Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!
Showing posts with label antimalware. Show all posts
Showing posts with label antimalware. Show all posts

Sunday, November 2, 2008

MSN cleaner

Fuente
INFO Tux & Cía:
Los usuarios que son clientes de Tux & Cía. deben recabar cierta información antes de usar el MSNCleaner. Esta herramienta de limpieza destruye un importante nivel de protección configurado en los equipos vendidos por la consultoría y a los que se implementó una Política de Protección de Datos.

Descripción:
MSNCleaner elimina malwares que utilizan programas de mensajería instantánea, como Msn Messenger, Windows Live Messenger, entre otros.
MSNCleaner no bloqueará su página de inicio y si por alguna razón no puede poner la página de su preferencia, utilice el programa IniRem 2.0.exe, el cual desbloqueará el navegador Internet Explorer y puede colocar la página de inicio que desee.

Algunos de los Malwares que elimina MSNCleaner

  • Foto_Celular.scr
  • Foto_Celular.zip
  • Foto_Posse.zip
  • Bush.exe
  • Desnuda.exe
  • F0538_jpg.zip
  • Fotos.zip - Fotos roberto.exe
  • img4851.zip
  • IMG-0024.zip
  • IMG0024.zip
  • MessengerSkinner
  • MSN Content Plus
  • MSN Messenger Guiños
  • MyGallery5156.zip
  • p0017_jpg.zip
  • Photos-webcam2007.zip
  • PictureAlbum2007.zip
  • portaldeayuda - portaldeayudita
  • S_00305_jpg.zip
  • W139_jpg.zip
  • Winks Instalador
  • Z058_jpg.zip
  • Listado completo de archivos que detecta y elimina MSNCleaner
  • Otras características
    • Desbloquea el "Regedit"
    • Desbloquea el "Task Manager"
    • Desbloquea la pagina de inicio en "IE".
    • Borra archivos temporales
    • Restaura valores originales del registro de Windows
    • Restaura el archivo "HOSTS" al original
    • Habilita las funciones del "Panel de Control".
    • Habilita el "Escritorio"
    • Habilita el "Iconos de Escritorio"
    • Habilita el "Reloj"
    • Habilita el "Apagar equipo" en el Menú Inicio.
    • Habilita el "Buscador" en el Menú Inicio.
    • Habilita el "Ejecutar" en el Menú Inicio.
    • Habilita el "Consola CMD"
    • Habilita el "Menú Contextual"
    • Habilita el "Opciones de Carpeta"
    • Sistema de Backup (respaldo) en "C:\MSNCleaner\BackUpMsnCleaner"
    • Función automática de "Borrar al reiniciar" para archivos rebeldes.

    Thursday, October 16, 2008

    EMSIsoft.com

    Source

    a-squared Free 3.5
    Freeware! This program contains only the basic scanner. Background Guard, Automatic Updates, Scheduled Scans and HiJackFree are only available with a-squared Anti-Malware.
    Version 3.5.0.25 - 7/31/2008 - for Windows XP, 2003/2008 Server and Vista, limited functionality on x64 (26 MB) changelog stable/beta

    a-squared Free Download

    a-squared Command Line Scanner 4.0
    Freeware! This program is a console application to scan your PC. It was made for professionals who don't need a setup or graphical user interface. All features of the Anti-Malware scanner are included.
    Version 4.0.0.14 - 9/13/2008 - for Windows XP, 2003/2008 Server and Vista, limited functionality on x64 (56 MB)

    a-squared Commandline Scanner Download

    a-squared Emergency USB Stick files
    Freeware!
    Contains a-squared Free and a-squared Commandline Scanner files. Unpack the zip to a USB Stick to make an easy to use scanning and removal tool.
    This file is kept always up to date with the latest program and signature files. For Windows XP, 2003/2008 Server and Vista, limited functionality on x64 (25 MB)

    a-squared Emergency USB Stick files Download

    a-squared HiJackFree 3.1
    Freeware!
    a-squared HiJackFree helps advanced users to detect and remove Malware manually.
    Version 3.1.0.16 - 5/12/2008 - for Windows XP, 2003/2008 Server and Vista, limited functionality on x64 (2 MB).

    a-squared HiJackFree Download
    Standalone EXE

    a-squared Anti-Dialer 3.5
    Freeware! a-squared Anti-Dialer scans the harddisk for Dialers and provides a permanent background guard protection against new Dialer infections.
    Version 3.5.0.5 - 6/11/2008 - for Windows XP, 2003/2008 Server and Vista, limited functionality on x64 (3 MB).
    a-squared Anti-Dialer Download

    XP Antivirus 2008, XP Antivirus 2009, and XPAntiVirus

    Extracted from Source

    What this programs does:
    XP Antivirus 2008, XP Antivirus 2009, and XPAntiVirus are rogue antivirus programs that, when run, display false results as a tactic to scare you into purchasing the software. Older versions of XP Antivirus would create 9 entries in your Windows Registry that impersonate infections on your machine. In reality, though, these registry entries were harmless and had absolutely no effect on your computer. Instead, these entries were set so that XP AntiVirus can find them when scanning your computer and report them as infections. The newer of versions of the program , such as XP Antivirus 2008 and XP Antivirus 2009, instead just display false results when scanning your computer that state infections were found. In order to remove these fake infections, though, you would first need to purchase the software as the trial does not allow you to remove them.
    While running, XP Antivirus will also display fake alerts stating that you are infected or under attack from some type of threat. These alerts are fake and can be ignored. If you do click on the alert, though, it will prompt you to purchase the software. Examples of text contained in these alerts can be found below.

    Privacy Violation alert!
    XP antivirus detected Privacy Violation. Some program is secretly sending your private data to untrusted internet host. Click here to block this activity by removing threats (Recommended).
    or
    System files modification alert!
    Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unathorised
    <sic> modification by removing threats (Recommended).

    As you can see these programs are fraudware because they make changes to your computer and then state these changes are infections as a scare tactic to have you purchase the software. It goes without saying that under no circumstances should you buy it. The older program, XPAntivirus, does come with a removal option in the computer's Add or Remove Programs list, but when you attempt to uninstall it, all that happens is the entry is removed from the list and program's process is terminated. Next time you reboot, XP AntiVirus will start up again. The newer versions of the program do not contain an entry in the Add or Remove Programs list at all.

    XP Antivirus 2008 screenshot
    XP Antivirus 2008 screenshot
    For more screen shots of this infection click on the image above.
    There are a total of 7 images you can view.

    Tools Needed for this fix:

    Wednesday, October 15, 2008

    McAfee Avert Stinger

    Source
    Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system. Stinger utilizes next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations.
    How do I use Stinger?
    The Stinger for W32/Polip can be found here
    1. Download v10.0.1.602 [2,482,695 bytes] (9/18/2008)

    2. Download ePOStg305.Zip EPO deployable version (for EPO administrators). Instructions for EPO 2.5X and EPO 3.X are available.
    3. This version of Stinger includes detection for all known variants:
      More...
    When the download is complete, navigate to the folder that contains the
    downloaded Stinger file, and run it. WindowsME/XP users read
    this first
    .
    Command-line parameters for Stinger. The parameters are displayed when passing Stinger the /? switch:
    • /ADL - Scan all local drives.
    • /GO - Start scanning immediately.
    • /LOG - Save the log file after scans.
    • /SILENT - Do not display graphical interface.

    MSN cleaner

    Fuente

    Descripción:
    MSNCleaner.exe Elimina malwares
    que utilizan Programas de mensajería instantánea, como Msn Messenger,
    Windows Live Messenger, entre otros.

    MSNCleaner no bloqueará su página de inicio y si por alguna razón no
    puede poner la página de su preferencia, utilice el programa IniRem 2.0.exe, el cual desbloqueará el navegador Internet Explorer y puede colocar la página de inicio que desee.


    Algunos de los Malwares que elimina MSNCleaner

  • Foto_Celular.scr
  • Foto_Celular.zip
  • Foto_Posse.zip
  • Bush.exe
  • Desnuda.exe
  • F0538_jpg.zip
  • Fotos.zip - Fotos roberto.exe
  • img4851.zip
  • IMG-0024.zip
  • IMG0024.zip
  • MessengerSkinner
  • MSN Content Plus
  • MSN Messenger Guiños
  • MyGallery5156.zip
  • p0017_jpg.zip
  • Photos-webcam2007.zip
  • PictureAlbum2007.zip
  • portaldeayuda - portaldeayudita
  • S_00305_jpg.zip
  • W139_jpg.zip
  • Winks Instalador
  • Z058_jpg.zip
  • Listado completo de archivos que detecta y elimina MSNCleaner



  • Utilización correcta del MSNCleaner
    .- Descargar el programa MSNCleaner.zip, lo puede descargar al final del tema

    .- Reiniciar el sistema en Modo a Prueba de Fallos

    .- Utilizar el programa MSNCleaner.exe (Ultima Versión)
    • Descomprimir el archivo MSNCleaner.zip
    • Ejecutar el archivo MSNCleaner.exe
    • Hacer Clic en el botón Analizar, Si se detecta algún archivo nocivo, se activará el botón Eliminar
    • Seleccionar las opciones "Eliminar archivos temporales" y "Restaurar el archivo Hosts"
    • Hacer Clic en el botón Eliminar
    .- Utilizar el programa CCleaner
    • Primero Ejecutar la opción "Limpiador" para eliminar cookies, archivos temporales, etc. Luego utilizar la opción de "Registro" para limpiar el registro de Windows (Recuerde hacer una copia de seguridad)
    .- Reinicie en modo normal.



    Otras características
    • Desbloquea el "Regedit"
    • Desbloquea el "Task Manager"
    • Desbloquea la pagina de inicio en "IE".
    • Borra archivos temporales
    • Restaura valores originales del registro de Windows
    • Restaura el archivo "HOSTS" al original
    • Habilita las funciones del "Panel de Control".
    • Habilita el "Escritorio"
    • Habilita el "Iconos de Escritorio"
    • Habilita el "Reloj"
    • Habilita el "Apagar equipo" en el Menú Inicio.
    • Habilita el "Buscador" en el Menú Inicio.
    • Habilita el "Ejecutar" en el Menú Inicio.
    • Habilita el "Consola CMD"
    • Habilita el "Menú Contextual"
    • Habilita el "Opciones de Carpeta"
    • Sistema de Backup (respaldo) en "C:\MSNCleaner\BackUpMsnCleaner"
    • Función automática de "Borrar al reiniciar" para archivos rebeldes.
    Descargar MSNcleaner:
    MSNCleaner.zip

    RogueRemover

    Source
    The Internet today is full of scam sites, otherwise known as phishing sites that try to sell you products. These products can be potenially harmful to your computer. They install malware, provide false feedback about your computer, and can slow down the computer drastically. These products are known as rogue applications and come in a variety of forms - from anti-malware applications to registry cleaners and even hard drive utilities.
    We at Malwarebytes realize this is becoming a more prevalent issue, and have created a free application to help keep you safe and secure - RogueRemover FREE
    RogueRemover FREE is an application that can remove rogue antispyware, antivirus, and hard drive cleaning applications with ease. Rogue applications provide false information about the safety of your computer as well as, give erroneous scan results or put their own malware on your computer.

