2011年2月24日星期四

It?s NOT Koobface! New multi-platform infector

Facebook continues being a popular target for malware authors as we discover yet another family that uses this popular social network to propagate. The main component, which we detect as Trojan:Java/Boonana, is written in Java which gives it cross platform capability infecting Windows, Mac and Linux users.

Trojan:Java/Boonana is sent via a link to a video to Facebook users. By clicking on the link, the user will be prompted to run the application ?JPhotoAlbum?, which is a Java class inside a JAR file (JPhotoAlbum.jar SHA1: 159e6bc0616dec2062c92a7dd918c8179b2de640). Independent of browser or platform, by clicking to allow this application to run, the rest of the payload will be downloaded and executed on the computer.

The components that are subsequently downloaded are:

 

 

It is worth noting that this threat family also contains malicious files targeting MacOS X.  Boonana updates multiple components of the Macintosh operating system to give root level privilege to the attacker. We detect these as Trojan:MacOS_X/Boonana.

We have detection for this from 1.93.1067.0 onwards.

Thanks to Andrei Saygo for his analysis of some of the threats in this family.

--Jaime Wong

computer problems fix my pc free pc fix

Myleene Klass themed scam mails

malware removal tools remove spyware adware malware best anti spyware malware

Definition file update for Ad-Aware.


149.601 is now available, new definition file for Ad-Aware 8.2.

150.286 is now available, new definition file for Ad-Aware 9.x, 8.3.

