Cisco Learning Network Store Promotions Page
Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

11.22.2016

People don't understand how they get infected with malware

 
A new Kaspersky Lab report says a lot of us end up with viruses on our machines, but we just don't know how. But, in fact, we very much do. Here are the report's figures.
 
Almost half (42 percent) of internet users have either come across or have been targeted by malware online. A fifth of those (22 percent) have fallen victim to it, and almost a third (29 percent) have "no idea how it ended up on their device".
 
Just after that, the report says this: "The study found the highest number of infections happen when people visit suspicious websites (42 percent). Fake apps and software (22 percent) and USB sticks (20 percent) are also cited by one in five as the source of a malware infection they have experienced".
 
"E-mails and messages are also a common source of infection", the report continues, before adding this: "Trusted websites that have been hacked and the transition of malware from another infected device are also mentioned".
 
So it’s hardly that we don’t know how. But the fact remains -- malware is a widespread problem.
 
It is a pain in the neck, and causes its victims to lose money. A quarter (24 percent) say their devices slowed down, a fifth (22 percent) say they get unwanted pop-up advertising, and 13 percent get directed to "suspicious" websites. For seven percent the device stopped working. Some even had to pay for repairs, spending on average of $121 per incident.
 
"With a third of Internet users completely unaware of how they became infected, this can help to further spread the virus and put even more of our devices, details and finances in danger", comments Andrei Mochola, head of Consumer Business at Kaspersky Lab.
 
Published under license from ITProPortal.com, a Future plc Publication. All rights reserved.
 
Photo Credit: fatmawati achmad zaenuri/Shutterstock
  
~ Sead Fadilpašić

11.13.2016

Furious Kaspersky is 'disappointed and dismayed' with Microsoft

 
Claims of anti-competitive behavior are incredibly common in the world of tech; Google finds itself on the defensive on just about a weekly basis. Microsoft is certainly no stranger to accusations of anti-competitiveness, most notably for bundling Internet Explorer in older versions of Windows. But now it's Microsoft's approach to security that's in the firing line.
 
Eugene Kaspersky (yes, that one: the Russian security expert and CEO of Kaspersky Lab) has fired a vitriolic tirade at Microsoft in which he complains about how Windows Defender works in Windows 10. Windows 10 has been lambasted for many reasons since it launched, and things are not really improving as we near the launch of Windows 10 Creators Update. Kaspersky is so furious about the way in which Defender operates that he has written a lengthy and bitter blog post entitled: "That's It. I've Had Enough!"
 
It would be easy to dismiss Kaspersky's epic 2,000-word diatribe as a 'rant', but it is much more than that. The blog post may be angry in its tone, but it is also level-headed and well-argued. Kaspersky accuses Microsoft of creating "a challenge for all computer users and the entire ecosystem of independent developers for Windows".
 
He points to complaints from Windows users that Windows 10 has been caught changing settings in the background, covertly switching default settings from third-party apps to Microsoft's own products. With Kaspersky's (both the name and his company) vested interest in security, it's little wonder that the main thrust of his complaint centers around Windows 10's Defender security product:
When you upgrade to Windows 10, Microsoft automatically and without any warning deactivates all 'incompatible' security software and in its place installs... you guessed it -- its own Defender antivirus. But what did it expect when independent developers were given all of one week before the release of the new version of the OS to make their software compatible? Even if software did manage to be compatible according to the initial check before the upgrade, weird things tended to happen and Defender would still take over.
Kaspersky is unhappy with the way Microsoft tries to encourage a switch to Defender even if it deems that compatible security software is installed. He points to a scary-looking window that appears and tries to entice users into re-enabling Defender -- which, if done, incidentally, means the third-party security tool is disabled. It's activity like this that leaves Kaspersky "both very disappointed and dismayed".Claims of anti-competitive behavior are incredibly common in the world of tech; Google finds itself on the defensive on just about a weekly basis. Microsoft is certainly no stranger to accusations of anti-competitiveness, most notably for bundling Internet Explorer in older versions of Windows. But now it's Microsoft's approach to security that's in the firing line.
 
