{"id":6343,"date":"2017-01-23T15:50:28","date_gmt":"2017-01-23T23:50:28","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/23\/news-181\/"},"modified":"2017-01-23T15:50:28","modified_gmt":"2017-01-23T23:50:28","slug":"news-181","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/01\/23\/news-181\/","title":{"rendered":"MSRT December 2016 addresses Clodaconas, which serves unsolicited ads through DNS hijacking"},"content":{"rendered":"<p><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">In this month\u2019s <\/span><a target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/download\/malicious-software-removal-tool-details.aspx\"><span style=\"line-height: 107%;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Microsoft Malicious Software Removal Tool<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"color: #333333;line-height: 107%;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"> (MSRT) release, we continue taking down unwanted software, the pesky threats that force onto our computers things that we neither want nor need.<\/span><\/p>\n<p><span lang=\"EN-US\"><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri\">BrowserModifier:Win32\/Clodaconas<\/span><\/a><span style=\"color: #000000;font-family: Calibri\">, for instance, displays ads when you\u2019re browsing the internet. It modifies search results pages so that you see unsolicited ads related to your searches.<\/span><\/span><\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">For example, if you were looking for a gift to give a loved one this holiday season and are searching for \u201cfitness tracker\u201d, your search results page might contain an ad like this:<\/span><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><img loading=\"lazy\" decoding=\"async\" width=\"484\" height=\"770\" class=\"alignnone size-full wp-image-9705\" alt=\"Screenshot of advertisements injected by Clodaconas to search results for \u201cfitness tracker\u201d\" src=\"https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/Clo1.png\" \/><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Figure 1. Ads injected by Clodaconas to search results for \u201cfitness tracker\u201d<\/span><\/span><\/i><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">It can also add pop-up ads when you\u2019re visiting online retailer websites. For example, if you previously searched for \u201cTV\u201d, and then visited an online shop, the threat may display the following ad: <\/span><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"313\" height=\"444\" class=\"alignnone size-full wp-image-9715\" alt=\"Screenshot of a pop-up ad injected by Clodaconas to online retailer pages\" src=\"https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/Clo2.png\" \/><\/p>\n<p><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Figure 2. Pop-up ad injected by Clodaconas to online retailer pages<\/span><\/span><\/i><\/p>\n<p><span style=\"color: #000000;font-family: Times New Roman\">\u00a0<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri\">BrowserModifier:Win32\/Clodaconas<\/span><\/a><span style=\"color: #000000;font-family: Calibri\"> does this by hijacking your domain name server (DNS) settings.<\/span><\/span><\/p>\n<h1 style=\"margin: 2pt 0cm 0pt\"><span lang=\"EN-US\"><span style=\"color: #2f5496;font-family: Calibri Light;font-size: large\">Injecting ads through DNS hijacking <\/span><\/span><\/h1>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">When you browse the Internet, your PC contacts a DNS server to resolve the domain of the website you\u2019d like to access. The DNS server returns the IP address of the website, which your PC then accesses to get the content to display.<\/span><\/span><\/p>\n<p><span style=\"color: #000000;font-family: Times New Roman\"><img loading=\"lazy\" decoding=\"async\" width=\"605\" height=\"334\" class=\"alignnone size-full wp-image-9725\" alt=\"Diagram showing the normal domain name resolution by legitimate DNS servers\" src=\"https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/Clo3.png\" \/><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Figure 3. Normal domain name resolution by legitimate DNS servers <\/span><\/span><\/i><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri\">BrowserModifier:Win32\/Clodaconas<\/span><\/a><span style=\"color: #000000;font-family: Calibri\"> compromises this process to inject ads. It modifies DNS settings in your registry so that they point to a rogue DNS server. All DNS queries are therefore redirected to this DNS server, which resolves specific domains to the IP address of another attacker-controlled server.<\/span><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">This results in a man-in-the-middle (MITM) attack. Instead of getting content directly from the server of the website you\u2019re accessing, your PC gets content from the MITM server. It contacts legitimate websites to get the actual content you\u2019re looking for, but modifies it before it is displayed on your browser. This is how the unwanted ads are displayed on your search results pages or on online retail websites.<\/span><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span><span style=\"font-family: Calibri\"><span style=\"color: #000000\"><img loading=\"lazy\" decoding=\"async\" width=\"605\" height=\"427\" class=\"alignnone size-full wp-image-9735\" alt=\"Diagram showing that In DNS hijacking, DNS requests are redirected to a rogue DNS server\" src=\"https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/Clo4.png\" \/>\u00a0<\/span><\/span><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Figure 4. In DNS hijacking, DNS requests are redirected to a rogue DNS server<\/span><\/span><\/i><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">This method of injecting ads meets the <\/span><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/portal\/mmpc\/shared\/objectivecriteria.aspx\"><span style=\"color: #0563c1;font-family: Calibri\">evaluation criteria<\/span><\/a><span style=\"color: #000000;font-family: Calibri\"> that Microsoft Malware Protection Center (MMPC) uses for identifying unwanted software. This threat modifies webpage content without your consent. It also does this without using the browser&#8217;s <\/span><a href=\"https:\/\/developer.microsoft.com\/en-us\/microsoft-edge\/platform\/documentation\/extensions\/microsoft-browser-extension-policy\/\"><span style=\"color: #0563c1;font-family: Calibri\">supported extensibility models<\/span><\/a><span style=\"color: #000000;font-family: Calibri\">, hence our classification of this program as unwanted software.