Showing posts with label Virus Protection. Show all posts
Showing posts with label Virus Protection. Show all posts

Wednesday, 6 March 2013

Nothing short of a shock: TDSSKiller says 2 threads detected during scan

Okay, when one hits something that may cause a question about the integrity of a system we delve into our tool chest to start pulling things apart.

TDSSKiller from Kaspersky is one such tool that we turn to if there is a suspected rootkit problem.

During the TDSSKiller scan we saw 2 Threats Found until the scan completed.

That was a bit of a heart stopping moment as the system that was being scanned is used for online banking and other such sensitive transactions (user runs as Standard though).

image

Once the process completed we were presented with the above.

It's almost laughable that the two "Threats Found" where HP driver related! :P

BTW, Kaspersky has an awesome free tools reference page.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
www.thirdtier.net/enterprise-solutions-for-small-business/

Windows Live Writer

Tuesday, 10 May 2011

Via Phone: Hi, We are the National Internet Service and You are Sending Our Systems a Virus!

One of our client’s users had the presence of mind to pause for a moment when they were called at home this morning and heard the line:

Hi, we are the National Internet Service and your computer is sending our systems a virus! Please sit down at your computer and . . .

They interrupted the speaker and told them that they would be calling their IT support folks ASAP and hung up.

When things like this happen it is important to get in touch with the authorities that handle fraud cases such as this:

Contact for the Canadian Anti-Fraud Centre:

It's not always easy to spot a scam, and new ones are invented every day.

If you suspect that you may be a target of fraud, or if you have already sent funds, don't be embarrassed - you're not alone.

If you want to report a fraud, or if you need more information, contact The Canadian Anti- Fraud Centre:

Toll Free: 1-888-495-8501

Toll Free Fax: 1-888-654-9426
Email: info@antifraudcentre.ca

To report economic crime on-line please click here

One can only imagine how one can be fooled into providing all sorts of information to a caller like this.

A pearl of wisdom from my Dad: Never volunteer _anything_ in the way of information. Be specific, to the point, and KISS.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 2 May 2011

WindowsRecovery Malware – Who To Trust For Removal?

One of our client’s users picked up this lovely nasty:

image

image

Note the lack of Task Manager button in the above or below screenshots.

image

  • WindowsRecovery Malware

Now, we went to this site to download Malwarebytes and its updates:

image

Once we downloaded the two we dropped them onto a USB flash drive and plugged it into the infected machine.

When we managed to navigate to the USB flash drive the MB file was missing?!? We ended up needing to reveal hidden files in Windows Explorer as WindowsRecovery had managed to set the MB install file as hidden!

Okay, we have MB and its update installed. We were able to use the Start –> Run command to get to the mbam.exe file (Windows XP SP3 is where the infection is) but it would not update.

Once we started the MB scan and it began to pick up the infected files the malware rebooted the machine.

When we slaved up the infected machine’s hardware Microsoft Security Essentials picked up one infected file while MB found a few more. We dropped the drive back into the machine and WindowsRecovery was still there. :(

Do a Bing search for Remove WindowsRecovery and the following happens:

image

If we can’t get the machine clean using the “traditional” product in Malwarebytes then it is looking like the only option for us is to wipe and reload. There is no way we are going to trust many if not all of the sites that are in the results above. Especially all of the ones offering a “free removal tool”.

If this is a sign of the way things are going with malware infections we are going to stop wasting both our client’s time and ours and advise that we would image the machine, wipe it, and then reload it.

Now, here we are a little later on and what do we find but:

After reading through the above instructions, we will still recommend a wipe and reload. Our policy is to make this recommendation whenever a Trojan or Rootkit are involved. Once a system is owned in this manner there is virtually no way to guarantee ownership after “cleaning”.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 25 April 2011

Microsoft KB: How to send malware to Microsoft for analysis

We run across a lot of different bugs, that is malware or viruses, in our business.

Fortunately we can submit any bugs that we encounter to a number of different vendors.

One is Microsoft:

The above KB describes the many ways that we can submit the bug.