    RogueRemover FREE has the ability to completely remove WinAntiSpyware / WinAntiVirus, SpyAxe, VirusBlast, VirusBursters, as well as a number of other rogue applications. In addition, we have implemented a threats center which will allow you to keep up to date with the latest rogue threats.

    Usage
    Simply download RogueRemover FREE from the one of the links below. Double click the downloaded file to install the application on your computer. Once the application is installed, double click on the RogueRemover FREE icon to start the program. When the application is open, select Scan and the application will guide you through the remaining steps.

    Download

    Monday, October 13, 2008

    prevx.com

    Source

    Prevx CSI

    Free PC Check

    What does Prevx CSI do?
    Scans your PC checking for active malware
    Prevx CSI includes a very fast malware scanner that will find and fix active rootkit, spyware, trojan, virus and malware infections in about 1 minute. It's free and you can use it as often as you like, you only pay if you want to use Prevx CSI to remove infections.

    Finds and fixes all types of PC infections Prevx CSI can be used free of charge to find active infections including rootkits and advanced spyware. You can use it as often as you like for free to ensure nothing has bypassed your antivirus or other security software. If your PC is infected you can use Prevx CSI to remove the infection and restore your PC to good health. Removal requires the purchase of a license key from our website.

    How does Prevx CSI find infections that other security products missed?Prevx CSI has been used by more than 2 million people to find and remove PC infections that were missed by other security products. Our database includes details of more than 3.5 million infections and we add protection for more than 500,000 new infections every month. That's more than any other security company. Most anti-virus products will only detect about 50% of the new threats we see every month.

    Use Prevx CSI free PC check to find rootkit, spyware, trojan, virus and malware infections on your PC
    Simply download and run Prevx CSI, it will check your PC for active infections in about a minute
    Check your PC and remove malware infections in around a minute with the World's fastest malware scanner.

    Prevx CSI at a glance
    • Ultra-fast scanner typically takes just a minute
    • Works with all major antivirus and security products
    • Always up to date with the World's largest threat database
    • Finds advanced spyware
    • Finds low volume targeted attack malware
    • Finds viruses, Trojans, Adware, Bots
    • Provides free detection
    • Can be run as often as you like
    • You only need pay to remove infections
    • The easiest and fastest guaranteed way to restore your PC to full health and safety
    Don't risk using an infected PC when fixing it is so cheap and easy

    ---------------------------------------------------------
    Prevx 2.0 (anti-malware) Protect your PC from rootkits, spyware, trojans, worms, viruses, and any other malicious files threatening your PC security.
    • Desktop / Laptop

    Windows XP and Windows 2000 Professional
    (All versions - 32/64bit)



    Windows Vista Beta (All versions - 32/64bit)
    (Please Note this is a BETA release - You must use an Admin type account and disable UAC).
    To
    turn off User Account Control (UAC) in Vista go to the Vista Control
    Panel, User Accounts and Family Safety, User Accounts, Turn User
    Account Control on or off.


    • Server Edition

    Windows 2003 Server (All versions - 32/64bit) and Windows 2000 Server (SP4 only).

    Saturday, October 11, 2008

    Reanimator 2.0.7

    Source
    Download
    filesize 455.31 KB

    Reanimator is a utility for automatically restarting all applications and background-only processes that have been shut down by another process.

    RegRun Reanimator | Rogue SW Reanimator

    Source (Software ruso!)
    Reanimator is a free of charge software for removing Trojans/Adware/Spyware and some of the rootkits.
    Reanimator does not contain any adware/spyware modules.
    Supported Windows 95/98/Me/NT4/2000/XP/2003/VISTA.
    Compatible with all known antiviral software. Download
    ---------------------------------------------------------

    NTOSKRNL.DLL is a user mode rootkit. It hides its presence in the registry and in the loaded modules listing.

    You could not delete it using standard Windows deletion methods.


    Removal Instructions

    1. Download our special software:
      RegRun Reanimator
      Unzip it to any folder on your hard drive.
    2. Open Reanimator.exe. Open "Reanimator" menu, "Execute Reanimator Job". Choose "ntsystem.rnr" file. "NTSYSTEM.RNR" job contains the procedure for activating RegRun Partizan and deleting the ntsystem.exe and ntoskrnl.dll at reboot.
      You will see the "RegRun Partizan" on the Windows blue boot screen in the same moment when Windows checking hard drives.
      Look at the messages on the screen to be sure that the dangerous files are deleted.
    3. Restart your computer. Open Reanimator and choose "Scan for Viruses" to be sure that it is complete.
    4. Visit our Support center if you have any questions.
      Open a support ticket and attach your detailed system report made by RegRun Reanimator.
    5. To remove Partizan from your computer, open Reanimator.exe, go to "Features", "Partizan".
      Click on the "Remove" button.


    Rogue SW: Triunfo Reanimator (shitware engañifle)
    Fuente (Sitio marcado como no fiable en wot.com!) Cuidado!