<\/span><\/span><\/p>\n<h2 style=\"margin: 2pt 0cm 0pt\"><span lang=\"EN-US\"><span style=\"color: #2f5496;font-family: Calibri Light;font-size: large\">Using rogue root certificate<\/span><\/span><\/h2>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Many websites use SSL encryption to protect transactions. This mechanism also prevents the modification of content served by websites. Browsers check the validity of a website\u2019s SSL certificate against trusted root certification authorities\u2019 certificates stored on your PC. Browsers show a warning page or icon if a website\u2019s certificate is not trusted.<\/span><\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">To avoid triggering this alert, <\/span><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri\">BrowserModifier:Win32\/Clodaconas<\/span><\/a><span style=\"color: #000000;font-family: Calibri\"> installs a root certificate as a trusted root certification authority. With the rogue root certificate installed, ads can be injected into encrypted content and still appear valid to the browser.<\/span><\/span><\/p>\n<h2 style=\"margin: 2pt 0cm 0pt\"><span lang=\"EN-US\"><span style=\"color: #2f5496;font-family: Calibri Light;font-size: large\">MSRT removes <\/span><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri Light;font-size: large\">Clodaconas<\/span><\/a><\/span><\/h2>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">This month, we\u2019re adding detections for <\/span><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"color: #0563c1;font-family: Calibri\">BrowserModifier:Win32\/Clodaconas<\/span><\/a><span style=\"color: #000000;font-family: Calibri\"> to <\/span><a target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/download\/malicious-software-removal-tool-details.aspx\"><span style=\"line-height: 107%;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Microsoft Malicious Software Removal Tool<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"color: #333333;line-height: 107%;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"> (MSRT). If your PC is infected with this threat, run MSRT to remove all related files and restore all system modifications on your PC. <\/span><\/p>\n<p style=\"margin: 0cm 0cm 8pt\"><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">You may need to clear your browser cache after the threat is removed. The browser might still hold cache of a website you recently visited, so you might still see the ads.<\/span><\/span><\/p>\n<h2 style=\"margin: 2pt 0cm 0pt\"><span lang=\"EN-US\"><span style=\"color: #2f5496;font-family: Calibri Light;font-size: large\">Prevention, detection, and recovery<\/span><\/span><\/h2>\n<p style=\"background: white\"><span lang=\"EN-US\" style=\"color: #333333;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Stay protected from <\/span><span lang=\"EN-US\"><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?Name=BrowserModifer%3aWin32%2fClodaconas\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">BrowserModifier:Win32\/Clodaconas<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"color: #333333;font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"> and other threats:<\/span><\/p>\n<ul type=\"disc\">\n<ul type=\"disc\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Keep your Windows operating system and antivirus <\/span><span lang=\"EN-US\" style=\"color: windowtext\"><a target=\"_blank\" href=\"http:\/\/www.microsoft.com\/security\/portal\/mmpc\/help\/updatesoftware.aspx\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">up-to-date<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">; if you haven\u2019t already, upgrade to <\/span><span lang=\"EN-US\" style=\"color: windowtext\"><a target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/windows\/windows-10-upgrade\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Windows 10<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">.<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"color: windowtext\"><a target=\"_blank\" href=\"https:\/\/blogs.windows.com\/msedgedev\/2015\/12\/16\/smartscreen-drive-by-improvements\/\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Use Microsoft Edge<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">. It can: <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Help warn you about sites that are known to be hosting exploits and other threats<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Help protect you from social engineering attacks such as phishing and malware downloads<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Automatically detect bad changes and protect settings<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Use the <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Settings<\/span><\/strong> app to reset to Microsoft recommended defaults if your default apps were changed. <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Launch the Settings app.<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Navigate to the <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Default apps<\/span><\/strong> page<u>.