Showing posts with label HijackThis. Show all posts
Showing posts with label HijackThis. Show all posts

Thursday, September 04, 2008

TeMerc Guide To Malware Forensics

I've written up a fairly small guide to malware forensics, be it pretty basic tho.
Didn't get into any sort of file analysis or code dissection.

It's just something for those looking to get into playing with malware to better understand it. How it spreads, infects a machine, how it displays symptoms and makes changes to the system.

Be sure you've got a machine to sacrifice as things can get pretty ugly and I've crushed my test machine a couple of times and had to reformat to get things back up and running.

Hope you enjoy it and please feel free to comment good, bad or whatever.

TeMerc Malware Forensics Instructional Guide



Saturday, December 29, 2007

1-5 PCs Unpatched; Flag Malware Sites

Couple of new links in the forums today.

From security researchers in Denmark comes the stat that 1 in 5 machines are unpatched Windows OSes. This of course could lead to zombie armies that run amok across the Net giving me loads of HijackThis! log files to do. Read on about my hobby-to-be continued-for-the-foreseeable-future

And from a malware specialist who has written some great detailed analysis of RBN comes a challenge for users to ruin a malware gangs holidays

Thursday, December 13, 2007

Root Kits On One In Five PCs

The folks over at PCWorld have a new set of stats, collected with Prevx that indicates root kits are on 20% of all machines. Read More Here.

Monday, September 03, 2007

Bot Infections Multiply Like Bunnies: SDFix to The Rescue

Within the world of malware there are a couple of infections which seem to develop new variants very quickly. The type which seem to be the fastest, with new variants uncovered daily are of the 'bot' variety. These include but are not limited to backdoors, proxies, password stealers, downloaders\droppers and spambots.

Their names can strike fear in the hearts and minds of IT professionals all across the world not to mention make a home user nearly passout. Hacker Defender, InfoStealer, Rustock are but to name a few.

These can in many cases be cleaned up, tho to be honest, wiping the drive and reformatting to reinstall Windows is probably the best advice. If you have one of these then you'll be needing to use a specialized tool called SDFix, by Andy Manchesta.

Do not attempt to clean any bots on your own. These can require some specific registry fixes even before you begin cleaning, not to mention many bots are coded to prevent running of removal tools. Instead first install and run HijackThis! and post the resultant log into my Countermeasures: Extraction Hlep forum and I'll assist in removal.

Thursday, August 23, 2007

Open Any eCards Lately? HijackThis Analysis Required

Well, if you have, shame on you. If you opened on and then clicked on the link contained therein, you ought to be smacked! People like you make spammers rich just on curiosity alone. WAKE UP!

NEVER open emails unless the sender is known to you. NEVER click a link in a suspicious email. If you have done so, you'll need to get HijackThis! from here
and install as instructed. Then post a log into my
Countermeasures:
Extraction Help Forum
.

Of course you'll need to register to gain access and post the log.

I'll be all over it, like white on rice....no 3, 5 or 10 day waiting at this forum, no sir.

Monday, August 20, 2007

Tech Support Alert Mentions Us!

qtkbkOnce again my site has been featured in a newsletter which as it turns out has brought over two dozen new users to the site. After being mentioned in TechSupport Alert Newsletter the doors were busted down by people looking to join! An amazing display of how popular it is and how much they regard Gizmo's
opinion.

They featured us as a site to get quick HijackThis! analysis.

I've been mentioned in several other newsletters, Clif Notes, InfoPackets, BootLIST, LanagList and Daves Computer Tips.

But none of those have ever generated this level of new user memberships. Not to take away from any of those publications mind you.

So thanks to everyone who joined, thanks to Gizmo(I emailed him personally to do so) and I hope the new users find the site\forum contains info they find helpful.

Friday, August 17, 2007

Got Pop Ups? Spyware? Unknown Rogue Apps?

Then you may have something on your system which you didn't ask for. Likely you're not sure where you even go it.

But help is just a few clicks away. Find out if your system is dragging due to malware installed, using up your CPU and making regular normal day to day operations a real painfully slow process.

With a HijackThis! log file I can help you find and remove these bits of annoying software\files\folders registry entries.

And it won't take 3 days. Or 5 days. Or 10 for that matter. I can get you going right away.

Join the forum and drop your log into the Countermeasures: Extraction Help section.

I'm waiting.

Monday, July 02, 2007

New Rogues Aplenty

We have several new entries into the Rogue anti-spyware listings. We now have three great resources for this, Eric Howes' list (no recent updates), as well as the developers of RogueRemover at Malwarebytes and finally Security Cadets.

With these guys on the job, rogues don't stand a chance in hell of getting too many victims to bite on their sleazy products. Read & Discuss Here

Got one of these rogues on your system? Post a HijackThis! log into our Countermeasures: Extraction Help Forum

Tuesday, June 12, 2007

MS Updates, Julie Amero, YouTube Worm, HijackThis!

This months Windows updates are out, be sure to check them out. Four critical ones, one important and one moderate.

Malware researchers have banded together to help prevent a fiasco such as the Julie Amero case from ever happening again. It has some very prestigious malware researchers involved, its called the Julie Group

And a new worm uses a video from YouTube to infect users. While they watch the vid, malware downloads a trojan to steal your info. I'm surprised there has not been more of this, read on.


Finally I have HijackThis! analysis available and it's fast too. No days of waiting to get assistance to remove malware. So if you have any unwanted software on your machine, join the forum and drop a log into Countermeasures: Extraction Help forum.

Tuesday, April 24, 2007

SmithFraud Fix, SDFix Tools

I've just updated a couple of threads in our Latest Malware Threats Forum. I updated the SmitFraud post to show links to changelogs and tools and added one for SDFix, a bot detection and removal tool.