<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-8721477802794636844</atom:id><lastBuildDate>Tue, 26 Aug 2008 19:45:18 +0000</lastBuildDate><title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools</title><description/><link>http://www.softe.org/</link><managingEditor>noreply@blogger.com (Mandy)</managingEditor><generator>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1483299811109891831</guid><pubDate>Tue, 26 Aug 2008 19:44:00 +0000</pubDate><atom:updated>2008-08-26T12:45:18.935-07:00</atom:updated><title>Downloader-UA.h Trojan fake music and video files</title><description>Overview -&lt;br /&gt;&lt;br /&gt;--- Update May 6th, 2008 --&lt;br /&gt;Due to an increase in prevalence being seen by our VirusScan Online Customers, the risk assessment of this threat was upgraded to Medium for Home Users and Low Profiled for Corporate Users.&lt;br /&gt;&lt;br /&gt;Downloader-UA.h trojans are fake music and video files associated with fastmp3player.com.&lt;br /&gt;Characteristics&lt;br /&gt;Characteristics -&lt;br /&gt;&lt;br /&gt;Downloader-UA.h trojans are fake music and video files associated with fastmp3player.com.&lt;br /&gt;&lt;br /&gt;File sizes vary as these files are padded with nulls. The file names varies as well. Here are some of the samples file names. &lt;br /&gt;&lt;br /&gt;preview-t-3545425-adult.mpg&lt;br /&gt;preview-t-3545425-changing times earth wind .mp3&lt;br /&gt;preview-t-3545425-girls aloud st trinnians.mp3&lt;br /&gt;preview-t-3545425-heartbroken fast t2 ft jodie.mp3&lt;br /&gt;preview-t-3545425-jij bent zo jeroen van den.mp3&lt;br /&gt;preview-t-3545425-meet bambi in kings harem.mp3&lt;br /&gt;preview-t-3545425-middle eastern chick.mpg&lt;br /&gt;preview-t-3545425-paint me bunmingham.mp3&lt;br /&gt;preview-t-3545425-paralyized by you.mp3&lt;br /&gt;preview-t-3545425-pull over levert.mp3&lt;br /&gt;preview-t-3545425-say it right remix.mp3&lt;br /&gt;preview-t-3545425-st trinnians girls aloud.mp3&lt;br /&gt;preview-t-3545425-theme godfather.mp3&lt;br /&gt;t-3545425-bentley bizzle.mp3&lt;br /&gt;t-3545425-dx vs randi orton 2007.mpg&lt;br /&gt;t-3545425-haloween special.mp3&lt;br /&gt;t-3545425-just got lucky.mp3&lt;br /&gt;t-3545425-lion king portugues.mpg&lt;br /&gt;t-3545425-los padres de ella.mpg&lt;br /&gt;t-3545425-para sayo freestyle.mp3&lt;br /&gt;t-3545425-peanut butter jelly amende.mp3&lt;br /&gt;t-3545425-stare at sun thrice.mp3&lt;br /&gt;t-3545425-suicide bride dana.mp3&lt;br /&gt;t-3545425-wayne and jane.mp3&lt;br /&gt;&lt;br /&gt;When a user attempts to load one of these MP3 and MPG files, they do not get the music/video they were hoping for; instead they are directed to download a file named PLAY_MP3.exe.  In fact, the MP3/MPG file they downloaded was completely fake, playing no media clip what so ever.&lt;br /&gt;&lt;br /&gt;If users agree to download and run PLAY_MP3.exe (detected as Generic PUP.a with McAfee DAT files)  a 4,800 word EULA is displayed. &lt;br /&gt;&lt;br /&gt;Method of Infection -&lt;br /&gt;&lt;br /&gt;Downloader-UA.h trojans are propagated through P2P networks</description><link>http://www.softe.org/2008/08/downloader-uah-trojan-fake-music-and.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-4779586466931443577</guid><pubDate>Thu, 03 Jul 2008 03:04:00 +0000</pubDate><atom:updated>2008-07-02T20:08:23.870-07:00</atom:updated><title>Microsoft MJPEG Decoder Vulnerability malicious file buffer overflow</title><description>&lt;span style="font-weight:bold;"&gt;Description&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Windows is an industry-standard operating system developed by Microsoft. A vulnerability in Microsoft DirectX may allow for remote code-execution attacks. The vulnerability lies in the processing of specially crafted MJPEG streams in AVI or ASF files. A user would have to open a malicious file or visit a Web site streaming a malicious file for an attack to occur.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Type &lt;/span&gt;- Buffer Overflow&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Impact of exploitation &lt;/span&gt;- Remote Code Execution&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;User Interaction&lt;/span&gt; - no user interaction is needed&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Attack Vector&lt;/span&gt; - Maliciously Crafted File&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Rating&lt;/span&gt; - Medium &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;CVE reference&lt;/span&gt; - CVE-2008-0011, &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Vendor Status&lt;/span&gt; - Responded and patched&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Vulnerable systems&lt;/span&gt;&lt;br /&gt;    Windows 2000  Sp4, &lt;br /&gt;    Windows  XP SP3, &lt;br /&gt;    Windows 2003  Sp2, &lt;br /&gt;    Windows Vista  SP0, &lt;br /&gt;    Windows Server 2008  &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Summary&lt;/span&gt;&lt;br /&gt;    A vulnerability in Microsoft DirectX may allow for remote code-execution attacks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Recommendations -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Download and install the patch available from Microsoft (951698): http://www.microsoft.com/technet/security/Bulletin/MS08-033.mspx</description><link>http://www.softe.org/2008/07/microsoft-mjpeg-decoder-vulnerability.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-4750149211257735076</guid><pubDate>Wed, 05 Mar 2008 19:03:00 +0000</pubDate><atom:updated>2008-03-05T11:06:49.885-08:00</atom:updated><title>Monagrey Win32 trojan modifies IE start page Trojan.Monagray Trojan.Win32.Monagrey.a (KAV)</title><description>&lt;span style="font-weight:bold;"&gt;Overview -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Monagrey is a trojan which modifies IE start page and prevents common applications from running.&lt;br /&gt;Aliases&lt;br /&gt;&lt;br /&gt;    * Trojan.Monagray (Symantec)&lt;br /&gt;&lt;br /&gt;    * Trojan.Win32.Monagrey.a (KAV)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Characteristics -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-- Update March 4, 2008 --&lt;br /&gt;The risk assessment of this threat has been updated to Low-Profiled due to media attention.&lt;br /&gt;&lt;br /&gt;Monagrey is a trojan which modifies IE start page and prevents common applications from running.&lt;br /&gt;&lt;br /&gt;It will modify the following registry key to run at startup:&lt;br /&gt;HKEY_LOCAL_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows: "%LOCATION%\SRVSPOOL.exe"&lt;br /&gt;&lt;br /&gt;(where %LOCATION % is the location of the folder where it resides e.g. C:\)&lt;br /&gt;&lt;br /&gt;Upon reboot, the trojan will display a pop up window.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.softe.org/uploaded_images/144216_1-763643.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.softe.org/uploaded_images/144216_1-763633.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It will change IE start page to point to the following URL:&lt;br /&gt;&lt;br /&gt;    * http://en.wikipedia.org/wiki/Human_rights&lt;br /&gt;&lt;br /&gt;and also prevent applications with the following names in their title bar from running:&lt;br /&gt;&lt;br /&gt;    * Date And Time&lt;br /&gt;    * Windows Task Manager&lt;br /&gt;    * Registry Editor&lt;br /&gt;    * Irfanview&lt;br /&gt;    * Google Talk&lt;br /&gt;    * Macromedia&lt;br /&gt;    * Adobe&lt;br /&gt;    * Microsoft Visual&lt;br /&gt;    * Windows Media Player&lt;br /&gt;    * Winamp&lt;br /&gt;    * Microsoft Office&lt;br /&gt;    * Microsoft Excel&lt;br /&gt;    * Microsoft Word&lt;br /&gt;    * Messenger&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Unexpected termination of previously mentioned applications&lt;br /&gt;    * Modification of IE start page to previously mentioned URL.