He goes on to complain about how developers have been restricted by Microsoft in how they can advertise an expired license to their users. Should your anti-virus license run out, developers can only warn you of this for a three-day period -- and if you don’t renew the license in this time, Windows Defender is automatically enabled for you. It could be argued that this is a case of Microsoft trying to keep computers secure, but it is also very easy to see it as being anti-competitive behavior. This is particularly true when you consider something else that Kaspersky points out:
Microsoft has introduced a limit on the number of antiviruses you can have on a PC: one (or two -- if one of them is Defender; see below). At first glance this looks like sense: all for a more comfortable user experience. But the devil's in the details...
Let's say you've an independent AV. You intentionally -- or not (e.g., with bundled software) -- install a trial version of a different AV, but forget to delete it or purchase a license for it. When the trial period is up, Windows quietly turns off both AVs, and -- you guessed it -- turns on Defender! So, it's out with two non-Microsoft products, and in with one Microsoft product, in no way whatsoever for a more comfortable -- or safer -- user experience.
Further ire is raised by what can happen next:
 
Kaspersky says it is only possible to come to one conclusion based on all of this evidence: "Microsoft is gradually squeezing independent developers out of the Windows ecosystem if it has its own application for this or that purpose". He has gone as far as complaining about Microsoft in both Russia and Europe:
We think that Microsoft has been using its dominating position in the market of operating systems to create competitive advantages for its own product. The company is foisting its Defender on the user, which isn't beneficial from the point of view of protection of a computer against cyberattacks. The company is also creating obstacles for companies to access the market, and infringes upon the interests of independent developers of security products.
Therefore:
We've taken the decision to address official bodies in various countries (including the EU and Russia) with a request to oblige Microsoft to cease its violation of anti-competition legislation and to remove the consequences of that violation.
Specifically:
To oblige Microsoft (i) to provide new versions and updates of Windows to independent developers in good time so they can maintain compatibility of their software to Windows; (ii) explicitly inform the user of the presence of incompatible software before upgrading Windows and recommend the user to install a compatible version of the software after the upgrade; (iii) always explicitly ask the user for his/her approval to enable Windows Defender.
Microsoft will almost certainly just dismiss these claims, but it will be interesting to see exactly how the company decides to respond.
 
Photo credit: tanuha2001 / Shutterstock
 
~ Mark Wilson

8.01.2016

Kaspersky 2017 brings VPN, better adware blocking and removal

 
Kaspersky Labs has released Kaspersky Anti-Virus 2017, Kaspersky Internet Security 2017 and Kaspersky Total Security 2017 in the US and Canada. New features include Secure Connection, a virtual private network which automatically kicks in to protect you when using wifi hotspots, web banking sites and more.
 
An Installation Assistance tool looks out for adware and other pests that get silently installed with some free software, and the Software Cleaner helps you decide what to remove.
 
An extended Anti-Banner system now uses a "powerful subscription catalog held by a third-party", making it significantly better at blocking popups, web ads and more.
 
The suites now include Kaspersky’s Software Updater. This checks for updates to common applications (Adobe Reader, Flash, Java, Chrome, Firefox, more), and can optionally install them without you having to see or do anything at all.
 
Kaspersky has "enriched the design and usability of the main screens for all the new line products", apparently.
 
The product is now fully compatible with Windows 10, but Kaspersky hasn’t forgotten about older systems -- 2017 still works with Windows XP.
 
Trials of Kaspersky Anti-Virus 2017, Kaspersky Internet Security 2017 and Kaspersky Total Security 2017 are available now.
 
~ Mike Williams

4.27.2016

Remove CryptXXX ransomware with Kaspersky's free decryption tool

 
Security firm Kaspersky has released a tool that can be used to decrypt files on computers hit by the CryptXXX ransomware. Rather than paying the ransom demanded to regain access to files, victims are now able to turn to the free RannohDecryptor utility.
 
