|
|
|
Announcements - Computer Virus News |
 |
|
| Conficker Worm - What is it and how to remove it. - posted Monday, October 26, 2009Conficker, also known as Downup, Downandup, Conflicker, and Kido, is a computer worm that surfaced November 21st, 2008 with Conficker.A
It targets the Microsoft Windows operating system. The worm exploits a known vulnerability (MS08-067) in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe. I don't know of ANY 1USA customer getting infected.
Advice and removal instructions for people who use AOL, MSN, Verizon, Comcast and other ISP services are here.
|
| Malware Purveyors Monkey Around with PBS Show Site - posted Tuesday, September 22, 2009The PBS.org website says it has fixed a security problem that allowed
attackers to compromise the website for the Curious George television
show and possibly serve malware to site visitors. The site popped up a
phony authentication page; when the login failed, an error page
containing malicious JavaScript was served. The attack targeted
vulnerabilities in Adobe Acrobat Reader, Apple QuickTime and others. To protect your computer from threats like this, use SafeSpace. |
| Go ahead and subscribe to Secunia's Weekly Summary email - posted Thursday, September 10, 2009Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, or compromise a vulnerable system.
For more information, refer to: http://secunia.com/advisories/36671/
--
Some vulnerabilities, security issues, and weaknesses have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people with physical access to the device to bypass certain security restrictions or disclose sensitive information, and by malicious people to disclose sensitive information, conduct cross-site scripting and spoofing attacks, cause a DoS (Denial of Service), or to compromise a user's system.
For more information, refer to: http://secunia.com/advisories/36677/
========================================================================
3) This Weeks Top Ten Most Read Advisories:
1. [SA35948] Adobe Flash Player Multiple Vulnerabilities
2. [SA35853] Sun Java JDK / JRE Multiple Vulnerabilities
3. [SA24314] Internet Explorer Charset Inheritance Cross-Site
Scripting Vulnerability
4. [SA35949] Adobe Reader/Acrobat SWF Content Arbitrary Code Execution
5. [SA36159] Sun Java JDK / JRE Multiple Vulnerabilities
6. [SA36001] Mozilla Firefox Multiple Vulnerabilities
7. [SA28713] Facebook Photo Uploader ActiveX Control Property Handling
Buffer Overflow
8. [SA36229] Microsoft Remote Desktop Connection Two Vulnerabilities
9. [SA24900] Akamai Download Manager ActiveX Control Buffer Overflow
Vulnerabilities
10. [SA36187] Microsoft Windows Various Components ATL Vulnerabilities
========================================================================
4) This Week in Numbers
During the past week 73 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.
This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:
Platforms:
Windows : 11 Secunia Advisories
Unix/Linux : 39 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 21 Secunia Advisories
Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 20 Secunia Advisories
Moderately Critical : 22 Secunia Advisories
Less Critical : 24 Secunia Advisories
Not Critical : 7 Secunia Advisories
========================================================================
Secunia recommends that you verify all advisories you receive,
by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use
those supplied by the vendor.
Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/
Subscribe: http://secunia.com/advisories/weekly_summary/
Contact details:
Web : http://secunia.com/
E-mail : support@secunia.com
|
| Hoaxes with file attachments that try to hack into your computer are being sent via email. - posted Monday, July 06, 2009Keep up on the latest hoaxes that are really dangerous - because they carry along file attachments that try to hack into your computer. List of current Hoaxes is on TrendMicro.Com |
| This Week's Top 10 Spyware Threats - - posted Wednesday, June 10, 2009Rogue security programs are on the rise and you really need to be cautious about whose software scans your computer.
