Showing posts with label Online Services. Show all posts
Showing posts with label Online Services. Show all posts

Web Sites Increasing Vigilance Against Malware

These days, if you're publishing a web site - or surfing the web - you have to watch your back, constantly. Merely publishing a secure site - or only surfing to secure sites - may not be enough. Any link on any web site might link to another web site, with malware. Worse, any link on any web site might not link to a web site with malware, but to a web site that links to another web site, with malware. And so on ...

How do you draw the line how far to look? You can use a browser add-on which monitors your surfing, and tells you which web sites are safe, or aren't safe - but that add-on better go beyond just checking the immediate web site.

This month, we see progress in that direction. Just yesterday, I was asked, in Blogger Help Forum: Something Is Broken

I see that Blogger says "Blog Unavailable"
Upon further investigation, I found interesting reports from "safebrowsing.clients.google.com", which appears to be a database fed by Google and StopBadware.org.


The top level reports simply says that "earnovertheinternet.blogspot.com" is a dodgy web site. Here I won't comment on the name, more commentary will be found elsewhere.



We click on the "Why was this site blocked" button, and see the report for "earnovertheinternet.blogspot.com". "earnovertheinternet.blogspot.com" is clean, but it links to "popuptraffic.com".



We click on the link for "popuptraffic.com", and see the report for "popuptraffic.com". "popuptraffic.com" is clean, but it links to "javapo.t35.com", "downner.blogspot.com", and "lpspain.galeon.com".



We click on the link for "javapo.t35.com", and see the report for "javapo.t35.com". "javapo.t35.com" is not clean. Reports for "downner.blogspot.com", and "lpspain.galeon.com" contained similar warnings.



I'll note here the stated dangers from "javapo.t35.com"
25 page(s) resulted in malicious software being downloaded and installed without user consent ...

Malicious software includes 26 exploit(s), 2 trojan(s), 1 scripting exploit(s). Successful infection resulted in an average of 5 new process(es) on the target machine ... Malicious software is hosted on 12 domain(s), including velassin.com/, rmbclick.com/, 39m.net/.

11 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including popuptraffic.com/, adtrak.net/, hele.t35.com/.
We see evidence that the web site monitoring process is persistently cyclic.
The last time Google visited this site was on 2009-09-04, and the last time suspicious content was found on this site was on 2009-09-04.
And, it describes details about the degree of danger.
Malicious software includes 26 exploit(s), 2 trojan(s), 1 scripting exploit(s). Successful infection resulted in an average of 5 new process(es) on the target machine.


"earnovertheinternet.blogspot.com" and "popuptraffic.com" had apparently been visited that same day, 2009/09/17.
What is the current listing status for earnovertheinternet.blogspot.com?
Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.
What happened when Google visited this site?
Of the 1 pages we tested on the site over the past 90 days, 1 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-09-17, and the last time suspicious content was found on this site was on 2009-09-17.


The owner of "earnovertheinternet.blogspot.com" (you'll note that I won't be linking there) states his intention to clean up his act, and to convince at least one other web site to do likewise.
I will remove those popups ... I asked the admin of popuptrafic


This is a start. Get the responsible web sites to remove their links to dodgy web sites. Enough action here, and one day, maybe no more dodgy web sites.

We can dream, can't we?

>> Top

Online Analysis Of Suspicious Websites

One of the neatest ways to distribute malware nowadays is by serving it from a web site. Why push malware by files to the victims computer - just put the bad stuff on your web site, and entice the victim to surf there. If he does so, intentionally, he's more likely to trust you, and badda bing, download your malware to his computer.

The classic way of protecting us from malicious web sites was stopping us from surfing there, generally using Hosts file based web site blocking.

Besides web site blocking, and malware protection (both active and passive) on your computer, you need malware scanning of any web site that you access. And what better way to do this than by using the power of the web?

  • AVG / Exploit Prevention Labs provides LinkScanner, which can be accessed as a browser add-on or queried online. LinkScanner does a live scan on Google, Yahoo and MSN search results, rather than querying a database of previous scan results.
  • FireTrust provides SiteHound, which can be accessed as a Firefox or Internet Explorer toolbar.
  • McAfee provides Site Advisor, which can be accessed as a Firefox add-on, or queried online. SiteAdvisor has an accumulated database, a web site popularity meter ("nitecruzr.net" shows a 2 of 4 - "some users"), plus does real-time evaluation when requested. They also accept comments from site readers, and from site owners.
  • A partnership between top academic institutions, technology industry leaders, and volunteers provides StopBadware.org, which feeds the Google search engine results pages. Google uses the StopBadware database, and accepts input by site owners through Google Webmaster Tools.
  • Symantec provides Norton SafeWeb, which appears to be intended as a plugin to a Norton security suite, though it does provide for web based queries. SafeWeb accepts comments from site readers.
So there are choices. Try them, and see which one suits your needs to the best degree.