CryptXXX had been identified by ProofPoint earlier in the month and described as being closely linked to the Reveton ransomware operation and Angler/Bedep. The ransom of $500 is considered to be quite high, but Kaspersky's free decryption tool means that files can be retrieved without having to part with a cent.
 
CryptXXX uses RSA4096, but Kaspersky's John Snow says that it is "very curious and greedy: not only does it encrypt the files, but it also steals bitcoins kept on victims’ hard drives and copies other data, which can be useful for cybercriminals". The ransomware encrypts not only local files, but those on attached storage devices, and there is a delay between infection and encryption to make detection trickier.
 
Despite the use of RSA4096, CryptXXX is "not that difficult to crack". Kaspersky had previously created the RannohDecryptor tool to decrypt files on computer hit by Rannoh ransomware. Now the company has updated the tool so it can also handle CryptXXX files.
 
Kaspersky explains:
If CryptXXX ransomware has found its way into your system, not everything is lost. To recover your files we will need the original (not encrypted) version of at least one file, which suffered from CryptXXX. If you have more files like this backed up, this will work. Then you need to do the following:
  1. Download the tool and launch it.
  2. Open Settings and choose drive types (removable, network or hard drive) for scanning. Don’t check the "Delete crypted files after decryption" option until you are 100% that decrypted files open properly.
  3. Click the "Start scan" link and choose where the encrypted .crypt file lies (that file, for which you have an unencrypted copy as well).
  4. Then the tool will ask for the original file.
  5. After that RannohDecryptor starts searching for all other files with ".crypt" extension and tries to decrypt all files, which weigh less than your original. The bigger file you’ve feed to the utility -- the more files would be decrypted.
If you've been struck by a CryptXXX infection, grab yourself a copy of the decryption tool from Kaspersky.
 
Photo credit: Bacho / Shutterstock
 
~ Mark Wilson

6.11.2015

Security firm Kaspersky Lab hacked by a 'nation state'

 
Security firms are supposed to keep us safe from threats like malware and hacker attacks, but occasionally they fall foul of the bad guys too. A year ago Avast was hacked, and some 400,000 user details were stolen. Two years ago, AVG and Avira had their websites taken over by pro-Palestinian hackers.
 
The latest security firm to be hacked is Russian anti-virus software maker Kaspersky Lab.
 
In a post on the company's blog, Chairman and CEO Eugene Kaspersky says the attack on its own internal networks was "complex, stealthy, [and] it exploited several zero-day vulnerabilities". The firm is also very confident that there was a "nation state" behind it all.
 
Antivirus firms like to name threats, and Kaspersky Lab has labeled this particular attack Duqu 2.0, after the Duqu Trojan which was used in attacks on Iran, India, France and Ukraine back in 2011.
 
Kaspersky Lab believes the purpose of the hack was to steal the company’s secrets, and says the attack was "a generation ahead of anything we’d seen earlier -- it uses a number of tricks that make it really difficult to detect and neutralize. It looks like the people behind Duqu 2.0 were fully confident it would be impossible to have their clandestine activity exposed".
 
The firm views the hack as being mostly a good thing because despite its sophistication, Kaspersky Lab was able to detect it, and now has everything it needs to protect customers against future attacks. No products or services were compromised in the hack, and customers remain perfectly safe.
 
Duqu 2.0 wasn’t only used to spy on Kaspersky Lab but, according to the firm, also used to spy "on several prominent targets, including participants in the international negotiations on Iran’s nuclear program and in the 70th anniversary event of the liberation of Auschwitz".
 