There is rogue software out there that lures users everyday. People who say "I don't know anything about computers" are usually the ones who are most likely to fall prey. Unbeknownst to them, the "supposed" solution is actually malware itself -- offering little or no real protection, and is often designed to steal personal information. "PersonalAntivirus" - "Windows Antivirus 2009" and similar names is a rogue anti-spyware application that claims to scan for and remove spyware from users' computers. It may be downloaded or installed through exploits or under dubious circumstances without user consent. It hijacks the user's desktop and typically displays exaggerated or false claims of spyware found to frighten the user into paying for the program. If a window pops up saying you have a virus or software and it is not your own anti-malware -- do not run it!!!
Trojan-Spy.Win32.Zbot.gen - Trojan Trojan-Downloader.Zlob.Media-Codec - Trojan Downloader Exploit.PDF-JS.Gen (v) - Exploit Trojan.1 - Trojan Trojan.DNSChanger.Gen - Trojan Favorit Network - Adware (General) PersonalAntivirus - Rogue Security Program INF.Autorun (v) - Trojan Trojan.StartPage.HMH - Trojan Virtumonde - Adware (General)
Stay on top of all the real-time threats at Malware Research Labs: |
| A vulnerability in Winamp has been discovered. - posted Thursday, May 21, 2009A vulnerability in Winamp has been discovered, which can be exploited by malicious people to potentially compromise a user's system.
For more information, refer to: http://secunia.com/advisories/35126/ To check your computer for vulnerabilities install the Personal Security Inspector at http://psi.secunia.com - it's free.
Remember to go into the Advanced screen and turn off the Monitoring service when you're done, otherwise it will monitor changes on the computer and will bog down the computer. 1USA.Com
"Our ISP service is better than yours." |
| Swine Flu Phishing Attacks and Email Scams - posted Saturday, May 02, 2009added April 27, 2009 at 03:04 pm | updated April 28, 2009 at 04:42 pm US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.
US-CERT encourages users to take the following measures to protect themselves:
UPDATE: Due to these potential phishing attacks and email scams, US-CERT encourages users to visit the Center for Disease Control (CDC) website for trusted information regarding the Swine Flu. |
| Multiple vulnerabilities reported in Adobe's Flash Player - posted Thursday, March 12, 2009 |
| Conficker Worm Attack Getting Worse: Protect Yourself - posted Friday, February 13, 2009 |
| Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG - posted Saturday, January 24, 2009NOTE THAT 1USA CUSTOMERS ARE PROTECTED FROM RECEIVING THESE VIRUS IN THEIR EMAIL IN-BOX.
CONTACT 1USA.COM TO GET YOUR OWN @1USA.COM EMAIL ADDRESS.
Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG
Iksmas.A is a malicious code that spreads via email. In the message,
which was initially sent a few days before Barack Obama took office as
president of the United States, it claims that Obama had decided to
decline to become president. The email includes a link pointing to a
spoof Web page with the headline of the corresponding story. Users that
try to read the story will be asked to download a plug-in in order to
view it. If they accept, they will really be allowing the worm to enter
their computers. You can see an image of the Web page here: http://www.flickr.com/photos/panda_security/3209435502/
Once the computer is infected, Iksmas.A looks for email addresses on the
system and uploads a file with the stolen information to a certain
address. It then sends copies of itself to these addresses, thereby
continuing the cycle.
Autorun.ARK is a downloader worm designed to download two backdoor
Trojans -detected as Bck/YahooMess.B and Bck/Poison.F. It also creates a
Windows Registry entry to ensure it is run on every system startup.
IRCBot.CIG is a worm that uses the MS08-067 vulnerability in Microsoft
Windows Server service in order to spread. Once it has infected a
computer, it gathers information about the system and sends it to its
creator via a Web page.
By modifying the Windows Registry it disables the task manager, firewall
notifications and the Windows antivirus. It also makes a modification so
that whenever the user tries to open Explorer, malware is run.
