Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Facebook Anti Malware and Spam

Malware is software that's designed to take unwanted actions on your behalf. This software can collect info from your account, send status updates or messages that look like they're from you, or cover your account with ads that crash your computer. If you think you have malware on your computer, we can help you try to clean it up.

Often when you have malware your account is used to like many Pages and follow a lot of people on Facebook. We recommend reviewing your recent account activity from your activity log. From here, you can delete anything you didn't mean to post and unfollow any people or Pages you didn't mean to follow. 


The behavior of this virus is it will automatically send message to your friends and once your friend will click the link, their account will also be infected by the virus and will send message to their friends. 





Using your desktop computer, follow these 4 steps:



  1. Change your Facebook password.
  2. Scan your computer. Sometimes one virus scan might not be able to fix the problem, so we've partnered with F-Secure, Trend Micro and Microsoft to help. Even if you already have anti-virus software on your computer, we recommend using our free scanners too:
  3. Upgrade your computer's browser. Current versions of browsers have built-in security protection. Facebook supports:
  4. Remove any suspicious browser add-ons.

Antivirus programs don't always look for browser add-ons (extensions, toolbars)--so you will want to check your browser add-ons for anything that seems suspicious and disable it and see if that resolves your issue:

BROWSER/DISABLE ADD-ON TECHNIQUE


IE 7: Open browser. Click "Tools", click "manage add-ons", click "Enable or Disable Add-ons", in the "Show" list click "Add-ons currently loaded in Internet Explorer", click the add-on you want to disable and under "Settings" click "Disable".

IE 8: Open browser. Click "Tools", click "manage add-ons", under "Show" click "All add-ons", click add-on you want to disable, then click "Disable".

IE 9: Open browser. On browser toolbar click the little gear icon, click 'Manage add-ons', in the 'Show:' box change to 'All add-ons', click suspicious add-on to highlight and select 'Disable' in the lower right of window.

GOOGLE CHROME: Open browser. Click customize(wrench) > Tools > extensions > disable add-on desired.

FIREFOX:
Open browser. Click menu > Tools > Add-ons > disable add-on desired.

SAFARI 2.x: From Safari menu select 'Preferences', click the 'Security' tab, uncheck 'Enable Plug-ins', click OK, close and relaunch your Internet browser.

SAFARI 3.x: Click the Safari menu, select 'Preferences', select 'Security' tab, remove check from 'Enable Plug-ins'.

NOTE: The program files for the add-ons are not deleted by the above. They can be re-enabled. To permanently remove the program files on PCs: Start > Control Panel > Add/Remove Programs (on Windows 7 operating system this is 'Programs and Features' folder) > select program and click delete. You will need to restart your computer.
MACs: I am not familiar with how to remove programs from MACs.


It is a good idea to clear your browser history, temporary internet files and cookies also (Start > Control Panel > Internet Options) OR (You can get to Internet Options from the Tools menu on your browser).
You can also use  CCLeaner for that .....


Share this post to help a Friend infected with Malware at Auto-Spam Virus



Ask Toolbar will be marked as “Unwanted Software” (or Malware) by Microsoft’s Security Tools

Microsoft security products will detect programs with browser search protection functionality from June 1, 2015.

Non-compliant programs that exhibit such functionality will be detected by our software signatures that look for browser search protection code. Any program using code that can potentially perform search protection may be detected, regardless of whether the code is active.

To avoid detection, developers should remove any search protection code from their programs, regardless of whether it is functional or not.

We’ll be working with search protection developers and vendors who have completely disabled search protection functionality from their programs in alignment with our evaluation criteria.

Developers and vendors can email mpcreply@microsoft.com to start this process. They should provide links to side-by-side downloadable samples of:

    Any programs with fixed behavior that does not exhibit search protection functionality, but has inactive, dormant search protection code.
    Any older programs that are non-compliant with our evaluation criteria.

MMPC  help reduce the risk of having programs with search protection functionality turned off, but still containing non-compliant code, being detected as developers work on completely removing the non-compliant code.

Ask Toolbar  will be marked as “Unwanted Software” (or Malware) by Microsoft’s security tools Microsoft previously warned it would take action against software that tries to prevent users from changing their browser’s default search engine.

Ask Toolbar has its own special annoyances. When installed it switches your browser’s default search provider to Ask.com, and when you try to switch away it attempts to prevent you from doing so with a pop-up warning. If you’re not careful the toolbar can also reappear the next time you update Java.



Ask’s Toolbar has managed to live on as software bundled with Oracle’s Java for Windows. In March, Oracle also extended the Ask Toolbar download to Macs.

Bundleware is bad enough since even veteran PC users can be tricked into installing unwanted software—especially when you’re multitasking.

