Showing posts with label AntiVirus. Show all posts
Showing posts with label AntiVirus. Show all posts

Jul 10, 2009

Microsoft's Next Patch Tuesday Could Be Big

Next Tuesday, July 13, Microsoft will issue 6 security bulletins and updates to fix the vulnerabilities described in them. Among these will be a DirectShow vulnerability disclosed in May and, possibly, the zero-day vulnerability that hit the Internet this week.

Three of the bulletins affect Microsoft Windows and all are critical on Windows 2000 and Windows XP. The first, for now designated "Windows 1" is rated critical on every shipping Windows platform and must be a doozy. The second appears to be for the DirectX flaws mentioned above, and affects Windows 2000, Windows XP and Windows Server 2003. The last affects only Windows XP (critical) and Windows Server 2003 (Moderate).

The other 3 vulnerabilities have the less-urgent rating of Important: vulnerability in Publisher 2007, one in ISA (Internet Security and Acceleration) Server 2006, and one in several current versions of Virtual PC and Virtual server.

A Microsoft blog on the update advance notification indicates that they believe they will be able to get an update of sufficient quality for the zero-day DirectX attack in time for Tuesday, but they aren't making promises at this point. In the meantime they recommend using the kill-bit workaround, a link to which they include in their blog.

The usual monthly update will also be put out for the Malicious Software Removal Tool and the Windows Mail Junk Filter. There will be a non-security update to Vista that should fix intermittent failures experienced by users that have a Bluetooth radio connected to a USB 2.0 hub. (story Link)

Jun 21, 2009

'Golden Cash' network - rent a botnet

Researchers at security firm Finjan said on Wednesday that they have uncovered an underground botnet-leasing network where cyber criminals can pay $5 to $100 to install malware on 1,000 PCs for things like stealing data and sending spam.

The Golden Cash network, dubbed "Your money-making machine" on its home page, sells access to botnets comprised of thousands of compromised PCs to cyber criminals for custom malware spreading jobs, according to issue 2 of the Cybercrime Intelligence Report for 2009.

Here's how it works: a cyber criminal creates a botnet by hiding malicious code in a legitimate Web site that is used to turn Web surfing PCs into zombies. The code, typically an iFrame, points the PCs to a separate Web site where they are then infected with a Trojan backdoor that reports back to the Golden Cash command and control server.

In order to increase the number of botnets, the Golden Cash server installs an FTP (file transfer protocol) grabber on new zombies to steal credentials used by the computers to run Web sites, giving the server control over additional legitimate Web sites. Approximately 100,000 domains, including corporate domains from around the world, were identified among the stolen FTP credentials under Golden Cash's control, according to the report.

Customers pay for the ability to install different types of malware on the Golden Cash bots, which are recycled for new jobs and new customers afterward. Prices are higher for compromised PCs in western countries, the report said.

"This advanced trading platform marks a new milestone in the cybercrime evolution," Finjan said in a statement.

More technical analysis is available on Finjan's Malicious Code Research Center blog, including the fact that the command and control server is hosted in Texas, the registrant country is China and the "proxy" Web site that tunnels traffic to the command and control server is hosted in Krasnodar, Russia.  (This article was originally posted on CNET News.)

Apr 29, 2009

Fix BSOD problems caused by latest Windows 7 updates

A couple of Windows 7 beta testers faced a blue screen of death (BSOD) after installing some recently released security updates. The error message stated a failure on k11.sys and may be caused by a conflict with the Kaspersky Antivirus Program. WindowsFixUp discovered an easy fix for this problem. First, boot up in Safe Mode, which can be done by tapping F8 during boot-up. Once in Safe Mode, type msconfig into run, click on the Startup tab and disable Kaspersky and any related items such as k11.sys. Restart and you should be able to boot up fine.

