Author Topic: The war against Adware is just beginning  (Read 6372 times)

0 Members and 4 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34059
  • malware fighter
The war against Adware is just beginning
« on: July 09, 2005, 08:46:44 PM »
Hi ye all,

Deafeating extended threats.

Much like it is with Spam to-day, Adware will transform to avoid detection and removal. Keeping machines clean will require a multi-layered approach and remediation strategy, including:

1. Educated users on the dangers of freeware and Internet downloads.
2. Tighten the Web gateway policy with URL-filtering and download restrictions (filtering on CAB & OCX files downloads)
3. Tighten Webbrowser's settings and maintain the current version of the browser.
4. Lockdown desktops to prevent new applications from laoding.
5. Use a two factor authentication.
6. Selectively use single purpose anti-malware tools to clean up desktops.
7. Ask your AV vendow to include more extended threats in the signature files.
8. Deploy enterprise anti-spyware tools only as a means of last resort.

greets,

polonus
« Last Edit: July 09, 2005, 08:48:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34059
  • malware fighter
Re: The war against Adware is just beginning
« Reply #1 on: December 10, 2014, 01:30:24 AM »
Another step is the beta extension Ad Nauseam extension making the clicking circle full
to help you defend against surveillance and tracking by ad-networks:
At the moment only for firefox: https://dhowe.github.io/AdNauseam/
Being prepared also to come to Chrome.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: The war against Adware is just beginning
« Reply #2 on: December 10, 2014, 02:07:27 AM »
99% of someones security is not their protection, rather the smartness of what they do online. If you're smart, theoretically, one would not need protection... Now, that being said, you have special cases with USB Worms. But for adware. Rule of thumb. Only go to Official Websites, read the EULA's, check, make sure none of the check-boxes are checked, or if they are, you know what it's doing. Read the EULA (End User License Agreement).

Now, obviously, people like me prefer having the security in case. But you cannot rely on it 100% people. If you do, don't be surprised if you get infected by adware!

(Great program to HELP is Unchecky. It won't block everything. But it does help for the slip ups!)

Unchecky download: http://unchecky.com/

Notes for Downloading: Have ad-blocker setup and functional. Sites like Bleeping Computer have ads that matching there's, making it slightly difficult to find the "Real McCoy".

Edit Reason: Fixed the Spelling errors
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: The war against Adware is just beginning
« Reply #3 on: December 10, 2014, 04:03:16 PM »
You have not seen the real bad boy yet http://www.bleepingcomputer.com/forums/t/559220/operation-global-iii-ransomware-not-only-encrypts-but-infects-your-data-as-well/

Quote
The Operation Global III ransomware is a computer infection that encrypts the data and executables on your computer so that they cannot be opened unless you pay a ransom. The current ransom for this infection is approximately $250 USD and must be paid with bitcoins. This particular ransomware is in some ways very basic, but includes new functionality that makes it more dangerous than previous ransomware infections. This is because not only does the Operation Global III ransomware encrypt your files, but it displays a lock screen that blocks you from using your computer till you pay the ransom, and also acts like a virus that infects your files with malicious code to spread to other computers. Thankfully, a decryption tool was able to be made, which is discussed at the end of this article.
Quote
When the ransomware is started it will display the above lockscreen so that you cant use your computer. It will also change your encrypted files extensions to .EXE and then infect them with malicious code that allows it to spread to other computers when the files are opened. If one of these files is then double-clicked it will launch the encrypter and encrypt and infect any new files. If one of these files is double-clicked on a previously unaffected computer, then this computer will become encrypted and infected as well.

Potentially the most dangerous feature of this ransomware is that it will look for unmounted network shares and mount them as a drive letter on your computer. It will then proceed to encrypt and infect the files found on these network shares as well. All previous ransomware infections would only target drive letters on the existing computer and would ignore unmapped network shares. Operation Global III on the other hands raises the ante by going after all network shares and infecting any files or executables it finds on them. As Windows by default does not display file extensions, someone on another computer would open one of these files not realizing that they are executables and then their computer would become infected as well.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: The war against Adware is just beginning
« Reply #4 on: December 10, 2014, 04:07:51 PM »
You have not seen the real bad boy yet http://www.bleepingcomputer.com/forums/t/559220/operation-global-iii-ransomware-not-only-encrypts-but-infects-your-data-as-well/

Quote
The Operation Global III ransomware is a computer infection that encrypts the data and executables on your computer so that they cannot be opened unless you pay a ransom. The current ransom for this infection is approximately $250 USD and must be paid with bitcoins. This particular ransomware is in some ways very basic, but includes new functionality that makes it more dangerous than previous ransomware infections. This is because not only does the Operation Global III ransomware encrypt your files, but it displays a lock screen that blocks you from using your computer till you pay the ransom, and also acts like a virus that infects your files with malicious code to spread to other computers. Thankfully, a decryption tool was able to be made, which is discussed at the end of this article.
Quote
When the ransomware is started it will display the above lockscreen so that you cant use your computer. It will also change your encrypted files extensions to .EXE and then infect them with malicious code that allows it to spread to other computers when the files are opened. If one of these files is then double-clicked it will launch the encrypter and encrypt and infect any new files. If one of these files is double-clicked on a previously unaffected computer, then this computer will become encrypted and infected as well.