    Instrucciones de eliminación de triunfo Reanimator
    Triunfo Reanimator es uno de las últimas versiones del software falsificado del anti-spyware Reanimator que pone en peligro el mundo de computadoras.
    Gane Reanimator se instala generalmente sobre su PC sin su permiso, con Vundo Trojan, virus o software falso. El triunfo Reanimator exhibirá alarmas falsas del sistema o alarmas falsas de la seguridad para trampear a usuario para comprar la versión pagada del triunfo Reanimator, para quitar el potencial y los problemas divulgados. ¡Los mensajes de error probables incluyen, “Windows han detectado la infección del spyware! Se recomienda para utilizar las herramientas especiales del antispyware para prevenir pérdida de los datos. Windows ahora descargará e instalará el antispyware más actualizado para usted. Haga click aquí para proteger su computadora contra spyware!” No sólo hace su máquina retrasar dramáticamente, también pondría su aislamiento y datos en riesgo.

    Utilidad de la detección de SpyHunter* Spyware de la transferencia directa.

    Instrucciones manuales de eliminación:

    Pare los procesos de Reanimator del triunfo:
    Triunfo Reanimator.exe

    Encuentre y suprima estos archivos de Reanimator del triunfo:
    Triunfo Reanimator.exe
    Triunfo Reanimator.lnk
    Triunfo Reanimator.url
    Triunfo Reanimator.lnk de Uninstall

    Quite los valores del registro de Reanimator del triunfo:
    HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ triunfo Reanimator

    Developer Merijn tools

    Source
    (Webpage of Merijn, developer of HijackThis and CWShredder)
    FAQ of HijackThis and CWShredder

    HijackThis 2.02 Beta

    HijackThis is a general homepage hijacker detector and remover that targets the methods used by the most common hijackers


    July 8th, 2007 GMT
    License: Freeware
    File size: 1.24 MB



    BugOff 1.10

    BugOff - Disable 3 exploits that browser hijackers commonly use, including CWS (CWShredder)


    April 19th, 2007 GMT
    License: Freeware
    File size: 25 KB



    CoolWebShredder 2.19

    CoolWebShredder will find and destroy all traces of the CoolWebSearch (CWS) hijacker on your system


    April 19th, 2007 GMT
    License: Freeware
    File size: 520 KB



    KazaaBegone 1.30.0

    KazaaBegone application was designed to be a Kazaa uninstaller that scans and removes all elements of all Kazaa


    April 19th, 2007 GMT
    License: Freeware
    File size: 74 KB




    ADS Spy 1.11

    ADS Spy was designed to be a small tool that will help you list, view or delete Alternate Data Streams (ADS)


    April 19th, 2007 GMT
    License: Freeware
    File size: 29 KB



    StartupList 2.02

    StartupList is a simple tool that lists all and every auto starting program on your system.


    November 1st, 2006 GMT
    License: Freeware
    File size: 158 KB



    BHOList 1.5.0

    A simple frontend for Tony Kleins BHO Collection.


    March 30th, 2006 GMT
    License: Freeware
    File size: 57 KB



    Itty Bitty Process Manager 1.04

    Itty Bitty Process Manager shows full paths to processes, optionally shows DLLs loaded by processes


    March 21st, 2006 GMT
    License: Freeware
    File size: 30 KB



    Kill2me 1.11

    Kill2me is a free removal tool specifically for the Look2Me parasite. Not for WinXP or 2000

    April 29th, 2004 GMT
    License: Freeware
    File size: 13 KB

    Friday, October 10, 2008

    Proteja seu Pen-drive de infecções

    Source
    Com o completo desuso dos disquetes chegamos a era dos pen-drives, objeto de armazenamento de arquivos simples, rápido e super prático. Bastou plugar em um PC qualquer e já estará funcionando.
    Devido a esta alta mobilidade dos pen-drives, é cada vez mais comum as infecções nestes dispositivos onde possuem um poder muito grande de disseminação. Pode parecer um artigo muito maçante e muito longo, mais que valerá a pena ser lido.

    Entenda como funciona:
    Ao plugar o seu pen-drive em um PC que já infectado, o seu pen-drive
    carregará a infecção para o seu próprio PC ou um outro PC no qual o seu
    pen-drive for plugado, formado uma cadeia.
    Isto também é válido para cartões de memória, telefones celulares, mp3/mp4 e demais dispositivos de armazenamento USB.

    Sintomas da infecção:

    • A Unidade fica inacessível
    • Erros de Autorun são comuns na tela
    • A opção de ver arquivos Ocultos fica desabilitada e/ou nunca fica ativada
    • Incapacidade de apagar/mover arquivos do pendrive
    Remoção da infecção: Ler mais
    Download PenClean
    Download USB WriteProtector
    Download AutoPlayConfig

    Thursday, October 9, 2008

    SiteHound

    Sitehound box small gifSiteHound protects you and your computer from phishing, scams, spyware, adware, security risks, viruses and objectionable content while you surf the web. Free version for Internet Explorer and Firefox.

    AWARD WINNING PROTECTION WHILE YOU USE THE INTERNET
    SiteHound is a toolbar for Microsoft Internet Explorer and Mozilla Firefox which alerts you if you're about to enter a potentially dangerous website.

    Today the most common route for attacks on your computer is through
    your web browser as you surf the web. Everyday, people around the world
    fall victim to online fraud, scams, security vulnerabilities and
    malware while surfing the web, and most people realise before its too
    late.


    SiteHound solves this alarming security gap by working with some of the world’s leading security watchdogs to provide you with instant and real-time protection for you as you surf the web.

    Leer Más Download

    MS Malicious Software Removal Tool

    Updated: September 9, 2008

    Tools iconSkip the details and download the tool

    The Microsoft Windows Malicious Software Removal Tool checks computers running Windows Vista, Windows XP, Windows 2000, and Windows Server 2003 for infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom—and helps remove any infection found. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.

    Microsoft releases an updated version of this tool on the second Tuesday of each month, and as needed to respond to security incidents. The tool is available from Microsoft Update, Windows Update and the Microsoft Download Center.

    Note  The version of the tool delivered by Microsoft Update and Windows Update runs in the background and then reports if an infection is found. If you would like to run this tool more than once a month, use the version on this Web page or install the version that is available in the Download Center.

    Because computers can appear to function normally when infected, Microsoft advises you to run this tool even if your computer seems to be fine. You should also use up-to-date antivirus software to help protect your computer from other malicious software.

    To download the latest version of this tool, please visit the Microsoft Download Center.

    Use browser security add-ons!

    Why users should...?

    Because when you search online for software or services, links to malware or rogue is around.
    Because when you click on a page or link, malware or rogue installers are around too.

    So what browser security add-ons do you use?
    We have a discussion at Calendar of Updates on September 2007 and I bump it today by updating what browser security add-ons is effective still and what is the new add-on that is also effective: Read it!

    Intrusion Prevention System

    An intrusion prevention system is a network security
    device that monitors network and/or system activities for malicious or
    unwanted behavior and can react, in real-time, to block or prevent
    those activities. Network-based IPS, for example, will operate in-line
    to monitor all network traffic for malicious code or attacks. When an
    attack is detected, it can drop the offending packets while still
    allowing all other traffic to pass. Intrusion prevention technology is considered by some to be an extension of intrusion detection
    (IDS) technology. The term "Intrusion Prevention System" was coined by
    Andrew Plato who was a technical writer and consultant for *NetworkICE


    Intrusion prevention systems (IPS) evolved in the late 1990s to
    resolve ambiguities in passive network monitoring by placing detection
    systems in-line. Early IPS were IDS that were able to implement
    prevention commands to firewalls and access control changes to routers.
    This technique fell short operationally for it created a race condition
    between the IDS and the exploit as it passed through the control
    mechanism. Inline IPS can be seen as an improvement upon firewall
    technologies (snort inline is integrated into one), IPS can make access
    control decisions based on application content, rather than IP address or ports as traditional firewalls
    had done. However, in order to improve performance and accuracy of
    classification mapping, most IPS use destination port in their
    signature format. As IPS systems were originally a literal extension of
    intrusion detection systems, they continue to be related.


    Intrusion prevention systems may also serve secondarily at the host
    level to deny potentially malicious activity. There are advantages and
    disadvantages to host-based IPS compared with network-based IPS. In
    many cases, the technologies are thought to be complementary.


    An Intrusion Prevention system must also be a very good Intrusion
    Detection system to enable a low rate of false positives. Some IPS
    systems can also prevent yet to be discovered attacks, such as those
    caused by a Buffer overflow.


    Host-based
    A host-based IPS (HIPS) is one where the
    intrusion-prevention application is resident on that specific IP
    address, usually on a single computer. HIPS compliments traditional
    finger-print-based and heuristic antivirus detection methods, since it
    does not need continuous updates to stay ahead of new malware. As
    ill-intended code needs to modify the system or other software residing
    on the machine to achieve its evil aims, a truly comprehensive HIPS
    system will notice some of the resulting changes and prevent the action
    by default or notify the user for permission.


    Extensive use of system resources can be a drawback of existing HIPS
    systems, which integrate firewall, system-level action control and sandboxing
    into a coordinated detection net, on top of a traditional AV product.
    This extensive protection scheme may be warranted for a laptop computer
    frequently operating in untrusted environments (e.g. on cafe or airport
    Wi-Fi networks), but the heavy defenses may take their toll on battery
    life and noticeably impair the generic responsiveness of the computer
    as the HIPS protective component and the traditional AV product check
    each file on a PC to see if it is malware against a huge blacklist.
    Alternatively if HIPS is combined with an AV product utilising whitelisting
    technology then there is far less use of system resources as many
    applications on the PC are trusted (whitelisted). HIPS as an
    application then becomes a real alternative to traditional antivirus products.

    Wednesday, October 8, 2008

    Decompression Delay & Security

    Source
    Decompression Delay Blinds On-Access Memory Scanners & Generic Unpacking Engines

    1. Executive SummaryA delayed execution of a compressed or crypted executable may cause memory scanners as well as file scanners using a generic unpacking engine (emulation) to scan a file while it is still encrypted. This will result in a signature mismatch so that malware becomes undetected.

    2. BackgroundWe assume that (i) certain on-access memory scanners try to scan an executable file immediately after its execution in order to reduce the time span in which malware can perform harmful activities or cloak itself, (ii) certain on-access memory scanners scan an executed file only once in order to minimize the scanner's impact on system resources, (iii) generic unpacking engines are slower than static unpacking engines and, therefore, must stop the emulation of a compressed or crypted file after a certain time period has expired, (iv) generic unpacking engines generally try not to emulate non-encrypted files.
    Against this background, we asked ourselves what will happen if an encrypted/compressed executable firstly performs a few instructions and then stops its execution for several seconds before it proceeds to unpack/decrypt itself into the memory. Will this behavior cause a memory scanner or generic unpacking engine to scan the file before it is decrypted? If yes: will the scanning of an encrypted file simply result in a signature mismatch so that the scanner effectively becomes blind or are there any fallback systems like clever heuristics that come into play?

    3. Test ProcedureWe took a few compressed/crypted malware samples (Bionet, Lithium, Optix Lite & Optix Killer) from our test archive. Subsequently, we modified these compressed/crypted samples so that the decompression/decryption procedure is delayed:

    (a) Original Trojan Samples
    Bionet 3.18 (crypted with Netwalker)
    Lithium 1.03 (compressed with PeX099)
    Optix Lite 0.4 (compressed/crypted with UPX, PeX099 or Netwalker)
    Optix Killer 3.0 (compressed with PeX099)

    (b) MessageBox Variants
    The MessageBox variants contain additional instructions displaying a message box. The file will not be decompressed/decrypted before the OK Button of the message box is pressed (i.e., the message box allows to "simulate" a stealthy decompression/decryption delay).
    In order to use the message box function we added the required imports from user32.dll or, alternatively, we "hardcoded" the respective function into the file (such samples will only run on Windows XP SP2). Moreover, we changed the original entry point of the compressed file so that it directs to a "cave" (i.e., an empty region of the file which does not contain any relevant data). At the location of the new entry point the instructions displaying the message box are located. After the respective instructions are performed a jump directs the execution flow to the orginal entry point where the file will be decompressed/decrypted as usual by the relevant decompression/decryption stub.

    (c) Sleep Variants
    The Sleep variants are more dangerous than the MessageBox variants and come very close to a "real world" threat (e.g., a compressed rootkit that uses a decompression delay in order to bypass on-access memory scanners or emulations until it had the chance to cloak itself so that it becomes entirely invisible). The executed sleepy variants are not decompressed/decrypted until they had a good night's rest (i.e., the execution of the file is delayed for a few seconds before the instructions of the decompression/decryption stub are performed).

    In order to use the sleep function we added the required imports from kernel32.dll and proceeded in the same way as described above under (b).

    (d) Sleep.WSA Variants
    In addition to the sleep function these variants contain a few instructions that may be used to fool a generic unpacking engine (i.e., very basic anti-emulation code). More specifically, we used instructions that are generally not performed prior to the decompression/decryption of a packed/crypted sample so that an emulation may come to the conclusion that it deals with a file that has already been decompressed/decrypted. In such case, the emulation may stop and the scan engine may be unable to match the sample with its signature database. This will depend on whether code-based signatures or alternative detection methods (e.g., heuristics or signatures taken from the resource section) are used.

    (e) Brute.Loop Variants
    These variants are based on the Sleep.WSA variants or, respectively, the original compressed samples. The Brute.Loop variants repeat thousands of "redundant" instructions before the PeX decompression stub is processed. The idea is to exploit the speed disadvantage of generic unpacking engines (i.e., because an emulation is much slower than a real computer it may have to stop the emulation before the unpacking stub is reached). The Brute.LoopC variants do not require a change of the original entry point or added imports. Starting from the original entry point the execution flow is simply directed to a loop and then redirected to the unpacking stub.

    The modified trojan variants were scanned with the help of various file and memory scanners. In addition to the modified variants we also scanned the original, uncompressed samples and non-modified, compressed/crypted samples. (This is to make sure that a scanner does not have any general problems to detect the particular trojan or handle the relevant packer/crypter.) In order to test the capabilities of an on-access scanner it was necessary to execute the test samples.

    Please note that we did not further modify the variants. In particular, we did not rebase or encrypt the samples (or otherwise complicate their detection).

    We do not describe the above test procedure (i.e., the creation of the modified variants and the tools used for adding imports, calculating jumps, assembling instructions etc.) in more detail because this is not a hacker site. We would like to mention, however, that it takes only a few minutes (or even less time) to modify a trojan in the above-described ways (i.e., we are not talking about complex code but only about 2-7 instructions and a few additional mouse clicks). Even inexperienced attackers may be able to replicate the above-described steps (and combine them with other anti-detection techniques).

    Security software

    Source
    Security Software categories:
      1. Anti-Virus
      2. Anti-Trojan
      3. Anti-Spyware/Malware
      4. Firewall
      5. SandBox/application monitoring (HIPS)
      6. Process related (process to port mapping)

      Other security softwares
      Conclusion

    The purpose of this page is to give you an example of a complete set of security softwares, to give you an idea as to how to secure you.
    Ok. let's start, i assume that if you have reached this point, you have already read and applied windows security tips given in the advices area.

    Main security software categories for home user :
      * Anti-Virus
      * Anti-Trojan
      * Anti-Spyware/Malware
      * Firewall
      * SandBox/application monitoring (HIPS)
      * Process related (process protection, process to port mapping)

    Additional security software categories i won't talk about :
      * Data Encryption (Files, network)
      * Privacy management

    (there are more, but i want to focus on the main ones. I know some could say that to talk about a minimum security to have without talking about privacy is idiot, but if you follow the software set above, your privacy will be indirectly safe, of course you can still add privacy related softwares.)

    1 - ANTI-VIRUS Probably with the Firewall categorie one of the most controversed topic, about which is good and which not, and why. I just recall to the reader that i give an example, a good one, but not necessarely the best.
    Their are so much viruses/worms in the wild that an AV is absolutly needed nowadays, it's a bare minimum to have. I have tested Kasperky, NOD32, Norton, and AVG.
    If you want to check an independant AV testing website, check out
    http://www.av-comparatives.org


    I advise NOD32, or KAV 6.0
    NOD32 has one of the best Heuristic module, which means that it performs very good at detecting unknown viruses, not yet added in any AV signatures base. It is also very light on ressources.
    NOD32 : http://www.nod32.com/download/trial.htm


    KAV 6.0 has probably one of the best detection rate (known viruses), and Kaspersky Lab is very quick at submiting new AV signatures when new viruses/worms are detected in the wild.
    (KInternetSecurity 6.0 has the same GUI than KAntiVirus 6.0)
    Moreover, KAV 6.0 includes the firewall leak tester awarded 'Proactive Defense' technology (that you can choose to not install if you wish installing the AV part only).
    KIS & KAV 6.0 : http://www.kaspersky.com/

    2 - ANTI-TROJAN Trojans can be more dangerous than a virus, while this one can destroy your files or altered them, a trojan can give a full access to a remote intruder who can do what he wants on your computer, in fact, he can do all you can do, he can find all your private and sensitive information.
    In the worst case, you computer can be turned in a "zombie", attacking target without your knowledge (e.g. Microsoft), and only making you visible (appear as the attacker) hiding the true one, the cracker.

    I advise
    Ewido
    Ewido 4.0 is in beta stage for now...
    Ewido is now part of the AVG Technologies family of world-class
    Anti-Virus and Internet Security products. ewido users will benefit
    from AVG's comprehensive threat research and support resources.
    Look for more on AVG:
    AVG Internet Security
    Anti-Virus, Anti-Spyware, Anti-Spam, Web Protection & Firewall
    Comprehensive protection for your computer! AVG ensures your safety
    while you search or surf the net, download music, documents and
    pictures, send emails or instant message by scanning documents, files,
    Web pages and Web links before you open them. AVG Internet Security is
    a reliable and easy-to-use solution for home and small office users.
    Unique Internet security thanks to new technologyOnly AVG gives you real-time protection against malicious websites thanks to our new LinkScanner technology.

    There is still techniques from the malware side to try fighting generic unpacking and emulation, if this subject interest you, you can read the following article :
    http://scheinsicherheit.pytalhost.de/decompdelay.htm

    3 - ANTI-SPYWARE/MALWARE Spywares are a recent annoying kind of threat, their purpose is to advertise you, by all the way possible (to make you go on a website, about different subjects, to the most simple like to buy a car, to the worst like porn website, a threat for your childs). To do that, they show you popups, redirect your surfing at an unexpected website, hijack your softwares (mainly your browser, mail client, instant messaging client), and write registry entries.
    All of that leads often to privacy leaks (retrieve information about you to the authors) system stress (CPU & Memory consumption), and surfing/playing annoyances (bandwitdh consumption).

    The two most well known Anti-Spyware are SpyBot and Ad-Aware.
    I talk about "Spybot S&D 1.4".
    Spybot is well known on the anti-spyware scene, and does it's job very well.
    Spybot provides an-demand scanner, and a resident protection called "tea-timer".
    One interesting feature is the IE "Immunization", described in the help file :

    The permanent immunity works on some Internet Explorer control options that are partly visible in the Internet Explorer interface, partly hidden in the registry only. It adds domains known to contain bad contents into the Restricted Zone, thus blocking installation of executable code from those pages; it also adds block options for bad executable code by its ID, and it sets known tracking cookies to not be accepted by Internet Explorer.

    To cut it short: it modifies Internet Explorer, through official ways, to block a lot of the bad stuff known to Spybot-S&D.
    Download link:

    safer-networking.org

    4 - FIREWALL Ouch, the hot topic.
    A "firewall" is not the same thing for everyone, so hard to tell you "the best" (i can't).
    A basic firewall, as it used to be, is a vanilla packet filter, which mean that it checks rules (ip adresses, ports, protocols) and allows traffic or drop it. Nowadays, Windows home users needs have evolved, and so, firewalls too. Now, their are firewalls which handles websites cookies, emails spam, websites popups, bandwitdh throttler, port to process mapper, and most include outbound application filtering (their are other features like plugins, etc...)
    Because everyone's needs is different, a "best" firewall can't be chose.

    Note : on this website i'm talking about leaktests, so about outbound application filtering. Thus, the "score board" does not show good and bad firewalls, only good and bad outbound application filtering (a firewall is more than that, but it's an important part ).

    I will talk about firewalls like softwares able to allow/block inbound/outbound network traffic, and have an outbound application filtering.

    i advise "Look'n'Stop 2.05".
    (their are a lot more like ZoneAlarm, Outpost, etc...)



    LNS uses very little ressources, what it mean that it won't slow down your computer or your surfing.
    It has the application filtering (one of the best) and the network filtering splitted, which mean that someone behind a NAT router (with a firewall integrated and well configured) can only use the application filtering without to bother to deal with the network filtering (that he can disabled).
    For others without routers, LNS provides you preconfigured set of rules to avoid you to waste time to setting it up.
    Their are advanced rules to really make you invisible to scans.
    If you are concerned by web's threat management by your "firewall", norton could be good despite of his bad application filtering and his "ressource hogger" behaviour.
    Look'n'Stop website

    5 - APPLICATION MONITORING This approach is very interesting and very effective, if you can't fight all known and unknown threats, the most effective is to prevent threats to load, simply.
    Because basically even the most sophisticated threat is just an executable, monitoring executables launching on his system is a strong additional layer of security.
    A real "SandBox" software (or HIPS, stands for Host Intrusion Prevention System) will write a list of trusted executables (BlakIce for instance checks all your system executables to the setup) and will block the launch of any other applications.

    I advise Ghost Security Suite 1.110 from Ghost Security

    Also take a look at the
    firewall leak tester awarded 'Proactive Defense' technology, part of KAV6 and KIS6.



    Ghost Security Suite includes two softwares in one, AppDefend & RegDefend. You can choose to buy or install either part alone, you are not required to install the suite.

