Tag: malicious

Game Password Stealers Exploit 0-day DirectX Vulnerability

June 28, 2009 by Jason

It is nothing short of ironic that game password stealing malware is being associated with an exploit designed to target a vulnerability in DirectX. But Microsoft officially confirmed that malicious code designed to harvest account credentials for online games had been detected bundled with exploits targeting the DirectShow vulnerability impacting Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003.

The flaw is Critical, the company warned in May 2009, when it revealed that users executing malicious QuickTime media files were at risk of remote code execution.

“Users, upon visiting a specially constructed web page that invokes the vulnerable media plug-in, will encounter exploit shellcode, which further execute and download additional malware to the infected machines. Intending to bypass antimalware protection, malware binaries are encrypted in the download data stream. New dog, same old tricks. To wrap up the attack scene, under the cover of the new exploits are the old long-lived online-game password stealers: PWS:Win32/Wowsteal.AP (drops PWS:Win32/Wowsteal.AP.dll); TrojanDropper:Win32/Dozmot.C (drops PWS:Win32/Dozmot.C and VirTool:WinNT/Dozmot.A); and TrojanSpy:Win32/Lydra.AE,” revealed Microsoft’s Lena Lin, Cristian Craioveanu, Josh Phillips and Patrick Nolan. Read More»

Conflicker Checker

April 04, 2009 by Jason

Contrary to some of the stories circulating in the more excitable sections of the media millions of PCs didn’t suddenly blow up following the much-anticipated reactivation of the Conflicker C virus on April 1st. In fact, at the time of writing nothing much seemed to have happened and the world moved on to more important matters. Nevertheless, this virus, and its ilk do present an ongoing threat, especially for PC owners who do not keep their security software and Windows Updates current. By the way, if you have any concerns about Conflicker C and malware in general and you think your PC may be infected I wouldn’t ask Google. I typed in ‘Conflicker C Removal’ a couple of days ago and the first three hits all led to websites carrying the virus!

If you have been lax with your security updates then your best bet is to download the free Microsoft Malicious Software Removal Tool, which scans your PC for Conflicker and a raft of other nasties, but in the end the best way to avoid becoming infected is to install a decent anti-virus program and regularly sweep your PC with cleaners like AdAware, A-Squared and Spybot.

malicious

Windows 7 Beta/RTM Official Security Solutions

January 05, 2009 by Jason

Just ahead of the public Beta of Windows 7, Microsoft has started recommending security solutions that can be integrated with the next iteration of its Windows client even at this early stage in the platform’s development. The first products designed to protect users running Windows 7 Beta come from Kaspersky and AVG, according to the Redmond company, which have promised to work with ISVs in order to produce security software compatible with Windows Vista’s successor since 2008. In this context, when it comes down to bulletproofing Windows 7, AVG and Kaspersky are ahead of the rest of the security industry with AVG Internet Security 8.0, AVG Anti-Virus 8.0, and the Technical Preview of Kaspersky Anti-Virus for Windows 7, respectively.

“Before you install antivirus software, check to make sure you don’t already have an antivirus product on your computer. If you do, be sure to remove the product you don’t want before you install the new one. It can cause problems on your computer to have two different antivirus products installed at the same time,” a message from Microsoft explains. Read More»

10 Spyware Warning Signs – Are You Infected?

November 20, 2008 by Jason

It’s been estimated that over 60% of all computers have some kind of spyware installed and most of their owners are unaware! If you are tired of your PC running slow and filling your screen with those nasty pop-up then you will want to read the 10 warning signs listed below.

Afterwards check out my “action plan” and what you can do to rid yourself of your spyware infestation.

1. Browser Hijacks – When I used to get a call from a customer saying that their homepage had suddenly changed, without them doing anything, I knew to bring my anti-spyware fighting software. Malicious programmers love to change your browser settings to transfer your homepage to their “client’s” websites.

2. PC is Crashing – Without warning, your PC starts crashing, freezing or locking up, but you haven’t added any new software or updated anything recently.

