|
|
|
Announcements - Computer Virus News |
 |
|
| Conficker Worm - What is it and how to remove it. - posted Monday, October 26, 2009Conficker, also known as Downup, Downandup, Conflicker, and Kido, is a computer worm that surfaced November 21st, 2008 with Conficker.A
It targets the Microsoft Windows operating system. The worm exploits a known vulnerability (MS08-067) in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe. I don't know of ANY 1USA customer getting infected.
Advice and removal instructions for people who use AOL, MSN, Verizon, Comcast and other ISP services are here.
|
| Malware Purveyors Monkey Around with PBS Show Site - posted Tuesday, September 22, 2009The PBS.org website says it has fixed a security problem that allowed
attackers to compromise the website for the Curious George television
show and possibly serve malware to site visitors. The site popped up a
phony authentication page; when the login failed, an error page
containing malicious JavaScript was served. The attack targeted
vulnerabilities in Adobe Acrobat Reader, Apple QuickTime and others. To protect your computer from threats like this, use SafeSpace. |
| Go ahead and subscribe to Secunia's Weekly Summary email - posted Thursday, September 10, 2009Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, or compromise a vulnerable system.
For more information, refer to: http://secunia.com/advisories/36671/
--
Some vulnerabilities, security issues, and weaknesses have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people with physical access to the device to bypass certain security restrictions or disclose sensitive information, and by malicious people to disclose sensitive information, conduct cross-site scripting and spoofing attacks, cause a DoS (Denial of Service), or to compromise a user's system.
For more information, refer to: http://secunia.com/advisories/36677/
========================================================================
3) This Weeks Top Ten Most Read Advisories:
1. [SA35948] Adobe Flash Player Multiple Vulnerabilities
2. [SA35853] Sun Java JDK / JRE Multiple Vulnerabilities
3. [SA24314] Internet Explorer Charset Inheritance Cross-Site
Scripting Vulnerability
4. [SA35949] Adobe Reader/Acrobat SWF Content Arbitrary Code Execution
5. [SA36159] Sun Java JDK / JRE Multiple Vulnerabilities
6. [SA36001] Mozilla Firefox Multiple Vulnerabilities
7. [SA28713] Facebook Photo Uploader ActiveX Control Property Handling
Buffer Overflow
8. [SA36229] Microsoft Remote Desktop Connection Two Vulnerabilities
9. [SA24900] Akamai Download Manager ActiveX Control Buffer Overflow
Vulnerabilities
10. [SA36187] Microsoft Windows Various Components ATL Vulnerabilities
========================================================================
4) This Week in Numbers
During the past week 73 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.
This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:
Platforms:
Windows : 11 Secunia Advisories
Unix/Linux : 39 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 21 Secunia Advisories
Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 20 Secunia Advisories
Moderately Critical : 22 Secunia Advisories
Less Critical : 24 Secunia Advisories
Not Critical : 7 Secunia Advisories
========================================================================
Secunia recommends that you verify all advisories you receive,
by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use
those supplied by the vendor.
Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/
Subscribe: http://secunia.com/advisories/weekly_summary/
Contact details:
Web : http://secunia.com/
E-mail : support@secunia.com
|
| .PPS or .PPT Powerpoint presentations - posted Thursday, August 13, 2009When someone emails you a Powerpoint presentation, ask them if they created it or if they are only forwarding it on from another person. There is currently an unresolved Hack out there for Powerpoint - and you don't want to be allowing those programs to RUN on your computer unless you are reasonably sure that the .pps or .ppt file is safe. If a .pps or .ppt file is not safe, it will attempt to turn off your software Firewall then attempt to download & install Malware and a Key-Logger program. Worst case scenario: It could give your bank account info and other passwords to thieves. Bottom line: Don't be too inquisitive. It could end up costing you a Computer Repair. |
| Air France Flight 447 Spam Arrives with PowerPoint Exploit - posted Monday, July 06, 2009After a blackhat SEO attack, cybercriminals are again using the terrifying catastrophe of Air France Flight 447 or about China-made C919 Jumbo Jets competing with Airbus and Boeing for malicious intent. This time, spam messages are sent with an attached PowerPoint presentation, which is specially crafted to exploit a vulnerability in Microsoft Powerpoint. Story Details at TrendMicro.Com |
| Hoaxes with file attachments that try to hack into your computer are being sent via email. - posted Monday, July 06, 2009Keep up on the latest hoaxes that are really dangerous - because they carry along file attachments that try to hack into your computer. List of current Hoaxes is on TrendMicro.Com |
| This Week's Top 10 Spyware Threats - - posted Wednesday, June 10, 2009Rogue security programs are on the rise and you really need to be cautious about whose software scans your computer.
