|
Bulletins: ..... 
SPECIAL NOTICE TO HELP COMMUNITY AND PC OWNER/USERS
Conficker type threats change Community Help forever April 11, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/04/11/conficker-type-threats-change-community-help-forever/ Conficker type threats change Community Help forever To all our Community Help brothers and sisters, to understand this you ARE going to have read any typical payload delivered by these and specifically referring to the Windows Updates, System Restore, and Safe Mode of Windows features inboard. These are the traditional well proven areas of use in Community and commercial Professional and Expert help for malware blocking, removal, and discovery. These are destroyed and/or booby trapped in these specific type botnets. As a good source to understanding this visit my Personal Website written up page on this at our net and org domains HERE: Resume / Amatuer PC Security Forensics ((( FORENSICS - BUILD ))) AMATUER PC SECURITY FORENSICS TITLE: “Pseudo 14 Teredo Trojan Botnet Attack” http://www.bluecollarpc.org/_mgxroot/page_10751.html AND Amatuer Forensics Resume ((( FORENSICS - BUILD ))) AMATUER PC SECURITY FORENSICS TITLE: “Pseudo 14 Teredo Trojan Botnet Attack” http://www.bluecollarpc.net/forensics.html SECURITY HORIZON …… These abilities frequenting may became in part or full in any variants as a standard payload. Conficker Worm Botnet is a prime example as a close cousin here. Obviously these new times is these new deadly criminal botnets have changed Malware Removal Help….. No longer in caution or common sense can Community…. # Giving Help Instructions for Malware Removals to reboot into diagnostics Safe Mode for removals can not safely be advised. If Safe Mode is not blocked, it may intentionally give access but is booby trapped to disallow regaining rebooting into Normal Mode. # Obviously Windows System Restore and Restore Points are rendered inoperable, deleted. # Windows Updates and Security Software websites are blocked. Windows Installer may well be rendered inoperable denying download / install abilities. # Windows Remote Invitations help may not be possible if client infected with keyloggers and crimeware culprits intercepting Password are entering first. May be inoperable. Also via encapsulated (or similar deceits) payloads may act as in the wild threats undetectable destroying both computer systems or engaging help in botnet via infection. # Mobile portable thumb drive (others) anti-malware may be needed to replace mentioned standard help avenues - and may need be prepared for Windows Installer repair. # More…..
What I discovered in a devastating catastrophic virtually successful Conficker type botnet attack is that actually the Windows Firewall (XP, and Vista has the upgraded one) was that one last little piece of defense beyond all that did in fact BLOCK reconnection and re-connectivity by the successful botnet installation. There are mysterious defenses in Microsoft Windows and they are the top programmers of the world - their system being Unix Certified (google it) . No one is going to find out all except perhaps in a reaction by the system in a severe case as this. Windows code is and has always been secret. A good part of it has been compromised when you see the millions of piracy copies available illegally. This is the “anti cracking” technologies area that Windows and most decent software have in them to prevent this. Quite obviously in other words, Windows anti cracking was obviously compromised a long time ago. What are you going to do…..well But my amendment is that I discovered Windows Firewall kind of acts like the Windows Data Execution Prevention - DEP. This is Windows and built in and on by default though some idiot may tell you to turn it off. In a nutshell DEP is about the last standing defense in an unprotected or compromised machine hit by specific viruses and worms that are designed specifically to actually destroy files and delete the entire Windows Operating System (worms). These are those threats not designed as like mass mailing spam worms or password stealing viruses and on an on. These are those