Showing posts with label Windows trojans SystemSecurity. Show all posts
Showing posts with label Windows trojans SystemSecurity. Show all posts

Sunday, January 01, 2017

Software and Tools - Backups

One of the most important things you can do after you secure your device is to make regular backups and just as important is to test your backups.

Why backup?

  • Hard drives fail.  It doesn't matter how new the drive is or even if it is a SSD they will fail sooner or later;
  • You lose your device or it is stolen;
  • You drop your device and now it does not work;
  • When you patch or update your operating system it fails.  It doesn't matter the O/S you are using, I have had failed Linux updates and it required me to rebuild the machine;
  • You migrate to a new device and want all the files on the old machine moved to the new machine;
  • You finger slips and you accidentally delete an important file/directory; 
  • There is a disaster (ie. fire or flood);
  • Your device(s) infected with a virus or a trojan.  Again, it doesn't matter the O/S you are using, there are nasty programs out there that works in Windows, Linux and OS/X.
If one or more of the above happens you will need a backup so that your important documents are available to you when you rebuild the device or copy to a new device.  I have had people come to me with dead and dying devices asking if I can pull off their data and they have not made any backups.  Too often I cannot recover all of their files and important documents, images, videos are lost and they don't have any backups.

Things to think about

How often do you backup? 

  • That all depends on your personal preferences and how many documents you are adding to your device;
  • If you don't create very many then it may be safe to backup infrequently (monthly); 
  • If you create a lot of files (like scanning family photos), then frequent backups (daily) may be a good thing;
  • Once you set a schedule stick to it.  I put up a recurring reminder in Google calendar to remind me of when backups should be run.  Also you can set up a recurring task in Windows and Linux (cron) to run your backup scripts on a set schedule.

How many copies do you want to keep?  

  • Again this is a personal preference, but, multiple full backups is a good thing just in case one fails for some reason; 
  • An option here is a monthly full backup and then weekly backups of new/changed (differential backups) files;
  • Another reason as backups may fail and if you have only one copy then you have nothing to go back to.  I know this happens as decades ago when at work we were doing a DRP (Disaster Recovery Plan) exercise at work and one of the corporate backup tapes failed.  It wasn't a major problem as we did keep multiple backups and restored from an older image;

Off-site location for your backups?  

  • It doesn't matter if you have a good set of backups if you cannot get access to your site;
  • How secure is the off-site.  If you have sensitive information you don't want anyone getting access to the backup;
  • You should also figure out who should have access to your backups and let them know where it is and how they can get access to the backups if required;

Media for backups.  

  • Decades ago floppies were the media, then CDs followed by USB drives;
  • When you backup make sure that the tools, hardware and software is there to allow you to read the backups.  An example of this is some time ago I had to pull off backups from my father-in-law 3.5" floppy drives as he didn't have a floppy drive in his machine.  We were lucky in that I have an external 3.5" USB floppy drive for this and it was set up in Linux.  I also have an external CD drive and a blu-ray drive (call me paranoid) so I can pull files from backups in that format;
  • To the cloud.  Don't depend on that as your main backup as it may not be there when you need it.  I like Google drive for a secondary backup myself and the bonus is that the files I put there are available anywhere I have a web browser (and the firewall allows access).  With the various sites getting hacked I also don't keep files there that are sensitive and when I do put up a file of that nature I use encryption on the file/directory.  I also have a small script using GRIVE in Linux to pull a backup from GOOGLE drive to my machine.

Software and file format for backups.  

  • Over time operating systems do change and the software that did the original backup may not run on your new device and the new devices may not even be able to read your backups;
  • I tend to work with the lowest common denominator for backups that does work across platforms.  I prefer to use "ZIP" files as I know Windows and Linux both can work with that file format.  I assume OS/X will be able to read them too, but, I don't use that operating system so I am not 100% sure;
  • On my Linux machine I am partial to KBACKUP.  It is fairly easy to set up and use and it stores the files in a format that I can open in an Linux distro and Windows;
  • On my Windows box I use a simple XCOPY routine.  It isn't pretty, but, it works and the files are in a format that my Linux machines can read;
  • For my Android devices they get backed up to Google drive;
  • Several times a year I take one of my backups and plug it into a different machine to see if it is readable and I can pull one or more files off the backup.  Make sure what is backed up can be restored!  It is also a quick and easy test to see if your restore steps work and if there is anything else you should be doing when restoring from a backup;

When you restore.