New definitions:
====================
Win32.TrojanDropper.Meno


Updated definitions:
====================
BAT.Trojandownloader.Agent
JS.Trojan.StartPage
MSIL.Backdoor.Agent
MSIL.Trojan.Agent
MSIL.TrojanDownloader.Agent
MSIL.TrojanDropper.Agent
MSIL.TrojanDropper.StubRC
MSIL.TrojanPWS.Agent
MSIL.TrojanPWS.Dybalom
MSIL.TrojanPWS.NetPass
MSIL.TrojanSpy.Agent
MSIL.TrojanSpy.KeyLogger
MSIL.TrojanSpy.Zbot
MSIL.Worm.Autorun
NSIS.Trojan.Agent
NSIS.Trojan.StartPage
NSIS.TrojanDropper.Agent
VBS.Trojan.Agent
VBS.TrojanClicker.Agent
Win32.Adware.180Solutions
Win32.Adware.AdRotator
Win32.Adware.Admoke
Win32.Adware.Agent
Win32.Adware.Astro
Win32.Adware.BHO
Win32.Adware.Boran
Win32.Adware.Cinmus
Win32.Adware.DM
Win32.Adware.Delf
Win32.Adware.EzuLa
Win32.Adware.FLVTube
Win32.Adware.FakeInstaller
Win32.Adware.Gaba
Win32.Adware.Gamevance
Win32.Adware.Mirar
Win32.Adware.RON
Win32.Adware.Stud
Win32.Adware.SuperJuan
Win32.Adware.Virtumonde
Win32.Adware.WinAD
Win32.Adware.Wsb
Win32.Adware.Zwangi
Win32.Backdoor.Agent
Win32.Backdoor.Agobot
Win32.Backdoor.Bandok
Win32.Backdoor.Banito
Win32.Backdoor.Bifrose
Win32.Backdoor.BlackHole
Win32.Backdoor.Cindyc
Win32.Backdoor.Curioso
Win32.Backdoor.Delf
Win32.Backdoor.Dplag
Win32.Backdoor.DsBot
Win32.Backdoor.EggDrop
Win32.Backdoor.Eklips
Win32.Backdoor.Firstinj
Win32.Backdoor.Gbot
Win32.Backdoor.Gootkit
Win32.Backdoor.HacDef
Win32.Backdoor.Hackdoor
Win32.Backdoor.Harebot
Win32.Backdoor.Hupigon
Win32.Backdoor.IRCBot
Win32.Backdoor.Inject
Win32.Backdoor.Ircnite
Win32.Backdoor.Kbot
Win32.Backdoor.Koutodoor
Win32.Backdoor.Kredoor
Win32.Backdoor.Lolbot
Win32.Backdoor.Nethief
Win32.Backdoor.Nihem
Win32.Backdoor.PPdoor
Win32.Backdoor.Papras
Win32.Backdoor.Poison
Win32.Backdoor.Prorat
Win32.Backdoor.Prosti
Win32.Backdoor.RBot
Win32.Backdoor.RShot
Win32.Backdoor.Ripinip
Win32.Backdoor.Rosex
Win32.Backdoor.SDBot
Win32.Backdoor.Shark
Win32.Backdoor.Shiz
Win32.Backdoor.Sinowal
Win32.Backdoor.Skill
Win32.Backdoor.Spammy
Win32.Backdoor.TDSS
Win32.Backdoor.Torr
Win32.Backdoor.Turkojan
Win32.Backdoor.VB
Win32.Backdoor.VanBot
Win32.Backdoor.WinUoj
Win32.Backdoor.Wintu
Win32.Backdoor.Xyligan
Win32.Backdoor.Yobdam
Win32.Backdoor.Zzslash
Win32.Dialer.Trojan
Win32.FraudTool.AdwareRemover
Win32.FraudTool.PowerAntiVirus2009
Win32.Hoax.ArchSMS
Win32.Hoax.Kornelia
Win32.Hoax.Renos
Win32.IRCWorm.Small
Win32.Monitor.ActMon
Win32.Monitor.ActualSpy
Win32.Monitor.Agent
Win32.Monitor.Ardamax
Win32.Monitor.NetMon
Win32.Monitor.PCPandora
Win32.Monitor.PCRecord
Win32.Monitor.Perflogger
Win32.Monitor.SpectorPro
Win32.P2PWorm.Agent
Win32.P2PWorm.Bacteraloh
Win32.P2PWorm.Harex
Win32.P2PWorm.Nugg
Win32.P2PWorm.Palevo
Win32.P2PWorm.Polip
Win32.P2PWorm.VB
Win32.Rootkit.Agent
Win32.Rootkit.Bubnix
Win32.Rootkit.Fdog
Win32.Rootkit.HideProc
Win32.Rootkit.Koobface
Win32.Rootkit.Qhost
Win32.Rootkit.TDSS
Win32.Rootkit.Tent
Win32.Toolbar.Agent
Win32.Trojan.Agent
Win32.Trojan.Agent2
Win32.Trojan.Antavmu
Win32.Trojan.AntiAV
Win32.Trojan.AutoIT
