Jun 20

What was I just saying in my most recent blog, “Apple Mac Arrogance or Pure Stupidity?“??

Hmmm, maybe I’m psychic? Or maybe I just know security! Ya think?

In a just published article on InfoWorld and MacWorld, Johnny Evans (MacWorld UK) reports that security vendors, SecureMac and Intego are separately reporting a new Trojan exploit for the Mac.

The Trojan horse is currently being distributed from a hacker website, where discussion has taken place on distributing the Trojan horse through iChat and Limewire.

The Trojan horse runs hidden on the system, and allows a malicious user complete remote access to the system, can reportedly transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging.

Additionally, the AppleScript.THT Trojan horse can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing. The Trojan horse exploits a recently discovered vulnerability with the Apple Remote Desktop Agent, which allows it to run as root.

My students have heard me preach and preach about the whole Limewire issue (not to mention bearshare and the others!) and I’ve stated in my referenced blog entry that Mac users are either arrogant or stupid if they believe they are exempt from these kinds of malware.

My God people, WAKE UP and smell the MALWARE!

To read the full InfoWorld Article, click the link: Full InfoWorld Article.



bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark

Share This Post

written by Admin \\ tags: , , , , , , , , , , , ,

Mar 31

This is one nasty bugger! WOW!

It starts out with an annoying pop-up message on your taskbar over by the clock. When the balloon error message disappears, you get a red X like the Microsoft Red X inside the security shield. This message however, is missing the security shield that windows uses.

The other thing I want to point out about the error message, is read the wording. Although this looks like a typical windows message, Microsoft can spell and uses proper grammar! Specifically, the message says, “It is recommended to use special antispyware tools to prevent data loss.” BAD GRAMMAR! Not Microsoft.

The message further states that “Windows will now download….” Another dead giveaway that this is not Microsoft. They NEVER ask your permission to do anything! (SMILE)

But seriously, here is the actual message pop-up.

Reanimator Malware

What’s bad about this one is that it does look like a typical windows message. In the case of my sisters PC, Trend blocked the reanimator from downloading its dastardly tools that would plant a nice Trojan onto the machine. But, we needed to get this thing out of her PC!

There were two affected files: winivstr.exe and braviax.exe that was hidden in the Windows folder and the Windows/system32 folder. Braviax.exe was slated to run at startup in MSCONFIG.

This bugger also totally disabled and hid Spybot Search & Destroy! We could not use it even when I found it by unhiding the hidden files and folders.

I booted in safe mode to no available.

I removed the files in safe mode, removed the prefetch files, turned off the msconfig startup of the file, and removed registry files only to have it reappear on normal boot.

It was listed inside the windows .dat files for Internet Explorer and the desktop. The more I tried to eliminate it, the more it returned.

After hours of trying to remove this sucker manually, I gave up and did a Google search to see if anyone else had successfully deleted it.

I’m always squeamish when it comes to freeware, but at this point I was ready to try anything.

And I’ve got to tell you that I found the most awesome removal tool for this thing!

Now, mind you that this website goes totally against everything I teach in my new CyberSleuthing Websites eBook, but it was worth the risk. If I couldn’t get the darn thing out of the computer, I’d have to reformat anyway. So if Trend PC-cillin decided that this tool was also a bad guy, either way I lost nothing. At best, these guys would be legitimate and we’d clean the machine!

Well, it worked! I couldn’t believe how fast and easy it was! And Trend didn’t mind it at all.

The tool? MALWAREBYTES ANTI-MALWARE.

Kudo’s to the folks at Malwarebytes.org!

Once the bugger was removed, guess what became available again? Spybot S&D! And even that played nice with Malwarebytes Anti-Malware program.

I am really, really, really impressed!



bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark bookmark

Share This Post

written by Admin \\ tags: , , , , , , , ,

© 2007-2008 MICE Training & Technology™.

Bad Behavior has blocked 47 access attempts in the last 7 days.