Showing posts with label Virus alerts. Show all posts
Showing posts with label Virus alerts. Show all posts

"FBI vs. Facebook" Storm Worm Makes Computers Go Mad

FBI warns users not to open any emails that are headed by the "FBI vs. Facebook" subject. They do not contain any information regarding a lawsuit, an investigation, or other activity that the two parts could be involved in. Clicking on the eye-catching titled emails will result in users being infected with a storm worm. This makes their machines part of a widespread storm worm botnet, which has the ability of transforming personal computers into machines that intermediate identity thefts or malware spread throughout the network.

Storm worm hidden in

When trying to visualize the email that promises details of the confrontation between the federal institution and the social network, users receive the message "Your download will start shortly. If you are unable to read the article, save it and run on your computer." Those who choose to save the executable file are infected with the storm worm and lose control over some of the activities on their computers.

"The spammers spreading this virus are preying on Internet users and making their computers an unwitting part of criminal botnet activity. We urge citizens to help prevent the spread of botnets by becoming web-savvy. Following some simple computer security practices will reduce the risk that their computers will be compromised," said Special Agent Richard Kolko, Chief, FBI National Press Office.

The FBI also offered some common sense advice to aid users in keeping their systems safe from becoming affected by the storm worm virus. They are warned not to click on emails coming from unknown senders, especially if these come with attached pictures, which can easily hide malware. Also, people are encouraged to go directly to the homepage of an institution and search from there, rather than click on a link they receive. Finally, the FBI recommends caution whenever someone, no matter how authoritative they may seem, asks for private information or, most importantly, for financial details.

[Source: softpedia]

New Worm Attack on Facebook and MySpace Users

Facebook and MySpace users are threatened by a new worm
Comments: Facebook and MySpace users are threatened by a new worm
Credits: techshout

Kaspersky Lab released a warning for MySpace and Facebook users, regarding two new versions of a worm, Net-Worm.Win32.Koobface.a. and Net-Worm.Win32.Koobface.b respectively, that put the security of those who have accounts on the two web services at risk.

The MySpace worm creates some catchy phrases that are sent to friends' accounts. Appealing taglines, such as "You must see it!!! LOL. My friend catched you on hidden cam" or "Paris Hilton Tosses Dwarf On The Street", are used to create spam messages that, click by click, are spread all over the network.

The spam messages Kaspersky specialists discovered include links to http://youtube.[skip].pl. and those who choose to click on these links are redirected to another address, http://youtube.[skip].ru. If users want to see the video they were interested in, they are told to click on an executable file that will provide them with the latest Flash Player version, which is compulsory in order to watch the media file. The codesetup.exe is installed on the computer and it acts as a link between Facebook and MySpace accounts. Users who received the spam message on one of the two networks would actually download the other worm on their computers.

Social networks have plenty of users, and most of them are not very careful when they click on some links apparently sent by their friends. If the link they are invited to visit actually contains some hidden malware, the damage extends not only to their social network accounts, but to a wider range of Internet applications.

"Unfortunately, users are very trusting of messages left by 'friends' on social networking sites. So the likelihood of a user clicking on a link like this is very high," says Alexander Gostev, Senior Virus Analyst at Kaspersky Lab. "At the beginning of 2008 we predicted that we'd see an increase in cybercriminals exploiting MySpace, Facebook and similar sites, and we're now seeing evidence of this. I'm sure that this is simply the first step, and that virus writers will continue to target these resources with increased intensity," he further noted.

[Source: softpedia]

Ethical Hacker from Syria Will Crack Any Program

The name of this hacker is Abdul-Rahman Mahaini, he is 26 years old and he lives in Damascus, Syria. According to him, he has so far cracked software programs worth millions of dollars and he will continue to do so, no matter how difficult it is to crack a certain program. He says that he does not do this for the hacking thrill, but because of the software sales restrictions imposed on Syria by the US. It all boils down to the fact that, since you cannot buy it, you can always hack it.

Abdul-Rahman Mahaini is not easily deterred by the complexity of a program or the measures employed to make cracking it more difficult. As long as you can get hold of him, he will be more than happy to hack into any software program you’ll give him. The thing is that Abdul follows a strict ethical guide and he will not go against it; so you might as well forget about asking him to break into someone's e-mail or bank account. But if you want him to crack GTA IV, he will do it for as little as $2.

Hackers such as Abdul are seen as the modern version of Robin Hood in Syria, because it is practically impossible for US software developers to sell their products there. The only viable means of getting hold of much needed software is through the aid of hackers. "If you try to deprive me, I will take it from you," says Abdul as cited by the LA Times.

Syrian hacker goes by ethics code
Comments: Syrian hacker goes by ethics code
Credits: LA Times

According to Abdul, there is a key difference between a hacker and a cracker: "Crackers destroy. Hackers create. When you're a professional hacker, you are a distinguished type of person. There's something sacred in the world of hackers."

Of course, there are some who approach the current situation in Syria from a political point of view. Samir Hamade, information science teacher with the Kuwait University comments: "This is the way they're fighting back against American aggression. They say a lot of companies are giving money to Israel, so it's even better to use pirated software than licensed software since you're taking money from Israel."

Updates and Task Manager Disabled by New Windows XP Worm

The Windows functions are always under attack because disabling a vital function of the operating system automatically means an open door for the hacker, who would be able to infiltrate into the computer and conduct his malicious activities. Today, a new worm has been spotted in the wild and, according to security company Trend Micro, it affects most flavors of the operating system produced by Microsoft, including Windows 98, ME, NT, 2000, XP and Server 2003.

But what's worse is that WORM_SILLYFDC.CY has a high damage potential
and a high distribution potential, two elements that underline the worm's capability to reach your computer and harm the data stored on it. In case you're curios about how can you get infected, the process is pretty simple: all you need to do is to visit an infected page. However, the worm may also be dropped by another piece of malware, Trend Micro explains.

The main targets of the worm are two important Windows functions: the Automatic Windows Update and the Task Manager. Both features of the operating system are disabled, so the users would not be able to update their Windows version or to check the running processes in order to shut down the infection.

The Windows Task Manager
Comments: The Windows Task Manager

Just like many other recent worms, WORM_SILLYFDC.CY spreads itself through the clean removable drives connected to the computer. Every time a removable drive is plugged into the system, the worm copies an Autorun.inf file to execute itself once the device is connect to another PC.

In addition, "it infects files of certain types. It does this by adding an iFrame tag that contains a link to a malicious site. As of this writing, the iFrame tag may contain a malicious URL," Trend Micro explains.

[Source: softpedia]

Hacked Antivirus Site Delivers Virus

‘Things just ain’t the same for gangsters,’ Dr Dre said in his album, 2001. He couldn’t have said it better to explain the situation AvSoft Technologies’ situation even if he had wanted to. It seems it’s not enough to be developing antivirus software in order to protect your clients’ computers and have a reputation for that, you gotta play it safe and look after your own back as well.

Roger Thompson, chief research officer with security vendor
AVG, told PC World that "They [AvSoft] let one of their pages get hit by an iFrame injection. […] It shows that anyone can be a victim. … It’s hard to protect web servers properly." iFrame attacks have been very common in the past months, as they exploit a technique frequently used by web developers to insert content into their web pages. Another opinion, that of McAfee Security Research Manager, Dave Marcus, says that the site was probably compromised by taking advantage of a web programming error, most likely in the site’s SQL or PHP code. Experts agree that hackers wrote automated programs that search for exactly this type of flaw and they automatically infect the respective site.

The software being installed on users’ computers is a variant of the Virut virus family, a ‘parasitic infector’ virus that is extremely difficult to remove. Ironically, AcSoft specializes in recovering data lost due to virus attacks. If you got infected by going to the company’s download page, chances are you’ll be hitting it again, to download their tool for mending the situation. Vicious circle?

The way Symantec sees Virut
Comments: The way Symantec sees Virut

The upside, if the term doesn’t seem ironic, is that the version automatically installed on page access is not a very complicated one, that only hones on the well-known bugs, so if the system is patched as well as possible, the loss won’t be all that great.

