Showing posts with label MalwareBytes. Show all posts
Showing posts with label MalwareBytes. Show all posts

Sunday, 4 March 2012

Rogues and the dark side of online money making

Scareware

Have you got the anti-virus software that shows you a list of threats and won't go away until you buy a registration for it? Does it look more like a virus than legitimate anti-virus? If that sounds about right then you most likely are dealing with rogue anti-malware threat. The following video by rynesandbergfan23 shows a demonstration of what the rogue anti-malware (or anti-virus for that matter) is and what it's capable of. The example of rogue anti-malware used in the video is called XP Anti Spyware. The attempt to get rid of the rogue software is made by the help of Malwarebytes Anti-Malware which, on this occasion, proves to be unsuccessful:

Here are some names of rogue security software: Antivirus PC 2009, PCSuperCharger, DrAntispy, AntiMalware Pro, AntiSpywareMaster. (Extensive list of names can be seen here.) Some common patterns can be singled out:
  • there is no name of the developer / publisher mentioned;
  • the software name includes 'super', 'pro', 'master' and probably other hyperbolic terms.

Method of removal

Rogue software should be treated as malware therefore its removal is carried out by using anti-malware software provided by genuine and established publisher. For suggested free malware and rogue software removal tools click here. I'd suggest to follow the computer cleaning method outlined by me here. All the more because the method suggested can be used without the computer being connected to the Internet.

If you want to report a website hosting malware/scareware/spyware

Help to make the Internet a better place and report malicious URLs by going to Badwarebusters.org. Thank you.

The dark side of cyber business

More information on what part of the Internet the rogue anti-virus software (scareware) belongs to, you can find in the extensive summary by Dmitry Samosseiko, a data security researcher at data protection company SophosLabs Canada. The aforementioned research deals with the dark side of the Internet:
  • spam and other online promotional tactics that are more or less of criminal nature;
  • adult and casino sites of obscure origin;
  • scareware;
  • fake pharmacy products;
  • Black Hat SEO.
While the article is supposed to be about the online affiliate programs known as Partnerka in Russia, it is informative enough for everyone in terms of awareness of what to look out for while browsing the Internet, clicking on advertising links, dealing with email and registering at websites, so that one can avoid of becoming a victim to malicious tactics used by cyber criminals. The file can be viewed and downloaded by clicking here.
The author of this blog strongly recommends against both: abuse of information and participation in criminal activities.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Thursday, 16 February 2012

Bot, Spybot and free malware removal

What are bots and Botnets?

By definition bot is a software application running automated tasks over the Internet like, for example, those best friends of SEO specialists: Google and Bing robot spiders/crawlers that index webpages. We however will be talking the removing of those bots that by About.com's definition are
type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'.
Description of botnets by Securelist.com website pretty much sums up the answer to questions like, what is a purpose of developing botnets and why would anyone want to create trojan bots:
Special Trojans – ‘bots’ (from “robot”) are created for this kind of networks, centrally managed by the remote “master”. The Trojan intrudes into thousands, tens of thousands or even millions of computers. This enables the master of the “zombie network” (or “bot-network”) to access resources of all infected computers and use them to own benefits. Sometimes such networks of “zombie-machines” come into the black Internet-market where they are acquired by spammers or rented.
The following video by rynesandbergfan23 explains what malicious bots are capable of, what to look out for and how to secure your machine so that its chances of getting infected are greatly reduced. (Note: if you haven't got a software to monitor your network connections similar to one shown in the video, you can use Command Prompt (Start-->Run-->cmd) instead. For the list of network connections and associated software applications maintaining them, type netstat -b in the Command Prompt and hit Enter):

Spybot

Last year my machine, despite the full ZoneAlarm's protection it had, got infected with what was known as Google Redirector malware. That's how I got familiar with a freeware called Spybot S&D (or Spybot Search&Destroy), a software project that financially depends on PayPal donations. This freeware is able to identify more than 820,000 pests (including Win32/Zbot (also known as ZeuS), SpyEye and TDSS trojans) by basically doing what it calls a bot-check. The following video will show you what features Spybot has got as well as how to scan and clean your machine:


Now, from my experience, Spybot is very useful to get rid of spyware, adware and all kinds of sneaky pests but it cannot serve as a replacement for an anti-virus software. Handling of malicious Windows Registry entries is one thing Spybot is really good at. The picture that follows is a screenshot of Spybot's scan results:


If you click on it and take a closer look, you can see that (apart from 2 DoubleClick tracking cookies) there are only 3 objects expanded that are not Registry entries.

Malware and spyware removal method

Let's get back to the video at this point. The author of the video comes up with what I see as a generally good idea as to how a Windows machine has to be cleaned: if one malware detection software comes up with detected objects after the scan, it is recommended that after deleting those objects, a system scan is run again, this time by using the same type of software by different vendor. In the video the free Malwarebytes Anti-Malware (appears to be most trusted free malware detector for Windows environment) scanner is used to compare scan results however, unlike that of the video author, our point here is not to demonstrate a comparison because no software is absolutely perfect. The point is using what Hitman Pro (also used in the video) developers call a 'second opinion'. Now, lets see what I've got after following this sequence: free Emsisoft Anti-Malware (Scan settings: Scan type: Deep Scan Objects: Rootkits, Memory, Traces, C:\ Scan archives: On ADS Scan: On) -->Spybot scan --> free Malwarebytes Anti-Malware (Deep Scan) --> Hitman Pro (Default scan):
  • Emsisoft Anti-Malware detects 387 objects each related to one of the following: mywebsearch toolbar, zwinky toolbar, funwebproducts, Trojan.Win32.AddUser and Trojan-Downloader.Agent.  (No screenshot provided because of the amount of objects found yet the scan Report can be viewed by clicking here.)
  • Spybot detects some MyWebSearch and FunWebProducts Windows Registry entries as seen in the screenshot above (the scan takes up to several hours)
  • Malwarebytes Anti-malware still detects some MyWebSearch entries in Windows Registry and a Start Menu Hijack:
  • Hitman Pro detects one remnant of malware in Windows Registry:

  • Now the machine can be considered free of both, malware and spyware. Remember, before you start cleaning your machine, make sure you have:
    • downloaded all the latest updates for the software you are going to use. If this doesn't work, the best thing to do is to obtain anti-malware software installation using other computer. Spybot for instance can be installed and run without the connection to Internet: latest updates is an optional step during the installation;
    • disconnected the machine from the network either by removing cable or disabling/removing your wireless adapter. This is actually the first thing you want to do if you suspect your computer has been infected and you seem to have no control over running processes.
But speaking of Google Redirector... The only free tool that got rid of it was HitMan Pro (Google redirection infection is known as TDL3/TDL4 rootkit).  Mind you, that was back in May 2011, and as we know, things constantly change.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall