Security Manager's Journal: Not even security managers immune to FakeAV infection
This insidious malware is hard to root out, which is why it's making a lot of money for its distributors
Computerworld - Can you believe it? As I sat down this morning to write this column, I got hit by a drive-by download of FakeAV.
My computer is infected with pop-up warnings and file scans telling me I have security problems, and Internet Explorer has been hijacked to keep sending me to a website where I can "purchase the software." Pop-ups are coming from my taskbar, showing up in the middle of the screen, and rifling through my files with a fake scan. My computer is being held for ransom.
How did this happen? And what am I going to do about it? I mean really, as a security manager you'd think I would be immune to this kind of problem. My antivirus software is up to date and actively scanning, and my system is fully patched. That's more than most people are doing. Fortunately, I also have current backups (more on that in a minute).
I wrote that a week ago. As it turned out, I had to do a lot more work to get rid of this infection than I anticipated.
I started with some research on what FakeAV is all about. I've been hearing a lot about it through word-of-mouth, and now I'm getting firsthand experience. According to Sophos, FakeAV is a rapidly growing threat on the Internet, mainly because it's profitable to the people who wrote and distributed it. Evidently, a lot of people are being tricked into sending money to these criminals to get back control of their computers. I hate to think how many people are being fooled by this malware into thinking it's a legitimate security scan. It would be a lot easier to just send them the money to get back control of my system. But I'm not going to let these guys win.
This is clearly a very advanced program. It looks exactly like the real Windows Security Center. It appears to be professionally programmed, with none of the crashes or bugs prevalent among more pedestrian malware.
Sophos says there are so many variants being released constantly that it can be difficult to detect using traditional signature-based antivirus, which is what I have. Even with the latest updates, the newest variants can get through. Some variants are also employing polymorphic code, which changes itself so frequently that the MD5 hashes used by antivirus programs cannot be effective. Well, that explains how I got it despite having a good, up-to-date antivirus product.
Earlier versions of FakeAV required the user to say "Yes" to something, such as a fake video codec installation to play a video or a fake Flash player update. Some even use the old-fashioned, tried-and-true technique of attaching the installer to a spam email notifying users of a password reset, package delivery or IRS refund, which I see a lot of at the office. But none of these is how I got infected. I was searching on Google. Search terms are being "poisoned" on Google. When an unsuspecting victim clicks on what seems to be a legitimate page, he is brought instead to a compromised website where the malware is lurking in an image or JavaScript code. When I'm searching on Google, I use CTRL-click to open interesting results in a new tab in Internet Explorer Version 8 (fully patched). Last week, when I did this, one of the pages I opened must have contained the JavaScript or image version. It opened in a new tab, where I left it for later viewing, and it infected my system. Pop-ups appeared, all my browser sessions closed, and my antivirus programs were disabled. This is what's known as a "drive-by download."
More by J.F. Rice
- Security Manager's Journal: Upgrading, and looking for the best we can afford
- Security Manager's Journal: Rights can be so wrong
- Security Manager's Journal: Reining in network accounts
- Security Manager's Journal: Getting up to date on expired access rights
- Security Manager's Journal: Ready to hire, but coming up empty
- Security Manager's Journal: Can an enterprise run its security with Microsoft's tools?
- Security Manager's Journal: New ransomware attack hurts trustworthiness of Web
- Security Manager's Journal: A new look at vulnerability scanners
- Security Manager's Journal: Handling zero-days with zero staff
- Security Manager's Journal: Security training on the cheap
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
