Solved

credit card fraud Malware Tools

Posted on 2014-07-25
4
226 Views
Last Modified: 2014-08-25
I have a customer running a Rental car company and a large number of customers credit cards have been defrauded. I have the task to identify if any of their pc are compromised. What would be the best tool to scan for this type of trojan or any other way to ensure the pc's are clean. They currently have Trend Micro Titanium installed. I'm running the standard tools like malwarebytes, spybot, JRT, Adwcleaner at the moment. Any other ideas or comments are appreciated. Thanks
0
Comment
Question by:co_ol
  • 2
4 Comments
 
LVL 87

Expert Comment

by:rindi
ID: 40219036
First of all I'd use an OS that isn't easily attacked by malware, like most Linux distributions. Second, make sure the user accounts used by the users don't have admin rights. Again in most Linux distro's that is the standard setting. Third, teach your users how to use common sense when using the PC, particularly when accessing the internet, not to go to every obscure site, not to blindly open every attachment you get with your mail, encrypt data that is sensitive, etc.
0
 
LVL 10

Expert Comment

by:Schuyler Dorsey
ID: 40220212
As far as malware, I would add TDSS Killer and the ESET Online Scanner to your list. But these will only go as far as detecting mainstream malware.

If someone has actually compromised the network, that would be harder to detect and I would recommend seeking out a professional if you think this to be the case.

As far as prevention, definitely do as the previous poster mentioned in regards to taking away admin rights. Also ensure to harden the computers. I would also seek out a better AV. Symantec and Kaspersky consistently score higher than Trend Micro. I would also consider a strong perimeter security device such as a next generation firewall from Palo Alto Networks.
0
 
LVL 87

Expert Comment

by:rindi
ID: 40220270
No, whatever you do, don't go for any Symantec products, they have the best records of making the worst products possible! They are almost malware already!
0
 
LVL 13

Accepted Solution

by:
Greg Hejl earned 500 total points
ID: 40222525
https://www.pcisecuritystandards.org/

Check that their payment processing systems adheres to the requirements of PCI DSS documentation.

make sure their firewall is correctly configured.

run Malwarebytes and combofix on windows devices.

review MSConfig for unrecognized startup programs, make sure the merchant is not using the payment processing device for any other use.

All transactons from modern device software transfer data via https protocol - investigate this.

good luck!
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now