What is SaveInfo?

The Malwarebytes research team has determined that SaveInfo is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue.

http://forums.malwarebytes.org/index.php?showtopic=126794

Summary

The following bulletins have undergone minor revision increments.
Please see the bulletins for more details.
 
 * MS12-044
 
Bulletin Information:

* MS12-044 - Important

  - http://technet.microsoft.com/security/bulletin/ms12-044
  - Reason for Revision: V1.1 (May 23, 2013): Revised bulletin to
    announce a detection change for the Microsoft Visio 2010
    (2810068) update. This is a detection change only. There were
    no changes to the update files. Customers who have successfully
    installed the update do not need to take any action.
  - Originally posted: May 14, 2013 
  - Updated: May 23, 2013 
  - Bulletin Severity Rating: Important
  - Version: 1.1

Summary

The following bulletins have undergone minor revision increments.
Please see the bulletins for more details.

* MS12-081
* MS13-037
* MS13-MAY

Bulletin Information:

* MS12-081 - Critical

- »technet.microsoft.com/security/b···ms12-081
- Reason for Revision: V1.1 (May 22, 2013): Added a link to
Microsoft Knowledge Base Article 2758857 under Known Issues
in the Executive Summary.
- Originally posted: December 11, 2012
- Updated: May 22, 2013
- Bulletin Severity Rating: Critical
- Version: 1.1

* MS13-037 - Critical

- »technet.microsoft.com/security/b···ms13-037
- Reason for Revision: V1.1 (May 22, 2013): Corrected the
Common Vulnerabilities and Exposures number for
CVE-2013-3140. This is an informational change only.
- Originally posted: May 14, 3013
- Updated: May 22, 2013
- Bulletin Severity Rating: Critical
- Version: 1.1

* MS13-MAY

- »technet.microsoft.com/security/b···ms13-MAY
- Reason for Revision: V1.1 (May 22, 2013): For MS13-037,
corrected the Common Vulnerabilities and Exposures number
for CVE-2013-3140. This is an informational change only.
- Originally posted: May 14, 3013
- Updated: May 22, 2013
- Version: 1.1

2013-05-22

Malware
+ SimplyTech.HomeTab
PUPS
+ Bandoo.Toolbar
Trojans
+ Banload + FakePorn.Winlock
Total: 2586623 fingerprints in 802866 rules for 7001 products.

http://www.safer-networking.org/about/updates/

Posted Wed, May 22 2013 8:50 by Don
Filed under:

What is Vaccine-365?

The Malwarebytes research team has determined that Vaccine-365 is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue.

http://forums.malwarebytes.org/index.php?showtopic=126666

The Spamhaus Ransomware is computer infection that displays a a screenlocker so you can not access your desktop and applications and encrypts your files. When infected with this malware, you will be presented with a screen when you login to Windows that pretends to be from the Spamhaus Project. This screen states that they have detected your computer participating in illegal activities and have blocked access to it until you pay a fine. This infection will also scan your computer for files that end with the .ddrw ,.pptm ,.dotm ,.xltx ,.text ,.docm ,.djvu ,.potx ,.jpeg ,.pptx ,.sldm ,.xlsm ,.sldx ,.xlsb ,.ppam ,.xlsx ,.ppsm ,.ppsx ,.docx ,.odp ,.eml ,.ods ,.dot ,.php ,.xla ,.pas ,.gif ,.mpg ,.ppt ,.bkf ,.sda ,.mdf ,.ico ,.dwg ,.mbx ,.sfx ,.mdb ,.zip ,.xlt extensions and then encrypt them. When the ransomware encrypts a file it will rename it as a HTML file and then embed the encrypted file inside of it. If you then attempt to launch any of these encrypted files, you will be taken to a web page, which is currently at http://xblblock.com, that prompts you to pay the ransom in the form of a MoneyPak voucher

http://www.bleepingcomputer.com/virus-removal/remove-spamhaus-ransomware

The Computer Crime and Intellectual Property Section ransomware is a computer infection that displays a screen requesting money before it allows you to access your Windows desktop. This screen locker pretends to be an alert from the FBI that states they have detected that you have been viewing child pornography, using unlicensed software, or distributing copyrighted files. They further state that in order to avoid federal prosecution you must pay a fee of $300 in the form of a MoneyPak voucher within 72 hours to gain access to your computer again.

