Keyword: trojan

Brevity: Headers | « Text »
  • Linux webserver botnet pushes malware

    09/13/2009 9:24:24 AM PDT · by dayglored · 18 replies · 1,059+ views
    The Register (UK Tech) ^ | 2009-09-12 | Dan Goodin
    A security researcher has discovered a cluster of infected Linux servers that have been corralled into a special ops botnet of sorts and used to distribute malware to unwitting people browsing the web. Each of the infected machines examined so far is a dedicated or virtual dedicated server running a legitimate website, Denis Sinegubko, an independent researcher based in Magnitogorsk, Russia, told The Register. But in addition to running an Apache webserver to dish up benign content, they've also been hacked to run a second webserver known as nginx, which serves malware. "What we see here is a long awaited...
  • Bank data-stealing Trojan infects hundreds of thousands of PCs - researcher

    07/31/2009 9:36:51 AM PDT · by the invisib1e hand · 9 replies · 1,318+ views
    Finextra ^ | July 30, 2009 | Finextra
    A "tremendous" amount of financial data has been stolen by a Trojan that has infected hundreds of thousands of corporate and personal PCs, according to information security specialist SecureWorks. Clampi, also known as Ligats, Ilomo or Rscan, has spread across Microsoft networks in a "worm-like fashion" and is "one of the largest and most professional thieving operations on the Internet" says Joe Stewart, director of malware research at SecureWorks' counter threat unit. Once it has infected a PC, the Trojan monitors Web sessions to see if one of 4500 targeted sites are visited. If a victim uses one of these...
  • Can this Trojan be deleted?

    07/01/2009 7:12:27 AM PDT · by Oshkalaboomboom · 65 replies · 1,975+ views
    July 1, 2009 | Oshkalaboomboom
    I have a rootkit trace that refuses to go away. Macafee can't delete it. Malwarebytes Antimalware claims to delete it but it's right there as soon as it closes. I find hundreds of references to it via Google but nobody says how to get rid of it and nobody even discusses what it does besides annoy you. My cd burning programs have been disabled so I can't make an alternative OS like BartPE. I can boot off the Windows CD and get into the Recovery console. I use DOS commands to delete the files but they come right back again....
  • Virus hit me on Facebook - help!

    06/11/2009 8:49:43 PM PDT · by MeneMeneTekelUpharsin · 24 replies · 1,175+ views
    Vanity | 11 June 2009 | Mene Mene Tekel Upharsin
    Was downloading a video from the internet (Kung Fu movie) when my Avast anti-virus software first warned me of a trojan (from the find site) and then a worm. I deleted both. Both Avast and Trend Micro House Call show no infection. However, on my Facebook account, something sent an ugly message with an even uglier link (which also warned on a virus) to everyone on my Facebook. I do not automatically log in to Facebook, I put in my password every time. How did it do that?
  • Leaked copies of Windows 7 RC contain Trojan

    05/05/2009 7:35:35 PM PDT · by dayglored · 44 replies · 1,181+ views
    ComputerWorld ^ | May 4, 2009 | Gregfg Keizer
    Some pirated builds on file-sharing sites harbor attack code... Pirated copies of Windows 7 Release Candidate (RC) on file-sharing sites contain malware, according to users who have downloaded the upgrade. Windows 7 RC, which Microsoft Corp. will officialy launch tomorrow, leaked two weeks ago, with copies first appearing on BitTorrent tracking sites on April 24. Some of the pirated builds include a Trojan horse, numerous users said in message forums and in comments on BitTorrent sites such as Mininova.org. "Just a warning for anyone downloading the new RC builds of windows 7. Quiet [sic] a lot of the downloads have...
  • Final Internet Worm Warning!!!

    03/31/2009 4:59:22 PM PDT · by papasmurf · 102 replies · 4,292+ views
    Self ^ | 03/31/09 | papasmurf
    The conficker worm, aka:Downup, Downadup and Kido, is scheduled to become active at 00:01:00 AM on 04/01/09. It's a complete unknown and has many experts worried. If you aren't sure about being protected on your Windows machine, please download the FREE application from Microsoft called Windows SteadyState , and install it. It only takes a few minutes, it's very easy and simple, and it will protect your hard drive. I use it on my XP Box and my Wife's Vista laptop, and I know it works. Download it, click to install, open it, and select "User Restrictions", and (if...
  • Pentagon Hit by Unprecedented Cyber Attack

    11/20/2008 4:43:58 PM PST · by Sammy67 · 244 replies · 11,834+ views
    FoxNews ^ | 11/20/08
    <p>Thursday, November 20, 2008 The Pentagon has suffered from a cyber attack so alarming that it has taken the unprecedented step of banning the use of external hardware devices, such as flash drives and DVD's, FOX News has learned.</p> <p>The attack came in the form of a global virus or worm that is spreading rapidly throughout a number of military networks.</p>
  • MSM Refusal to Vet Obama: Affirmative Action President?

