Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Monday, November 25, 2013

Cryptolocker Virus Warning!



Recently there has been a dangerous new virus going around which poses significant risk to both personal and business computers alike. Cryptolocker, as it is commonly known, is a new virus variant which seeks to encrypt all useful files on a computer and then hold the user for ransom to unlock them. This virus preys upon users who click or preview an attachment in an email; typically disguised as a bill of lading from a shipping company. Once the attachment is opened or previewed, it will utilized a vulnerability in older versions of java to execute and encrypt not only the entire contents of the offending computer, but all files over a network which that computer has access to. The virus is difficult to detect and is sophisticated enough to evade capture by even modern anti-virus solutions. Worse yet, if you are infected, removal of the virus removes the encryption key needed to unlock your files, rendering all of your data completely useless.

Once a machine is infected, anything with the following file extensions will be encrypted (you will notice these are just about all useful files):
*.odt, *.ods, *.odp, *.odm, *.odc, *.odb, *.doc, *.docx, *.docm, *.wps, *.xls, *.xlsx, *.xlsm, *.xlsb, *.xlk, *.ppt, *.pptx, *.pptm, *.mdb, *.accdb, *.pst, *.dwg, *.dxf, *.dxg, *.wpd, *.rtf, *.wb2, *.mdf, *.dbf, *.psd, *.pdd, *.eps, *.ai, *.indd, *.cdr, ????????.jpg, ????????.jpe, img_*.jpg, *.dng, *.3fr, *.arw, *.srf, *.sr2, *.bay, *.crw, *.cr2, *.dcr, *.kdc, *.erf, *.mef, *.mrw, *.nef, *.nrw, *.orf, *.raf, *.raw, *.rwl, *.rw2, *.r3d, *.ptx, *.pef, *.srw, *.x3f, *.der, *.cer, *.crt, *.pem, *.pfx, *.p12, *.p7b, *.p7c

Recovery from such an attack is limited to 2 options. Pay the ransom (a dangerous idea by basically dealing with criminals) or restore from a backup. This emphasizes the importance of maintaining incremental backups on a regular basis. Even more insidious, unless the backups are themselves encrypted (a common feature available in business class backup solutions) or the backup system is separated from view of users on the network, then the backups themselves risk being encrypted.

Prevention, as most risks in the virus landscape, involves layers of preventative measures. The most important is awareness and common sense when handling email attachments. Only open attachments which you are clearly expecting to receive from an individual, and even better, contact the individual who sent the attachment to verify they sent one. Also, turn off any preview options within Outlook to prevent accidental selection of emails from automatically opening bad attachments. Organizations should review their business critical data, and ensure that access is limited to key individuals, rather than globally through group policy. The last thing you want is for a weekend book keeper to take down all of your data because they had access to more than just the accounting network share. Users should be compartmentalized to access only what is necessary to perform their job function. Finally… backup, backup, backup, backup. It cannot be stressed enough that maintaining good, encrypted, incremental backups on a regular basis is not just a good idea, but critical for any business.


Or contact your account manager for network assessment.


Chris Bodenhamer
Sierra Computer Group Dispatch

Tuesday, December 13, 2011

Zero Access Infection


Recently I encountered a threat that infected a client's computer.    The Client noticed that their Antivirus Program intervened and requested a reboot of the computer to finish the remediation.   Upon Rebooting the user was unable to log on.   Worse yet she had no mouse or keyboard.    Fearing the worst the user pushed the power button to shut down the computer; which responded normally and gracefully shutdown the computer.    Next she tried to get into Safe Mode by pressing f8.   Windows booted into safe mode but again no keyboard or mouse inputs it seemed.

I was able to verify the customers complaint.   Only I noted that system was still alive and I was able to PING it, which to me meant that it was still working.  I remotely accessed the machines registry and enabled remote access to the machine.    When attempting to connect remotely I discovered I did not have the local administrators account password.    After rebooting the computer with a bootable Password Recovery CD I recovered the four letter local administrator password in only 9 seconds.  

Using the recovered password I was able to remotely connect to the computer and was able to determine that the installed and updated Antivirus Software had clobbered the Windows XP PS/2 Driver (i8042prt.sys) used for both PS/2 keyboard and PS/2 Mouse Input.  

I booted from the Windows XP CD and using the repair console manually replaced the i8042prt.sys driver, however I was still unable to have the system use a PS/2 Keyboard or Mouse.    I found an unused USB Keyboard and began to work on the system running some additional virus removal tools.    One of the tools had identified an infection known as Zero Access.    After the tool completed the removal steps the system still did not work with the PS/2 Keyboard and Mouse but did work with the USB Keyboard.

I decided to run a repair install of windows to correct the issue.   The repair install soon reached the point in the setup process where it booted from the hard drive, and disturbingly again I had no PS/2 Mouse and no PS/2 keyboard access.    After a little research  and on a hunch, I aborted the repair install (knowing that it would resume upon reboot) and tried a decidedly different tactic.  

Most of the variants of the Zero Access Rootkit will infect the Master Boot Record of the hard drive which causes the machine to load part of the rootkit while the machine is still vulnerable and unprotected from viruses.    I booted the Windows Recovery Console from the CD and had windows replace the MBR and Boot Sector.

Next I crossed my fingers let windows reboot.  Next Windows setup continued the repair install and voila I now had access via the PS/2 Keyboard and PS/2 Mouse again and the Machine was fully remediated.

The Client was upset that the anti-virus program had disabled their computer, when they should have realized this was a fortunate circuit breaker.  Their real concern should have been that their system and all their activity was almost exposed to some unknown source.    Without the anti-virus program disabling this computer, every single input to the computer would be collected and redirected...and probably not for the forces of good.

Remain vigilant.



Dave Hendricks
System Engineer
Sierra Computer Group

Tuesday, November 30, 2010

One VERY Impressive Piece of Malware - Stuxnet

You may have heard about Stuxnet, but like me didn't get into the details until now.   If so, you'll be impressed.  



It's hard to believe its development will stay secret forever, so someone will eventually take credit and maybe even write a book.  Whatever the case, and whom ever created and managed it, Stuxnet was one amazing malware campaign with it's zero-day exploits, subtle damage approach and peer to peer upgrade channel.

Don't worry if you're a technophobe, the article below reads like a Hollywood script and brings to mind how Churchill subtlety used Ultra (or didn't use it) to further the allied objectives.  The story even has a climax, with discovery day cleanup already prepared - very impressive.  Here's the link :



And the more technical Wiki version :

Wiki on Stuxnet

It makes one wonder what unknown code may be running on other computers...

Be prepared.

Rod Coleman, General Manager - Sierra Computer Group