01 May 2007
Trojan Hides in Postcard
Sophos has just posted a warning about an electronic postcard that is being sent out containing the Trojan Mal/Zapchas-A.
The email's appearance makes one think that it came from a friend and is very similar to any other postcard one might receive asking the users to go the some site to download the postcard. The file is named postcard.exe which should serve as a warning immediately - most e-postcards and e-cards run as a flash animation embedded in the website itself.
Full information and a copy of the actual text of the message can be found here.
The email's appearance makes one think that it came from a friend and is very similar to any other postcard one might receive asking the users to go the some site to download the postcard. The file is named postcard.exe which should serve as a warning immediately - most e-postcards and e-cards run as a flash animation embedded in the website itself.
Full information and a copy of the actual text of the message can be found here.
Labels: email, microsoft, spam, spyware, trojan, virus, windows
21 February 2007
False News Virus
An email is circulating claiming news about the heart attack of the Australian prime minister. Of course it is completely bogus, but the reality of it is the Trojan horse that it leads recipients to.
Along with a the Trojan, a web server is also installed to allow access to the machine whenever it is online. Websense analysts claim that the attackers are using a control panel that enables them to see a list of all infected machines, their IP addresses, ports and the countries the computer is from.
The email is mostly circulating in Australia and links to a page that appears to come from The Australian. The link actually leads to a page that downloads the Trojan before redirecting the user's browser to The Australian's site.
Along with a the Trojan, a web server is also installed to allow access to the machine whenever it is online. Websense analysts claim that the attackers are using a control panel that enables them to see a list of all infected machines, their IP addresses, ports and the countries the computer is from.
The email is mostly circulating in Australia and links to a page that appears to come from The Australian. The link actually leads to a page that downloads the Trojan before redirecting the user's browser to The Australian's site.
23 January 2007
Internet Love Email Virus
There is a virus going around email right now with the subject of Internet Love
It claims to be from Symantec and contains an attachment (attachment.dat).
Below is the text of the actual email that was sent.
This message has been processed by Symantec's AntiVirus Technology.
greeting postcard.exe was infected with the malicious virus Trojan.Peacomm and has been deleted because the file cannot be cleaned.
For more information on antivirus tips and technology, visit
http://ses.symantec.com/
Do not go to the above website, as you can see it is obviously not Symantec's website - notice the ses in place of www.
It claims to be from Symantec and contains an attachment (attachment.dat).
Below is the text of the actual email that was sent.
This message has been processed by Symantec's AntiVirus Technology.
greeting postcard.exe was infected with the malicious virus Trojan.Peacomm and has been deleted because the file cannot be cleaned.
For more information on antivirus tips and technology, visit
http://ses.symantec.com/
Do not go to the above website, as you can see it is obviously not Symantec's website - notice the ses in place of www.
Labels: email, internet, safety, trojan
19 January 2007
Storm-Worm Blows Through Computers Worldwide
F-Secure has posted a video showing the spread of the so called Storm-Worm.
The Storm-Worm is passing through emails pretending to be a news article about the current storm in Europe. The heading in the email states '230 dead as storm batters Europe'. Attached to the email is a virus and Trojan named Small.damTROJAN. The virus allows the spammer to take control of the infected computer and allows the message to be sent to others. So far it is estimated that this virus has infected over 10,000 computers.
The Storm-Worm is passing through emails pretending to be a news article about the current storm in Europe. The heading in the email states '230 dead as storm batters Europe'. Attached to the email is a virus and Trojan named Small.damTROJAN. The virus allows the spammer to take control of the infected computer and allows the message to be sent to others. So far it is estimated that this virus has infected over 10,000 computers.
Labels: email, spam, trojan, worm
Spam Newsletters and News
Spammers have developed a new way of avoiding email filters.
It seems spammers are taking standard newsletters that may be sent by legitimate well-known sources and adding either malware or adware in the message or adding links to malicious websites.
Similarly there are also spam emails emerging with the appearance of breaking news stories to try to get users to open them.
All of these types of spam can carry a Trojan and according to Sophos' monitoring there was a point where up to one in 200 emails contained a Trojan. The spam usually contain files such as Full Clip.exe, Full Story.exe, Full Video.exe, Read More.exe, and Video.exe.
