PCCare247.com Blog, PC Care 247 Tech Support Redefined
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Wednesday, 28 March 2012

Take note for the Social Media is indeed a potent source of Malware

Social media even though considered to be a vital cog in the communication process tends to possess chinks in its armour through which malware can easily seep into an organization. And in this scenario just to put the point across; the famous breed of malware which gets introduced into an organization through unfettered use of social media popularly tends to comprise of:

Malware Removal• Koobface
The worm is known to target social media biggies such as Facebook, Twitter, MySpace along with other social media sites. The main goal of the worm is to gather login information for purposes of building a peer-to-peer botnet.

• Boonana
Written in Java and first reported in late October 2010, Boonana is known to target Macs. The modus operandi of this worm is very much like that of Koobface.

• Bugat
Considered to resemble the infamous keystroke-logging malware Zeus, Bugat is responsible for delivering a large-scale phishing attack against famous social media application LinkedIn. www.pccare247.com

Monday, 5 March 2012

Beware!! For these processes have a Malicious Intent


Malware RemovalMalware – The term is so synonymous with everything that intends to shred the security of our PC into tatters. But then again, also on a flipside, in spite of the entire hullabaloo, not all malware is malicious in intent and is commonly referred to as spyware; malicious software truly hell bent on infiltrating computers every now and then.

A case wherein hackers end up refining the capabilities of malware, expanding the flux technologies in order to obscure the infrastructure and making it even harder to locate their servers. However, in the recent times recent variants have come out that are able to detect when someone is investigating an activity; in order to respond with a flooding attack against an investigator. In short, malware is becoming stickier on target machines and more difficult to shut down.

So, just in case to prepare PC users better, we ended up preparing a list of processes which need to be watched out for in order to take any malware threat head on. Starting with:

ISASS.EXE
A part of Optix.Pro virus, Isass.exe is also better known as the Optix.Pro Trojan that carries along with it a payload ability to disable firewalls, local security protections and the ability to open a backdoor capability for fairly unrestricted access into a PC. The Trojan was a brainchild of someone by the name of s13az3; who at the same instance also ended up being a part of the Evil Eye Software crew.

NVCPL.EXE
A component of W32.SpyBot.S Worm; Nvcpl.exe is a process that is registered as the W32.SpyBot.S worm (It at the same time is also associated with the Yanz.B worm which again is once again just another name). Taking advantage of the Windows LSASS vulnerability, the process creates a buffer overflow, forcing a PC to shut down. Although not necessarily considered to be a particularly destructive piece of malware, it is a nuisance since it continues to access an e-mail address books while at the same time sending spam to contacts.

CRSS.EXE
Crss.exe is a process-forming part of the W32.AGOBOT.GH worm. The spyware worm is distributed via the Internet through e-mail and acquires the form of an e-mail message, in the hope that a PC user would end up opening the hostile attachment. The worm has its own SMTP engine to gather E-mails from a local computer while at the same instance trying to re-distribute itself. Yet, at the same time in worst case circumstances, the worm also ends up allowing attackers to access a PC while stealing personal data and passwords.

SCVHOST.EXE
A part of the W32/Agobot-S virus family, the scvhost.exe file belongs to the Agobot (aka Gaobot) PC worm family. The Trojan ends up spreading itself via networks and allows attackers to access a PC from remote locations, steal their passwords and along with it all forms of Internet banking and personal data.

SVHOST.EXE
Svhost.exe is a process associated with the W32.Mydoom.I@mm worm. The worm is distributed as an e-mail message and requires a PC user to open a hostile attachment. Using the SMTP engine, the MyDoom worm is known to gather e-mails from a local computer in order to redistribute itself. Further, as it would go, the other payload carried by the process was a denial of service attack on the website of SCO Group. But that’s somehow not it, for the later versions of the worm have also been known to carry out denial of service attacks on other sites, and those popularly being Google and Lycos. http://www.pccare247.com/pc-security/malware-removal.html

Wednesday, 21 December 2011

Look out!! Malware seeks to fuel its gluttonous zest with your PC

Instead of succumbing to the voguish threat hype, organizations and individuals can accentuate their threat tolerance through creation and promotion of a more secure system. Sprucing up defenses against an ever-evolving malware industry via strategic investment in security policies; thus eliminating vulnerabilities in the times to come.