Win32.Trojan.BHO
Win32.Trojan.Bombibom
Win32.Trojan.Buzus
Win32.Trojan.Cariez
Win32.Trojan.Chifrax
Win32.Trojan.Chinaad
Win32.Trojan.Cosmu
Win32.Trojan.Cospet
Win32.Trojan.Cossta
Win32.Trojan.DNSchanger
Win32.Trojan.DelAll
Win32.Trojan.Delf
Win32.Trojan.Dialer
Win32.Trojan.Diamin
Win32.Trojan.Diple
Win32.Trojan.Eyestye
Win32.Trojan.FakeAV
Win32.Trojan.Fakedefrag
Win32.Trojan.Fakems
Win32.Trojan.FormatC
Win32.Trojan.FraudST
Win32.Trojan.Fraudpack
Win32.Trojan.Gabba
Win32.Trojan.Genome
Win32.Trojan.Gibi
Win32.Trojan.Gofy
Win32.Trojan.Inject
Win32.Trojan.Jkfg
Win32.Trojan.Jorik
Win32.Trojan.Kolweb
Win32.Trojan.Larwa
Win32.Trojan.Lebag
Win32.Trojan.Lexip
Win32.Trojan.Llac
Win32.Trojan.MMM
Win32.Trojan.Mahato
Win32.Trojan.Menti
Win32.Trojan.Mepaow
Win32.Trojan.Microfake
Win32.Trojan.Midgare
Win32.Trojan.Miser
Win32.Trojan.Monder
Win32.Trojan.Oficla
Win32.Trojan.Pakes
Win32.Trojan.Pasta
Win32.Trojan.Pincav
Win32.Trojan.Pirminay
Win32.Trojan.Plapon
Win32.Trojan.Powp
Win32.Trojan.Qhost
Win32.Trojan.Redosdru
Win32.Trojan.Refroso
Win32.Trojan.Regie
Win32.Trojan.Regrun
Win32.Trojan.Sadenav
Win32.Trojan.Sasfis
Win32.Trojan.Scar
Win32.Trojan.Sefnit
Win32.Trojan.Shutdowner
Win32.Trojan.Siscos
Win32.Trojan.Skillis
Win32.Trojan.Slefdel
Win32.Trojan.Smardf
Win32.Trojan.Staget
Win32.Trojan.StartPage
Win32.Trojan.Starter
Win32.Trojan.Swisyn
Win32.Trojan.Tdss
Win32.Trojan.VB
Win32.Trojan.Vaklik
Win32.Trojan.Vapsup
Win32.Trojan.Vbkrypt
Win32.Trojan.Vilsel
Win32.Trojan.Vkhost
Win32.Trojan.Webprefix
Win32.Trojan.Zapchast
Win32.TrojanClicker.Adclicer
Win32.TrojanClicker.Agent
Win32.TrojanClicker.Casu
Win32.TrojanClicker.Cycler
Win32.TrojanClicker.Delf
Win32.TrojanClicker.Small
Win32.TrojanClicker.VB
Win32.TrojanClicker.VBiframe
Win32.TrojanDDoS.VB
Win32.TrojanDownloader.ACVE
Win32.TrojanDownloader.Adload
Win32.TrojanDownloader.Agent
Win32.TrojanDownloader.Apher
Win32.TrojanDownloader.Autoit
Win32.TrojanDownloader.Banload
Win32.TrojanDownloader.BaoFa
Win32.TrojanDownloader.Bespal
Win32.TrojanDownloader.Calac
Win32.TrojanDownloader.Calipr
Win32.TrojanDownloader.Calper
Win32.TrojanDownloader.CodecPack
Win32.TrojanDownloader.Dadobra
Win32.TrojanDownloader.Delf
Win32.TrojanDownloader.Dluca
Win32.TrojanDownloader.Fload
Win32.TrojanDownloader.FlyStudio
Win32.TrojanDownloader.Fosniw
Win32.TrojanDownloader.Fraudload
Win32.TrojanDownloader.Gamup
Win32.TrojanDownloader.Genome
Win32.TrojanDownloader.Geral
Win32.TrojanDownloader.Gogogovb
Win32.TrojanDownloader.Hmir
Win32.TrojanDownloader.ISTBar
Win32.TrojanDownloader.Injecter
Win32.TrojanDownloader.Knigsfot
Win32.TrojanDownloader.Lipler
Win32.TrojanDownloader.Liwak
Win32.TrojanDownloader.Mufanom
Win32.TrojanDownloader.Murlo
Win32.TrojanDownloader.Myxa
Win32.TrojanDownloader.NSIS
Win32.TrojanDownloader.Petrolin
Win32.TrojanDownloader.Pher
Win32.TrojanDownloader.Piker
Win32.TrojanDownloader.Qhost
Win32.TrojanDownloader.Refroso
Win32.TrojanDownloader.Satray
Win32.TrojanDownloader.Shoter
Win32.TrojanDownloader.Small