It seems spammers are taking standard newsletters that may be sent by legitimate well-known sources and adding either malware or adware in the message or adding links to malicious websites.
Similarly there are also spam emails emerging with the appearance of breaking news stories to try to get users to open them.
All of these types of spam can carry a Trojan and according to Sophos' monitoring there was a point where up to one in 200 emails contained a Trojan. The spam usually contain files such as Full Clip.exe, Full Story.exe, Full Video.exe, Read More.exe, and Video.exe.
Labels: adware, email, phishing, scam, spam, spyware, trojan
25 December 2006
Not so Merry Christmas Greeting
A PowerPoint presentation is going around emails right now called Christmas+Blessings-4.ppt which contains a version of the Hupigon (Hupigeon) Trojan. This installs two other files called msupdate.dll and sdfsc.dll.
The Trojan comes in an email with the subject "Merry Christmas to our hero sons and daughters!". There isn't much known about the attack but it is assumed to be based on the MS06-012 exploit in MS Office that lets commands be executed from a remote source.
The Trojan comes in an email with the subject "Merry Christmas to our hero sons and daughters!". There isn't much known about the attack but it is assumed to be based on the MS06-012 exploit in MS Office that lets commands be executed from a remote source.
Labels: email, microsoft, powerpoint, trojan, vulnerability
03 December 2006
Trojans With Your Vista Cracks
Vista features an image-based install process to allow third-party software to be included on the installation DVD, making it easier for corporate users to have their private software pre-installed. Unfortunately, this can allow for images to be distributed with Trojan horses and other malware included.
People looking for cracks for Windows Vista are very likely to find a Trojan horse, specifically PSW.Win32.LdPinch.aze. I can't say that I am very worried about this though. It should be expected that when downloading something illegal, there is a high probability of having something more than you want.
The money that can be got by gaining personal information from computers is high enough that the people involved are looking for any way possible of getting that information, what easier way than let you install it yourself.
People looking for cracks for Windows Vista are very likely to find a Trojan horse, specifically PSW.Win32.LdPinch.aze. I can't say that I am very worried about this though. It should be expected that when downloading something illegal, there is a high probability of having something more than you want.
The money that can be got by gaining personal information from computers is high enough that the people involved are looking for any way possible of getting that information, what easier way than let you install it yourself.
Labels: crack, microsoft, os, trojan, vista
25 November 2006
Free Porn For Your Most Personal Information
Nothing is free these days and that is certainly true of online porn.
It seems the current form of social engineering is to attract Internet Explorer users to sites offering free pornography. Currently, there is a major spam campaign against unpatched versions of Internet Explorer offering free pornography while actually providing the Psyme-DL Trojan. When users open the link, they are taken to a page that automatically installs the Trojan. Firefox users are asked to switch browsers and are unaffected as are fully patched IE users and users of IE 7.
This is just another reminder of why people should practice safe browsing habits, but despite all the warnings many users will find such an email impossible to resist and go to it anyway, which is exactly what the creators of such social engineering schemes are hoping for.
It seems the current form of social engineering is to attract Internet Explorer users to sites offering free pornography. Currently, there is a major spam campaign against unpatched versions of Internet Explorer offering free pornography while actually providing the Psyme-DL Trojan. When users open the link, they are taken to a page that automatically installs the Trojan. Firefox users are asked to switch browsers and are unaffected as are fully patched IE users and users of IE 7.
This is just another reminder of why people should practice safe browsing habits, but despite all the warnings many users will find such an email impossible to resist and go to it anyway, which is exactly what the creators of such social engineering schemes are hoping for.
Labels: email, safety, spam, trojan
05 November 2006
Spyware is a danger for all
Most people on the Internet have heard of spyware, but there still are many who consider it as something that only happens to others. Of course, this is where they are wrong and the effects of this are great. Spyware is known for causing many problems and doing many things including stealing people's identity, causing a computer to function as a spam relay, displaying pop-up ads, and slowing the system so much that it's difficult to use.
There are two types of spyware, one is very harmful and includes Trojans and keyloggers designed to steal information while the other is happy to just redirect users to other content and monitor their Internet activity. While this second type is not stealing personal information, it is still harmful for your computer as it will slow it down. This may not be much for one piece of "adware", but usually it is never just one piece and you will notice a difference.
