional operation. The attacks stopped in the end on February 3, a day after Adobe an emergency patch was announced for the leak.

Microsoft Protects Windows 10 Device With Guard


During the RSA Conference in San Francisco, Microsoft announced a new security measure for Windows 10 that infection of computers and laptops by malware should avoid. With Device Guard , as the hot solution, organizations can systems from both known and unknown malware and Advanced Persistent Threats (APTS) protect, as well as zero-day attacks.

Using the security measure merely changes programs of specific suppliers, the Windows Store or organization authorized. All other software will block Windows 10. Companies can decide which providers Device Guard trust. The solution comes with software that makes it possible for applications that are not signed by the original supplier itself signings, so they can be used anyway.

To determine whether a program is executed to trust the Device Guard hardware and virtualization technology to isolate the decision of the rest of Windows 10, which is intended to protect against attackers or malware to gain system privileges have full knowledge. According to Microsoft, this is a significant advance over traditional virus scanners and whitelisting solutions such as AppLocker, which are vulnerable to manipulation by administrators or malware. Several manufacturers, including Acer, Fujitsu, HP, Lenovo and Toshiba, have pledged to support the use of Device Guard on their equipment.