Monday, February 12, 2007

SpyCrush Is Another Fake Antispyware Program

I've been busy with real life and haven't posted much over the last few months, but the bad guys have been busy. SpyCrush is the latest in the line of fake spyware removal programs that try to trick you into buying it. The same people who make the program are the ones who put the spyware on your computer. Other programs like this include SpywareQuake, SpyFalcon, SpywareStrike, SpySheriff and many others.

Besides the pop up warnings and other advertising trying to get you to buy it, you'll see this line in a Hijackthis log:

O4 - HKLM\..\Run: [SpyCrush] C:\Program Files\SpyCrush\SpyCrush.exe

Smitfraudfix has been updated to remove this pest, so you can use the removal instructions here. Alternative fix is posted at Bleeping Computer. Information about spycrush.com and how the program SpyCrush resembles and older rogue VirusBurst located at Security Cadets.

Sunday, February 11, 2007

Winpatrol 2007 for Vista

I'm a big fan of Winpatrol and wouldn't even consider running my PC without Scotty sitting in my task bar, keeping an eye on things for me.

BillP Studios have been busy testing a new version of Winpatrol and the full and final version is due for release tomorrow. Winpatrol 2007 is fully Vista compatible and has a great new feature called Delayed Start.


You probably have programs which you do want running in the background but you
don’t need to launch immediately on boot up. WinPatrol’s Delayed Start allows
you to specify the time to wait before launching programs which may typically
try to load while other system initialization are happening.
If you use
Vista's UAC(User Access Control), you may find some startup programs require
your permission before they can begin. Moving these programs to our Delayed
Start list can prevent simultaneous annoying systems pop ups.

The free Winpatrol version is fully functional and will provide you with all the protection that the Plus version gives you, however I do recommend that you upgrade to the Plus version, see here for comparisons.

Keep up with Winpatrol happenings at Bits From Bill

Thursday, February 08, 2007

MS Security Bulletin, Advance Notification for February

Microsoft have released an advance notification for the updates that are due to be released next Tuesday.

Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 13 February 2007 Microsoft is planning to release:

Security Updates

  • Five Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. Some of these updates will require a restart.
  • Two Microsoft Security Bulletins affecting Microsoft Office. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
  • One Microsoft Security Bulletin affecting Microsoft Windows and Microsoft Visual Studio. The highest Maximum Severity rating for this is Important. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. These updates will require a restart.
  • One Microsoft Security Bulletin affecting Microsoft Windows and Microsoft Office. The highest Maximum Severity rating for this is Important. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
  • One Microsoft Security Bulletin affecting Step-by-Step Interactive Training. The highest Maximum Severity rating for this is Important. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. These updates may require a restart.
  • One Microsoft Security Bulletin affecting Microsoft Data Access Components. The highest Maximum Severity rating for this is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. These updates may require a restart.
  • One Microsoft Security Bulletin affecting Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft ForeFront. The highest Maximum Severity rating for these is Critical. These products provide built-in mechanisms for automatic detection and deployment of updates. Some of these updates may require a restart.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.
    Note that this tool will NOT be distributed using Software Update Services (SUS).
Non-security High Priority updates on MU, WU, WSUS and SUS
  • Microsoft will release two NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
  • Microsoft will release eight NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
Microsoft Security Bulletin Advance Notification

Microsoft will also be hosting a webcast on Wednesday February 14th 11:00 AM Pacific Time (US & Canada), for attendees to ask questions about the bulletins and get answers from the security experts.

Tuesday, February 06, 2007

Safer Internet Day 2007

Today is Safer Internet Day.

Almost 40 countries will participate in the fourth edition of Safer Internet Day (SID) which this year takes place on 6 February. The event is organised by European Schoolnet, coordinator of Insafe, the European safer internet network (www.saferinternet.org). Viviane Reding, EU Commissioner for the Information Society and Media is once again patron of Safer Internet Day, as in the past two years.

The highlight of the day will once again be a worldwide blogathon, which will reach Australia on 6th February and progress westward through the day to finish up in the USA and Canada. Following the huge success encountered in 2006, this year's blogathon goes one step further to include the voices of hundreds of youngsters. In the framework of a competition launched in October 2006, more than 200 schools in 25 countries across the globe have been working in pairs, using technology to cross geographical borders, to create internet safety awareness material on one of three themes: e-privacy, netiquette, and power of image. On Safer Internet Day, all of the projects they have produced will be uploaded to the blogathon.

Links for more information and activities below;

Blogathon
Insafe Safer Internet Day 2007
EIS Safer Internet
BBC Technology Pages
EGov Monitor
The Register


Monday, February 05, 2007

Parental Controls in Vista

One of the exciting new features available in Windows Vista are the Parental Controls. These controls will help you, as a responsible parent, to allow your children to use the technology that is available for them in a safe and monitored environment.

