Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Monday, December 20, 2010

Unraveling Malware Myths

     Computer Viruses throughout this era have evolved in a very complex manner that a lot of people have started to make their own perceptions of these creations. In this post we'll clarify some myths about computer viruses that most of our folks had spread in our neighborhood.

Throughout this post we'll refer to our subject as Malware, since we're not just referring to computer viruses but all sort of harmful software which is itself Malware. So here are some myths about Malware that either you've heard, or you already believe with.

1. Malware spreads in Hardware. This is entirely crazy for me. Malware are software, and they can only affect software. No malware can eat your GPU nor make your processor break its pins, so if your computer gets infected, transferring some of your hardware peripherals and parts won't matter. They cannot infect other computers, except for your hard disk drive, for this is where the malware is saved. Actually nowadays some malware developers have included their works of art in some specific hardware such as printers and other removable media. Now this rarely happens as those who do this aim on targeting only specific systems. They do not really intend to cause so much ruckus but mostly focus on breaking into systems.

2. Once you get infected, Malware will spread, even with your system off. Just as mentioned before, every malware is a piece of software, so it requires a functional operating system to propagate. It cannot run with just itself and infect your hard drives without your fake Windows operating systems installed and more obviously, it will not work if your computer's power is off. This is the same with your removable storage devices such as flash drives. The phase of infection starts when your device is plugged in. So no matter how fast you transfer your data into your device or into your computer, if the host computer is infected with a removable-media-spreading malware, it will get a copy of the malware even before you start what you will do. Moreover,  malware do not actually run on the flashdrive, but on the host computer itself. If you ever find your device attached with something like a malware and whenever you delete it, it just comes back, then you probably have that one running in your system.

3. I have one or more Anti-virus (AV) software, so I am protected. This is never true. No matter how expensive nor whoever created your AV, you still have a chance of catching a malware in some way. Everyday, tens of thousands of new variants of malware are created. Even if these AV companies get a hold with most of these, there are still some malware out there in the wild that are still unrecognized by your AV. Even installing all of those AVs that you know won't make you invulnerable and actually, that is a big waste of your computer resources. Practically, you only need one AV Software. These AV Software are almost the same with their services, though some of them offer some other feature that are not present with the other ones. So generally, if you want malware protection, grab only one AV software and always have it updated. No AV is good without an update.

4. Viruses can destroy any sort of file. Viruses, also known as file-infecting malware, are also coded or made by humans, not computers themselves, so they only have specific and limited features. Most viruses spread by infecting .exe, .com and .scr files in a system, while some target only specific files such as .doc and other ones. There is a very rare sort of malware that encrypt a lot of types of files, rendering them unusable without the aid of the creator of the malware itself. This sort of malware is also known as Ransomware, where the malware encrypts files, making it only reusable with the use of a certain password, which can only be obtained from the maker of the malware himself. However, these ransomware do not encrypt all sort of files

5. You cannot catch malware from image files. These malware folks have already made a way for you to catch their pets by just opening a simple image. These images, when opened, executes a set of commands which initiates the malware, or just downloads the malware itself.

6. AV Companies create malware. If you are in the Infosec industry, you probably already understand this. These companies are already busy coping up with the battalion of malware that are created every minute, and the developers of these malware already outnumber them. I do not work for any AV Company and this one may sound possible, but it is not.

7. You won't catch malware if you don't download or transfer files from removable storage devices. Another falsity. There are hundreds of ways on how you can catch malware, such as simply browsing webpages, or being connected over a local network or the internet itself, depending on your level of security.

     There are a lot of other funny myths out there that I might have possibly missed in this post. Whatever those are, it's up for you to decide whether they are true or not. Just always remember, Vigilance is the best protection.


Read more...

Securelist Malware Statistics as of August 2010

     Here comes Securelist's malware statistics as based on the infections and malicious activities last month of August.


Direct Link:

http://www.securelist.com/en/analysis/204792135/Monthly_Malware_Statistics_August_2010

     As usual, there are new comers in the top 20 and the malware developers are still harassing unpatched vulnerabilities. What actually caught my attention this time is CVE-2010-2568, a vulnerability in Windows LNK Shortcuts. Four of the malware in the top 20 list uses this exploit by creating a link inside directories. The malware is triggered when a user explores a folder that contains one of these nice shortcuts. Fortunately, I did not encounter any of these cute little pets in my system this recent month.

Read more...

Wednesday, September 8, 2010

Securelist Malware Statistics as of August 2010

     Here comes Securelist's malware statistics as based on the infections and malicious activities last month of August.


Direct Link:

http://www.securelist.com/en/analysis/204792135/Monthly_Malware_Statistics_August_2010

     As usual, there are new comers in the top 20 and the malware developers are still harassing unpatched vulnerabilities. What actually caught my attention this time is CVE-2010-2568, a vulnerability in Windows LNK Shortcuts. Four of the malware in the top 20 list uses this exploit by creating a link inside directories. The malware is triggered when a user explores a folder that contains one of these nice shortcuts. Fortunately, I did not encounter any of these cute little pets in my system this recent month.

