Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

18 July, 2011

Hijacked proxy

HijackThisImage via WikipediaWhile I was having the ODP.NET and VS2010 installation issues at work, I experienced some problem with my internet explorer at home. I cannot connect to any website.

The behaviour is the same with Firefox, Flock 3x, and Maxthon.

The only exception is flock 2.xxx. This is what I used to troubleshoot the problem.

It was also a long and arduous troubleshooting scheme, making much use of web articles and downloadable fixes. But I did find some help that really helped me.

Malwarebyte's antimalware
SuperAntiSpyware

These are the 2 applications that helped me clean up my infected laptop. Why infected? My wife was asking why there suddenly is a song being played, and it is in Spanish.

I also did notice that when I am rebooting the machine, I would get a flash of ads - every time.

SUPERAntiSpyware Professional Edition 4.50 2-user License Lifetime SubscriptionBut I didn't know that it was that bad. To me, I deemed it something intermittent, for why would I be able to access internet using Flock 2.xxx version, and not the others?

I also did find HijackThis software, which I run to remove the registry entry of the proxy server, which I don't have, since I am directly connected to the internet. (Hey, this is home network, not office, no).

This is a couple of days only, since I am also quite in a hurry to fix this.

The web that introduced HijackThis software is where I found the inetcpl.cpl procedure that I followed. It is Internet Options in XP, but in Windows 7, you type it is the Start box. It leads you to the IE settings, Connections, LAN Settings, and this is where you untick the 'Use a proxy server..." selection (below), and tick the "Automatically detect settings" selection (above).

So it was a handful of steps that I followed, and it got me back my internet connection:

1. Run Antispyware softwares (Malwarebyte's Antimalware and SUPERAntiSpyware).
2. Run HijackThis, and removed the registry setting that is identified as hijacked proxy.
3. Correct my IE LAN settings.

Malwarebytes Anti-Malware LifetimeAnd with that, all things are back to normal. I should say that it got me worried at the time I was  hit, because there were critical updates for Windows that I know are coming, but they fail to be downloaded, so that actually added on to the pressure of me getting back my home internet connection (on my laptop, that is).

Till then!
Enhanced by Zemanta

19 February, 2010

The misuse of computer knowledge at work?

Google's first production server rack, circa 1999Image via Wikipedia

2,400 FIRMS, GOVT AGENCIES HIT BY HACKERS
-----------------------------------------

SAN FRANCISCO - Coordinated cyber attacks launched from Europe and China breached computers at firms and government agencies worldwide in the past 18 months, The Wall Street Journal reported on Wednesday.

The Journal quoted computer security firm NetWitness as saying the attacks made mountains of data vulnerable to mining by hackers, although the damage had yet to be fully assessed.

Information bared to hackers ranged from credit card transactions to intellectual property of slightly more than 2,400 victims, including 10 US government agencies, according to the Journal.

The hacking operation began in late 2008 in Germany and has yet to be stopped, NetWitness said.

Workers at companies were tricked into visiting websites or opening email attachments that promised to clean viruses from computers but instead infected machines.

Malicious code used in the attacks allowed hackers to seize control of computers remotely. Evidence cited by NetWitness indicated the culprits may be Eastern European gangsters.

The report came in the wake of Google revealing it was targeted by a sophisticated cyber attack aimed at the US firm's source code and Gmail accounts of Chinese human rights activists around the world. Computer industry specialists subsequently said more than 30 companies were hit by those attackers.

The apparent online espionage prompted Google to vow it would stop bowing to Chinese censors and shut down its China search service if it cannot operate unfettered. Google continues to filter searches in accordance with Chinese law while trying to negotiate a compromise with officials there. AFP

From TODAY, Friday, 19-Feb-2010

----------

Reblog this post [with Zemanta]

30 June, 2009

Jackson's death sparks barrage of online scams

Michael Jackson StarImage via Wikipedia

And so, beware. Needless to say, keep enough sense and watch out for anything suspicious…

----------

06/30/2009 | 08:15 AM

SAN JOSE, California — Minutes after any big celebrity dies, Internet swindlers get to work. They pump out specially created spam e-mails and throw up malicious Web sites to infect victims' computers, hoping to capitalize on the sudden high demand for information.

Michael Jackson's death was no different, and security experts say the fraud artists are just getting started.

The scams started cropping up almost instantaneously as Jackson's death was still hitting the news. As days have gone by, they've gotten more sophisticated — and dangerous.

Jackson's death "took a lot of people by surprise — the spammers, too," said Dermot Harnett, principal analyst for anti-spam engineering at Symantec Corp., a security software maker. "It might take them some time to really pounce on this issue. They are catching up pretty quickly, though."