Interestingly, this worm exploits the same vulnerability as Conficker,
which continues to spread and has now affected 6% of computers scanned
by Panda Security worldwide
(http://www.pandasecurity.com/spain/homeusers/media/press-releases/viewn
ews?noticia=9524)
You can find more information about the dangerous Conficker worm and how
to remove it here: http://www.pandasecurity.com/spain/homeusers/security-info/about-malware
/encyclopedia/overview.aspx?idvirus=204292
"Cases such as Conficker demonstrate how important it is to keep
computers up-to-date in order to prevent infections", explains Luis
Corrons, Technical Director of PandaLabs. "There is no point in a user
scanning a system with an antivirus and removing the malware if the
computer is not kept up-to-date, as the infection will simply return on
visiting certain Web pages".
For more information about these and other malware threats, go to: http://www.pandasecurity.com/homeusers/security-info/latest-threats/?sit
epanda=particulares
|
| Millions Hit with Windows Worm as Infection Spreads - posted Tuesday, January 20, 2009Some people have not installed WindowsUpdates yet from October 2008
Remember that inserting a floppy drive, USB memory stick etc into a computer in an office could potentially infect the whole office network if there is a hidden virus on the removable media. Full story: http://www.eweek.com/index2.php?option=content&do_pdf=1&id=51251 |
| Malicious Sites with Fake Obama News Infect Users with Malware - posted Tuesday, January 20, 2009 |
|
| Conficker Worm - What is it and how to remove it. - posted Monday, October 26, 2009Conficker, also known as Downup, Downandup, Conflicker, and Kido, is a computer worm that surfaced November 21st, 2008 with Conficker.A
It targets the Microsoft Windows operating system. The worm exploits a known vulnerability (MS08-067) in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe. I don't know of ANY 1USA customer getting infected.
Advice and removal instructions for people who use AOL, MSN, Verizon, Comcast and other ISP services are here.
|
| Malware Purveyors Monkey Around with PBS Show Site - posted Tuesday, September 22, 2009The PBS.org website says it has fixed a security problem that allowed
attackers to compromise the website for the Curious George television
show and possibly serve malware to site visitors. The site popped up a
phony authentication page; when the login failed, an error page
containing malicious JavaScript was served. The attack targeted
vulnerabilities in Adobe Acrobat Reader, Apple QuickTime and others. To protect your computer from threats like this, use SafeSpace. |
| Go ahead and subscribe to Secunia's Weekly Summary email - posted Thursday, September 10, 2009Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, or compromise a vulnerable system.
For more information, refer to: http://secunia.com/advisories/36671/
--
Some vulnerabilities, security issues, and weaknesses have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people with physical access to the device to bypass certain security restrictions or disclose sensitive information, and by malicious people to disclose sensitive information, conduct cross-site scripting and spoofing attacks, cause a DoS (Denial of Service), or to compromise a user's system.
For more information, refer to: http://secunia.com/advisories/36677/
========================================================================
3) This Weeks Top Ten Most Read Advisories:
1. [SA35948] Adobe Flash Player Multiple Vulnerabilities
2. [SA35853] Sun Java JDK / JRE Multiple Vulnerabilities
3. [SA24314] Internet Explorer Charset Inheritance Cross-Site
Scripting Vulnerability
4. [SA35949] Adobe Reader/Acrobat SWF Content Arbitrary Code Execution
5. [SA36159] Sun Java JDK / JRE Multiple Vulnerabilities
6. [SA36001] Mozilla Firefox Multiple Vulnerabilities
7. [SA28713] Facebook Photo Uploader ActiveX Control Property Handling
Buffer Overflow
8. [SA36229] Microsoft Remote Desktop Connection Two Vulnerabilities
9. [SA24900] Akamai Download Manager ActiveX Control Buffer Overflow
Vulnerabilities
10. [SA36187] Microsoft Windows Various Components ATL Vulnerabilities
========================================================================
4) This Week in Numbers
During the past week 73 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.