    10/17/2008 9:29:12 PM PDT · by Bronco_Buster_FweetHyagh · 18 replies · 556+ views
    Joe the Plumber asks Barack Obama a simple question, which elicits a damaging and revealing peek into Obama's true beliefs. Within two days, the Main Stream Media and left wing pundits and bloggers have waged a full blown character assassination of Joe the Plumber. (1) Insinuation Joe Lied about his name (its his middle name) (2) Accusation that Joe is a deadbeat (he has a tiny back tax bill), (3) Accusation that Joe is a law breaker (he works under the license of a different plumber like MANY tradesmen across the US), (4) Accusation he's a wife beater and a...
  • Scientists calculate the exact date of the Trojan horse using eclipse in Homer

    06/24/2008 11:49:01 AM PDT · by LibWhacker · 37 replies · 60+ views
    Telegraph ^ | 6/24/08 | Roger Highfield
    The exact date when the Greeks used the Trojan horse to raze the city of Troy has been pinpointed for the first time using an eclipse mentioned in the stories of Homer, it was claimed today. # The truth about an epic tale of love, war and greed Scientists have calculated that the horse was used in 1188 BC, ten years before Homer in his Odyssey describes the return of a warrior to his wife on the day the "sun is blotted out of the sky". The legend of the fall of Troy is mentioned in Virgil and Homer's poems...
  • Incredible Message About[Dr. Don Boys'] Islam Book from a Muslim Nation!

    06/09/2008 7:46:55 PM PDT · by John Leland 1789 · 2 replies · 152+ views
    Preacher Helps ^ | June 9, 2008 | Dr. Don Boys
    Incredible Message About my (Dr. Don Boys) Islam Book from a Muslim Nation! How this brother got my book on Islam I don’t know. He must have purchased it while visiting in another country or someone sent it to him. He says he would be killed by followers of that peaceful religion of Islam if it were known that he had my book! What a way to live! Following is his email except for his name and country. I got to read some parts of your book Islam: America 's Trojan Horse. I would like to mention that it is...
  • The New E-spionage Threat (CHINA)

    04/14/2008 4:34:47 AM PDT · by Perseverando · 11 replies · 200+ views
    BusinessWeek Magazine ^ | April 10, 2008 | Brian Grow, Keith Epstein and Chi-Chu Tschang
    A BusinessWeek probe of rising attacks on America's most sensitive computer networks uncovers startling security gaps The e-mail message addressed to a Booz Allen Hamilton executive was mundane—a shopping list sent over by the Pentagon of weaponry India wanted to buy. But the missive turned out to be a brilliant fake. Lurking beneath the description of aircraft, engines, and radar equipment was an insidious piece of computer code known as "Poison Ivy" designed to suck sensitive data out of the $4 billion consulting firm's computer network. The Pentagon hadn't sent the e-mail at all. Its origin is unknown, but the...
  • Worm infected Daughters Laptop (worm.win32.netsky)

    02/06/2008 6:12:48 PM PST · by SandRat · 23 replies · 76+ views
    Ok, Daughter's laptop with an up to date anti-virus program and firewall has gotten infected with a worm called worm.win32.netsky. Can't find a removal program for this bugger and the scans haven't found or removed it. She was going to various School District web sites to apply for a teaching job when it happened It loaded on it's own new desktop icons, and diabled remove program from the task bar along with Ctl-Alt-Del. Anyone out there got ideas?
  • DIGITAL PHOTO FRAME WITH VIRUS

    01/18/2008 6:48:33 PM PST · by SWAMPSNIPER · 8 replies · 281+ views
    self | January 18, 2008 | swampsniper
    Digital photo frames containing malware have been found, heads up! http://isc.sans.org/diary.html?storyid=3807 http://isc.sans.org/diary.html?storyid=3787
  • (Reggie) Bush evidence mounts

