Category: Malware/Trojans

  • PS Guard Removal

    PS Guard is viscious scareware that loads itself each time you attempt
    to unistall it.  It is malware that claims to be malware
    remover.  It disables your Task Manager, informs you that your
    system is infected and doesn't allow you to exit from it while it scans
    your computer for viruses.

    Removing PS Guard
    it is a bit tricky.  Adaware and Hijack this will do nothing to
    remove it.  Noahdfear over at GeekstoGo.com wrote a sweet little
    script to remove it called smitrem.  It does the trick in removing PS Guard

    I picked it up at some Russian warez site on my Honeypot sytem.

  • Surfing with an Admin account or How to Get Owned

    Martin McKeay over at mckeay.net is has good methods of securing his home network:

    I'm a strong believer in the 'rule of least privileges' as my wife and children well know; at least once a week I get called over to the kids computer to log in as administrator and install some program for them. The kids have gotten used to it, but my wife hasn't and she's forgotten that I gave her the adminstrator password.

    The reason it is a great idea to use the least priveleges possible and not go surfing the net with Admin priviledges is that if you (or anyone on your computer with admin priviledges) hit an exploit site that downloads something on your system, it will do so with your administrator permissions. 

    It is best to surf the web with an account that does not have permission to download anything from the web, with elevated security features on Internet Explorer (cookies and java scripts turned off).  In fact, just use and patched version of Firefox. 

    More Security on Internet Explorer

    You can increase security feature of IE by going to Tools | Internet Options | Security tab.  Adjust the trust you have for the Internet by adjusting the level on the slider in the “Security Level for this Zone Area.” 

    If you surf the web with an administrator account without a firewall not only will you more than likely get hit with a trojan and worms you will give the masters of these products elevated priviledges to your system as they will install code in the C:\Windows\System32 – also known as root. From root a criminal hacker can do practically anything they want with your computer (including install a keylogger that copies everything you type and send the data back to some IRC room on the Internet.)

    In layman's terms, they will OWN your ass.  

    If your really paranoid: 

    Customize your selected security levels by clicking the “Custom Level” button inthe “Security Level for this Zone Area.”  Disable Active X, and Java to completely destroy the ability of malicious mobile code to affect Internet Explorer (unless its already on your system).  This will impare your ability to expirience anything beyond text.

     

  • 40 Million Credit Card Numbers Stolen – CardSystem Solutions Incompetence

    CardSystems Solutions moronic security efforts have resulted in the potential theft of information for 40 million credit cards. Hackers were able to install a rogue program, probably a Trojan, in the CardSystems security network. This program captured credit card information including the cardholder’s name, account number and verification code.

    CardSystems Solutions is an Atlanta-based company. Prior to this incident, it processed approximately $15 billion dollars in credit card transactions each year. Small businesses were the primary users of the system.

    The FBI and MasterCard International have launched investigations into the hack. It has become apparent CardSystems Solutions should be charged with gross negligence. The company failed to comply with MasterCard security regulations and failed to destroy the information of cardholders after prescribed time periods.

    In a matter of gross incompetence, CardSystems failed to encrypt any of the credit card data for users. This is the equivalent of your bank sending monthly account statements will all the information printed on the outside of the envelope. It is simply inexcusable and has led to potentially the biggest theft of financial information in history.

    Which Credit Cards?

    The incompetence of CardSystems Solutions will have an impact on every major credit card group. Estimated numbers range from about 20 million Visa cards exposed to 14 million MasterCard credit cards. As many as 4 million American Express and Discover accounts were also put on the sacrificial altar by CardSystems.

    What You Should Do

    You should review all charges on credit card statements over the next 12 months. Contrary to popular belief, hackers typically will not go out and charge up thousands of dollars on the card. Instead, you should look for small charges of $10 to $20 from companies with bland names. Hackers know that many people will not call to reverse a small charge. Don’t be lazy! Closely inspect your statement and contest any charges that aren’t familiar.

    Closing

    How big is this hack? There are approximately 300 million people in the United States. 40 million accounts equates to 1 in every 7.5 people. Yes, people carry multiple credit cards, but it is still a huge number. CardSystems Solutions should pay a heavy price for its incompetence. Frankly, it should be liquidated. There is little doubt the major credit card companies will take action.