This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:
Platforms:
Windows : 11 Secunia Advisories
Unix/Linux : 39 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 21 Secunia Advisories
Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 20 Secunia Advisories
Moderately Critical : 22 Secunia Advisories
Less Critical : 24 Secunia Advisories
Not Critical : 7 Secunia Advisories
========================================================================
Secunia recommends that you verify all advisories you receive,
by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use
those supplied by the vendor.
Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/
Subscribe: http://secunia.com/advisories/weekly_summary/
Contact details:
Web : http://secunia.com/
E-mail : support@secunia.com
|
| Hoaxes with file attachments that try to hack into your computer are being sent via email. - posted Monday, July 06, 2009Keep up on the latest hoaxes that are really dangerous - because they carry along file attachments that try to hack into your computer. List of current Hoaxes is on TrendMicro.Com |
| This Week's Top 10 Spyware Threats - - posted Wednesday, June 10, 2009Rogue security programs are on the rise and you really need to be cautious about whose software scans your computer.
There is rogue software out there that lures users everyday. People who say "I don't know anything about computers" are usually the ones who are most likely to fall prey. Unbeknownst to them, the "supposed" solution is actually malware itself -- offering little or no real protection, and is often designed to steal personal information. "PersonalAntivirus" - "Windows Antivirus 2009" and similar names is a rogue anti-spyware application that claims to scan for and remove spyware from users' computers. It may be downloaded or installed through exploits or under dubious circumstances without user consent. It hijacks the user's desktop and typically displays exaggerated or false claims of spyware found to frighten the user into paying for the program. If a window pops up saying you have a virus or software and it is not your own anti-malware -- do not run it!!!
Trojan-Spy.Win32.Zbot.gen - Trojan Trojan-Downloader.Zlob.Media-Codec - Trojan Downloader Exploit.PDF-JS.Gen (v) - Exploit Trojan.1 - Trojan Trojan.DNSChanger.Gen - Trojan Favorit Network - Adware (General) PersonalAntivirus - Rogue Security Program INF.Autorun (v) - Trojan Trojan.StartPage.HMH - Trojan Virtumonde - Adware (General)
Stay on top of all the real-time threats at Malware Research Labs: |
| A vulnerability in Winamp has been discovered. - posted Thursday, May 21, 2009A vulnerability in Winamp has been discovered, which can be exploited by malicious people to potentially compromise a user's system.
For more information, refer to: http://secunia.com/advisories/35126/ To check your computer for vulnerabilities install the Personal Security Inspector at http://psi.secunia.com - it's free.
Remember to go into the Advanced screen and turn off the Monitoring service when you're done, otherwise it will monitor changes on the computer and will bog down the computer. 1USA.Com
"Our ISP service is better than yours." |
| Swine Flu Phishing Attacks and Email Scams - posted Saturday, May 02, 2009added April 27, 2009 at 03:04 pm | updated April 28, 2009 at 04:42 pm US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.
US-CERT encourages users to take the following measures to protect themselves:
UPDATE: Due to these potential phishing attacks and email scams, US-CERT encourages users to visit the Center for Disease Control (CDC) website for trusted information regarding the Swine Flu. |
| Multiple vulnerabilities reported in Adobe's Flash Player - posted Thursday, March 12, 2009 |
| Conficker Worm Attack Getting Worse: Protect Yourself - posted Friday, February 13, 2009 |
| Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG - posted Saturday, January 24, 2009NOTE THAT 1USA CUSTOMERS ARE PROTECTED FROM RECEIVING THESE VIRUS IN THEIR EMAIL IN-BOX.
CONTACT 1USA.COM TO GET YOUR OWN @1USA.COM EMAIL ADDRESS.
Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG
Iksmas.A is a malicious code that spreads via email. In the message,
which was initially sent a few days before Barack Obama took office as
president of the United States, it claims that Obama had decided to
decline to become president. The email includes a link pointing to a
spoof Web page with the headline of the corresponding story. Users that
try to read the story will be asked to download a plug-in in order to
view it. If they accept, they will really be allowing the worm to enter
their computers. You can see an image of the Web page here: http://www.flickr.com/photos/panda_security/3209435502/
Once the computer is infected, Iksmas.A looks for email addresses on the
system and uploads a file with the stolen information to a certain
address. It then sends copies of itself to these addresses, thereby
continuing the cycle.
