Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

Monday, 24 June 2013

Remove File Encrypting Harasom Ransomware

Video tutorial to remove file encrypting ransom-ware  'department of justice' . There are other forms of ransom-ware such as MBO  which are all part of the Win32/Harasom.A Trojan family.

This infection will also scan your computer for files that end with the .ddrw ,.pptm ,.dotm ,.xltx ,.text ,.docm ,.djvu ,.potx ,.jpeg ,.pptx ,.sldm ,.xlsm ,.sldx ,.xlsb ,.ppam ,.xlsx ,.ppsm ,.ppsx ,.docx ,.odp ,.eml ,.ods ,.dot ,.php ,.xla ,.pas ,.gif ,.mpg ,.ppt ,.bkf ,.sda ,.mdf ,.ico ,.dwg ,.mbx ,.sfx ,.mdb ,.zip ,.xlt extensions and then encrypt them. 


When the ransomware encrypts a file it will rename it as a HTML file and then embed the encrypted
file inside of it. If you then attempt to launch any of these encrypted files, you will be taken to a web page, which is currently at htxp://mdlblock.in, that prompts you to pay the ransom in the form of a Money Store, Vanilla Reload, or Reload it voucher.



What you will need.
You will need  to download Hitman Pro, Malwarebytes and Emsisoft Harasom decrypt tool, and in worse case scenario if you can't boot into OS you may have to download and make a rescue disk to boot up off of. You can download either Kaspersky Rescue disk  or AVG Rescue disk. These links can be found on my blog  under Free Software Tools.

Follow the video tutorial below:
 Credits Brian : http://briteccomputers.co.uk/

Note: 
The XPS viewer folder mentioned is situated in the Appdata folder. If you cannot find the Appdata folder  this is probably because the application data folder is hidden by default. You need to tell your OS so show hidden files and folders.
To do this open Windows Explorer  (windows key + E) click on Tools at top then Folder Options. Then click on the 'View' tab and check the tick box "Show hidden files and folder"


Tuesday, 11 June 2013

Malware... what is my best form of protection?

The computer security industry is swarming with hundreds of applications claiming to keep your PC free of spyware. Some of them are great, some are just decent, and some are a plain waste of money, or might harm your PC themselves!

Malware

Freedom from spyware and adware,malware Trojans can come free, you just have to know the right tools to do so. I recommend these two anti spyware programs, they are proven and tested to be the best of the best, and they won't even cost you a penny. Become an educated computer user, and keep your PC free from spyware infections with these two programs.



Super-Anti-Spyware (SaS)
Super-Anti-Spyware has quickly shown itself to be one of the best free anti adware programs available. It is known to catch many infections that other programs miss, scans fairly quickly, and is fairly simple to use.





 
MalwareBytes Anti-Malware (Mbam)
MalwareBytes is also is great for catching the elusive spyware infections. However, MalwareBytes is not as good as cleaning up smaller things such as tracking cookies. I advise people who use MalwareBytes to use it in conjunction with Super anti-Spyware.





What SaS may miss Mbam will find or vice-visa so I keep both programs on my PCs and update them and run them fortnightly. Note run them one after another not at the same time.

Links to SaS and Mbam  can be found in my free software tools section of my blog.

Running the malware programs with Ccleaner  by Piriform and my antivirus keeps my PC's  100% healthy.

Thursday, 6 June 2013

Infamous Zeus Malware has once again resurfaced

The infamous Zeus malware (Trojan Horse)has once again resurfaced, but this time it’s using Facebook to further its crime spree. First detected in 2007, Zeus has infected millions of computers over the past six years. Despite the efforts of numerous security firms to combat the Trojan horse, it has only gotten stronger with age.

 
Following the initial infection, the virus lays dormant until an online banking site is opened. It then uses keyloggers to steal the unsuspecting victim’s usernames and passwords. Sometimes the Zeus malware goes even further - it replicates the bank's website, using a fake interface to obtain social security numbers, credit card digits, and other sensitive information.

It is for this reason that Zeus is so effective. Even when your bank account is fully drained, the malware continues to search for any tidbits of data that can be sold on the black market. And unlike most malicious software, there are little to no warning signs - the computer will continue to operate normally, as an outright crash was never the intent.

Fake or Bogus Facebook pages are now being used to spread the malware.The big concern is how little Facebook is doing to combat the threat. The social media giant, Facebook suggested that users should take matters into their own hands by signing up for scanners that can identify and remove the Trojan.

Below:  how the Zeus malware works

We recommend that you use the tools listed below to remove this malware:
  • Rkill ( preferably run this in safemode - this will stop any unwanted processes and allow the removal tools to run effectively )
  • Malwarebytes ( malware removal tool - removes infection )
  • Super anti Spyware ( malware removal tool- i would use this after Malwarebytes to make sure that all infections have been removed ).
Links to these programs can be found here: Free Software & Tools