Articles Archive for 2 July 2009

Gumblar Invades Best Buy
Posted in Information and Removal on 2 July 2009

Earlier today, Trend Micro Technical Account Manager Fioravante Souza in Brazil spotted a (potentially harmful) URL that redirects users from the Best Buy domain site.
Users who visit www.bestbuy.com, as it turns out, are redirected to the URL, hxxp:// pics.bubbled.cn/gallery/hardcore/?23c4f60c1b9f604d6ffb21cba599301f. The compromised page in the domain is found to be the landing page where visitors can [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Gumblar Invades Best Buy

Spam Speculates Michael Jackson’s Murder
Posted in Information and Removal on 2 July 2009

Michael Jackson has been dead for a week already, but there are still a lot of speculations regarding his death. The spam runs are plenty as well — a Michael Jackson-related spam was seen bearing the subject Who killed Michael Jackson?, coming from a sender named x-files.
The spam message suggests that the icon was killed, [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Spam Speculates Michael Jackson’s Murder

Win32/Jusabli.A
Posted in CA Security Advisor on 2 July 2009

This malware is detected by eTrust Antivirus solutions. Please see above for the relevant signature updates. This malware is being dissected by the CA Security Advisory Team - a detailed analysis will be available shortly.

 

Win32/PolyCrypt!packed
Posted in CA Security Advisor on 2 July 2009

This malware is detected by eTrust Antivirus solutions. Please see above for the relevant signature updates. This malware is being dissected by the CA Security Advisory Team - a detailed analysis will be available shortly.

 

Win32/SillyProxy.DG
Posted in CA Security Advisor on 2 July 2009

This malware is detected by eTrust Antivirus solutions. Please see above for the relevant signature updates. This malware is being dissected by the CA Security Advisory Team - a detailed analysis will be available shortly.

 

Three Months Later: Where’s DOWNAD?
Posted in Information and Removal on 2 July 2009

Exactly three months ago, the whole IT sector was waiting with bated breath for April 1. The latest DOWNAD/Conficker variant–WORM_DOWNAD.KK–was poised to strike. We know that on that day, it would attempt to access 500 of 50,000 websites and download new malicious files. This led to fears–somewhat misplaced–that new, possibly damaging payloads could cause severe [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Three Months Later: Where’s DOWNAD?

PC Confidential
Posted in Information and Removal on 2 July 2009

PC Confidential is a fake spyware remover, which uses malicious tactics both to spread and to sell. This parasite typically relies on trojans, such as Vundo, or worms, to enter the system. PC Confidential has a range of tactics it uses to trick people into purchasing its full version.
Upon infecting the system, PC Confidential begins its dirty [...]