<\/u> <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<ul type=\"circle\">\n<ul type=\"square\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">From Home go to <strong><span style=\"font-family: 'Segoe UI',sans-serif\">System <\/span><\/strong>&gt;<strong><span style=\"font-family: 'Segoe UI',sans-serif\"> Default apps<\/span><\/strong>.<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<\/ul>\n<ul type=\"circle\">\n<ul type=\"square\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Click <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Reset<\/span><\/strong>.<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<\/ul>\n<\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Ensure your antimalware protection (such as <\/span><span lang=\"EN-US\" style=\"color: windowtext\"><a target=\"_blank\" href=\"http:\/\/windows.microsoft.com\/en-us\/windows\/using-defender#1TC=windows-10\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Windows Defender<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"> and <\/span><span lang=\"EN-US\" style=\"color: windowtext\"><a target=\"_blank\" href=\"http:\/\/www.microsoft.com\/en-us\/download\/malicious-software-removal-tool-details.aspx\"><span style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\"><span style=\"color: #0563c1\">Microsoft Malicious Software Removal Tool<\/span><\/span><\/a><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">) is up-to-date. <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span>\n<ul type=\"circle\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">If you are using Windows Defender, you can check your exclusion settings to see whether the malware added some entries in an attempt to exclude folders from being scanned. <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span>\n<ul type=\"square\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">To check and remove excluded items in Windows Defender: <\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ul>\n<ul type=\"circle\">\n<ul type=\"square\">\n<ol type=\"1\" start=\"1\">\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Navigate to <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Settings<\/span><\/strong> &gt; <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Update &amp; security<\/span><\/strong> &gt; <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Windows Defender<\/span><\/strong> &gt; <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Add an exclusion<\/span><\/strong>.<\/span><\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span style=\"color: #000000;font-family: Times New Roman\"><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Go through the lists under <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Files<\/span><\/strong> and <strong><span style=\"font-family: 'Segoe UI',sans-serif\">File locations,<\/span><\/strong> select the excluded item that you want to remove, and click <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Remove<\/span><\/strong>.<\/span><\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span style=\"color: #000000;font-family: Times New Roman\"><\/span><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Click <strong><span style=\"font-family: 'Segoe UI',sans-serif\">OK<\/span><\/strong> to confirm.<\/span><span style=\"color: #000000;font-family: Times New Roman\"><\/span><\/li>\n<\/ol>\n<\/ul>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li style=\"background: white;margin: 0cm 0cm 8pt;line-height: normal;font-size: 12pt;font-style: normal;font-weight: normal\"><span lang=\"EN-US\" style=\"font-family: 'Segoe UI',sans-serif;font-size: 10.5pt\">Use cloud protection to help guard against the latest malware threats. It\u2019s turned on by default for Microsoft Security Essentials and Windows Defender for Windows 10. Go to <strong><span style=\"font-family: 'Segoe UI',sans-serif\">All settings<\/span><\/strong> &gt; <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Update &amp; security<\/span><\/strong> &gt; <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Windows Defender<\/span><\/strong> and make sure that your <strong><span style=\"font-family: 'Segoe UI',sans-serif\">Cloud-based Protection<\/span><\/strong> settings is turned <strong><span style=\"font-family: 'Segoe UI',sans-serif\">On<\/span><\/strong>.<\/span><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">\u00a0<\/span><\/span><\/li>\n<\/ul>\n<\/ul>\n<p style=\"margin: 0cm 0cm 8pt\"><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">Jody Koo<\/span><\/span><\/i><\/p>\n<p><i><span lang=\"EN-US\"><span style=\"color: #000000;font-family: Calibri\">MMPC<\/span><\/span><\/i><\/p>\n<p><a href=\"https:\/\/blogs.technet.microsoft.com\/mmpc\/2016\/12\/13\/msrt-december-2016-addresses-clodaconas-which-serves-unsolicited-ads-through-dns-hijacking\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this month\u2019s Microsoft Malicious Software Removal Tool (MSRT) release, we continue taking down unwanted software, the pesky threats that force onto our computers things that we neither want nor need. BrowserModifier:Win32\/Clodaconas, for instance, displays ads when you\u2019re browsing the internet. It modifies search results pages so that you see unsolicited ads related to your&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[10760,10858,11024,11025,11026,11027,10785,10786,11028,10768,10761,10762],"class_list":["post-6343","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-antimalware-research-for-it-pros-and-enthusiasts","tag-browser-modifier","tag-browsermodifierwin32clodaconas","tag-clodaconas","tag-dns-hijacking","tag-injecting-ads","tag-microsoft-malicious-software-removal-tool","tag-msrt","tag-msrt-removes-clodaconas","tag-unwanted-software","tag-windows-10","tag-windows-defender"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6343"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6343\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6343"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}