Smart Fortress Incident
EXTREMELY slow system performance The Initial Issue EXTREMELY slow system performance
Running Windows XP Professional Version 2002 Due to old, poorly managed system…? Or something worse…?
The Real Problem Security Monitor: WARNING! Attention! System detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. Your private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need to update your current security software. Click Yes to download official intrusion detection system (IDS software). Initial pop-up that displayed on my computer’s lock screen as I was finishing up at work. First real detection of an issue.
Smart Fortress 2012 Smart Fortress 2012 – Rogue anti-spyware tool; fraudulent computer security program
Smart Fortress 2012 Info Type: Spyware Analysis: Installs & gathers info from a PC without user permission Cause of Infection: By downloading freeware & shareware Common Symptoms: Alters PC settings, excessive pop-ups, degraded PC performance
What’s the Big Deal? Smart Fortress 2012 appears as a simple annoyance However, simply “removing” the program WILL NOT WORK Gets worse as it remains on the system Eventually DENIES ALL ACCESS The “Warning” message displays any time the user attempts to execute a legitimate application. Antivirus also disabled. Warning! Application cannot be executed. The file <appname> is infected. Please activate your antivirus software.
AA39754E-715219CE to “neutralize” the virus in a sense
Trojan Killer Not free software; used for manual removal of infected files http://trojan-killer.net/absolutely-approach-smart-fortress-virus-removal/
Utilizing Malwarebytes
Issues Faced & Lessons Learned Essentially no response from company employees Nonchalant attitude No IT dept/person whatsoever Lack of acknowledgement/understanding of importance of computer & network security Disregard to consequences of ignoring security issues & vulnerabilities Took a receptionist to realize there was a problem………