(Update 2009/09/18): Today, we note a significant increase in vigilance.


>> Top

Get Reliable Online Malware Advice

Usenet will always be the best place, for many, for looking for help. The true geeks hang out in the forums there, because Usenet (or its predecessors, the dialup bulletin boards) has been around before the Web.

The attractions of Usenet are several.


  • Easy access. Anybody with a computer, and either a newsreader (like Forte Agent or Mozilla Thunderbird), or with a browser and access to Google Groups, can access Usenet. Many people have no idea where Google Groups started.
  • No authenticated registration or identity verification required. Just read and write. Or just write (as the trolls and spammers will do).
  • No obligations incurred. You can write what you wish, and nobody will ever hunt you down in person to discuss your mistakes.

And there is a summary of the problems of getting advice from Usenet, without researching each forum carefully.

If you have a malware problem, you absolutely need reliable advice. Ask for help in Usenet, and you may well get advice from one of the trolls that hang out there. For reliable malware analysis and removal, get advice from a reliable forum which requires identity verification. All such forums are web accessed, and require authenticated registration, which is generally free, and should offer posting history with the helpers.

These are but 7 forums which help with malware in general, and HijackThis logs in particular. There are several others, too. You may find still more on your own. I will describe my favourites, 3 of the above 7.

BBR Security Cleanup has a very dynamic mix of helpers. With BBR Forums (of which the BBR Security Cleanup Forum is but a part), the experienced helpers there, like the other forums, are registered (thus have verifiable identity). With BBR Forums, though, there's a much wider range of expert knowlege; and with the helpers being registered, you can cross-reference all previous posts made by each helper. So it's easy to note which helpers are more trustworthy, and have more complete knowlege of what they write. To start asking for help in BBR Security Cleanup, you will do well to start with their FAQ: Mandatory Steps Before Requesting Assistance.

Conversely, I have watched SpywareInfo develop over the past few years. They have a management structure there, with a training and certification process, and very professional behaviour. That's not a place of frivolity, nor flaming, so anybody fearing Usenet (everybody posting to Usenet gets flamed eventually) need not fear SWI Forums. SWI Forums is very narrowly focused, on malware detection and removal, and they do a very good job of both. To start asking for help in SWI Forums, you will do well to start with their FAQ: How to remove spyware or a hijacker.

And Tom Mercado has been working with security for a good while, and is well known in the above forums. In TeMerc's Internet CounterMeasures, Tom offers a personalised approach, with same day response on HijackThis logs.

Whichever forum you choose, though, note that each forum has procedures which they want you to follow, which help the helpers there interpret your log accurately and consistently. That's to everybody's benefit. So be very diligent - read, and follow, the instructions they provide.

Work with the helpers, and they will work with you.

Online Analysis Of Suspicious Files

Let's say you run any one of my favourite problem analysis or detection tools, such as:


and you find one or more mysterious entries. What do you do now? Kill, then delete the processes? It may not be quite that easy - or that safe. Please, research what you're deleting, and the possible consequences of deleting it, BEFORE you do so.

A lot of malware today will install itself in a package - creating 2 or more processes on your computer. Also, some security software, badly designed, may protect you, but may use names, or other identity elements, that may give it the appearance of malware.

It's relatively easy to identify a single, active process that steals your passwords, throws ads on the screen, or creates links to distant, mysterious computers.

Some malware, though, will package itself in 2 or more components. It will include protective components, that ensure that the other process(es) continue running on your computer, even if you try to delete or kill them. When the protective processes detect that the active processes were deleted or terminated, it will make new copies of the other processes, frequently using different names, and restart the bad active processes.

Delete or kill one program, and suddenly you'll have a second program (maybe with a different name), doing the work of the process that you just killed. You have to kill the background protective processes first. When you find a suspicious file or process, examine it, and ensure that there's no other process referencing or protecting it.

There are several web sites where you can upload any suspicious file found on your computer, which will submit your uploaded file to multiple scanning engines for intensive analysis. Just go to either website and upload the file using the web page. This takes maybe 30 seconds to upload a file, then wait 5 - 10 minutes for a free analysis.

Examining the logs from any of the above utilities, do you see any malware identified? If so, don't panic - do some research. Note which scanning engines detected the malware, and cross-reference those to free, online system scanning services.

In order for a protective bad process to restart a protected bad process (one that's detected by HijackThis), the protective bad process has to contain some portion of, or reference to, the active bad process. Any individual scanning engine (called by Jotti and/or VirusTotal), that can find malware in an active bad process, should similarly be able to find the same malware in any other file on the computer, if additional bad files exist. Running a whole system scan, you look for other files that contain the detected malware.

