TOP NEWS

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Maecenas mattis nisi felis, vel ullamcorper dolor. Integer iaculis nisi id nisl porta vestibulum.

Showing posts with label Internet Security. Show all posts

Monday, July 4, 2011

'Indestructible' Malware Strain Infects Millions of PCs

A new strain of super malware infected more than 4.5 million PCs in the first three months of 2011, and shows no signs of slowing down.


The malware, a rootkit variously called TDSS, TDL or Alureon, has been active since 2006, continually evolving and growing more powerful. Due to its devious and damaging capabilities, it is nearly impossible to detect and has been called "indestructible" by researchers at the security firm Kaspersky Lab.

Its newest variant, TDL-4, is "the most sophisticated threat today," Kaspersky wrote. Often hidden on adult content and bootleg websites, as well as file-storage services, TDL-4 infected 4,524,488 computers around the world from January through March of this year. A quarter of them were in the United States, the most lucrative market for cybercriminals.

Once it worms its way into users' systems by bypassing authentication protocols, TDL-4 opens a "back door" to cybercriminals, making it possible for them to load keystroke loggers, adware and a host of other malicious programs onto the infected computers.

TDL-4 allows attackers to remotely take over infected systems, manipulate search engines and act as "a launch pad for other malware," Kaspersky Lab wrote.

Like other rootkits, TDL-4 inserts itself into the kernel, the main program at the heart of a computer's operating system, making it extremely difficult to detect or remove.

Microsoft shielded Windows 7 against rootkits by demanding that all new software show digital certificates signed by trusted sources before installation.

But TDL-4 has gotten around this obstacle. It now infects the master boot record of a PC, the section of the hard drive that the computer reads when starting up, and alters Windows 7 upon loading to permit unauthorized software installations. TDL-4 is present before the computer is even up and running.

"I wouldn't say it's perfectly indestructible, but it is pretty much indestructible," malware expert Joe Stewart of Dell SecureWorks told Computerworld. "It does a very good job of maintaining itself."

TDL-4 encrypts the protocol used for communication between infected computers and the command and control servers of the master botnet — a massive network of Internet-connected computers programmed to distribute spam and malware and launch cyberattacks.

This encrypted connection makes TDL-4 difficult to detect, and even more difficult to slow down its spread.

It also does a security scan of its own, seeking out and destroying competing viruses, Trojans and worms in order to dominate the environment and lull the PC user into thinking everything's OK.

Finding TDL-4 is a little like detecting a black hole in outer space — you can't actually see it, but you can observe its distorting effects upon system processes and network traffic. Removal would mean erasing the entire hard drive and reinstalling the operating system.

It is "one of the most technologically sophisticated, and most complex to analyze, [pieces of] malware," Kaspersky Lab wrote.

Despite its prominence, and the threat it poses to computers all over the world, there's one place where TDL-4 has infected no systems at all.

"Remarkably, there are no Russian users in the statistics," Kaspersky Lab wrote. This is because, as researchers explain, the cybercriminals that pay to have their spam and malware sent via the botnet "do not offer payment for infecting computers located in Russia."
12:03 AM by: Andrea 0

Wednesday, May 4, 2011

Fake FBI Email Fans Fears of 'Illegal' Websites

Online thieves have kicked off a new campaign to steal your money, and this time they're using the long arm of the law to hide their devious scheme.


At this FBI command center, they probably aren't after you. Credit: FBI

Researchers at the security firm AppRiver noticed a batch of emails spreading around the Web claiming to be from the FBI, with the accusatory subject line: "You visit illegal websites."

The message informs the recipient, "We have logged your IP-address on more than 40 illegal websites." although it specifies none of the sites.

Such a social engineering scam can resonate with guilty (or gullible) Web surfers. The criminals behind the scam know this and have included a questionnaire with the fake FBI message that, presumably, could help you out of your legal jam.

Of course, downloading the attached document, titled only "document.zip" will not help you at all.

Instead, the file will automatically drop a piece of malware onto your computer that is capable of opening "a permanent backdoor on your PC in order to further download malicious payloads such as keyloggers and spyware," AppRiver wrote.

Web users are advised never to open suspicious attachments, even if they come from trusted sources like friends or co-workers. Just a few weeks ago, the government-managed Oak Ridge National Laboratory was hacked via an email that claimed to be from the company's human resources representative.
12:20 AM by: Andrea 0

Tuesday, May 3, 2011

Osama bin Laden's death is sure to kick off a cyberscammer arms race, with spam messages, fake videos and poisoned pictures used as their weapons of choice.