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection -&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;All Users:&lt;br /&gt;Use specified engine and DAT files for detection and removal.&lt;br /&gt;&lt;br /&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).&lt;br /&gt;&lt;br /&gt;Additional Windows ME/XP removal considerations</description><link>http://www.softe.org/2008/03/monagrey-win32-trojan-modifies-ie-start.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-2948700464284265852</guid><pubDate>Thu, 28 Feb 2008 06:41:00 +0000</pubDate><atom:updated>2008-02-27T22:42:45.042-08:00</atom:updated><title>PWS-LegMir.gen.k.dll passwword stealer virus</title><description>&lt;span style="font-weight:bold;"&gt;Overview -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PWS-LegMir.gen.k.dll is dropped by PWS-LegMir.gen.k. It steals password from multiple games. It may also detect and terminate antivirus applications.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Characteristics -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PWS-LegMir.gen.k.dll is dropped by PWS-LegMir.gen.k. It steals password from multiple games. It may also detect and terminate antivirus applications.&lt;br /&gt;&lt;br /&gt;The following antivirus applications are detected and terminated:&lt;br /&gt;&lt;br /&gt;    * KAV (Kaspersky)&lt;br /&gt;    * RAV (Rising)&lt;br /&gt;    * AVP (Kaspersky)&lt;br /&gt;    * KAVSVC (Kaspersky)&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Unexpected termination of previously mentioned antivirus applications.&lt;br /&gt;&lt;br /&gt;Method of Infection&lt;br /&gt;Method of Infection -&lt;br /&gt;&lt;br /&gt;PWS-LegMir.gen.k.dll is dropped by PWS-LegMir.gen.k.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.</description><link>http://www.softe.org/2008/02/pws-legmirgenkdll-passwword-stealer.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1143028079012302581</guid><pubDate>Thu, 14 Feb 2008 21:06:00 +0000</pubDate><atom:updated>2008-02-14T13:08:54.103-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>WORM_NUWAR.AR Malware Email Virus</category><title>WORM_NUWAR.AR Malware Email Virus</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.softe.org/uploaded_images/WORM_NUWAR_AR_BD-707345.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.softe.org/uploaded_images/WORM_NUWAR_AR_BD-707341.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;To get a one glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.&lt;br /&gt;javascript:void(0)&lt;br /&gt;Publish Post&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Malware Overview&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This worm arrives as attachment to email messages spammed by another malware or a malicious user.&lt;br /&gt;&lt;br /&gt;It drops files detected by Trend Micro as TROJ_PEACOMM.BK.&lt;br /&gt;&lt;br /&gt;It propagates by sending email messages containing a link, which redirects users to a malicious Web site where a copy of itself can be downloaded.</description><link>http://www.softe.org/2008/02/wormnuwarar-malware-email-virus.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-237728109280383269</guid><pubDate>Wed, 13 Feb 2008 00:18:00 +0000</pubDate><atom:updated>2008-02-12T16:26:18.312-08:00</atom:updated><title>W32/Nujama.worm!p2p Peer To Peer Worm Virus.Win32.VB.cy  W32.Nujama W32/Nujama-A</title><description>&lt;span style="font-weight:bold;"&gt;Overview -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;W32/Nujama.worm!p2p is a worm which can propragate through network shares, removable drives and  peer to peer applications.&lt;br /&gt;Aliases&lt;br /&gt;&lt;br /&gt;    * Virus.Win32.VB.cy&lt;br /&gt;&lt;br /&gt;    * W32.Nujama&lt;br /&gt;&lt;br /&gt;    * W32/Nujama-A&lt;br /&gt;&lt;br /&gt;Characteristics&lt;br /&gt;Characteristics -&lt;br /&gt;&lt;br /&gt;W32/Nujama.worm!p2p is a worm which can propragate through network shares, removable drives and  peer to peer applications.&lt;br /&gt;&lt;br /&gt;    * Upon execution, it creates a copy of itself into the Windows system directory:&lt;br /&gt;&lt;br /&gt;    %Windir%\system32\SystemMonitor.exe, %Windir%\system32\ptsnoop.exe, %Windir%\system32\InfoVersion.exe, %Windir%\system32\commpu.exe, %Windir%\system32\call of duty.exe&lt;br /&gt;&lt;br /&gt;    (where %WinDir% is the default Windows directory, for example C:\WINNT, C:\WINDOWS etc.)&lt;br /&gt;&lt;br /&gt;    * Creates the following registry key to hook at system startup:&lt;br /&gt;&lt;br /&gt;     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Sysmon: "%Windir%\system32\SystemMonitor.exe"&lt;br /&gt;&lt;br /&gt;    * Modifies the following registry keys so that a user cannot view hidden files and file extensions.&lt;br /&gt;&lt;br /&gt;    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced&lt;br /&gt;    HideFileExt = "1"&lt;br /&gt;&lt;br /&gt;    * Drops the following files:&lt;br /&gt;&lt;br /&gt;    %Windir%\Web\Desktop.ini&lt;br /&gt;    %Windir%\Web\Folder.htt&lt;br /&gt;    %Windir%\system\oeminfo.ini&lt;br /&gt;&lt;br /&gt;    * Copies itself  into the root folder of all drives(including removable drives and network drives) with filename as as Datos de %Computer_Name%.exe&lt;br /&gt;    * Copies itself to all the subfolders of these drives with filename as %sub_folder%.exe&lt;br /&gt;&lt;br /&gt;    (For instance, it copies itself as WINDOWS.exe in the folder c:\WINDOWS and copies itself as system.exe into the folder c:\WINDOWS\system)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * created registry key as described above&lt;br /&gt;    * created f iles as described above&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The worm may propagate via Peer-to-Peer Networks, network shares and removable drives.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal - &lt;/span&gt;</description><link>http://www.softe.org/2008/02/w32nujamawormp2p-peer-to-peer-worm.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3455734399664724530</guid><pubDate>Tue, 05 Feb 2008 21:27:00 +0000</pubDate><atom:updated>2008-02-05T13:29:22.542-08:00</atom:updated><title>JS/Exploit-YahooGrid datagrid.dll mediagridax.dll buffer overflow vulnerability</title><description>&lt;span style="font-weight:bold;"&gt;Overview -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;JS/Exploit-YahooGrid is a generic detection for YMPDataGrid (datagrid.dll) and YMGMediaGridAx (mediagridax.dll) ActiveX controls buffer overflow vulnerability in Yahoo! Music Jukebox and Yahoo! Messenger.&lt;br /&gt;&lt;br /&gt;The buffer overflow vulnerabilities occurs while supplying a long string to the AddImage, AddButton or AddBitmap functions. This vulnerability could be exploited by a malicious user to cause remote code execution.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This detection is sufficiently generic, such that it can cover a number of threats that contain the exploit code.  Therefore, it is not possible to describe specific symptoms or details about system changes that can occur from this threat.  However, simply seeing this detection does not mean that any exploit code was run at all as such exploit code could only run on a vulnerable system.&lt;br /&gt;&lt;br /&gt;Additionally some exploits simply cause Internet Explorer to crash and nothing more.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This threat could be delivered via an email message, IM or an infectious web page.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.</description><link>http://www.softe.org/2008/02/jsexploit-yahoogrid-datagriddll.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-8671984767852655483</guid><pubDate>Tue, 05 Feb 2008 21:18:00 +0000</pubDate><atom:updated>2008-02-05T13:19:44.942-08:00</atom:updated><title>W32/Tufik virus which infects .exe files</title><description>&lt;span style="font-weight:bold;"&gt;Overview -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;W32/Tufik is virus which infects .exe files. It downloads files from a malicious url.