Thursday, 17 October 2013

Hacker Horrorshow Shaping Up for Halloween

Blue Coats Malware Security Get yourself ready for the frights of October! We're not talking about ghosts or ghouls, but malware threats. In a recent blog post, Solera Network, a Blue Coat company, warned victims of this month's malware infection campaign to keep a watchful eye out for more dangers. These include the ransomware CryptoLocker, clickfraud on a massive scale, and the theft of personal data like passwords.
CryptoLocker CountdownIn early September, malware present on actively infected PCs began to receive instructions from its Command and Control server to download the CryptoLocker ransomware application. CryptoLocker wastes no time and encrypts most document file types on the victim's computer. Other ransomware campaigns normally try to convince the user that he or she is going to be arrested for an alleged cybercrime.
CryptoLocker isn't joking around. It employs a 72-hour countdown clock with the following warning: pay up 300 dollars before time runs out or the malware will delete the decryption key which will render files unreadable. A year ago, ransomware criminals typically charged 200 dollars for data retrieval. CryptoLocker changes the desktop background to a threatening message that is revealed if your antivirus program deletes the program. It warns that you won't be able to decrypt your files unless you download the Trojan again.
CryptoLocker threat
CryptoLocker is pretty simple to find, kill, and delete because this malware runs under a suspiciously long, random-looking filename in the device's Application Data folder. However, if the Trojan finds a way into your system and you don't have your files already backed up, they're likely gone for good.
You should run regular backups on your computer for recovery, as well as antivirus software to keep CryptoLocker from breaking in. In case you find CryptoLocker on your system, the best possibility to get your data back is to recover it from your backup.
Medfos MaladvertisingUnfortunately, the malware campaign doesn't end here. It also employed Medfos, a Trojan that has write-ups from 2012. Medfos is a clickfraud Trojan that earns profit for malware distributors by running on unattended computers.
Medfos receives a list of websites that allow Pay Per Click advertising. Advertising agencies pay associates based on the number of clicks through an advertisement. This Trojan loads these websites in "headless" web browser applications that do not have visible windows and pretends to click an advertisement.
It only takes one computer infected with Medfos to overwhelm a home broadband connection; it loads hundreds of ads per minute. To add insult to injury, the bot controller performs regular checks to make sure Medfos is continually running and reinstalls the Trojan as needed.
Watch out for signs that your computer has been infected by Medfos. The Trojan runs from two DLLs that are visible in the process list from the Application Data folder. Additionally, it adds a new browser add-on, most recently dubbed Addons Engine 3.0.1 to Firefox, but normally uses Internet Explorer for heavy downloading. Medfos hijacks search engine settings in your browser so that when you think you're searching Google, you're actually sending information to Medfos-controlled pages.
Kegotip Wants EverythingIt's common for cybercriminals to steal and spread victims' personal information like passwords. In this recent malware campaign, perpetrators scan the infected system's files to search for anything that resembles an email address.
The Trojan, called Kegotip, sends a batch of email addresses every 15 to 30 seconds in a specially crafted packet to a server specifically listening to them on Transmission Control Protocol) (TCP) port 20051. You can identify this packet because the data portion always starts with the text string "Asdj," which ends up actually translating to "QXNka" according to the encoding format used by the bot.
Kegotip sifts through Internet-enabled applications, like File Transfer Protocol (FTP) clients, email apps or browsers, for stored credentials. These cybercriminals work efficiently: the report claims that two Kegotip attacks carried out transmitted over 15MB of stolen email addresses and fake credentials from two infected machines in the lab network.
Stop Infection Before It StartsMalware threats are certainly frightening, so it's important that you protect your devices before they get infected. Invest in antivirus software and keep it updated to protect yourself against future threats. Some good choices are our Editors' Choice Bitdefender Antivirus Plus (2014), Norton Antivirus (2014), or Webroot SecureAnywhere Antivirus 2013. Remember the fight against cybercriminals isn't hopeless; you can overcome these malware demons like your childhood nightmares.

Webroot Proves 'Secure' Need Not Mean 'Slow'

Fast planes
Back in the dark days of 2005 and 2006, many computer users started noticing an unpleasant phenomenon. They'd install a recommended security suite only to find that ordinary activities got sluggish, or worse. Norton had a particularly bad reputation for hogging resources. Some people were permanently traumatized by the experience; to this day, they believe that installing a security suite will bring their daily computer use to a grinding halt. Well, it just ain't so, not anymore. One suite in particular is both crazy small and crazy lightweight, but suites in general are doing much better.
Measuring Performance Impact
Starting five or six years ago, security vendors got the message. It's not enough to pile on code for protection against phishing, malware, spam, and exploits. They also needed to streamline that code, make it as efficient as possible, and look for every possible way to limit use of system resources. And they're succeeding!
I run several tests to evaluate what impact a suite's protection has on system performance. One script moves and copies a ton of huge files between drives. A suite whose real-time antivirus spends too much time checking these files might slow down that process. The same might happen to another script that zips and unzips this same collection. I time ten or twelve runs with no suite and average the result, then do the same with a security suite installed. Recent suites have averaged a 20 percent increase in time required for the move/copy test, and 16 percent for the zip/unzip test, which is nothing compared to the bad old days.
Getting all of those security services running at startup can take time, so I also measure boot time with and without a suite. This one's a little harder, because a number of modern security suites will let the user trade security for speed by choosing to delay the launch of some security components. If there's a choice, I always switch to maximum security. The average modern suite slows the boot process by 24 percent. Give that might mean the system boots in a minute and a quarter instead of a minute, again that's not so bad.
The Tiniest Impact
I find that some security suites run ten or fifteen distinct processes and services. A few actually install and run multiple separate modules—Trend Micro Titanium Maximum Security 2014 is an example. At the far opposite extreme is Webroot SecureAnywhere Complete (2014), with just one process. Not surprisingly, Webroot has less impact than any other suite in my tests.
Webroot also takes less space on disk than any other suite I've seen. The installer (which is the same for all Webroot products) is about three quarters of a megabyte in size, and Webroot SecureAnywhere Antivirus (2014) takes barely more than that once installed. Even with all of the additional features in the full Webroot suite, it's still less than 100MB on disk.
I spoke with Joe Jaroch, a VP of Engineering at Webroot, about just how this is possible. Jaroch explained that the designers always look for ways to re-use code. The same antivirus code that checks for a changed file can be used by the backup system to identify a file that needs to be re-synced, for example. Also, as much of the malware analysis process as possible occurs in the cloud, not on the local system. He noted that the user interface is almost entirely created using drawing commands, not by stored bitmaps and other resources.
However they manage to do it, Webroot is definitely the smallest suite around, with the lightest performance impact I've measured. Sure, it does omit spam filtering and parental control, but not everyone needs those. If you're still traumatized by the days of big, resource-hogging suites, Webroot may be just what the doctor ordered