Set your priorities Right!!
MalwareFor enhancing the malware-defense capability, security professionals would need to stop chasing malware flavor of the month and instead develop proactive security measures for proactively stopping it. All going on to suggest, if you have not opted for “defense against malware” as a top priority, it is high time you ended up doing so.

As time runs out variants in present times are fast becoming more polymorphic, stealthy, targeted and agile – indubitably leaving no doubt malware is capable of exploiting several vulnerabilities. With effect, giving security professionals sleepless nights and work hard towards detecting malicious elements looking to penetrate into an environment.

Sheath your PC out of harm’s way
Shielding a PC is easy if you know how!! Believe us, for following such handy tips is bound to ensure your PC remains in the pink of health.  

·         Offline malware and threat Detection
Inline technologies, such as IPS and secure Web gateways, need to adhere to line speed and therefore are restricted in the amount of analysis which can be performed. But, offline detection capabilities provided by a number of vendors in the market can go a long way in conducting a much deeper analysis and catching malware otherwise missed.

·         Whitelisting the maladies
In a highly controlled environment, white listing is a powerful tool against anomalies, including malware. One can end up applying it to Web accesses, software installed on servers and endpoints, and server-to-server communication. Organizations however using Whitelisting must have a fast response capability towards handling exceptions and the rarest of cases.

·         Enhancing the Browser security
With a majority of malware issues spreading via the Web and looking to exploit browser vulnerabilities, a hardened browser environment works towards eliminating such a major threat. With new technologies being regularly released from prominent vendors in the market, a full-proof browser security is no more an invincible prospect. www.pccare247.com

Saturday, 17 December 2011

Phising Attacks: Malafide Intentions Personified

In the times gone by, it was observed financial credentials ended up bearing the brunt of phishing attacks. But Snap!! Coming back to the present, phishing attacks have evolved; targeting sensitive corporate data. A fact evidenced by high-profile data breaches. At the receiving end have been organizations targeted with advanced persistent threats and phishing and spear-phishing emails posing as entry vectors.

Email SupportSo Take Care!! Representing the greatest threat to even the biggest organizations they are there to decimate the best defense put forth by you.

Phishing Attacks high on Adrenaline Rush
The seriousness of phishing threats may sound very theoretical, but a harsh reality is – “phishing attacks are achieving their malicious goals”. Organizations are on the knife’s edge thanks to devastating breaches resulting from phishing and spear-phishing attacks. With attackers leaving no stone unturned to utilize a broad spectrum of technologies and techniques. Highly focused and persistent, often these attacks are considered to be highly opportunistic in their orientation.

Specimens of a Phish Attack
  • Phishing emails sent – employees are not necessarily high profile or high value targets.
  • Email is crafted well enough and even if it is caught by the email security solution employees may be   tricked into retrieving it from their quarantine.
  • The employee then clicks on the URL in the message, initiating a drive-by download of malware.
  • Malware may be designed to coax a desktop machine to reach out to command and control servers.
  • Malware propagates across the network, searching for specific user accounts with relevant privileges (initial entry points/accounts may not have sufficient administrative rights).
  • With sufficient privileges and target systems reached, data is acquired and staged for exfiltration.
  • Data is exfiltrated (extracted outside the organization), typically via encrypted files over available ports – FTP, HTTP, or SMTP. www.pccare247.com

Friday, 2 December 2011

Malware: An ultimate nemesis for SMB’s

Malicious attacks via social networks and through other mediums are considered to be a number one cause for data breaches, surpassing lost or stolen laptops and accidental sharing.


Impacting businesses big time, the costs comprise of detection, remediation, notification efforts, tech support, credit monitoring and legal fees.


Malware SupportIn dire situations, resources are even diverted from other sales, marketing, customer service projects to focus on repair and damage control. With effect, leading the management teams to shift tasks to emergency communication efforts in order to repair customer trust.

But that’s not all, in addition to increased costs; businesses even end up risking the loss of their intellectual property. And if in a situation a cybercriminal were to end up gaining access to a corporate network, the company stands to lose new product development plans, confidential marketing, shareholder information and even its intellectual capital.

SMB’s need to tread with caution
Malware attacks can end up playing havoc with any organization, but for SMBs (Small and Medium-Sized Businesses) the costs are magnified. And in such a situation, the best protection strategy against social networking malware would be to go in for a two-pronged approach: education and technology.