  • If the restore is due to a virus or a trojan I strongly recommend that you don't ever use your backups until you have a clean and patched machine.  If the machine is still infected and the media you are using can be written to you don't want those backup files corrupted;
  • Make a checklist of what you need to do the restore and the steps performed when doing a restore.  This includes steps on how to verify that the restore worked;

My KBACKUP routine

Here are screen shots of my starting KBACKUP, running the backup and when it finishes.
Shortcut in my toolbox

Loading my backup profile

Directory & file list for backup

Backup running

Backup done with filename

Sunday, November 13, 2016

My guess for next gen malware encryption

I am going to make a bet that the next generation of file encryption malware is going to be a lost nastier.  Your best defence is:

  • Backups.  Keep multiple backups and not connected to any network after your backups are done.  Don't just do backups, test them!  Too many times someone approaches me saying they need help as they tried to restore files from backups and they don't work;
  • Up-to-date software.  When patches comes out for your operating system and applications install them ASAP.  Most of the time those patches are due to holes and the hackers are already using them.  It does not matter what O/S you use, Windows, Linux, OS/X all need to be up-to-date;
  • Home routers.  Keep them up-to-date also.  Sometimes your ISP will patch their routers, ASK them to keep their hardware up-to-date;
  • Good anti-virus software and keep them up-to-date;
  • Do and not opening up attachments from emails that you didn't ask for is also a good step;
  • Good web surfing habits.  Sometimes a site will pop-up 'You need to update or install this program to view'.  Don't trust any site doing this.  Most of the time it is for Flash and people think 'Oh, I am out-of-date again' and click install.  NEVER DO THAT, go directly to the source of the program and check.  If it is out-of-date install from the maker directly and not from a web site.
Unfortunately the writers of these nasty programs won't stop there.  They have been using ad-malware and then getting into legit sites serving ads and try to infect you when you view their "ads" and try to bypass asking your permission to install.

Right now when your system is infected and your files are encrypted some people recommended to turn back the system clock so time does not expire. Right now that works, but, I suspect not for very long.  The writers of these programs know that "trick" and I suspect they are working on how to counter that.  I see them saving the system clock information and the network time information at time of infection.  With that they know exactly when they installed on your system.  They also can determine the basic time differential between your system and the network.  If they then compare that information the next time it runs the program may just nuke your files if the date on system clock is less than their time-stamp.  Also, if they are really nasty they will also nuke the files if they cannot make a connection to the network to verify the time.  When they can make a connection they will use the time differential to see if you played with the system clock.  I would also be willing to bet that they will advertise what they did and why so that fact will spread around that playing with your system clock or unplugging from the network will nuke your files.  I don't know if (or when) that will happen, but, it will make your backups much more important as the only way to restore your system is to do a total wipe and restore.

Sunday, September 29, 2013

Some tools for securing & cleaning your Windows machine

This is not a fancy or pretty article, but, functional.  The following are various tools I use to help secure and clean computers.  This is a list of links I keep on my Google Tablet for when I visit and I can quickly download and install software.  The Windows Defender offline I install on to two USB sticks (32 bit and 64 bit versions).  The rest of the utilities I download and then copy to a USB stick just in case the person does not have a working internet connection.