Credit: FBI


While most of the world slept after -- or possibly through -- President Barack Obama's announcement late last night (May 1) that bin Laden had been killed in a targeted attack on his Pakistan compound, cybercriminals quickly rushed to the offensive in an attempt to cash in on the earth-shattering news.

Here's what to watch out for in the coming days and weeks, as news of the death of al-Qaida's top terrorist takes over the Web. (This morning it was leading in Google searches and Twitter hashtags.)

Phony news stories

A spam message found by the security firm Sophos claims to have the "real" story of how bin Laden was killed, complete with images. Although the message carries an air of legitimacy by purporting to be from a real news source, clicking on the link, however, directs users to an ad for window replacement.

This particular ad won't harm your computer or steal your money, but it's a definite sign of what's to come.

Undoubtedly, as with any news that grabs the world's attention, there are sure to be scores of people who will chase down any potential development on bin Laden's death.

Be careful of news stories -- especially from sources you may never have heard of -- that promise footage of information no other site has. As the saying goes, if it seems too good to be true, it probably is.

Live video

If you had the chance to see a live video of U.S. ground forces killing bin Laden, would you watch it?

Cybercriminals certainly think so, and a fake video claiming to have such highly coveted footage is already making its presence known on a Spanish-language website. The website, according to Michael Sutton with the security firm Zscaler, hits visitors first with a gruesome -- but fake -- photo of bin Laden after being shot.

If that isn't enough to lure readers in, the site offers visitors a video of bin Laden's killing. But, as with the fake news stories, the video is a setup -- a clever front. If you click on the video, you are first told to upgrade a Flash Player plugin, which is actually a piece of malware that allows criminals to gain unauthorized access to your computer.

Fake videos, as seen during March's devastating tsunami in Japan, are surefire tactics cybercriminals deploy to capture users' attention following global news events. If you click on a video, make sure its source is legitimate, and not a clever spoof of a real news or video website such as YouTube.

Facebook follies

A similar video quickly showed up on Facebook, still ripe new territory for scammers. A link circulating today promised "Shocking NEW VIDEO of Osama Bin Ladens DEATH!!," reported Sophos.

But of course there was no video -- Facebook users who clicked on the link got yet another video that generates ad revenue for the poster, and also had the privilege of the link being broadcast to all their friends.

Tricky trends

The hashtags #osama and #obl (Osama bin Laden) are currently the top trending topics on Twitter. And as with all events that draw worldwide online attention, bin Laden's death is spreading quickly through social networking sites like Twitter and Facebook.

You can be sure online criminals are scheming to divert some of that massive Web traffic to their own malicious pages.

As the aforementioned rigged videos and fake news stories find their footing and start spreading virally through the social networking giants, it's important to exercise caution about what you click. Even if your friends' Twitter feeds and Facebook walls are flush with bin Laden-related messages and links, it doesn't mean it's safe to click on those links.

"Don't blindly trust links you see online, whether in emails, on social networking sites, or from searches," Sophos' Paul Ducklin wrote.

Poisoned pics

Another vector for attack cybercriminals often use is poisoned SEO and images -- the tactic of creating malicious websites and rigged pictures tied to high-profile topics.

Last week's Royal Wedding, for instance, sparked criminals to quickly build phony websites -- including enticing pictures -- aimed at cashing in on search terms such as "Royal Wedding" and "Kate Middleton wedding dress." The Japanese tsunami drew similar scams, targeting people's natural curiosity to back up what they'd been reading about with visual proof.

With a news item as international as bin Laden's death, it's important to remain vigilant while browsing the Web. Online criminals are constantly looking for the next big topic, and this one is sure to stick around for a while.
11:53 PM by: Andrea 0

New Malware Goes After Mac Users

Mac users have typically been less vulnerable to dangerous computer viruses and online attacks, but that trend seems to be quickly changing.

A new malware campaign is targeting Mac OS X users, trying to convince them their computer is infected with a virus, then trick them into downloading a corrupted version of the popular MacDefender antivirus software, The Next Web reports.

The new malware targets victims of Apple's Safari Web browser via rigged Google Images; when users click on the infected pictures, the bogus MacDefender program automatically downloads onto their systems. Once downloaded, the rogue antivirus software asks victims to pay for protection they don't need.

Luckily for users, this scareware scam goes after only their insecurities; it doesn't actually infect systems with any damaging viruses that will steal sensitive information.

To stay safe and prevent Safari from automatically downloading the fake MacDefender software, The Next Web says, Safari users are advised to select "Preferences," then "General," then uncheck "Open 'safe' files after downloading."

To stop the app from running if it's already in use, check "Activity Monitor" under the "Applications" tab, and "disable anything that relates to MacDefender."

Malware makers largely have spared Macs while concentrating on attacking bigger sellers, but this isn't the only Mac-specific scam on the loose right now.

