Security [CENTRAL] Forum - SCforum.info
24. May 2012., 08:18:05 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11258
Latest: donna717
Stats
Total Posts: 15637
Total Topics: 4337
Online Today: 2172
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Security Shield hacks BitTorrent & uTorrent (download removal tools)  (Read 1348 times)
0 Members and 1 Guest are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 14. September 2011., 07:46:53 »



Attackers hijacked two popular Bittorrent websites and tampered with their download mechanisms, causing visitors trying to obtain file-sharing software to instead receive malware.

The hacks on bittorrent.com and utorrent.com replaced the sites' standard software downloads with a piece of fake antivirus software known as Security Shield, an advisory warned: http://blog.bittorrent.com/2011/09/13/security-incident/
Anyone who downloaded and installed software from those sites between 4:20 a.m. California time and 6:10 a.m. should scan their systems immediately for infections.

Once installed, Security Shield delivers false reports that a computer is infected with multiple pieces of malware and prompts the user for payment before claiming to disinfect the machine. The attack affected only users who downloaded and installed software from bittorrent.com and utorrent.com during the hour-and-fifty-minute window that the sites were compromised. Those who installed software previously are unaffected.

"We take the security of our systems and the safety of our users very seriously," the Bittorrent advisory stated. "We sincerely apologize to any users who were affected."

(ElReg)


Download SuperAntispyware or/and MalwareByte's to remove Fake AV "Security Shield"!

SuperAntispyware: http://scforum.info/index.php/topic,116.0.html

MaleareByte's:  http://scforum.info/index.php/topic,2201.0.html


Logged

Security [CENTRAL] Forum - SCforum.info
« on: 14. September 2011., 07:46:53 »



 Logged
Pez
SCF Advanced Member
***

KARMA: 25
Posts: 189


Pez


WWW
« Reply #1 on: 15. September 2011., 08:50:46 »

Some clarification and updates of this from:
http://blog.bittorrent.com/2011/09/13/security-incident/

Security Incident (Updated 9/14)

 
This morning on 9/13/2011 at approximately 4:20 a.m. Pacific Daylight Time (UTC -7), the uTorrent.com and BitTorrent.com Web servers were compromised. Our standard Windows software download was replaced with a type of fake antivirus “scareware” program. (UPDATE: See below for removal instructions.)
 

Just after 6:00 a.m. Pacific time, we took the affected servers offline to neutralize the threat. Our servers are now back online and functioning normally.
 
We have completed preliminary testing of the malware. Upon installation, a program called ‘Security Shield” launches and pops up warnings that a virus has been detected. It then prompts a user for payment to remove the virus. We recommend anyone who downloaded software between 4:20 a.m. and 6:10 a.m. Pacific time run a security scan of their computer.
 
We take the security of our systems and the safety of our users very seriously. We sincerely apologize to any users who were affected.
 
Clarification: This only affects users who downloaded software specifically from utorrent.com or bittorrent.com between the hours above this morning. Users who previously downloaded our software are not affected.
 
Update #2: After further analysis, we don’t believe BitTorrent.com or the BitTorrent Mainline/Chrysalis clients were part of the incident.
 
Update #3: File Removal Instructions
 
This particular piece of malware renames itself as a different .exe file every time it installs on a new machine. Therefore, first you need to determine the file name. To do this, visit the following File Directory on your Windows hard drive:
 
Windows XP: Click Start, click Run, and then type in “%USERPROFILE%\Local Settings\Application Data\” without the quotes. The file will be called [random].exe
 Windows Vista and Windows 7: Click Start, in the search box type in “%localappdata%” without the quotes. The file will be called [random].exe.
 
To delete the file, first you need to make sure to kill the application first:
 – Open your Task Manager (Control-Alt-Delete), select the [random].exe (the name you found in the file directory). Click “End Process” and select “Yes.”
 
- Next: select the file name (or right-click on the name) and hit Delete.
 
- Empty your trash.


Logged

Their is two easy way to configure a system!
Every thing open and every thing closed.
Every thing else is more or less complex.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #2 on: 15. September 2011., 16:51:51 »


Thanks for info's pal...  thumbsup

Logged

Fireberg
SCF Advanced Member
***

KARMA: 19
Posts: 153


« Reply #3 on: 21. September 2011., 21:37:04 »

i read this note too late, but thanx for info buddy

Thanx
Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 21. May 2012., 13:00:39