that are created to quite intentionally destroy computers and computer equipment. There is a difference. I found therein that the Windows Firewall acts like DEP in a totally compromised PC that I personally just recently suffered. From experience I saw this right in front of my face in action. So my security advice is to disregard talk just here that it is strongly not recommended to have two firewalls running as they can conflict. Generally that means like at the Airports now getting “shook down” and with 2 firewalls everything is like being put through that twice and can hang up and can cause freezing up even of the system or even a crash and reboot. THIS has been extremely rare if ever through the years since XP Firewall was released as even myself have tried it on and with different other firewalls like older Norton Personal Firewall, McAfee Personal Firewall, Sygate Personal Firewall, Trend Micro Suite Personal Firewall, and others I may have forgotten …. and point…. ever a conflict ? NO never actually. Said all that to say this that the Windows Firewall (XP, Vista) is actually part of the Windows Operating System just like Internet Explorer and Outlook Express (XP) and Windows Mail (Vista) are. That being said - there IS a SECRET here with the further abilities of Windows Firewall (and crimeware will not find out) as such being an incorporated actual part of the Windows OS (operating system) as best described as acting like DEP techno and has indeed DENIED a crimeware botnet unknown from establishing a hijacked spoofed broadband connection illegally. I indeed have this first hand experience and was in front of me and happened in approximately 6 to 7 seconds after the complete devastation and destruction by the included worms and wiping of DNS and browser informations. My entire Registry was exported and Microsoft sent in the Dr.Watson Debugger which failed. Mine on my PC was intentionally disabled after years of use as one “reputable” software company that misused it to corrupt other software. I reestablished connectivity after rebuilding System Restore and then restoring Network Integrity. My bottom line is leave Windows Firewall ON ALL THE TIME !!! This is why. Disregard ALL else. Me as a “source”…. the bluecollarpc.net domain has been accepted kind of as the poor man’s CastleCops. SOURCE Data Execution Prevention: frequently asked questions (Applies to all editions of Windows Vista) http://windowshelp.microsoft.com/Windows/en-US/help/186de3d0-01af-4d4c-981d-674637d2f4bf1033.mspx Microsoft: Data Execution Prevention (DEP) feature in Windows XP Service A detailed description of the Data Execution Prevention (DEP … Describes the Data Execution Prevention (DEP) feature in Windows XP Service In Microsoft Windows XP Service Pack 2 (SP2) and Microsoft Windows XP Tablet http://support.microsoft.com/kb/875352 gerald philly pa usa webmaster www.BlueCollarPC.Net BCPCGroup ~ The BlueCollarPC.Net Website Security Group —————————————————————————————— MEMBERS AREA: http://www.bluecollarpc.net/joingroup.html Mail domain bluecollarpc.net Live List Owner: bcpcgroup-listowners@bluecollarpc.net Service List Owner: bcpcgroup-owner@bluecollarpc.net Post to Group (Members Only): bcpcgroup@bluecollarpc.net Help address bcpcgroup-help@bluecollarpc.net Subscription address: bcpcgroup-subscribe@bluecollarpc.net Unsubscription address: bcpcgroup-unsubscribe@bluecollarpc.net #Sender Policy Framework (SPF, http://spf.pobox.com) Protected #ALL Posts Moderated and List Protected with Antivirus Service. *Guard archive (message digests). Archive access requests from unrecognized SENDERs will be rejected. *Subscription requires confirmation by reply to a message sent to the subscription address. *Unsubscribe requires confirmation by a reply to a message sent to the subscription address. #####BlueCollarPC.Net Memberships: ##### BlueCollarPC.Net Website Help Group http://www.bluecollarpc.net/joingroup.html BlueCollarPC.Net Portal Forums http://bluecollarpc.net/smf/index.php http://bcpcnet-com-portal.forumotion.net/forum.htm BlueCollarPC Yahoo Group http://tech.groups.yahoo.com/group/BlueCollarPC/ BlueCollarPC.Net WebLog http://bluecollarpc.net/wordpress/ Spy-Lerts Mail Lists http://www.bluecollarpc.net/spy-lerts.html Subscribe: spy-lerts-subscribe@bluecollarpc.net RSS: http://groups.google.com/group/spylerts/feed/rss_v2_0_msgs.xml?num=50 RSS: http://rss.groups.yahoo.com/group/Spy-Lerts/rss Dial Up Friendly http://www.bluecollarpc.org/
