Saturday, October 31, 2009

[Lockergnome] Computer Security ~ October 31, 2009

Lockergnome
Lockergnome's Computer Security ~ October 31, 2009   



AMF Daily Planner and PIM: The super sleek, fully network compliant, Internet-enabled PIM is finally here! AMF Daily Planner & PIM is the easiest personal organizer you've ever used. With drag & drop appointment scheduling, week and year at a glance calendar views, CallerID support, call logging, birthday/anniversary support, a rolodex-style phonebook, customizable contact data fields, fast and powerful data searches, faxing, business letter creation, automatic phone dialing, one-click mail merges and more, AMF Daily Planner & PIM is your... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

AimAtFile Fast File Search: AimAtFile helps you find files by their contents. It provides content search (full-text search) functionality based on Microsoft Indexing Service included in Windows 2000/XP/2003. There are many third party file search utilities, but they scan all files each time you try to find a file. AimAtFile Indexing Service scans files in the background as a low-priority process and then requests this index and returns search results. You receive a list of files matching your... [Click Here to Download]

Administrivia

Tech Help and How To


Are You Bothered By the Lack Of A Proper Menu With Windows 7? Solution Follows

Call Of Duty 2 Modern Warfare - Use The Game and Return It For A Re »

Microsoft Security Essentials ? Really the Best?

Microsoft Discontinues Accounting Software - Express Version Is Still Free

Turn Your Windows 7 Laptop Into A Wi-Fi Hotspot

Bernard Pretty Purdie, Jon Hammond, Jerry Jemmott backstage at Hair Show

HP Gets Custom Backgrounds On Windows 7 Starter Edition

Microsoft Discontinues Office Accounting

Carpool

KipKay: The Rocket Powered Matchbox car

How Reliable Is Your Windows 7 Installation? Here?s How To Check It

Should I Get Droid or Wait For the Hero?

Concert Streaming ? A New Trend?

Dell Is Selling The Nintendo Wii For $179 + Free Shipping

You?re Not Wasting Time Online; You?re ?Brain Training?

Save up to 39% and get free shipping on Harmony 1100 Advanced Touch »

Microsoft Branded Stores ? Long On Looks, Short On Substance

Hundreds of Millions (More) Just Went to Pakistan

Windows 7 - Microsoft Clarifies What An Upgrade Is, Contrary To Wha »

Community Broadband? It?s Working In Minnesota


TrendLabs | Malware Blog - by Trend Micro - 2 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles

  1. Trick or Threat?
  2. This Halloween, Enjoy the Treats but Be Wary of Online Tricks
  3. More Recent Articles
  4. Search TrendLabs | Malware Blog - by Trend Micro

Trick or Threat?

The month of October in the threat landscape is often associated with scary social engineering tactics in time for Halloween. As in years past, the threats that lurk in and plague the current threat landscape are real. Most of them can cause irreparable damage, often resulting in information, or worse, identity theft as shown in the following blog entries:

  • Weather Report for Halloween: High Chances of a Storm
  • "Halloween Costumes" Bring More Fright Than Expected
  • But just how scary is the Web 2.0 environment nowadays? Let us run down a list of the scariest threats thus far:

  • 2009 saw the emergence or resurfacing of three of the most notorious botnets in relation to information, financial, and identity theftKoobface, ZeuS, and Ilomo. Botnets control more compromised machines than previously believed. Only a handful of cybercriminals have more than 100 million computers under their control. This means they have more computing power at their disposal than the entire world's supercomputers combined. It's no wonder then that more than 90% of all email worldwide is now spam.
  • Koobface is most known for preying on social networking and micro-blogging site users. It has transcended from its original design of taking over accounts to spread malicious links using the affected users' credentials to spreading a FAKEAV or its variant to users who just happen to visit a compromised site or to click anywhere on a malicious page where a copy of the malware is hosted.ZeuS/ZBOT

    The ZeuS botnet, on the other hand, is best known for ebanking attacks targeting small businesses that do not have full-time IT staff and only 1–2 payroll personnel. It was first introduced by Rock Phishers this April, paving the way for the rise of easy-to-use kits that yielded professional-looking phishing pages. Its latest components, also known as "ZBOT variants," now come compressed in more and more complex packers.

    Ilomo  – The third most dangerous botnet, Ilomo, also known as "CLAMPI" or "LOMOL," is known for injecting code into an affected user's browser to wait for him/her to connect to one of over 4,000 banking, financial, or Web mail sites so it can steal his/her credentials. It can, however, also "piggyback" on the user's session to transfer funds from his/her account to a remote one while making a mockery of the bank's secure login system. The botnet also sells "anonymity as a service" as every infected machine can act as a proxy, allowing cybercriminals to route their illegal activities through different networks and countries, thereby evading detection.