&lt;br /&gt;Characteristics&lt;br /&gt;Characteristics -&lt;br /&gt;&lt;br /&gt;W32/Tufik is virus which infects .exe files.&lt;br /&gt;&lt;br /&gt;Upon execution, it copies itself to %WinDir%\alg.exe, then kills itself.&lt;br /&gt;&lt;br /&gt;It creates the process alg.exe.&lt;br /&gt;&lt;br /&gt;It connects a remote URL to download updated variants of itself and additional malware. The downloaded file is saved as %WinDir%\svchost.exe&lt;br /&gt;&lt;br /&gt;(where %WinDir% is the default Windows directory, for example C:\WINNT, C:\WINDOWS etc.)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;It creates the following registry keys:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\lsass="%WinDir%\alg.exe"&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\svchost="%WinDir%\svchost.exe"&lt;br /&gt;&lt;br /&gt;The virus infects.exe files by prepending itself.&lt;br /&gt;&lt;br /&gt;It can proprogate via network shares or removable drives by infecting the .exe files in the shared folders or in the removable drives.&lt;br /&gt;Symptoms&lt;br /&gt;Symptoms -&lt;br /&gt;&lt;br /&gt;-registry keys added by the virus as described above&lt;br /&gt;&lt;br /&gt;-processes created by the virus as described above&lt;br /&gt;Method of Infection&lt;br /&gt;Method of Infection -&lt;br /&gt;&lt;br /&gt;W32/Tufik is a virus that infects PE and spreads over floppy drive and other removable devices and network shares. It can also be downloaded through another malware or variant.</description><link>http://www.softe.org/2008/02/w32tufik-virus-which-infects-exe-files.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-5511788376995068898</guid><pubDate>Thu, 24 Jan 2008 23:20:00 +0000</pubDate><atom:updated>2008-01-24T15:22:32.220-08:00</atom:updated><title>TROJ_AGENT.HJS malicious Trojan</title><description>This Trojan may be downloaded unknowingly by a user when visiting malicious Web sites.&lt;br /&gt;It drops files also detected by Trend Micro as TROJ_AGENT.HJS.&lt;br /&gt;It creates a registry entry to enable its automatic execution at every system startup.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Solution:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Important Windows ME/XP Cleaning Instructions&lt;br /&gt;&lt;br /&gt;Users running Windows ME and XP must disable System Restore to allow full scanning of infected computers.&lt;br /&gt;&lt;br /&gt;Users running other Windows versions can proceed with the succeeding solution set(s).&lt;br /&gt;&lt;br /&gt;Restarting in Safe Mode&lt;br /&gt;&lt;br /&gt;This malware has characteristics that require the computer to be restarted in safe mode. Go to this page for instructions on how to restart your computer in safe mode.&lt;br /&gt;&lt;br /&gt;Removing Autostart Entry from the Registry&lt;br /&gt;&lt;br /&gt;Removing autostart entries from the registry prevents the malware from executing at startup.&lt;br /&gt;&lt;br /&gt;If the registry entry below is not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.&lt;br /&gt;&lt;br /&gt;   1. Open Registry Editor. Click Start&gt;Run, type REGEDIT, then press Enter.&lt;br /&gt;   2. In the left panel, double-click the following:&lt;br /&gt;      HKEY_CURRENT_USER&gt;Software&gt;Microsoft&gt;&lt;br /&gt;      Windows&gt;CurrentVersion&gt;Run&lt;br /&gt;   3. In the right panel, locate and delete the entry:&lt;br /&gt;      Regscan = "%System%\regscan.exe"&lt;br /&gt;      (Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)&lt;br /&gt;   4. Close Registry Editor.</description><link>http://www.softe.org/2008/01/trojagenthjs-malicious-trojan.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-2518195636789703081</guid><pubDate>Thu, 24 Jan 2008 23:19:00 +0000</pubDate><atom:updated>2008-01-24T15:20:09.752-08:00</atom:updated><title>WORM_IMBOT.AC  memory resident worm malware</title><description>This memory-resident worm may be dropped by other malware or downloaded unknowingly by a user when visiting malicious Web sites.&lt;br /&gt;&lt;br /&gt;It propagates via the popular instant messaging application, MSN Messenger. It does this by sending a message and a .ZIP file that contains a copy of itself to target contacts.&lt;br /&gt;&lt;br /&gt;The message it sends may be any of the following:&lt;br /&gt;&lt;br /&gt;• Did you see this picture, it's hilarious!!!!!&lt;br /&gt;• Have I shown you this new picture of my cat :)&lt;br /&gt;• Hey, check out this great photo from my trip to England&lt;br /&gt;&lt;br /&gt;This worm also has backdoor capabilities. It connects to random TCP ports and executes the commands from a remote malicious user. It also terminates certain processes, if found running in memory.</description><link>http://www.softe.org/2008/01/wormimbotac-memory-resident-worm.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-54865865800358777</guid><pubDate>Thu, 24 Jan 2008 23:16:00 +0000</pubDate><atom:updated>2008-01-24T15:19:13.752-08:00</atom:updated><title>SYMBOS_BESELO.A Malware Alert</title><description>This Symbian malware infects mobile devices running Symbian OS/S60 2nd Edition.&lt;br /&gt;&lt;br /&gt;It drops a file also detected by Trend Micro as SYMBOS_BESELO.A. It also drops two other non-malicious files.&lt;br /&gt;&lt;br /&gt;It spreads via Multimedia Messaging Service (MMS) messages. It creates an MMS message with an attached copy of the .SIS installer. These MMS messages contain a copy of the malware.&lt;br /&gt;&lt;br /&gt;This Symbian malware also spreads via Bluetooth-enabled mobile phones. It arrives as a .SIS file, using certain file names.</description><link>http://www.softe.org/2008/01/symbosbeseloa-malware-alert.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-7450101180085995811</guid><pubDate>Wed, 09 Jan 2008 11:06:00 +0000</pubDate><atom:updated>2008-01-09T03:09:47.419-08:00</atom:updated><title>GPCoder.h Trojan Win32 ransomware trojan</title><description>This is a detection for a ransomware trojan.  It encrypts files on the harddrive, creates a text-file indicating what has happened, and gives email addresses to send the ransom money to.&lt;br /&gt;Aliases&lt;br /&gt;&lt;br /&gt;    * Backdoor:Win32/Kollah.D (Microsoft)&lt;br /&gt;&lt;br /&gt;    * TSPY_KOLLAH.F (TrendMicro)&lt;br /&gt;&lt;br /&gt;    * Virus.Win32.Gpcode.ai (Kaspersky)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Characteristics&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-- Update July 17, 2007 --&lt;br /&gt;The risk assessment of this threat has been updated to Low-Profiled due to media attention at:&lt;br /&gt;&lt;br /&gt;This trojan encrypts documents, depending on the file extension, and then attempts to extort money from the victim in order for them to obtain a decryptor tool to recover the documents.