Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, 17 September 2007

A Virus that Spreads through USB or Removable Disks

Using Pen Drive or USB Flash Drive or Memory Cards etc? Beware of this AHKHeap-A virus. It does some pretty crafty dirty tricks! All you need to do to be infected is to just plug it in!

You will be infected if you insert an infected removable disk on your computer and let it Autoplay, if you double-click the Drive Icon, or double click a folder that you created earlier!

So what should you do? So what happened?

If you had inserted your removable drive on some computer infected with the AHKHeap virus, when you create a directory on the removable drive, say "test", the virus converts the folder into a system, hidden folder. Then, it creates an application with the same name - test.exe. The trick is that the test.exe application that is created has an icon that exactly resembles a folder!



In the above screenshot, you see a folder named MicrosoftPowerPoint. But actually, its a virus and not a folder! See the Properties page for it below:


Its an EXEcutable file! (Type of file: Application). How come it looks like a folder? Simple. It has its icon set to look exactly like a folder!

When you plug the removable drive to another PC and try to open the folder by double clicking it, the virus exe file runs and infects that computer too. You don't get to see the real folder because it has attributes set a system, hidden.

It even sets the Autoplay.ini file to start the viral executable. So if your Windows stupidly runs the executable as soon as you plug in the removable drive, you are infected. See the Autorun.ini contents:

[Autorun]
open=MicrosoftPowerPoint.exe
shellexecute=MicrosoftPowerPoint.exe
shell\Auto\command=MicrosoftPowerPoint.exe

Another interesting thing is that the virus disables "Show hidden files and folders" option. Go to Explorer, click Tools Menu > Folder Options > View Tab. "Do not show hidden files and folders" option will be checked. Try changing it to "Show hidden files and folders". If your computer was infected, you will not be able to save the changes! You have to re-set the option from the registry. Go to HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL and set CheckedValue to 1. Now, you can change the setting to show all files and folders.

What can you do to prevent this virus? DO NOT AUTOPLAY removable disks! If you shared your removable disk among computers and if you think there is any chance that those computers infected, do not open folders that are on the removable drives by double clicking them - use the [+] sign on the explorer's folders pane. Better still, use the command prompt if you know how to.

Do not trust drives that belongs to others.

What is the payload of this virus? It stops you from accessing orkut and youtube and displays its signature dialog box that says orkut is banned and reportedly produces strange sounds :) !

The virus does this: it creates a directory c:\heap41a and sets up a key in the registry so that it auto-starts (HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run). Then, it infects each and every removable disk you insert into the computer.

How to remove the virus from your computer?

Read these articles: 1 2

First, you have to kill the viral processes running as svchost under your user name. To do this, press Ctrl+Alt+Del and open Task Manager. There will be svchost processes running under SYSTEM, LOCAL SERVICE or NETWORK SERVICE. Leave them alone. If you find any svchost process under some other username, right click it and select 'End Process Tree'.

Then remove the start-up hooks from the registry. I found them in HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run. Its better if you search for "heap41a" in the registry. Remove any viral entries you find.

Then, you have to remove the virus from your hard disk. Use Command Prompt. c:
cd \
dir /a

If you find heap41a directory, you have to delete them. First, you have to un-protect them.
attrib -s -h heap41a
cd heap41a
attrib -s -h *.* /s /d
del *.* /s

You should now be able to delete the heap41a directory. If you are unable to, there are more protected files in it - Remove them using attrib -s -h filename and del filename.

Then, reset the Show Hidden Files Option as said earlier. (Go to HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL and set CheckedValue to 1).

Now, you have to clean your Removable Drives. Make sure you don't re-infect your system when you do this. When you insert the disk, make sure Windows does not autoplay any executable. You must not trigger Auto-play on the drive by right-clicking the drive icon. You must not also double-click applications that look like folders.

The best way to clean the removable drive is to Quick-format it. If you need to try to recover some data from it, try this:

Go to the command prompt. Do a dir /a and see if there are any suspicious executables or hidden folders. Delete them all. Repeat them for any sub-directories. Delete autoplay.ini.

My AVG with latest updates (Sep 17 2007) was unable to recognise all of the executable - though it did catch many. For example, it did not recognise the c:\heap41a\svchost.exe! Makes me wonder how much you can trust them!

Thursday, 13 September 2007

Prevention is Better than Cure

When it comes to antivirus, its my opinion that it should be better used for prevention of an infection rather than to cure an infected system.

Ideally, you should install the antivirus software as soon as you install the operating system and before most other programs. More importantly, you should install the antivirus before you connect your system to other systems via a LAN or the Internet - before Viruses, worms and Trojans get a chance to infect your system.

Someone who administers 200 computers told me that AVG Antivirus is useless and they were being let down. On discussion with him, I found out that they tried to install antivirus software after a computer was suspected to be infected. Most systems were not updated with security and critical updates and had vulnerabilities dating back to 2002! And none had firewalls turned on. Every single system was used routinely with administrative accounts.