    Richard Chapo, Esq., is a business lawyer with http://www.sandiegobusinesslawfirm.com – offering legal advice to San Diego businesses. This article is for general education purposes and does not address every facet of the subject matter. Nothing in this article creates an attorney-client relationship

  • 5 Simple ways to keep your computer secure and virus free

    These simple tips will help you stay virus and spyware free, even if you're connected to the internet 24 hours a day.

    1. Protect yourself

    Good protection on the Internet these days consists of 3 components: anti-virus software, anti-spyware software and a firewall.

    Good virus protection doesn't need to cost you a fortune. You can get excellent free anti-virus software at www.grisoft.com. Even the professional version of their software is very affordable.

    For spyware protection, go to www.lavasoft.de and download Ad-Aware SE Personal, also free. This will zap the most common spyware and adware found on the Internet.

    As for a firewall, Windows XP ships with a decent enough firewall. Just make sure it is always enabled. Alternatively you can visit a site like www.download.com and search for Zone Alarm, which has an excellent free version.

    The most important thing to keep in mind is that you need to keep your anti-virus software up to date. An anti-virus program that uses definitions that are months old is just about useless.

    Update your anti-virus and anti-spyware software at least once a week.

    2. Stop opening every attachment you receive.

    Most of the devastating worms and viruses of recent times were distributed via email. These viruses feed on the curiosity and also the ignorance of a huge number of email users. People will get an email from fakename@weirdsuspiciousdomain and they'll just open whatever file is attached to it.

    If you don't know the sender, don't open the attachment – just delete it. It doesn't matter if the subject promises you'll see Britney Spears dancing nude on the kitchen table, just delete it.

    If the email is from someone you know, always scan any attachments first before downloading or opening them.

    If every email user in the world followed these simple guidelines the distribution of viruses via email will grind to a halt.

    3. Stay clear of pornographic and illegal software sites

    *I know, I know… Why on earth go on the Internet if you can't have your porn and download it too?!  There are safe Porn sites but we will not address those in this blog… sorry.. Fark has some pretty good links to decent smutt.*

    If you want to pick up viruses and spyware quickly, visit some pornographic web sites. One wrong click on a subtle little pop-up or security warning window (which you'll run into often on these type of sites) and you'll have infested yourself with trojan horses, spyware, dialers and other unfavorable software that could leave your computer wide open to further attacks.

    The same goes for web sites distributing software, serial codes and cracks illegally (warez).

    Simply put – keep out of the dark side of the web and the odds of keeping your computer clean shifts decidedly in your favor.

    4. Watch out what you download

    Spyware is embedded in a lot of software on the Internet – especially those related to ripping, converting and playing music and videos. That free MP3 player or DVD Ripper you just downloaded may have installed a bunch of harmful spyware without you even knowing about it.

    5. Keep yourself informed

    Major anti-virus software developers like Symantec and Grisoft updates their sites regularly with the latest virus alerts. Visit these sites frequently to keep yourself aware of what threats are doing the rounds and how to avoid them.

    Using these simple and software I have kept my computer virus-free for the past 3 years. It's not rocket science. Just stay alert, use some common sense and you too can stay bug free while still enjoying your Internet experience.

     

    Tips on Broadband Security –>

    http://elamb.blogharbor.com/blog/BroadbandInternetSecurity

    Get rid of Trojans Smithfraud/HWclock.exe

  • Insecurity at Black Hat: antivirus vulnerabilities

    This is the reason I manually remove many of the viruses that I've gotten.  For one thing they sometimes don't recognize the virus and until the anti virus software creators update the signature file and for another thing experts are warning that the popularity of antivirus software could turn the defensive measure into a security risk.

    read more | digg story

  • Finding Anit Virus, Anti Spyware Resources

    The whole arena of spyware intrusion is extremely fluid with the
    spyware writers trying to outsmart everyone, and the software
    protection writers diligently working to keep up with the hundreds of
    new worms and viruses appearing nearly every day.

    Fortunately, there are generous individuals and organizations who
    have the facilities to review the work of the Anti-spyware developers
    and make the results available for all of us everyday users of the
    Internet.

    The challenge for us is to know where to go for these results and
    recommendations, and to know which of the anti-spyware and anti-virus
    programs to use on our computers.

    There are many web masters, newsletter, and Blog publishers who
    constantly monitor the results published by the anti-spyware reviewers.
    Most of them pass these information alerts on to their readers and
    subscribers, often offering suggestions and advice based on their own
    personal experiences and expertise.