To start with the easiest way to prepare employees against malware would be by means of showing them examples. Say for instance, one could always start by showing screenshots of Facebook scams, Twitter hacks or fake LinkedIn invitations. Yet, at the same time coming up with inclusive quick tips on how to avoid social malware via creation of strong passwords, using only trustworthy news sources and not clicking on questionable links. www.pccare247.com

And yes at the end of the day when employees do up realizing how convincing such attacks might be, giving them a good understanding of how to end up avoiding them.

Source your antivirus judiciously
Only employee education won’t do, for at the end of the day blue-chip business antivirus solutions are considered as an effective solution against social malware. However, as it goes all AV solutions are equal, so the one you should end up choosing should be inclusive of:
  •  A powerful scanning technology. High-quality AV solutions come in good towards analyzing and   detecting potential viruses and malware before they end up infecting user machines.
  •  Active monitoring and protection as a majority of the SMBs don’t have time or resources to constantly monitor their networks for security threats. So, investing in a solution protecting your network and user machines in real time would end up helping big time.
  • Web filtering for malicious elements and blocking bad URLs before they hit the network. This should  be done by implementing a solution using the latest behavioral analysis and malware URL detection technology.

Sunday, 6 November 2011

Beware!! Top 5 Malware Delivery Networks look to prey on unsuspecting netizens

The best of the breed Firewall and Anti-Virus software are bound to fail in front of malware delivery networks comprising of dynamic links and ever changing payload servers. Elements working towards luring innocent netizens by offering them sugar coated baits comprising of online storage solutions and free software downloads. And with those remaining untouched often coming up tagged with categories such as:
·         Search Engines (39.2%)
·         E-mail (6.9%)
·         Pornography (6.7%)
·         Social Networking (5.2%)

Once again driving home the point conventional firewall and anti-virus software would be deemed as incompetent for dealing with dynamic and constantly changing threats. Thus, pushing home the point of employing an intelligent, real-time cloud based Web defense that is dynamic and equally effective at the same time. However, then again coming back to the question of malware delivery networks, on any given day there would be nothing less than 50 operational and highly active malware networks. But since we can’t talk about all of them, herein we are just listing the top 5 networks which may play havoc with any security software.

Take Care!! The evil 5 are still thriving and throbbing
Network Support
Netizens really need to take care; for there are 5 networks still thriving and throbbing which intend to make a huge dent in any security establishment. Well here goes nothing. Starting with:

1.    Shnakule
As the name sounds, equally is the destructive force of this malware network. With a Unique Attacks Hosts tally comprising of 2001 and going up to teach a maximum of 4357, the network in the first half of 2011 nearly drew about 21000 users on an average, with the maximum touching a whopping 51000 users. Broad based in origin, the Shnakule has a number of malicious activities in its kitty; primarily comprising of fake Anti-Virus and Codecs, Fake Flash and Firefox updates, Fake Wares, Botnet commands and controls. With Search Engine poisoning being a major USP of the network, Shnakule has a stake in many categories such as pornography, gambling, pharmaceuticals, link farming and work-at-home scams.

2.    Ishabor
Exclusively devoted to distributing fake anti-virus scareware and comprising of unique attack hosts averaging up to 766 and the maximum touching up a whopping figure of 1140, extensive research revealed Ishabor was riding piggy back on Shnakule from the very beginning to spread around its nefarious designs.  

3.    Cinbric
With unique attack host raking up an average of 505 hosts and going up to touch a maximum of 1602 hosts, Cinbric as a network tends to primarily rely on spam to drive traffic to porn-centric ransomware. At the same time luring users with the promise of exclusive Web cam access, if they were to download and install their software.  

4.    Naargo
Notching up impressive figures of 199 for unique attack hosts and the maximum number going up to as good as 299, even though Naargo is not devoted to malware delivery, the network tends to exhibit a number of shady characteristics; calling for continued tracking and investigation. The network also tends to heavily rely on using spam and search engine poisoning for driving traffic to porn sites.

5.    Vidzeban
Boasting of a significant Russian-language presence, the malware network with its unique attack hosts tallying up to 156 and the maximum tally climbing up to as good as 347, Vidzeban ends up wooing netizens by promising them easy to download and install software. In short, the basic premise on which the network tends to thrive is Search Engine Poisoning. http://www.pccare247.com/pc-security/malware-removal.html

Friday, 21 October 2011

Is Social Networking really an evil or more of a necessity?

The platform of social networking is always ready to embrace one and all. For not only in reality is it a concept where old acquaintances and friends can go ahead and catch up on old times but rather are also at a liberty to opinionate and shop around for some of the most lucrative deals around. 


