Latest Post
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Android Trojan Capable of Launching DDOS Attacks from your Smartphone

Written By Unknown on Friday, 28 December 2012 | 11:07

Security researchers from Russian firm Doctor Web have come across a new Android Trojan they call Android.DDoS.1.origin. The piece of malware can be used for various malicious tasks, including to launch distributed denial-of-service (DDOS) attacks and to send SMS messages.

For the time being, it’s uncertain how the Trojan is distributed, but experts believe the cybercriminals might be disguising it as a legitimate Android application.

Once it’s installed on a smartphone, the malware creates a fake Google Play icon on the desktop. When executed, this shortcut opens the real Google Play in order to avoid raising any suspicion.

After being executed, the Trojan connects to a remote server, sends it the victim’s phone number, and waits for further SMS commands.

The masterminds of Android.DDoS.1.origin can send various SMS commands. One of them orders the infected device to start sending out packets to a certain server, basically launching a DDOS attack against it.

While this only affects the phone’s performance, there are other activities that can be done by this threat. For instance, the cybercriminals can order the device to start sending out SMS messages to certain numbers.

These SMSs can be used to sign up the victim for premium mobile services or they can be utilized to send out spam.

Messages can also be sent to premium rate numbers, inflating the victim’s phone bill and implicitly filling the fraudsters’ pockets.

“Activities of the Trojan can lower performance of the infected handset and affect the well-being of its owner, as access to the Internet and SMS are chargeable services. Should the device send messages to premium numbers, malicious activities will cost the user even more,” experts noted.

Doctor Web has updated its products to ensure that its customers are protected against this threat.

Which is the most popular antivirus software?

Written By Unknown on Thursday, 28 June 2012 | 04:25



In an over-crowded antivirus software market, end and corporate users are often finding it difficult to differentiate between a value-added market proposition, next to the “me too” vendors of solutions. As in every other market segment, any scientific insight into the market share of various vendors offers an invaluable perspective into the market dynamics, what are customers purchasing, and most importantly, are they living in a world of ‘false feeling of security’.

Using a data set consisting of 120,000 data points, researchers from OPSWAT recently released an informative overview of the antivirus market, answering an important question - which is the most popular antivirus vendor?

According to their findings, that’s avast! Free Antivirus, followed by Microsoft Security Essentials and ESET NOD32 Antivirus.

Detailed market share statistics:

Avast - 17.4% worldwide market share
Microsoft - 13.2% worldwide market share
ESET - 11.1% worldwide market share
Symantec - 10.3% worldwide market share
AVG - 10.1% worldwide market share
Avira - 9.6% worldwide market share
Kaspersky - 6.7% worldwide market share
McAfee - 4.9% worldwide market share
Panda - 2.9% worldwide market share
Trend Micro - 2.8% worldwide market share
Other - 11.1% worldwide market share

Microsoft is the market leader in North America, followed by Symantec and AVG. Not surprisingly, the market leading avast! Free Antivirus is relying on the so called “freemium” business model, where the company grows and gains market share by offering a free alternative of their software, and earns revenue thanks to the successful conversion of free users to paid ones. Earlier this year, the company announced that it has 150 million active users worldwide, a clear indication of a working “freemium” business model.

What do you think? Is antivirus software still relevant in the age of Stuxnet, Duqu and Flame, the so called poster kids of the DIY targeted attack toolkits and weaponized malware releases? Do think free antivirus is offering a ‘false feeling of security’ compared to subscription based license models?

How To Protect Yourself From DNSChanger

Written By Unknown on Sunday, 13 May 2012 | 12:08

DNS Changer

In July the Internet Systems Consortium will permanently shut down DNS servers deployed to serve as temporary surrogates for rogue DNS servers shut down as part of Operation Ghost Click, an FBI operation that brought down an Estonian hacker ring last year. If your PC is one of the more than 1 million computers infected that carry DNSChanger you might unknowingly be relying on one of the FBI's temporary servers to access the Internet, and if you don't eliminate DNSChanger from your PC before the FBI pulls the plug on its servers, you'll be left without Internet access. Read on to learn how to discover whether you're infected with DNSChanger, and what you can do to eliminate it from your system.