    01/10/2008 10:02:58 PM PST · by stainlessbanner · 30 replies · 122+ views
    Yahoo Sports ^ | January 10, 2008 | Charles Robinson and Jason Cole
    A former business associate of the failed marketing agency that attempted to secure Reggie Bush as a client told Yahoo! Sports he spoke directly to Bush about the company's business plan before the running back completed his junior season at the University of Southern California. Such an action would have violated NCAA rules and is the latest in a series of facts uncovered in a Yahoo! Sports investigation that indicate Bush and his family had an improper relationship with New Era Sports & Entertainment. Ben Delanoy, now CEO of Next Level Sports Marketing, said Bush indicated he would be part...
  • Bhutto murder used to spread malware

    12/28/2007 8:23:00 PM PST · by snarkpup · 7 replies · 260+ views
    The Register ^ | 12/28/2007 | John Leyden
    Malicious JavaScript pushes Trojan Virus writers are exploiting morbid curiosity about the assassination of former Pakistani Prime Minister Benazir Bhutto's to spread malware. Surfers searching for video footage of the suicide attack that killed Bhutto and at least 21 others on Thursday are liable to find malware posing as video clips that attempts to trick users into running malign ActiveX controls. The malicious downloaded file is detected by Symantec as the Emcodec-Trojan.
  • Online Crooks Target Macs With Porn Ruse (Apple)

    11/01/2007 8:38:22 PM PDT · by Alter Kaker · 23 replies · 392+ views
    Associated Press ^ | 1 November 2007 | Jordan Robertson
    SAN FRANCISCO — In a backhanded compliment to Apple Inc., online criminals are apparently so impressed with its scorching sales they are sending Macintosh computers an attack typically aimed at machines running Microsoft Corp.'s dominant Windows operating system. Symantec Corp. researchers said the Web sites serving up the new attack also deploy a Windows version. "For a while Mac users have enjoyed the benefits of being a small enough population that hackers didn't go after them directly _ that's obviously now changing," said Ben Greenbaum, senior research manager at Symantec Security Response. Lynn Fox, an Apple spokeswoman, said the Cupertino-based...
  • Multi-Middleman 'Mpack' Attacks Use Google AdWords to Lure Victims

    06/19/2007 6:11:16 PM PDT · by Cicero · 1 replies · 474+ views
    BetaNews ^ | June 19, 2007 | Scott M. Fulton, III
    Multi-Middleman 'Mpack' Attacks Use Google AdWords to Lure Victims By Scott M. Fulton, III, BetaNews June 19, 2007, 11:46 AM One of Russia's fastest growing markets, and quite possibly a contributor to stabilizing that country's fickle economy, is cut-rate, self-deploying Trojan horse packages. As malware writers there have discovered, rather than baiting and waiting for victims to fall into their traps at random, so that they carry out DoS and identity theft attacks without knowing they're doing so, would-be victims worldwide will gladly pay for the privilege of knowingly carrying out those same attacks. "In terms of social engineering," writes...
  • Keylogging Trojan Dodges Anti-virus Detection -Alert!!

    05/25/2007 2:34:07 PM PDT · by Ernest_at_the_Beach · 46 replies · 1,939+ views
    HardOCP ^ | Brian Prince | Brian Prince eWeek
    A new variant of the Russian Trojan Gozi, armed with keylogging functionality, is making the rounds again. What makes this time different is that the Trojan can scramble itself to avoid detection by your anti-virus software. The Trojan is believed to have been spreading since April 17. Like the original, which was discovered earlier in 2007, the new version of Gozi steals data from encrypted SSL (Secure Sockets Layer) streams. The latest variant was uncovered May 7 by Don Jackson, a security researcher at SecureWorks in Atlanta. Comments Posted by Steve 3:15 PM (CDT)
  • Computer Help Request- Win:Agent32 trojan -{vanity)

    05/22/2007 3:44:13 AM PDT · by Tainan · 7 replies · 584+ views
    n/a ^ | 22 May 2007 | self
    I have discovered a Win32:Agent trojan resident in a file on my C: drive. It is located in my Thunderbird email files section. Try as I may, I cannot seem to delete this. It appears to be growing in size. I have read a lot about this one and they refer to it as a "sleeper" trojan. How can I remove this trojan? I run Firefox, Thunderbird as email client, XP Pro, Avast & AVG 7.5 Internet Security System, Zone Alarm Pro, along with Spy Bot S&D and Spyware Blaster.Can anyone help with this?Thanks
  • Phoney Windows piracy check steals credit cards; New attack attempts to spoof WGA