Surfing habits of users have been seen as a cause of more or less spyware with children's sites giving the most adware and gaming sites containing spyware and adware. Online shopping is the safest and usually doesn't add any malicious software to a system.
More information including how to protect and prevent spyware from stay on your system can be found here.
There are two types of spyware, one is very harmful and includes Trojans and keyloggers designed to steal information while the other is happy to just redirect users to other content and monitor their Internet activity. While this second type is not stealing personal information, it is still harmful for your computer as it will slow it down. This may not be much for one piece of "adware", but usually it is never just one piece and you will notice a difference.
Surfing habits of users have been seen as a cause of more or less spyware with children's sites giving the most adware and gaming sites containing spyware and adware. Online shopping is the safest and usually doesn't add any malicious software to a system.
More information including how to protect and prevent spyware from stay on your system can be found here.
Labels: adware, internet, safety, spyware, trojan
17 October 2006
You've won an MP3 player but lost your passwords and security
When you win a free product, you usually don't expect the brand new device to have any malicious software on it, but that seems to be exactly what has happened to 10000 people who have won MP3 players from McDonald's and Coca-Cola in Japan.
The players were shipped with the McDonald's logo and were preloaded with 10 songs and a bonus password stealing Trojan known as QQPass. It isn't exactly known how computers can be infected from the MP3 player but some say all that is required is to plug the thing into a computer.
How can this happen with hardware coming directly from the factory? This is the major question that should be asked. Did no one check the devices for quality before shipping? Was the Trojan in one of the songs or loaded separately? This incident leaves a lot of questions about the legality of the pre-loaded MP3s and where they were obtained as well as the level of quality assurance found at producers of MP3 players.
The players were shipped with the McDonald's logo and were preloaded with 10 songs and a bonus password stealing Trojan known as QQPass. It isn't exactly known how computers can be infected from the MP3 player but some say all that is required is to plug the thing into a computer.
How can this happen with hardware coming directly from the factory? This is the major question that should be asked. Did no one check the devices for quality before shipping? Was the Trojan in one of the songs or loaded separately? This incident leaves a lot of questions about the legality of the pre-loaded MP3s and where they were obtained as well as the level of quality assurance found at producers of MP3 players.
11 October 2006
Haxdoor Trojan Affects Thousands in the UK
UK users have their personal data to worry about.
It was just revealed that thousands of users in the UK have had data stolen from their computers by the Haxdoor Trojan. Recently it was sent out throughout Europe through spam emails in an attachment some of which were named rakningen.zip or rechnung.zip.
The Metropolitan Police have been trying to contact people who may be affected by this by sending out email messages to them, but most of these messages have been ignored.
The Haxdoor Trojan is a backdoor and rootkit that has spying capabilities as well. It is able to hide itself and it's processes, therefor making it difficult to detect without anti-virus tools that use kernel drivers or rootkit detectors. When running it hides itself, but it also either hides the Winlogon.exe process or the Explorer.exe process. This can be very helpful in detecting if your computer is infected. Of course removing it is another issue. Also access to the sites of many anti-virus vendors will be blocked by the Trojan.
Haxdoor steals IMAP passwords, server names and usernames along with Inetcomm server passwords, Outlook passwords, POP passwords, POP server and user names, protected storage passwords, The Bat! passwords and Windows registration information. It can also steal some passwords that are stored in memory. This information will be posted on a server at the website of skynet.info.
Not only does it steal your information, but it also listens on TCP port 16661 for commands that can allow the hacker to download files from your computer or upload them to your computer, view file contents, find files, run files, send emails, show a messagebox, gain full access to the Windows Registry, enable or disable keyloggers, copy to and from the clipboard, move the location of the cursor, disable or enable the keyboard, change file attributes including its location, kill processes, disable drives, change the time, swap mouse buttons, take screenshots of a desktop, play media files, send messages to applications, start services, play a system beep, log off or shutdown Windows, open or close the CD-ROM tray, uninstall the Trojan, and open other ports.