Potentially the most dangerous feature of this ransomware is that it will look for unmounted network shares and mount them as a drive letter on your computer. It will then proceed to encrypt and infect the files found on these network shares as well. All previous ransomware infections would only target drive letters on the existing computer and would ignore unmapped network shares. Operation Global III on the other hands raises the ante by going after all network shares and infecting any files or executables it finds on them. As Windows by default does not display file extensions, someone on another computer would open one of these files not realizing that they are executables and then their computer would become infected as well.

That, is NASTY. If I understood right.... It's a combination of Win32:Sality/Vitro and Crytowall/CryptoLocker? *Shudders*. They'll never stop with new ideas. It's nice (someone) made a decryption tool for that though. Anything to clean up the malicious code from the files like the Sality Cleaner?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: The war against Adware is just beginning
« Reply #5 on: December 10, 2014, 04:11:34 PM »
Nope, recover your data and wipe the computer, re-install

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: The war against Adware is just beginning
« Reply #6 on: December 10, 2014, 04:22:51 PM »
write down everything on paper ... it can't encrypt that    ;D


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: The war against Adware is just beginning
« Reply #7 on: December 10, 2014, 04:25:16 PM »
write down everything on paper ... it can't encrypt that    ;D

Maybe not, but I find I lose paper more then my documents!! Rule of Thumb still applies though. Don't open the susipicous emails (Which, I do anyways). Browse carefully (No torrenting, Downloading watching things you really ought not to be) and don't click on downloaded files unless it's from an Official site.

Edit: Essex, does Cryptoprevent block the encryption? Any ideas about that?

« Last Edit: December 10, 2014, 04:27:37 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: The war against Adware is just beginning
« Reply #8 on: December 10, 2014, 04:38:06 PM »
Quote
Don't open the susipicous emails (Which, I do anyways)
use US mail, it is safe to open  ;)   ..... well unless it is sendt from Ted Kaczynski




Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6699
  • Trust only what you test yourself!
Re: The war against Adware is just beginning
« Reply #9 on: December 10, 2014, 08:10:41 PM »

use US mail, it is safe to open  ;)   ..... well unless it is sendt from Ted Kaczynski

He's doing life without parole as a gift of the People of the United States.
I'm pretty sure that if he mails something it's safe to open.  8)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: The war against Adware is just beginning
« Reply #10 on: December 10, 2014, 08:18:22 PM »
Pondus, I'm Canadian, not American, remember? (I had to google this Ted Guy). Seems he a serial killer.....

Yeah, I wouldn't open that either lol.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: The war against Adware is just beginning
« Reply #11 on: December 10, 2014, 08:20:18 PM »
-Use common sense when doing stuffs online.
- Only go to trusted and official websites.
- Use strong passwords.
- Install trustworthy antivirus program like AVG or Avast (keep both programs up-to-date)
- Install antimalware programs like MBAM Free and SuperAntiSpyware Free (keep both programs up-to-date)
- Keep your Windows OS up-to-date by installing updates provided by Microsoft Update.
- Keep your other programs i.e. flash, java,adobe, and your other program you use up-to-date.
- Keep a back-up copy of your computer in an external hard disk.
« Last Edit: December 10, 2014, 09:09:53 PM by Staticguy »
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: The war against Adware is just beginning
« Reply #12 on: December 10, 2014, 08:39:46 PM »
Unless AVG has gotten better over the years, I don't find it trustworthy...
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: The war against Adware is just beginning
« Reply #13 on: December 10, 2014, 09:08:52 PM »
Unless AVG has gotten better over the years, I don't find it trustworthy...

I have it installed in my desktop computer. Does a good job with it. Desktop is also 2 and a half years old. I am writing this forum in my laptop with Avast 2015. Both of them is Windows 7 SP1

I have used many antivirus program in the past Panda Cloud antivirus, mcafee, trend micro, MSE, Windows Live One Care. None of these are good and not trustworthy.

I have used AVG for many years (i think since the release of AVG 2012) and I have been using Avast in my laptop when it released version 7. I have been using MBAM Free since version 1.70 and SAS Free since version 5.0.1108.
« Last Edit: December 10, 2014, 09:24:12 PM by Staticguy »
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2