Example is Avira bundle with Ask Toolbar.


Microsoft warned that as of June 1 any program containing search protection functionality—code that tries to stop you from changing your browser or default search settings—would be treated as malware.

It appears Microsoft made good on its promise. Microsoft’s Malware Center now lists the Win32/Ask Toolbar as posing a “High threat to your PC.” The Ask Toolbar entry was first published in February, but was updated on Tuesday.

Microsoft’s security products including Windows Defender on Windows 8 and up, and Microsoft Security Essentials for Windows 7 and Vista can now detect and remove the toolbar.


{source} : http://blogs.technet.com/b/mmpc/archive/2015/05/26/detection-changes-search-protection-code.aspx



BEWARE of the SCAM/ SURVEY WEBSITE "rewards-ph"

Puregold, SM, Robinsons Sodexo Followers, please BEWARE of the SCAM/ SURVEY WEBSITE:

To any e-mail message/s that you'll be receiving from business.news@horoscopefree.com
or from rewards-ph.com that tells you:

"Our system tells us that you may be a possible winner with the right to claim a prize:
P20,000 Puregold, SM and Robinsons Gift Certs!
rewards-ph.com - P10,000 Puregold, SM and Robinsons Gift Certs
Please verify your claim as soon as possible as all prizes that are not claimed will be entered into a new draw."




THIS IS NOT AN INITIATED PROMO OF PUREGOLD, SM, ROBINSON, AND SOSEXO

Please ignore this! The following company/store does not have this kind of promo and customers are notified via a call should they be winners in a promo then an email is sent after communicating with the winner.

May this be a WARNING to those who may receive the same type of e-mail message SCAM as what is shown in the pictures.

Please take the necessary precaution!  site is Germany-based and knowing Europe, they could easily get your identity online.When they get your identity they can use that to steal CREDIT CARD ACCOUNT.

According to Whois record of Rewards-ph.com, it is owned by Vincent Jouvin of Planet49 GmbH since 2014. Rewards-ph was registered with PSI-USA INC. DBA DOMAIN ROBOT on July 10, 2014. Vincent Jouvin resides in Sulzbach, Germany and their email is domains@spark5.de.

Almost 1 year na nag sscam etong website na eto, and Pinoy loves Promos they can easily hook up with this kind of scam.

THE BUGOS WEBSITE ALSO POSTED ON LEGIT ONLINE ADS MAKING IT SEEMS LEGIT.

PLEASE SHARE THIS INFO

PUREGOLD POSTED WARNING ABOUT THIS WEBSITE ON THEIR PAGE 2014:
https://www.facebook.com/puregold.shopping/photos/a.114627672151.119291.114161442151/10152681168402152/

source: https://whois.easycounter.com/rewards-ph.com





FBI SEIZED MEGAUPLOAD DOMAINS LINK TO SCAM ADS AND MALWARE

Well over three years have passed since Megaupload was shutdown, but there is still little progress in the criminal proceedings against the operation.

The United States hopes that New Zealand will extradite Kim Dotcom and his colleagues, but the hearings have been delayed several times already.

Meanwhile, several domain names including the popular Megaupload.com and Megavideo.com remain under the control of the U.S. Government. At least, that should be the case. In reality, however, they’re now being exploited by ‘cyber criminals.’

Instead of a banner announcing that the domains names have been seized as part of a criminal investigation they now direct people to a Zero-Click adverting feed. This feed often links to malware installers and other malicious ads.

One of the many malicious “ads” the Megaupload and Megavideo domain names are serving links to a fake BBC article, suggesting people can get an iPhone 6 for only £1.

The Department of Justice has made a grave error as several seized Megaupload domains are now being exploited for nefarious purposes. A few days ago both Megaupload.com and Megavideo.com began directing visitors to scams and malware, presumably because the FBI's cybercrime unit lost control of the main nameserver.

And here is another example of a malicious ad prompting visitors to update their browser.


The question that immediately comes to mind is this: How can it be that the Department of Justice is allowing the domains to be used for such nefarious purposes?

Looking at the Whois records everything seems to be in order. The domain name still lists Megaupload Limited as registrant, which is as it was before. Nothing out of the ordinary.

The nameserver PLEASEDROPTHISHOST15525.CIRFU.BIZ, on the other hand, triggers several alarm bells.




CIRFU refers to the FBI’s Cyber Initiative and Resource Fusion Unit, a specialized tech team tasked with handling online crime and scams. The unit used the CIRFU.NET domain name as nameserver for various seized domains, including the Mega ones.

Interestingly, the CIRFU.NET domain now lists “Syndk8 Media Limited” as registrant, which doesn’t appear to have any connections with the FBI. Similarly, CIRFU.BIZ is not an official CIRFU domain either and points to a server in the Netherlands hosted by LeaseWeb.