  • Tricking users into downloading FAKEAV has been an age-old cybercriminal tactic that apparently has not stopped working. Hence the continuous rise in the number of FAKEAV pushed to unwitting scam victims up to this day. Trend Micro estimates that more than 100,000 users receive messages saying they have been infected by malware while visiting malicious sites and that there are more than 48,000 FAKEAV offerings per month.Apart from its ability to rake in a lot of dough, it is also hard to detect due to its numerous domains and redirectors, giving security experts a hard time tracking all related activities down. FAKEAV will thus continue to plague users for a long time because its ploy works.
  • In June 2009, Microsoft broke its December 2008 record of releasing patches for 28 vulnerabilities with the release of 10 security advisories to address 31 vulnerabilities in its OSs and other software.
    Unpatched vulnerabilities can allow cybercriminals to exploit users' systems. For instance, unpatched vulnerabilities in a system's browser can allow cybercriminals to run arbitrary code if the user happens to browse through a malicious website, leaving him/her at the mercy of online predators.Microsoft was not alone in this predicament though. Adobe and Firefox have had their share of exploited vulnerabilities as well.
  • Why do more and more people join the cybercriminal bandwagon? The answer is plain and simple, because there is a lot of money to be made in infecting users. FAKEAV, for instance, sell for an average price of US$50 each. Just imagine how much money cybercriminals can make even if they just sell to a fraction of their target user base!  Our threat research papers provide detailed information of such cybercrime activity, if you’re interested, you can read them here.

    And if that isn't scary enough, Trend Micro's threat researchers found that the going rates for stolen data (credit card information and user credentials) and for infecting users' systems continue to rise each year. Cybercriminals never seem to run out of tricks to spread threats to users throughout the Web. No wonder U.S. President Obama officially announced October as the "National Cyber Security Awareness Month!"

    Post from: TrendLabs | Malware Blog - by Trend Micro

    Trick or Threat?


    This Halloween, Enjoy the Treats but Be Wary of Online Tricks

    We often associate Halloween with pumpkins and costumes but for cybercriminals it's merely another avenue to exploit, steal, and trick users into giving away their personal identities. Treats are fun but we all need to be on the lookout for the sneaky and tricky ways cybercriminals slither into our computers.  Below are the TrendLabs, top 7 scariest threats that might be knocking on your door:

    1. Tailor-made ZBOT spam makes its way to employees' mailboxes

    The Zeus botnet is well-known for e-banking attacks that target small businesses without a dedicated IT staff and only 1–2 payroll personnel; the most notorious ZBOT attack to date sent out tailor-made spam to the employees of several of these types of small companies. The spammed messages were made to look legitimate and non-malicious when, in fact, they contained Trojan spyware designed to steal information and identities.

    2. Vulnerabilities hit critical mass: Patch me if you can

    Microsoft set a record in December 2008 of 28 patches for its OS vulnerabilities. In June 2009, the company broke that record with the release of 10 security advisories for 31 OS and other software vulnerabilities. What does this mean for users? It means that unpatched vulnerabilities can allow cybercriminals to exploit their systems. For instance, unpatched vulnerabilities in a system's browser can allow cybercriminals to run arbitrary code if the user happens to browse through a malicious website, leaving him/her at the mercy of online predators.

    3. FAKEAV: Surrender hard-earned money for fake security

    We've seen several strains of FAKEAV abound on the Web. Most employ "scareware" tactics, displaying a blue screen or bogus graphical user interfaces (GUIs) to warn users of infection. Some of the most dangerous variants, however, employ "ransomware" tactics. Users who fall victim to FAKEAV scams end up buying useless applications or may even be robbed of critical information apart from their hard-earned money. Sold at an average US$50 apiece, it is clear that big money can be made from pushing FAKEAV to users. This is why we can expect the debut of more FAKEAV in the future.

    4. Expand your circle of friends but beware of KOOBFACE malware

    This year, we saw the emergence of the KOOBFACE botnet that specifically targeted social networking and micro-blogging site users. Facebook and Twitter, two of the top-ranking social networking/micro-blogging sites today have millions of users worldwide, making them favorite cybercriminal targets. The popularity of these sites may be unprecedented but so is the rise in number of malware targeting them. Victims of KOOBFACE variants can end up with FAKEAV infections, wrangled into being a part of the widespread KOOBFACE botnet, or owners of compromised profiles, take your pick.

    5. More sophisticated attacks = More victims

    Cybercriminals continue to up the stakes as they come up with more sophisticated attacks to lure more victims into their traps. A new variant of the BEBLOH family of information stealers went well beyond logging keystrokes and sending it to a server to exploit. It stole user information and used it right away while effectively avoiding detection. The latest BEBLOH variant produces static pages that show remaining account balances and previous transactions to cover its tracks. Victims will not know they have been robbed unless they accessed the online banking site from an uninfected machine or used separate facilities such as ATMs.