Fix BSOD problems caused by latest Windows 7 updatesVisit WindowsFixUp for step-by-step instructions on how to fix this problem. (Story Link)

Mar 9, 2009

AutoRun patch a long time coming for XP users

Nearly 18 months after it was discovered, Microsoft has finally fixed a hole in the AutoRun function of older Windows versions that allowed viruses to spread via external storage devices.
While it's good to know Microsoft is finally listening to the complaints of the Windows community, the company's delay in applying important patches put our systems at risk unnecessarily.
The old saying about the squeaky wheel getting the grease applies to the manner in which Microsoft prioritizes its product fixes. The more noise customers make, the more likely the problems will be rectified. Most recently, the Conficker worm has been spreading across networks, often entering systems via USB flash drives and other removable media. Shamefully, Microsoft could have — and should have — prevented this massive infection from happening in the first place.
In October 2007, Nick Brown documented in his blog how viruses and worms were entering his network via USB memory sticks. The next month, WS associate editor Scott Dunn explained in a Top Story on Nov. 8, 2007, the fact that Microsoft's suggested settings to disable AutoRun weren't effective. He described the so-called @SYS trick, which allows you to truly disable AutoRun, preventing infected devices from launching their attacks.
Fast-forward to one year ago. Will Dormann and US-CERT (the United States Computer Emergency Readiness Team) published information on Mar. 20, 2008, confirming that Microsoft's AutoRun advice didn't block threats. The same @SYS workaround that Scott documented was supported by US-CERT in its alert.
In July 2008, Microsoft released security bulletin MS08-038. The patch in this bulletin made it possible for users to control AutoRun properly, but only on Windows Vista and Server 2008.

XP, Win 2K, Server 2003 users left in the lurch

So what happened to the equivalent patch for Windows 2000, XP, and Server 2003? In May 2008, Microsoft had in fact released a patch for these systems, which is described in Knowledge Base article 953252. However, as described in a Jan. 22, 2009, Computerworld article, US-CERT found that the fix for XP/2000/2003 had to be applied manually. Furthermore, Microsoft was not making the patch available automatically via any Windows Update service.
It wasn't until Feb. 24 of this year that Microsoft distributed this patch via Windows Update to XP, 2000, and 2003. This is described in the company's security advisory 967940.
Many home and business PC users rarely deploy patches that aren't available through Windows Update, Microsoft Update, or WSUS (Windows Software Update Services). Add to this the confusing and conflicting information about the AutoRun patch, and it's no wonder the Conficker worm, which exploits AutoRun functionality, made the inroads that it did.
You may be wondering why it took Microsoft so long to distribute for XP/2000/2003 users the fix that permits AutoRun to be properly disabled. One clue may be found in the file versions listed in KB article 967715. The Windows Server 2003 files are dated Feb. 10, 2009. Typically, Microsoft doesn't release a fix for one platform if it's still developing a fix for another platform. This is done to avoid putting one set of customers at risk while protecting others.
That's usually a valid reason to wait before distributing patches. But when you open up the files described in the earlier KB article 953252, you find that all the files in that hotfix date back to mid-2008.
Why did it take an admonition from CERT to convince Microsoft to add this vital fix to Automatic Updates for those versions of Windows? To make things even more confusing, the way Microsoft released the XP/2000/2003 fix at the end of February caused many people to think it was an out-of-cycle security patch.
If this patch had been pushed to all Windows users sooner, much of Conficker's pain might have been avoided.
Microsoft's Feb. 6 TechNet alert makes the problem clear. Among other things, the Conficker worm uses the AutoPlay feature (which is related to but separate from AutoRun) to infect PCs via USB drives and other portable storage devices. This vulnerability occurs even if the systems have installed the update described in Microsoft security bulletin MS08-067. Therefore, the TechNet article recommends disabling AutoRun, saying:

  • "Disable the AutoPlay feature through the Registry or using Group Policies, as discussed in Microsoft Knowledge Base article 953252. Windows 2000, Windows XP, and Windows Server 2003 customers must deploy the update associated with Microsoft Knowledge Base article 953252 to be able to successfully disable the AutoRun feature. Windows Vista and Windows Server 2008 customers must deploy the security update associated with Microsoft security bulletin MS08-038 to be able to successfully disable the AutoRun feature."