&lt;br /&gt;&lt;br /&gt;When run this trojan searches for files using the following extensions:&lt;br /&gt;&lt;br /&gt;    * .12m&lt;br /&gt;    * .3ds&lt;br /&gt;    * .3dx&lt;br /&gt;    * .4ge&lt;br /&gt;    * .4gl&lt;br /&gt;    * .7z&lt;br /&gt;    * .a&lt;br /&gt;    * .a86&lt;br /&gt;    * .abc&lt;br /&gt;    * .acd&lt;br /&gt;    * .ace&lt;br /&gt;    * .act&lt;br /&gt;    * .ada&lt;br /&gt;    * .adi&lt;br /&gt;    * .aex&lt;br /&gt;    * .af3&lt;br /&gt;    * .afd&lt;br /&gt;    * .ag4&lt;br /&gt;    * .ai&lt;br /&gt;    * .aif&lt;br /&gt;    * .aifc&lt;br /&gt;    * .aiff&lt;br /&gt;    * .ain&lt;br /&gt;    * .aio&lt;br /&gt;    * .ais&lt;br /&gt;    * .akf&lt;br /&gt;    * .alv&lt;br /&gt;    * .amp&lt;br /&gt;    * .ans&lt;br /&gt;    * .ap&lt;br /&gt;    * .apa&lt;br /&gt;    * .apo&lt;br /&gt;    * .app&lt;br /&gt;    * .arc&lt;br /&gt;    * .arh&lt;br /&gt;    * .arj&lt;br /&gt;    * .arx&lt;br /&gt;    * .asc&lt;br /&gt;    * .asm&lt;br /&gt;    * .ask&lt;br /&gt;    * .au&lt;br /&gt;    * .bak&lt;br /&gt;    * .bas&lt;br /&gt;    * .bb&lt;br /&gt;    * .bcb&lt;br /&gt;    * .bcp&lt;br /&gt;    * .bdb&lt;br /&gt;    * .bh&lt;br /&gt;    * .bib&lt;br /&gt;    * .bpr&lt;br /&gt;    * .bsa&lt;br /&gt;    * .btr&lt;br /&gt;    * .bup&lt;br /&gt;    * .bwb&lt;br /&gt;    * .bz&lt;br /&gt;    * .bz2&lt;br /&gt;    * .c&lt;br /&gt;    * .c86&lt;br /&gt;    * .cac&lt;br /&gt;    * .cbl&lt;br /&gt;    * .cc&lt;br /&gt;    * .cdb&lt;br /&gt;    * .cdr&lt;br /&gt;    * .cgi&lt;br /&gt;    * .cmd&lt;br /&gt;    * .cnt&lt;br /&gt;    * .cob&lt;br /&gt;    * .col&lt;br /&gt;    * .cpp&lt;br /&gt;    * .cpt&lt;br /&gt;    * .crp&lt;br /&gt;    * .cru&lt;br /&gt;    * .csc&lt;br /&gt;    * .css&lt;br /&gt;    * .csv&lt;br /&gt;    * .ctx&lt;br /&gt;    * .cvs&lt;br /&gt;    * .cwb&lt;br /&gt;    * .cwk&lt;br /&gt;    * .cxe&lt;br /&gt;    * .cxx&lt;br /&gt;    * .cyp&lt;br /&gt;    * .d&lt;br /&gt;    * .db&lt;br /&gt;    * .db0&lt;br /&gt;    * .db1&lt;br /&gt;    * .db2&lt;br /&gt;    * .db3&lt;br /&gt;    * .db4&lt;br /&gt;    * .dba&lt;br /&gt;    * .dbb&lt;br /&gt;    * .dbc&lt;br /&gt;    * .dbd&lt;br /&gt;    * .dbe&lt;br /&gt;    * .dbf&lt;br /&gt;    * .dbk&lt;br /&gt;    * .dbm&lt;br /&gt;    * .dbo&lt;br /&gt;    * .dbq&lt;br /&gt;    * .dbt&lt;br /&gt;    * .dbx&lt;br /&gt;    * .dfm&lt;br /&gt;    * .djvu&lt;br /&gt;    * .dic&lt;br /&gt;    * .dif&lt;br /&gt;    * .dm&lt;br /&gt;    * .dmd&lt;br /&gt;    * .doc&lt;br /&gt;    * .dok&lt;br /&gt;    * .dot&lt;br /&gt;    * .dox&lt;br /&gt;    * .dsc&lt;br /&gt;    * .dwg&lt;br /&gt;    * .dxf&lt;br /&gt;    * .dxr&lt;br /&gt;    * .eps&lt;br /&gt;    * .exp&lt;br /&gt;    * .f&lt;br /&gt;    * .fas&lt;br /&gt;    * .fax&lt;br /&gt;    * .fdb&lt;br /&gt;    * .fla&lt;br /&gt;    * .flb&lt;br /&gt;    * .frm&lt;br /&gt;    * .fm&lt;br /&gt;    * .fox&lt;br /&gt;    * .frm&lt;br /&gt;    * .frt&lt;br /&gt;    * .frx&lt;br /&gt;    * .fsl&lt;br /&gt;    * .gtd&lt;br /&gt;    * .gif&lt;br /&gt;    * .gz&lt;br /&gt;    * .gzip&lt;br /&gt;    * .h&lt;br /&gt;    * .ha&lt;br /&gt;    * .hh&lt;br /&gt;    * .hjt&lt;br /&gt;    * .hog&lt;br /&gt;    * .hpp&lt;br /&gt;    * .htm&lt;br /&gt;    * .html&lt;br /&gt;    * .htx&lt;br /&gt;    * .ice&lt;br /&gt;    * .icf&lt;br /&gt;    * .inc&lt;br /&gt;    * .ish&lt;br /&gt;    * .iso&lt;br /&gt;    * .jar&lt;br /&gt;    * .jad&lt;br /&gt;    * .java&lt;br /&gt;    * .jpg&lt;br /&gt;    * .jpeg&lt;br /&gt;    * .js&lt;br /&gt;    * .jsp&lt;br /&gt;    * .key&lt;br /&gt;    * .kwm&lt;br /&gt;    * .lst&lt;br /&gt;    * .lwp&lt;br /&gt;    * .lzh&lt;br /&gt;    * .lzs&lt;br /&gt;    * .lzw&lt;br /&gt;    * .ma&lt;br /&gt;    * .mak&lt;br /&gt;    * .man&lt;br /&gt;    * .maq&lt;br /&gt;    * .mar&lt;br /&gt;    * .mbx&lt;br /&gt;    * .mdb&lt;br /&gt;    * .mdf&lt;br /&gt;    * .mid&lt;br /&gt;    * .mo&lt;br /&gt;    * .myd&lt;br /&gt;    * .obj&lt;br /&gt;    * .old&lt;br /&gt;    * .p12&lt;br /&gt;    * .pak&lt;br /&gt;    * .pas&lt;br /&gt;    * .pdf&lt;br /&gt;    * .pem&lt;br /&gt;    * .pfx&lt;br /&gt;    * .php&lt;br /&gt;    * .php3&lt;br /&gt;    * .php4&lt;br /&gt;    * .pgp&lt;br /&gt;    * .pkr&lt;br /&gt;    * .pl&lt;br /&gt;    * .pm3&lt;br /&gt;    * .pm4&lt;br /&gt;    * .pm5&lt;br /&gt;    * .pm6&lt;br /&gt;    * .png&lt;br /&gt;    * .ppt&lt;br /&gt;    * .pps&lt;br /&gt;    * .prf&lt;br /&gt;    * .prx&lt;br /&gt;    * .ps&lt;br /&gt;    * .psd&lt;br /&gt;    * .pst&lt;br /&gt;    * .pw&lt;br /&gt;    * .pwa&lt;br /&gt;    * .pwl&lt;br /&gt;    * .pwm&lt;br /&gt;    * .pwp&lt;br /&gt;    * .pxl&lt;br /&gt;    * .py&lt;br /&gt;    * .rar&lt;br /&gt;    * .res&lt;br /&gt;    * .rle&lt;br /&gt;    * .rmr&lt;br /&gt;    * .rnd&lt;br /&gt;    * .rtf&lt;br /&gt;    * .safe&lt;br /&gt;    * .sar&lt;br /&gt;    * .skr&lt;br /&gt;    * .sln&lt;br /&gt;    * .swf&lt;br /&gt;    * .sql&lt;br /&gt;    * .tar&lt;br /&gt;    * .tbb&lt;br /&gt;    * .tex&lt;br /&gt;    * .tga&lt;br /&gt;    * .tgz&lt;br /&gt;    * .tif&lt;br /&gt;    * .tiff&lt;br /&gt;    * .txt&lt;br /&gt;    * .vb&lt;br /&gt;    * .vp&lt;br /&gt;    * .wps&lt;br /&gt;    * .xcr&lt;br /&gt;    * .xls&lt;br /&gt;    * .xml&lt;br /&gt;    * .zip &lt;br /&gt;&lt;br /&gt;Found documents are encoded and a text file named read_me.txt is placed in the directory containing the following text:&lt;br /&gt;&lt;br /&gt;    Hello,    your   files   are   encrypted   with   RSA-4096   algorithm&lt;br /&gt;    (http://en.wikipedia.org/wiki/RSA).&lt;br /&gt;    You  will  need  at least few years to decrypt these files without our&lt;br /&gt;    software.  All  your  private  information  for  last  3  months  were&lt;br /&gt;    collected and sent to us.&lt;br /&gt;    To decrypt your files you need to buy our software. The price is $300.&lt;br /&gt;    To  buy  our software please contact us at: %s and provide us&lt;br /&gt;    your  personal code %d. After successful purchase we will send&lt;br /&gt;    your  decrypting  tool,  and  your private information will be deleted&lt;br /&gt;    from our system.&lt;br /&gt;    If  you  will not contact us until 07/15/2007 your private information&lt;br /&gt;    will be shared and you will lost all your data.&lt;br /&gt;    Glamorous team&lt;br /&gt;&lt;br /&gt;The following registry key is created to run itself at Windows login:&lt;br /&gt;# HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion&lt;br /&gt;\winlogon\userinit = "%SysDir%\userinit.exe, %SysDir%\ntos.exe,"&lt;br /&gt;&lt;br /&gt;(Where SysDir is the Windows System directory, e.g. C:\Windows\System32)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Symptoms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * File types mentioned previously, overwritten with "garbage" (encrypted data).&lt;br /&gt;    * Presence of aforementioned read_me.txt files.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Method of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.</description><link>http://www.softe.org/2008/01/gpcoderh-trojan-win32-ransomware-trojan.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3804805945235727063</guid><pubDate>Wed, 05 Dec 2007 17:48:00 +0000</pubDate><atom:updated>2007-12-05T09:52:40.804-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Microsoft</category><title>The next generation of security threats, Microsoft</title><description>REDMOND, Wash.--Microsoft security engineer Robert Hensing had a question for the hundreds of his company's developers seated before him: can a person's PC become infected with a rootkit simply by opening a PowerPoint file?&lt;br /&gt;&lt;br /&gt;In the packed conference center, a smattering of developers raise their hands. Nearby, in an adjacent room, where hackers invited to speak at Microsoft's Blue Hat conference watch the presentations on TV, an entire table of hands go up.&lt;br /&gt;&lt;br /&gt;"That's one thing I want you to take away from this," Hensing tells the Microsoft developers. "Applications are dangerous."&lt;br /&gt;"We're attacking today's problems. We certainly have to do that. We also need to get ahead."&lt;br /&gt;--Matt Thomlinson, head of security engineering efforts, Microsoft&lt;br /&gt;&lt;br /&gt;Indeed, even though Microsoft has spent a fortune securing Windows, experts say that hackers are moving beyond the operating system. Threats such as rootkits, which can corrupt an operating system, can now be transferred by applications or Web-based programs. A new crop of Web-connected mobile devices represent another emerging threat.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.softe.org/uploaded_images/Andrew-bug-711883.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://www.softe.org/uploaded_images/Andrew-bug-711881.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;"Operating system vulnerabilities are on the decline," Hensing said in his talk at the most recent Blue Hat security conference in September. "Application vulnerabilities are on the rise."