It appears that the domain which the Department of Justice (DoJ) used as nameserver is no longer in control of the Government. Perhaps it expired, or was taken over via other means.

As a result, Megaupload and Megavideo are now serving malicious ads, run by the third party that controls the nameserver.

This is quite a mistake for one of the country’s top cybercrime units, to say the least. It’s also one that affects tends of thousands of people, as the Megaupload.com domain remains frequently visited.

Commenting on the rogue domains, Megaupload founder Kim Dotcom notes that the people who are responsible should have known better.

“With U.S. Assistant Attorney Jay Prabhu the DOJ in Virginia employs a guy who doesn’t know the difference between civil & criminal law. And after this recent abuse of our seized Mega domains I wonder how this guy was appointed Chief of the Cybercrime Unit when he can’t even do the basics like safeguard the domains he has seized,” he tells TF.

“Jay Prabhu keeps embarrassing the U.S. government. I would send him back to law school and give him a crash course in ‘how the Internet works’,” Dotcom adds.

Making matters worse for the Government, Megaupload.com and Megavideo.com are not the only domain names affected. Various poker domains that were previously seized, including absolutepoker.com and ultimatebet.com, also link to malicious content now.

While the Government appears to have lost control of the old nameservers, it can still correct the problem through a nameserver update at their end. However, that doesn’t save those people who had their systems compromised during recent days, and it certainly won’t repair the PR damage.






Here's How to Hack digital pictures to send malicious exploits

The next time someone sends you a link to picture, be it that of a funny cat or a beautiful sunset, be careful before you click on it—it might hack your computer.

That image might look just like another regular image, but thanks to a technique devised by Saumil Shah, a security researcher from India, a hacker could hide malicious code inside the picture’s pixels, literally hiding an exploit in plain sight.

The malicious code, dubbed IMAJS, is a combination of both image code as well as JavaScript hidden into a JPG or PNG image file. Shah hides the malicious code within the image’s pixels, and unless somebody zoom a lot into it, the image looks just fine from the outside.

The technique is called “Stegosploit” and Shah gave Motherboard a demo of the technique ahead of the talk he gave on Thursday at the Amsterdam hacking conference Hack In The Box.

Shah has found a way to hide malicious code directly into an image using steganography, an ancient technique that consist of stashing secret text or images in a different text or images. In this case, the malicious code or exploit is encoded inside the picture’s pixels, and it’s then decoded using an HTML 5 element called Canvas, which allows for dynamic rendering of images. Shah calls it the “magic sauce” behind Stegosploit.



This way, Shah said, all he needs to hack someone is an image file, nothing more.

“I don’t need to host a blog, I don’t need to host a website at all. I don’t even need to register a domain,” Shah told Motherboard during the demo last week. “I can take an image, upload it somewhere and if I just point you toward that image, and you load this image in a browser, it will detonate.”

The malicious code, which Shah calls “IMAJS,” is a mix of image code and javascript hidden into a JPG or PNG file. Shah hides the code within the picture’s pixels, and from the outside, unless you zoom a lot into it, the picture looks just fine.

Shah, who’s been working on this research during his spare time for almost five years, showed me exactly how it works using my own profile picture in a Skype demo. He then prepared a demo video for Motherboard using his own picture as the guinea pig.



In the first video, embedded above, Shah shows step by step how he is able to hide malicious code inside an image file, using steganography.



In this second video, Shah shows how Stegosploit actually works. He has programmed the image to run the exploit when the target opens the image on his or her browser (this technique only works in browsers) and clicks on it (he could program it to run it when the image is loaded too).

Once the target clicks on the image, you can see the computer’s CPU shooting up to 100 percent usage, indicating the exploit worked. The malicious code then sends data from the target’s computer back to the attacker, and creates a text file on the target’s computer that says: “You are hacked!”

I asked Shah to make that text file to theatrically show that a hacker could do practically anything he wants on a victim’s computer using his technique. Shah, however, could have programmed the malicious image to do something more stealthy, such as downloading and installing spyware, or pilfering data out of the victim’s computer.

For him, the big takeaway here is that image files should not be “presumed innocent” anymore. They can hide malicious code just like PDFs or other types of files that are typically used to deliver an exploit.

Patrick Wardle, the director of research at Synack, who has previously worked at the NSA, said that Stegosploit would be a good way for attackers to bypass detection on some image sharing websites, though advanced scanners should be able to detect an image that contains malicious javascript code.

In any case, for these techniques to work, an attacker still needs to take advantage of a vulnerable (in other words, unpatched) browser, and an exploit that can take advantage of that, according to Ken Westin, a senior analyst at web security company Tripwire.