AvSoft wasn’t available for comment, but if you’re using their software, you’d better clear off of their download page until something certain is posted on the company’s site.

[Source: softpedia]

Warning: MBR Rootkit Hunting Windows XP Computers!

I must mention from the beginning that every unpatched system connected to the web is vulnerable to this rootkit, so in case you're running an outdated version of Windows XP, you may be in danger pal! Now, let's see some juicy (if you're one of those loving computer infections)
details about the rootkit. First of all, you should know that this new threat infects the MBR (Master Boot Record) of the hard disk, so only a few antivirus technologies would be able to detect and stop it. Symantec's antivirus is one of these exceptions, the application labeling the infection as Trojan.Mebroot, Elia Florio wrote on the Symantec blog.

Infecting the MBR means that the Trojan.Mebroot harms you computer even before the operating system is loaded, so antiviruses are somehow useless. "The main problem is that some versions of Microsoft Windows allow programs to overwrite disk sectors directly (including the MBR) from user mode, without restrictions. As such, writing a new MBR into Sector 0 as a standard user is a relatively easy task", the Symantec official explained.

Elia Florio wrote that Trojan.Mebroot affects Windows XP users, no matter what Service Pack has been deployed. Windows Vista users seem to be protected of the rootkit, according to the Symantec report. The Windows XP vulnerability is caused by "some hard-coded values inside the attack code", as the Symantec official wrote.

It seems like the virus writers found a way to avoid Windows antiviruses
Comments: It seems like the virus writers found a way to avoid Windows antiviruses
Credits: ciasolutions.com.au

What's worse is that the infection cannot be removed while the operating system is running, Elia Florio explained. "It must be removed while the rootkit code itself is not running", Florio stated. "During our tests, running the 'fixmbr' command from within the Windows Recovery Console successfully removed the malicious MBR entry. To help prevent similar attacks in the future, and if your system BIOS includes the Master Boot Record write-protection feature, now is a good time to enable it!"

[Source: softpedia]

If You’re Seeing Gooogle, You’re Infected

Google has long been the target to many attacks and on the odd occasion it redirects to infected pages. This was the case noticed last week, of many Google Groups links that supposedly had pictures or movies of stars performing various actions (more into the pr0n area, none were giving money away to charity). That was pretty well put together, it sent
users to a page that had a YouTube lookalike player image that said it was loading and, if memory serves me right, below was a link to "Watch full video here." Needless to say, clicking that was the beginning of a strong symbiosis between the computer accessing it and a flock of viruses.

This week, there’s a "Gooogle.com" virus, that mimics the real search engine’s page, except for one additional ‘o’ in the logo. At the moment, it has only been reported in Italy and it has embedded some malicious code that automatically loads the file registrazione.exe. You really don’t want to see that on your computer, it contains the file TROJ_AGENT.AAFY and the URL it hosts is detected as HTML_AGENT.AAFX, according to Trend Micro.

That's an option...

After the two files finish their job, users will be redirected to a horoscope website while downloading additional malware such as TROJ_AGENT.ZTH just to keep the previous two company if you’re lucky, but if you caught this, I guess the stars weren’t shining for you. After all is installed and downloaded, there will be an error message that the desired web page cannot be loaded. Upon opening a new page, users will be redirected to another site that claims to be the default Google homepage, www.googler.com. Congratulations, you passed the virus’ test, you’re the lucky owner of some serious malware on your computer.

On a side note, if a non-infected user tries to access any of these sites, he will be redirected to the official Google page, due to The Anticybersquatting Consumer Protection Act which says that typosquatting is clearly illegal.


[Source: softpedia]

From Hackers with Love

Never trust email, even if they tell you what you’d want to hear. Taking advantage of human ego, which apparently has everybody running circles around it, hackers and cyber criminals have found a new way to convince unsuspecting victims to open and download their infected messages.

In case you see an email telling you that you have a secret admirer,
don’t light up and hurry to open it, you’re not 16 any more and the person who is so shy to tell you in person won’t just attach a picture and a declaration. Instead, do the smart thing and check to see whether you know the person who sent you the email, or if it doesn’t look like a bunch of hooey (biq3ygr81b@whatever.com, for example).