Read more...

Monday, August 16, 2010

Browsing Safety: Scanning hyperlinks

     Malware-spreading technology nowadays have become so innovative that even visiting a webpage can cause your machine to be infected. So how do we make sure the links and webpages that we visit do not contain something malicious? Here are some tips that you might want to take note for a safe browsing.

1. Use a Sandboxed Browser. This is one (if not the) of the most basic and safest way to ensure that no webpage can cause unpleasant changes to your computer. With a sandboxed browser, you are sure that any attempt to change the settings or copying files into your computer are blocked or filtered.

2. Stop and Look before clicking. How sure are you that the link you see in the webpage directs you to the page you are expecting? With simple HTML, a malicious coder can have you visit his webpage that contains a Drive-by or downloader that infects your computer. Here's an example:

http://www.google.com/cse?cx=002683415331144861350%3Atsq8didf9x0&q=online+link+scanner&ie=utf-8&sa=Search

     If you simply read the link above, you would assume that you are to visit a search result in google, But if you check your browser's status bar(bottom row in your browser that shows the status of a webpage), it actually points to my blog's URL. This may seem to be an easy trick, but if you are in some exciting read about something over the internet, you most likely don't give notice to this.

3. Believe in your Anti-virus' link scanner. When your AV says it is a blacklisted page or URL, believe it. Dont risk your crucial data and information over your wrong suspicions. IT Guys know what is harmful and what is not for your system.

4. Scan the suspicious link! If you got the seconds to do so, scan your links with online link scanners. There are lot of 'em out there in the wild. A good sample that I personally use is www.UrlVoid.com.*

5. Use a proxy website. This one may not be so convenient, but in case you are sure that the webpage you are to visit is unhealthy for your computer and you only need to read a few lines from it, use a Proxy website. Just like Online Link Scanners, there are lot of them and they are also free to use.

     There are a lot of other techniques to ensure safety when browsing that I did not happen to include here so just google 'em.

*TrendMicro Link scanner always report proxy websites as infected. I do not actually trust their report. XD


Read more...

Wednesday, August 11, 2010

Securelist Malware Statistics as of July 2010

     Here is Securelist's Malware statistics as based from the recent activities last month of July.

Direct link:
http://www.securelist.com/en/analysis/204792130/Monthly_Malware_Statistics_July_2010

The above link brings you to Securelist's offical statistics. I didn't bother posting it here since you'll most likely look at it. (And the image is too big for the width of my blog). Actually, I did encounter the one in the 2nd position just recently in my machine, though MSE just slapped it back. I'm hoping you didn't have a lot of these in your machines. :]

Read more...

Thursday, June 24, 2010

Online File Scanning Websites

     Almost all of us download a stuff or two over the internet almost everyday. So how do we make sure those stuff are not infected? Not something unpleasant to our system? Of course we use our Anti-malware tools and others. But what if our Anti-virus software can't detect the anomaly in our things? To make sure of it, one of the best way is to upload it to an online file scanning website.

     Here's a list of online file scanning websites. These websites allow you to upload a file and have it scanned by their bunch (if not complete) of anti-virus applications FOR FREE. Just look for their upload button somewhere in the page. (Check the links in your browser's status bar to make sure my links does not direct you somewhere else.)

  NoVirusThanks
  VirusTotal
  VirusChief
  VirScan
  Filterbit
  Jotti Viruscan

     Those websites delivers the files to Anti-virus companies for further assessment*, so in case the Malware attached in your file is still undetectable, sooner or later, it will surely be. There are a lot of other same websites out there that I may not have mentioned here, though their services may just be the same. In addition, almost all Anti-virus companies have their own such service so you may want to check 'em in their own websites.

*NoVirusThanks have an option to not to distribute your file to AV Companies.

Read more...

Friday, October 30, 2009

autorun.inf - Demystified

     Some have mistaken this type of file as something harmful to their computer. Now lets demystify what an autorun  file is.
     INF of .inf files are setting and configuration files that are made up of a set of commands that tell Windows what executable file to execute, what icon to display and so on. These are commonly used on CDs and DVDs. Autoruns cannot actually contain malicious codes or scripts. However, they can be used on any removable storage device. With this, the contents of a removable device, such as flash drives, can be automatically played just like on CDs and DVDs; that which could be harmful.

     Most of viruses developed today make a copy of themselves and an autorun file on removable devices attached to their host computer. That autorun file executes the virus associated with it once their carrier device is played or opened. This is why some people mistake it as a virus.
     Though sometimes harmful, autorun files can provide good features for our devices. I won't be teaching you how to write autorun files but I'll be leaving a nice precaution for you guys: If ever you've seen an autorun file in your removable device without ever remembering you put one, then your device is most likely infected...

Read more...