In fact, as trends would point out social networking as a concept also does well to blur boundaries, increase transparency and create fluidity in almost anything and everything we do. Linking a twelfth of society and growing rapidly, it may be added companies large and small can no longer ignore or even try blocking social networking. In essence, all I can say it is the part of the fabric in which we not only learn but play and work at the same time.

Making sense of social networking
Social Networking Help
The reality is you need to go where your target audiences are and people are more likely to participate in a social media forum than any other venue. Clients, channel partners and employees alike are more or less likely to engage via social media –  in short, it is a way for you to stay connected, gather feedback, recruit, and collaborate. As a result, I can really vouch that supporting social media in any environment readily gives an impetus to innovation, productivity, and accelerated growth which will ensure a business expands well and beyond what is expected.

The Ugly face of Social Networking
In spite of factors such as personalization, the ease with which information can be shared, and the real-time nature of the medium, it might be worth pointing social media also ends up posing significant risks to a business. And following are the top four risks which come tagged along with social networking. Starting with:

·         Malware
With more than 700 billion minutes being spent per month on Facebook alone, social networking sites are fast turning into ideal malware targets. And yes, if statistics would be anything to go by then nearly 40% of users are infected by malware from social networking sites. Typical attacks often stem from the trust relationship established between users and their connections users are tricked into giving up financial information that can be further exploited for financial gain. Some examples of malware are:

o   Phishing: Employing increasingly sophisticated techniques; attackers pose as legitimate social networking connections and try to lure PC users into providing sensitive information, such as your login credentials. Preying on the tendency of most people to use same passwords for all accounts hackers believe PC users are tricked into divulging confidential information related to banking and other financial transactions.
o   Click-Jacking: This concept uses the dynamic nature of social networking and a willingness to click on links from known contacts, and even those ones you don’t know to reach a large audience, cajoling you into revealing private information (e.g. through surveys), collecting hits for ad revenues and eventually allow access to an entire social network.



·         Productivity Loss
Online destinations such as social networking enable you to post and read messages, date, shop, upload or check out videos, and play games. In turn making such platforms an increasingly convenient and engaging target for users, drawing them to spend more and more time and better still at the end of the day making it increasingly challenging for a business to apply control.

·         Bandwidth Consumption
With nearly 40% of employees accessing social networking sites at work, a potential strain on bandwidth ends up acting as a detriment of other business applications.

·         Data Loss
There been cases in which employees have unintentionally posted proprietary software code to social networking sites, exposing sensitive intellectual property. These actions, though unintentional, can potentially violate industry specific regulations, impact reputation, or put an organization at a competitive disadvantage with unprecedented data loss. Just visit any kind of Support for Malware Removal http://www.pccare247.com/pc-security/malware-removal.html

Wednesday, 19 October 2011

Antivirus software: Do you know how it really works?

Antivirus Support

Anytime when our conversation hovers around the word antivirus, we only end up talking about renowned antivirus brands such as Bitdefender, Norton, Avast, Vipre, Kaspersky, Mcafee, Norton and what not (Phew!! I am out of breath for the list is certainly long). Extending the jargon long and not really giving a serious thought as to how the software really works and which brand would end up providing us the best protection against viruses and malware. 

So, just to get you enlightened and save you from the ignominy of becoming a sitting duck for conniving software retailers I would  like to share the detection techniques inherent to any antivirus software and what role they serve in defending your PC.

Virus Detection Techniques and their connotations
• Signature-based detection 
Pro
It is a technique where key aspects of an examined file are utilized to create a static fingerprint of known malware. With the signature representing a series of bytes in the file, this method of detecting malware has become an essential aspect of antivirus tools since their inception. 

Con
However, a major limitation of signature-based detection method lies in its inability to flag malicious files sans any signatures. Keeping this in mind, modern attackers frequently mutate their creations for retaining malicious functionality by changing the file’s signature.

• Heuristics-based detection 
Pro
The technique detects new malware by statically examining files for suspicious characteristics without an exact signature match. The tool might even emulate running the file to see what it would happen if executed, attempting to do so without noticeably slowing down the system. 

Con
Wherever the characteristics end up exceeding the expected risk threshold the tool may classify the file as malware. The biggest disadvantage of heuristics is it can even tag legitimate files as malicious.

• Behavioral detection 
Pro
Considered as a detection method for observing how the program executes rather than merely emulating its execution. The approach of this method is to identify malware by looking for suspicious behaviors and thereby detecting the presence of previously unseen malware on the system. As it is the case with heuristics, actions by such a method aren’t considered as sufficient for classifying a program as malware. 
               
Con
The use of behavioral detection techniques brings antivirus tools closer to the category of host intrusion prevention systems (HIPS) which have traditionally existed as a separate product category.

Though the approaches above are listed under individual headings, the distinctions between various techniques are often blurred. So, to keep up with the intensifying flow of malware samples, antivirus vendors have to incorporate multiple layers into their tools and refrain from relying on a single approach. Ring and Grab Instant Virus Removal Support at +1-855-877-5848, www.pccare247.com

Thursday, 13 October 2011

The Battle for a more Secure OS Rages On

The battle lines have been drawn and both the operating systems are going all out to woo PC users. Moreover, supporters from both the camps are also pitching in to prove as to why their OS has a bigger fan following over the other. However,in the recent past things have started to become more interesting for it seems the onslaught unleashed by the Mac Malware and Trojans has ended up bringing down things to quite an even keel.

Malware Blues: Mac OS Vs Windows
OS Support
The sparring continues with regards to ability of both the OS to resist malware. Mac users have an unflinching belief that their OS has only a fraction of vulnerabilities as compared to Windows. But then again to counter the argument Windows aficionados have a belief the subscriber base for their OS is way too big and the Mac has just got to show only a fraction of the same.



Honey, it’s all in the genes
The follies affecting the Microsoft OS are certainly a result of poor engineering rather a large subscriber base. For when Microsoft Windows 95 was launched, the internet and high-end network connectivity had started to grow by leaps and bounds. The advancement ended catching Microsoft on the wrong foot for the amateur PC users using the OS became too easy a prey for hackers and malware. And yes, if it may be pointed out the insecure coding of the OS did not help matters out much either.

On the other hand the Mac was always recognized for its ability to provide a good baseline security and a safe haven where malware was always kept at bay. But then again in the recent times it seems viruses and Trojans such as OSX.Trojan.iServices.B, has ended up blowing the Mac’s security hoopla to smithereens.    

All the more it seems Mac social engineering attacks have gained momentum in the recent past. However, cybercriminals have also ended up realizing the malware being developed by them ends up promising far less returns and ends up gobbling a huge chunk of their resources. Leading to a conclusion the stakes are way far too less as and where Mac users are concerned. And better still at the end of the day, the malware unleashed by them would end up reaping far better returns if and when a larger population comprising of Windows users was to be targeted.  www.pccare247.com 

Thursday, 29 September 2011

Malware is out there to get you

Malware, Viruses, Trojans as a dreaded trifecta have made the internet an easy and plum target for cyber criminals. And with malware scoring heavily over the other two, organizations are in dire need to take drastic measures for safeguarding their crucial data. For the failure to do so may bring all doomsday theories to life; while at the same time leaving one groping for answers as to what really devoured their data with such nonchalant ease.

The Weapons Creators
·         Zero-day exploit finders  - Wade though software, digging up undocumented  bugs and vulnerabilities

·         Toolkit Authors  - Purchase exploits and build malware using them, before licensing o selling it out to attackers
PCCare247 Malware Support

The Launderers
·         Mules - Figure out ways to transfer or move stolen money to the hands of criminals running malware networks, for a percentage fee.
·         Exchangers - Acquire large amounts of virtual currencies to split and sell in smaller, untraceable quantities.

·         Virtual currency sellers - Sell stolen virtual currencies.

The Attackers
·         Financial data stealers - Either sell your credit card and bank information by the hundreds to other criminals, or use them to make fraudulent transactions on your behalf.

·         Identity Stealers - Steal and user identities, including financial and personal.

·         PPC generators - use infected computers to deliver millions of fake ad clicks on web sites, earning money from ad providers like Google in the process.

The Delivery Amplifiers
·         Botnet herders - A key component of the malware supply chain, herders infect and turn tens of thousands of computers around the world into “zombies”. Controlling them to do anything such as spreading viruses, producing internet traffic or attacking websites.

·         Spammers - Infect millions of unsuspecting users by sending them infected attachments or guide them to infected websites.

·         Phishers - Create fake Web sites for tricking users into revealing their personal information.

·         Black hat SEO - Use illegal techniques to boost search engine rankings of malware removal-hosting Web sites, usually by commandeering botnets

    PCCare247.com Copyright © 2012-2013 by PCCare247 Solutions (P) Ltd.