MalWare Corrective actions

Sorry, Apple People, You’re Just Not That Popular

I know, you think I’m less than smart, but let me assure you, I have some idea what I’m talking about. I began as a wildly satisfied Apple ][+ user many decades ago. While others bought “inferior” computers that hit the market, from PET, Commodore, Atari and TRS-80…well, Atari was the bomb for gaming….I was forging ahead. I moved to the Mac line with a 512K, then an SE, a Mac II, then a IIcx. I learned how to make a computer work for humans because of Apple.

However, here’s the reality. Macs aren’t that popular. I support this by playing into the meme that Macs don’t get viruses, ergo, they are superior platforms. Nope, you have that wrong, but there is the genius of not only Apple, but the evangelized Apple faithful that have somehow missed the point of their lack of bad programmings disrupting their lives at the worst moment, as PC users have come to know and still not love.

Here’s the truth staring you in the face, Apple fanatics: You’re not popular with the people who create viruses, and therefore, you don’t get them. It’s not that your computer is in this uber operating system world, impenetrable by mere mortals out to steal credit card and bank account numbers. I know, in just about every single movie where the earth is saved from alines of environmental disaster, Apples are prominently displayed and used in the crucial scenes. I also know some of you believe that to be the real case.

What’s really up is this: The MacOS is built on top of UNIX, which is very secure, but the face that, depending on the link, the Apple market is about 10-12% and therefore, the effort to infect them is not worth the ROI, on one analysis point. Take the next step: How many Macs are used to manage and handle credit card databases, and large customer files? Pretty much none. Besides taking quite a bit of effort to learn the system inside and out, even if they could find ways in through security flaws, they would most likely find intellectual property, but not something they could make money on, like entire user profiles of banking/financial services, a key set of data for identity theft.

Consider, from a business owner’s view point: If you could set up to serve 87-90% of the market for the same effort to serve 10-13%, with the return per customer the same, which direction would you head? There will be a minnow out there (thank you, Scott Weber!) who gets this answer wrong and insists loudly they are correct, but you all know the right answer to remain viable in the market. That’s why you’re also not infected. Far more ROI in spending your energy developing and working the PC market and the associated Windows based server farms. Not to mention, Apple made a run at the server world and built a very cool piece of technology, but like Beta tape, the public went for the lesser versions in the PC based systems using LINUX and Windows.

That all being said, there are those, because the Apple market share is growing no doubt, who are taking up the challenge to infect the Apple Faithful. You’ve been spared due to not being attractive (I’m not talking the aesthetics of the device design, but the ugly fact that Apples aren’t used to conduct serious financial business). That’s my tough love for you. Some are coming after you and the good news is you can now enjoy virus and malware protection as we PC users do.

Now let me, after turning your meme upside down, drop it on (your) its head: If the MacOS doesn’t get viruses, as some smuggly post to Facebook, why, pray tell, would giant anti-virus companies have software on the market to provide anti-virus for the MacOS that doens’t get viruses? Oh, yeah, it would be a very silly and costly idea to serve a market that has no need, right? Software costs money and then, as any product has to return some what of a profit, or it will be dropped from the company offerings for failing to add to the bottom line.

Check this Dogpile search out: Looks like Symantec, ESET, Norton and Webroot, Avast, AVG just to name a few “small” companies trying to sell something “real” Mac users don’t need.

I’m hoping this dose of reality spurs the Apple faithful to break down and admit they have been a tool in the greater Mac propaganda machine, but then get online and download an appropriate software package to protect themselves. Speaking as a complete PC/Windows user for all my own (too) many computers, it’s a pain to get them, I have two layers of anti-malware/virus on all my systems, just to practice as much safe computing as possible. I encourage you Mac types to do the same. I see the helplessness in people’s eyes all the time, when they have contracted such an infection. Trust me, you don’t want to feel that way, let alone missing your working hours while I or your Mac tech (who should have already advised you to get software – if they haven’t, send them this link so they can be better providers for their customer base) conduct the technical exorcism rites.

If you need help in getting protected, contact me and let’s get you into the real world you actually live in.

Malware and Virus attacks get more “life-like”

I spent a few hours pulling a serious malware infection, actually a set of 8 different ones, off a client’s main system yesterday. He contracted the mess at 5:40 PM last Monday.

My contention os these attacks are getting more “life-like” is based on the manner in which he identified the moment of problems: He has a major customer and he ships mountains of product to them via UPS. On Monday afternoon (consider what else was going on in the Post-Christmas days and UPS), he received and email indicating an updated delivery status for his UPS shipment. His comment was it appeared to look very much like others he had received via the major customer, so he clicked on it. He said it didn’t have fancy graphics, but it certainly was a detailed looking email, not a one liner with a link.

It also reminds me of the 1-3 emails I get a day into one of my other blogging emails that obviously some scraper picked up off that site. They tend to be advertisements, but they are mixed in with emails that are my accounts at (fill in the banking institution) suspended, blocked, etc. Some of them actually are all dressed up with HTML graphics layouts, too. I stay away, but then I deal with this daily. For others, like my client, when one comes that makes sense to their work flow/life/personal business/social networking, there is a likelihood they will allow the malware in, and their firewalls may not stop it.

For the user: You have to be wary of things that look kinda true , but something still tells you it’s not kosher and look closer before clicking.