Ed Bott of the security website ZDNet has spotted a "fully operational kit specifically designed to build malware aimed at the Mac OS platform."

The kit, available on underground malware markets, is called "Weyland-Yutani BOT," according to the Danish information technology firm CSIS Security Group.

Researcher Brian Krebs spoke with the maker of Weyland-Yutani BOT, who told Krebs he designed the exploit kit to target Mac users running the Google Chrome and Mozilla Firefox Web browsers.

The malware targeting Mac users could have widespread and damaging implications, Bott explained. And with malware coming from all angles -- Safari, Chrome and Firefox -- Mac users are threatened whichever way they go.

"Only a tiny percentage of Macs run antivirus software,” Bott said, “and Mac users have been conditioned to believe they're immune from Internet threats. That's a deadly combination."
11:16 PM by: Andrea 0

Thursday, March 18, 2010

Spamfighter Pro

A spam-filtering program that lets you fine-tune filtering levels and create your own black- and white-lists.

In terms of everyday operation, Spamfighter Pro is almost indistinguishable from our Silver Award winner Cloudmark. Both add Block and Unblock buttons to your email program's toolbar (compatible with Outlook, Outlook Express, Windows Mail and Thunderbird) and both rely to some extent on the user community to accurately flag and filter spam. Both are also good at what they do, collectively having blocked 50 billion spam messages according to the live statistics collated by each application.

Spamfighter Pro is marginally cheaper than Cloudmark and also provides a slightly better level of control over the sensitivity of the filter (five levels are on offer, from ‘very soft' to ‘very hard').
The main distinction between the two products is in their black- and white-listing abilities. Email addresses (or domains) in a blacklist will always be classified as spam while those on the white-list will always be allowed through. So what's the difference? Well, Cloudmark doesn't have a local blacklisting facility as such - only white-listing. In other words, Cloudmark users have to rely on Cloudmark's blacklist, while those protected by Spamfighter Pro can augment the community blacklist with local exceptions.
12:30 PM by: Andrea 0

Thursday, March 11, 2010

BitDefender Anvivirus 2010

BitDefender has done it again; with Internet Security 2010, they’ve upped the ante as one of the best internet security suites. With new features, improved protection and performance, BitDefender Internet Security 2010 has once again redefined excellence in security software.

Not only does BitDefender 2010 provide complete PC security, but it offers protection on several fronts, all complimented with a value-driven price. For the ultimate internet security solution, including protection from viruses, spyware, phishing, spam and more, don’t overlook BitDefender Internet Security. (For all these features and additional PC tune-up utilities, online backup and storage, consider BitDefender Total Security).  Their antivirus scanner is excellent, but their anti-spyware scanner isn't quite as good as Webroot's.

Standout Features
  • Parental controls
  • IM encryption
  • Active Virus Control
  • Adjustable user interface

Antispyware:   Excellent
BitDefender Internet Security 2010 is equipped to protect your computer and your personal information from a variety of identity threats, including adware, trojans, keyloggers, and even browser hijackers. New intrusion detection tools block attacks made by DLL code injection, and stop unauthorized attempts to change your system files and registry keys, access your memory, or attempt to kill BitDefender processes.

BitDefender Internet Security can even encrypt all of your IM conversations for additional security, and will help you effectively reduce or eliminate annoying (and potentially dangerous) spam messages. Furthermore, the software includes anti-phishing, so you don’t have to worry about losing your important information or identity to these scams.

Another advanced feature for keeping your important info safe is available with the File Vault. You can securely store your personal information and/or secret files in this designated “digital safe” and have them completely inaccessible to others.

Antivirus:   Excellent
Virus detection is one of the most important aspects of a robust internet security suite, and BitDefender’s protection is certainly superior. Not only has BitDefender received awards and certifications from third party security testers like ICSA and Virus Bulletin 100, the software has been shown to provide some of the fastest scans while requiring some of the lowest requirements (on-access and on-demand memory) in the industry.

The kernel-level virus protection of BitDefender Internet Security is second to none, and is regularly (read: hourly) updated for up-to-date virus signatures and definitions. One of the reasons BitDefender is so effective is because the software is equipped to scan all (in and out) PC communication, including e-mail, instant messages, and all web traffic. But the scan isn’t just comprehensive, it also runs in real-time to effectively stop threats before they even have a chance to infiltrate your PC.

Another impressive BitDefender technology that keeps your computer safe is Active Virus Control. This extra layer of protection is a proactive, heuristic detection method designed to uncover stealth threats. With security suites and antivirus software gaining strength, some malware has been specifically engineered to sneak around them and go undetected. But Active Virus Control monitors all activity of applications to analyze file behavior and stop even these stealth viruses.

