Skip to main content

McAfee Releases Free Tool That Removes Pinkslipbot Leftovers That Use Your PC as Proxy


Last week, McAfee released a tool named AmIPinkC2, a Windows command-line application that removes remnant files of Pinkslipbot infections that allow the malware to continue to use previously infected computers as proxy relays, even if the original malware's binary has been cleaned and removed from infected hosts.


The malware in question is Pinkslipbot, a banking trojan that appeared in 2007 and is also tracked under three other names, such as Qakbot, Qbot, and PinkSlip.

http://www.mcafee.com/activate


Pinkslipbot is a well-known and dangerous threat
Pinkslipbot is a well-known threat on the malware landscape, mainly due to its specific targeting. Its authors aren't going after regular users, but have historically targeted North American companies, especially those in lucrative industry sectors, such as corporate banking, financial institutions, treasury services, and others.

This banking trojan isn't always active, and it keeps coming back in waves, as part of very well-planed campaigns. In the past years, numerous cyber-security companies have tracked its attacks and broken down its different versions [1, 2, 3, 4, 5, 6, 7, 8, 9, 10].

The most recent campaign was spotted by IBM security researchers, who noticed Pinkslipbot versions that caused Active Directory lockouts on infected computers.

McAfee finds new wrinkle in Pinkslipbot infections
One of the companies that have historically tracked Pinkslipbot campaigns is McAfee. Its researchers presented an analysis of the trojan's C&C server infrastructure and its method C&C communications at last year's Virus Bulletin security conference.

Last week, while looking over past and present Pinkslipbot campaigns, researchers found a new wrinkle in the trojan's mode of operation.

Researchers say Pinkslipbot authors are much clever than they initially thought. According to McAfee, besides stealing the user's  data, the banking trojan also uses infected hosts as proxy servers to relay information from the central C&C server to other infected hosts, in a mesh-like network.

New McAfee tool removes last remnants of Pinkslipbot infections
According to McAfee, most security tools remove only the malware's main binaries, crippling the trojan's ability to collect passwords from infected hosts.



These Pinkslipbot removal procedures leave intact the code that creates these proxy servers, which run via the Windows UPnP (Universal Plug and Play) service.


McAfee's new tool will remove these remaining files and prevent Pinkslipbot from using users' PCs to relay C&C commands or to hide the exfiltration of stolen data through a mesh of proxies.


Get More Help- Redeem McAfee Retail Card


Comments

Popular posts from this blog

How to Activate McAfee Product?

Before you begin Check for other security applications. If you have other security software installed on your computer, remove them using the instructions provided by their product manufacturer. Removing these security application is necessary to prevent application conflicts and degraded performance. Follow these steps to redeem a McAfee software product card that you purchased in a store. Activate McAfee Live Safe After you redeem the card, you can  download and install  your McAfee software and  activate your subscription . Open a web browser and go to the link shown on your retail card (for example  http://www.mcafeeactivatehome.com/ . Select:   Your  country Your  language The registration page tries to select the correct region, but it might not always get this right. Confirm that the region is correct before you continue.   Type: ...

How to Use McAfee VirusScan Plus? - mcafee.com/activate

Activate your Card- http://www.McAfee.com/activate   Plus establish on your PC. You can purchase software CD/DVD by dealer and use it. Or McAfee antivirus software you can buy and download and install. Plus 125 MB of hard disk space Required for installation (75 MB after). RAM and Windows 2000 or XP 300 MHz processor with at least 256 MB will need one. Vista 512 MB RAM and a 800MHz processor will required. Access from your programs menu Security centre. From here you can directly manage their McAfee products.  Get More Help- McAfee Activate

What do you think of McAfee AntiVirus?

While I have not had for years McAfee virus got through, they did now and then, there are also some bad ones. Security 2012 virus is a technique that took hours to recover after three disastrous run-ins, I switched to Norton. To do this, since I was not in any way a single event. Activate McAfee Retail Card Get More Help- McAfee Activate