Be careful out there and practice safe computing!

For you techs, looking how to get rid of this:

Anyhow, it really embedded itself within his system, flagged as a Win32 password stealer by Microsoft Security Essentials. The good news, in early Tuesday, I convinced him to take the rest of the year off and reward himself for a great year, and I’d be over Thursday morning (since the malware would allow a network connection for a few moments, then cut it off, so a remote session was out of the question.

I used MalwareBytes, Microsoft Security Essentials, Kaspersky TDSS Root Killer and old school digging through the entire registry, after seeing the names in the user appdata roaming and local files under nonsense random lettering named .exe files and folders.

I called this one a “repeater,” as MSE would identify it, clean it, then it would fire itself back up about 30 seconds later. I would see 8 different start up program listings named BitNefender 2016, turn them off, and they would be back, activated in the next reboot. Interestingly enough, searching for that name in the registry never found anything, even after several tries.

It was the searching for the keys and values in the registry and manually deleting them) that, in combination of the MSE and MalWareBytes scans that finally got things working normally, including restoring a constant network connection.

It’s Flu Season….for computers, too!

I’ve mentioned it lately, but I’m keeping busy chasing smarter viruses. Now I’ve seen “repeaters,” meaning the anti-malware/virus software did it’s job, but something in the background was watching over the process and did the ET “Phone home” thing, and in one case, within seconds, the malware was coming right back up as being detected. End result? I took a long look at the history in Microsoft Security Essentials (MSE) and then went chasing the indications on the net. The thing that caught my eye was a infection/hijacking of an add-in to FireFox, the main browser they used.

Response: Control panel>Uninstall FireFox. Then I went to the (windows Vista settings) user/application data> local and roaming directories and deleted the FieFox folders completely. Then downloading and installing a new copy of FireFox solved the problem. That was three days ago, and I’ve not been called back for subsequent fixes.

I have been chasing the Windows XP Anti-Virus 2012 and Firewall malware for about a week now, in a home with three computers, that don’t share data, but the malware seems to get taken off, then shows up on one of the other (or both) computer(s). a day later. The computers are all being used for separate uses, so common websites/files aren’t a condition. Best guess I can come to right now is the Internet Explorer * is compromised on one of the systems, since we can scan with several products, block with firewalls, and at some point, it’s either hammering to get in with great rapidity, or it reappears on the screen. Today I had them shift that computer to FireFox as the default browser and it’s been quiet on the phone since this morning. Haven’t gotten an email or call, so I suspect that’s the case. In a few days, barring a reinfection, I’ll have to figure out how to uninstall IE 8 and put it back in again.

Between all of these, I can’t figure a common thread of how it’s happening, but the result is not so good for the users. I have a suspicion one of the flash game websites, frequented by one user may be injecting scripts, but that’s still just speculation right now.

Be careful out there! Make sure any links you click are really good ones…..that will be the topic of another full featured post soon: How to validate links.

My User is being directed into another users folder named TEMP

Malware, BadWare, ScareWare, RansomWare, just make you MadWare. I couldn’t get back far enough to find the cause, but the brief version began with a call well before business hours from a client…

I didn’t get to see all the problems, as he tired to fix it first, before deciding this was something different. The story goes like this: “I had a message on the screen to upgrade [not update] Avast.” He did as directed, and it said it had to reboot. When he came back to the login screen, all three users were presented and he clicked on his own icon. In he went, to a balck desktop, missing all but the public icons. When he started Outlook 2007, it took him to the new install, set up a new account wizard.

He ran a restore point, yet the results were the same. He left me a message.

I go there and began to look for the associated “hide all your icons” malware, but the user documents folder was empty…not even any hidden files, just like a new Windows 7 user would be. Found the Outlook .pst, and it was very small, but there with a new date. His desktop folder had none of his files/icons, so this left me wondering what was up. I pulled up the cmd line and what caught my eye was the initial directory was “C:\Users\TEMP>,” not one named for his user, as he signed in under.

From here, I wondered what was up, so I went to regedit and did a serach for “\users\temp.” I got the result I was looking for (in HKey_Users), but it was the surrounding registry entries that clued me to the fix required: The malware had taken the normal -1000 (first user) and had renamed in with a “.bak” extension, and then in the now existing -1000 user settings, it had used his login in name, but pointed his settings to the “\user\temp” folders, which now explained the absence of any of his files.

I went back to Windows Explorer and confirmed all his files were actually in the user folder bearing his name, and then, being a bit smarter on the problem, noted the temp user folders were, of course, like a brand new user.

The repair was simple at this point: Rename the offending -1000 user with a “.bad” extension on the entry, then removed the “.bak” from his real -1000 user entry. Of course, I first backed up the registry as it was, just in case I would find out this wasn’t the case, and then, with the changes in place, restarted the system and all was now back to normal.

Still can’t tell you the exact cause, but the symptoms were a solid black desktop, and empty files for My Documents/Pictures/etc, and Outlook wanted to create a new install for a new user. All it turned out to be was the infection had copied and renamed the proper user registry entry, and put iteslf in is the user, and, while using the the correct user name, it was sending the coputer to the new “TEMP user name, now new and empty folders.

The reboot after correcting the registry entries worked fine, and that was two weeks ago.