How to Tell Whether DNSChanger Has Infected Your PC

To figure out whether you've been infected with DNSChanger, just point your Web browser to one of the (admittedly amateur-looking) DNSChanger Check-Up websites that Internet security organizations maintain across the globe. The link above will take you to a DNS Changer Check-Up page in the United States that the DNS Changer Working Group maintains; if you live outside the United States, you can consult the FBI's list of DNSChanger Check-Up websites to find an appropriate service for your region.

Unfortunately, if your router is infected, those websites will think that your PC is infected, even though it may be clean; worse, if your ISP redirects DNS traffic, your PC may appear to be clean even though your DNS settings may have been maliciously altered. If you want to be certain that your PC is free of DNSChanger malware, you need to manually look up the IP addresses of the DNS servers that your PC contacts to resolve domain names when browsing the Web.

To look up which DNS servers your Windows 7 PC is using, open your Start menu and either run the Command Prompt application or type cmd in the Search field. Once you have a command prompt open, type ipconfig /allcompartments /all at the command line and press Enter. A big block of text should appear; scroll through it until you see a line that says 'DNS Servers', and copy down the string(s) of numbers that follow (there may be more than one string here, meaning that your PC accesses more than one DNS server).

It's even easier for Mac OS X users to determine the IP addresses of the DNS servers that their PC uses. Open the Apple menu (usually located in the upper-left corner of the screen) and select System Preferences. Next, click the Network icon to open your Network Settings menu; navigate to Advanced Settings, and copy down the string(s) of numbers listed in the DNS Server box.

DNS Changer

Once you know the IP addresses of the DNS servers that your PC is using, head over to the FBI DNSChanger website and enter those addresses into the search box. Press the big blue Check Your DNS button, and the FBI's software will tell you whether your PC is using rogue DNS servers to access the Internet.
What to Do If Your PC Is Infected by DNSChanger

If your PC is infected with DNSChanger, you'll have to do some intensive work to get rid of it. DNSChanger is a powerful rootkit that does more than just alter DNS settings; if you've been infected with DNSChanger, your safest course is to back up your important data, reformat your hard drive(s), and reinstall your operating system.

If you're leery of reformatting your entire PC, you can try rooting out the DNSChanger rootkit with a free rootkit removal utility such as Kaspersky Labs' TDSSKiller. As the name implies, Kaspersky released the program to help PC owners seek and destroy the TDSS rootkit malware, but it also detects and attempts to eliminate DNSChanger and many other forms of rootkits.

If the infected PC is on a network, you'll have to check every other PC on the network for signs of infection, and then check your router's settings to ensure that it isn't affected (DNSChanger is programmed to change router DNS settings automatically, using the default usernames and passwords of most modern routers). To do this, copy down your router's DNS server IP addresses (located in your router's settings menu) and check them against the FBI's IP address database mentioned above. If your router is infected, reset the router and confirm that all network settings are restored to the manufacturer's defaults.

When you're done, repeat the steps outlined above to verify that your PC is no longer infected with DNSChanger. With all traces of this vicious malware eliminated, you should have nothing to fear when the FBI shuts down the ISC's temporary DNS servers in July.

Kaspersky: Apple security is like Microsoft's in 2002

Written By Unknown on Thursday, 3 May 2012 | 07:18

Apple customers are more at risk from malware now because of their misconception that their iDevices and Macs are secure and because of Apple's poor attitude to security, according to experts.

Top Mac OS C Malware

David Emm, senior security researcher at Kaspersky Lab confirmed that Apple had cultivated the image of the Mac as intrinsically safer than PCs and now that Macs were under attack from bot armies like the Flashback Trojan, the fruity firm would have to change its attitude.

"I think it will take some time before we see a significant change in attitude from Apple," he said. "It's not simply about code, but about adopting a different security posture and updating and reviewing processes that reflect this."

Because Mac users have long believed that their computers are safe from malware - and Apple fostered this belief in ads like the 2006 one that compared the healthy Mac to the sick PC - they are intrinsically more at risk compared to wary Microsoft users.

"Even when Apple added signature detection to Mac OS, in the form of it's 'XProtect' module, it was done quietly, without any sort of fanfare," says Emm.

"I think Mac customers are more at risk because of the historical mis-perception about Mac security. But I would hope that Flashfake will be a wake-up to anyone using a Mac, that they need to secure themselves from online threats."

Eugene Kaspersky, founder and CEO at the Lab, told Computer Business Review last week and confirmed to Pro Hacking Tricks that Apple was about ten years behind Microsoft in terms of security.

Kaspersky Lab thinks that this is just the start of the attacks that the fruity firm can expect now that Macs have become so much more popular.