Shah himself hasn’t fully tested his technique on known image sharing sites such as Imgur or Dropbox, and he admits that it might not work everywhere. The malicious file has to be uploaded without an extension for the browser to be tricked into rendering it, and some sites, such as Dropbox, don’t allow that. Moreover sites like Facebook reprocess the images when they are uploaded, causing the loss of the malicious code, according to Shah.

"These techniques are coming, sooner or later."
You should not presume the image files as "innocent" anymore, as they can hide malicious code deep inside its pixels that could infect your computers.
In other words, this is not an easy technique to reproduce, and there’s no evidence it’s been used in the wild yet. Still, Shah believes it’s just a matter of time and that “these techniques are coming, sooner or later.”

“You’re never the only one to figure things out,” he said during our conversation. “I’m the only one talking about it on stage but I’m sure there are other people that have figured this out."




Rombertik Malware Auto Destroy Hard Drive When Detected

A new type of malware resorts to crippling a computer if it is detected during security checks, a particularly catastrophic blow to its victims.

The malware, nicknamed Rombertik by Cisco Systems, is designed to intercept any plain text entered into a browser window. It is being spread through spam and phishing messages, according to Cisco’s Talos Group blog on Monday.

Talos’ goal is to protect our customer’s networks.  Reverse engineering Rombertik helps Talos achieve that goal by better understanding how attackers are evolving to evade detection and make analysis difficult.  Identifying these techniques gives Talos new insight and knowledge that can be communicated to Cisco’s product teams.  This knowledge can then be used to harden our security products to ensure these anti-analysis techniques are ineffective and allow detection technologies to accurately identify malware to protect customers.





 Rombertik has been identified to propagate via spam and phishing messages sent to would-be victims.  Like previous spam and phishing campaigns Talos has discussed, attackers use social engineering tactics to entice users to download, unzip, and open the attachments that ultimately result in the user’s compromise.

While this file may appears to be some sort of PDF from the icon or thumbnail, the file actually is a .SCR screensaver executable file that contains Rombertik.  Once the user double clicks to open the file, Rombertik will begin the process of compromising the system.

Rombertik goes through several checks once it is up and running on a Windows computer to see if it has been detected.

That behavior is not unusual for some types of malware, but Rombertik “is unique in that it actively attempts to destroy the computer if it detects certain attributes associated with malware analysis,” wrote Ben Baker and Alex Chiu of the Talos Group.

Once loaded into the system, Rombertik first runs a series of anti-analysis checks to determine if it is running within a sandbox.
In case it isn’t running within the sandbox, Rombertik decrypts and installs itself on the victim's machine, which then allows the malware to launch a second copy of itself and overwrite the second copy with the malware's core spying functionality.


After completing this process and before begins spying on users, Rombertik runs a final check to make sure it is not being analyzed in memory. In case it finds any indication of being analyzed, the spyware attempts to destroy the master boot record (MBR) of the vulnerable computer.
Rombertik then restarts the machine, and because now the MBR is missing from the hard drive, the victim’s computer will go into an endless restart loop.

MBR is the first sector of a computer’s hard drive that the system looks for before loading the operating system. However, deleting or destroying MBR involves re-installing of operating system, which means valuable data is lost.
In cases where the malware is under the microscope of security experts or any rival malware author, Rombertik will self-destruct itself, taking the contents of a victim's hard drive along with it.

Security researchers reverse-engineered the malware and found that Rombertik contains volumes of "garbage code" that have to be analyzed. The researchers were able to capture a small sample and found that…
...the unpacked Rombertik sample was 28KB in size while the packed version is 1264KB, including 75 images and 8,000 functions that are never used.
Rombertik other Tricks involve:
Moreover, Rombertik keeps itself in sandboxes by writing a random byte of data to memory 960 million times in an effort to overwhelm analysis tools that try to detect malware by logging system activity.

"If an analysis tool attempted to log all of the 960 million write instructions, the log would grow to over 100 gigabytes," researchers explained in a blog post.

"Even if the analysis environment was capable of handling a log that large, it would take over 25 minutes just to write that much data to a typical hard drive. This complicates the analysis."

Data wiping and Self-destructing malware:

Data wiping and self-destructing malware are not new. In last three years, we have seen a hike in malware evasion capabilities.
Wiper malware was used against South Korean banks and TV broadcasters in 2013 as well as against Sony Pictures Entertainment last year, which marked history in a massive data breach.
Also last year, the German Aerospace Centre was targeted by a self-destructive malware in an espionage attack, believed to be conducted by China.




Older Post ►
 

Copyright 2011 Gadgets Technology is proudly powered by blogger.com