No wonder he feels that antivirus solutions inadequate. I advised him to follow a minimum security procedure: Windows Updates, Early Antivirus installation, giving non-admin accounts for day to day usage, firewall configuration etc. Security is a habit, it seems. Lets see if things improve.

Thursday, 2 August 2007

HijackThis

HijackThis is a must have tool for advanced users. TrendMicro's website says:

"HijackThis™ is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware, malware or other unwanted programs. HijackThis creates a report, or log file, with the results of the scan.

IMPORTANT: HijackThis does not determine what is good or bad. Do not make any changes to your computer settings unless you are an expert computer user. ... Not an expert? Just save the HijackThis report and let a friend with more troubleshooting experience take a look."

So HijackThis lists all installed browser add-ons, buttons, startup items, search engine settings etc. If you find something that is causing problems, you can easily remove them using the tool itself.

Here is what a typical log will look like:

Logfile of HijackThis v1.98.0
....
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Microsoft Office\Office\FRONTPG.EXE
E:\Documents and Settings\Sootah\Desktop\HijackThis1980.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theregister.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar2.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - E:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll


You must be an advanced user to realise which is a virus or spyware or crapware and which is not. You may end up with a crashed system if you don't know what you are doing. Once you are very certain that a program is unwanted, go ahead and remove them with HijackThis and get rid of it.

If you do not understand fully what to do, but are having a problem with your PC which you suspect is due to a virus/spyware, you can visit so many forums that help you see what is wrong.

Download HijackThis from Merijn, Download.com.

For detailed information on how to analyse the HijackThis Logs, visit about.com's article.

Hardware, Software, Malware

What is Malware? Here is what Wikipedia says:

"Malware is software designed to infiltrate or damage a computer system without the owner's informed consent. It is a mix of the words "malicious" and "software". The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code."

The variety of hostlile, intrusive or annoying software includes: worms, viruses, trojan horses, spyware, bad adware etc.

How can you prevent your computer from being damaged by malware?
  1. You MUST have an Anti-Virus tool
  2. The Anti-Virus must cover your E-mail and Chat too
  3. Have a firewall turned on
  4. Use McAfee SiteAdvisor to keep you out of bad sites on the net
  5. Use a non-administrator account for email and browsing.
  6. Do Not Download from unpopular/unfamiliar sites. If you are looking for freeware or shareware versions of popular programs, stick to tucows.com, downloads.zdnet.com and download.com.

Sunday, 29 July 2007

Hardware, Software, Crapware

What's Crapware? Software that you don't need but is installed on your PC and taking up valuable resources.Get rid of them with the Add/Remove Programs applet in the Control Panel.
And watch http://www.cnettv.com/9710-1_53-28721.html for a nice video.

Sunday, 24 June 2007

Minimise Online Risks - Don't Use an Administrator Account

If you are using the Administrator account or an account with administrator privillages for routine work like internet browsing, email etc, then you are asking for trouble.

If a worm or a virus manages to get past your antivirus software (you have antivirus, don't you?), then the worm or virus will have all the previllages that your administrator account has - that's total control. It can install itself wherever it pleases, do whatever it wants and the total system will be at its mercy. System wide malfunction will occur. Removing the virus will be very dificult.

On the other hand, if you are using a non-administrator, limited account, the maximum rights that the virus can get is limited to your limited account's previllages. Atleast it wont be able to modify system files, install iteself everywhere etc. The infection will not be system wide and it will be relatively easier to recover from too.

To findout what your previllages you currently have, go to the Control Panel > User Accounts. If you are using an account that's labeled 'Computer Administrator', you better use another account which is a Limited account for Internet and email. If needed, create a new user with Limited privileges just for Internet and email.

Use the latest version of FireFox or Internet Explorer 7 to increase security. Go to Windows Update website to keep your software up-to-date.

Thursday, 14 June 2007

Free Antivirus for You

Does your system have an anti-virus software installed? If your answer is no, you defenity are looking for trouble. YOU NEED ONE.

Here is a list of antivirus software for you to choose from.

In my own experience, I have found Norton Antivirus to be very effective and comprehensive. It seems to stop a virus even before the virus sees your network cable! But you have to pay the price for it: Firstly, it would cost around Rs. 1500 per year. Secondly and most importantly, I have found it to be too demanding on the computer's resources. I have noticed performance degradation on most computers with Norton Antivirus installed. What ever does it do with my Dual Core 3Ghz CPU, 512 MB RAM, 7200RPM SATA HDD?

I find Grisoft's AVG offering to be pretty neat. AVG Anti-Virus Free Edition is totally free of cost and includes regular updates from the Internet. I have found it to be satisfactorily effective in fighting against viruses. The free version does not include spy-ware protection or a firewall. But if you know what you are doing with your computer and on the Internet, you will find that AVG is a no-fuss, effective and keep-it-simple thing to have. The plus points are: 1. Its light on resources, 2. It doesn't cost anything.

You can also buy feature-rich versions of AVG Anti-virus if you need them.

Overall, a simple, must-have, no-fuss antivirus. Best when used along with some firewall.