"For many years I've been saying that from a security point of view there is no big difference between Mac and Windows," he said.

"Cyber criminals have now recognised that Mac is an interesting area. Now we have more, it's not just Flashback or Flashfake. Welcome to Microsoft's world, Mac. It's full of malware."

Unpatched Java Vulnerability Exploited – Macs Infected With Flashback Malware

Written By Unknown on Tuesday, 3 April 2012 | 10:19

mac.jpg
A Java vulnerability that hasn't yet been patched by Apple is being exploited by cybercriminals to infect Mac computers with a new variant of the Flashback malware, according to security researchers from antivirus firm F-Secure.

Flashback is a computer Trojan horse for Mac OS that first appeared in September 2011. The first variant was distributed as a fake Flash Player installer, but the malware has been changed significantly since then, both in terms of functionality and distribution methods.

Back in February, several antivirus companies reported that a new Flashback version was being distributed through Java exploits, which meant that the infection process no longer required user interaction.

The Java vulnerabilities targeted by the February exploits dated back to 2009 and 2011, so users with up-to-date Java installations were protected.

However, that's no longer the case with the latest variant of the malware, Flashback.K, which is being distributed by exploiting an unpatched Java vulnerability, security researchers from F-Secure said in a blog post Monday.

Oracle released a fix for the targeted vulnerability, which is identified as CVE-2012-0507, back in February and it was included in an update for the Windows version of Java.

However, since Apple distributes a self-compiled version of Java for Macs, it ports Oracle's patches to it according to its own schedule, which can be months behind the one for Java on Windows.

Security experts have long warned that this delay in delivering Java patches on Mac OS could be used by malware writers to their advantage, and the new Flashback.K malware confirms that they were right.

After being dropped and executed on the system via the CVE-2012-0507 exploit, the new Trojan horse prompts a dialog window that asks the user for their administrative password.

Regardless of whether the user inputs the password or not, the malware still infects the system, F-Secure said in its description of the malware. The Trojan's purpose is to inject itself into the Safari process and modify the contents of certain Web pages.

There are rumors that a new exploit for a different unpatched Java vulnerability is currently being sold on the underground market and could be used to target Mac users in a similar way in the future, the F-Secure researchers said.

"If you haven't already disabled your Java client, please do so before this thing really become an outbreak," they said. The antivirus company provides instructions on how to do this.

Apple stopped including Java by default in Mac OS X starting with version 10.7 (Lion). However, if Lion users encounter a Web page that requires Java, they are prompted to download and install the runtime and might later forget that they have it on their computers.

Android Malware Now Exploits Steganography

Written By Unknown on Monday, 30 January 2012 | 08:32

android logo
Summary: Malware makers are turning to quite sophisticated tricks to disguise the true purpose of rogue applications.

Security firm F-Secure have released details on how Android malware makes use of steganography to hide the control parameters for rogue code.

First, what is steganography? It’s the technique of hiding messages within something else, in this case, an icon file.

F-Secure first suspected that Android malware was making use of steganography when researchers came across this line of code:

android malware

Further digging revealed more code, and it soon became clear that the image file being referenced here was the icon file bundled with the rogue application:

android malware

So what’s this hidden information used for? It’s used to control how and when premium rate SMS messages are sent from the victim’s handset, which, as far as the bad guys are concerned, is the primary purpose of the rogue application.

You’ve got to admit, that’s a pretty clever use of steganography.

Worm compromises 45,000+ Facebook logins

Written By Unknown on Friday, 6 January 2012 | 03:41

Facebook worm
A nasty bit of malware making the rounds on Facebook has reportedly made off with the usernames and passwords of more than 45,000 users.

Most of those affected by the worm--called Ramnit--are from France and the United Kingdom, according to a bulletin issued by security researchers at Securlet. It is capable of infecting Windows executables, Microsoft Office, and HTML files, according to McAfee.

"We suspect that the attackers behind Ramnit are using the stolen credentials to log-in to victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," Securlet said in its bulletin. "In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks."

The worm was first discovered in April 2010 stealing sensitive information such as stored FTP credentials and browser cookies. In August 2011, after malware developers borrowed source code from the Zeus botnet, Ramnit "went financial." With that added strength, Ramnit was able to "gain remote access to financial institutions, compromise online banking sessions and penetrate several corporate networks." Approximately 800,000 machines were infected between September 2011 and the end of the year.