3. Pop-Ups – You open your browser to visit your favorite blog site then “WHAM!” You are suddenly drowning in pop-ups! Your screen is full of brightly colored lures to porn, gambling or gaming websites. You click on the “Close” or the “X” to shut it down
uh, oh something is downloading to your machine! Read More»

Windows 7 Malware Kit

November 18, 2008 by Jason

The exploit for a vulnerability affecting the Server Service on all supported versions of Windows has been included in a commercial malware kit, available for sale. MS08-067 is labeled with a maximum severity rating of Critical, and the security bulletin is designed to patch vulnerable Windows operating systems, which could allow for remote code execution via a successful attack involving a specially crafted, malicious RPC request. The vulnerability affects the latest Windows client and server operating systems, including Windows 7, Windows Vista Service Pack 1 and Windows XP Service Pack 3.

“Probably the most widely reported topic in the Chinese Security community this month will be the availability of a commercial MS08-067 attack pack, customized for Chinese users. On October 26th, 2008, exploit code was posted on to a well-known public repository site. In a few days, malware kit author, WolfTeeth, was quick to sell a MS08-067 port scanning tool with attack capability to his ‘customers,’ using free code from the Internet,” revealed Haowei Ren and Geok Meng Ong, from the McAfee Avert Labs.
The security issue is rated Critical on Windows Server 2004, Windows XP (including SP3), and Windows Server 2003, and just Important on Windows Vista (SP1) and Windows Server 2008. Microsoft made available MS08-067 as an out-of-band release in October 2008. During the same month the company issued the first security patch for Windows 7, designed for the pre-Beta Build 6801 Milestone 3 release. Read More»

Windows Vista and Malware Immunity

May 21, 2008 by Jason

At the beginning of May, security company PC Tools revealed that Windows Vista “is not so immune.” And in this attempt to wrap the obvious together with statistics from a limited pool of users and serve the result as a revelation, the security outfit went on to claim that “Windows Vista is more susceptible to malware than the eight year old Windows 2000 operating system, and only 37% more secure than Windows XP”. Apparently, PC Tolls had detected 639 unique threats per 1,000 Vista machines, in comparison to just 586 for Windows 2000, 478 for Windows Server 2003, and 1,021 for XP. The conclusion is, of course, nothing short of obvious and was stated as clear as possible, with a challenge to Vista’s malware immunity.

Now, the fact is that citing data from over 450 million computers, in respect to PC Tools’ just 1.4 million machines, Microsoft disputed the findings, and continued to claim that Windows Vista is the safest Windows operating system on the market. Microsoft has repeated this refrain since Vista was launched, and provided ample proof, from the data collected through the Malicious Software Removal Tool to vulnerability counting games involving the main platforms. Read More»

Windows Malicious Software Removal Tool

May 14, 2008 by Jason

An update version of the Microsoft Windows Malicious Software Removal Tool is now available for download and it’s a perfect fit for the latest service packs for Windows Vista and Windows XP. The Redmond company releases new versions of the Windows Malicious Software Removal Tool on the second Tuesday of each month, accompanying the availability of the Security Bulletins dropped as part of the monthly patch cycle. The updated version of MSRT is distributed via Windows Update, Microsoft Update, Windows Server Update Services and is also up for grabs on the Download Center.

Microsoft has failed to emphasize the fact that MSRT integrates seamless with both Windows Vista Service Pack 1 and Windows XP Service Pack 3. However, tests reveal that the tool plays well with the latest releases of the two operating systems. Vista SP1, RTM’d on February 4, 2008, was released to the general public on March 18, and XP SP3 is accessible to end users since May 6, having been released to manufacturing on April 21. Read More»

Is That a Worm in Your Windows Live Messenger ?

January 29, 2008 by Jason

Windows Live Messenger accounts for the largest community for any IM client worldwide. At the end of 2007, in November, as Microsoft was unveiling Windows Live 2.0, the next generation of its suite of software and services in the cloud, the company estimated that Windows Live Messenger had an install base of approximately 300 million users. In this context, it failed to come as a surprise the fact that Windows Live messenger was the most attacked instant messaging platform in 2007, according to statistics provided by FaceTime Communications. And with such a high profile, it is bound that the trend will continue into 2008. Read More»