    05/07/2007 7:17:40 PM PDT · by holymoly · 15 replies · 1,478+ views
    computing ^ | 07 May 2007 | Shaun Nichols
    Online criminals are using Windows registration pages as new way to fool consumers into divugling confidential information, researchers with Symantec have noticed. The security firm said that it has spotted a new trojan that steals credit card information by posing as an anti-piracy control for Windows XP. The phishing trojan mimicks the behavior of Microsoft's Windows Genuine Advantage (WGA) anti-piracy software, which tracks down pirated copies of the operating system. On startup, the trojan produces a window informing the user that their copy of Windows has been activated by another user. In order to "re-activate" Windows, the software asks the...
  • Storm Worm variant ignites e-mail virus deluge

    04/13/2007 10:31:55 AM PDT · by holymoly · 24 replies · 2,127+ views
    ZDNet ^ | April 13, 2007 | Caroline McCarthy
    Thursday likely marked the largest proliferation of e-mail virus attacks in more than a year, according to security company Postini. Postini said that two variations of the Storm Worm virus, which originally spread across the Internet in January, have quickly driven global virus levels 60 times higher than their daily average. E-mail users should be on alert for messages with "love"-related subject lines and an executable attachment that would contain a Trojan virus, as well as messages with "Worm Alert!" subject lines that contained a .zip file full of malicious code. Postini, which is based in San Carlos, Calif., says...
  • Hacker admits identity theft

    02/23/2007 8:43:17 AM PST · by APRPEH · 3 replies · 346+ views
    Irish Dev News ^ | 23 February 2007 | non attributed
    IT security and control firm Sophos is welcoming news that a US man has pleaded guilty to charges of writing and distributing a Trojan horse designed to steal usernames and passwords from computer users. "The Trojan has been the key development in cybercrime in recent years - hackers use them to steal info and money from unsuspecting internet users" Graham Cluley, Sophos Richard C Honour, 31, faces a maximum penalty of five years in prison and a fine of $250,000 after admitting releasing malware that infected users of DarkMyst, an IRC chatroom popular with players of online role-playing games. Honour,...
  • Inventor broke after Trojan fails to catch fire [full body armor exoskeleton for the troops a bust]

    02/08/2007 1:37:23 AM PST · by LibWhacker · 126 replies · 4,885+ views
    Hamilton Spectator ^ | 2/7/07 | Wade Hemsworth
    Troy Hurtubise is facing eviction after his Trojan invention flopped.Troy Hurtubise really put everything he had into his bulletproof combat suit. He spent two years and tens of thousands of dollars developing the Trojan, hoping to sell it to the Canadian or American armed forces, or to another friendly government. Now he's broke. Last month, he promised the Trojan would give soldiers in the field affordable, lightweight protection from bullets and bombs alike. He had worked all kinds of extras into the body armour: a ventilation system and multiple lights in the helmet, pepper spray that could shoot from the...
  • [Vanity]Trojan removal help INTCODEC-V6.766[1].EXE, with circumstances

    09/07/2006 1:51:01 PM PDT · by JerseyHighlander · 24 replies · 697+ views
    http://www.freerepublic.com ^ | 9/6/06 | JerseyHighlander
    I have a trojan, do not know how I picked it up: intcodec-v6.667.exe and intcodec-v6.400.exe The WGA on this WinXP pro was made invalid, and now I can't DL updates for Norton Virus either. Those are seperate issues. Immediate need is to remove this virus, only ref I got on the net was here http://fileinfo.prevx.com/adware/qq2b5d34188554-INTC22293613/INTCODEC-V6.766%5B1%5D.EXE.html but I do not know anything about prevx.com or the free removal tool for this trojan. Does anyone know if prevx is legit, and does anyone know of any other ways to remove this trojan? Thanks for the help.
  • New Trojan (BHO) disguises malicious traffic

    08/08/2006 7:14:04 PM PDT · by holymoly · 12 replies · 449+ views
    ITNews.com.au ^ | 9 August 2006 | Gregg Keizer
    Websense raises the alarm about a phishing Trojan that uses a new technique to cloak its activity. The Web security company said that the Trojan, which installs itself as an Internet Explorer helper object, waits for the user to enter information in specific Web site forms -- particularly online banking sites -- then zaps the stolen data back to the attacker. What's unique about the new Trojan, said Websense, is that it delivers that data via ICMP packets. Keylogging Trojans usually transmit purloined usernames and passwords via e-mail or a HTTP POST command. Both can be easily spotted. "Instead, this...
  • Trojan Spoofs Firefox Extension, Steals IDs