Of course, as with anything that is new to us, getting our heads around how to actually use it can be a bit daunting. My friends at Bleeping Computer have just produced a great guide that will hopefully take a little of the head scratching out of setting up your Parental Controls.

With the launch of Windows Vista, Microsoft has introduced a new security feature called Windows Parental Controls. Windows Parental Controls allows a parent to configure, on a per user basis, various restrictions on what that user can do on the computer. These settings range from blocking websites to controlling what games they can play. Having access to these types of controls allows a parent to feel comfortable with their children using a computer and at the same time gives them the flexibility to customize these settings to their specific needs.

It is important to note that not all programs are compatible with Windows Parental Controls. In order for Windows Parental Controls to properly monitor and control certain activities on the computer, the application must be compatible with this new service. For the most part, most of the settings can be enforced across all applications, but it is important to test these controls using the applications that your users will be using. This way you know for sure that any restriction you put into place can be enforced. It is also important to note that Windows Parental Controls can only be assigned to a Standard User, which is a user with limited rights on the computer, and cannot be assigned to accounts that are configured as an Administrator. This is so a user cannot remove restrictions placed on them.

One of the more powerful features of this new service is that you will be able to view reports of the activity for each user that you have configured Parental Controls. The information you see will be determined by whether or not the user is using applications that are compatible with Windows Parental Controls. Assuming that all the applications are compatible you will be able to monitor the following activity.

  • Most recent websites blocked.
  • Attempts to visit sites that have been specifically blocked or allowed.
  • What files were downloaded.
  • What file downloads were blocked.
  • When the user logged on.
  • What programs they have run.
  • Emails sent and received
  • Instant Messages sent and received.
  • What games were played.
  • What media such as movies and videos were played.

For the full tutorial, please visit Setting up Windows Vista Parental Controls

Friday, February 02, 2007

Trojans Go to Superbowl XLI

The web site for Dolphin Stadium, where Super Bowl XLI will be played, got hacked and malicious code was added to it, Websense Security Labs reports . The web site for the Miami Dolphins, who play in Dolphin Stadium, also was attacked and infected with the same malware. The hackers changed the web page so it downloaded a file called w1c.exe to your computer. If your computer is not up to date on Windows security updates, then the hackers could get complete control of your computer. The good news is that all of the web sites have been fixed and are no longer offering the trojan.

The web sites that were affected are:
Dolphinsstadium.com
Dolphinstadium.com
Proplayerstadium.com
MiamiDolphins.com

You are vulnerable if you haven't installed these security updates MS06-014 and MS07-004 from Microsoft. If you are not sure if you are up to date, then visit Windows Update and select the express install to get your computer fully updated.

At the time of this post, the files that attack your computer are not detected well by most spyware and antivirus programs. Some of the files that attack your computer from this exploit are w1c.exe, msmsgs.exe, ADupdate.exe, 1.exe and 3.exe. These files and others have been submitted to the security companies, so they should be added to detection databases in the coming days.

Wednesday, January 24, 2007

Want To Know More About Rootkits?

I'm very very proud to announce the publication of Rootkits For Dummies.

Some friends of mine have been working very hard on this book for quite a while now and it is fantastic to see it finally in print. Here is a bit of blurb for you.

Product Details

Authors: Larry Stevenson and Nancy Altholz
Tech Editor: Lawrence Abrams

Forensics Advisor: Dave Kleiman
Media Advisor: Mahesh Satyanarayana (swatkat)
Firefox Advisor: Abdul-Rahman Elshafei (AbuIbrahim),
Firewall Advisor: Allen C Weil (PCBruiser),
IE7 Advisor: Bill Bright.
Rootkit Research Team: Don Hoover (Hoov), James Burke (Dragan Glas), Anil Kulkarni (wng_z3r0), wawadave, and Michael Sall (mrrockford).

ISBN: 0471917109
ISBN-13: 9780471917106
Format: Paperback, 384pp
Publisher: Wiley, John & Sons, Incorporated
Edition Description: BK&CD-ROM
Series: Dummies Series

This book provides a thorough introduction to the topic of rootkits-- what they are, how to detect them, how to dispose of them and how to know when the best thing to do is to wipe your system clean and start all over, and how to mitigate damage if it's possible.

The CD will include several important tools for detecting rootkits, conducting forensic analysis, and making quick security fixes is like an emergency first-aid kit for network administrators and regular users.

I've already ordered my copy from Amazon. :-)


Friday, January 19, 2007

Beware the Storm Worm

Over the last few days we have suffered some severe weather in the UK, yesterday was truly horrendous with winds of up to 99 miles per hour causing 11 deaths, many injuries and millions of pounds worth of damage.

