Monday, August 27, 2012

Facebook connects users to free antivirus software

Facebook is now directing users who think their computer might be infected to sites where they can get free antivirus software.

The Malware Checkpoint for Facebook sends people either to sign up for Microsoft Security Essentials or McAfee Scan and Repair. Mac users are referred to an Apple Security Updates site.

Facebook already notifies users when the site detects a possible malware infection on an individual machine, and provides these users free antivirus software to clean up the infection. The social network has now opened up its anti-malware campaign to all users in order to them them proactively protect themselves, according to a post on the Facebook Security page:

If you are concerned that your device may have been infected by malware, you can visit http://on.fb.me/infectedMSE or http://on.fb.me/infectedMcA to be self-enrolled in either our Microsoft Security Essentials or McAfee Scan and Repair malware checkpoints...
1. The McAfee option will download a small program onto your Windows computer to perform a one-time scan of your system for malware. It will not interfere with your existing anti-virus or other security products. After it scans your system, it will give you the option to automatically or manually remove the files it flags as malicious.
2. The Microsoft Security Essentials option is a full anti-virus product. Upon download and install, it will add anti-virus software to your computer that will continue to protect your system with the latest anti-virus signatures from Microsoft.

Last year, Facebook added new security features, including Login Approvals and warnings when users are about to get hit by clickjacking and cross-site scripting attacks or malicious links on sites. Earlier this year, the site began offering free antivirus assistance and improved its external blacklist system to protect users from malicious Web sites.




Article Source

Friday, August 24, 2012

Nasty Trojan that encrypts your files

There is a lot of nasty malware out there and a new one popped up this week. This particular malware is a Trojan and the idea behind it is not new though the Trojan now has new and improved ways to spread. Unsuspecting users can be infected by the Trojan by clicking on infected links, particularly in forums.

This Trojan is a ransomware that encrypts your files (documents, image and shortcut files) and demands a password to decrypt the files. This password is available for the small price of €50. If the user attempts to enter a password, he will get five attempts before the files are locked and sealed, impossible to decrypt. The Trojan is called Trojan:W32/Ransomcrypt. Once the files have been encrypted, the EnCiPhErEd ending is added to their file name. A text message is displayed, offering the user to enter a password. If the password is wrong (which it of course is because the user has no idea what it could be), another text message appears that offers the release of the encrypted files after the ransom has been paid. F-PROT Antivirus users will be happy to know that a virus definition for this infection has already been released. F-PROT Antivirus users with updated programs should be safe from this malicious Trojan.

To avoid infection of this type, we encourage users to avoid clicking on suspicious links and never to enter their credit card number or transfer money after a mysterious pop-up message from a product or service that you did not request is displayed on their computer. Installing and using a good antivirus is also essential. Also, and this can not be said too many times, it is absolutely vital to have a back up of all files, photos and documents. Regularly take a back up of all your computer data and store it in a safe place.

Article Source

McAfee antivirus update hits enterprise customers

DAT 6807 and 6808 updates crippled antivirus programs and left some computers without an Internet connection

A buggy update released last week by security vendor McAfee for its consumer and enterprise antivirus products, left the computers of its customers unprotected and, in some cases, unable to access the internet.

The incident affected both home and business users, some of whom were still trying to sort out the problems caused by the updates on Monday and Tuesday, according to messages posted on McAfee's community forums and Facebook page.

The problems were introduced by McAfee updates DAT 6807, released on 17 August and the subsequent DAT 6808, depending on which product was used.
After installing these updates some home users started encountering errors when accessing the McAfee Security Center console, which prevented them from performing any action inside the program. Other users experienced a loss of internet connection on their computers.

McAfee confirmed these problems on Sunday in a technical document that described two possible solutions, both requiring users to update to a newly released DAT 6809 file.

One workaround, intended for users who lost internet connectivity on their computers, involved uninstalling the product, rebooting the computer, downloading an updated version of the product from McAfee's website and installing it.

The other solution described automatic and manual methods of updating existing installations to DAT 6809. Users who continued to encounter errors after updating to this DAT version were advised to uninstall the product using a specialised tool called McAfee Consumer Product Removal (MCPR) and then install the updated version of the product.

Users of McAfee VirusScan Enterprise (VSE) 8.8.x, the company's flagship enterprise antivirus product, had to wait until Monday for a so-called superDAT hotfix that wouldn't require them to reinstall the product on thousands or hundreds of affected computers.