One is the following:

image

Note the How to prepare files for submission section later on in the article states:

How to prepare files for submission
Use care when you handle files that may be classified as malware. Add suspected malware files to a compressed archive file that uses a password. By doing this, you avoid infecting other computers when the files are in transit or when you send the files. To add the files to an archive file that uses a password, follow these steps.
Note If WinZip or a similar compression utility is installed, you can use it to create the archive. However, you must use the same file name and the same password that are included in these steps.
  1. In Windows Explorer, open the folder that contains the suspected malware files.
  2. Right-click a blank area in the window, point to New, and then click Compressed (zipped) Folder.
  3. Type malware.zip to name the new archive file, and then press ENTER.
  4. Drop the suspected malicious software files into the archive file as you would drop them into a typical Windows folder.
  5. Double-click the archive file.
  6. On the File menu, click Add a Password.
  7. In the Password box, type infected.
  8. In the Confirm Password box, retype infected, and then click OK.

If, during our searches we do not turn up any information on a bug that we have encountered we would follow through on submitting it just in case.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 9 March 2010

It Seems That Even USB Battery Chargers Are Vulnerability Deliverers?

The wonders of the human mind. :|

Ingenuity comes in many forms, with the old cliché being Necessity is the mother of all invention. The necessity for the bad folks is grabbing our banking information, identity, or anything else of value from our computer.

While Energizer has no idea as of yet as to how the Trojan software was planted in their device’s monitoring software package, it is now pretty much out in the open that their product did indeed deliver a Trojan to folk’s computers if they installed it.

image

A while back, USB based electronic picture frames were delivering some malicious software to folk’s systems too.

It is getting to the point where we need two systems, whether one physical and one virtual, or otherwise so that we can split off the extremely important things such as online banking to a Vista/Win 7 box with UAC enabled, Standard User permissions, and _NO_ e-mail or other browsing allowed.

Obviously, the VM OS would be used to run the daily tasks with the host being the exclusive banking and sensitive transaction machine.

We flatten. We format and reset that drive to “0” leaving no sector unturned.

If the system’s owner refuses to allow for that and requires us to “clean” a Trojan or Rootkit infected machine we get them to sign a liability waiver that exonerates us before they walk out the door.

There are absolutely _NO_ guarantees when it comes to “cleaning” a system that had a backdoor in it. None. Nada. Zippo. Zilch.

The same goes for a compromised DC by the way.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 26 February 2010

Excellent Virus Information Site Along With Links To Free Tools

This link comes by way of Harry Waldron (blog link).

image

The resources on this site are absolutely amazing! The links to free tools that can be used to detect and clean almost any type of virus or malware infection are priceless.

This is one site to bookmark and it even has an RSS link for the reader!

Thanks Harry! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 12 February 2009

ExchangeDefender is a huge time and money saver for our clients and us!

We moved our domains over to the ExchangeDefender E-mail Hygiene and Reputation Services Provider not quite three weeks ago now.

One of the first things that got noticed was the drastic reduction of junk showing up in our Junk Mail folders. By drastic reduction, we mean maybe 1 piece of spam for every couple of days!

Another change is the elimination of illicit SMTP connections to our SBS (previous blog post) based Exchange server as ISA now only allows SMTP connections from the ExchangeDefender servers.

The ExchangeDefender reports are amazing. They show how much e-mail is spam, and how much is not. They give our clients and us a pretty good idea of how much time we are saving by not having to deal with spam!

Ultimately, we no longer need to deal with all of that spam which is a huge time waster when we look at the amount of time spent sifting through the garbage everyday!

The other aspect to having our outbound e-mail passing through the ExchangeDefender servers is no longer needing to monitor black lists for our IP address or IP subnet on all of the blacklists that are out there. That in turn means that we no longer need to jump through all of the hoops required to take our IP off of a blacklist.

The big time waster when it comes to having our IP address blacklisted is the inability to send e-mail to any domain that subscribes to that blacklist. We would then end up waiting hours, days even, before our IP was considered “safe” by the recipient’s e-mail servers once we found the blacklist site and its Remove IP feature.

The ExchangeDefender service is worth it for both our clients and us. That is why we signed up with OWN as a Service Provider!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Tuesday, 28 October 2008

SBS 2008 Lab Test - Spam Filtering

The primary purpose of this post is to present our SBS 2008 lab users' e-mail addresses to the world as a spam trap.

Let's see just how good the Forefront and LiveOneCare for Server setup is.


Just in case you are wondering, the above users are setup in the SPRINGERS SBS domain as part of the book I am co-authoring with Harry Brelsford of SMB Nation fame tentatively called the SBS 2008 Blueprint.

Once we get things rolling along pretty good, we might even setup a couple "Out of Office" replies just to spice things up a bit! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 24 September 2008

Vista - UAC spots rootkits? ... now to say "No"!

This article at Network World is a real eye opener as far as rootkits are concerned: Vista's UAC spots rootkits, tests find.

The kicker? If the user cancelled the UAC prompt when the rootkit tried to install itself the install was dead in the water ... nada ... kaput ... done did be toast!

To say that again: Rootkit tries to install, user clicks CANCEL when they are prompted by UAC, they will not get infected.

Now how about that!

For all of the "pain" around UAC, that to us is a "killer app" folks in more ways than one and with the pun too!

The article is a good read, and provides some not so surprising results for rootkit cleaning not-so-success rates and then some.

Now, to continue on training our client's users to not turn the UAC off and to be wary if they were not doing something to bring about the prompt in the first place.

You see dark figures lurking in a dark cubby hole down the street seemingly looking right at you, what you going to do? Assess and make a decision pronto! That rootkit is no different ... street smarts = Internet smarts!

There is no product out there that can handle these situations better than a well trained user!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Thursday, 4 September 2008

Trend Micro Worry Free Security is not so worry free?

Folks, please keep in mind that this post is coming out of a ongoing frustration with a couple of situations we are having with Trend's WFBS ... this being the key one:

One of our clients, going on ten years in our business relationship, has been entirely virus free. To date, we were running Symantec's Enterprise A/V product through its various versions up to 10.2 which is just prior to their new EndPoint product.

We may have our beefs with Symantec as a business and with its business practices, but at least the product worked.

With our client's recent hardware and software refresh, we opted for Trend Micro's SMB product which is now Worry Free Business Security.

We have all seen the plethora of ZIP files attached to emails about air flight plans and the like that have been filling our Spam or Junk folders.

Well, one of the principles of said client absentmindedly clicked on one of those zip files because they just happened to have made their flight plans with the Subject's airline.

Now, in the past, Symantec's A/V would have popped up a window stating that there was a virus embedded in the ZIP file, blocked access, and deleted or quarantined the file.

For whatever reason, the Trend product did not do this. So, after essentially 10 years of being virus free, we now have a laptop that we needed to quarantine, pull off the network, and rebuild after pulling essential data off of it. We do not like Trojans - all infected systems get flattened.

We checked, and double checked the Trend Management Console on the server and it clearly indicated that it was directing the clients to scan ZIP archives. In fact, we went through all of the settings in the console to make sure that things were as they should be for client settings and they were.

On the infected client, we tested a number of different scenarios and the Trend A/V client never even considered there to be a problem.

And yes, our server and clients were up to date with the current A/V definitions.

This situation has left a very sour taste in our mouth. For now, we will be holding off any further Trend installs.

BTW, this situation was the impetus for us to sign up with Vlad and OWN to begin looking at implementing Exchange Defender at our client sites.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Friday, 22 August 2008

"Anatomy of a malware scam" is a good malware read

Have a few minutes to spare?

How about checking out how creative malware scam artists are getting: The Register: Anatomy of a malware scam: The evil genius of XP Antivirus 2008.

From the article's conclusion:


This should serve as a dire warning to all: be extremely careful what you trust, and question everything that looks even remotely suspicious. For example, no website can run an anti-malware scan on your computer simply by your visiting the site. Any site that purports to do so is almost certainly run by criminal gangs.

No website should ever offer you to download an anti-malware package as soon as you visit the site. Any site that purports to do so is either run by criminal gangs or by an organization whose business practices are so deceptive that you should never consider doing business with it. A reputable site will present you with product information and then leave the downloading decision up to you, not force it upon you. No software that pushes the purchase decision so heavily in your face is likely to be legitimate.


Part of our responsibility as the go to person for our client's I.T. needs is knowing what the threat landscape looks like.

From there, we can educate them with a simple note every once in a while that provides some dos and don'ts while browsing the Internet.

UPDATE: The above article came via a link that I could not for the life of me find. Go figure ... it popped up when I logged into another machine.

Credit goes to Jesper's Blog: Anatomy of a Hack 2008 ... which is a good read in and of itself. My apologies for originally missing the credit Jesper!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Thursday, 14 February 2008

Sage Accpac ERP - Version Mismatch Error - Refer to Solution ID 22331

A recent SBS Premium setup needed to have Sage Accpac ERP installed and configured with a SQL backend on the server.

This setup came after the fact.

The actual setup of the databases, connectivity, DSNs, and more will be in a separate post when we have a little more time.

For now, we had the following error on every workstation:

Sage Accpac ERP

Version mismatch. Two Microsoft support files (SQLSRV32.DLL and ODBCBCP.DLL) are different versions. Please refer to Solution ID 22331 for more information
A search for said Solution ID turned up nothing.

Since we were working with a SQL 2005 installed database, the thought was that something within Accpac was expecting an older SQL version, or some files were updated while others were not.

So, we searched the server and found the following files:
  • SQLSRV32.DLL = Version 2000.86.1830.0
  • ODBCBCP.DLL = Version 2000.86.1830.0
Since the versions on the server were seemingly the same, we moved onto the workstation and found the following:
  • SQLSRV32.DLL = Version 2000.85.1117.0
  • ODBCBCP.DLL = Not Found
We made sure to shut down Accpac, then we placed a copy of the SQLSRV32.DLL from the server on a network share.

Both files were found under %windir%\System32 on the server.

We copied the SQLSRV32.DLL off the share to the same %windir%\system32 location on the workstation after making sure Accpac was shut down properly.

We then tried to run Accpac and received the same Version Mismatch error.

So, we copied the ODBCBCP.DLL file off of the server to the same share location. We then copied the file from the share to the %windir%\System32 on the workstation.

We fired Accpac up again, logged on to the company file and we were connected successfully.

Here is a screen shot of what both the server and the workstation file compare after completing the file copy to the workstation:

Correct file versions on both the Server and Workstation

By the way, while searching for the solution, we came upon one so-called solution site promising a video of it. We were invited to install an ActiveX component before we could view the video though. We were not permitted to close the Tab that the site was in nor were we permitted to click the X to close the browser. That browser and its tabs could only be shutdown via the Task Manager and an End Task. As always, Internet "Street Smarts" are important!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 9 January 2008

From Symantec to Trend Micro and a little ForeFront Client Security

We are moving away from Symantec.

In one case, we have a relatively new install at a long time client who moved offices and needed a fresh start.

It is now almost 18 months later, and we have finally worked out getting the Symantec licensing .slf file problems worked out ... almost. The management console keeps telling us that certain clients are in license violation mode and won't update the client's definition files when this happens. And there are seemingly no good answers forthcoming from Symantec ... even with the Gold Support.

*sigh* and a deep breath.

So, we are going to try out the Trend Micro NeatSuite with a new client.

Trend's name passes through the RSS reader every once in a while. Sometimes good, and sometimes bad, but from what we can tell, a number of leading SBSers out there rely on it for protection.

What this means is a heavy investment of time to learn a new product. Hopefully the Trend setup will be fairly straight forward.

By the way, we did look into ForeFront Client Security as a possible option, but the management console requires a full version of SQL2005 server installed. SQL 2005 Workgroup on SBS 2K3 R2 Premium does not cut it. Even on the Open Value Licensing scheme it was too expensive for SMB to include SQL. While we can install the workstation client in a "not managed" mode, this does not strike us as the right direction to go in a server/client environment.

So, a new product adventure begins! :D

And, in the case of our existing clients, once their Symantec licensing lapses we will move them over to Trend.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.