If that wasn't bad enough, it seems that the bad guys took advantage of this and sent out a mass email attack with a trojan horse attatchment with the subject line, "230 dead as storm batters Europe."

As reported by TechRepublic;

"Storm Worm," one of the larger Trojan horse attacks in recent years, is baiting people with timely information about a deadly, real-life storm front, security researchers said Friday.

Over an eight-hour period Thursday, malicious e-mails were sent across the globe to hundreds of thousands of people, said Mikko Hypponen, chief research officer for F-Secure.

People who open the attachment then unknowingly become part of a botnet. A botnet serves as an army of commandeered computers, which are later used by attackers without their owners' knowledge.

Storm Worm carries the subject line "230 dead as storm batters Europe," Hypponen said, noting the unusual twist to the e-mail.

"The e-mail was started 15 hours ago, when the storm was peaking in Central Europe," Hypponen said. "This is unusual in that it was very timely."

Storm Worm is a Trojan horse with an executable file as an attachment. Cybercriminals took advantage of social engineering, using the news of the European storm to get people to open the attached malicious file, which promises more news on the weather emergency. The recipient must open the file for it to execute.

The file creates a back door to a computer that can be exploited later to steal data or to use the computer to post spam.

Email to watch out for;

Subject
230 dead as storm batters Europe
U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel
A killer at 11, he''s free at 21 and kill again!
British Muslims Genocide

Attachment
Read More.exe
Full Clip.exe
Full Story.exe
Video.exe


Monday, January 15, 2007

A-Squared False Positive - winlogon.exe

If you are a devotee of the excellent A-Squared anti malware scanner then you might have got a bit of a shock if you ran a scan today.

The legitimate winlogon.exe file has been identified as a trojan, this has been confirmed as a false positive however and it will be fixed in the next update. See Emisoft forums for more details.

Friday, January 12, 2007

Spybot Search and Destroy January 12th

Spybot Search & Destroy - http://spybot.info/en/updatehistory/index.html

2007-01-12
Adware

+ NSIS Media Extension
Dialer
+ Cassava
Malware
+ Fakealert + Hitvirus + Leena + Look2Me + PornWebTV + Smitfraud-C.AntiFirewall + SpyFalcon + SpyGuard + SpywareBot + TrustCleaner ++ Win32.VB.dm + Zlob.KeyGenerator (2)
PUPS
+ AdwarePunisher + Hotbar + MyWay.MyWebSearch + Oska.Deskmates + SpywareKnight
Spyware
+ SVerner.Search
Trojan
+ AnotherBOT + ConHook + Innovagest2000.SpyDeface + Kuasio.Ka + Troj.PrintSpool + Win32.Agent.Acz + Win32.Gadu + Win32.Microjoin + Win32.Small.avq + Win32.Small.cyh + Zlob.DirectVideo (2) + Zlob.SiteTicket + Zlob.VideoAccess (2) + Zlob.VideoActiveXObject ++ Zlob.VideoCodec2007
Total: 348611 fingerprints in 58163 rules for 2611 products.

Friday, January 05, 2007

MS Security Bulletin, Advance Notification for January

Microsoft have released an advance notification for the updates that are due to be released next Tuesday.

Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 9 January 2007 Microsoft is planning to release:

Security Updates

  • One Microsoft Security Bulletin affecting Microsoft Windows. The highest Maximum Severity rating for this is Critical. This update will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. This update will require a restart.
  • Three Microsoft Security Bulletins affecting Microsoft Office. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
Microsoft Windows Malicious Software Removal Tool
  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.
    Note that this tool will NOT be distributed using Software Update Services (SUS).
Non-security High Priority updates on MU, WU, WSUS and SUS
  • Microsoft will release No NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
  • Microsoft will release two NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
Microsoft Security Bulletin Advance Notification

Microsoft will also be hosting a webcast on Wednesday January 10th 11:00 AM Pacific Time (US & Canada), for attendees to ask questions about the bulletins and get answers from the security experts.

Wednesday, January 03, 2007

Windows Defender (beta2) Has Expired

Windows Defender Beta2 expired on 31st December, please make sure you upgrade to Windows Defender Final.

Windows Defender is a free program that helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software. It features Real-Time Protection, a monitoring system that recommends actions against spyware when it's detected and minimizes interruptions and helps you stay productive. Now with 2 free support incidents for Windows XP and Windows Server 2003.

Note: If you have version 1.1.1592.0, you must first manually uninstall Windows Defender before you can install this newer version. To configure or remove the existing version, use Add/Remove programs in the Control Panel. You can check your version of Windows Defender by clicking the down arrow next to the help icon and choosing ‘About Windows Defender’.