Opening emails that have subjects like "Love Rose," "Rockin’ Valentine" or "Just You" might prove to be a mistake due to the valentine.exe file included. Greg Day, a security analyst at McAfee, told Web User that "This virus will try to steal the personal information you keep on your PC, try to bring down your security defenses and sign your machine up to an online army." Nobody likes joining the army. The attachment, however, isn’t the source of the infection, it only contains some piece of code that will ‘persuade’ your PC to search for the malware by itself. In case you have ever been faced with the pain of admitting your computer has been infected, you know the agony to have lost every little information you had to give up just to get it clean.


Opening the file will grant cyber criminals with the access to use you PC "to blast out millions of junk emails and to carry out denial of service attacks – by flooding a computer, system or website with so much information that it brings it down," Day said. So, live your love without online thrills and just stay on the safe side.

[Source: softpedia]

Mobile Users – Ransomware Trojan Victims

Symbian Series 60 owners in China are facing a rather disturbing problem right now, that of the Kiazha-A Trojan, that holds the phone for ransom, according to reports from McAfee. It is a component of a sophisticated mobile malware bundle, dubbed MultiDropper-CR, that infects other devices via Bluetooth or corrupted MMS messages.

The message owners of the S60 are greeted with
a message that is roughly translated as "Warning: Your device has been affected, please prepare a recharge card of RMB 50 yuan and connect QQ account [specified in the original message but removed by the security company in the report], or your phone will be paralysed!!!" The sum of money isn’t big, converted into US dollars it would cost $7 to regain control of the phone.

The QQ mentioned is an instant messaging network very popular in China, used time and time again for password stealing Trojans over the last months because it supports its own currency, called QQ coins.

McAfee anti-virus analyst Jimmy Shah describes the whole process going on with the infection: "MultiDropper-CR uses malicious payloads (Beselo, Commwarrior) to convince the user their phone is infected. It also sets up SMS forwarding (SmsSend-G) to collect information and potentially passwords. In case the victim doesn’t have a QQ account the malware will order (SmsSend-F) one for them. After all that, Kiazha-A deletes SMS messages to cover its tracks and displays the offer to fix the user’s phone for a small fee." The scheme is devilishly well thought of, and difficult to track back following the malware’s components because "It appears that the author, with a lot of effort and testing, put together various malware like pieces from a toolkit." That method of going back to its roots via specific coding is thus removed entirely.

Everybody hates this kind of messages from Trojans
Comments: Everybody hates this kind of messages from Trojans

Strangely enough for mobile phone malware, it looks like the author worked so hard on getting all of the pieces to work together for a profit, and not to increase his notoriety, as per usual.

[Source: softpedia]

Pro-Tibetan Aimed Cyberattacks

People supporting the Tibetan cause have more to worry about than Chinese censorship and retaliation, there’s a new wave of attacks aimed at them and in many aspects it’s far more dangerous. The human rights
groups that are sympathetic to the anti-Chinese protesters are targeted by cybercriminals, and the messages are all designed in such a way that anti-virus tools will not detect them as being malicious.

The emails all have attachments, a welcomed change from the usual links within the text, but the formats and the blending with malicious code is worrying to say the least. PDF, Microsoft Word and Microsoft Excel formats have been changed to install keyloggers among other malware. Security company F-Secure has provided additional information on the matter, including the means of propagating the unwanted emails and their contents: "These emails have been sent to mailing lists, private forums and directly to persons working inside pro-Tibet groups. Some individuals have received targeted attacks like this several times a month."

Should you receive an email that has attached one of the following files, delete them right away, or, under no circumstance download them, as the malware is automatically installed upon opening: UNPO Statement of Solidarity.pdf, Daul-Tibet intergroup meeting.doc and tibet_protests_map_no_icons__mar_20.ppt. The documents appear to contain legitimate information in support of the protests in the Tibetan capital of Lhasa between Chinese soldiers and those militating for Tibet having more independence.



