Google Search

Showing posts with label infect. Show all posts
Showing posts with label infect. Show all posts

Monday, January 7, 2013

Beware Thanksgiving screensavers designed to infect your PC with malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

ThanksgivingMillions of Americans are preparing to celebrate Thanksgiving with their families and friends.

And some might be allowing their computers help spread some festive cheer, by playing holiday tunes and - perhaps - installing Thanksgiving screensavers.

Well, hold your horses, easy on the gravy and take the mashed potato off the hotplate..

That Thanksgiving screensaver that you just downloaded from the net may not be entirely safe.

For instance, here's a Thanksgiving screensaver that we analysed in our labs in the last 24 hours.

The filename looks innocuous enough: Thanksgiving Day.scr

And, judging by the screenshots that it displays on your screen, it's suitably cheesie Thanksgiving fare:

Images displayed by Thanksgiving screensaver

But behind the scenes, while you are being presented with a slideshow, the screensaver is silently connecting to a website and attempting to download malicious code, allowing malicious hackers to take remote control of your computer.

Section of code, downloading further content from the net

The malware also drops a new DLL, called ssheay.dll, which poses as an Add-in for Outlook. A link to the DLL is added into the Registry, ensuring that the code is run automatically each time the computer is started.

Sophos products detect the malware as the Troj/DwnLdr-KJW Trojan horse.

The lesson, of course, is not to trust every program that you run into on the net, and think twice before installing code of dubious provenance. Don't think you can take a short cut and not worry about computer security just because it's Thanksgiving.

If you're celebrating Thanksgiving, please look after yourself, your friends, and your computers. Do yourself and your friends a favour by ensuring that anti-virus software is up-to-date and your computers are properly patched against the latest security flaws.

If you haven't already done so, check out some of the free security tools that Sophos makes available.

Best wishes from all of us at Naked Security and Sophos.

Follow @gcluley

Thanks to Zoe in SophosLabs UK for assisting with this article.


View the original article here

Wednesday, November 7, 2012

Skype worm spreads, using LOL trick to infect unwary users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SkypeSkype users are warned to be on their guard, regarding malicious instant messages that have been sent through the service, designed to infect Windows computers.

A malicious worm is taking advantage of the Skype API to spam out messages similar to the one below:

lol is this your new profile pic? http://goo.gl/[REDACTED]?img=[USERNAME]

Clicking on the suspicious links leads to the download of a ZIP files (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC.

The Trojan horse opens a backdoor, allowing a remote hacker to take control of infected PCs, communicating with a remote server via HTTP.

On execution the malware copies itself to

%PROFILE%\Application Data\Jqfsfb.exe

and sets the autostart entry as below:

entry_location = "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"entry = "Jqfsfb"description = "Skype "publisher = "Skype Technologies S.A."image = "c:\documents and settings\support\application data\jqfsfb.exe"launch_string = "C:\Documents and Settings\support\Application Data\Jqfsfb.exe"

Before you know it, your computer has been recruited into a botnet (the malware is a variant of the Dorkbot worm) and could fall victim to a ransomware attack.

There have been many variants of the Dorkbot attack spotted over the least year or so, spreading via Facebook and Twitter. The threat can also spread via USB sticks, and various instant messaging protocols.

The danger is, of course, that Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users.

Always remember to be suspicious of unsolicited out-of-character messages sent to you by your online friends.

You don't know that it was a friend who sent you the message, all you know is that it was their account which posted it to you... and who knows if it was compromised or not?

Follow @gcluley

Thanks to Anna and Julie at SophosLabs for their assistance with this article.


View the original article here