&lt;br /&gt;&lt;br /&gt;In part, Microsoft is something of a victim of its own success in securing Vista and Windows XP before it. Halvar Flake, a security researcher who attended the latest Blue Hat, estimates the total cost of Microsoft's years-long security push at more than $1 billion, with a significant chunk spent on Vista. George Stathakopoulos, a general manager in Microsoft's security unit, wouldn't say how much Microsoft has spent, but said that it's "a big number."&lt;br /&gt;&lt;br /&gt;Flake, CEO of security firm Zynamics, said that all of that spending has paid off. "Vista is the most difficult mainstream OS to break into that I've ever seen," he said. Because it is harder to hack, it is more expensive for criminals to target.&lt;br /&gt;&lt;br /&gt;Paradoxically, it's not clear that Vista's improved security is persuading people to move to the operating system any faster. "Security is a tough sell, really," Flake said. "Customers can't really measure it."&lt;br /&gt;&lt;br /&gt;Vista's security is likely making life more difficult for hackers. Flake said the malicious side of him "would hope Vista is a huge flop" and, as a result, that no company ever spends that kind of money and effort securing an operating system.&lt;br /&gt;&lt;br /&gt;The true measure of the effectiveness of Vista's new security likely won't be measured for years. Microsoft and other vendors often tout how their newest releases have many fewer flaws than previous versions. That's usually true, but it's only part of the picture. Most of the major operating system vendors have seen their total number of vulnerabilities rise since 2004. New operating systems tend to have fewer flaws upon release, but operating systems live for five to seven years.&lt;br /&gt;&lt;br /&gt;As a result, operating system makers try to design products to withstand the types of attacks their software may face toward the middle and end of its life--when operating systems are most heavily adopted.&lt;br /&gt;&lt;br /&gt;"We're attacking today's problems," said Matt Thomlinson who heads Microsoft's security engineering efforts. "We certainly have to do that. We also need to get ahead."&lt;br /&gt;&lt;br /&gt;The attacks themselves, meanwhile, have grown increasingly targeted. From the mass mailers, to broad phishing scams, to more recent attacks aimed at individuals. Experts expect that trend to continue, with malicious software growing ever more evasive.&lt;br /&gt;&lt;br /&gt;Malicious software getting more complex&lt;br /&gt;This year marks a turning point, according a report this week from Cisco Systems-owned IronPort Systems. "For a time, security controls designed to manage malware were working," said Tom Gillis, vice president of marketing for IronPort. "Just when malware design seemed to have reached a plateau, new attack techniques have burst forth, some so complex--and obviously not the work of amateurs--they could have only been designed by means of sophisticated research and development."&lt;br /&gt;Photos: Microsoft's bug hunters&lt;br /&gt;&lt;br /&gt;Modern malicious software, IronPort suggests, borrows many characteristics from today's social-networking sites. They are collaborative and adaptive. Plus, the company said, they fly under the radar, "living on enterprise or residential PCs for months or years without detection."&lt;br /&gt;&lt;br /&gt;IronPort sees Trojan horses and malicious software becoming "increasingly targeted and short-lived," which will make them still harder to spot.&lt;br /&gt;&lt;br /&gt;Layered atop that trend is the rise of new attacks that target software applications. While there are only a handful of major operating systems, there are literally thousands of applications, some used by millions of people.&lt;br /&gt;&lt;br /&gt;Microsoft has spent significant time and money on securing its applications. After the experience of Slammer, for example, the company's SQL Server database became a model within the company for how to adopt secure development. Security researcher Dan Kaminsky, who has also attended Blue Hat and done a significant amount of security consulting for Microsoft, said that SQL Server has made significant gains over Oracle thanks to those improved practices.&lt;br /&gt;&lt;br /&gt;The Office team, too, has taken note of the fact that its documents are frequently targeted as means for an attack. One of the less-discussed reasons for Office's new XML file formats, in fact, is that they are designed from scratch to be more secure, according to Microsoft.</description><link>http://www.softe.org/2007/12/next-generation-of-security-threats.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-7226950351606167784</guid><pubDate>Wed, 28 Nov 2007 17:26:00 +0000</pubDate><atom:updated>2007-11-28T09:26:50.103-08:00</atom:updated><title>Trojan.Win32.StartPage.jo</title><description>&lt;span style="font-weight:bold;"&gt;Aliases&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Trojan.Win32.StartPage.jo&lt;/span&gt; (Kaspersky Lab) is also known as: StartPage-AI.gen (McAfee),   Trojan.StartPage (Symantec),   Trojan.StartPage.350 (Doctor Web),   Trojan:Win32/StartPage.EZ (RAV),   TROJ_STARTPAG.JO (Trend Micro),   TR/OLCheck.2 (H+BEDV),   Win32:Trojan-gen. (ALWIL),   Startpage.6.AR (Grisoft),   Trojan.StartPage.EZ (SOFTWIN),   Trojan.Startpage.gen-11 (ClamAV),   Trj/StartPage.HE (Panda),   Win32/StartPage.JO (Eset)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Description added  Nov 23 2007&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Behavior  &lt;/span&gt;Trojan&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Technical details&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This Trojan has a malicious payload. It is a Windows PE EXE file. It is 11776 bytes in size. It is packed using UPX. The unpacked file is approximately 48KB in size. It is written in Delphi.&lt;br /&gt;Payload&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Once launched, the Trojan will:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;   1. modify the following system registry key values:&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;      "Start Page" = "http://www.find-online.net/index.htm"&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;      "Use Search Asst" = "yes"&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;      "Search Page" = "http://www.find-online.net/index.htm"&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;      "Search Bar" = "http://www.find-online.net/sp.htm"&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\SearchURL]&lt;br /&gt;      "Default" = "http://www.find-online.net/index.htm"&lt;br /&gt;      [HKCU\Software\Microsoft\Internet Explorer\SearchURL]&lt;br /&gt;      "provider" = "gog1"&lt;br /&gt;      [HKLM\Software\Microsoft\Internet Explorer\Search]&lt;br /&gt;      "SearchAssistant" = "http://www.find-online.net/sp.htm"&lt;br /&gt;&lt;br /&gt;      These changes modify the configuration of Internet Explorer.