<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>PC-Armor Computer Security News Blog &#187; Malware</title>
	<link>http://www.pc-armor.com/blog</link>
	<description>Computer Security News for Everyday Computer Users</description>
	<pubDate>Sun, 22 Jun 2008 06:21:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>Nasty Trojan causes Task Manager and Registry Editor to stop working</title>
		<link>http://www.pc-armor.com/blog/?p=138</link>
		<comments>http://www.pc-armor.com/blog/?p=138#comments</comments>
		<pubDate>Mon, 02 Jun 2008 02:40:17 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[Knowledge Base]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[On the Radar]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=138</guid>
		<description><![CDATA[I received a call from a friend over the weekend asking for help to rid his neighbor&#8217;s computer of a nasty Trojan.  Apparently, he had been working on the problem for days and didn&#8217;t know what else he could do, so I took a look and it was indeed a nasty infection.  The computer had [...]]]></description>
			<content:encoded><![CDATA[<p>I received a call from a friend over the weekend asking for help to rid his neighbor&#8217;s computer of a nasty Trojan.  Apparently, he had been working on the problem for days and didn&#8217;t know what else he could do, so I took a look and it was indeed a nasty infection.  The computer had McAfee and Norton security products installed, but they apparently didn&#8217;t help prevent the infection, so we removed them and installed CounterSpy and F-Secure.</p>
<p>What happened was the Trojan hijacked the desktop and changed it to a Bright Red background with a warning stating that the computer was infected with a malicious program and provided a link to for the user to click to purchase a program that would clean the computer.  Obviously, this was not a legitimate link, so I copied the link location to notepad and it pointed to hxxp://antispyspider.us/69.  <u><strong>DO NOT GO TO THIS LINK, IT IS VERY BAD!</strong></u>  Some other things this infection did was change the IP address and subnet mask; disabled the Task Manager and Registry Editor; and caused Internet Explorer to launch every couple of minutes to connect to the malicious site.  There was also a service that was added to the computer and it launched when Windows XP started.</p>
<p>The steps we used to try and defeat this nasty infection included:</p>
<blockquote><p>- Running &#8220;<strong>msconfig</strong>&#8221; to disable all programs from starting<br />
- Disabled the &#8220;Service&#8221; that was installed<br />
- Turned off the System Restore feature, since we didn&#8217;t want anything malicious to be included in a restore<br />
- Installed and ran <strong>CounterSpy</strong>, which found many malicious files, registry entries, and cookies.  We removed everything successfully</p></blockquote>
<p>But we could not kill the Trojan, so I googled &#8220;AntiSpySpider&#8221; and found a very good web page showing how to kill this critter and if you need the instructions, you can get them from:</p>
<p><a href="http://www.bleepingcomputer.com/malware-removal/antispyspider" title="AntiSpySpider Removal" target="_blank">http://www.bleepingcomputer.com/malware-removal/antispyspider</a></p>
<p>The fix includes running a program to restore the registry editor, as well as a file to restore the task manager.  The instructions do a great job showing the victim how to remove this threat, so if you are one of the unfortunate souls, try this fix.  Then if you get it removed, you might consider running CounterSpy and F-Secure Internet Security; both of these programs have been quite dependable protecting our computers, as well as people we know.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=138</wfw:commentRss>
		</item>
		<item>
		<title>Malicious PDF File Outbreak Today</title>
		<link>http://www.pc-armor.com/blog/?p=116</link>
		<comments>http://www.pc-armor.com/blog/?p=116#comments</comments>
		<pubDate>Fri, 26 Oct 2007 19:17:08 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[On the Radar]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=116</guid>
		<description><![CDATA[There are a Couple of things worth mentioning today: The malicious Psycho Kitty eCard is still circulating, because I received one today with the subject of:
Subject: You have yet to open your ecard.

