Showing posts with label Definitions. Show all posts
Showing posts with label Definitions. Show all posts

Monday, March 22, 2010

Adware

1) Generically, adware (spelled all lower case) is any software application in which advertising banners are displayed while the program is running. The authors of these applications include additional code that delivers the ads, which can be viewed through pop-up windows or through a bar that appears on a computer screen. The justification for adware is that it helps recover programming development cost and helps to hold down the cost for the user.

Adware has been criticized because it usually includes code that tracks a user's personal information and passes it on to third parties, without the user's authorization or knowledge. This practice has been dubbed spyware and has prompted an outcry from computer security and privacy advocates, including the Electronic Privacy Information Center.

Noted privacy software expert Steve Gibson of Gibson Research explains: "Spyware is any software (that) employs a user's Internet connection in the background (the so-called 'backchannel') without their knowledge or explicit permission. Silent background use of an Internet 'backchannel' connection must be preceded by a complete and truthful disclosure of proposed backchannel usage, followed by the receipt of explicit, informed consent for such use. Any software communicating across the Internet absent of these elements is guilty of information theft and is properly and rightfully termed: Spyware."

A number of software applications, including Ad-Aware and OptOut (by Gibson's company), are available as freeware to help computer users search for and remove suspected spyware programs.

2) AdWare is also a registered trademark that belongs to AdWare Systems, Inc. AdWare Systems builds accounting and media buying systems for the advertising industry and has no connection to pop-up advertising, spyware, or other invasive forms of online advertising.

Malware

Introduction

Along with viruses, one of the biggest threats to computer users on the Internet today is malware. It can hijack your browser, redirect your search attempts, serve up nasty pop-up ads, track what web sites you visit, and generally screw things up. Malware programs are usually poorly-programmed and can cause your computer to become unbearably slow and unstable in addition to all the other havoc they wreak.

Many of them will reinstall themselves even after you think you have removed them, or hide themselves deep within Windows, making them very difficult to clean. This guide will detail the different varieties of malware along with basic preventive measures. In a follow-up article, we will examine the removal process and review a set of spyware removers. Although also considered to be malware, programs such as viruses, worms, trojans, and everything else generally detected by anti-virus software will not be discussed here, and the use of the word malware will only explicitly refer to software that fits in the categories listed below.

You can get infected by malware in several ways. Malware often comes bundled with other programs (Kazaa, iMesh, and other file sharing programs seem to be the biggest bundlers). These malware programs usually pop-up ads, sending revenue from the ads to the program's authors. Others are installed from websites, pretending to be software needed to view the website. Still others, most notably some of the CoolWebSearch variants, install themselves through holes in Internet Explorer like a virus would, requiring you to do nothing but visit the wrong web page to get infected.

The vast majority, however, must be installed by the user. Unfortunately, getting infected with malware is usually much easier than getting rid of it, and once you get malware on your computer it tends to multiply.

Types of malware

Although there is no official breakdown, we can divide malware into several broad categories of malware: adware, spyware, hijackers, toolbars, and dialers. Many, if not most malware programs will fit into more than one category.

It is very common for people to use the words adware, spyware, and malware interchangeably. Most products that call themselves spyware or adware removers will actually remove all types of malware.

Adware

Adware is the class of programs that place advertisements on your screen. These may be in the form of pop-ups, pop-unders, advertisements embedded in programs, advertisements placed on top of ads in web sites, or any other way the authors can think of showing you an ad. The pop-ups generally will not be stopped by pop-up stoppers, and often are not dependent on your having Internet Explorer open. They may show up when you are playing a game, writing a document, listening to music, or anything else. Should you be surfing, the advertisements will often be related to the web page you are viewing.

Spyware

Programs classified as spyware send information about you and your computer to somebody else. Some spyware simply relays the addresses of sites you visit or terms you search for to a server somewhere. Others may send back information you type into forms in Internet Explorer or the names of files you download. Still others search your hard drive and report back what programs you have installed, contents of your e-mail client's address book (usually to be sold to spammers), or any other information about or on your computer – things such as your name, browser history, login names and passwords, credit card numbers, and your phone number and address.

Spyware often works in conjunction with toolbars. It may also use a program that is always running in the background to collect data, or it may integrate itself into Internet Explorer, allowing it to run undetected whenever Internet Explorer is open.

Hijackers

Hijackers take control of various parts of your web browser, including your home page, search pages, and search bar. They may also redirect you to certain sites should you mistype an address or prevent you from going to a website they would rather you not, such as sites that combat malware. Some will even redirect you to their own search engine when you attempt a search. NB: hijackers almost exclusively target Internet Explorer.

Toolbars

Toolbars plug into Internet Explorer and provide additional functionality such as search forms or pop-up blockers. The Google and Yahoo! toolbars are probably the most common legitimate examples, and malware toolbars often attempt to emulate their functionality and look. Malware toolbars almost always include characteristics of the other malware categories, which is usually what gets it classified as malware. Any toolbar that is installed through underhanded means falls into the category of malware.

Dialers

Dialers are programs that set up your modem connection to connect to a 1-900 number. This provides the number's owner with revenue while leaving you with a large phone bill. There are some legitimate uses for dialers, such as for people who do not have access to credit cards. Most dialers, however, are installed quietly and attempt to do their dirty work without being detected.


Antivirus Software



Antivirus (or "anti-virus") software is a class of program that searches your hard drive and floppy disks for any known or potential viruses. The market for this kind of program has expanded because of Internet growth and the increasing use of the Internet by businesses concerned about protecting their computer assets.

Virtual Private Network (VPN)

Basically, a VPN is a private network that uses a public network (usually the Internet) to connect remote sites or users together. Instead of using a dedicated, real-world connection such as leased line, a VPN uses "virtual" connections routed through the Internet from the company's private network to the remote site or employee.

