AutoRun For Malware
AutoRun For Malware : One out of everyeights attack come via a usb device(dari pendrive la maknanya)..
PRAGUE, Czech Republic, November 3, 2010 - AVAST Software, developer of the award-winning avast! antivirus program, is detecting a growing number of malware attacks targeting the AutoRun function in Windows and plug-in USB devices. Researchers found that, of the 700,000 recorded attacks on computers in the avast! CommunityIQ system during the last week in October, one out of every eight attacks – or 13.5% – came via USB devices.
The key attack point for malware is the ‘AutoRun’ feature in Microsoft Windows operating systems (OS). AutoRun alerts computer users when a new device such as a memory stick is connected and is designed to help them choose what application should run with the new files.
“AutoRun is a really useful tool, but it is also a way to spread more than two-thirds of current malware. The threat of USB-distributed malware is much more widespread than just the Stuxnet attacks on enterprise computers – which were also spread via infected memory sticks,” said Virus Lab analyst Jan Sirmer. “Cyber-criminals are taking advantage of people’s natural inclination to share with their friends and the growing memory capacity of USB devices. Put these two factors together and we have an interesting scenario.”
This feature is misused when a USB device infected by “INF:AutoRun-gen2 [Wrm]”, avast!’s generic detection term for this type of malware worm, is connected to a computer. The infected device – most commonly a memory stick, but potentially any device with a mass-storage capacity such as a PSP, digital camera, some cellular phones, and mp3 players – starts an executable file which then invites a wide array of malware into the computer. The incoming malware copies itself into the core of the Windows OS and can replicate itself each time the computer is started.
Out of the total AutoRun-gen2 attacks, 84% of the attempts were repelled by the on-access scans in the avast! System Shield. The malware was detected at the time when the USB device was initially connected. The remaining 16% were discovered during scans of the computer hard-drives.
CommunityIQ is a select group of avast! users that automatically send data on the malware they encounter to the Virus Lab. As a cross-section of avast!’s global user pool of over 130 million, the CommunityIQ represents a statistically significant sample of current malware dangers. The submitted data is then analyzed and incorporated into avast! protective shields and the virus database sent to all users.
The low cost of USB memory sticks makes it easy for friends and work colleagues to exchange large media files and creates a convenient target for cyber criminals. “In a work environment, staff will often bring in their own USB memory sticks to move files around,” Mr. Sirmer comments. “This can bypass gateway malware scanners and leave the responsibility for stopping malware just on the local machines’ antivirus software.”
Detecting AutoRun-gen2 is complicated by the growing memory of USB devices and more complex obfuscation techniques. “A full scan can take up to an hour for a one terabyte device, so people will skip this entirely or just go for a quicker on-access scan,” said Mr. Sirmer. This danger is poised to increase with the introduction of the new USB 3 standard. In parallel with these technological improvements, the writers of AutoRun malware are developing new code and ways how to obfuscate their work. “Once I found ‘y0u c4nt st0p us’ in the middle of some code,” quipped Mr. Sirmer. “They know they are in the lead.”
How Did My PC Get Infected with Autorun Malware?
The following are the most likely reasons why your computer got infected with Autorun Malware:
- Your operating system and Web browser's security settings are too lax.
- You are not following safe Internet surfing and PC practices.
Downloading and Installing Freeware or Shareware
Small-charge or free software applications may come bundled with spyware, adware, or programs like Autorun Malware. Sometimes adware is attached to free software to enable the developers to cover the overhead involved in created the software. Spyware frequently piggybacks on free software into your computer to damage it and steal valuable private information.
Using Peer-to-Peer Software
The use of peer-to-peer (P2P) programs or other applications using a shared network exposes your system to the risk of unwittingly downloading infected files, including malicious programs like Autorun Malware.
Visiting Questionable Web Sites
When you visit sites with dubious or objectionable content, trojans-including Autorun Malware-, spyware, and adware, may well be automatically downloaded and installed onto your computer.
Detecting Autorun Malware
The following symptoms signal that your computer is very likely to be infected with Autorun Malware.
PC is working very slowly
Autorun Malware can seriously slow down your computer. If your PC takes a lot longer than normal to restart or your Internet connection is extremely slow, your computer may well be infected with Autorun Malware.
New desktop shortcuts have appeared or the home page has changed
Autorun Malware can tamper with your Internet settings or redirect your default home page to unwanted web sites. Autorun Malware may even add new shortcuts to your PC desktop.
Annoying popups keep appearing on your PC
Autorun Malware may swamp your computer with pestering popup ads, even when you're not connected to the Internet, while secretly tracking your browsing habits and gathering your personal information.
E-mails that you didn't write are being sent from your mailbox
Autorun Malware may gain complete control of your mailbox to generate and send e-mail with virus attachments, e-mail hoaxes, spam, and other types of unsolicited e-mail to other people.
Also Be Aware of the Following Threats:
USB safety pointers
- Be aware. Around 60% of malware can now be spread via USB devices. This is an under-appreciated threat to home and business computers.
- Don’t start attached. Turning on a PC with a USB device attached can result in malware being loaded directly to the computer ahead of some antivirus programs starting up.
- Scan first, look second. Make sure you have enabled “on-access auto-scans” in your antivirus program.
Comments
Post a Comment