About Us

The Immunet Blog is maintained by the Immunet team as a forum for discussing news and issues related to AntiVirus, security and cloud technology.

Search

Entries in Malware (16)

Friday
Jul232010

Need Another Reason For Layered Protection? Here’s One. 

It’s not just you and me that have to worry about malware. This week, tech giant Dell discovered malware in its delivery of motherboards. The company is now in the process of overhauling its testing process to resolve issues before dispatching hardware to customers.

The culprit seems to be motherboards for PowerEdge servers that might  contain the W32.Spybot worm in flash storage. As reported in PC World:

Flash on motherboards are susceptible to the same kind of malware infections that USB flash devices are prone to, said Simha Sethumadhavan, assistant professor of computer science at Columbia University. This incident shows how hardware, either flash or a processor, if hacked, can be used as a way to transmit malware.

"All software runs on hardware. If the processor is hacked then it can subvert all software countermeasures. Since hardware is the root of trust, attacks on hardware are potentially more dangerous," Sethumadhavan said.

As you might recall, earlier this week wrote about the USB malware issue. This motherboard attack reinforces the need for layered of protection, as you never know if the problem will come from a tainted delivery batch or from your best friend’s infected PC.  Do you have layered protection?



Thursday
Jul012010

Don't Get Infected by Twilight Malware - Make Sure You're Protected

It’s no surprise that hackers have piggybacked on the pop culture hoopla surrounding yesterday’s release of the new Twilight installment, “Eclipse.” Fans are eagerly scouring the web for information on the movie, but more than half of the links they’re getting are tainted with malware, according to news reports.

Consider what this means for malware infiltration. If hackers can contaminate more than 50% of links on a particularly hot topic, our vulnerability to viruses is higher than we think. We take for granted that our Internet searches are safe -- after all this is information we’re seeking. It’s not as though we’re clicking on fishy links sent to us via spam. Well, that’s the old way of thinking. In the new world of malware, gaming search engines is a clever way to get savvy web surfers to stumble upon malware. And even if you’re not searching the web for Twilight content, there’s probably someone in your life who is. Are you protected?



Thursday
Jun102010

Oliver Friedrichs on Keeping Families Safe 

Yesterday, Immunet CEO Oliver Friedrichs was invited to be a guest on Cyberhood Watch Radio to talk about the importance of keeping families safe online. Hosts Dave & Bill tapped into Oliver’s expertise to inform audience about keeping teens safe this summer as they spend more time online connecting with their friends. They also asked for Oliver’s take on the urgency of malware lurking on social networks and how Immunet Protect’s unique social network can help you – and your children -- make good decisions online. Take the time to listen and learn about the looming threats online and why traditional antivirus products aren’t working. Click on the show titled “What Consumers Need to Know About Antivirus Software & How to Stay Protected.”
Listen to internet radio with Dave and Bill on Blog Talk Radio
Wednesday
Jun092010

‘Gaming’ Malware 

You are exploring the Wild West – at every turn there are grisly town hangings, gunfire ambushes, and reckless gambling sprees. All of this is just part of a day’s work. What actually stops you in your tracks is, when you’re suddenly warned that you have a dangerous virus – a computer virus, that is.

Hackers recently exploited the popular Wild West-themed computer game Red Dead Redemption with scareware. While scareware seems strangely appropriately for a game that thrives on danger, this malware was not part of the amusement. In fact, this is the latest in a string of video games to become prey for malicious software.  

While games being infected with malware is nothing new, the problem is gamers are sometimes reluctant to install antivirus software on their PCs for fear of slowing down their machines and hampering their gaming experience. But as gaming grows from a niche activity to an all-out national pastime, gaming malware could proliferate rapidly unless we step up and protect ourselves. Already we’ve seen popular social games, like Zynga, have become targets of malware and phishing scams.

And here’s the good news. Being protected doesn’t mean turning your computer into a brick anymore. That’s the outmoded desktop-approach to antivirus. Immunet Protect’s cloud-based protection installs less than 10 megs on your PC --- the lightest in the industry. All detection will happen virtually in the cloud, not on your desktop -- so your gaming experience won’t be weighed down. For those who are already protected, Immunet will give you an added layer of essential protection , still without slowing down your PC.

As we’ve mentioned here before, we’re launching a stellar new product next week that takes cloud AV protection to the next level. Stay tuned for more details. And in the meantime, be a friend to Immunet, and promote our new website (also coming next week) with a free Immunet Badge.



Friday
Jun042010

Did I Infect my Friends? Part 3: Clickjacking

This week, Facebook users were struck with a clickjacking worm that deceives users into “liking” sites to spread the virus. Clickjacking, similar to phishing, either tricks users into giving away sensitive information or works by hackers taking control of a computer when a user clicks on what seems like a harmless site. Here’s how the Facebook clickjacking worked, as reported in InformationWeek:

Clickjacking -- also known as likejacking -- works by spamming Facebook users with such content as "LOL this girl gets owned after a police officer reads her status message” and “the prom dress that got this girl suspended from school."

Click on the link, and a user will go to a seemingly blank page that says “click here to continue.” But thanks to “an invisible iFrame,” said [Graham Cluley, senior technology consultant at Sophos, on the company’s blog], clicking anywhere on the page actually republishes the attack content and link on the Facebook user’s status page, “in a similar fashion to the ‘Fbhole’ worm we saw earlier this month.” Fbhole likewise spread via Facebook status messages.