The security researcher has notified Facebook and provided the social-networking giant with all the stolen credentials found on Ramnit's server.

Android Bug Allows Hackers to Install Malicious Code Without Warning

Written By Unknown on Wednesday, 21 September 2011 | 08:00

android-malware
It's been more than a month since researchers reported two serious security vulnerabilities in Android, but so far there's no indication when they will be purged from the Google-spawned operating system that's the world's most popular smartphone platform.

The first flaw allows apps to be installed without prompting users for permission. The permission-escalation vulnerability permits attackers to surreptitiously install malware in much the way a proof-of-concept exploit researcher Jon Oberheide published last year did. In that case, an app he planted in the Android Market and disguised as an expansion pack for the Angry Birds game secretly installed three additional apps that without warning monitored a phone's contacts, location information and text messages so data could transmitted to a remote server.

“The Android Market ecosystem continues to be a ripe area for bugs,” Oberheide wrote in an email. “There are some complex interactions between the device and Google's Market servers which has only been made more complex and dangerous by the Android Web Market.”

The second bug resides in the Linux kernel where Android originates and makes it possible for installed apps with limited privileges to gain full control over the device. The vulnerability is contained in code device manufacturer have put into some of Android's most popular handsets, including the Nexus S. The bug undermines the security model Google developers created to contain the damage any one application can do to the overall phone.

Oberheide and fellow researcher Zach Lanier plan to speak more about the vulnerabilities at a two-day training course at the SOURCE conference in Barcelona in November. In the meantime, they put together a brief video showing their exploits in action.



One of the hopes for Android a few years back was that it would be a viable alternative to Apple's iOS, both in terms of features and security. With the passage of time, the error of that view is becoming harder to ignore. And if i'm not wrong, Google developers have updated Android just 16 times since the OS debuted in September 2008. The number of iOS updates over the same period is 29.

It's a far cry from the approach Google takes with its Chrome browser, which is updated frequently, and has been known to release fixes for the Flash Player before they're even released by Adobe.

Even more telling, when a new version of iOS is released, it's available almost immediately to any iPhone user with the hardware to support the upgrade. Android users, by contrast, often wait years for their phone carriers to supply updates that fix code execution vulnerabilities and other serious flaws.

Owners of the Motorola Droid, for instance, are stuck running Android 2.2.2 even though that version was released in May 2010 and contains a variety of known bugs that allow attackers to steal confidential data and remotely execute code on handsets the run the outdated version.

Oberheide has more here.

Windows 8 to come with built-in Malware Protection

Written By Unknown on Thursday, 15 September 2011 | 04:50

windows-8
Microsoft's next version of Windows will ship with "tons of security features," including one that automatically scans boot drives for malware and a revamped version of the Windows Defender antivirus program, company executives said.

At the company's BUILD conference in Anaheim, California on Tuesday, Corporate Vice President of Windows Planning and Ecosystem Michael Angiulo demonstrated an early version of Windows 8 that automatically scanned an infected USB drive used to boot the next generation operating system. Before the OS was able to load, the computer stopped the process and displayed a warning that the boot volume contained an "invalid signature" indicating it had been compromised.

He was able to get the valid version of Windows to load by turning off the system and turning it back on. The presentation starts around the 1:08 mark in the following video:



The technology making this possible is known as UEFI, short for Unified Extensible Firmware Interface. A successor to the BIOS ROM firmware that Microsoft operating systems have relied on since their beginning, UEFI was designed to shorten the time it takes a PC to start up. It was built by Intel, but is designed to work with a variety of CPU architectures.

"It's not just about speed and having a boot that looks better," Angiulo said during Tuesday's keynote, referring to UEFI. "It's about security, too."
Steven Sinofsky, president of Microsoft's Windows and Windows Live division, went on to say that Windows 8 developers "have taken Defender and we've actually built a whole new range of protection, all the way up though antimalware, antivirus." Users are free to run Defender or security software supplied by another company. In all, the new OS will offer "tons of security features," he added.

The company issued a statement Wednesday saying Windows 8 would include "low-level security features such as Secured Boot to help defeat classes of threats, and user facing features including Windows Defender and SmartScreen" spam-filtering. The statement didn't elaborate.

Windows 8 will also offer a new way to log on to PCs equipped with a touchscreen. Sam Bowne, a security instructor at San Francisco City College, provided a screenshot here that describes the feature this way: "You choose the picture – and the gestures you use with it – to create a password that's uniquely yours."