There is rogue software out there that lures users everyday. People who say "I don't know anything about computers" are usually the ones who are most likely to fall prey. Unbeknownst to them, the "supposed" solution is actually malware itself -- offering little or no real protection, and is often designed to steal personal information. "PersonalAntivirus" - "Windows Antivirus 2009" and similar names is a rogue anti-spyware application that claims to scan for and remove spyware from users' computers. It may be downloaded or installed through exploits or under dubious circumstances without user consent. It hijacks the user's desktop and typically displays exaggerated or false claims of spyware found to frighten the user into paying for the program. If a window pops up saying you have a virus or software and it is not your own anti-malware -- do not run it!!!
Trojan-Spy.Win32.Zbot.gen - Trojan Trojan-Downloader.Zlob.Media-Codec - Trojan Downloader Exploit.PDF-JS.Gen (v) - Exploit Trojan.1 - Trojan Trojan.DNSChanger.Gen - Trojan Favorit Network - Adware (General) PersonalAntivirus - Rogue Security Program INF.Autorun (v) - Trojan Trojan.StartPage.HMH - Trojan Virtumonde - Adware (General)
Stay on top of all the real-time threats at Malware Research Labs: |
| A vulnerability in Winamp has been discovered. - posted Thursday, May 21, 2009A vulnerability in Winamp has been discovered, which can be exploited by malicious people to potentially compromise a user's system.
For more information, refer to: http://secunia.com/advisories/35126/ To check your computer for vulnerabilities install the Personal Security Inspector at http://psi.secunia.com - it's free.
Remember to go into the Advanced screen and turn off the Monitoring service when you're done, otherwise it will monitor changes on the computer and will bog down the computer. 1USA.Com
"Our ISP service is better than yours." |
| Swine Flu Phishing Attacks and Email Scams - posted Saturday, May 02, 2009added April 27, 2009 at 03:04 pm | updated April 28, 2009 at 04:42 pm US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.
US-CERT encourages users to take the following measures to protect themselves:
UPDATE: Due to these potential phishing attacks and email scams, US-CERT encourages users to visit the Center for Disease Control (CDC) website for trusted information regarding the Swine Flu. |
| House Committee Seeks Information on P2P Data Theft, Briefing on Fighter Jet Data Theft - posted Saturday, April 25, 2009(April 22 & 23, 2009)
The US House Committee on Oversight and Government Reform has sent letters to Attorney General Eric Holder and Federal Trade Commission (FTC) chairman Jon Leibowitz asking what the Justice Department and the FTC have done to prevent illegal use of peer-to-peer (P2P) filesharing
applications. Specifically, the committee is concerned about the applications being used to steal financial account information, health data and other sensitive information. Security experts would like to see the committee focus on encouraging agencies to prevent workers from downloading P2P applications. In a separate story, the same House committee is seeking a cyber security briefing following allegations that cyber intruders stole information about the Joint Strike Fighter. http://www.washingtonpost.com/wp-dyn/content/article/2009/04/21/AR2009042103508_pf.html http://www.nextgov.com/nextgov/ng_20090423_8694.php http://fcw.com/Articles/2009/04/22/Web-cyber-security-briefing.aspx
[Editor's Note: While technical means for controlling P2P use exist, they're certainly not foolproof. From my perspective, nothing works better than making the installation of an unapproved application a fireable offense AND monitoring your networks and following through
on the threat.]
|
| Multiple vulnerabilities reported in Adobe's Flash Player - posted Thursday, March 12, 2009 |
| Your Government at work - IRS Taxpayer data determined to be insecure - posted Friday, February 20, 2009 |
| New Hack for Adobe's brand of .PDF viewer software - posted Friday, February 20, 2009First, I noticed that Adobe's brand of .PDF viewer software chews up 64 MB of space... and FoxIT's brand of .PDF viewer uses less than 3 MB...
