Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

13 October 2009

SPAM: Server Upgrade

I have been alerted to a couple of users who are receiving spam that contains links to external websites. the message is as follows:

Attention!

On October 16, 2009 server upgrade will take place. Due to this the system may be offline for approximately half an hour.

The changes will concern security, reliability and performance of mail service and the system as a whole.

For compatibility of your browsers and mail clients with upgraded server software you should run SSl certificates update procedure.

This procedure is quite simple. All you have to do is just to click the link provided, to save the patch file and then to run it from your computer location. That's all.

http://updates.<your domain>.<various>/ssl/id=73616375-<email>-patch2844683.aspx

Thank you in advance for your attention to this matter and sorry for possible inconveniences.

System Administrator

I have noticed the following domain names being used so far which I have blocked on my proxy server:

*.admin-db.net
*.1ssl-certs.com

According to: http://www.dshield.org/diary.html?storyid=7333

The link leads the user to a download which disables AV and has Trojan / key logger characteristics.

Once again the URL contains the users email address so the site will probably log the entry to a db for future spamming.

I would suggest that you add all the domain names that you encounter in these messages to your proxy blocked list to prevent users from giving their email addresses away for future attacks.

28 September 2009

tax-statement-taxpayer_id*.exe

There are some fake IRS spam mails circulating at the moment that go to a page and try to get you to download a virus file which trend micro office scan picks up as TROJ_ZBOT.CBY.

I am particularly worried about this email as it seems as though the URL contains the email address of the user it was sent to. This will then allow the owner of the site to log valid email addresses when someone clicks on the link in the email. They don't even need to download the file to now be a bigger target for spam.

Solution: I also noticed that there are multiple domains that users are being redirected to so I decided to block *.irs.gov.*.com on our Proxy server to prevent users getting themselves on a spam list.

I found the following domain names in this type of attack so far:

*.irs.gov.y11dera.com

*.irs.gov.fedas1am.com

*.irs.gov.fedasaz.com

*.irs.gov.y11derq.com

image

Screenshot of the website you get redirected to when you click on the link in the emails.

13 June 2008

Ransomware

Ransomware seems to be a relativly old form of malware that is beginning to resurface according to Trend Micro. This form of malware takes certain files on your computer and encrypts them. You will not be able to access the files unless you pay the malware writer a fee for the program to decrypt the files. You can find more information about this malware on Wikipedia.

I think that this type of malware is particulary destructive / disruptive and could cause massive problems for computer administrators in future if this type of threat increases.

29 April 2008

Trend Micro Officescan 8.0 Clients Crashing


Double Click Error



Right Click Error



We seem to be experiencing some difficulty with Trend Micro Officescan lately. When a client right clicks on the system tray icon and tries to open the Officescan console Trend Crashes. If they try to double click on the tray icon Officescan also crashes.

This is happening on all the clients that are attached to the servers that we recently updated to the latest patch from Trend Micro. It is happening to both Windows XP SP2 machines as well as Windows Vista Business SP1 machines. As yet I have been unable to find any information on the Trends website on how to resolve the issue.

When you double click you get the following error on Windows Vista:
"Trend Micro Officescan Monitor has stopped working"

When you right click you get the following error on Windows Vista:
"Trend Micro Officescan Management Console (32-bit) has stopped working"

Server Version: Officescan 8.0 build 1834

28 January 2008

WORM_IRCBOT.OY

Trend finally found the Virus! It took them some time but the mymsnpictures.com virus has finaly been detected in the file I downloaded from the link sent to me in MSN.
You can find information about the virus here:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FIRCBOT%2EOY&VSect=Sn

24 January 2008

SOLUTION: Hey, is this your picture?? MSN Virus

After an evening of fighting I think I have finally beaten this MSN virus! I ran Adaware, SpyBot, Windows Defender and Trend Micro Office Scan, but they all left some trace of the virus behind.

I noticed that the sneaky code modified my host file and pointed all anti-virus websites to local host as well as making the host file read-only. You can fix this by going to %SystemRoot%\System32\Drivers\Etc\ and right clicking on hosts file and unchecking the read only checkbox.

You can then open the file in something like wordpad and delete all the entries that show up near the bottom. Mine had a huge list.

Once you have doe this the instructions to get rid of the virus can be found on this helpfull blog:
http://2j07--jamboree.blogspot.com/
Look at the entry " Wednesday, January 23, 2008"

Hope this helps you out!

Hey, is this your picture?? MSN Virus

I got a message from a firend in MSN that said Hey, is this your picture?? followed by a link to a website mymsnpictures.com. Appon following the link a file was downloaded to my machine. The file was a .com file which kind of set off some red lights in my head.
So I tried scanning the file with Trend Micro Office Scan Client and it didn't pick up anything.
So I then decided to try the following online scanners:
  • Trend Micro House Call
  • Bit Deffender Online Scanner
  • kaspersky Online Scanner
None of them picked up anything. So curiousity got the better of me and I decided to open the file.
At that point Windows Defender started screaming like mad!
I imagine that shortly after that multiple MSN windows opened and closed in quick succession on my PC, but I have not been able to verify that yet as I pulled out my network cable. None of my msn contacts have complained yet, but I suggest you ignore any links to pictures in MSN for now.

I will keep you posted as I am currently doing full system scans with Trend and with windows defender.

30 October 2007

PDF Vulnerability

We recently got hit with a new threat in the form of a vulnerability in Adobe Acrobat Reader that allows a PDF file with malicious code to download a trojan off the internet.
When you open the pdf file a command line window may appear, and internet explorer or firefox may attempt to open. I have also heard of a case where outlook/outlook express is opened as well.

In order to combat this threat you need to download a patch from the Adobe site here.

You can find out more information on the vulnerability and its exploits below:

27 July 2007

Trend UltraVNC Problem

My Trend Micro Office Scan server has recently started poping up with tons of TROJ_Generic.MRS viruses. I managed to narrow it down and determine that Trend is picking up my UltraVNC Server on some of my computers as this TROJ_Generic.MRS virus.

To stop multiple errors from poping up on the client machine you can temporarily stop the UltraVNC service.
NOTE:
Once you stop the service the UltraVNC exe file will be deleted from the machine so you may need to re-install the application.

To prevent the anti-virus from picking up the UltraVNC server as a trojan again you can add an exclusion to the OfficeScan server via the webconsole.
Click on Clients -> Scan Options -> Real Time Scan Settings.
In the Real Time scan settings page check the Enable Exclusion list.
Click on the Exclusion list link and in the folder section add the UltraVNC directory.
C:\Program Files\UltraVNC and then click add.