 

 http://www.bleepingcomputer.com/virus-removal/remove-computer-crime-intellectual-property-section

Summary

The following bulletins have undergone minor revision increments.
Please see the bulletins for more details.
 
  * MS13-045
  
Bulletin Information:

* MS13-045 - Important

  - http://technet.microsoft.com/security/bulletin/ms13-045
  - Reason for Revision: V1.1 (May 15, 2013): Corrected link to the
    download location in the Detection and Deployment Tools and
    Guidance section. This is an informational change only.
  - Originally posted: May 14, 3013 
  - Updated: May 15, 2013 
  - Bulletin Severity Rating: Important
  - Version: 1.1


Summary

The following bulletins have undergone minor revision increments.
Please see the bulletins for more details.
 
  * MS13-009
  
Bulletin Information:

* MS13-009 - Critical

  - http://technet.microsoft.com/security/bulletin/ms13-009
  - Reason for Revision: V1.2 (May 14, 2013): Revised this bulletin
    to announce a detection change to correct an offering issue for
    Windows Server 2012 (Server Core installation). This is a detection
    change only. There were no changes to the security update files.
    Customers who have already successfully updated their systems do
    not need to take any action.
  - Originally posted: February 12, 2013 
  - Updated: May 14, 2013 
  - Bulletin Severity Rating: Critical
  - Version: 1.2

Security Advisories Updated or Released Today

* Microsoft Security Advisory (2846338)
  - Title: Vulnerability in Microsoft Malware Protection Engine
    Could Allow Remote Code Execution
  - http://technet.microsoft.com/security/advisory/2846338
  - Revision Note: V1.0 (May 14, 2013): Advisory published.

* Microsoft Security Advisory (2820197)
  - Title: Update Rollup for ActiveX Kill Bits
  - http://technet.microsoft.com/security/advisory/2820197
  - Revision Note: V1.0 (May 14, 2013): Advisory published.

* Microsoft Security Advisory (2755801)
  - Title: Update for Vulnerabilities in Adobe Flash Player in
    Internet Explorer 10
  - http://technet.microsoft.com/security/advisory/2755801
  - Revision Note: V12.0 (May 14, 2013): Added the 2840613 update
    to the Current Update section.

* Microsoft Security Advisory (2847140)
  - Title: Vulnerability in Internet Explorer Could Allow Remote
    Code Execution
  - http://technet.microsoft.com/security/advisory/2847140
  - Revision Note: V2.0 (May 14, 2013): Advisory updated to reflect
    publication of security bulletin.

 

Event ID: 1032538728
Language(s):  English.
Product(s):  computer security and information security.
Audience(s):  IT Decision Maker, IT Implem_IT Generalist and IT Manager.

Join us for a brief overview of the technical details of this month's Microsoft security bulletins. We intend to address your concerns in this webcast. Therefore, Microsoft security experts devote most of this webcast to answering the questions that you ask.

Presented by:

Dustin Childs, Group Manager, Response Communications, Microsoft Corporation

and

Jonathan Ness, Security Development Manager, Microsoft Corporation

Register for Event
Starts: Wednesday, May 15, 2013 11:00 AM
Time zone: (GMT-08:00) Pacific Time (US & Canada)
Duration: 1 hour(s)

Posted Tue, May 14 2013 13:24 by Don
Filed under:

Note: There may be latency issues due to replication, if the page does not display keep refreshing

Today Microsoft released the following Security Bulletin(s).

Note: »www.microsoft.com/technet/security and »www.microsoft.com/security are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.