so I asked myself "Why does Adobe's software need so much - just to see .PDF files?" Well, here is a new hack on the street this week attacking the Adobe viewer's ability to run JavaScript (programming language) inside a .PDF file. To turn OFF the ability to run Javascript when viewing .PDF files, open Adobe, then goto Edit > Preferences > JavaScript ... then uncheck the box that says "Enable Acrobat JavaScript". Otherwise, if you'd rather switch to the leaner & faster (and Free) FoxIT brand of .PDF viewer software, the link is here. (Choose the free version on the left. I've been using it forever...) Read the full story about the security issue here.
|
| Conficker Worm Attack Getting Worse: Protect Yourself - posted Friday, February 13, 2009 |
| Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG - posted Saturday, January 24, 2009NOTE THAT 1USA CUSTOMERS ARE PROTECTED FROM RECEIVING THESE VIRUS IN THEIR EMAIL IN-BOX.
CONTACT 1USA.COM TO GET YOUR OWN @1USA.COM EMAIL ADDRESS.
Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG
Iksmas.A is a malicious code that spreads via email. In the message,
which was initially sent a few days before Barack Obama took office as
president of the United States, it claims that Obama had decided to
decline to become president. The email includes a link pointing to a
spoof Web page with the headline of the corresponding story. Users that
try to read the story will be asked to download a plug-in in order to
view it. If they accept, they will really be allowing the worm to enter
their computers. You can see an image of the Web page here: http://www.flickr.com/photos/panda_security/3209435502/
Once the computer is infected, Iksmas.A looks for email addresses on the
system and uploads a file with the stolen information to a certain
address. It then sends copies of itself to these addresses, thereby
continuing the cycle.
Autorun.ARK is a downloader worm designed to download two backdoor
Trojans -detected as Bck/YahooMess.B and Bck/Poison.F. It also creates a
Windows Registry entry to ensure it is run on every system startup.
IRCBot.CIG is a worm that uses the MS08-067 vulnerability in Microsoft
Windows Server service in order to spread. Once it has infected a
computer, it gathers information about the system and sends it to its
creator via a Web page.
By modifying the Windows Registry it disables the task manager, firewall
notifications and the Windows antivirus. It also makes a modification so
that whenever the user tries to open Explorer, malware is run.
Interestingly, this worm exploits the same vulnerability as Conficker,
which continues to spread and has now affected 6% of computers scanned
by Panda Security worldwide
(http://www.pandasecurity.com/spain/homeusers/media/press-releases/viewn
ews?noticia=9524)
You can find more information about the dangerous Conficker worm and how
to remove it here: http://www.pandasecurity.com/spain/homeusers/security-info/about-malware
/encyclopedia/overview.aspx?idvirus=204292
"Cases such as Conficker demonstrate how important it is to keep
computers up-to-date in order to prevent infections", explains Luis
Corrons, Technical Director of PandaLabs. "There is no point in a user
scanning a system with an antivirus and removing the malware if the
computer is not kept up-to-date, as the infection will simply return on
visiting certain Web pages".
For more information about these and other malware threats, go to: http://www.pandasecurity.com/homeusers/security-info/latest-threats/?sit
epanda=particulares
|
| Millions Hit with Windows Worm as Infection Spreads - posted Tuesday, January 20, 2009Some people have not installed WindowsUpdates yet from October 2008
Remember that inserting a floppy drive, USB memory stick etc into a computer in an office could potentially infect the whole office network if there is a hidden virus on the removable media. Full story: http://www.eweek.com/index2.php?option=content&do_pdf=1&id=51251 |
| Malicious Sites with Fake Obama News Infect Users with Malware - posted Tuesday, January 20, 2009 |
|
| Conficker Worm - What is it and how to remove it. - posted Monday, October 26, 2009Conficker, also known as Downup, Downandup, Conflicker, and Kido, is a computer worm that surfaced November 21st, 2008 with Conficker.A
It targets the Microsoft Windows operating system. The worm exploits a known vulnerability (MS08-067) in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe. I don't know of ANY 1USA customer getting infected.
Advice and removal instructions for people who use AOL, MSN, Verizon, Comcast and other ISP services are here.
|
| Malware Purveyors Monkey Around with PBS Show Site - posted Tuesday, September 22, 2009The PBS.org website says it has fixed a security problem that allowed
attackers to compromise the website for the Curious George television
show and possibly serve malware to site visitors. The site popped up a
phony authentication page; when the login failed, an error page
containing malicious JavaScript was served. The attack targeted
vulnerabilities in Adobe Acrobat Reader, Apple QuickTime and others. To protect your computer from threats like this, use SafeSpace. |
| Go ahead and subscribe to Secunia's Weekly Summary email - posted Thursday, September 10, 2009Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, or compromise a vulnerable system.