Bowne and his students have been testing the security features in the new Windows beta, according to a source.

"There is built in antivirus, and it works!" he wrote "It stopped not only thr EICAR test file, but more than a dozen malware items in Metasploit. So it might be time to sell your Symantec stock."

Bittorent Site Compromised, Serves Malware to Downloaders

Written By Unknown on Wednesday, 14 September 2011 | 08:30

uTorrent
Attackers hijacked two popular Bittorrent websites and tampered with their download mechanisms, causing visitors trying to obtain file-sharing software to instead receive malware.

The hacks on bittorrent.com and utorrent.com replaced the sites' standard software downloads with a piece of fake antivirus software known as Security Shield, an advisory warned. Anyone who downloaded and installed software from those sites between 4:20 a.m. California time and 6:10 a.m. should scan their systems immediately for infections.

Once installed, Security Shield delivers false reports that a computer is infected with multiple pieces of malware and prompts the user for payment before claiming to disinfect the machine. The attack affected only users who downloaded and installed software from bittorrent.com and utorrent.com during the hour-and-fifty-minute window that the sites were compromised. Those who installed software previously are unaffected.

"We take the security of our systems and the safety of our users very seriously," the Bittorrent advisory stated. "We sincerely apologize to any users who were affected."

Malware pretends to be Microsoft Utility

Written By Unknown on Wednesday, 7 September 2011 | 10:32

Researchers from PandaLabs have spotted a Microsoft themed ransomware variant.

The ransomware claims that a user's Windows machine is running an unlicensed copy of Windows and threatens to cripple the victim's computer unless marks pay €100 to obtain an unlock code, which can be purchased via credit card via a scam website. The malware attempts to spook intended victims with entirely bogus claims that a criminal prosecution will be launched unless payment is received within 48 hours. In addition, the Trojan says that all data and applications on targeted systems will be "permanently lost".

The malware, which targets German-speaking users (as illustrated by this screenshot), is being distributed via spam and P2P downloads. Panda Software, the Spanish net security firm which detected the threat, warned that the Trojan is difficult to remove manually.

Microsoft-malware
Click on the image to enlarge

"These types of Trojans are very dangerous because once they infect the computer it is extremely difficult to remove them manually, forcing users to pay the ransom or reformat their devices," said Luis Corrons, technical director of PandaLabs. "In addition, because Ransom.AN appears to come from Microsoft and threatens actions from authorities, many users believe what the Trojan says and make the payment out of fear."

Previous ransomware strains have encrypted files in a bid to force users into paying for getting infected. The tactics used by Ransom-AN Trojan are a more aggressive extension of the basic scam, using threats of prosecution and outwardly convincing screenshots supposedly from Microsoft to peddle the ruse.

The unlock key for the ransomware currently detected as Ransom.AN is QRT5T5FJQE53BGXT9HHJW53YT

Free Banking Trojan Detection Tool

Written By Unknown on Tuesday, 6 September 2011 | 07:32

A Finnish penetration testing company has released a free tool it says can detect all variants of five major families of malicious software that steal online banking credentials.

The tool, called Debank, was built by Finnish penetration testing company Fitsec, which has used the tool to scan its customers' machines, said company founder Toni Koivunen.

The tool works by scanning a computer's process memory, Koivunen said. Most malicious software these days is "packed," or compressed, before it is distributed. That can fool antivirus programs, since the malware can appear to be a different program each time it is repacked.

Koivunen said antivirus programs often use heuristics as an alternative way to detect malware aside from traditional signatures, but that method is not always as successful as a full memory sweep.

Debank looks at the program after it has been executed on a computer. Malware authors rarely change the core code of the program, which is what Debank analyzes.

Koivunen said Debank can detect nearly all variants of SpyEye, Zeus, CarBerp, Gozi and Patcher, five well-known banking malware programs. The malware has to be running for Debank to detect it and the tool only works on computers running Windows, he said.

Debank was able to detect more than 200 variants of Patcher after FitSec found a part of its code common to all variants. FitSec has also tested it against hundreds of variants of SpyEye, a particularly advanced piece of code that operates as part of a botnet. It can harvest credentials for online accounts and also initiate transactions even while a person is logged into their account.

Fitsec decided to just give the tool away and has made it available for download on their blog. "We had no reason to start charging for it," Koivunen said. "Basically, we hate malware."