Other recent examples of this type of attack include, the “Distracting Beach Babes.”   If you’re struck, the key is to remove all the "likes and interests" from your profile. Then, delete the page from your newsfeed, most likely to be found in the ‘Recent Activity’ section of the profile but you may have scroll down for a bit. Then, get yourself protected to keep it from happening again. Your best bet is a product, like Immunet Protect, that is designed specifically to target malware on social networks, in particular Facebook. And if you haven’t yet been hit, download AV protection now as a preventative measure.

There’s really no reason not to take this simple step. It’s free to download Immunet Protect, it’s lightweight and won’t slow down your computer, and it provides essential security for your PC.

Tuesday
May252010

Doing Our Part to Ensure Facebook Safety 

Yesterday, Facebook’s CEO Mark Zuckerberg promised new privacy controls in the Washington Post, amid some criticism of the site’s recent changes. Kudos to Zuckerberg for stepping up and reinforcing Facebook’s commitment to users. In the Washington Post, Zuckerberg  points out, "there needs to be a simpler way to control your information.” And "in the coming weeks, we will add privacy controls that are much simpler to use." Great! But what he didn’t address was the troubling influx of malware on the site in recent weeks.

Let’s recap. There was the free giftcard scam, the Facebook worm, the beach babe virus, the “sexiest video ever,” among others. The malware that users share on Facebook spreads like wildfire because Facebook's viral sharing hooks really work, even if the content being shared is damaging to end users. 

We know that Facebook’s security team is hard at work trying to combat the malware issues that arise when criminal hackers are financially motivated to prey upon Facebook’s 400 million active users. However, while Facebook is doing what it can to keep us safe through their own security controls and through user education (like the Facebook Security page), ultimately the responsibility to protect -  both ourselves and our networks - falls on us. Facebook has no control over what software you do or don't have installed on your PC to protect yourself, but you can see why Facebook would be a safer community if every user on Facebook had real-time, effective antivirus protection that they could easily share for free. 

With antivirus products like Immunet Protect that are specifically tailored protect users of social networks like Facebook, it’s never been easier to be safer online, or easier to protect your community. It takes seconds to download protection that will last you a lifetime. What are you waiting for?

Thursday
Feb042010

RE: US Branded Dirtiest Web Hosting Nation (SC Magazine)

Today, the fine reporters of SC Magazine ran a bit of research from Sophos about the US being branded “the dirty man of the web world”. Infected websites, malware and malicious software abound.

We already know Twitter viruses, Facebook viruses and the host of other social networking attacks are an issue. Now, the trustworthiness of legit websites is an increasing concern and time is an issue - time, in the sense that antivirus protection follows the identification of a threat. This could take days for traditional software. There are plenty of examples around the forums

This is precisely the reason overlaying existing antivirus software with Immunet Protect is beneficial. Immunet’s community focus plus the Collective Immunity protection feature means if anyone using Immunet Protect registers a virus, all users are instantly protected against that virus. To better illustrate this point, have a look over the actual numbers:

 

 

Traditional

Immunet

Sample Collection

1 Day – 1 Month

Real-time

Sample Processing

1 Day – 2 Weeks

Real-time

Publishing

1 Hour – 1 Day

Real-time

Footprint

28 – 352 MB

10MB

Detection Technology

File Based, Signature Focused

Data Mining, Network Centric

 

Tuesday
Feb022010

Immunet beats out Microsoft Security Essentials and Avira in MRG Rogue AV Test!

Immunet Protect Beta 1.0.24 was recently put through its paces by the folks over at Malware Research Group (MRG). MRG is doing a well thought out monthly review of 30 anti-malware products to see how well they detect fresh, real world, active Rogue Anti-Virus programs.  The report titled “Rogue Software Infection Prevention Test, Januaryshowed Immunet Protect Beta performed quite handily. In fact, we beat out both Microsoft Security Essentials and Avira  at detecting these in-field threats. It’s great vindication for our community (and the development team of course..), particularly given we are in beta with some ways to go before all of our detection engines are deployed!

Tuesday
Feb022010

1.0.25 Updaters Posted

All,

The updater files for migration to 1.0.25 are now posted. The updaters will install the new product, uninstall old product if you have it and then load your new drivers. Migration can be done from any Immunet build from 1.0.14 up to current (1.0.24). You will be prompted for a reboot as we are replacing drivers with this install. Windows XP SP2 is not supported, only XP SP3 and up. Vista SP1 + and Windows 7 are also supported.

The primary changes in 1.0.25 are:

  • Fixed an installer issue where some driver failures were occurring on non-native English OS installs.
  • Fixed an 'Offline Mode' issue related to DNS under certain platforms.
  • Increased efficacy of the ETHOS engine and reduced it's memory footprint.
  • Fixed an issue with the local system cache which causes some look-ups to fail.


The Immunet Protect Beta 1.0.25 32 bit Updater is:Here
The Immunet Protect Beta 1.0.25 64 bit Updater is:Here

Our intention is for this to be our last update for the product until our April release.

Thursday
Jan282010

Updaters are now available to migrate to 1.0.24

All,

The updater files for migration to 1.0.24 are now posted. The updaters will install the new product, uninstall old product if you have it and then load your new drivers. Migration can be done from any Immunet build from 1.0.14 up to current (1.0.24). You will be prompted for a reboot as we are replacing drivers with this install. Windows XP SP2 is not supported, only XP SP3 and up. Vista SP1 + and Windows 7 are also supported.

The Immunet Protect Beta 1.0.24 32 bit Updater is: Here
The Immunet Protect Beta 1.0.24 64 bit Updater is: Here

Next week or the week after we will be shipping 1.0.25 which is purely a bug fix release. We will also ship updaters for this coming build.