Skip to main content

Security Shenanigans – May 2010

I’ve noticed a few irritating trends in the virus/spam/spyware world recently.  Here are some things to watch out for:

Web Nasties
  • Steer clear of downloading screensavers, they can often be infected with viruses
  • Steer clear of apparently free tools that contain irritating adware, e.g. freeripmp3 which contains “Adware.ADON”
  • Be very careful of Online Poker sites.  These often require the downloading of software or a browser add-on which could be infected.
  • If you are browsing the web and are informed that your computer has a virus or infection treat this message with a healthy degree of scepticism.  Has the message popped up from your security software?  This should be fairly obvious.
    • Here, for example is what a security pop-up from ESET Smart Security looks like:
    • image
    • E.g. here is what a security pop-up from Norton Internet Security looks like:
    • image
    • It’s very common for spyware to infiltrate your PC by pretending to be legitimate software which tells you that you have a security problem on your PC which can magically be fixed by downloading a product such as AntiVirus 2010.  When this software is unwittingly downloaded it can really get medieval on your computer!  Here are some examples:
    • image
    • image
    • image
    • So, look at the title of the warning pop-up message.  Is it coming from your security software?  You do have security software (AKA anti-virus) yes?  Is the message popping up as window in your web browser?  If so then shut down all web browser windows.  Can’t close them all?  Try using the Alt+F4 keyboard combination.  Failing that, save any changes to any documents you might have open elsewhere and restart your computer.
Email Nasties

As always, be really careful with email attachments.  It’s amazing how often we can forget this.  Do you know the sender?  If not I’m inclined to just delete the email if it has the attachment.  If you know the sender then ask yourself if this is expected.  If not, email them and ask them if they meant to send you an attachment.  If they say yes, even then it pays to be cautious…

  • Email from security@facebook.com
    • Subject is: Facebook Password Reset Confirmation!
    • Contains Kyrptik.BKR trojan
  • Email from invitations@twitter.com
    • Subject is: Your friend invited you to Twitter
    • Contains Merond.AA worm
    • You are asked to look at an attachment (Invitation Card.zip)
    • You have to ask why you would need to do this and not just click a link to go to their website?
  • Email from greetingcard.org
    • Subject is: You have Received a Greeting Card
    • Contains Kyrptik.CEJ trojan
  • Email from various different addresses
    • Subject is: UPS Delivery Problem Number...
    • Contains Wigon.KQ trojan (rather nasty)
  • Email from various different addresses claiming to be DHL
    • Subject "Please get your parcel NR..."
    • Contains TrojanDownloader.Bredolab.AN trojan (rather nasty)
  • Email from Facebook Team
    • Subject "updated account agreement"
    • Contains an attachment such as “Facebook_Password_4cf91.zip”
    • Contains TrojanDownloader.Bredolab.AN trojan (rather nasty)
  • Email from Microsoft Team
    • Subject is: "Conflicker.B Infection Alert"
    • Contains Kryptik.CJT trojan

Comments

Popular posts from this blog

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Copying NTFS Permissions with RichCopy

 Microsoft's RichCopy is a fantastic tool for copying/moving files.  It's multithreaded so moves things along quicker and has a nice log so you can see what's working and what's going wrong. It's kind of like a GUI on top of RoboCopy and you can get it here... However, I always forget that it doesn't copy file/folder NTFS permissions by default.  This is what you need to do if you want permissions to copy across to the destination: - Click the "View" menu and then click on "Advanced". - Then click the "Option" button on the right below the "Source" and "Destination" buttons. - Click on "File attributes, Error Handling" - Tick the relevant boxes under the "Security information" section. Hope this helps.

XP Startup Issues - The Recovery Console

The Windows Recovery Console is a fantastically useful tool if you find yourself with a PC that will not boot Windows. There are many useful Windows startup tools such as Last Known Good Configuration and the many different flavours of Safe Mode but all of these rely on a bootable Windows system. System Restore is completely useless in this scenario since it relies on one being in Windows to use it. The kinds of things that could couse an unbootable Windows system could be: Corrupted boot files - e.g. NTLDR, NTDETECT.COM Corrputed Windows system files - NTOSKRNL.EXE, HAL.DLL The Recovery Console allows you to boot into an environment "underneath" that of your Windows installation (by using the Windows CD or by choosing it at boot time if you pre-installed it) and so you can perform major low level repairs to your Windows installation. Follow the link below to find out how to use the Recovery Console: http://support.microsoft.com/kb/314058/