The body of the email reads, &#8220;Someone sent you this Psycho Kitty card. It is Hilarious!&#8221; and of course, there is a link [...]]]></description>
			<content:encoded><![CDATA[<p>There are a Couple of things worth mentioning today: The malicious <strong>Psycho Kitty eCard</strong> is still circulating, because I received one today with the subject of:</p>
<p><em><strong>Subject: You have yet to open your ecard.<br />
</strong></em><br />
The body of the email reads, &#8220;<strong><em>Someone sent you this Psycho Kitty card. It is Hilarious!</em></strong>&#8221; and of course, there is a link the criminals want you to click that points to an IP Address.</p>
<p>The other notable news from today is about a <strong>PDF Malware Spam outbreak throughout the Internet</strong>.  My <strong>F-Secure Anti-virus</strong> program has a nice little feature called &#8220;<strong>Security News</strong>&#8221; and during high levels of malicious activity, a balloon will pop up by the system clock with a warning to the consumer.</p>
<p>Today, the balloon popped up with an <strong>F-Secure Level 2 Security Alert</strong> and it read,</p>
<blockquote><p>&#8220;<em><strong>Malicious PDF files being spammed out in volume. The files have &#8220;report&#8221; themed subjects and CVE-2007-5020 exploit that they use to download further components from the net.</strong></em>&#8220;</p></blockquote>
<p>As usual, F-Secure protects against this threat; but other Anti-virus program may not, so please be aware that malicious PDF files are currently being spammed and you need to be extra cautious before opening them.</p>
<p>Also, Make sure you have the latest version of <strong>Adobe Acrobat</strong> and <strong>Acrobat Reader</strong>, because Adobe recently released security patches to address a critical vulnerability that if exploited, could have given the attacker complete control of the infected system.</p>
<p>To learn more about the latest PDF Threat, visit the <strong>F-Secure advisory</strong> at:</p>
<p><strong><a href="http://www.f-secure.com/v-descs/exploit_w32_adobereader_k.shtml" title="F-Secure PDF Outbreak Alert" target="_blank">http://www.f-secure.com/v-descs/exploit_w32_adobereader_k.shtml</a></strong></p>
<p>Or the <strong>SANS advisory</strong> at:</p>
<p><strong><a href="http://www.f-secure.com/weblog/archives/00001303.html" title="SANS Malicious PDF Advisory" target="_blank">http://www.f-secure.com/weblog/archives/00001303.html</a></strong></p>
<p>Stay safe out there&#8230;cyberspace is a hostile place!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=116</wfw:commentRss>
		</item>
		<item>
		<title>Subject: Football Fan Essentials</title>
		<link>http://www.pc-armor.com/blog/?p=110</link>
		<comments>http://www.pc-armor.com/blog/?p=110#comments</comments>
		<pubDate>Sun, 09 Sep 2007 18:44:09 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[On the Radar]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=110</guid>
		<description><![CDATA[Lately, anytime something “newsworthy” crops up, the spammers and phishers jump all over the story and as many people know, today is the NFL’s opening day.  Well, it didn’t take long for malicious e-mails to start surfacing, in fact, I received one this morning with the subject line of “Football Fan Essentials”.
In this particular e-mail, [...]]]></description>
			<content:encoded><![CDATA[<p>Lately, anytime something “newsworthy” crops up, the spammers and phishers jump all over the story and as many people know, today is the NFL’s opening day.  Well, it didn’t take long for malicious e-mails to start surfacing, in fact, I received one this morning with the subject line of “<strong>Football Fan Essentials</strong>”.</p>
<p>In this particular e-mail, the bait is an “<strong>Online Game Tracker</strong>” and by clicking a link pointing to “http://<em>IP address</em>”, the victim is led to believe they will be able to follow the scores of the football games throughout the day.  However, the unsuspecting victim will most likely become infected with a variant of the Storm Worm.</p>
<p>As usual, when I saw this, I did my homework and checked out the <strong>SANS Internet Storm Center Diary</strong> for any late-breaking news about this latest threat and sure enough, they were on top of it.  Here is the story:</p>
<p><a href="http://isc.sans.org/diary.html?storyid=3361" title=""Are you ready for some football?" " target="_blank"> http://isc.sans.org/diary.html?storyid=3361</a></p>
<p><strong>F-Secure</strong> also posted a warning on their Blog at: <a href="http://www.f-secure.com/weblog/" title=""Storm and NFL"" target="_blank">http://www.f-secure.com/weblog/</a></p>
<p>Anyone who reads security news blogs and articles understands that <strong><u>it is never a good idea to click on any link containing an IP Address</u></strong> and this link is no different.  Don’t take the bait…just delete the e-mail!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=110</wfw:commentRss>
		</item>
		<item>
		<title>Watch out for the &#8220;Storm&#8221;</title>
		<link>http://www.pc-armor.com/blog/?p=106</link>
		<comments>http://www.pc-armor.com/blog/?p=106#comments</comments>
		<pubDate>Wed, 22 Aug 2007 03:24:48 +0000</pubDate>
		<dc:creator>blog</dc:creator>
		
		<category><![CDATA[Malware]]></category>

		<category><![CDATA[On the Radar]]></category>

		<guid isPermaLink="false">http://www.pc-armor.com/blog/?p=106</guid>
		<description><![CDATA[The Storm Worm is mutating and you need to be aware of this latest outbreak.  This critter&#8217;s signature changes every 30 minutes or so; therefore, you cannot rely on your AV or Anti-spyware software to detect and stop the attack.
SANS has a good write-up about this latest threat and you can read it at:
http://isc.sans.org/diary.html?storyid=3298
Here is [...]]]></description>
			<content:encoded><![CDATA[<p>The Storm Worm is mutating and you need to be aware of this latest outbreak.  This critter&#8217;s signature changes every 30 minutes or so; therefore, you cannot rely on your AV or Anti-spyware software to detect and stop the attack.</p>
<p><strong>SANS</strong> has a good write-up about this latest threat and you can read it at:</p>
<p><a href="http://isc.sans.org/diary.html?storyid=3298" title="Storm of the Day (Welcome Member)" target="_blank">http://isc.sans.org/diary.html?storyid=3298</a></p>
<p>Here is a variation I received today and if you read the SANS article, there are a lot of similarities; but what is important here is to realize this is just another example of a social engineering trick designed to tempt the unfortunate victim into clicking the link; which by the way is an IP Address&#8230;another dead giveaway that this is not an e-mail you should trust.  Below is a sample of the e-mail I received and of course, I changed the e-mail address and link address to protect the readers; but the content is very similar to the SANS example.</p>
<blockquote><p><em>Subject: Secure Registration<br />
From: &#8220;Recipes Galore&#8221; &lt;spoofed address@spoofed domain&gt;</p>
<p>Welcome Member,</p>
<p>Thank You for Joining Recipes Galore.</p>
<p>User Number: 866599439<br />
Your Temp. Login ID: user1846<br />
Your Password ID: tk604</p>
<p>Your temporary Login Info will expire in 24 hours. Please login and change it.</p>
<p>Use this link to change your Login info: http://www.xxx.yyy.zzz/</p>
<p>Enjoy,<br />
Welcome Department<br />
Recipes Galore</em></p></blockquote>
<p>Be careful out there!  There&#8217;s nasty weather ahead!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pc-armor.com/blog/?feed=rss2&amp;p=106</wfw:commentRss>
		</item>
	</channel>
</rss>