Tags: best practices, botnet, Community, crimeware, malware removal, Restore Points, safe mode, safe practices, security software, system restore, worm Posted in BCPCNet WebLog
FOLLOW UPs... Resume: Amatuer Forensics Build “Pseudo 14 Teredo Trojan Botnet Attack” April 11, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/04/11/resume-amatuer-forensics-build-pseudo-14-teredo-trojan-botnet-attack/
Security tip for Vista Firewall, others, against Conficker threats (Symantec)….. April 8, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/04/08/security-tip-for-vista-firewall-others-against-conficker-threats-symantec/
Restoring false positive threat from Quarantine, Safe Mode dangers April 3, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/04/03/restoring-false-positive-threat-from-quarantine-safe-mode-dangers/
Conficker Worm Targets Microsoft Windows Systems - Overblown? March 30, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/03/30/conficker-worm-targets-microsoft-windows-systems-overblown/
BCPCNet-Modcasts: “Malware Botnet Cartel” by BlueCollarPC.Net February 12, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/02/12/bcpcnet-modcasts-malware-botnet-cartel-by-bluecollarpcnet/
Death Of A Sails Man: Pseudo 14 Teredo Trojan Botnet Attack January 28, 2009 by bluecollarpc http://bluecollarpc.wordpress.com/2009/01/28/death-of-a-sails-man-pseudo-14-teredo-trojan-botnet-attack/ I guess a good name for this one is “Death Of A Sails man” ….. in referring to all the fun years on my Windows XP Home Edition Personal Computer. Sailing, surfing - you get it.
------------------------
IMPORTANT NOTICE TO ALL VISITORS..... JUNE 02/03 2008:
BlueCollarPC Domain Defaced, Promptly Removed… June 3, 2008 by bluecollarpc http://bluecollarpc.wordpress.com/2008/06/03/bluecollarpc-domain-defaced-promptly-removed/ FOLLOWING HACK OCCURRED AND IS REMOVED JUNE 03 2008…… SOURCE: BlueCollarPC.Net Incident Reports: http://www.bluecollarpc.net/reports.html
News: BlueCollarPC.Net passes 4,000,000 Website Hits ! (Four Million) .... Blue Collar PC Dot Net Passes One Million Hits Mark! (Includes our sub-domain PDAMobileCafe) http://bluecollarpc.net/webalizer/index.html http://pdamobilecafe.bluecollarpc.net/modlogan/index.html
NEW: For our WEBSITE GROUP (bcpcgroup) - the Sender Policy Framework (SPF) technology had been added for all email from any of the primary domain BlueCollarPC.Net and sub domains website email addresses. SEE: SPF - http://spf.pobox.com/
BlueCollarPC.Net WebLog Launched Fall, 2007: http://bluecollarpc.wordpress.com/ (New/Secured Jan 2008) (Paste this feed into favorite RSS/XML Readers): or click: http://bluecollarpc.wordpress.com/feed/
Cybercrime Treaty Gains Momentum... Article: http://www.networkworld.com/news/2008/040108-cybercrime-treaty-gains-more-interest.html?fsrc=rss-security Council Of Europe: http://www.conventions.coe.int/Treaty/Commun/ChercheSig.asp?NT=185&CM=8&DF=&CL=ENG
PLAY))) Malware Botnet Cartel (BCPCNet-Modcasts) http://www.bluecollarpc.net/downloads/DestroyBotnetCartel.wma COMMENTS: (bluecollarpc) As concise as possible, this is a very, very great news story. Personally as an Advanced User average consumer on PC - I launched this personal community website for malware removal and computing safety ongoing to best save a lot of aggravation and time for the newer community members of the world web, as we all have gone through with the advent of spyware from early adware days (lost innocense). Actually with 4 million (hits) visitors in just 2 years and various groups and forums I have been to - it is almost too easy to conclude that malware and the removal and protection against it is practically too much of a learning curve for a major percentage of home and even office computer users, and I mean that includes the most