Win32.TrojanDownloader.Tiny
Win32.TrojanDownloader.VB
Win32.TrojanDownloader.Wintrim
Win32.TrojanDownloader.Zlob
Win32.TrojanDropper.Agent
Win32.TrojanDropper.BHO
Win32.TrojanDropper.Binder
Win32.TrojanDropper.Cadro
Win32.TrojanDropper.Clons
Win32.TrojanDropper.Danseed
Win32.TrojanDropper.Decay
Win32.TrojanDropper.Delf
Win32.TrojanDropper.Drooptroop
Win32.TrojanDropper.Flystud
Win32.TrojanDropper.Grizl
Win32.TrojanDropper.HeliosBinder
Win32.TrojanDropper.Javdrop
Win32.TrojanDropper.Joiner
Win32.TrojanDropper.Ljoiner
Win32.TrojanDropper.Microjoin
Win32.TrojanDropper.MuDrop
Win32.TrojanDropper.MultiBinder
Win32.TrojanDropper.MultiJoiner
Win32.TrojanDropper.NSIS
Win32.TrojanDropper.Nail
Win32.TrojanDropper.Pincher
Win32.TrojanDropper.Startpage
Win32.TrojanDropper.TDSS
Win32.TrojanDropper.Typic
Win32.TrojanDropper.VB
Win32.TrojanDropper.Vedio
Win32.TrojanDropper.Wlord
Win32.TrojanMailfinder.Banker
Win32.TrojanMailfinder.Blen
Win32.TrojanPWS.AccountHunter
Win32.TrojanPWS.Agent
Win32.TrojanPWS.Bjlog
Win32.TrojanPWS.Delf
Win32.TrojanPWS.Dybalom
Win32.TrojanPWS.Emelent
Win32.TrojanPWS.Frethoq
Win32.TrojanPWS.Gamad
Win32.TrojanPWS.Kates
Win32.TrojanPWS.Kukuraz
Win32.TrojanPWS.Kykymber
Win32.TrojanPWS.LdPinch
Win32.TrojanPWS.Lmir
Win32.TrojanPWS.Magania
Win32.TrojanPWS.Nilage
Win32.TrojanPWS.OnlineGames
Win32.TrojanPWS.Papras
Win32.TrojanPWS.PdPinch
Win32.TrojanPWS.QQPass
Win32.TrojanPWS.QQRob
Win32.TrojanPWS.Qbot
Win32.TrojanPWS.Qqfish
Win32.TrojanPWS.Qqten
Win32.TrojanPWS.Ruftar
Win32.TrojanPWS.Taworm
Win32.TrojanPWS.Tibia
Win32.TrojanPWS.VB
Win32.TrojanPWS.WOW
Win32.TrojanProxy.Agent
Win32.TrojanProxy.Glukelira
Win32.TrojanProxy.Puma
Win32.TrojanProxy.Small
Win32.TrojanProxy.Wintu
Win32.TrojanRansom.Digitala
Win32.TrojanRansom.Fakeinstaller
Win32.TrojanRansom.Gimemo
Win32.TrojanRansom.Hexzone
Win32.TrojanRansom.HmBlocker
Win32.TrojanRansom.PornoBlocker
Win32.TrojanRansom.PornoCodec
Win32.TrojanSpy.Agent
Win32.TrojanSpy.Amber
Win32.TrojanSpy.BZub
Win32.TrojanSpy.Banbra
Win32.TrojanSpy.Bancos
Win32.TrojanSpy.Banker
Win32.TrojanSpy.Banker2
Win32.TrojanSpy.Brospa
Win32.TrojanSpy.Delf
Win32.TrojanSpy.Flystudio
Win32.TrojanSpy.IESpy
Win32.TrojanSpy.Keylogger
Win32.TrojanSpy.Lpxenur
Win32.TrojanSpy.MultiBanker
Win32.TrojanSpy.Plankton
Win32.TrojanSpy.Pophot
Win32.TrojanSpy.Proagent
Win32.TrojanSpy.SpyEyes
Win32.TrojanSpy.VB
Win32.TrojanSpy.Webmoner
Win32.TrojanSpy.Wemon
Win32.TrojanSpy.Zbot
Win32.Worm.Agent
Win32.Worm.Allaple
Win32.Worm.AutoIt
Win32.Worm.AutoTsifiri
Win32.Worm.Autorun
Win32.Worm.Bagle
Win32.Worm.Bezopi
Win32.Worm.Brontok
Win32.Worm.Bybz
Win32.Worm.Carrier
Win32.Worm.Ckbface
Win32.Worm.FlyStudio
Win32.Worm.Fujack
Win32.Worm.Hlux
Win32.Worm.Kolab
Win32.Worm.Kolabc
Win32.Worm.Koobface
Win32.Worm.LovGate
Win32.Worm.Mabezat
Win32.Worm.Mydoom
Win32.Worm.Mytob
Win32.Worm.Qvod
Win32.Worm.Rokut
Win32.Worm.Sohanad
Win32.Worm.Trojandownloader
Win32.Worm.VB
Win32.Worm.Vbna
Win32.Worm.Viking
Win32.Worm.Warezov
Win32.Worm.Yahos