For VSE, the bad updates caused issues with the on-access scanner (OAS), a critical component that checks all files accessed by the system for signs of malware, the company said in a support document published on August 20.

Some administrators in charge of antivirus deployment in corporate environments expressed concern that while the OAS remains disabled a user could get infected and the malware could spread to other computers on the network.

"I have 46 out of 152 computers, having this issue," said a user on the McAfee community forum for business products. "I currently have over 3000 endpoints with this problem - solution asap please McAfee," another user said.

"The issue is well over 24 hours old now, and it's been 'officially' confirmed for nearly 24. That's a very long time to have AV [antivirus] in a faulty state," one wrote hours before McAfee released VSE 8.8 Hotfix 793640 to remediate the issue. "At least one saving grace is that many customers had their machine switched off over the weekend," he said in a later post.

VSE 8.8 Hotfix 793640 is mandatory and includes the full DAT 6809 package, McAfee said.

Because of this the file is approximately 100MB in size and deploying it to thousands of machines posed a challenge for some administrators.

"McAfee is working on a smaller solution that will remediate the issue without the need to include the full DAT package," the company said. "There is no current ETA for this release."

In the meantime, McAfee recommended that the hotfix be deployed in stages on networks with offsite branches, where it might cause bandwidth issues. "For example, schedule the update task to run for one group at a time," the company said.

Another problem encountered by administrators was determining which of the systems under their care were affected. The ones with the buggy DAT files should report a DAT and antivirus engine version of 0.0000 to the central ePolicy Orchestrator (ePO) server.

However, after the hotfix is deployed, some computers can continue to report this bogus information because of caching until they are forced to provide full property data to the ePO server, McAfee said.

Even though the hotfix does not force a reboot, the company recommended that administrators reboot all client systems at their earliest convenience in order to validate that the fix was successfully installed.

Some users whose affected systems include servers were not happy with this. "This has predominantly affected our servers and rebooting them isn't an option," a customer said on the McAfee forum yesterday.

"I work in a very tightly controlled environment and rolling out a 100mb hotfix that MAY require a reboot ASAP is not going to happen," another user said.

This is not the first time that McAfee has issued a bad DAT file. In April, a DAT update for McAfee email gateway security products resulted in system crashes and message scan failures.

However, McAfee is not the only antivirus company that was forced over the years to deal with buggy updates that affected their customers' computers in a serious manner.

"Since these events are becoming a worrying trend, should we implement test procedures inside our organiSations as we do with other updates like the ones deployed by Microsoft with Windows Update?" asked Manuel Humberto Santander Pelaez, a security incident handler at the SANS Internet Storm Center.

Some users who responded to Pelaez believe that testing every antivirus update would cost too much time and resources compared to the possible benefits. Others said that delaying the update deployment by 24 hours or deploying the updates in stages starting with the least critical systems would limit the impact of a bad update.

Delaying antivirus updates increases a computer's window of exposure to the latest threats. However, this is a calculated risk that some administrators are apparently willing to take.

Article Source

Tuesday, July 17, 2012

Symantec antivirus update causes Windows XP machines to crash

Customers were not happy after security firm Symantec made a recent update to its antivirus software, causing some Windows-based PCs to crash repeatedly, showing a dreadful “blue screen of death” in many cases. The company released a statement on its website saying it received a number of reports with machines running Windows XP that were continuing to show the blue screen after rebooting.

It was discovered that the issue had been limited to machines running any combination of Windows XP, the latest Sonar antivirus software version, the 18 Sonar signature set from the July 11 revision and software from third parties. “The root cause of the issue was an incompatibility due to a three way interaction between some third party software that implements a file system driver using kernel stack based file objects – typical of encryption drivers, the SONAR signature and the Windows XP Cache manager,” Symantec said.

Enraged customers said they were forced to remove the software manually and disable their machines. Someone had said on the discussion boards that Symantec would compensate customers for the inconvenience, but the company recently responded to the problem saying that it would not be providing compensation packages. Symantec said it was working hard on a solution and providing technical support to customers, including directly reaching out to customers who had posted about the issue on the discussion boards.

Monday, July 16, 2012

Bitdefender 2013 launched

Bitdefender has released its 2013 range: Antivirus Plus 2013 ($49.95), Internet Security 2013 ($69.95), and the high-end Total Security 2013 ($79.95).