(What's the difference between AutoRun and AutoPlay? AutoPlay associates multimedia file types with specific applications, while AutoRun executes autorun.inf files found on various drives. For more on the distinctions between AutoRun and AutoPlay, see Microsoft's help article on the subject.)
For home users, I'm not yet ready to pull the fire alarm and tell everyone to disable AutoRun. But I do urge you to be very leery of plugging USB flash drives into your system if you're unsure whether they've been used on other computers. Large organizations, however, should consider disabling AutoRun on their networked PCs, considering how hard it's been to stomp out the Conficker worm and others.

How to apply the patches and control AutoRun

If you followed the instructions in Scott's 2007 article to block AutoRun by adding a Registry key, you should remove the key before applying the Microsoft AutoRun patch to prevent any possible interaction. Take the following steps for complete protection:

  • Step 1. Remove the @SYS line from the Registry, if you added it. In Windows XP, click Start, Run. (In Vista, click Start.) Type regedit and press Enter. In the left pane, navigate to and select the following key:
    HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ IniFileMapping \ Autorun.inf
    Press the Del key to remove the key. Close the Registry Editor.
  • Step 2. Install the patch described in KB article 953252 (for Vista and Windows Server 2008) or 967715 (for XP, 2000, and Server 2003).
  • Step 3. For security reasons, it's strongly recommended you disable AutoRun for all devices. In non-Home versions of XP and Vista, use the Group Policy Editor. In XP, click Start, Run. (In Vista, click Start.) Type gpedit.msc and press Enter. In the left pane, under Computer Configuration, expand Administrative Templates.
    In XP Professional, select System in the right pane under Administrative Templates, right-click Turn off Autoplay in the right pane, and choose Properties. Click Enabled, select All drives in the "Turn off Autoplay" box, click OK, and close the Group Policy Editor.
    In Vista Business and higher, expand Windows Components and select AutoPlay Policies. In the right pane, double-click Turn off Autoplay, click Enabled, choose All drives in the drop-down menu next to "Turn off Autoplay on," click OK, and close the Group Policy Editor.
    To disable AutoRun in the Home versions of XP and Vista — which don't have the Group Policy Editor — use the Registry Editor. In XP, click Start, Run. (In Vista, click Start.) Type regedit and press Enter. Navigate to and select the following key:
    HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer
    In the right pane, double-click NoDriveTypeAutoRun, enter 0xFF in the "Value data" field, make sure Hexadecimal is selected under Base, click OK, and exit the Registry Editor.
  • Step 4. If you ever need to re-enable AutoRun for a certain system, open the Group Policy Editor (on non-Home versions of Windows) or the Registry Editor (Home versions). Then follow the instructions in KB article 967715 (for XP, 2000, and Server 2003) or 953252 (for Vista and Windows Server 2008) to return AutoRun to its default state or customize its settings. AutoRun can be configured, for instance, to work differently for CD-ROMs than for other media.

Once you've disabled AutoRun, you'll have to use Windows Explorer to access data files on the USB memory devices and optical media you insert in your system. If you load a disc that contains audio or video, you may want to open your favorite media player to run the content. However, this is a small price to pay for the security edge you gain by disabling AutoRun.

by: Susan Bradley  (with thanks)

Feb 28, 2009

Firefox Trojan Steals Passwords

A new Trojan horse program identified by anti-malware company BitDefender as Trojan.PWS.ChromeInject.B works as a Firefox plug-in.

Two files, one Javascript and one Windows executable, conspire to steal user logon credentials whenever you log on to one of 103 domains, largely belonging to banks (see the BitDefender link for the complete list). The sites are largely out of the US.

BitDefender identifies ChromeInject as "...the first malware that targets Firefox." It's the first we've heard of as well. The writeup has no information on how the file is being distributed or if it's mislabeled as something else, but they give it a spreading factor of "very low".

Take this as a warning, in case you thought otherwise, that Firefox is vulnerable to all the usual forms of attack. Use common sense when surfing even in Firefox, and especially when installing plug-ins. (story Link)

You Need Anti-Virus For Your Mac

Thanks to Brian Krebs of the Washington Post for pointing out a recently published Apple Technical Note that encourages Mac users to get antivirus software:

Apple encourages the widespread use of multiple antivirus utilities so that virus programmers have more than one application to circumvent, thus making the whole virus writing process more difficult. Here are some available antivirus utilities:


It then goes on to list Intego, Symantec, and McAfee AV products for the Mac.