    07/26/2006 7:26:07 AM PDT · by ShadowAce · 71 replies · 1,978+ views
    TechWeb ^ | 25 July 2006 | Gregg Keizer
    An identity-stealing keylogger that disguises itself as a Firefox extension and installs silently in the background was discovered Tuesday by security vendor McAfee. According to the Santa Clara, Calif.-based company, the "FormSpy" Trojan horse monitors mouse movements and key presses to steal online banking or credit card usernames and passwords, other login information, and URLs typed into Firefox, the popular open-source browser. Another component of the Trojan sniffs out passwords from ICQ and FTP sessions, and IMAP and POP3 traffic, said McAfee. All collected information is sent to an IP address hard-coded into the Trojan. The scam starts with spam...
  • New Trojan Asteroid Hints At Huge Neptunian Cloud

    06/15/2006 2:26:20 PM PDT · by blam · 19 replies · 708+ views
    New Scientist ^ | 6-15-2006 | Kelly Young
    New Trojan asteroid hints at huge Neptunian cloud 19:00 15 June 2006 NewScientist.com news service Kelly YoungThe four known Neptune Trojans are shown in their position 60 degrees ahead of Neptune. The known clusters of Trojan asteroids on either side of Jupiter are also shown (Illustration: Scott Sheppard) A newly discovered asteroid in Neptune's orbit indicates the existence of a much larger, but as-yet-unseen, cloud of rocks in that region. The asteroids in Neptune's orbit might even outnumber those in the main asteroid belt between Mars and Jupiter, the new research suggests." The asteroid was discovered by Scott Sheppard of...
  • Europe rethinks its 'safe haven' status-(45 percent of Muslim immigrants "unintegratable,")

    05/24/2006 9:39:15 PM PDT · by Flavius · 17 replies · 845+ views
    chritian science monitor ^ | 5/24/06 | Sarah Wildman,
    VIENNA - The night air in Vienna has finally turned warm, filling the city's trams with visitors. On the Ringstrasse, tourists take in the city, pointing out the City Hall and the parliament. ADVERTISEMENT "Did you see that one girl - so young! And wearing a veil," a woman clucks in lightly accented English, staring out the window of tram D. "They will form a separate culture." The sentiment isn't isolated. Earlier this month, Austria's Interior Minister Liese Prokop announced that 45 percent of Muslim immigrants were "unintegratable," and suggested that those people should "choose another country." In the Netherlands,...
  • Trojan Freezes Computer, Demands Ransom

    04/28/2006 12:40:23 PM PDT · by Former Fetus · 54 replies · 1,786+ views
    yahoo news ^ | 4/28/06 | Jeremy Kirk
    A new kind of malware circulating on the Internet freezes a computer and then asks for a ransom paid through the Western Union Holdings money transfer service. A sample of the Trojan horse virus was sent to Sophos, a security vendor, said Graham Cluley, senior technology consultant. The malware, which Sophos named Troj/Ransom-A, is one of only a few viruses so far that have asked for a ransom in exchange for releasing control of a computer, Cluley said. The new Trojan falls into a class of viruses described as "ransomware." The schemes had been seen in Russia, but the first...
  • Microsoft Official: Malware Recovery Not Always Possible

    04/04/2006 6:41:25 PM PDT · by HAL9000 · 133 replies · 3,179+ views
    FoxNews.com (Excerpt) ^ | April 4, 2006 | Rayn Naraine
    Excerpt - LAKE BUENA VISTA, Fla. — In a rare discussion on the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation. "When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit," Mike Danseglio, program manager in the Security Solutions group at Microsoft, said in a presentation at...
  • How deep does this rabbit hole go?