Virtual private networks help distant colleagues work together.

F I R E W A L L

A firewall is a dedicated appliance, or software running on a computer, which inspects network traffic passing through it, and denies or permits passage based on a set of rules.

It is normally placed between a protected network and an unprotected network and acts like a gate to protect assets to ensure that nothing private goes out and nothing malicious comes in.

A firewall's basic task is to regulate some of the flow of traffic between computer networks of different trust levels. Typical examples are the Internet which is a zone with no trust and an internal network which is a zone of higher trust. A zone with an intermediate trust level, situated between the Internet and a trusted internal network, is often referred to as a "perimeter network" or Demilitarized zone (DMZ).

A firewall's function within a network is similar to physical firewalls with fire doors in building construction. In the former case, it is used to prevent network intrusion to the private network. In the latter case, it is intended to contain and delay structural fire from spreading to adjacent structures.

Wednesday, October 21, 2009

W32/Koobface.worm spreads via Facebook and MySpace

W32/Koobface.worm spreads via Facebook and MySpace. Current variants only target either Facebook or MySpace specifically.
------------------------------------------------------------------------------------------------------------------------------

A new variant of Koobface.worm has been seen spreading. It creates a copy of itself in %WINDOWS% directory as:

  • freddy35.exe

(where %WINDOWS% is the Windows directory e.g. C:\Windows)

It connects to the following domains and IP to send informations and receive command through HTTP request.

  • 1dns2[blocked].com
  • temp2[blocked].com
  • wm210[blocked].com
  • open21[blocked].com
  • er21[blocked].com
  • websrv[blocked].com
  • rserve[blocked].org
  • 94.142.129.[blocked]

Issued commands includes downloading and installing new malware.

STARTONCE|http://www.blankpages.be/[blocked]/websrvx.exe
START|http://www.blankpages.be/[blocked]/captcha6.exe
STARTONCE|http://www.blankpages.be/[blocked]/kaka.exe
FBTARGETPERPOST|10
RAZLOG|1
#BLACKLABEL

Downloaded malwares are identified as PWS-LDPinch, Generic Downloader.x and Puper.

The worm sends messages with a link like the one shown below, to FaceBook users.


Unsuspecting users may click the link which redirects to a page, a snapshot of which is as follows:

The displayed page contains an ActiveX control, which tells the user that their Flash Player is out of date. An attempt to update links to the Koobface malware file. At the time of testing this file was called "flash_update.exe"

Upon execution of the flash_update.exe file displays an error message but infacts drops and executes a




The file is a downloader and makes connections to the following domains:

  • y171108.com
  • aibcvienna.org
  • mediabspl.com
copy of itself from %WinDir%\bolivar28.exe

Upon execution, it downloads and opens an innocent picture(saved as %WinDir% \joke.gif) from the following web site:

  • img.123greetings.com

(where %WinDir% is the default Windows directory, for example C:\WINNT, C:\WINDOWS etc.)


It also downloads malwares(identified as BackDoor-AWQ.b trojan and Generic Backdoor trojan) from the following remote server:

  • ipluginu.cn
  • currentsession.net

The downloaded malwares further download other malwares.

The following files are added in %WinDir% folder:

  • %WinDir% \system32\splm\kbdsapi.dll
  • %WinDir% \system32\splm\lmfunit32.dll
  • %WinDir% \system32\splm\mcaserv32.dll
  • %WinDir% \system32\splm\ncsjapi32.exe
  • %WinDir%\system32\nScan\ecls.exe
  • %WinDir%\system32\nScan\ekrn.exe
  • %WinDir%\system32\nScan\ekrnAmon.dll
  • %WinDir%\system32\nScan\ekrnEmon.dll
  • %WinDir%\system32\nScan\ekrnEpfw.dll
  • %WinDir%\system32\nScan\ekrnScan.dll
  • %WinDir%\system32\nScan\em000_32.dat
  • %WinDir%\system32\nScan\em001_32.dat
  • %WinDir%\validate.inf

The following registry keys are added:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: "%WinDir% \System32\splm\ncsjapi32.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: "%WinDir% \System32\splm\ncsjapi32.exe"
  • HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: "2"
  • HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: "%WinDir% \System32\splm\ncsjapi32.exe"
  • HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: "%WinDir% \System32\splm\ncsjapi32.exe"
  • HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: "14\8\2008"

Hosts file is modified to disable the compromised machine to access most of security web sites:

such as:

  • ar.atwola.com
  • my-etrust.com
  • trendmicro.com
  • norton.com
  • nai.com
  • sophos.com
  • etc

The following files could be created depending on the variant (the filepath is hardcoded):

  • C:\WINDOWS\fbtre6.exe
  • C:\WINDOWS\mstre6.exe
  • C:\WINDOWS\f49f4d98.dat
  • C:\WINDOWS\t49f4d98.dat
  • C:\WINDOWS\fmark2.dat
  • C:\WINDOWS\tmark2.dat

The worm can connect to the following domain to do a HTTP post command and receive instructions to download and execute additional malware files:

  • zzzping.com

Facebook users receives links to download the worm via Inbox messages from infected users while links are posted in MySpace commentaries when infected MySpace users log into their account.

Current variant of the worm is faked as a codec installer named as codecsetup.exe. When the worm is ran, a dialog box will pop up with the message "Error installing Codec. Please contact support"

Symptoms -

Unexpected network connections to the previously mentioned domain

Method of Infection -

The worm spreads by fooling users into downloading and running it from links sent via Facebook and MySpace users.

Removal -

All Users:
Use specified engine and DAT files for detection and removal by your desktop Antivirus Program.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Aliases

  • Net-Worm.Win32.Koobface.b (Kaspersky)


Courtesy: McaFee.com