Autoruns for windows
Technet.Microsoft.com/en-ca/sysinternals


AVAST:
www.avast.com


CCLEANER:
www.piriform.com


Chrome (note this installs only and no download):
www.google.com/Chrome

chrome://extensions
chrome://plugins


Firefox:
www.mozilla.org

To reset all and lose everything:
about:support and click Reset Firefox
safe mode: firefox.exe -safe-mode


Malwarebytes:
www.malwarebytes.org


SlimWare Utilities:
www.slimwareutilities.com


SPYBOT Search and Destroy:
www.safer-networking.org/private


SUPERAntiSpyware:
superantispyware.com


Window defender offline
Windows.Microsoft.com/en-CA/what-is-windows-defender-offline

Monday, May 14, 2012

It does not matter what O/S you use when it comes to malware

Now that the Apple people got a reality check on how secure their O/S really was when they got hit with flashback.  We all may want to think about securing our machines.  It does not matter what O/S you run, we call can have our machine taken over by malware.  A few things that we all should be doing to at least slow down and make the lives of malware authors a bit harder:

  • Keep your machines up-to-date by applying patches when they are available.
  • Never open attachments from people you don't know and be skeptical about attachments when you get one from someone you know and you didn't ask for that file.  
    • Assume that senders are not as vigilant and check with them before opening.
    • Assume that the from account name was forged.
  • Never believe a popup window in your browser stating your software is out-of-date and install the update via that convenient link.
  • Never believe those popups or messages while browsing that they scanned your system and you are (or could be) infected.  
  • Never run an account with admin priviliges.  Create a simple user account that cannot add, change or delete programs.
  • Do regular backups of your files.  External USB hard drives are inexpensive.  When you are done remove the backup and do not leave it connected all of the time to your machines.  If you do get malware at least you have a chance that the backup is still clean.
  • Use a simple firewall on your computer at a minimum.  
  • If your router has the option to enable a firewall then use that firewall too.
  • Assume that your machine will get taken over and make plans on how you will rebuild your system and recover your documents.
  • Install, use and keep up-to-date an anti-virus package and scan on a regular basis.  It really does not matter now what O/S you use, assume malware writers can take over your machine.
  • If someone hands you a CD, DVD, USB Memory stick or USB drive scan it before doing anything else.  Never assume that the media is clean.
At home every machine is running A-V software (for windows I like AVG as it gives good protect, fast running and not a resource hog).

I assume that sooner or later one or more of my computers at home will get infected and I will have to wipe and rebuild the system(s).  I do run backups on all of the machines so while I may lose some recent documents or email it won't be a total loss.

Thursday, June 02, 2011

Linux on a USB stick

For the last couple of months I have been playing with a variety of Linux distros, but, they are running on a USB memory stick.  I found a nice program UNETBOOTIN that allows me to download and then install on the memory stick a number of Linux distros. You have the option of having the progam download the ISO itself or you can point it to the ISO image on your machine.  The program does everything else for you and at the end you have a bootable Linux.

I find this tool to be extremely useful as I can quickly test out a new distro and not waste CDs if the distro does not meet my needs.  I have two sticks right now with Linux.  The first stick for now is SABAYON and the 2nd will be for a security and recovery distro.  I need the second stick as friends and neighbors have problems with viruses, trojans and spyware getting on their machines and I figure a secure Linux distro that can help me clean this up will be very useful.

Tuesday, January 18, 2011

Windows and a royal pain removing a trojan

I had to remove 'System Security' trojan from Jane's friend again.  We are not totally sure how it keeps getting back on after I remove it.  This is a royal pain of a program to remove as it seems to keep getting back on when they visit some site somewhere.  The first two times it was fairly easy to remove, but, this one mutated and rather than a series of numbers for the directory name and/or program name its a random series of characters for the directory and program name.  I found it by using a program that showed me what was starting up and when I saw that strange directory and program I knew it was the problem.

After removing the program and directory I set up two user profiles without admin rights and rebooted the machine.  The machine rebooted without a problem and we didn't have that crapware running on the machine.

You can read more at the wiki site about this program and how to remove it.

A few observations if you run windows:
  1. Keep your virus software and trojan scanners up-to-date.
  2. Keep you machine fully patched.
  3. Don't blindly download and install programs.  Do your homework and check it out before installing.
  4. Do not use the 'ADMIN' account.  Create a normal user with no rights to add/change/delete programs.
  5. Keep a good set of backups and backup on a regular basis.
I now have an USB stick with a number of tools that helps me look for the crap or just do cleanups and check for program updates.
  1. Sypbot Search & destory
  2. Malwarebytes anti-malware
  3. CCleaner
  4. Secunia PSI
There are probably other good ones, but, I like these as they work for me.