For more information, refer to: http://secunia.com/advisories/36671/
--
Some vulnerabilities, security issues, and weaknesses have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people with physical access to the device to bypass certain security restrictions or disclose sensitive information, and by malicious people to disclose sensitive information, conduct cross-site scripting and spoofing attacks, cause a DoS (Denial of Service), or to compromise a user's system.
For more information, refer to: http://secunia.com/advisories/36677/
========================================================================
3) This Weeks Top Ten Most Read Advisories:
1. [SA35948] Adobe Flash Player Multiple Vulnerabilities
2. [SA35853] Sun Java JDK / JRE Multiple Vulnerabilities
3. [SA24314] Internet Explorer Charset Inheritance Cross-Site
Scripting Vulnerability
4. [SA35949] Adobe Reader/Acrobat SWF Content Arbitrary Code Execution
5. [SA36159] Sun Java JDK / JRE Multiple Vulnerabilities
6. [SA36001] Mozilla Firefox Multiple Vulnerabilities
7. [SA28713] Facebook Photo Uploader ActiveX Control Property Handling
Buffer Overflow
8. [SA36229] Microsoft Remote Desktop Connection Two Vulnerabilities
9. [SA24900] Akamai Download Manager ActiveX Control Buffer Overflow
Vulnerabilities
10. [SA36187] Microsoft Windows Various Components ATL Vulnerabilities
========================================================================
4) This Week in Numbers
During the past week 73 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.
This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:
Platforms:
Windows : 11 Secunia Advisories
Unix/Linux : 39 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 21 Secunia Advisories
Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 20 Secunia Advisories
Moderately Critical : 22 Secunia Advisories
Less Critical : 24 Secunia Advisories
Not Critical : 7 Secunia Advisories
========================================================================
Secunia recommends that you verify all advisories you receive,
by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use
those supplied by the vendor.
Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/
Subscribe: http://secunia.com/advisories/weekly_summary/
Contact details:
Web : http://secunia.com/
E-mail : support@secunia.com
|
| .PPS or .PPT Powerpoint presentations - posted Thursday, August 13, 2009When someone emails you a Powerpoint presentation, ask them if they created it or if they are only forwarding it on from another person. There is currently an unresolved Hack out there for Powerpoint - and you don't want to be allowing those programs to RUN on your computer unless you are reasonably sure that the .pps or .ppt file is safe. If a .pps or .ppt file is not safe, it will attempt to turn off your software Firewall then attempt to download & install Malware and a Key-Logger program. Worst case scenario: It could give your bank account info and other passwords to thieves. Bottom line: Don't be too inquisitive. It could end up costing you a Computer Repair. |
| Air France Flight 447 Spam Arrives with PowerPoint Exploit - posted Monday, July 06, 2009After a blackhat SEO attack, cybercriminals are again using the terrifying catastrophe of Air France Flight 447 or about China-made C919 Jumbo Jets competing with Airbus and Boeing for malicious intent. This time, spam messages are sent with an attached PowerPoint presentation, which is specially crafted to exploit a vulnerability in Microsoft Powerpoint. Story Details at TrendMicro.Com |
| Hoaxes with file attachments that try to hack into your computer are being sent via email. - posted Monday, July 06, 2009Keep up on the latest hoaxes that are really dangerous - because they carry along file attachments that try to hack into your computer. List of current Hoaxes is on TrendMicro.Com |
| This Week's Top 10 Spyware Threats - - posted Wednesday, June 10, 2009Rogue security programs are on the rise and you really need to be cautious about whose software scans your computer.
There is rogue software out there that lures users everyday. People who say "I don't know anything about computers" are usually the ones who are most likely to fall prey. Unbeknownst to them, the "supposed" solution is actually malware itself -- offering little or no real protection, and is often designed to steal personal information. "PersonalAntivirus" - "Windows Antivirus 2009" and similar names is a rogue anti-spyware application that claims to scan for and remove spyware from users' computers. It may be downloaded or installed through exploits or under dubious circumstances without user consent. It hijacks the user's desktop and typically displays exaggerated or false claims of spyware found to frighten the user into paying for the program. If a window pops up saying you have a virus or software and it is not your own anti-malware -- do not run it!!!