And the headline addition this time is Safepay, a secure virtual browser which aims to protect your online banking and shopping details (although the technology will help to shield any confidential online activity). It’s a useful feature and is available on all three products.

The 2013 products also now include a “USB Immunizer”. Right-click a flash drive in Explorer, select “Immunize this drive” and it’ll be protected against future infection by autorun-based malware.



The other major new feature is Anti-Theft, a computer location service which is available in Total Security 2013 only. If your system is lost or stolen then just log in to your Bitdefender account, and you may be able to display its whereabouts on a map, as well as locking the computer remotely or, as a last resort, wiping it clean.

And just as you’d expect, several of the existing features have also seen worthwhile enhancements. The parental controls are more capable, Safebox now allows secure file sharing, and the MyBitdefender dashboard now makes your program status accessible to any internet-connected device, for instance.

Put it all together and this looks like a solid move forward for Bitdefender. Safepay in particular seems a very effective way to avoid malware, and it’s good to see the tool available in every program across the range. If you’re looking for a new security suite then Antivirus Plus 2013, Internet Security 2013, and Total Security 2013 deserve careful consideration, and 30-day trial builds of each are available now.


Thursday, July 12, 2012

Avira AV update hangs systems

A faulty update for Avira's paid-for anti-virus software blocks harmless processes and may in some cases stop computers from booting. The update results in the ProActiv behavioural monitoring component becoming oversensitive in its treatment of executable files.

According to user reports, ProActiv blocks trusted system processes such as cmd.exe, rundll32.exe, taskeng.exe, wuauclt.exe, dllhost.exe, iexplore.exe, notepad.exe and regedit.exe. In some cases this results in Windows failing to boot properly. It also appears to be blocking non-OS applications such as Microsoft Office, the Opera web browser and Google's Updater program.

All versions which include the ProActiv behavioural monitoring component are affected, including Avira Antivirus Premium 2012 and the enterprise version; only 32-bit systems are affected, as ProActiv doesn't currently support 64-bit operating systems. On the Avira forum, an employee of a company which runs Avira on one hundred computers complains that, "This update has been pretty catastrophic. The whole company ground to a standstill."



Until the problem has been resolved, users are advised to disable Avira's ProActiv behavioural monitoring component
In view of the arbitrariness with which the behavioural monitoring component is blocking files, users who have installed the update are advised to disable ProActiv. To do so, access Avira's settings, activate the Expert mode using the switch on the left and uncheck 'Enable Avira ProActiv' under 'Realtime Protection', 'ProActiv'. According to user reports, if Windows is having difficulty booting, this can be fixed in some cases by starting in safe mode and then deactivating ProActiv.

In a statement to The H's associates at heise Security, Avira confirmed the problem and said that its developers are currently working on an automatic update to resolve the bug. The potential scale of the bug is huge – according to Avira, the faulty update has already been downloaded more than 70 million times; this figure includes those running the free version of Avira which is not affected. The company has now stopped distributing the update.

Update: Avira recommends adding exceptions for the affected system processes to the ProActiv's Application filter. However, as the list of processes is rather long, it is still advised for the time being to disable ProActiv.

Update 16-05-12: Avira has released an update for its products that caused them to block legitimate Windows applications and system processes.

Monday, July 9, 2012

Bitdefender Clueful removed from the Apple app store

The Bitdefender app for Apple devices cluefulapp.com was removed from the appstore.

Clueful was designed to be the only way to really understand iOS apps, how they use your private data and treat your privacy. This one-of-a-kind product identifies intrusive applications and shows you what they do behind your back.

We do not know at the moment why Apple did this, no comments were issued on the topic.

With Clueful, Bitdefender said it can now answer questions about what your apps are doing. It shows which apps are accessing your location, tracking your in-app usage, reading your address book, linking your actions across apps to a single identity, needlessly keep GPS running, thereby draining your battery, accessing your UDID, and a host of other ills. To do so, Clueful examines what applications are running in memory and then retrieves audit information from the “Clueful Cloud.” (That’s the name for the space where Bitdefender maintains all the data on apps, and it’s also the way they ensure communication between the app and Bitdefender’s research labs.)
To create the Clueful Cloud, Bitdefender built proprietary technology similar to what they use for their anti-virus products, but customized for iOS apps. But because it’s a proprietary technology and patent pending, the company won’t go into detail about the specifics of how it works. But the long and short of it is this: Bitdefender tests apps, creates a database, and then shares that info with the Clueful app to give you insight about the apps you use on your phone.