simple basic protection of antivirus softwares. In 2007, the best of the best (including Serf) estimated 7 to 11 percent of world computers were hijacked into malware botnets (zombie networks / slang). In year 2008 now, the estimate has dramatically increased to 1 out of 4 (yes 25 percent) are hijacked by malware botnet crimewares including the infections (virus/worm) and infestations (spyware/trojans/rootkits). Looking at that - yes real numbers have almost doubled in one year ! (Finally peaked ?). This is an impossible subject to cover in one paragraph, but... to roughly sum up - I concluded over a year ago with personal experience and others that it will take a concerted World Government empowered legally to smash what I call the "Malware Botnet Cartel". I think even the newbie immediately perceives the internet does not exist without internet commerce, and that is what is in danger beyond all the horrifying tragedies of individual incidents of IDTheft directly attributed to cyber crime and crimewares employed (not even mentioning businesses hacked) - and these are in part and wholly being swallowed up by the 'botmasters' (or bot herders) who are engaging "Bot Lord" Wars like an American Mafia movie in today's terms of Gang Wars - the end of cyber crime itself. This news story is perhaps the heart of this and perhaps the real and actual light at the end of the tunnel. There comes the point when the various Governments are going to have to be trusted to "purge the system" of all malwares and rouge computers of criminals with wholesale arrests of the cyber criminals. Laws will need to be temporarily suspended to accomplish this or, otherwise, it will take more and more years of legislation with all the arguements to get it passed at the expense of all the not-so- advanced users. Case in point, USA Better Business Bureau places crimeware IDTheft in the USA alone at 45 Billion dollars for just year 2007 ! This "Cyber Crime Treaty" may actually be that 'silver bullet' the security industry and users have longed for blindly even. PLAY))) Malware Botnet Cartel (BCPCNet-Modcasts) http://www.bluecollarpc.net/downloads/DestroyBotnetCartel.wma --------* Jan/Feb 2006: The RASAutodial regsitry items by adware and spyware are discovered by yours truly. You will not find removal of these items in any anti-spyware software in the industry, I am the first to discover them. Much more at our Spyware Removal Center page here at the website. Items appear at: HKEY_CURRENT_USER\Software\Microsoft\RASAutodial\Addresses\ (spyware name) Click Spyware Removal Center page here at the website for full details and Computer Help Center page for Registry orientation links. -------* LEGAL REASONS TO HAVE PROTECTION IN PLACE The Legal Risks of Computer Pests and Hacker Tools Jiffy Lube International, 4 CCH Computer Cases para. 46845 (US Dist. Ct. Md. 1993), a corporate telecommunications customer, Jiffy Lube International, ... http://research.pestpatrol.com/KnowledgeBase/Whitepapers/LiabilityofPests.asp The Legal Risks of Computer Pests and Hacker Tools http://www.pestpatrol.com/Whitepapers/LiabilityofPests.asp
FBI: Over 1 Million Potential Victims of Botnet Cyber Crime ..... Press Release For Immediate Release June 13, 2007 http://www.fbi.gov/pressrel/pressrel07/botnet061307.htm Washington D.C. FBI National Press Office
Identity Theft Remains Threat For Those Online http://www.tylerpaper.com/article/20080413/BUSINESS0503/804110354 ..8.1 million Americans last year... The average amount lost per individual as a result of ID theft last year was about $5,500, for a total of $45 billion. Despite the decline in reported ID theft, the Better Business Bureau warns that thieves and hackers still lurk online and is offering advice consumers can use to protect their personal and financial information.
Study: $3.2 Billion Lost to Phishing in 2007 http://blog.washingtonpost.com/securityfix/2007/12/study_32_billion_lost_to_phish_1.html U.S. consumers were scammed out of roughly $3.2 billion over the past year from phishing scams, a significant increase over last year, according to a survey released this week.... |