Showing posts with label malware threats. Show all posts
Showing posts with label malware threats. Show all posts

Monday, March 17, 2014

Protect your PC from malware

Are your Google search results being redirected to annoying ad sites?
double_malware

Did you know there are plenty of free software programs that will identify and remove malware hiding in Microsoft Windows?

Google’s Chrome browser has been seeing issues with ‘chrome-navigation-error.inof redirect’.  It is suspected of being botnet related.

I use the Firefox web browser with Adblock, and I run AVG anti-virus. Frequently, but not always, when I click on a link in a Google search result, it takes me to a page advertising something instead of going to the page indicated. If I go back to the search results and click the same link, it usually goes to the correct site. I thought this might be malware, but I have scanned with AVG and Malwarebytes, including anti-rootkit, and there is no indication of anything wrong. Researching the problem, I came across concerns that the Chrome browser could have this behaviour, and the suggestion was to disable extensions. I’m not very happy to do this because my various Firefox extensions add functionality I value. Geoff from Google

Apple Mac OS X and Linus users are also seeing this, although, no Firefox users have reported the issue.
When there is malware on your computer, the best way to take care of the situation is to identify it.

Malware is dangerous to your computer because an attacker can use a small security hole to install more malicious software.

Before trying to get rid of malware, make sure you have all your programs and data backed up.

malware

 

Malware Removal

  1. Run Malwarebytes Anti-Malware in Safe Mode for faster removal of malware.
  2. Reboot your PC and keep pressing F8 before Windows loads.
  3. When in the Boot Menu, run Malwarebytes again
  4. Keep rebooting and re-running Malwarebytes until there are no longer issues
Using Microsoft’s SmartScreen filter is helpful in keeping your system protected.  The SmartScreen filter creates an SHA-256 hash of executable code and sends it to a Microsoft server.

The bad code or websites is blocked and a message saying “Windows protected your PC,” will appear.
Most malware usually targets the ‘low hanging fruit’ that hundreds of millions of users who never install patches.  Also users who run pirated copies of software with a built-in back door are attacked.

For help with malware removal or information on computer security call us at 619-325-0990.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:
How can I remove redirection malware from my PC? – The Guardian
http://www.theguardian.com/technology/askjack/2014/mar/13/how-can-i-remove-redirection-malware-from-my-pc

Why major companies fail to act on malware threats.

Destructive data breaches hit companies all the time.  Last year, Target was hit and exposed 40 million credit and debit cards along with 70 million customers personal data.


The-Target-Security-Breach-What-to-Do-Right-Now-to-Protect-Your-Credit


The malware installed on Target’s (TGT) security and payments system was designed to steal every credit card used at the 1,797 U.S. stores.

Target has acknowledged that the breach could have been avoided if they paid closer attention to alerts generated by their security monitoring tools.

Targets credit card payment system is still out-of-date.  The systems aren’t able to pull up your account to tell you how much money you owe on your monthly statement.

Target is not the only one with an out dated system that is subjected to  high security risks.  More than 90 lawsuits have been filed against Target by customers and banks for negligence and compensatory damages.

Often, companies deploy security technologies with default alerts, resulting in many false positive warnings, Joe Schumacher, a security consultant for Neohapsis added.

Many alarms are overlooked because sometimes it doesn’t mean anything bad is happening.  Sometimes a security alert shows their have been inappropriate actions, which happen very often.

Six months before the breach, Target installed a network monitoring tool security vendor FireEye that alerts the security personnel of malware on its networks.  The tool has cost Target $1.6 million, but that’s only a fraction of how much damage could have been caused by the considerable compromise.  They spent $61 million responding to the breach through Feb.1, 2014.

Target’s profit for holiday spending fell 46% from the same quarter the year before.

The FireEye system could have been configured to automatically remove the threat.  The software was new and untested at Target, and the feature was not activated.


target-attack


Target fell short on the process and policies.  Many companies don’t take security as seriously as they should.  A highly secured network can cost companies millions of dollars.  Dollars they sometimes would like to spend elsewhere.

In this instance, the breach could have been automatically stopped.  The system’s option to automatically delete malware as it’s detected was turned off by Target’s security team.

If Target’s security team had followed up on the earliest FireEye alerts, it could have been right behind the hackers on their escape path.

The malware uncovered user names and passwords for the hackers to embed the code on their servers.
It’s unfortunate to know that this could have been easily avoided.  Maybe the security team was focused on some other security alert, or maybe they just didn’t see the alert as important.  Maybe the security team underestimated the severity of a simple malware warning message.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:
Major companies, like Target, often fail to act on malware alerts – Computer World
http://www.computerworld.com/s/article/9246942/Major_companies_like_Target_often_fail_to_act_on_malware_alerts

Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It – Bloomberg Business Week Technology
http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data#p4