Want to be your friend on Facebook? A Fake Facebook Request

Written By Unknown on Tuesday, 30 August 2011 | 06:26

Malicious spam messages generated by the infamous Cutwail botnet are targeting Facebook users as potential banking Trojan victims.

The messages arrive in the guise of a Facebook friend invite notification. The emails look genuine enough on casual inspection, thanks to the malware-spinners' apparent use of a genuine Facebook template. But where a genuine Facebook invite contains links to the real social networking site, the malicious emails feature custom links to malware sites. In addition, the emails differ from the genuine article because they do not feature Facebook profile photos. The recipient's email address is also absent from the fine print at the bottom of the bogus invites.

facebook-spam

Users tricked into clicking on the malicious link are exposed to a double-barrelled malware based attack. Firstly they are offered a bogus Adobe Flash update. In addition, clicking on the link opens a hidden iFrame, which then loads data from a remote server hosting the Blackhole Exploit Kit. The exploit kit attempts to exploit browser security holes, most notably involving insecure Java installations.

Both techniques attempt to download a variant of the infamous ZeuS banking Trojan onto compromised systems. Impersonating email notifications from Facebook is a common enough technique among spammers and purveyors of survey scams, but I've never seen it applied to punt banking Trojans before.

A full write-up of the scam can be found in a blog post by M86 Security here.

Android Malware Posing as Google+ app

Written By Unknown on Wednesday, 17 August 2011 | 08:27

android-malware
A new flavor of Android malware is disguising itself as a Google+ app in an attempt to capture instant messages, GPS, location, call logs, and other sensitive data.

Uncovered by the team at Trend Micro, the new malware known as ANDROIDOS_NICKISPY.C can also automatically answer and record phone calls. To capture data, the app loads at boot-up and runs certain services that can monitor messages, phone calls, and the user's location, thereby stealing e-mail and other content.

Detailing its findings in a blog Friday, Trend Micro said it discovered that the malicious app tries to trick people by installing itself under the name Google++.

But instead of providing access to Google's new social network, the app sends its stolen user data to a remote site where presumably cybercriminals can grab it. Unlike some malware in the past that masqueraded as legitimate apps through Google's Android Market, this particular one must be downloaded by an unsuspecting user from a malicious Web site and then manually installed.

And even if installed, the app can be uninstalled from an Android device by selecting Settings > Application > Manage applications, choosing Google++ and then clicking Uninstall, according to Trend Micro.

Trend Micro gives the app a low-risk rating, but it's still something that Android owners should be sure to avoid.

Android users concerned about security can learn how to better protect themselves through Trend Micro's online guide "5 Simple Steps to Secure Your Android-Based Smartphones."

SUPERAntiSpyware Acquired By Support.com

Written By Unknown on Sunday, 19 June 2011 | 08:26

SUPERAnti SPyware
SUPERAntiSpyware is one of those popular malware removal software that provide both free and paid version. Many users find the free version sufficient for all related tasks, while fewer find it necessary to upgrade to the professional version for extra features such as threat realtime blocking or daily definition updates. Most have used the program in addition to traditional antivirus solutions, and especially in cases where other security software have failed to resolve issues on a system.

The acquisition announcement on the SUPERAntiSpyware website may have come as a shock to many long time users of the free or paid version of the application.

Information are scarce at this point in time, the only useful bits from the announcement are that the whole team will join support.com in the near future. The post mentions that “some things will change” but does not go into details what those things might be. The press release at support.com includes additional information.

Support.com has paid $8.5 million in cash for SUPERAntiSpyware and plans to “expand SUPERAntiSpyware’s business with increased distribution and product enhancements”.

When you look at support.com’s offerings you will note that they provide tech support to consumers and businesses alike. Services include one-time fixed prices for support requests, or subscriptions plans for round the clock PC support.

Services include installing hardware, troubleshooting computer problems or removing viruses and spyware. SUPERAntiSpyware will be added to the list of programs the company offers directly to consumers and small businesses.

But what about the free version of the software? Will it still be around after the acquisition? According to SUPERAntiSpyware founder Nick Skrepetos it will.

Of course we will honor lifetime licenses and the free edition isn’t going away
So, users who have a lifetime license will keep their licenses and will continue to get updates, and free users will still get access to a free version of the application.