Attacks against supporters of an anti-Chinese government movement are dating back to 2002, according to SANS, and previous targets include Falun Gong and the Uyghurs. The current crisis is very controversial, both in aim and in course of action, as the Chinese government has declared that 19 people have been killed in the riots, but the Tibetan government, exiled now, states that at least 99 have lost their lives.

[Source: softpedia]

"Apple iPod" Shipped with Virus

First of all, let's clarify a matter: because you may ask "what's with the quotes in the title?" I must explain you one thing. This article is not about one of those popular
MP3 players manufactured by the Cupertino-based company, it's actually about a crappy device probably made by some Chinese firm which attempted to lure more consumers by using Apple's logo and product name (some of you may consider that the "d" at the end of iPod looks like an "a" but, what the heck, it's obvious the manufacturers wanted to take advantage of Apple's success on the market).

Although it's obviously a trademark infringing case, we're not here to talk about legal disputes but about some security issues recently discovered.

As you know, more and more computer infections attempt to propagate themselves by copying their files on USB removable drives and, once connected to a clean computer, they install and compromise the system. But, what's worse is that some devices which provide USB connectivity are shipped with pre-installed viruses, probably due to the ignorance of the manufacturer or to some errors in the scanning process made before shipping. It happened in the past with digital photo frames and it also happened one week ago with HP's flash drives.

It\'s Chinese, but it\'s still a virus
Enlarge picture
However, it seems like MP3 players are also affected by this issue. And this is the time when we start talking about that fake Apple iPod (which by the way, says it provides 1 GB of storage space) because, according to Michael of Viruslist.com, it has been shipped with a pre-installed virus. Just like usual, the infection was detected once the USB connection was established, the installed Kasperksy Internet Security identifying and blocking the threat.

It's Chinese, but it's still a virus
Comments: It's Chinese, but it's still a virus
Credits: Michael for Viruslist.com

So, in a era when more and more threats affect the USB-based devices and when such products are shipped with all kinds of accessories, including headsets, connectivity cables, viruses and Trojan horses, antiviruses are simply a must-have...

[Source: softpedia]

Troj/Dloadr-BKU - Yet Another EXE Downloader

Finding malicious websites on the Internet or receiving emails with infected files is something usual these days so it's pretty important to have an up-to-date antivirus
which would be able to block these threats. However, new infections are born every day so, if you really want to keep your system clean, you must keep an eye on the advisories released by security companies. One of the recently spotted infections is Troj/Dloadr-BKU, a Windows Trojan horse which installs its files into the registry and attempts to drop more malware on the affected computer.

What's worse is that recovering and repairing a computer infected with this Trojan horse requires the user to restore the mlang.dll file from the Windows CD, even if your antivirus manages to clean the whole system.

According to a security report published by Sophos, the Trojan horse drops three executable files on the affected systems, namely 1.exe, 2.exe and 3.exe. Sophos states that 1.exe was detected as Mal/EncPk-DI while 3.exe is said to be a sample of Troj/Dloadr-BKU. The 2.exe executable file can be safely deleted as it doesn't harm the computer.

Trojan horses have always been a problem
Comments: Trojan horses have always been a problem
Credits: Waynecounty

In addition to the mentioned files, the Trojan horse also creates and executes a BAT file, namely a.bat, which, according to Sophos, is detected as Troj/Dloadr-BKU, exactly the Trojan horse we're talking about. "Troj/Dloadr-BKU installs itself as a browser helper object which sends information about the infected system and downloads updates," the security company explained.

Since most antivirus products have already released protection against this threat, it's recommended to run an update and apply the latest patches provided by the security vendor. Also, extra care is advisable as well as a full computer scan in case of suspicious activity spotted on the system

[Source: softpedia]

Malicious Behavior Threat Searching for Windows Stations

Although this month may appear to be a calm and quiet period because no new dangerous threats have appeared, there are a lot of reports concerning spyware, Trojan horses and
other type of infections that came out to find new vulnerable systems. But thanks to the security companies out there, our security products are able to spot and block them without allowing the infections to reach our valuable data.

Security company Sophos warned today that a new malicious behavior malware has been spotted in the wild but, at the moment, only a few details are available. All we know is that Mal/Behav-222 affects Windows computers but the security company didn't mention the affected file formats or the method the threat reaches the vulnerable computers.