    A real benefit for us is that most of the top rated anti-spyware
    and anti-virus programs are free, or available in Trial or Demo
    versions.

    All we need do is find out where to get them. But first, we need to find the reviewers who post the alerts.

    If subscribing to newsletters and Blogs isn't your usual surfing
    activity, you can do a search for security alert newsletters or
    security alert blogs. For example, do a Yahoo search for “security
    alert newsletter” (use the quotation marks to get the most appropriate
    search results). Do the same for a Yahoo or Google search on “virus alert blog”. (Blogs are web logs).

    Investigate the first and second pages of the search results and
    select three or four of the listings as a starting point. Many
    newsletters are published on a monthly schedule and may not contain the
    most current information. Some are published weekly. They may be better
    choices.

    Blogs are usually much more current since Blog authors often post
    their information every couple of days – some even on a daily basis.

    Blogs are riding a major wave of popularity. For the serious
    searchers of current information, this is a great benefit. There aren't
    as many Blog sites as web sites yet, so it's often much easier to find
    the information you're looking for.

    Many Blog authors make their publications available for RSS (Real
    Simple Syndication) readers. If you have added a RSS reader to your
    browser, you can get up-to-the-minute alerts presented to you
    automatically. You don't need to go looking for them.

    Many updated browsers, like Netscape 8 and Firefox include this
    feature as part of their package. Expect the newest Internet Explorer
    to have a RSS Reader, too.

    Don't be overwhelmed by all of the information you get. After doing
    these searches and reviews once or twice, it will be a simple task to
    select what you need to keep yourself current.

    For starters, it is generally accepted practice to select and use
    at least two anti-spyware programs. Choose from among the two or three
    that receive the highest recommendations and ratings from the
    newsletter and Blog authors. Be especially watchful for and select one
    of those programs that provides 'Real Time' monitoring. (Which means
    that they monitor and catch any incoming bugs that may try to infect
    your machine while you are online).

    Downloading instructions are nearly always present with the
    reviews. If not, you'll find sites like c|net.com to be a good source
    for download links.

    Just don't forget to check for and update your security software. The spyware writers won't give you a break if you do.

  • Importance of applying security to your system

    This is an update on my first post about the removing the trojan called smithfraud.  I help my friend get rid of the trojan and had the system purring, but shortly after he got back on the Internet with no protection and got hacked again.  This time worse then before.  Not only did he get smithfraud AGAIN but he got some crap I never even heard of.  I may have to wipe his entire hard drive.

    I constantly tell him how important it is to secure your system even if your on dial-up.  Just having Sp2 for XP is not enough.  I recommend at least a firewall

    If you have a broadband connection check out my walk through on securing broadband Internet connections.

  • Remove the HWCLOCK.EXE/W32.Hwbot-A Trojan

    I got the HWCLOCK.EXE when I was testing my new Internet connection.  I noticed it when my Internet DSL connection started feeling like a  56K dialup. 

    I removed it by going into Showing all files, going into Safe Mode and deleting the HWCLOCK.exe/W32.Hwbot-A Trojan.

    This is a trojan that can actually steal your passwords and other personal data.  On my system is was attacking other system.

    I've got more detail instructions on how to remove the HWCLOCK.exe at http://elamb.blogharbor.com/hacked/hwclock.htm

    If you found this post or others useful, feel free to donate to

    elamb – Home Computer Security.  No amount is too low (or high).

  • Removal of TROJAN-SPY.HTML.SMITFRAUD.C

    A lot of people seem to have the Smitfraud trojan and seem to looking all over the place to get a fix.  So I've consolidated the best resources that I've found on the Smithfraud this blog.  Enjoy.

  • Trojan_Agent.go

    New Trojan Agent Go

    Is a memory-resident trojan that comes through via downloads from malicious web sites.  It executes files from other websites.

    Remove Trojan_Agent.go:

    Open Task Manager:
    Use CTRL+ALT+DELETE or
    CTRL+SHIFT+ESC (on XP), then click the Processes tab.

    locate the process:
    EVTHTM.EXE

    Select the EVTHTM.EXE process, then press either the End Task or the End Process button, depending on the version of Windows on your system.

    1. To check if the malware process has been terminated, close Task Manager, and then open it again.
    2. Close Task Manager.

    If the process does not shutdown, Go to Safe Mode and shut it down.

     

    Recources:

    TrendMicro

    PCHELL