I’d give the company the benefit of the doubt, but we have seen acquisitions in the past were promises were made but not kept. Lets hope that this is not one of those cases.

Android Malware Found in Angry Birds Add-On Apps

Written By Unknown on Sunday, 12 June 2011 | 15:09

Google recently removed at least 10 applications from the Android Market, all of which contained malicious code disguised as add-ons to one of the most popular apps of all time.

Each of the removed apps posed as a cheat or an add-on to Angry Birds, the much-lauded mobile application created by Finnish game development studio Rovio.

A number of the apps in question contained a spyware program called Plankton, which connects to a remote server and uploads phone information like the IMEI number, browser bookmarks and browsing history.

“Market descriptions for these apps included the statement ‘brought to you free sponsored by Choopcheec Platform,’” Lookout Security spokesperson Alicia diVittorio told Wired.com. “[They include] a link to an EULA that does seem to accurately describe the behavior observed to date. We do not see these as desirable behaviors and classify it as Spyware.”

Xuxian Jiang, an assistant professor of computer science at North Carolina State University, initially discovered the malicious applications last week, and reported them to Google on June 5. Google suspended the questionable applications the same day, “pending further investigation.”

Jiang found malicious programs other than Plankton in his research. YZHCSMS, for example, is a Trojan horse virus that jacks up your phone bill by sending large amounts of SMS messages to premium numbers. Jiang says apps containing the virus were available on the Android Market for at least three months before Google pulled them.

Jiang found a similar application, DroidKungFu, circulating Chinese application markets before YZHCSMS made its way to the Android Market. “DroidKungFu can collect various information about the infected phone, including the IMEI number, phone model and Android OS version,” according to a Lookout Security blog post.

For many app developers, the Android Market offers a freedom not found in other application retail outlets. Unlike Apple’s strict application review process, apps submitted to the Android Market are published almost instantaneously. Many appreciate the freedom given to push programs out to the public at such a speed.

However, the Android Market’s app submission process comes at a cost. Google’s lack of vetting applications lends the Market to security vulnerabilities like these. Google mostly relies on a self-policing community — including researchers like Jiang — to spot offending apps, which means malware can sit in the market for months before someone spots it.

With a relatively open submission process like Android’s, this obviously isn’t Google’s first run-in with malicious app removals. Google pulled nearly two dozen malware-infected applications in early March, but not before close to 200,000 downloads occurred.

Going outside of the official Android Market for apps can be even riskier. Because users are able to download applications from alternative app markets — a feature unavailable to iPhone users — many have popped up over the past two years. Without Google’s moderation capabilities in these outside markets, users are more susceptible to downloading malicious apps. A Trojan with “botnet-like capabilities” popped up in early April, for example, highlighting the risk in going to alternative markets for applications.

Mac Malware Is Gradually Becoming A Serious Threat

Written By Unknown on Tuesday, 17 May 2011 | 08:23

Apple -- and many Mac users -- argue that Mac OS X has a special recipe for security that makes it less likely to be infected with malware. Many security researchers counter that the Mac's seeming immunity stems not from its security, but from its lack of market share.

The debate may finally be settled.

The emergence of a serious malware construction kit for the Mac OS X seems to mimic a 2008 prediction by a security researcher. The prediction comes from a paper written in IEEE Security & Privacy (in .pdf), which used game theory to predict that Macs would become a focus for attackers as soon as Apple hit 16 percent market share.

Last week, security researchers pointed to a construction kit for creating Trojans for the Mac OS X as a major issue for Mac users. Currently, three countries -- Switzerland, Luxembourg and the United States -- have Mac market share around that level.

"The kit is being sold under the name Weyland-Yutani Bot and it is the first of its kind to hit the Mac OS platform," Peter Kruse, partner and security specialist at security firm CSIS, writes in a blog post. "CSIS finds this crimekit to be quite disturbing news since Mac OS previously to some degree has been spared from the increasing amount of malware which has haunted Windows-based systems for years."

Weyland-Yutani Bot, named for the corporation in the 1979 movie Alien, is currently being sold by its developers. While it is not the first attack on the Mac OS X, crimeware has enabled criminals in the past to scale up attacks quickly.

"What is happening is that people are testing the waters," says Adam O'Donnell, chief architect of the cloud technology group at SourceFire and the author of the 2008 paper. "It just becomes economically viable to do it, so you start seeing these attacks becoming more common."