Pick one or more of the scanning services which identified the malware, and do a complete system scan. Either a HijackFree, or a HijackThis, log is a good starting point; but both HJF and HJT are limited, in that they find malware using established patterns. Make sure the malware you are experiencing is not in other places too. Use all possible analytic tools.

In the case of very well written malware, it may be very difficult (if not impossible) for YOU to identify, and delete, all components of the malware simultaneously. Its protective processes may be written to detect your feeble human actions, and it can restart itself faster than you can kill or delete it.

But don't despair! Just identify all components of the malware at any time (without killing and / or deleting anything). Then use Pocket Killbox. You identify ALL of the bad files or processes to Pocket Killbox, and Pocket Killbox takes care of them for you. It's like having a team of well trained snipers, each aiming at a different bad guy. firing simultaneously, and killing all of the bad guys without warning any.

If you have any doubts about this technique, or if even Killbox can't get rid of the bad stuff, remember the Expert Help Forums. Any time Jotti or VirusTotal identifies a bad file, spend some time searching thru 2 or 3 of these forums. Find out what techniques and tools are currently being used to remove the identified malware. Again, Strength Thru Diversity.

Just don't guess at the problem. Use the power of the web, and work from the experience of those who have already dealt with your malware.

Now for the bad news. Some malware may protect itself, from being deleted or interrupted, by hiding itself. You cannot delete that which you cannot see.

As malware has evolved, the properly designed anti-malware protection will also scan each web page as you surf the Internet. In some cases, you should have access to an OnLine Web Site Analysis product.

>> Top

Online System Virus Scanning Services

Please understand me here - don't misunderstand the purpose of this article. You absolutely must have up to date, real time virus protection on your computer. Even if you have no money to pay for one, that's OK, there are several excellent, free products. As far as a vendor recommendation, please feel free to peruse the neverending discussions in alt.comp.virus.

But even with up to date, real time protection (and please don't try running two installed virus protection products simultaneously), you will experience times when a second - and a third - opinion is necessary.

Fortunately, you don't have to download and install more software. In this case, there are several excellent free online services, that will scan your entire system, using applets running under the control of your browser, at your convenience.


BitDefender
eTrust
F-Secure
Kaspersky
McAfee
MicroWorld
Panda
RAV
Symantec
TrendMicro

Eric Howes Rogue/Suspect Anti-Spyware Products & Web Sites has another list of online virus scanning services, with more possibilities.

Not all of the above work with both Microsoft and Mozilla browsers, but choose carefully, and you should be able to find one or more that will work for you.

Getting Help On Usenet - And Believing What You're Told

Usenet, and other online forums, will always be the best place on the Internet for free help. The true geeks hang out in the forums there, because Usenet (or its predecessors, the dialup bulletin boards) has been around before the Web, when a forum was a computer with one or more modems, and posting to a forum meant dialing up to that computer. If you have a Usenet Reader, don't just use web based forums, and you've been around for a while, you may know what I mean.

The best - and the worst - thing about Usenet is the anonymity. You can be who ever you wish to be, and nobody can tell the difference. Anonymity on Usenet is a blessing, and a curse. If you need advice, how do you know who to trust?

Common sense is a good way to start.


  • Look for a forum where the posts contain serious, well stated questions, and serious, well stated answers.
  • Look for a forum where people seem to use first and last names, or first names anyway, and where people seem to recognise and respect each other.
  • Avoid forums where people post in "leet speak", or use mysterious names.
  • Avoid forums where half the posts consist of arguments, or flame wars.


Here, Google is your friend. Google has all Usenet forums, archived for some time previous. When you find a forum where you feel comfortable, and find persons who seem to be useful, spend some time reading older posts.

Peer review is a benefit of Usenet. The helpers in a forum where serious help is provided will not tolerate bad technical advice. Anybody speaking from lack of knowledge will be quickly corrected. Look for helpers who provide careful, well stated advice, and who don't get corrected a lot. Or look for helpers who make mistakes, accept and acknowlege their mistakes, and fix their mistakes. Remember that many helpers are learning too.

Remember, anybody can post on Usenet, and can use any name that they like. Be careful when you accept advice - if you find what looks like good advice, spend some time reading previous posts by that advisor, and make sure the content and style of all articles is consistent. Make sure that the advice you're accepting is from someone who has been providing advice for a while, and not by an imposter or imitator - in serious help forums, anybody giving bogus or misleading advice won't be tolerated for long.

In short, don't be mislead by trolls.

And, when you ask for help, try and fit in. If you respect and trust the helpers, it's likely that they will respect and help you.

Help Us To Help You.

  • Trust us.
  • Provide relevant background information about your problem.
  • Don't edit or munge the diagnostic data requested. Since you don't know what the problem is (if you do, why are you looking for help?), you don't know what detail might be relevant to its diagnosis.