Autorun.ARK is a downloader worm designed to download two backdoor
Trojans -detected as Bck/YahooMess.B and Bck/Poison.F. It also creates a
Windows Registry entry to ensure it is run on every system startup.
IRCBot.CIG is a worm that uses the MS08-067 vulnerability in Microsoft
Windows Server service in order to spread. Once it has infected a
computer, it gathers information about the system and sends it to its
creator via a Web page.
By modifying the Windows Registry it disables the task manager, firewall
notifications and the Windows antivirus. It also makes a modification so
that whenever the user tries to open Explorer, malware is run.
Interestingly, this worm exploits the same vulnerability as Conficker,
which continues to spread and has now affected 6% of computers scanned
by Panda Security worldwide
(http://www.pandasecurity.com/spain/homeusers/media/press-releases/viewn
ews?noticia=9524)
You can find more information about the dangerous Conficker worm and how
to remove it here: http://www.pandasecurity.com/spain/homeusers/security-info/about-malware
/encyclopedia/overview.aspx?idvirus=204292
"Cases such as Conficker demonstrate how important it is to keep
computers up-to-date in order to prevent infections", explains Luis
Corrons, Technical Director of PandaLabs. "There is no point in a user
scanning a system with an antivirus and removing the malware if the
computer is not kept up-to-date, as the infection will simply return on
visiting certain Web pages".
For more information about these and other malware threats, go to: http://www.pandasecurity.com/homeusers/security-info/latest-threats/?sit
epanda=particulares
|
| Millions Hit with Windows Worm as Infection Spreads - posted Tuesday, January 20, 2009Some people have not installed WindowsUpdates yet from October 2008
Remember that inserting a floppy drive, USB memory stick etc into a computer in an office could potentially infect the whole office network if there is a hidden virus on the removable media. Full story: http://www.eweek.com/index2.php?option=content&do_pdf=1&id=51251 |
| Malicious Sites with Fake Obama News Infect Users with Malware - posted Tuesday, January 20, 2009 |
|
|
|
|
|
|
Not Logged In |
 |
|
You're not logged into this website.
If you are a member on this website or a 1USA subscriber, please log in.
Others: $60 per year for website access, computer tech support, and a @1usa.com email address that stops the spams & scams. Register Here
Don't have a @1usa.com email address?
No problem.
If you are reading the pages on this website... and you like what you see... but only have a @AOL, @NetZero, @Hotmail (etc.) email address, you can sign up with 1USA and retrieve ALL your emails in one safe place: - You can keep your other less-secure Email Address for any length of time. Our 1USA Mail Servers can 'pull' emails from any other server.
Our 1USA server will 'import' your other emails and run them through our four different anti-virus & anti-malware scanners - where you can be pretty sure that the 'nasties' don't get into your In-Box.
To start, simply Register on this website.
Still Confused? Contact us. You're not logged into this website.
If you are a member on this website or a 1USA subscriber, please log in.
Others: $60 per year for website access, computer tech support, and a @1usa.com email address that stops the spams & scams. Register Here
Don't have a @1usa.com email address?
No problem.
If you are reading the pages on this website... and you like what you see... but only have a @AOL, @NetZero, @Hotmail (etc.) email address, you can sign up with 1USA and retrieve ALL your emails in one safe place: - You can keep your other less-secure Email Address for any length of time. Our 1USA Mail Servers can 'pull' emails from any other server.
Our 1USA server will 'import' your other emails and run them through our four different anti-virus & anti-malware scanners - where you can be pretty sure that the 'nasties' don't get into your In-Box.
To start, simply Register on this website.
Still Confused? Contact us. |
|
|