This is a pretty low-key, technical endorsement, and as Krebs notes, Apple Store employees are still telling customers otherwise, as are Apple advertisements.

There is malware for the Mac (see here and here for example), but it's still not a gangbusters malware market. In fact, if I were to say that the amount of Mac malware doubled or tripled this year it would not necessarily be a reason for panic.

But it is a reason for concern: Apple undoubtedly knows that they are not immune to malware, they just haven't been the target of it much, and that could change. Perhaps they are actually seeing enough of it among real customers that they are concerned about those users' unpreparedness for attack. Anti-virus may be an inadequate security solution for Windows users, but at least they have some protection that will stop a very high percentage of attacks. Mac users still have an open door and a welcome mat out.

Don't look for Apple to be much more public about their users' need for anti-malware protection, as it would be a serious buzz-killer for their hype. This could change if a real attack commenced and got traction against Mac users. Security experts have mumbled about such a real possibility for years. (story Link)

Norton Internet Security for Mac

Do you need security software for the Mac? This is a subject of ongoing debate with some recent developments. Many Mac users ignore such products, but many don't.

Now Symantec thinks there is a market and/or a need for security software on the Mac and they are releasing Norton Internet Security 4.0 for the Mac today. There really is malware for the Mac and some users do get attacked by it. How many is "some"? Probably not a lot, and if malware were really a problem it would obviously be a problem.

Could it develop into a more serious problem? Absolutely it could, and that's a reason to be prepared. NIS4Mac isn't the first or only anti-malware for the Mac; some, such as Intego VirusBarrier, specialize in the Mac, and there are more than a few users who take measures to protect themselves.

But even if you scoff at the notion of anti-malware for the Mac, NIS4Mac has many security features that would be beneficial for you. Symantec argues it has the best firewall on the Mac, adding features that aren't available in other products. There are location-based network rules which set different rules based on where you are connecting from (home, office, Starbucks, etc.). You can set rules for which applications can access the Internet and log that access. Symantec integrates blacklist data gathered from their worldwide DeepSight network to block access from known-malicious sites. The firewall also includes an IDS of sorts with signatures for vulnerability-based attacks in the Mac and 3rd party apps on the Mac.

There's no reason to think Mac users get phished any less than Windows users, so NIS 4 the Mac includes phishing protection based on blacklists and heuristics. Norton Confidential lets you define text or files that is sensitive, such as bank account numbers and records, and which shouldn't be sent out to the Internet without explicit consent. File Guard encrypts sensitive files.

Are you a techie Mac user? Like the command line? NIS for the Mac has a terminal interface for doing scans, manipulating firewall features and other functions of configuring the product.

Do you run Windows in a VM on your Mac? Then Norton Internet Security for Mac Dual Protection could be a bargain. It adds a copy of Norton Internet Security 2009 for Windows for your VMs and a 1 year license for it for $10 more. Many of the features in NIS 4 the Mac seem innovative there, but old news on Windows, and that's natural. In some cases the Mac doesn't implement a Windows feature; NIS on Windows updates itself very frequently with short updates because of the level of activity on that platform. But on the Mac updates are much less common, as little as once a week. If more become necessary they’ll do more. That will be good news for them, bad news for users. (story Link)

Feb 17, 2009

Norton Utilities

Legend has it that in 1982 Peter Norton accidentally deleted an important file and wrote the pivotal UNERASE utility to get it back. UNERASE became the centerpiece of the wildly popular Norton Utilities collection. Peter Norton Computing merged with Symantec in 1990 and Norton Utilities continued to grow and evolve until 2005, when it was absorbed by Norton System Works. Norton Utilities 14 ($49.99 list) marks the return of the Norton Utilities name, but the product itself is completely different, a clean break with the old version. It's built almost entirely on technology obtained by Symantec with its acquisition of PC Tools last year, and it's highly focused on fixing and optimizing your system. I was troubled to find that, while I only had a day or so to test the code before its release, I couldn't measure any significant performance benefit.