&lt;br /&gt;   2. create the following registry key:&lt;br /&gt;      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;      "ziphelp" = "%WinDir%\ziphelp.exe"&lt;br /&gt;&lt;br /&gt;      This will cause "%WinDir%\ziphelp.exe" to be launched each time the system is started, assuming that such a file is present on the victim machine&lt;br /&gt;   3. create the following shortcuts in the current user's Favorites folder:&lt;br /&gt;      %USERPROFILE%\Favorites\FINDONLINE.net&lt;br /&gt;      %USERPROFILE%\Favorites\Free PORN Ezines&lt;br /&gt;      %USERPROFILE%\Favorites\Free PORN Tickets&lt;br /&gt;      %USERPROFILE%\Favorites\PORN FINDONLINE.net&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Breast Enlargement Pills&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Penis Enlargement Pills&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Sex Toys&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Sexual Enhancers&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Single Girls&lt;br /&gt;      %USERPROFILE%\Favorites\Adult\Swinger Clubs&lt;br /&gt;      %USERPROFILE%\Favorites\Health\Fitness&lt;br /&gt;      %USERPROFILE%\Favorites\Health\Human Growth Hormone&lt;br /&gt;      %USERPROFILE%\Favorites\Health\Men Health&lt;br /&gt;      %USERPROFILE%\Favorites\Health\Weight Loss&lt;br /&gt;      %USERPROFILE%\Favorites\Health\Women Health&lt;br /&gt;      %USERPROFILE%\Favorites\Insurance\Auto Insurance&lt;br /&gt;      %USERPROFILE%\Favorites\Insurance\Business Insurance&lt;br /&gt;      %USERPROFILE%\Favorites\Insurance\Health Insurance&lt;br /&gt;      %USERPROFILE%\Favorites\Insurance\Home Insurance&lt;br /&gt;      %USERPROFILE%\Favorites\Insurance\Travel Insurance&lt;br /&gt;      %USERPROFILE%\Favorites\Internet\Antivirus&lt;br /&gt;      %USERPROFILE%\Favorites\Internet\Internet Businesses&lt;br /&gt;      %USERPROFILE%\Favorites\Internet\Spyware Remover&lt;br /&gt;      %USERPROFILE%\Favorites\Internet\Web Hosting&lt;br /&gt;      %USERPROFILE%\Favorites\Internet\Web Site Design&lt;br /&gt;      %USERPROFILE%\Favorites\Online Games\Black Jack&lt;br /&gt;      %USERPROFILE%\Favorites\Online Games\Craps&lt;br /&gt;      %USERPROFILE%\Favorites\Online Games\Online Casinos&lt;br /&gt;      %USERPROFILE%\Favorites\Online Games\Poker&lt;br /&gt;      %USERPROFILE%\Favorites\Online Games\Roulette&lt;br /&gt;      %USERPROFILE%\Favorites\Online Pharmacy\Hydrocodone&lt;br /&gt;      %USERPROFILE%\Favorites\Online Pharmacy\Online Pharmacy&lt;br /&gt;      %USERPROFILE%\Favorites\Online Pharmacy\Prozac&lt;br /&gt;      %USERPROFILE%\Favorites\Online Pharmacy\Valium&lt;br /&gt;      %USERPROFILE%\Favorites\Online Pharmacy\Viagra Online&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;      The Trojan then ceases running.&lt;br /&gt;      Removal instructions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;      If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;         1. Use Task Manager to terminate the Trojan process.&lt;br /&gt;         2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).&lt;br /&gt;         3. Revert the following system registry key values:&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;            "Start Page" = "http://www.find-online.net/index.htm"&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;            "Use Search Asst" = "yes"&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;            "Search Page" = "http://www.find-online.net/index.htm"&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\Main]&lt;br /&gt;            "Search Bar" = "http://www.find-online.net/sp.htm"&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\SearchURL]&lt;br /&gt;            "Default" = "http://www.find-online.net/index.htm"&lt;br /&gt;            [HKCU\Software\Microsoft\Internet Explorer\SearchURL]&lt;br /&gt;            "provider" = "gog1"&lt;br /&gt;            [HKLM\Software\Microsoft\Internet Explorer\Search]&lt;br /&gt;            "SearchAssistant" = "http://www.find-online.net/sp.htm"&lt;br /&gt;         4. Delete the following registry key:&lt;br /&gt;            [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;            "ziphelp" = "%WinDir%\ziphelp.exe"&lt;br /&gt;         5. Delete all shortcuts created by the Trojan.&lt;br /&gt;            %USERPROFILE%\Favorites\FINDONLINE.net&lt;br /&gt;            %USERPROFILE%\Favorites\Free PORN Ezines&lt;br /&gt;            %USERPROFILE%\Favorites\Free PORN Tickets&lt;br /&gt;            %USERPROFILE%\Favorites\PORN FINDONLINE.net&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Breast Enlargement Pills&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Penis Enlargement Pills&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Sex Toys&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Sexual Enhancers&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Single Girls&lt;br /&gt;            %USERPROFILE%\Favorites\Adult\Swinger Clubs&lt;br /&gt;            %USERPROFILE%\Favorites\Health\Fitness&lt;br /&gt;            %USERPROFILE%\Favorites\Health\Human Growth Hormone&lt;br /&gt;            %USERPROFILE%\Favorites\Health\Men Health&lt;br /&gt;            %USERPROFILE%\Favorites\Health\Weight Loss&lt;br /&gt;            %USERPROFILE%\Favorites\Health\Women Health&lt;br /&gt;            %USERPROFILE%\Favorites\Insurance\Auto Insurance&lt;br /&gt;            %USERPROFILE%\Favorites\Insurance\Business Insurance&lt;br /&gt;            %USERPROFILE%\Favorites\Insurance\Health Insurance&lt;br /&gt;            %USERPROFILE%\Favorites\Insurance\Home Insurance&lt;br /&gt;            %USERPROFILE%\Favorites\Insurance\Travel Insurance&lt;br /&gt;            %USERPROFILE%\Favorites\Internet\Antivirus&lt;br /&gt;            %USERPROFILE%\Favorites\Internet\Internet Businesses&lt;br /&gt;            %USERPROFILE%\Favorites\Internet\Spyware Remover&lt;br /&gt;            %USERPROFILE%\Favorites\Internet\Web Hosting&lt;br /&gt;            %USERPROFILE%\Favorites\Internet\Web Site Design&lt;br /&gt;            %USERPROFILE%\Favorites\Online Games\Black Jack&lt;br /&gt;            %USERPROFILE%\Favorites\Online Games\Craps&lt;br /&gt;            %USERPROFILE%\Favorites\Online Games\Online Casinos&lt;br /&gt;            %USERPROFILE%\Favorites\Online Games\Poker&lt;br /&gt;            %USERPROFILE%\Favorites\Online Games\Roulette&lt;br /&gt;            %USERPROFILE%\Favorites\Online Pharmacy\Hydrocodone&lt;br /&gt;            %USERPROFILE%\Favorites\Online Pharmacy\Online Pharmacy&lt;br /&gt;            %USERPROFILE%\Favorites\Online Pharmacy\Prozac&lt;br /&gt;            %USERPROFILE%\Favorites\Online Pharmacy\Valium&lt;br /&gt;            %USERPROFILE%\Favorites\Online Pharmacy\Viagra Online</description><link>http://www.softe.org/2007/11/trojanwin32startpagejo.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3967941556926885359</guid><pubDate>Tue, 13 Nov 2007 06:23:00 +0000</pubDate><atom:updated>2007-11-12T22:23:42.559-08:00</atom:updated><title>Virus Profile: PWS-Banker.gen.ak</title><description>Virus Profile: PWS-Banker.gen.ak&lt;br /&gt;Risk Assessment   &lt;br /&gt;  - Home Users:  Low&lt;br /&gt;  - Corporate Users:  Low&lt;br /&gt;Date Discovered:  11/12/2007&lt;br /&gt;Date Added:  11/12/2007&lt;br /&gt;Origin:  Unknown&lt;br /&gt;Length:  N/A&lt;br /&gt;Type:  Virus&lt;br /&gt;SubType:  Generic&lt;br /&gt;DAT Required:  5161</description><link>http://www.softe.org/2007/11/virus-profile-pws-bankergenak.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-5767929670980751899</guid><pubDate>Tue, 13 Nov 2007 06:09:00 +0000</pubDate><atom:updated>2007-11-12T22:21:52.034-08:00</atom:updated><title>Virus Profile: W32/Sdbot.worm.gen.z</title><description>&lt;span style="font-weight:bold;"&gt;Recent Threats&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Risk Assessment   &lt;/span&gt; &lt;br /&gt;  - Home Users:  Low&lt;br /&gt;  - Corporate Users:  Low&lt;br /&gt;Date Discovered:  12/15/2004&lt;br /&gt;Date Added:  9/22/2004&lt;br /&gt;Origin:  N/A&lt;br /&gt;Length:  Varies&lt;br /&gt;Type:  Virus&lt;br /&gt;SubType:  Generic Worm&lt;br /&gt;DAT Required:  4394&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Virus Characteristics&lt;/span&gt;&lt;br /&gt;Due to the large volume of members of this virus family, the size of extra.dats required to detect these is very large. AVERT have therefore split the detection into multiple drivers although the behavior of all members is broadly similar.&lt;br /&gt;&lt;br /&gt;Please review the W32/Sdbot.worm.gen description.&lt;br /&gt;&lt;br /&gt;The W32/Sdbot.worm.gen.z exhibits the following behavior:&lt;br /&gt;&lt;br /&gt;    * The worm file is eXPressor protected&lt;br /&gt;    * Mlqm.exe process will listen for TCP communication on port 3032&lt;br /&gt;    * Issues a DNS query to the following domain: r3x.ma7d.com&lt;br /&gt;&lt;br /&gt;Files Added&lt;br /&gt;&lt;br /&gt;    * %WINDIR%\system32\dllcache\mlqm.exe&lt;br /&gt;&lt;br /&gt;The worm attempts communication with a server for further instructions. A remote attacker can use the worm to perform various tasks:&lt;br /&gt;&lt;br /&gt;Gather system information (CPU, Driver Space, RAM, OS Version, User name, Computer name, IP Address)&lt;br /&gt;SYN Flood others&lt;br /&gt;Kill processes&lt;br /&gt;Download files&lt;br /&gt;Execute files&lt;br /&gt;&lt;br /&gt;At the time this was analyzed the worm attempted to SYN Flood various addresses provided by the server.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Indications of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Presence of %WINDIR%\system32\dllcache\mlqm.exe&lt;br /&gt;&lt;br /&gt;Unexpected TCP communication on port 3032&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Method of Infection&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The exact method of propagation will vary between variants. However, the following characteristics are typical:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Share Propagation&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    *&lt;br /&gt;      The worm propagates via accessible or poorly-secured network shares, and some variants are intended to take advantage of high profile exploits:&lt;br /&gt;    * DCOM RPC vulnerability (MS03-026) -http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx&lt;br /&gt;    * LSASS vulnerability (MS04-011) - http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal Instructions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;All Users:&lt;br /&gt;Use current engine and DAT files for detection and removal.&lt;br /&gt;&lt;br /&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).</description><link>http://www.softe.org/2007/11/virus-profile-w32sdbotwormgenz.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-8802512775796535109</guid><pubDate>Thu, 08 Nov 2007 21:25:00 +0000</pubDate><atom:updated>2007-11-08T13:34:58.085-08:00</atom:updated><title>WordPress founder looks into blogging's future</title><description>LAS VEGAS, Nev.--If you type "Matt" into the Google search bar, you won't immediately get results for the actor Matt Damon or the political site owner Matt Drudge, as you might expect.&lt;br /&gt;&lt;br /&gt;Instead, the No. 1 listing points to the site of Matt Mullenweg, the 23-year-old founder of WordPress, the widely used open-source software for blogging.&lt;br /&gt;&lt;br /&gt;Befitting his Google ranking, Mullenweg could be considered a superstar here at the BlogWorld conference, where he spoke to hundreds of attendees Thursday about how he started WordPress and the future of blogging. To be sure, when people in the audience were asked if they use WordPress for their personal blogs, a unanimous show of hands went up. Everyone from political to bowling bloggers seemed eager to get Mullenweg's advice on the art of the craft--and how to make money from it.&lt;br /&gt;&lt;br /&gt;Mullenweg offered simple pearls of wisdom about what makes a blog compelling.&lt;br /&gt;&lt;br /&gt;"One universal about blogging is a lot like music: You have to be unique and you have to absolutely love what you're doing," he said.&lt;br /&gt;&lt;br /&gt;Mullenweg started developing WordPress while he was still in college; and he worked on it over several years, including while at CNET, publisher of News.com. Once he left CNET in late 2005, he started the business behind WordPress, called Automattic, which sells blog hosting services and an anti-spam application.&lt;br /&gt;&lt;br /&gt;Now, the site draws roughly 100 million unique monthly visitors and is among the top 25 global sites, according to research firm Comscore.&lt;br /&gt;&lt;br /&gt;Still, WordPress and Automattic only have 18 employees and they operate from a small investment made in the company more than two years ago, Mullenweg said. How do they fulfill all that demand with 18 people? "Lots of caffeine," he said.&lt;br /&gt;&lt;br /&gt;When asked about the future of his business, he answered that he likes the Craigslist model, which as a company has stayed relatively small and does not accept advertising. But he said that he believes there's a way to incorporate ads that are tasteful.&lt;br /&gt;&lt;br /&gt;"I would like to stay small but logistically we need many more people on the support side."&lt;br /&gt;&lt;br /&gt;Blogs are also one tier in the frenzied social media industry that encompasses Facebook and others. Asked how his software meshes with sites like Facebook, he said he'd like to see more incorporation between the two. Because ultimately, he said, blogs are more telling of a person's personality. That's why he believes Wordpress will become a more popular social network platform, allowing people to post things like widgets of their Facebook profile on a blog or vice versa.&lt;br /&gt;&lt;br /&gt;"The software is getting smaller, faster and lighter but what you can do with it is going up," he said.&lt;br /&gt;&lt;br /&gt;In the grand scheme of things, Mullenweg said he wants the future of the Web to be open source; and he hopes to get more people using open source platforms to write their blogs, even if it's not WordPress.&lt;br /&gt;&lt;br /&gt;But he's obviously driven competitively, too. (His blog ranks No. 1 on Google because of all the links back to his site from WordPress.) He recently saw a survey from Google, in which the search giant examined all of the http headers of Web. He found that .8 percent of those pages were powered by WordPress.&lt;br /&gt;&lt;br /&gt;"That's how far we've come, but we have a lot of work to do," he said.</description><link>http://www.softe.org/2007/11/wordpress-founder-looks-into-bloggings.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1767070242685705307</guid><pubDate>Tue, 06 Nov 2007 19:25:00 +0000</pubDate><atom:updated>2007-11-06T11:50:39.226-08:00</atom:updated><title>Exploit posted for Viewpoint Media Player flaw</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.softe.org/uploaded_images/viewpoint-729642.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://www.softe.org/uploaded_images/viewpoint-729639.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Exploit code for an unpatched vulnerability in the widely distributed Viewpoint Media Player has been posted on the Internet, putting millions of Internet Explorer users at risk of code execution attacks.&lt;br /&gt;The exploit, available at Milw0rm.com, takes advantage of a stack-based buffer overflow in the Viewpoint browser plug-in that sits on millions of computers thanks to bundling deals with AOL, AIM, Netscape and Adobe.&lt;br /&gt;&lt;br /&gt;The player serves as the graphics engine for AOL Instant Greetings, AIM Themes and other popular web applications and is also used to power product tours for the Toyota 4Runner and Sony laptop, desktop, and server computing products.&lt;br /&gt;&lt;br /&gt;According to “Shinnai,” the hacker who discovered the flaw, the exploit was tested on a fully-patched Windows XP Professional SP2 with Internet Explorer 7.&lt;br /&gt;&lt;br /&gt;The bug was found in the xMetaStream.dll (version 3.3.2.26), which is marked as safe for scripting.&lt;br /&gt;&lt;br /&gt;The AxMetaStream activex contains various methods which accept parameters as String. All these methods are vulnerable to a stack based buffer overflow when you pass an overly long (greater than 6999 characters).&lt;br /&gt;&lt;br /&gt;In the absense of a patch, Shinnai recommends uninstalling the Viewpoint Media Player.&lt;br /&gt;&lt;br /&gt;“Shinnai” was the hacker behind the Month of ActiveX Bugs project.</description><link>http://www.softe.org/2007/11/exploit-posted-for-viewpoint-media.