MD5 checksum for Ad-Aware core.aawdef is bdb59bf52c9732f6e69cce41b2fb3a34

anti spyware software antimalware how to remove spyware

Re: A "How-To" on Manually Updating the Norton Recovery Tool

Dear Pieter Viljoen,

I tried to access the documents, but I receive the following message:

Cannot Access Attachment.

You do not have sufficient rights to access the attachment.
Is there another way to access the files?, I need to include the RAID drivers to scan my machine and your documents would be very useful.
cheers

free pc fix free pc repair pc fixer

CVE-2010-3962 ? The weekend warrior

The Microsoft Malware Protection Center has been tracking a recent 0-day vulnerability for Microsoft Internet Explorer very closely after it was found in the wild in early November, apparently being used in targeted attack attempts.  As public exploit code became available and attackers began integrating the code into their toolkits, we continued to closely monitor the attack attempt patterns through the coverage (Exploit:Win32/CVE-2010-3962) provided to customers.

The attack patterns for this vulnerability have been somewhat unusual.  The Friday after we began our tracking effort, we saw our first spike in activity, predominantly targeting users in Korea, and secondarily attempting to exploit users in China.  Although attacks in China trended down over subsequent weeks, we continued to see weekend-related spikes in Korea.  However, after the second weekend spike, even these attack attempts continued to trend down, revealing a smaller number of attack attempts each coming weekend.  The following chart shows the geo-location of computers reporting the attack attempt along with the ?trending down? effect we?ve seen.

CVE-2010-3962 attack attempts

Image 1 - CVE-2010-3962 attack attempts by geo-location

Over the past few days, attack attempts in China have been on the rise, again, the downward trend that occurred during the first month is unusual for an 0-day vulnerability such as this one. One explanation might be that the attackers did not achieve the success rate that they had hoped.  Although the Microsoft Security Advisory (2458511) lists Windows 7, Windows Vista and Windows Server 20008 as affected operating systems, these platforms include DEP/ASLR mitigations (described in depth by TwC Security Science?s Matt Miller in a recent blog post).

When you pair those platforms with Internet Explorer 8 and above, DEP/ASLR technologies are enabled by default to protect IE.  So, perhaps the attackers have not been reaching the attack surface they had originally hoped and are starting to move on.  The following charts shows the number of Windows XP and Windows 2003 systems reporting attack attempts versus Windows Vista and Windows 7:

CVE-2010-3962 attack attempts by target OS

Image 2 - CVE-2010-3962 attack attempts by target OS

In any case, we?re happy to say that the bulletin addressing this issue is planned to be released on Tuesday, Dec.  14 as part of our usual monthly update cycle. As always, we urge all Microsoft customers to apply this update along with the protection technologies you may have had in place already.

- Holly Stewart, MMPC

pc errors how to fix runtime error fix computer problems

Another day, another PS3 security story

anti spyware free malware and spyware malware infection

Where am I?

I don’t know about the rest of the world, but in Russia the most popular SMS message is “Where are you?” But very soon that particular question is going to be irrelevant.

A few days ago Gartner published its list of the top 10 mobile applications to watch out for in 2012. First place went to Location-Based Services (LBSs).

Of course, there’s nothing new in technology that can pinpoint a mobile phone user’s location, and the whole range of services that comes with it offering information about individual users has been in the works for some time now.

But the thing is...

A few days ago one of my colleagues, who was in San Francisco listening to Bill Clinton’s keynote session at the RSA Conference, noticed on Facebook that his GPS and mobile services had gone a bit haywire. According to Google Maps, he had managed to visit Berlin, Disneyland in Florida and make it back to San Francisco all in the space of 2 minutes.

Another visitor to RSA also said that his location had been given as Disneyland in Florida for almost the whole week and that it was going to be difficult explaining to his boss what he’d been doing there instead of San Francisco :)

But on a more serious note, we are witnessing a very interesting process in human behavior. On one hand, users of mobile devices are increasingly willing to make public their exact whereabouts! I constantly see messages from my colleagues sent via Foursquare, for example, stating that they have arrived home (with a map of the town) or they are currently at some airport or other. This level of information is incomparable with the amount of personal data people used to make public. ‘Location’ used to mean the name of a town or city, but now it’s: “I’m here, right now!” to within a few meters.

On the other hand, monitoring people’s whereabouts is of more and more interest not only for law enforcement agencies but also for employers. Your employer can give you a company mobile and in return can expect to receive information about where you are, especially when you’re on a business trip. This type of tracking could even be used in legal disputes!

The situation is ideal for location-based services - there are people who want to publicize their whereabouts and there are other people who want to use that information. The consequences of this can be catastrophic. Here’s just one recent story about how people can be kidnapped and murdered as a result of information made public from their smartphones and posted on Facebook and Google.

OK, you might say these are exceptions and I’m paranoid. Maybe. But it can’t be hard to imagine a situation where a husband and wife end up having an argument after tracking each other’s movements. Or what about if an employer sees that his worker is in Disneyland like the story above? You can hardly blame it all on Bill Clinton :)

The growth in these services will soon lead to such serious problems protecting your personal life that all previous problems will seem like child’s play.

If I created applications for mobile phones, I’d seriously think about an app that didn’t state my real location but a false one!

I’d definitely buy it.

Or at least I’d do everything so that this type of functionality appeared in our Mobile Security product :)

antimalware how to remove spyware malware blocker