The 2008 paper used game theory to calculate when attackers would start seeing a payoff in focusing on the Mac OS X over Windows. It simplified the problem by assuming that all PC users ran antivirus software and that no Mac users did. The assumptions helped reduce the problem down to two factors: the effectiveness of the defenses and the marketshare of the dominant platform.

With detection rates for antivirus in the 80 percent range, the Mac OS X becomes an attractive target around 16 percent marketshare. If PC defenses are better than 80 percent, then the Mac market share at which attackers become interested drops. For example, if antivirus programs detect attack 90 percent of the time, then attackers will focus on the Mac OS X at approximately 6 percent marketshare, says O'Donnell.

"It is much more of an argument that at the low rates of penetration of the Mac in the market is why there is no malware," he says. "You get a few points up, and like we are seeing now, you will start seeing malware."

Will the same model work to predict when significant malware will appear on smartphone handsets? Not necessarily. One of the assumptions is that the value of compromising a PC and Mac are identical. That assumption is less likely to hold up between a PC and a handset.

"The difference between a PC and a handset is that there is going to be different values in attacking each," O'Donnell says. "That difference will be a big factor in when people move to attacking a new platform."

Notorious Koobface worm ported to Mac OS X

Written By Unknown on Wednesday, 27 October 2010 | 05:44

Security researchers say they've been monitoring a Mac OS X version of the notorious Koobface worm, which uses advanced rootkit techniques to stealthily hijack infected machines.

Although the Mac version isn't yet ready for prime time, it is nonetheless a sophisticated piece of software that developers put a fair amount of effort into implementing. It was designed to use Oracle's Java framework to infect not just Macs, but Linux and Windows machines as well, according to Mac antivirus provider Intego. Once installed, the malware gives attackers complete control over the computer.

“While this is an especially malicious piece of malware, the current Mac OS X implementation is flawed, and the threat is therefore low,” Intego researchers wrote in a blog post published Wednesday. “However, Mac users should be aware that this threat exists, and that it is likely to be operative in the future, so this Koobface Trojan horse may become an issue for Macs.”

For that to happen, attackers will probably have to figure out how to bypass a window OS X prominently displays warning that a self-signed Java applet is requesting access to the computer. Assuming they do, or are able to trick users into clicking “Allow” anyway, they will also need to resolve issues preventing the downloaded files from installing.

Those are high hurdles. But Koobface's considerable success on Windows shows just how gullible many marks are when it comes to scams promising free videos.

Once installed, the downloaded files are stored in an invisible folder and give the infected Mac the ability to run a local webserver or IRC server and to act as an DNS changer.

Intego is calling the malware OSX/Koobface.A, while SecureMac, which also blogged about the attack, calls it trojan.osx.boonana.a.

Java surpasses Adobe kit as most attacked software

Written By Unknown on Tuesday, 19 October 2010 | 05:48

Oracle's Java framework has surpassed Adobe applications as the most attacked software package, according to a Microsoft researcher who warned she was seeing “an unprecedented wave of Java exploitation.”

The spike began in the third-quarter of last year and has climbed steadily since, according to data reported on Monday by Holly Stewart, a member of the Microsoft Malware Protection Center. By the beginning of this year, the number of Java exploits “had well surpassed the total number of Adobe-related exploits we monitored,” she said.

The spike is mostly driven by attacks on three separate vulnerabilities that Oracle patched long ago. As a result attacks on Java have “gone from hundreds of thousands per quarter to millions,” Stewart blogged.

As Microsoft has released new versions of its software that are harder to exploit, attackers looking for ways to install malware have turned their attention to other ubiquitous PC titles. With a massive share of Windows machines, Adobe Reader emerged earlier this year as the world's most exploited app, according to antivirus provider F-Secure. Adobe's Flash Player, also because of its broad base of users, has long been a favorite as well.

Java, which Oracle inherited from Sun Microsystems, has remained vulnerable, too, and exploits are now coming into the mainstream. One of the things driving the trend, according to security reporter Brian Krebs, are updates that add Java attacks to Eleonore, Crimepack and other exploit kits that malware purveyors use to streamline the installation of malware on victim machines.

“Java is ubiquitous, and, as was once true with browsers and document readers like Adobe, people don't think to update it,” Stewart wrote. “On top of that, Java is a technology that runs in the background to make more visible components work.”

The software has never lived up to many of the promises that Sun made about it. Chances are it can be uninstalled from most desktop machines and the user won't even notice.
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger