Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts

Thursday, 16 February 2012

Bot, Spybot and free malware removal

What are bots and Botnets?

By definition bot is a software application running automated tasks over the Internet like, for example, those best friends of SEO specialists: Google and Bing robot spiders/crawlers that index webpages. We however will be talking the removing of those bots that by About.com's definition are
type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'.
Description of botnets by Securelist.com website pretty much sums up the answer to questions like, what is a purpose of developing botnets and why would anyone want to create trojan bots:
Special Trojans – ‘bots’ (from “robot”) are created for this kind of networks, centrally managed by the remote “master”. The Trojan intrudes into thousands, tens of thousands or even millions of computers. This enables the master of the “zombie network” (or “bot-network”) to access resources of all infected computers and use them to own benefits. Sometimes such networks of “zombie-machines” come into the black Internet-market where they are acquired by spammers or rented.
The following video by rynesandbergfan23 explains what malicious bots are capable of, what to look out for and how to secure your machine so that its chances of getting infected are greatly reduced. (Note: if you haven't got a software to monitor your network connections similar to one shown in the video, you can use Command Prompt (Start-->Run-->cmd) instead. For the list of network connections and associated software applications maintaining them, type netstat -b in the Command Prompt and hit Enter):

Spybot

Last year my machine, despite the full ZoneAlarm's protection it had, got infected with what was known as Google Redirector malware. That's how I got familiar with a freeware called Spybot S&D (or Spybot Search&Destroy), a software project that financially depends on PayPal donations. This freeware is able to identify more than 820,000 pests (including Win32/Zbot (also known as ZeuS), SpyEye and TDSS trojans) by basically doing what it calls a bot-check. The following video will show you what features Spybot has got as well as how to scan and clean your machine:


Now, from my experience, Spybot is very useful to get rid of spyware, adware and all kinds of sneaky pests but it cannot serve as a replacement for an anti-virus software. Handling of malicious Windows Registry entries is one thing Spybot is really good at. The picture that follows is a screenshot of Spybot's scan results:


If you click on it and take a closer look, you can see that (apart from 2 DoubleClick tracking cookies) there are only 3 objects expanded that are not Registry entries.

Malware and spyware removal method

Let's get back to the video at this point. The author of the video comes up with what I see as a generally good idea as to how a Windows machine has to be cleaned: if one malware detection software comes up with detected objects after the scan, it is recommended that after deleting those objects, a system scan is run again, this time by using the same type of software by different vendor. In the video the free Malwarebytes Anti-Malware (appears to be most trusted free malware detector for Windows environment) scanner is used to compare scan results however, unlike that of the video author, our point here is not to demonstrate a comparison because no software is absolutely perfect. The point is using what Hitman Pro (also used in the video) developers call a 'second opinion'. Now, lets see what I've got after following this sequence: free Emsisoft Anti-Malware (Scan settings: Scan type: Deep Scan Objects: Rootkits, Memory, Traces, C:\ Scan archives: On ADS Scan: On) -->Spybot scan --> free Malwarebytes Anti-Malware (Deep Scan) --> Hitman Pro (Default scan):
  • Emsisoft Anti-Malware detects 387 objects each related to one of the following: mywebsearch toolbar, zwinky toolbar, funwebproducts, Trojan.Win32.AddUser and Trojan-Downloader.Agent.  (No screenshot provided because of the amount of objects found yet the scan Report can be viewed by clicking here.)
  • Spybot detects some MyWebSearch and FunWebProducts Windows Registry entries as seen in the screenshot above (the scan takes up to several hours)
  • Malwarebytes Anti-malware still detects some MyWebSearch entries in Windows Registry and a Start Menu Hijack:
  • Hitman Pro detects one remnant of malware in Windows Registry:

  • Now the machine can be considered free of both, malware and spyware. Remember, before you start cleaning your machine, make sure you have:
    • downloaded all the latest updates for the software you are going to use. If this doesn't work, the best thing to do is to obtain anti-malware software installation using other computer. Spybot for instance can be installed and run without the connection to Internet: latest updates is an optional step during the installation;
    • disconnected the machine from the network either by removing cable or disabling/removing your wireless adapter. This is actually the first thing you want to do if you suspect your computer has been infected and you seem to have no control over running processes.
But speaking of Google Redirector... The only free tool that got rid of it was HitMan Pro (Google redirection infection is known as TDL3/TDL4 rootkit).  Mind you, that was back in May 2011, and as we know, things constantly change.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Friday, 10 February 2012

How a banking trojan can steal your data and money

A quick look at Zbot

There are many ways hackers can try to steal personal data from computers. We will take a look at what is known as Zeus to give you the idea of how your banking information can be stolen, so that you know what to be aware of, and how to avoid of becoming a victim.