Firewall:   Excellent
BitDefender Internet Security features a flexible 2-way firewall. Whether you’re at your office, home, or on the road, you can connect with confidence knowing that the versatile firewall will automatically adjust its settings to most appropriately suit your location.

An integrated Wi-Fi monitor is designed to protect you and your computer from attempts made by others to access your (Wi-Fi) network.

The firewall BitDefender uses has been tested, approved, and certified by the West Coast Labs for being among the most effective available.

A disabled firewall won’t do you much good, yet it’s common practice for gamers to turn off firewall settings to access and run computer games. With BitDefender’s gamer mode, there’s no need to disable (and re-enable/forget about) the firewall. Not only will you stay protected while you’re gaming, but the gamer mode stops any interference while you’re in full-screen mode (for games, videos, or presentations).

Other Security/Features:   Excellent
BitDefender Internet Security includes powerful and flexible parental controls. With customizable web filters and account rules, you can set up individualized restrictions/permissions for each child. You can even get separate email alerts associated with each child.

The improved website filter utilizes specific category definitions and has a better detection rate (without over protecting and blocking legitimately appropriate sites).

Not only can you restrict/enable and monitor your child’s internet content, parents can also choose to limit internet and other application access to specific times or just give a time allowance. Let Timmy access the computer from 3 to 7, but only allow him to play games from 4 to 5. Or let Jane access the internet (with standard teenager web filtering, of course) whenever she wants, but give her an allowance of 3 hours per day. With the flexible parental controls and monitoring tools, it’s easy for parents to maintain control while giving kids some internet freedom and responsibility.

Ease of Use:   Excellent
BItDefender is certainly powerful, and has usually been pretty easy to manage, but now it’s even more easy to use than before. With a redesigned interface and flexible layout, BitDefender 2010 can accommodate any level of user.

When you first install and configure the software you will choose from four user types (typical, parent, gamer, or custom) and three interface levels (novice, intermediate, or expert). These choices will help you get the custom interface that will be most appropriate for your specific PC use and what level of interaction you want with your security software. The versatile options allow you to have access to the most in-depth processes, or simply let the software do its job behind the scenes without any direction from you.

Whether you’re a security beginner or an antivirus pro, you can easily manage BitDefender Internet Security and take advantage of all that the software has to offer. Each interface is effectively organized and features an intuitive interface, making program navigation easy and enabling simple use of all the tools.

BitDefender had problems a few years ago with system slowdown, but have made impressive strides to improve speed and performance. 2010’s installment takes advantage of technology to eliminate the need to scan files that are known to be safe, reducing system load, and significantly decreasing scan time (not to mention required resources). Last year’s scans were relatively quick, but now they’re even 30% faster, making BitDefender scan times (and boot time) on par with competing antivirus and security software.

Ease of Installation/Setup:   Excellent
BitDefender Internet Security is simple to install and easy to setup. It is available as an immediate download, or you can purchase a physical disc (which can also be used as a bootable rescue disc to save crashed and unbootable PCs, restoring them to a working state). Installing the software to your computer is easy, and will walk you through each step of the process.

We had the software up and running in no time. Initial scans may take a while to cover everything, but get you started with a clean slate, and will certainly be worth it in the long run (as you remove deep viruses and otherwise improve system performance).

Further working with the software is easy, and doesn’t require constant intervention and annoying interruptions that plague some security software.

Whether you purchase a 3-user license of the software or simply have other BitDefender solutions running on other computers on your home network, you can easily manage them all from a single computer. Backups, scans, updates or other configurations can all be performed (or scheduled) remotely. (For the record, BitDefender updates are already scheduled to run automatically every hour, and even self-repair if for some strange reason they cause problems or file damage).

Help/Support:   Excellent
BitDefender has an impressive support system, complete with easy-to-access professional assistance and a wealth of helpful resources. You can find answers to a number of questions and product specific help online. If you can’t find the information you need or simply need personal assistance, it’s easy to call (24/7), email, or even instantly connect via live chat with a live support specialist.

It’s great to see such an impressive lineup of help available, with a variety of outlets and options. What’s even better?: that you likely won’t need to use them much, if at all because the product is easy to use and effective.

Summary: 
BitDefender Internet Security is a streamlined, solid, and powerful (and don’t forget reasonably priced) internet security suite. The unique combination of features and impressive utility make it one of the most versatile and powerful security solutions. For most users, BitDefender Internet Security 2010 should provide more than enough security while maintaining complete usability. Overall, BitDefender Internet Security is a perfect solution that will keep your computer clean and secure without significantly sacrificing performance.
2:35 PM by: Andrea 0