    6. No system is immune from security attacks, certainly not Macs

    The days when Mac users felt safe from today's threat landscape are over. The recent proliferation of Mac attacks reiterates what security researchers have been saying all along—that no system is immune from security attacks, certainly not Macs. The number of Mac users continues to increase, unfortunately so does the number of
    cybercriminals targeting the Mac OS. Cybercriminal attacks on the growing Mac user base are becoming more and more complex, preying on the earlier belief that the OS X is malware-free.

    7. Blackhat SEO attacks climb the charts

    Just as cybercriminals strive to make their malware-ridden pages climb to the top of search results, so has the number of documented blackhat SEO attacks. As if the usual blackhat SEO techniques were not crafty enough, cybercriminals just learned to use new nifty gadgets—Google Trends and GeoIP tracking—to increase the chances that users will click on links that direct them to specifically crafted malware-ridden pages. This kind of attack can affect anyone searching for information on the Web. All it takes to get infected is click a top-ranking search result.

    If you are concerned that your computer may have been affected by a cyber attack, try our free prevention and clean up tools, available here

    Post from: TrendLabs | Malware Blog - by Trend Micro

    This Halloween, Enjoy the Treats but Be Wary of Online Tricks


    More Recent Articles



    Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change your subscription or subscribe

     
    Unsubscribe from all current and future newsletters powered by FeedBlitz
    Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

     

    Friday, October 30, 2009

    [Lockergnome] Computer Security ~ October 30, 2009

    Lockergnome
    Lockergnome's Computer Security ~ October 30, 2009   



    Redirector: Want to get a copy of your email on your Blackberry, T-mobile Danger Sidekick, phone, pager, or other wireless device? Want to consolidate your mailboxes including Hotmail, AOL, Yahoo! Mail, Mail.com, or POP3? Are you constantly checking more than one account? Use Redirector to redirect a copy while retaining who it's sent to so that you can reply to the sender if you want to. Redirector will run unattended conveniently in your system tray. [Get... [Click Here to Download]

    Lockergnome help - Antivirus Discussions

    Lockergnome help - Trojans/Spyware Discussions

    Lockergnome help - Antivirus Discussions - General Discussions

    Lockergnome help - Antivirus Discussions - McAfee

    Lockergnome help - Antivirus Discussions - Symantec/Norton

    Lockergnome help - Antivirus Discussions - AVG

    Lockergnome help - Antivirus Discussions - F-PROT

    Lockergnome help - Antivirus Discussions - Panda

    Lockergnome help - Antivirus Discussions - Free Antivirus

    Lockergnome help - Antivirus Discussions - Others

    Lockergnome help - Trojans/Spyware Discussions - General Discussions

    Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

    Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

    Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

    MediaWiper: MediaWiper is the perfect companion tool to WipeDrive. It can wipe all your drives (except the Windows operating system drive [generally your C: drive] and any CD-ROM/DVD drives). Installs and runs from the Windows start/programs menu - simply run MediaWiper and choose which disk to sanitize. Answer "yes" to confirmation prompts to erase your media. It automatically formats drives after wiping so you can reuse the disk right away. MediaWiper sanitizes media and permanently erases... [Click Here to Download]

    Administrivia

    Tech Help and How To


    How Reliable Is Your Windows 7 Installation? Here?s How To Check It

    Should I Get Droid or Wait For the Hero?

    Concert Streaming ? A New Trend?

    Dell Is Selling The Nintendo Wii For $179 + Free Shipping

    You?re Not Wasting Time Online; You?re ?Brain Training?

    Save up to 39% and get free shipping on Harmony 1100 Advanced Touch »

    Microsoft Branded Stores ? Long On Looks, Short On Substance

    Hundreds of Millions (More) Just Went to Pakistan

    Windows 7 - Microsoft Clarifies What An Upgrade Is, Contrary To Wha »

    Community Broadband? It?s Working In Minnesota

    Mozilla Thunderbird Email Client - Reviewed

    Quick Look: Karmic Koala

    Todd Bryant Weeks on HammondCast KYOU Radio by Jon Hammond

    Panasonic Lumix DMC-ZS3 10MP Digital Camera for $285 + Free Shipping!

    The Figures Are In, U2 on YouTube ? Almost 10 Million Streams

    Buying A New PC? Make Sure You Run PC Decrapifier - It Is Still Free

    Ubuntu 9.10 ? How Many Will Make the Free Upgrade?

    Will The Real MicroHoo Deal Please Stand Up?

    Manufacturer of Baseball Bat Loses Lawsuit

    KipKay: The Amazon Atlatl


    Subscribe via email

    Enter your email address:

    Delivered by FeedBurner

    Blog Archive