Any major world event, such as the recent protests in Iran, triggers a barrage of Internet attacks. Security experts say the malicious traffic associated with Jackson's death will likely match and perhaps exceed those of other big spamming campaigns, such as those connected with the swine flu outbreak and Saddam Hussein's execution.

Spam is the most common way for fraudsters to find victims after these types of events. They can use a shotgun approach with a boilerplate message about Jackson, taking advantage of people's interests in the topic to improve their batting average over their usual spam campaigns.

By enticing users with such messages and tricking them into clicking on e-mail attachments, scammers can easily infect victims' computers and take command of them for more nefarious activities.

The spam about Jackson's death gets more convincing every day.

One message promises a YouTube video showing the exclusive "last work of Michael Jackson." Instead, victims get a malicious program that steals their passwords. Another promises to show the "latest unpublished photos" of Jackson if you click on a link — one that also tries to install a password-stealing program on your machine.

Others purport to be from legitimate news outlets and may contain accurate enough information to convince viewers they're real enough to click on. Others promise access to secret songs.

The effects of specific spam campaigns, like the one surrounding Jackson's death, are hard to quantify, though. Spam levels are already so high that there might not be a noticeable increase in overall spam levels, Harnett said. By some estimates spam accounts for more than 90 percent of all e-mail sent around the world, though the bulk of the messages get filtered out before ever reaching the user.

Celebrity deaths are a gold mine for criminals because lots of people go online looking for news. Google Inc. says the spike in searches for news stories about Jackson's death was so sharp the company initially mistook it for an automated attack.

Many of the information-seekers can be tricked, via e-mail, into visiting malicious Web sites. That opens the door to all kinds of nastiness, like spying on what someone's typing or using the hijacked machine to send spam.

There are also so many more Web sites about celebrities after their deaths that it's hard to figure out which ones are legitimate fan sites, and which ones were created by criminals.

Registrations of domain names related to Jackson have spiked since the pop icon died Thursday afternoon. A leading registration company, GoDaddy.com, said it registered about 7,500 such names since then. Actress Farrah Fawcett, who died the same day, got about 100 domains in the same period. GoDaddy said, however, that it had yet to get any complaints that any of those addresses were used for scams.

Within minutes of Jackson's death hitting the news, scammers started sending out spam e-mails with links purportedly to provocative news stories or videos about Jackson. The news stories, of course, never appear. Instead, people who click on those links are often directed to sites that try to install viruses.

Another thing to remember: It's not wise even to just "check out" a link you're interested in if you suspect the site might be bogus. Sometimes just visiting a malicious Web site is enough to get you infected, and you don't need to actively download anything at all.

Many scams do ask people to download a video player or other piece of software — supposedly so they can see the video or hear the audio — that winds up being a piece of malicious software.

The lesson for users is, as always, avoid unsolicited links from senders you don't know, and don't install any programs that an unknown site is telling you need. – AP

From GMANews.tv; see the source article here.

Reblog this post [with Zemanta]

22 June, 2009

Twitter message could be cyber criminal at work

By Kevin Voigt, CNN

STORY HIGHLIGHTS

  • Some officials say cyber crime has eclipsed drug trade as a money maker
  • Latest ploy is planting malicious software in intriguing Twitter topics
  • Some companies give in to extortion and remain silent, officials say
  • Skimmed credit card numbers can be found for sale on Web sites

TwitterMsg Savvy cyber criminals are taking advantage of our increasing reliance on computers and the Internet.

(CNN) -- Cyber criminals are setting snares that move at the speed of news.

Panda Security, a Spain-based antivirus maker, has been monitoring an onslaught of links with malicious software, or "malware," on Twitter that tag hot topics such as the Air France crash, the NBA finals, "American Idol" runner-up Adam Lambert and the new iPhone.

"Cyber criminals have been targeting Twitter users by creating thousands of messages (tweets) embedded with words involving trending topics and malicious URLs," Sean-Paul Correll, a threat researcher for Panda Labs, wrote recently on a blog for the company.

The growing sophistication of malware attacks mirrors the growing threat -- and cash -- generated by online crime. Already, cyber crime is estimated to cost companies and consumers more than $100 billion worldwide. Some officials claim it has now eclipsed illegal drugs as a criminal moneymaker.

"It's very seldom reported ... if discovered by companies, they generally don't want the public to know they've been had," said Eugene Spafford, a computer security specialist at Purdue University who has advised two U.S. presidents and numerous companies and government agencies.

