<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MVP Jubo Security Blog : Malware</title><link>http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx</link><description>Tags: Malware</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft Security Intelligence Report Vol. 6</title><link>http://msmvps.com/blogs/jubo/archive/2009/04/11/1686776.aspx</link><pubDate>Fri, 10 Apr 2009 23:23:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1686776</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1686776</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/04/11/1686776.aspx#comments</comments><description>&lt;p&gt;The Microsoft Security Intelligence Report (SIR), vol. 6, provides an in-depth perspective on the changing threat landscape including software vulnerability disclosures and exploits, malicious software (malware), and potentially unwanted software.&lt;/p&gt;  &lt;p&gt;More at: &lt;a href="http://www.microsoft.com/security/portal/sir.aspx" target="_blank"&gt;Microsoft Malware Protection Center&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Get your copy at the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=147935" target="_blank"&gt;Microsoft Download Center&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1686776" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/News/default.aspx">News</category></item><item><title>An Online ticket?!?</title><link>http://msmvps.com/blogs/jubo/archive/2008/09/22/1648754.aspx</link><pubDate>Mon, 22 Sep 2008 14:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1648754</guid><dc:creator>jubo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1648754</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/09/22/1648754.aspx#comments</comments><description>&lt;p&gt;What a surprise... This morning I was happily working at the office, hhmm... okay, from home..., when Outlook notified me that I had received an email. When I checked it was from an unknown company USA3000 Airlines. When I read the email they even had a ticket for me and had charged the credit card for $646.27. I thought, that should be at least a ticket to fly across the pond. Well, could have been a surprise from my wife since she&amp;#39;s visiting family in the USA. But no, I unzipped the file and there was a file called: &amp;quot;eTicket.doc.exe&amp;quot; and... not detected by McAfee&amp;#39;s antivirus program... yet... Submitted the file to &lt;a target="_blank" href="http://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt;&amp;nbsp;and you can find the result &lt;a target="_blank" href="http://www.virustotal.com/analisis/47fc08723f21ca1450717d5b0855c9fe"&gt;here&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Then I also submitted the file to McAfee&amp;#39;s &lt;a href="http://www.webimmune.net/"&gt;WebImmune&lt;/a&gt;&amp;nbsp;and they found a &amp;quot;new detection&amp;quot; and named it &amp;quot;&lt;a target="_blank" href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;amp;virus_k=141745"&gt;spy-agent.bw&lt;/a&gt;&amp;quot;. Not really a new one but a new variant. Not long after that I received an &amp;quot;Extra.dat&amp;quot; file from &lt;a target="_blank" href="http://www.avertlabs.com/"&gt;AvertLabs&lt;/a&gt; for some extra protection. See also McAfee&amp;#39;s Avert Labs Blog: &lt;a target="_blank" href="http://www.avertlabs.com/research/blog/index.php/2008/07/25/invoice-spam-takes-flight/"&gt;Invoice Spam Takes Flight&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;No e-ticket for me this morning... but the computer is still safe. Now I only wonder how it came through the company&amp;#39;s security. They run Symantec stuff...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1648754" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Olympic attachment?</title><link>http://msmvps.com/blogs/jubo/archive/2008/08/08/1643892.aspx</link><pubDate>Fri, 08 Aug 2008 06:36:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643892</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1643892</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/08/08/1643892.aspx#comments</comments><description>&lt;p&gt;Not only the Olympic games have started, but also the malware games related to the Olympics. One of the latest is that if you receive an attachment named as: &amp;quot;ioc_guidelines_for_persons_accredited_at_the_xxix_olympiad.pdf&amp;quot; then delete this immediately. If you open it then it could execute a malicious JavaScript that exploits a patched Adobe Reader vulnerability. And it follows to install a backdoor detected as &lt;a href="http://vil.nai.com/vil/content/v_143081.htm" target="_blank"&gt;BackDoor-DMG&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;McAfee has named this one: &amp;quot;Exploit-PDF.b&amp;quot;; for more detailed information about it check this article: &lt;a href="http://vil.nai.com/vil/content/v_144105.htm" target="_blank"&gt;Exploit-PDF.b&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Aliases:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.trendmicro.com/vinfo/emea/virusencyclo/default5.asp?VName=EXPL_PIDIEF.O" target="_blank"&gt;EXPL_PIDIEF.O&lt;/a&gt; (TrendMicro)&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-020915-1008-99" target="_blank"&gt;Trojan.Pidief.C&lt;/a&gt; (Symantec)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;If you do not have Adobe Reader version 9 installed, then you can download it from the &lt;a href="http://www.adobe.com/products/acrobat/readstep2.html?promoid=BUIGO" target="_blank"&gt;Adobe Download&lt;/a&gt;. Unfortunately it comes with Adobe AIR, which you can uninstall through Windows &amp;quot;Add/Remove Programs&amp;quot;. Also, during the installation process you might want to uncheck the option to install the Google toolbar.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643892" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/McAfee+Security/default.aspx">McAfee Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Let The (malware) Games Begin...</title><link>http://msmvps.com/blogs/jubo/archive/2008/04/15/1588400.aspx</link><pubDate>Tue, 15 Apr 2008 11:20:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1588400</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1588400</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/04/15/1588400.aspx#comments</comments><description>&lt;p&gt;Few days ago the McAfee &lt;a href="http://www.avertlabs.com/research/blog/" target="_blank"&gt;Avert Labs&lt;/a&gt; received an email with a executable flash movie. The attachment was called: &amp;quot;RaceForTibet.exe&amp;quot;, which eventually seems to be a keylogger program. Even a log file is being send to a provider in China. &lt;/p&gt; &lt;p&gt;Just want to warn you: never open or run a file that you get from (un)known people. Keep your Windows updated and/or check your version at &lt;a href="http://update.