Optimizing the System

The product's many features are organized into four main panels: Optimize, Monitor, Windows Tools, and Administer. I ran every single feature on the Optimize panel and let them do their good work. To start I launched "Clean Your Registry", which found almost 200 distinct errors (erroneous or useless data) in the Registry. I let it fix all the errors knowing that if by some mischance this cleanup caused a problem another of the tools would let me roll back those changes.

Windows and programs are constantly adding, changing, and deleting items in the Registry. Like the file system on disk the Registry can get fragmented, possibly making for slower Registry access. I ran the Defragment Your Registry tool, which said it could shrink the Registry by eight percent while defragmenting it. I let it do the job.

Unnecessary Windows services running in the background can slow system performance, but most users have no idea what is and isn't necessary. Turning off the wrong service can bring Windows to a crashing halt, so in general only experts should consider making changes in this area. Norton Utilities offers to manage your services by turning off all but a carefully selected set of recommended ones. It can also cut back to a minimal set of services for raw speed, possibly at the expense of some functionality. And of course you can undo either change. I chose the recommended services option.

You also take a performance hit when too many programs launch at startup and keep running in the background. Norton Utilities offers to manage your startup, but it doesn't offer any particular advice the way it did for services. I left the startup items alone. (full Story)

Feb 5, 2009

2009’s Best Internet Security Suites

The list of available 2009-model security suites is now essentially complete. A running theme in this year's suites is the promise that these new versions will do more for your security while tying up fewer system resources. It's about time: Users have had it with suites that offer security but bog down the computer. Several vendors have introduced new "in the cloud" technologies to keep up with the accelerating growth of new malware. And many have redesigned their user interfaces to be more attractive and look lighter and faster. Some are new, innovative, and speedy. Others haven't kept pace. Which are which? I put them all through grueling tests to find out.

Performance Testing

Starting with the 2009 crop of suites, I added an entire day of performance testing per suite to my already lengthy set of evaluations. I wrote and gathered a collection of batch files, scripts, and freeware components to measure how long a number of common activities take on the computer. I ran the scripts many times on a system with no suite installed and then on that same system with each suite installed. Averaging the results let me see just how much each suite affected system performance.

I get a lot of complaints about how long PCs take to boot up in the morning, and many users blame their security suites for lengthening the process. The first part of my test script, therefore, calculates the time it takes from the start of the boot process (as reported internally by Windows) to the time when the system is completely ready to use. "Ready" is a fluid concept—I defined it as meaning that 10 seconds have passed with CPU usage under 5 percent. I ran this test 50 to 100 times and averaged the results; the test system with no suite installed takes almost exactly 60 seconds to boot. Norton Internet Security 2009 and Kaspersky Internet Security 2009 added only about 15 seconds to the boot time. That's not bad!

Some of the other suites added significantly to boot time. F-Secure Internet Security 2009 and McAfee Total Protection 2009 nearly doubled it, and BitDefender Total Security 2009 more than doubled it. The timings for Webroot Internet Security Essentials (WISE) averaged even higher—almost 2.5 times the baseline. However, the data set included a number of unexplained instances when booting up took 5 or even 10 minutes. Eliminating those quirky outliers brought the average boot time for WISE (the smallest suite) a bit below that of McAfee (the largest suite)—still not impressive.

Real-time malware scanners can kick in on any kind of file access and can slow ordinary file operations, especially if they redundantly scan the same file more than once during the operation. I set up a series of file move and copy actions using a variety of file types and timed how long it took with and without a security suite. Kaspersky added just 2 percent to the time required for this test, and Trend Micro Internet Security Pro added 6 percent. Norton and Panda Global Protection 2009 came in between those two. On the slow side, the system running ZoneAlarm Internet Security Suite 2009 took half again as long to perform the test.

Another of my new tests zips and unzips large groups of files, and my testing showed that this activity takes more of a performance hit from most security suites than moving and copying do. Panda had the lightest touch here, adding just 8 percent to the baseline time. Norton, Kaspersky, Trend Pro, and Webroot all added in the neighborhood of 25 percent to the time. Under ZoneAlarm the zip test took twice as long, and under BitDefender it took 2.5 times as long. That's dreadful! (full Story)