There is an in-depth analysis of ZeuS Banking trojan to be found at SecureWorks website by authors Kevin Stevens and Don Jackson, Security Researchers from SecureWorks Counter Threat Unit SM (CTU). While it is suggested that you read the whole article, I will post some excerpts here:
ZeuS is a well-known banking Trojan horse program, also known as crimeware. This trojan steals data from infected computers via web browsers and protected storage. Once infected, the computer sends the stolen data to a bot command and control (C&C) server, where the data is stored. ZeuS has evolved over time and includes a full arsenal of information stealing capabilities:
  • Steals data submitted in HTTP forms
  • Steals account credentials stored in the Windows Protected Storage
  • Steals client-side X.509 public key infrastructure (PKI) certificates
  • Steals FTP and POP account credentials
  • Steals/deletes HTTP and Flash cookies
  • Modifies the HTML pages of target websites for information stealing purposes
  • Redirects victims from target web pages to attacker controlled ones
  • Takes screenshots and scrapes HTML from target sites
  • Searches for and uploads files from the infected computer
  • Modifies the local hosts file (%systemroot%\system32\drivers\etc\hosts)
  • Downloads and executes arbitrary programs
  • Deletes crucial registry keys, rendering the computer unable to boot into Windows
  •  
How to detect the ZeuS Banking Trojan on your computer
Computers infected with this version of ZeuS will have the following files and folders installed. The location depends on whether the victim has Administrator rights. The files will most likely have the HIDDEN attribute set to hide them from casual inspection.
With Administrator rights: 
%systemroot%\system32\sdra64.exe (malware)%systemroot%\system32\lowsec%systemroot%\system32\lowsec\user.ds (encrypted stolen data file) %systemroot%\system32\lowsec\user.ds.lll (temporary file for stolen data) %systemroot%\system32\lowsec\local.ds (encrypted configuration file)
Without Administrator rights: 
%appdata%\sdra64.exe%appdata%\lowsec%appdata%\lowsec\user.ds%appdata%\lowsec\user.ds.lll%appdata%\lowsec\local.ds 
ZeuS also makes registry changes to ensure that it starts up with Administrator privileges:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinlogonFrom:"Userinit" = "C:\WINDOWS\system32\userinit.exe"To:"Userinit" = "C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe"
Without Administrator rights:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunAdd:"Userinit" = "C:\Documents and Settings\<user>\Application Data\sdra64.exe" 
The sdra64.exe program uses process injection to hide its presence in the list of running processes. Upon startup, it will inject code into winlogon.exe (if Administrator rights available) or explorer.exe (for non-Administrators) and exit. The injected code infects other processes to perform its data theft capabilities.

How your system can get infected

There is a list of ways your system can get infected to be found in one of my other posts here. Things you really should watch out for, and avoid, are emails supposedly sent from your bank where you are asked to follow a certain link in order to update your security details, or to download a file attached to the e-mail message. Here are few samples of such e-mail messages:

Dear Customer,
We detected irregular activity on your
Internet banking account.
For your protection, you must verify this
activity before you can continue using your
account.
Please download the document attached to this
email to review your account activity.
We will review the activity on your account
with you and upon verification, we will remove any restrictions placed on
your account.
If you choose to ignore our request, you leave us no choice
but to temporary suspend your account.
We ask that you allow at least 72 hours for the case to be
investigated and we strongly recommend to verify your
account in that time.
© Copyright Barclays Bank Holdings plc 2012 - All rights reserved


and

Dear Valued Customer,
Your account is suspended due to the number of incorrect login attempts.
For your protection, we've suspended your account .
To reactivate your account please download the document attached to this
e-mail and review your account activity.
If not completed until February 09, we will be forced to close your account .
Note: If you received these e-mail in your BULK/SPAM section please
add to your address book [e-mail address withdrawn]

Thank you,

Customer Support Service.

Copyright © NatWest Bank Plc. Limited. All rights reserved.


On both occasions senders obviously have made an opportunistic attempt to get me into downloading their malicious HTML files attached to messages without knowing that I'm not a customer of either of aforementioned banks.
So, what would have happened if I'd downloaded the attached file? I would most likely have infected my machine with a trojan bot spyware that would be capable of sending data from my computer to a remote server on the Internet, controlled by a cyber criminal, and basically making my machine a part of a botnet.
Or, if there would have been a link to follow, then, by clicking it, I would most likely have ended up on some bogus website designed by a cyber criminal for malicious purposes such as pharming (URL redirections with purpose of information stealing) or spreading malware infections. Example of a phishing message:

Dear Valued Customer,
our security filter noticed a malicious activity in your online account.
We were able to trace it to an unknown link thereby, placing
your online banking on suspension till this is resolved.
We implore you to go over your account details so
as to continue with your online transactions.
Click here to resolve the problem.
[Link withdrawn]

Thank you for helping us to render you a maximum protection.

Security Department.

Alliance-leicester online banking.


Things to keep in mind

Regardless of the content of the message, remember: banks will not ask you for any security details or security updates via e-mail. Don't just click on links in emails you receive from someone. Make sure the sender is trusted and genuine, and the link does not look dodgy. (The same applies to Instant Messenger chats.) If you receive a suspicious email supposedly sent from your bank, and you are asked to proceed with giving away any of your personal or financial details, or to download an attachment, don't. Instead, forward the email message to the bank. Almost on all occasions you can find e-mail address for forwarding phishing emails to at the bank's official website. For more detailed information on types of scams related to Online banking, and to get a genuine advice, please visit Bank Safe Online, a website developed by UK Payments Administration Ltd.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall