Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, June 7, 2011

Heads Up for Windows x64 and Mac OS Users

The latest malware is now on the loose, threatening both Microsoft's Windows x64 and Apple's Mac operating systems. This is composed of a 64-bit rootkit that works on 64-bit versions of Windows with a rogue antivirus for Mac computers.


According to Kaspersky Lab Expert, Vyacheslav Zakorzhevsky, the threat executes a downloader to download fake antivirus programs, including one for Mac. The downloader will also run under Windows, the fake Mac antivirus is also downloaded, but it will not be executed.


Zakorzhevsky also mentioned that this may show those behind the fake antivirus for Mac are distributing it by all possible means, without knowing what they are going to install on target computers.


"Interestingly, one link leads to Hoax.OSX.Defma.f which we recently wrote about. Most importantly, the rootkit tries to run it... under Windows! It appears that the developers of the latest rogue AV program for MacOS are actively distributing it via intermediaries, who don’t really understand what it is they are supposed to install on users’ computers,"


– as mentioned on Zakorzhevsky's blog post.


Zakorzhevsky said that the rogue program is downloaded and installed with the BlackHole Exploit Kit, exploiting the weak points in Java as well as in Adobe PDF reader software.


Both drivers are basic rootkits with high functionality. One is a 32-bit while the other a 64-bit driver.


The 64-bit driver is signed using a so-called testing digital signature that executes Windows Vista and 7 if it is booted in "TESTSIGNING" mode. A "TESTSIGNING" mode lets drivers and applications being developed by software developers to launch in Windows.


Where's the "Panic Button" when you need it..?
"Cybercriminals also use this loophole: they execute the command ‘bcdedit.exe –set TESTSIGNING ON’ that enables them to launch their driver without an authorized signature," Zakorzhevsky noted.


When the driver is loaded successfully and runs on the system, the rootkit halts the execution of drivers belonging to anti-rootkit and antivirus products.

Tuesday, May 3, 2011

Do Not Fall for Facebook's Latest Spam Scam

If you’ve logged on to Facebook lately, there are certain invitation that intends to show you a list of people who viewed your profile. If you come across with something like this, don't ever think about clicking the link

Trend Micro’s Malware Blog warns the users that clicking on the link, or accepting the invite would cause the user to share spam without their unknowingly. Here is a walk through on how this scam works.

If you have received an ‘invitation’ on your Facebook account and it showed up in the Events section with the heading “How to Find Out Who’s Viewing Your Profile,” you could get curious and click on the link.

Whatever you do, do NOT click the link
Once you have read the instructions and  it says: You NEED TO FOLLOW ALL INSTRUCTIONS BELOW TO FIND OUT WHO’S IS VIEWING YOUR PROFILE. Even if it has some typographical error, you read that you have to invite your friends to be able to “attend” said event. Once your done, you will receive a message that goes like, WHEN DONE GO TO http://bit.ly/...AND SEE WHO’S IS VIEWING YOUR PROFILE.

This will not actually direct you to the link that shows the list of your friends viewing your profile. Instead, you just executed a script that shares the same link to your other friends on Facebook.

Spammers are the bottom feeders of the cyber world these days. Their latest strategy plainly shows the lengths they will go to just so they can make some money out of their unsuspecting prey.