    03/31/2006 9:05:27 AM PST · by grandpa jones · 11 replies · 898+ views
    Business week ^ | 04/10/06 edition | staff
    This Worm Is Nasty, Brutish, And Sneaky As a data security specialist, Jeremy Pickett sees all kinds of digital tricks. So on Mar. 20, when he was tracing the origins of a computer worm that had been blocked the night before from entering a client's computer network, Pickett wasn't too surprised that it tried to connect with four sleazy Web sites, most of them, he believes, in Russia. Or that it then tried to load victims' PCs with as many as 30 new pieces of "malware," ranging from spam programs to those that automatically dial in to expensive phone-sex services....
  • 'Critical' IE bug threatens PC users

    03/27/2006 6:58:48 PM PST · by Ernest_at_the_Beach · 43 replies · 1,092+ views
    theregister.co.uk ^ | Monday 27th March 2006 09:14 GMT | Ciara O'Brien, ElectricNews.net
    A dangerous new exploit in Internet Explorer could put PCs and data at risk, Microsoft has admitted. The flaw, for which code has already been published on the internet, could be exploited to set an email-borne virus free on the unsuspecting public. Potential viruses could come as an attachment that conceals the code, or could possibly redirect users to a site that will unleash the code on the user's machine, leaving the computer open to remote attack. Once the PC is being controlled by a malicious user, it can then be used to launch attacks on other PCs. Even supposedly...
  • New Twist on Spyware--Ransonware (My Title)

    03/16/2006 7:43:24 PM PST · by yhwhsman · 36 replies · 1,313+ views
    LurHQ ^ | March 11, 2006 | by LURHQ Threat Intelligence Group
    In May 2005, a trojan called PGPcoder was discovered in the wild by Websense Security Labs. The trojan's purpose was to encrypt a user's files, then demand a ransom for their decryption. Although this scheme seemed novel, it is actually predated by over 15 years, by a similar scam in 1989. LURHQ's Threat Intelligence Group has now discovered a third such scheme involving ransomware which we are calling Cryzip. Unlike PGPcoder, which used a custom encryption scheme (which was subsequently reverse-engineered by LURHQ), Cryzip uses a commercial zip library in order to store files inside a password-protected zip. Although the...
  • New virus seeks 'ransom' for computer files

    03/15/2006 11:34:19 PM PST · by martin_fierro · 21 replies · 710+ views
    AFP/Yahoo ^ | Wed Mar 15, 12:56 PM ET
    New virus seeks 'ransom' for computer files Wed Mar 15, 12:56 PM ET WASHINGTON (AFP) - In the equivalent of a holdup in cyberspace, a new computer bug locks up a user's file with encryption and demands a 300-dollar "ransom," security experts say. The so-called "ransomware" Trojan was discovered Saturday by the security firm LURHQ, which said it was based on a similar scheme perpetrated 15 years ago. Users whose computers are infected receive an e-mail stating that their files have been encrypted and will not be unlocked unless they transfer 300 dollars to a special account. In poorly written...
  • FR Folding@Home Project Update - We're in the Top 165 teams (A Tribute to Ronald Reagan)

    03/13/2006 8:55:21 AM PST · by soccer_maniac · 217 replies · 2,984+ views
    Folding@Home Official Stats ^ | 3-13-2006 | soccer_maniac
    Time for a new FreeRepublic folding@home thread. Our FreeRepublic team of 300+ members comprised primarily of Free Republic members in good standing have banded together to donate their excess CPU cycles to a worthy cause. Via distributed computing, millions of computers around the world, contribute directly to scientific research, in the quest for a greater understanding of diseases such as Alzheimer's, Cancer, and Mad Cow (BSE). Currently, the team is in 164th place (with 992 CPUs - nearly 19,000 completed Work Units and 2,982,241 points) This is an entirely voluntary program, and if you want to learn more, please see...
  • The First Mac OS X Virus? (A New OS X Trojan)

    02/16/2006 5:27:22 AM PST · by Panerai · 50 replies · 1,084+ views
    MacRumors.com ^ | 02/16/2006
    On the evening of the 13th, an unknown user posted an external link to a file on MacRumors Forums claiming to be the latest Leopard Mac OS X 10.5 screenshots. The file was named "latestpics.tgz" The resultant file decompresses into what appears to be a standard JPEG icon in Mac OS X but is actually a compiled Unix executable in disguise. An initial disassembly (from original discussion thread) reveals evidence that the application is virus-like or was designed to give that impression. Routines listed include: _infect: _infectApps: _installHooks: _copySelf: The exact consequences of the application are unclear, but according to...
  • US hacker pleads guilty to hijacking thousands of computers

    01/25/2006 5:35:35 AM PST · by Calpernia · 16 replies · 585+ views
    Middle East Times ^ | January 25, 2006
    LOS ANGELES, CA, USA -- A US computer hacker on Monday pleaded guilty to hijacking around 400,000 computers, including military servers, and infecting them with malicious software. In the first such prosecution of its kind, "botmaster" Jeanson Ancheta, 20, admitted infecting the computers with software that caused them to send spam, show ads and launch crippling attacks on Internet sites. In federal court in Los Angeles, Ancheta admitted conspiring to violate both the Computer Fraud Abuse Act and an anti-spam law, to causing damage to US defense computers and to hacking into computers to commit fraud. His plea comes after...
  • The Windows MetaFile Backdoor?