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1224388645987728926</guid><pubDate>Sun, 04 Nov 2007 22:48:00 +0000</pubDate><atom:updated>2007-11-04T14:50:59.101-08:00</atom:updated><title>Bogus FTC e-mail has virus</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.softe.org/uploaded_images/email-virus-752856.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://www.softe.org/uploaded_images/email-virus-752853.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;The Federal Trade Commission, which has declared war on Internet scams, warned consumers on Monday not to open a bogus e-mail that appears to come from its fraud department because it carries an attachment that can download a virus.&lt;br /&gt;The e-mail says it is from "frauddep@ftc.gov" and has the FTC's government seal.&lt;br /&gt;&lt;br /&gt;But it was not issued by the agency and has attachments and links that will download a virus that could steal passwords and account numbers, the agency said.&lt;br /&gt;&lt;br /&gt;"It's a treasure trove for identity theft," said David Torok of the FTC's Bureau of Consumer Protection. "We're concerned. The virus that's attached to the e-mail is particularly virulent."&lt;br /&gt;&lt;br /&gt;The agency, which is one of several government agencies investigating cyber fraud, did not know how many people had received the e-mail.&lt;br /&gt;&lt;br /&gt;"We've received hundreds if not thousands of calls and complaints, this one may have had a large distribution," he said.&lt;br /&gt;&lt;br /&gt;Recipients should forward the e-mail to spam@uce.gov, an FTC spam database used in investigations.&lt;br /&gt;&lt;br /&gt;Nine percent of people surveyed in a poll conducted in August and September reported having had their identities stolen, Bari Abdul, a vice president at security software maker McAfee, said at a cybersecurity conference on October 1.</description><link>http://www.softe.org/2007/11/bogus-ftc-e-mail-has-virus.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1820732776973530839</guid><pubDate>Thu, 01 Nov 2007 23:15:00 +0000</pubDate><atom:updated>2007-11-01T16:15:47.828-07:00</atom:updated><title>Fighting spyware</title><description>Fighting spyware may seem like an uphill battle, but it is a campaign that most of us have little choice but to wage. Over a 15-month period. Microsoft's MSRT alone removed 16 million instances of malicious software from 5.7 million computers, 62 percent of which housed at least one backdoor trojan.&lt;br /&gt;Even the most computer- and security-savvy Internet users occasionally fall victim to spyware. Given the financial gain that drives spyware, these pests will undoubtedly continue to proliferate. For spyware. the best defense is a strong offense: taking reasonable steps to prevent and detect spyware can reduce your risk of compromise and your need for expensive remediation .&lt;br /&gt;&lt;br /&gt;The old adage, "An ounce of prevention is worth a pound of cure" certainly applies to spyware. Once spyware has been installed on a host, it can be extremely difficult to return that host to a trustworthy state. Efficient spyware defense starts with proactive steps intended to circumvent popular delivery methods.</description><link>http://www.softe.org/2007/11/fighting-spyware.html</link><author>noreply@blogger.com (Mandy)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1753925278917914352</guid><pubDate>Thu, 01 Nov 2007 21:18:00 +0000</pubDate><atom:updated>2007-11-01T14:19:21.112-07:00</atom:updated><title>Porn Trojan may mark new era for Mac security</title><description>&lt;span style="font-weight:bold;"&gt;A new piece of malware, specifically designed to exploit Apple's OS X, has been found by Mac security software firm Intego, but Symantec has said the firm is prone to "hype".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Intego issued an alert on Wednesday, warning Mac users of the OSX.RSPlug.A malware, which it describes as a Trojan horse.&lt;br /&gt;&lt;br /&gt;The malware is being distributed via a porn site that promotes itself as offering free content. Mac users are being lured to it via links distributed to a number of Mac community message boards.&lt;br /&gt;&lt;br /&gt;When visitors attempt to launch the video, they are advised that QuickTime cannot be used and, to view the content, they must download a new version of codec. For the Trojan to be installed, it requires the user to open up the .dmg (disk image) file, click the installer.pkg file, and enter the administrator's password, according to Intego.&lt;br /&gt;&lt;br /&gt;If the user does install the Trojan, it changes the user's domain name system (DNS) settings and redirects them to phishing or a number of porn websites. DNS settings are used to look up the correspondence between domain names and IP addresses for websites.&lt;br /&gt;&lt;br /&gt;Users of the Mac OS X 10.4 operating system — Tiger — will be unable to see the changed DNS server in the operating system's graphical user interface (GUI). However, those using Mac OS X 10.5 — Leopard — are able to view the changed DNS through its advanced network preferences. The added DNS servers are dimmed in Leopard's GUI, reports Intego.&lt;br /&gt;&lt;br /&gt;Intego claims the vulnerability is likely to exist in older versions of Apple's operating system because all versions of OS X have what Intego calls the "scutil command", which allows the DNS server to be altered.&lt;br /&gt;&lt;br /&gt;"The Trojan horse also installs a root crontab which checks every minute to ensure that its DNS server is still active. Since changing a network location could change the DNS server, this ensures that, in such a case, the malicious DNS server remains the active server," said Intego on its blog.&lt;br /&gt;&lt;br /&gt;For users that do fall for the scam, Intego claims its security software can remove the Trojan. However, Macworld's Rob Griffith has also provided instructions for users on how to manually remove it.&lt;br /&gt;&lt;br /&gt;New era or just vendor hype?&lt;br /&gt;Symantec claimed that Intego tends to "overhype things", but Alex Eckelberry, of security firm Sunbelt, disagreed on his blog, citing the firm's resident Mac guru as being "genuinely surprised" by the Trojan discovery.&lt;br /&gt;&lt;br /&gt;"I've been using Macs since 1989. This is the first time I've seen something like this," Eckelberry wrote, quoting his colleague.&lt;br /&gt;&lt;br /&gt;"I'm not trying to over-hype. Mac users hungry for pr0n really do have to go through a few hoops to get this thing loaded. But we now have millions of new Mac devices out there, between the Touch and iPhone, running OS X," Eckelberry added.&lt;br /&gt;&lt;br /&gt;Simon Clausen, director of security vendor PC Tools, agreed the Trojan is a significant milestone for Mac users.&lt;br /&gt;&lt;br /&gt;The use of cron tabs — a file that tells the operating system to run commands — is rudimentary, but it's just a first attempt.&lt;br /&gt;&lt;br /&gt;"It's the same thing that happened when Vista came out; people had to go through a few steps to get infected, but that was until people figured out a way to get around it. Really, the Mac is less about being a computer than it is about being an everyday device. That's why there's a huge potential for people to target that platform in general. Think how attractive it is to tap the iPhone market that is always on and owned by upper middle-class [users]," said Clausen.&lt;br /&gt;&lt;br /&gt;"Anything that's targeted towards Macs is the beginning of Macs becoming a targeted platform. Macs are not impossible to get around. There are probably less known exploits, but they are only less known because fewer people are focusing on the platform," Clausen added.</description><link>http://www.softe.org/2007/11/porn-trojan-may-mark-new-era-for-mac.html</link><author>noreply@blogger.com (Mandy)</author></item></channel></rss>