"Mal/Behav-222 is a malicious program for the Windows platform," Sophos informs. Moreover, the security company asked users who believe that they got infected with Mal/Behav-222 to contact the firm in order to help the employees provide more information about the threat. "Detection for members of Mal/Behav-222 is behavior based. It is extremely important that customers report detections of Mal/Behav-222 to Sophos and send a sample for analysis," Sophos wrote.


The security of our computers is one of the aspects that shouldn't be neglected by any of you, because by using such a malicious tool, an attacker could get into the system and browse, copy or delete any file he wants to. That's why users are always advised to keep their antivirus solutions up-to-date with the latest virus definitions, apply the newest patches and fixes, and keep the security products enabled in order to spot and block any new threat spotted on the web. In addition, don't forget to deploy the latest software updates to avoid exploits and vulnerability attacks.

[Source: softpedia]

New Phishing Scams Available on the Web

Hackers and phishers don't rest until they devise a new scheme, by which they can force honest web users into giving them their personal information. A number of phishing schemes have recently been reported that
appear to use a scenario based on recent worldwide events. The Federal Bureau of Investigation has recently warned the general public about a new scheme by which scammers intended to take the users' IRS fund check.

The FBI webpage shows a fragment of the phishing email
Comments: The FBI webpage shows a fragment of the phishing email

According to the FBI, users would receive an email, presumably from the IRS, advising them to get their economic stimulus rebate money by direct deposit. The email usually states that, in so doing, they will be able to receive their refund as soon as possible. By clicking the provided link, users are directed to a website where they are asked for their bank account information and other personal data. The text in the mail also states that the information has to be filled before a certain date, after which their request will be processed with delay.

According to Special Agent Richard J. Kolko of the FBI national press office, this phishing scam isn't the only one that is currently available on the web. He also added that people should be careful and take extra precautions as to where they give their personal information.

Another phishing scam that is currently undergoing has based its scenario on the Call for support of the Myanmar victims. Microsoft has warned about a phishing scam that redirects users to a false donations web page, allegedly set up for the victims of Cyclone Nargis. The scam pretty much follows the same patterns as the IRS one, with users receiving an email informing them about how they can help the disaster victims.

Users receiving similar mails should first question their authenticity and then post their personal data, if asked for. All the major security companies have issued warnings about the means by which phishing scammers are trying to get the users' personal data.

[Source: softpedia]

MSN Messenger Kissing Pig Virus Still on the Web

About one month ago, the folks at Panda Labs warned that a new MSN Messenger worm was spotted on the web, searching for vulnerable computers through the
popular instant messaging client. The "kissing pig" worm still exists on the web, according to some users, but what's more important is that the majority of anti-virus solutions have already included protection against it. Now, how can you notice the worm? Well, it's simple. The W32/MSNworm.EI.worm was especially designed to propagate through MSN Messenger, so it is automatically sent to users of the application. What's more interesting is that, once the file is executed, the worm displays a picture of a funny pig, the main sign that your computer has been infected.

According to a security notification published by Panda Labs, the worm also downloads a backdoor, namely the IRCBot.BWB, which is installed on the affected computer in order to connect to an IRC server and wait for remote commands. The worm only affects Windows 2003, Windows XP, Windows 2000, Windows NT and Windows 98, Panda Security explains.

"Its main objective is to spread via MSN Messenger and affect as many computers as possible. Additionally, it downloads the backdoor detected as IRCBot.BWB to the affected computer," the security company added in the advisory.

Just like usual, you're advised to update your anti-virus protection to the latest version and apply the newest virus definitions as soon as possible. It's important to note that most anti-virus technologies on the market have already added protection against the worm, so this is probably the best and the easiest method to stay secure while chatting on MSN Messenger.

The MSN Messenger kissing pig
Comments: The MSN Messenger kissing pig
Credits: Panda Security

However, you can also turn to the more paranoid-like methods to staying on the secure side and ignore messages that look suspicious and block any message coming from untrusted contacts.

[Source: softpedia]