Bulletin Summary:

»technet.microsoft.com/en-us/secu···ms13-may

Critical (2)

Microsoft Security Bulletin MS13-037
Cumulative Security Update for Internet Explorer (2829530)
»technet.microsoft.com/en-us/secu···ms13-037

Microsoft Security Bulletin MS13-038
Security Update for Internet Explorer (2847204)
»technet.microsoft.com/en-us/secu···ms13-038

Important (8)

Microsoft Security Bulletin MS13-039
Vulnerability in HTTP.sys Could Allow Denial of Service (2829254)
»technet.microsoft.com/en-us/secu···ms13-039

Microsoft Security Bulletin MS13-040
Vulnerabilities in .NET Framework Could Allow Spoofing (2836440)
»technet.microsoft.com/en-us/secu···ms13-040

Microsoft Security Bulletin MS13-041
Vulnerability in Lync Could Allow Remote Code Execution (2834695)
»technet.microsoft.com/en-us/secu···ms13-041

Microsoft Security Bulletin MS13-042
Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397)
»technet.microsoft.com/en-us/secu···ms13-042

Microsoft Security Bulletin MS13-043
Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399)
»technet.microsoft.com/en-us/secu···ms13-043

Microsoft Security Bulletin MS13-044
Vulnerability in Microsoft Visio Could Allow Information Disclosure (2834692)
»technet.microsoft.com/en-us/secu···ms13-044

Microsoft Security Bulletin MS13-045
Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707)
»technet.microsoft.com/en-us/secu···ms13-045

Microsoft Security Bulletin MS13-046
Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2840221)
»technet.microsoft.com/en-us/secu···ms13-046

Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety 1-866-727-2338. International customers should contact their local subsidiary.

As always, download the updates only from the vendors website - visit Windows Update and Office Update or Microsoft Update websites. You may also get the updates thru Automatic Updates functionality in Windows system.

Security Tool
Find out if you are missing important Microsoft product updates by using MBSA.

What is Boan Safe?

The Malwarebytes research team has determined that Boan Safe is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue.

http://forums.malwarebytes.org/index.php?showtopic=126166

What is Booster-Clean?

The Malwarebytes research team has determined that Booster-Clean is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue.

http://forums.malwarebytes.org/index.php?showtopic=126120

This is an advance notification of 10 security bulletins that Microsoft is intending to release on May 14, 2013.

2 rated as Critical and 8 with a rating of Important

http://technet.microsoft.com/en-us/security/bulletin/ms13-may

Security Advisories Updated or Released Today

* Microsoft Security Advisory (2847140)
  - Title: Vulnerability in Internet Explorer Could Allow
    Remote Code Execution
  - http://technet.microsoft.com/security/advisory/2847140
  - Revision Note: V1.1 (May 8, 2013): Added link to Microsoft
    Fix it solution, "CVE-2013-1347 MSHTML Shim Workaround," that
    prevents exploitation of this issue.

2013-05-08

Adware

+ Somoto.BetterInstaller + Yontoo.Pagerage
PUPS
++ Avanquest.PCSpeedMaximizer ++ USTechSupport.MyCleanPC
Malware
++ FindLyrics ++ Iminent.Messanger ++ Install.DomaIQ ++ Qtrax ++ Tuguu.VAFPlayer
Spyware
++ IronInstall.Toolbar.Amazon ++ SaveByClick
Trojans
+ Dexon.Agent + Win32.Expiro
Total: 2585519 fingerprints in 802514 rules for 6998 products.

http://www.safer-networking.org/about/updates/

Posted Wed, May 8 2013 7:10 by Don
Filed under:

What is VaccineTools?

The Malwarebytes research team has determined that VaccineTools is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue.

http://forums.malwarebytes.org/index.php?showtopic=125872

Security Advisories Updated or Released Today

* Microsoft Security Advisory (2847140)
  - Title: Vulnerability in Internet Explorer Could Allow
    Remote Code Execution
  - http://technet.microsoft.com/security/advisory/2847140
  - Revision Note: V1.0 (May 3, 2013): Advisory published.

The Security Pro rogue hijacks the .exe extensions and effectively blocks other programs. It can also delete wuauserv and disables shared access.

http://www.youtube.com/watch?v=YVf14ef6uC4

More Posts Next page »