If, as Kaspersky Lab believes, a nation state is behind the attack, there’s obviously one important unanswered question -- which one? The company isn’t saying. Whether it's because it doesn't know, or simply doesn't want to get involved in that kind of finger-pointing is a matter for debate. However, Eugene Kaspersky did have this to say:
Governments attacking IT security companies is simply outrageous. We’re supposed to be on the same side as responsible nations, sharing the common goal of a safe and secure cyberworld. We share our knowledge to fight cybercrime and help investigations become more effective. There are many things we do together to make this cyberworld a better place. But now we see some members of this 'community' paying no respect to laws, professional ethics or common sense.
People living in glass houses shouldn’t throw stones.
To me, it’s another clear signal we need globally-accepted rules of the game to curb digital espionage and prevent cyberwarfare. If various murky groups -- often government-linked -- treat the Internet as a Wild West with no rules and run amok with impunity, it will put the sustainable global progress of information technologies at serious risk. So I’m once again calling on all responsible governments to come together and agree on such rules, and to fight against cybercrime and malware, not sponsor and promote it.
Image Credit: lolloj/Shutterstock
 
~ Wayne Williams

2.05.2014

PassMark Software reveals best-performing 2014 security software



Photo Credit: Oxlock/Shutterstock
 
PassMark Software has released its 2014 Consumer Security Products Performance Benchmarks report, the results of in-depth testing on the speed and impact on your system of 16 leading security packages.
 
First place in the security suite test went to Norton Internet Security 2014 for its excellent scan times, fast launch, and minimal effect on other applications and PC tasks. Kaspersky and Bitdefender Internet Security 2014 were second and third, while products from Avast, G Data, McAfee, Panda and Trend Micro trailed behind.
 
Norton topped the antivirus test, too, although its minimal scan times helped push AVG AntiVirus into second place. Avast scored well in third, while G Data, Panda, Kaspersky, McAfee and Trend Micro weren’t so impressive.
 
The rankings need to be evaluated with some care, because although they’re based on the scores of 19 tests, these aren’t all of equal value. PassMark measures the installation time and size, for example, as well as the product’s memory use; these can be interesting figures, but as long as you’ve reasonably powerful hardware, they’re unlikely to make any noticeable difference.
 
Forget about these less crucial assessments, concentrate on others, and some very different results can emerge. If you look only at the two scan time tests, say, G Data AntiVirus 2014 comes out on top, completing one benchmark in half the time of Norton Antivirus.
 
It’s also worth noting that the test was run on Windows 7, and other versions of Windows may deliver significantly different results. AV-Test.org’s latest benchmarks also score Norton Internet Security 2014 high for Windows 7 performance, but rank it much lower on Windows 8.
 
Despite these issues, PassMark’s report is a useful document, which provides a great deal of useful performance information on this year’s top security products. Just be sure to browse the individual benchmark results, as well as the overall rankings.
 
It’s worth adding that the top performers within the report, namely Norton Internet Security 2014, Kaspersky Internet Security 2014 and Bitdefender Internet Security 2014, are all available, deeply discounted, from the Downloadcrew Software Store.
 
~ Mike Williams

6.19.2013

New Android malware should be wake-up call for security admins

Takeaway: Security firm Kaspersky reported on a new malware threat that it calls the most sophisticated it has seen in targeting Android phones

IT pros in the enterprise rely on a wide array of tools needed to keep users secure: firewalls, intrusion detection systems, centralized software updates, anti-malware definition updates, policy statements, and so on. But when it comes to mobile security, quite often many businesses do not hold the same strict policies as they do for desktops, despite the clear evidences that smartphones are now just as powerful as a full computer, and bad guys are out there targeting them.
 
Just last week, security firm Kaspersky published a report about the most complex Android malware they have found so far. In many ways, it mimics what a modern desktop worm would have to do to infect computers. The first surprising finding is how many unknown vulnerabilities that this single malware was exploiting. Typically, most worms and viruses are created to exploit a single security
hole. As soon as a Java or Flash exploit is found, for example, hackers go out and create code that can take advantage of it, and then try to get as many people as possible before a fix happens. But the serious desktop threats are those pieces of malware which are sophisticated enough to use many paths of entry, and complex enough to remain undetected via multiple means of stealth. This is what this particular malware is doing.

Backdoor intruder

Nicknamed Backdoor.AndroidOS.Obad.a, this malware used a hole in the code packing system to create an executable that should be found invalid, but still gets processed on an Android smartphone, by planting deliberate errors in the AndroidManifest file. Once there, it can get elevated to the Device Administrator status, but using a security hole in Android, it will not get listed in the apps listing, making it impossible to remove. And the complexity doesn’t stop there. The malware uses a lot of encryption to keep all of its variable names secret, and it will go out through a network connection, downloading a part of the Facebook home page, and use that as its encryption key, to ensure it is truly online and able to connect to its control servers.
 
Once it has set itself deep in your phone, it starts receiving commands from the command and control system to update itself, download more malware, and start sending expensive SMS messages to foreign numbers. All of this means that it was hard to find, hard to analyze, and could be modified on the fly to thwart attempts to remove it. In this particular case, right now the infection rate is still very low, with most victims being in Russia. Mobile antivirus software are also being modified to detect it. But the fact remains that this sort of complex malware was not seen before on mobile phones, only on desktops. It proves that smartphones have become a big enough target for even the most sophisticated criminals to go after them.

Be more aggressive on the mobile front

The problem with all of this is that according to a recent report, 63% of businesses do not manage corporate information on devices. With the latest BYOD trend, people are being allowed to bring their own devices, which may be compromised, into the office without any check or balance. 67% of respondents say that employees have personal devices at work that connect to their corporate networks, and 79% said they have had some type of mobile security incident in the past.
 
Fortunately, the lessons of the desktop have been learned by modern mobile platforms. All of the popular devices including iOS, Windows Phone, BlackBerry, and Android have a much higher security threshold from the get go. Apps are sandboxed against each other, the user does not run with administrator privilege by default, and a centralized store system means that apps can be killed remotely, and devices wiped. Still, what else can you do as an IT pro to make sure your employees’ devices are safe? First, make sure you have some kind of centralized management. You can use Microsoft ActiveSync to control what goes on these devices, and there are many popular third party tools like Citix’s XenMobile.
 
Using these tools, you can ensure encryption is used, you can control which apps your employees can download and use, and you can block rooted or jailbroken devices from infecting your network. You can also use one of the many anti-malware solutions available on the various app stores, and just recently Malwarebytes said they would be releasing an Android version of their popular software
by the end of the year. Overall, the security situation for mobile devices is much better than it is on the desktop, but that doesn’t mean you should leave yourself completely open to problems, and just as desktop malware evolved into more and more sophisticated threats, mobile malware is sure to go the same way.

 
~ Patrick Lambert 

1.15.2013

Bitdefender tops AV-TEST, Microsoft Security Essentials bottom feeds

Who offers the best antivirus protection? It’s not an easy question to answer, but independent testing labs AV-TEST and AV-Comparatives have just released their latest results and reports, and they make very interesting reading.

AV-TEST places Bitdefender Internet Security 2013 in first place, for instance, with 5/6 for usability,
5.5/6 for repair and an excellent 6/6 for protection. But F-Secure Internet Security 2013 and Trend Micro Titanium Maximum Security 2013 also rate 6/6 for protection, while Kaspersky Internet Security 2013 and Norton Internet Security 2013 rating well all round.

And while half a point here and there doesn’t mean much, the fact that Microsoft Security Essentials 4.1 rates a 1.5 for protection, when just about every other package scored 4/6 or higher, probably tells you that there really is a very major difference in quality.

One lab’s results don’t necessarily mean a great deal, of course. But AV-Comparatives has just released its own December report that looks quite similar: Bitdefender takes their “Product of the Year” award by a very narrow margin over Kaspersky, and F-Secure scoring well on proactive (heuristic/ behavioral) detection.

And while Microsoft did receive one award here for low positive detections (none whatsoever), the package otherwise scored poorly in regular detection tests. Let’s hope things pick up in 2013.

If you do want to switch -- right now -- to a higher-rated security package, though, keep in mind that we have some excellent deals on the Downloadcrew Store at the moment. Bitdefender Total Security 2013 is available for $29.95, for instance, a 63-percent discount; Kaspersky Internet Security 2013 can be yours for $24.95, 69 percent off the regular price; or, if you’re on a budget, Bitdefender Antivirus Plus 2013 is available for a mere $5.95, 85 percent off list.

~ Mike Williams