Trojan-Spy.Win32.Zbot.gen - Trojan Trojan-Downloader.Zlob.Media-Codec - Trojan Downloader Exploit.PDF-JS.Gen (v) - Exploit Trojan.1 - Trojan Trojan.DNSChanger.Gen - Trojan Favorit Network - Adware (General) PersonalAntivirus - Rogue Security Program INF.Autorun (v) - Trojan Trojan.StartPage.HMH - Trojan Virtumonde - Adware (General)
Stay on top of all the real-time threats at Malware Research Labs: |
| A vulnerability in Winamp has been discovered. - posted Thursday, May 21, 2009A vulnerability in Winamp has been discovered, which can be exploited by malicious people to potentially compromise a user's system.
For more information, refer to: http://secunia.com/advisories/35126/ To check your computer for vulnerabilities install the Personal Security Inspector at http://psi.secunia.com - it's free.
Remember to go into the Advanced screen and turn off the Monitoring service when you're done, otherwise it will monitor changes on the computer and will bog down the computer. 1USA.Com
"Our ISP service is better than yours." |
| Swine Flu Phishing Attacks and Email Scams - posted Saturday, May 02, 2009added April 27, 2009 at 03:04 pm | updated April 28, 2009 at 04:42 pm US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.
US-CERT encourages users to take the following measures to protect themselves:
UPDATE: Due to these potential phishing attacks and email scams, US-CERT encourages users to visit the Center for Disease Control (CDC) website for trusted information regarding the Swine Flu. |
| House Committee Seeks Information on P2P Data Theft, Briefing on Fighter Jet Data Theft - posted Saturday, April 25, 2009(April 22 & 23, 2009)
The US House Committee on Oversight and Government Reform has sent letters to Attorney General Eric Holder and Federal Trade Commission (FTC) chairman Jon Leibowitz asking what the Justice Department and the FTC have done to prevent illegal use of peer-to-peer (P2P) filesharing
applications. Specifically, the committee is concerned about the applications being used to steal financial account information, health data and other sensitive information. Security experts would like to see the committee focus on encouraging agencies to prevent workers from downloading P2P applications. In a separate story, the same House committee is seeking a cyber security briefing following allegations that cyber intruders stole information about the Joint Strike Fighter. http://www.washingtonpost.com/wp-dyn/content/article/2009/04/21/AR2009042103508_pf.html http://www.nextgov.com/nextgov/ng_20090423_8694.php http://fcw.com/Articles/2009/04/22/Web-cyber-security-briefing.aspx
[Editor's Note: While technical means for controlling P2P use exist, they're certainly not foolproof. From my perspective, nothing works better than making the installation of an unapproved application a fireable offense AND monitoring your networks and following through
on the threat.]
|
| Multiple vulnerabilities reported in Adobe's Flash Player - posted Thursday, March 12, 2009 |
| Your Government at work - IRS Taxpayer data determined to be insecure - posted Friday, February 20, 2009 |
| New Hack for Adobe's brand of .PDF viewer software - posted Friday, February 20, 2009First, I noticed that Adobe's brand of .PDF viewer software chews up 64 MB of space... and FoxIT's brand of .PDF viewer uses less than 3 MB...
so I asked myself "Why does Adobe's software need so much - just to see .PDF files?" Well, here is a new hack on the street this week attacking the Adobe viewer's ability to run JavaScript (programming language) inside a .PDF file. To turn OFF the ability to run Javascript when viewing .PDF files, open Adobe, then goto Edit > Preferences > JavaScript ... then uncheck the box that says "Enable Acrobat JavaScript". Otherwise, if you'd rather switch to the leaner & faster (and Free) FoxIT brand of .PDF viewer software, the link is here. (Choose the free version on the left. I've been using it forever...) Read the full story about the security issue here.
|
| Conficker Worm Attack Getting Worse: Protect Yourself - posted Friday, February 13, 2009 |
| Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG - posted Saturday, January 24, 2009NOTE THAT 1USA CUSTOMERS ARE PROTECTED FROM RECEIVING THESE VIRUS IN THEIR EMAIL IN-BOX.
CONTACT 1USA.COM TO GET YOUR OWN @1USA.COM EMAIL ADDRESS.