    01/16/2006 9:48:37 AM PST · by ShadowAce · 106 replies · 2,090+ views
    Security Now! ^ | 13 January 2006 | Steve Gibson/Leo LaPorte
    This is a transcript from a show Steve Gibson did with Leo LaPorte. The link to the audio is at the above link. Also, I will excerpt a little of the relevant information here.Steve: And so, you know, because I'm a developer when I'm not being a hacker, I wanted to understand - oh, and the other thing is, I want to write a robust testing application, you know, that always works all the time. So I wanted to know, like, okay, what bytes have to be set which way, what matters, what doesn't. Because, you know, that's the way...
  • WMF (Windows meta file) exploit

    01/02/2006 5:07:56 AM PST · by KeyWest · 49 replies · 2,023+ views
    The SANS Institute ^ | January 2, 2005 | Various
    Looking forward to the week ahead, I find myself in the very peculiar position of having to say something that I don't believe has ever been said here in the Handler's diary before: "Please, trust us." I've written more than a few diaries, and I've often been silly or said funny things, but now, I'm being as straightforward and honest as I can possibly be: the Microsoft WMF vulnerability is bad. It is very, very bad.
  • Microsoft To Patch Windows on January 10th; Attack Spreads

    01/03/2006 11:42:23 AM PST · by HAL9000 · 52 replies · 3,196+ views
    Dow Jones News Service (excerpt) ^ | January 3, 2006 | Chris Reiter
    Excerpt - NEW YORK -(Dow Jones)- Microsoft Corp. (MSFT) plans to release a patch for a new security flaw at its next scheduled update release on Jan. 10, leaving users largely unprotected until then from a rapidly spreading computer virus strain. "Microsoft's delay is inexcusable," said Alan Paller, director of research at computer security group SANS Institute. "There's no excuse other than incompetence and negligence." "It's a problem that there's no known solution from Microsoft," said Alfred Huger, senior director of engineering at Symantec Corp.'s (SYMC) security response team. SANS Institute, via its Internet Storm Center, has taken the unusual...
  • Windows PCs face ‘huge’ virus threat

    01/02/2006 3:54:03 PM PST · by Swordmaker · 204 replies · 7,058+ views
    Financial Times via Drudge ^ | January 2 2006 18:18 | By Kevin Allison in San Francisco
    Computer security experts were grappling with the threat of a newweakness in Microsoft’s Windows operating system that could put hundreds of millions of PCs at risk of infection by spyware or viruses. The news marks the latest security setback for Microsoft, the world’s biggest software company, whose Windows operating system is a favourite target for hackers. “The potential [security threat] is huge,” said Mikko Hyppönen, chief research officer at F-Secure, an antivirus company. “It’s probably bigger than for any other vulnerability we’ve seen. Any version of Windows is vulnerable right now.” The flaw, which allows hackers to infect computers using...
  • Potential new unpatched IE exploit ? ~ Yes...may affect other Browsers also...

    12/28/2005 2:55:03 PM PST · by Ernest_at_the_Beach · 69 replies · 2,811+ views
    Websense Security Labs ^ | Dec 28 2005 11:19AM | Websense Security Labs Blog Staff
    This alert is a follow-up to a post made yesterday on our blog: http://www.websensesecuritylabs.com/blog/ Websense® Security Labs™ has discovered numerous websites exploiting an unpatched Windows vulnerability in the handling of .WMF image files. The websites which have been uncovered at this point are using the exploit to distribute Spyware applications and other Potentially Unwanted Soware. The user's desktop background is replaced with a message warning of a spyware infection and a "spyware cleaning" application is launched. This application prompts the user to enter credit card information in order to remove the detected spyware. The background image used and the "spyware...
  • Exploit Released for Unpatched Windows Flaw

    12/28/2005 5:45:47 PM PST · by Salo · 25 replies · 1,345+ views
    Washington ComPost ^ | 12/28/05 | Brian Krebs
    Security researchers have released instructions for exploiting a previously unknown security hole in Windows XP and Windows 2003 Web Server with all of the latest patches applied.
  • First Neptune Trojan Discovered