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt;, keep your antivirus and/or antispyware updated. &lt;/p&gt; &lt;p&gt;For more (technical) details about the above keylogger program see this topic: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/04/14/is-malware-writing-the-next-olympic-event/" target="_blank"&gt;Is Malware Writing the Next Olympic Event?&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1588400" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/McAfee+Security/default.aspx">McAfee Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>WinCE/InfoJack - Trojan disables Windows Mobile Application Installation Security</title><link>http://msmvps.com/blogs/jubo/archive/2008/02/27/1525785.aspx</link><pubDate>Wed, 27 Feb 2008 08:46:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1525785</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1525785</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/02/27/1525785.aspx#comments</comments><description>&lt;p&gt;From: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/02/26/windows-mobile-trojan-sends-unauthorized-information-and-leaves-device-vulnerable/" target="_blank"&gt;McAfee Avert Labs Blog&lt;/a&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;&amp;quot;A Window Mobile PocketPC trojan that disables Windows Mobile application installation security has been discovered in China. &lt;/em&gt; &lt;p&gt;&lt;em&gt;WinCE/InfoJack sends the infected device’s serial number, operating system and other information to the author of the trojan. It also leaves the infected mobile device vulnerable by allowing silent installation of malware. The trojan modifies the infected device’s security setting to allow unsigned applications to be installed without a warning.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1525785" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/McAfee+Security/default.aspx">McAfee Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Windows+Mobile/default.aspx">Windows Mobile</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Microsoft Launches Malware Protection Center</title><link>http://msmvps.com/blogs/jubo/archive/2007/07/11/1015301.aspx</link><pubDate>Wed, 11 Jul 2007 19:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1015301</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1015301</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/07/11/1015301.aspx#comments</comments><description>&lt;p&gt;Get the latest information about malware and potentially unwanted software on the Microsoft Malware Protection Center Portal. Browse the MMPC&amp;#39;s malware encyclopedia, download the latest virus/spyware definitions, submit malware samples, and find links to additional content.&lt;/p&gt;
&lt;p&gt;See: &lt;a class="" href="http://www.microsoft.com/security/portal/" target="_blank"&gt;Microsoft Malware Protection Center&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1015301" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Malware Removal Starter Kit</title><link>http://msmvps.com/blogs/jubo/archive/2007/07/11/1015061.aspx</link><pubDate>Wed, 11 Jul 2007 11:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1015061</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1015061</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/07/11/1015061.aspx#comments</comments><description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Many small- and medium-sized organizations use antivirus software, and yet new viruses, worms, and other forms of malicious software (malware) continue to infect large numbers of computers in these organizations. Malware proliferates at alarming speed and in many different ways, which makes it particularly widespread today.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This guide is intended for IT Generalists who want information and recommendations that they can use to effectively address and limit malware that infects computers in small- and medium-sized organizations. This guidance provides a set of tasks that licensed Windows® users can perform at no cost to create the Malware Removal Starter Kit. Recommendations for free malware-scanning tools are included. You can use these tools in combination with the kit to conduct scans, detect problems, and remove malware from your computer.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;More information at: &lt;a class="" href="http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx" target="_blank"&gt;TechNet&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Download at: &lt;a class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=6cd853ce-f349-4a18-a14f-c99b64adfbea&amp;amp;DisplayLang=en" target="_blank"&gt;Download Center&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1015061" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Malware Removal Guides at Bleepingcomputer</title><link>http://msmvps.com/blogs/jubo/archive/2007/07/07/1007679.aspx</link><pubDate>Sat, 07 Jul 2007 17:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1007679</guid><dc:creator>jubo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1007679</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/07/07/1007679.aspx#comments</comments><description>&lt;p&gt;More spyware and malware removal guides are posted at &lt;a class="" href="http://www.bleepingcomputer.com/" target="_blank"&gt;Bleepingcomputer&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98916.html" target="_blank"&gt;How to remove Ultimate Cleaner&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98811.html" target="_blank"&gt;How to remove Ultimate Defender&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98808.html" target="_blank"&gt;How to remove PC Turbo Pro or PCTurboPro&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98801.html" target="_blank"&gt;How to remove Privacy Protector or PrivacyProtector&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98791.html" target="_blank"&gt;How to remove SpyShredder or Spy-Shredder&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://www.bleepingcomputer.com/forums/topic98706.html" target="_blank"&gt;How to remove VirusLocker&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;For more malware removal instructions, see the &lt;a class="" href="http://www.bleepingcomputer.com/forums/forum55.html" target="_blank"&gt;Spyware and Malware Removal Guides and Reading Room&lt;/a&gt;&amp;nbsp;at &lt;a class="" href="http://www.bleepingcomputer.com/" target="_blank"&gt;Bleepingcomputer&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1007679" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item></channel></rss>