To make matters worse a Haxdoor toolkit is being sold for $2000 on the black market by a Russian hacker called "Corpse" and allows anyone to create their own variant of the Trojan making it even more difficult to stop.
It was just revealed that thousands of users in the UK have had data stolen from their computers by the Haxdoor Trojan. Recently it was sent out throughout Europe through spam emails in an attachment some of which were named rakningen.zip or rechnung.zip.
The Metropolitan Police have been trying to contact people who may be affected by this by sending out email messages to them, but most of these messages have been ignored.
The Haxdoor Trojan is a backdoor and rootkit that has spying capabilities as well. It is able to hide itself and it's processes, therefor making it difficult to detect without anti-virus tools that use kernel drivers or rootkit detectors. When running it hides itself, but it also either hides the Winlogon.exe process or the Explorer.exe process. This can be very helpful in detecting if your computer is infected. Of course removing it is another issue. Also access to the sites of many anti-virus vendors will be blocked by the Trojan.
Haxdoor steals IMAP passwords, server names and usernames along with Inetcomm server passwords, Outlook passwords, POP passwords, POP server and user names, protected storage passwords, The Bat! passwords and Windows registration information. It can also steal some passwords that are stored in memory. This information will be posted on a server at the website of skynet.info.
Not only does it steal your information, but it also listens on TCP port 16661 for commands that can allow the hacker to download files from your computer or upload them to your computer, view file contents, find files, run files, send emails, show a messagebox, gain full access to the Windows Registry, enable or disable keyloggers, copy to and from the clipboard, move the location of the cursor, disable or enable the keyboard, change file attributes including its location, kill processes, disable drives, change the time, swap mouse buttons, take screenshots of a desktop, play media files, send messages to applications, start services, play a system beep, log off or shutdown Windows, open or close the CD-ROM tray, uninstall the Trojan, and open other ports.
To make matters worse a Haxdoor toolkit is being sold for $2000 on the black market by a Russian hacker called "Corpse" and allows anyone to create their own variant of the Trojan making it even more difficult to stop.
29 September 2006
More Vulnerabilities for Microsoft
Microsoft has just released a patch for the VML vulnerability in IE, but it seems another bug has popped up this time for Microsoft PowerPoint 2000 to 2003 and PowerPoint 2004 for Mac.
The new vulnerability is being used to install a Trojan on the computer. This Trojan runs an executable file and installs two DLL files to function as backdoors. All information entered into Internet Explorer is posted to a web site on compromised computers.
Users need not worry too much about this, it is considered a limited risk due to the small number of victims so far. Also users need to run the malicious file for their computer to be infected so it is very easy to protect yourself from this exploit.
The new vulnerability is being used to install a Trojan on the computer. This Trojan runs an executable file and installs two DLL files to function as backdoors. All information entered into Internet Explorer is posted to a web site on compromised computers.
Users need not worry too much about this, it is considered a limited risk due to the small number of victims so far. Also users need to run the malicious file for their computer to be infected so it is very easy to protect yourself from this exploit.
Labels: IE, microsoft, powerpoint, trojan, vulnerability
05 September 2006
Word 2000 Vulnerability
A very critical security advisory has been released today regarding a vulnerability in MS Word 2000 that is actively being exploited. The vulnerability has been reported in Windows 2000, 98, 95, ME, NT and XP systems running Word 2000, but there is a possibility that it is present in other systems as well.
The only solution currently is to not open any Word documents that you don't trust.
The Trojan.MDropper.Q, actually located in the document file, uses the vulnerability to install a form of the Backdoor.Femo backdoor onto the system. These are names used by Symantec while McAfee has discovered it as well and is calling it W32/Mofei.worm.
More information can be found from McAffee and Symantec on this issue.
The only solution currently is to not open any Word documents that you don't trust.
The Trojan.MDropper.Q, actually located in the document file, uses the vulnerability to install a form of the Backdoor.Femo backdoor onto the system. These are names used by Symantec while McAfee has discovered it as well and is calling it W32/Mofei.worm.
More information can be found from McAffee and Symantec on this issue.
Labels: microsoft, office, trojan, vulnerability
03 September 2006
Zcodec is NOT a video codec
A new program has been introduced into the world, although I wouldn't say it's a positive program.
Zcodec tries to fool people into thinking it is a video codec. After doing that it has the ability to change the results of web searches, install adware, and trick users into installing other malicious software such as Trojans.
The installation of this program involves installing 3 programs, one of which is a rootkit while the other two are executables.
One of the executable files is designed to modify search engine results to display a different page. This can be used to direct people to sites that pay hosts for each click that a user makes or they can be directed to pages that steal information from user's computers.
The other executable installs Ruins.MB Trojan. The purpose of this file is downloading other malicious programs.
Zcodec does not spread itself but rather relies on users downloading it. This makes it easy to prevent yourself from getting the virus if you know that Zcodec is in fact not a codec at all. Also to prevent yourself from other such files, an antimalware scanner that detects viruses, adware and other unwanted programs and prevents them from being installed and run on a system is a invaluable tool. Of course it's useless if you don't keep it updated and running at all times.
If you are unlucky enough to have this installed on your system, it can be removed and as well Panda Software gives some information on how to remove it from the _Restore folder in both Windows XP and ME.
Zcodec tries to fool people into thinking it is a video codec. After doing that it has the ability to change the results of web searches, install adware, and trick users into installing other malicious software such as Trojans.
The installation of this program involves installing 3 programs, one of which is a rootkit while the other two are executables.
One of the executable files is designed to modify search engine results to display a different page. This can be used to direct people to sites that pay hosts for each click that a user makes or they can be directed to pages that steal information from user's computers.
The other executable installs Ruins.MB Trojan. The purpose of this file is downloading other malicious programs.
Zcodec does not spread itself but rather relies on users downloading it. This makes it easy to prevent yourself from getting the virus if you know that Zcodec is in fact not a codec at all. Also to prevent yourself from other such files, an antimalware scanner that detects viruses, adware and other unwanted programs and prevents them from being installed and run on a system is a invaluable tool. Of course it's useless if you don't keep it updated and running at all times.
If you are unlucky enough to have this installed on your system, it can be removed and as well Panda Software gives some information on how to remove it from the _Restore folder in both Windows XP and ME.
Labels: internet, security, trojan
24 August 2006
Trojan uses your money to install on your computer
There's another trojan horse that is on the loose. This one has been reported by SophosLabs and is said to come in a spam email claiming that your credit card has been charged £125. This trojan named Troj/Dloadr-AMA comes in a file called paycheck.zip and when the executable in this zip file is run the trojan is installed. Of course like most malicious software this begins downloading more malicious software to your computer.
While this trojan tries to get users upset enough to not be so cautious and install it without thinking, people should still try to be calm when reading their messages.
When users are reading spam and messages such as this one, they should always first think if something seems strange about this message. Why would a company be emailing you in this situation? Wouldn't they just call? If you have some message like this that you think might be true, but it's not your bank sending it, maybe you should contact your bank to see if they have any record of such an charge.
Secondly, when you see a message that seems to good to be true, it is. There are no such deals. In the lucrative world of spam and malicious sites and software, the most interesting or shocking messages get the most people to run it or go to the site and give their personal information.
And my last tip for email. Don't trust anything. You wouldn't let just anyone into your house. We've all heard of the person who claims to be from some utility or other company who gains access into your house and then robs your house. Well, consider strangers in email exactly like you would at your front door. It will keep you a lot safer.
While this trojan tries to get users upset enough to not be so cautious and install it without thinking, people should still try to be calm when reading their messages.
When users are reading spam and messages such as this one, they should always first think if something seems strange about this message. Why would a company be emailing you in this situation? Wouldn't they just call? If you have some message like this that you think might be true, but it's not your bank sending it, maybe you should contact your bank to see if they have any record of such an charge.
Secondly, when you see a message that seems to good to be true, it is. There are no such deals. In the lucrative world of spam and malicious sites and software, the most interesting or shocking messages get the most people to run it or go to the site and give their personal information.
And my last tip for email. Don't trust anything. You wouldn't let just anyone into your house. We've all heard of the person who claims to be from some utility or other company who gains access into your house and then robs your house. Well, consider strangers in email exactly like you would at your front door. It will keep you a lot safer.
Labels: email, safety, spam, trojan
23 August 2006
Software protection from keylogging in IE
Users of Internet Explorer have a chance of gaining a little more security. QFX Software has released a plugin for IE 6 that encrypts a users keystrokes to make it harder for keyloggers to get any useful information. The free version will encrypt the data typed for passwords and user names while the professional version encrypts all data coming from your keyboard for the price of about $25.
People should remember though that while this does help protect them, that doesn't mean it's not impossible to decrypt the data. Users should still avoid risky actions that can cause the installation of a trojan or keylogger. Just because you have insurance protecting you if your car is stolen, doesn't mean you should leave the doors unlocked with your key in the ignition, think of your computer in the same way.
People should remember though that while this does help protect them, that doesn't mean it's not impossible to decrypt the data. Users should still avoid risky actions that can cause the installation of a trojan or keylogger. Just because you have insurance protecting you if your car is stolen, doesn't mean you should leave the doors unlocked with your key in the ignition, think of your computer in the same way.
19 August 2006
Protect your computer from rootkits
With all the security risks nowadays, if you're worried that your computer may have a rootkit F-Secure Blacklight is one possible application to search for and eliminate them.
This software is able to detect and eliminate active rootkits which anti-virus usually cannot do. It also does not provide the user with a list of suspected objects so the non-technical person is able to use it without risking damaging anything. It also allows the user to still be using their computer while it is testing for rootkits without issuing any false positives.
This stand-alone application will only be available until 1 October 2006. After that you would have to purchase F-Secure Internet Security Suite.
F-Secure Internet Security Suite will cost you just under £39 and includes virus and spyware protection, a firewall and a spam filter. The virus protection is updated daily from AV-Test.org allowing for extremely fast protection from new viruses. It also can protect and prevent children from viewing certain Internet content and has the ability to prevent children from surfing the web for too long. Also this software can be set to allow only certain applications to access the Internet. This software supports all versions of Windows from 98 to XP except for server editions of Windows 2000.
This software is able to detect and eliminate active rootkits which anti-virus usually cannot do. It also does not provide the user with a list of suspected objects so the non-technical person is able to use it without risking damaging anything. It also allows the user to still be using their computer while it is testing for rootkits without issuing any false positives.
This stand-alone application will only be available until 1 October 2006. After that you would have to purchase F-Secure Internet Security Suite.
F-Secure Internet Security Suite will cost you just under £39 and includes virus and spyware protection, a firewall and a spam filter. The virus protection is updated daily from AV-Test.org allowing for extremely fast protection from new viruses. It also can protect and prevent children from viewing certain Internet content and has the ability to prevent children from surfing the web for too long. Also this software can be set to allow only certain applications to access the Internet. This software supports all versions of Windows from 98 to XP except for server editions of Windows 2000.
Labels: rootkit, security, trojan
05 August 2006
Backdoor Trojan Warning
The trojan Backdoor.Win32.SdBot.asr seems to be popular currently. Detected on 21 June, it is installed on a computer then procedes to download more files that it needs to function. After that it procedes to create an IRC account and listen for commands to come in from that account.
Aside from finding information about your computer, it can also download files to your computer, take files off your computer, run or end an application, reboot your computer and load web pages. A complete list of the commands and activities this trojan can do can be found here.
If this trojan is detected on your system make sure it is not only removed from the system but also that it is removed from the Windows Registry or it will just reload itself when you reboot.
Aside from finding information about your computer, it can also download files to your computer, take files off your computer, run or end an application, reboot your computer and load web pages. A complete list of the commands and activities this trojan can do can be found here.
If this trojan is detected on your system make sure it is not only removed from the system but also that it is removed from the Windows Registry or it will just reload itself when you reboot.
22 July 2006
Google toolbar users - be wary
A new trojan has been found that sends an email from Google to you. It provides you with instructions on how to update your Google toolbar. Users unlucky enough to follow the instructions and links will be taken to a page very similar to Google's with an option to install the trojan ("toolbar"). After the install your system will become part of a series of computers sending spam emails.
The only advice I can give on this one, always be careful where you are on the internet and be careful what you install.
The only advice I can give on this one, always be careful where you are on the internet and be careful what you install.
Labels: Google, internet, trojan