    12/28/2005 3:40:34 PM PST · by SunkenCiv · 7 replies · 459+ views
    Lowell Observatory ^ | January 8, 2003 | Kristi Phillips, Manager of Media Relations and Public Affairs
    This small body, known as 2001 QR322, leads Neptune around its orbit in such a way as to maintain, on average, approximately equal distance from Neptune and the Sun. As such, it mimics the Trojan asteroids of Jupiter which orbit the Sun in two clouds approximately 60 degrees ahead of and behind Jupiter. The first Jovian Trojan was discovered in 1906 and approximately 1,560 such objects are known today. However, until the discovery of 2001 QR322, Trojan-like objects associated with other giant planets had not been found.
  • Spy Axe 3.0

    12/06/2005 8:16:34 PM PST · by Carling · 87 replies · 4,971+ views
    My PC ^ | 12/6/05 | Me
    I hate vanity posts, but I am wondering if anyone in FR land knows anything about the Spy Axe 3.0 virus. It has set up shop in my toolbar and has hijacked my home page. eTrust isn't touching it. Help?!?!
  • UGLY SPYAXE VIRUS ALERT (VANITY)

    12/06/2005 6:38:12 PM PST · by CAWats · 61 replies · 8,327+ views
    12-06-2005 | Cawats
    My computer apparently picked up a virus from spyaxe.net. I have a pop-up window saying I have spyware and "it is recommended to use antispyware tools to prevent data loss." Everytime I close the popup it pops up again. I got tired of closing it and installed it then removed it with "Add/Remove Software" in the control panel. The pop-up is back. Can anyone help?
  • Trojan exploits unpatched IE flaw

    12/01/2005 7:41:41 AM PST · by ShadowAce · 28 replies · 871+ views
    The Register ^ | 1 December 2005 | John Leyden
    The release of a Trojan that exploits an unpatched IE hole has prompted speculation that Microsoft may release an emergency out-of-cycle security patch. The Delf-DH Trojan downloader uses an Internet Explorer vulnerability to infect unprotected Windows users who stray onto maliciously constructed websites. Delf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites. The attack relies on a flaw in the way IE handles requests to the window() object, highlighted by proof-of-concept code last week and now used in anger by VXers. Even fully patched Windows 2000 and Windows...
  • Sony Rootkits: A Sign Of Security Industry Failure (List of 52 CD Titles)

    11/18/2005 3:16:07 PM PST · by Eagle9 · 32 replies · 1,299+ views
    TechWeb News ^ | November 18, 2005 | Gregg Keizer
    Sony's controversial copy-protection scheme had been in use for seven months before its cloaking rootkit was discovered, leading one analyst to question the effectiveness of the security industry. "[For] at least for seven months, Sony BMG Music CD buyers have been installing rootkits on their PCs. Why then did no security software vendor detect a problem and alert customers?" asked Joe Wilcox, an analyst with JupiterResearch. "Where the failure is, that's the question mark. Is it an indictment of how consumers view security software, that they have a sense of false protection, even when they don't update their anti-virus and...
  • MS' Reaction to Sony's Rootkit Raises Some Questions

    11/17/2005 6:09:52 AM PST · by ShadowAce · 79 replies · 1,624+ views
    Groklaw ^ | 13 November 2005 | Pamela Jones
    When the news first broke in the mainstream press that Windows expert and blogger Mark Russinovich (he wrote a book about Windows for Microsoft) had found that Sony's anti-piracy efforts had gone too far and that Sony's DRM was installing an undetectable rootkit on customers' computers which they couldn't safely remove, the first reaction from Microsoft was guarded. They were concerned, they said, and were evaluating what, if anything, to do: Microsoft, which also ships an anti-spyware program, recently renamed "Windows Defender," hasn't yet decided whether it will also flag the Sony DRM software as malicious code, the spokesperson said....
  • Sony has infected over one-half million world wide nets incl U.S. Military

    11/15/2005 1:43:21 PM PST · by dickmc · 109 replies · 4,351+ views
    Welcome to Planet Sony ^ | 2005-11-15 09:28 | Dan Kaminsky
    More than one-half million networks infected by Sony including U.S. military and various countries. Dan Kaminsky, http://www.doxpara.com/ ,is the expert who broke this and did the work. His U.S. and Europe infection maps are shown below and are frightening. Dan did a hell of a good job. Search Google News for "sony numbers trouble" for more in an excellent article today that is very worth reading.