    RegDefend is a kernel registry protector, it intercepts read/write access to the registry and allow/block/ask depending of the settings. It can so prevent a malware from writing an entry in the "Run" registry key, thus preventing it to automatically run at each startup. Registry parts to monitor are completely customisable.

    AppDefend is a "sandbox" or HIPS software, it is a system monitoring software, allowing the user to watch application activities, and to allow or block what he wants to. From AppDefend forum, below are the threats that AppDefend protects against :
    Network access, Process creation, Process execution, Global Hooks (DLL injection / Keyloggers), Process/Thread suspension and context modification, Virtual Memory modification, Remote Thread Creation, Physical Memory access, Termination of threads and processes, Rootkit installation methods.

    The Proactive Defense included in KAV 6.0 or KIS 6.0 can globally do the same, except for process termination. On the other side, the Proactive Defense can detect invisible processes, hidden from the task manager by a rootkit driver. Both products have overlaps, but also have complementary features.
    By configuring both correctly, it is possible to run them concurrently, and to gain a very strong security layer.
    Download links :
    Ghost Security Suite
    Kaspèrsky AntiVirus

    6 - PROCESS RELATED In this area, i will talk about 1 kind of software :
    * process to port mapping
    The "process to port mapping" means that you can trace which process is using which port, which protocol, is connected to which IP adress, etc...
    By being able to see your system connections states, you are able to detect by yourself trojans, spywares, or worms.
    Because sometimes you can allow a software to run, and then allow it to connect to the internet to do one action, but because sometimes you are not sure if you can totally trust it, with a process to port mapper you can see excatly what it does.

    There are several process to port mapper out there, not one relying on the same method to detect _accuratly_ processes and ports, some are slow, others innacurate.
    The best i have ever seen is "Port Explorer" 1.800 from DiamondCS.



    This security software provides usefull tools to analyse processes and their network's connections. You can choose one line and to terminate the process, or let it alive but preventing it just to send data (but letting it to receive), or preventing it to send and/or received data, you can spy what a process send/received with a built in packet sniffer, you can restrict bandwitdh a process can use (for instance block it to 5Kb/s max), and you can do many other things like whois/lookup etc...
    An intesresting feature is that Port Explorer will let you see possible suspicious processes by highliting them in red, such processes have one or many sockets belonging to them, but hasn't any windows displayed (like trojans does). Of course a simple Instant messaging minimized to the systray will be in this case, but a trojan too... it allows you to quickly see suspicious processes.
    At the end, the display is totally customizable, you can choose all colours, and choose your language between : Dutch, English, French, German, Italian, Portuguese, Spannish, and Sweddish.
    To test it or buy it

    Other security softwares :

    With such softwares installed and _properly configured_ your computer is turned on a heavy fortress. Of course it asks time, personal investigation, and money... but these softwares really worth it, atleast try them.

    For those who want more choice, as a quick example, an other software set could be : Kaspersky, BoClean, Spybot, Outpost, Abstrusion protector, Port Explorer, ProcessGuard, even if there is in this list softwares that don't have all the features of those i chose.

    You can try to improve even more your security by doing data encryption or by adding specialized privacy related softwares, but i stop here because all software shown are sufficient to provide you a strong security.

    Conclusion :
    If everyone was educated to the security, worms and viruses would fall down in the dark and we would never anymore heard of them.
    It has nothing to do with "IQ", but with education, you don't know that you have to do something until you learn it from your mistakes, or from someone else.
    I know, sadly, a lot of friends who never update Windows and doesn't have any security related softwares, sometimes just an Anti-Virus outdated, don't wonder how worms can spread around the world, it's all about education.

    After many years of studying security, I have noticed that threats level has "jumped" when the Internet has became ordinary at home, when high bandwidth connections started to be available at low prices for everyone, when it has became a fashion.
    Which wasn't important before that, all security stuff, is nowadays a must to have.
    For proof, just format and install Windows, connect to the internet, and you will be infected by a worm in 10s or less, it would have sounds unbelievable there are few years.
    The internet isn't anymore a game place where you can go on gaming sites, forums, looking at beautifull wallpapers, and listen music and enjoy with all entertainments... users have now to understand real risks they can encounter, they have to bother with security (i say "bother" because i know people not enthousiasm to do that) _before_ their personal entertainments.

    So, keep using best guidances, install a security software suite and understand it, keep going on security forum to be aware of lastest threats, and you will see that to have a safe computer never hurted by malicious threats is possible, but only possible if you want it.

    Tuesday, October 7, 2008

    StartupMonitor

    Source

    StartupMonitor is a small utility that runs transparently (it doesn't even use a tray icon) and notifies you when any program registers itself to run at system startup. It prevents annoying programs from registering themselves behind your back.
    StartupMonitor does not require Startup Control Panel, but it complements it nicely. When you choose not to allow a program to register itself, the program's entry becomes disabled in Startup
    Control Panel, so you can go back and enable it later if necessary.
    StartupMonitor watches the Start Menu's Startup folders and the Run entries in the registry.
    StartupMonitor works on all modern versions of Windows through XP. I haven't tried it on Windows Vista yet.

    gadgetbar

    Internet Security Software

    The best compilation! Thanks to firewallguide.com!

    Patches, Updates & Service Packs

    Anti-Malware
    Internet
    Communication
    • Email Client --
      Try
      Thunderbird with anti-spam and anti-phishing as an alternative to Outlook Express.
    • Email Encryption -- Try
      the Hush Mail email service.
    • Instant Messaging Security -- Try
      IMSecure