Cyber crime is one of the few industries benefiting from the financial crisis. Last year, antivirus maker McAfee saw a 500 percent increase in malware types -- more than the company had seen in the previous five years combined. In the United States, the FBI reported a 33 percent increase in Internet crime last year.

Companies lost an average of $4.6 million in intellectual property last year, according to a survey of 1000 firms worldwide by Purdue University and McAfee.

"As the economy has declined, we've seen the threat landscape increase," David DeWalt, president and CEO of McAfee, recently told Richard Quest for CNN International's "Quest Means Business."

That increase has helped antivirus makers such as McAfee snare record returns -- the company's first quarter profits were 21 percent higher than same period last year.

But companies and governments find themselves in a losing war with Web-savvy criminals, experts say.

"The fundamental fact is cyber criminals are highly organized with sophisticated corporate structures and business chains," said Michael Fraser, director of the Communications Law Centre at the University of Technology Sydney in Australia.

"They have R&D departments, strong distribution networks and Web sites for the discerning cyber criminal," Fraser said.

On these Web sites, would-be criminals can purchase toolkits to learn how to side step security measures or create their own "botnet" -- referring to software that can, unbeknownst to victims, turn their computers into spamming foot-soldiers for criminal networks. One Web site advertises software that can capture information for a popular Internet secured-payment provider for $500 -- discounted to $400 for the first 100 buyers.

Skimmed credit card numbers and other personal-identity information stolen from computers also can be found for sale on Web sites, Fraser said. "When police shut these Web sites down, they just mushroom up some other place," he said.

Although the techniques of cyber crime have evolved, online criminals pray on human vulnerabilities like criminals throughout the ages. In the digital age, that means tempting with free downloads, money schemes and pornography.

The range of tools used by cyber criminals reveals the quick evolution of the industry. Viruses -- the first generation of the computer culprits -- are used for the computer equivalent of vandalism, as the malicious programs replicate, spread and damage computers.

"When the company was set up, we were seeing two or three new viruses a week," said Mahendra Negi, chief financial officer of Tokyo-based antivirus maker Trend Micro. "Now there's a new one every two-and-a-half seconds.

"With the arrival of spam in 2001 and 2002, the big difference was it was commercial malware," Negi said. "Once money became involved, the level of sophistication raised a hundred-fold."

Now the biggest threats include "phishing" schemes and "botnet" attacks.

Phishing is where criminals masquerade as a legitimate business or Web site and trick victims into revealing passwords, credit card information and other personal data.

Botnet attackers commandeer personal computers as part of a large network of "zombie" computers that, on command, target companies for spam attacks to cripple IT capabilities. Botnets -- some of which are large enough to deploy tens of billions of spam e-mails a day -- are often used in extortion schemes.

"They ring up the IT manager of a company and say, 'Pay us a million or we'll take you down'," said Fraser, who has worked with companies victimized by botnet attacks.

Companies often pay up and shut up, computer experts say, rather than report the crime and garner publicity that may hurt their corporate reputation.

And unlike prankster virus-makers, these malware makers are determined to stay hidden.

"Once it became a business, then (cyber criminals) began to look at what companies like us were doing, and figure out weaknesses," he said. "They are very customer friendly ... they sell updates, they will highlight what the product does and what antivirus software can't detect them.

Adding to the difficulty is the legal situation that in many jurisdictions, it is not illegal to create or sell malware.

"It's like the arms industry ... it's not a crime to build and sell them," Negi said.

And because of the transnational nature of the crime, it's extremely difficult to prosecute. A scan of 500 headlines on Internet-related arrests from newspapers around the world the past two years found about 90 percent were related to child-pornography cases.

"Child pornography is easier to prosecute because it is possible to find the evidence on the perpetrator's computer systems," said Spafford of Purdue University.

Cyber-criminal networks are as porous as the Internet itself.

"There are multiple jurisdictions and unless it's an ongoing crime that uses the same path all the time, the trail goes cold quickly," Spafford said. "I may be able to trace back to a computer system, if I'm lucky, or trace it back to a cyber cafe -- but how do I know who was behind it?"

Often criminal networks are run in countries such as Russia and China, where government officials turn a blind eye to these activities -- so long as their victims reside outside the host country, Spafford said.

"For the host countries, that's dangerous ... it's kind of like breeding tigers in the back yard and saying, 'Well, they haven't hurt anyone here yet,'" he said. "Mexico is a wonderful example ... they tolerated drug smugglers for years, and now it's such a major problem and incredibly painful and costly to run them out.

"I'm not saying (cyber criminals) are involved in physical violence, but it's not out of the realm of possibility," he said. "What are they doing with all that money?"

From CNN.com; see the source article here.

Reblog this post [with Zemanta]