Three worms, Iksmas.A, Autorun.ARK and IRCBot.CIG
Iksmas.A is a malicious code that spreads via email. In the message,
which was initially sent a few days before Barack Obama took office as
president of the United States, it claims that Obama had decided to
decline to become president. The email includes a link pointing to a
spoof Web page with the headline of the corresponding story. Users that
try to read the story will be asked to download a plug-in in order to
view it. If they accept, they will really be allowing the worm to enter
their computers. You can see an image of the Web page here: http://www.flickr.com/photos/panda_security/3209435502/
Once the computer is infected, Iksmas.A looks for email addresses on the
system and uploads a file with the stolen information to a certain
address. It then sends copies of itself to these addresses, thereby
continuing the cycle.
Autorun.ARK is a downloader worm designed to download two backdoor
Trojans -detected as Bck/YahooMess.B and Bck/Poison.F. It also creates a
Windows Registry entry to ensure it is run on every system startup.
IRCBot.CIG is a worm that uses the MS08-067 vulnerability in Microsoft
Windows Server service in order to spread. Once it has infected a
computer, it gathers information about the system and sends it to its
creator via a Web page.
By modifying the Windows Registry it disables the task manager, firewall
notifications and the Windows antivirus. It also makes a modification so
that whenever the user tries to open Explorer, malware is run.
Interestingly, this worm exploits the same vulnerability as Conficker,
which continues to spread and has now affected 6% of computers scanned
by Panda Security worldwide
(http://www.pandasecurity.com/spain/homeusers/media/press-releases/viewn
ews?noticia=9524)
You can find more information about the dangerous Conficker worm and how
to remove it here: http://www.pandasecurity.com/spain/homeusers/security-info/about-malware
/encyclopedia/overview.aspx?idvirus=204292
"Cases such as Conficker demonstrate how important it is to keep
computers up-to-date in order to prevent infections", explains Luis
Corrons, Technical Director of PandaLabs. "There is no point in a user
scanning a system with an antivirus and removing the malware if the
computer is not kept up-to-date, as the infection will simply return on
visiting certain Web pages".
For more information about these and other malware threats, go to: http://www.pandasecurity.com/homeusers/security-info/latest-threats/?sit
epanda=particulares
|
| Millions Hit with Windows Worm as Infection Spreads - posted Tuesday, January 20, 2009Some people have not installed WindowsUpdates yet from October 2008
Remember that inserting a floppy drive, USB memory stick etc into a computer in an office could potentially infect the whole office network if there is a hidden virus on the removable media. Full story: http://www.eweek.com/index2.php?option=content&do_pdf=1&id=51251 |
| Malicious Sites with Fake Obama News Infect Users with Malware - posted Tuesday, January 20, 2009 |
|
|
|
|
|
|
Not Logged In |
 |
|
You're not logged into this website.
If you are a member on this website or a 1USA subscriber, please log in.
Others: $60 per year for website access, computer tech support, and a @1usa.com email address that stops the spams & scams. Register Here
Don't have a @1usa.com email address?
No problem.
If you are reading the pages on this website... and you like what you see... but only have a @AOL, @NetZero, @Hotmail (etc.) email address, you can sign up with 1USA and retrieve ALL your emails in one safe place: - You can keep your other less-secure Email Address for any length of time. Our 1USA Mail Servers can 'pull' emails from any other server.
Our 1USA server will 'import' your other emails and run them through our four different anti-virus & anti-malware scanners - where you can be pretty sure that the 'nasties' don't get into your In-Box.
To start, simply Register on this website.
Still Confused? Contact us. You're not logged into this website.
If you are a member on this website or a 1USA subscriber, please log in.
Others: $60 per year for website access, computer tech support, and a @1usa.com email address that stops the spams & scams. Register Here
Don't have a @1usa.com email address?
No problem.
If you are reading the pages on this website... and you like what you see... but only have a @AOL, @NetZero, @Hotmail (etc.) email address, you can sign up with 1USA and retrieve ALL your emails in one safe place: - You can keep your other less-secure Email Address for any length of time. Our 1USA Mail Servers can 'pull' emails from any other server.
Our 1USA server will 'import' your other emails and run them through our four different anti-virus & anti-malware scanners - where you can be pretty sure that the 'nasties' don't get into your In-Box.
To start, simply Register on this website.
Still Confused? Contact us. |
|
|