Articles Archive for 2 March 2010

Trojan.FakeAV.BXB
Posted in BitDefender on 2 March 2010

Trojan.FakeAV.BXB

Four Computer Hackers Broke in Concert Ticket Sites
Posted in Information and Removal on 2 March 2010

Four men were accused for purchasing and reselling more than one million tickets to various concerts and sport matches with a help of modern computer programs. Kenneth Lowson, Kristofer Kirsch, Faisal Nahdi and Joel Stevenson used a computer program to bypass protection tools that control the number of tickets that one person can buy. Usually [...]

Text Spam and Text Scams
Posted in Information and Removal on 2 March 2010

Text scams are increasingly becoming common again due to the forthcoming Philippine national and local elections, as political campaigns take to rampant text messaging for faster political mobilization. Earlier, I received a text message with the following content:
May GOD bountifuly bles u & ur family. Have a blissful day Fr Frends of UNI-MAD Party List, [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Text Spam and Text Scams

Calling Windows for Help May Lead to Vulnerability
Posted in Information and Removal on 2 March 2010

Asking for help in Windows could lead to more trouble.
A newly discovered vulnerability in Internet Explorer (IE) leverages the ability of a Visual Basic script to invoke a .HLP (Windows Help file format) file, which could give a remote attacker the ability to run arbitrary code on an affected system.
Visual Basic uses the following syntax [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Calling Windows for Help May Lead to Vulnerability

“System Alert:Virus Chin09.Win”
Posted in Information and Removal on 2 March 2010

“System Alert:Virus Chin09.Win” is a new annoying notification that has been created by hackers who expect their victims to become scared and additionally purchase Dr. Guard for getting rid of this announced “virus”. In fact, this notification tells the truth but the virus is another. As you may have read, Dr.Guard is a rogue anti-spyware, [...]

Adware:W32/Yabelink
Posted in F-Secure on 2 March 2010

This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.

Botnet Rises in the Name of Chuck Norris
Posted in Information and Removal on 2 March 2010

Just when you think old-school network bots are dead, a group of cybercriminals revives them from them grave in the name of Chuck Norris. Dubbed the “Chuck Norris botnet,” based on the Italian comment in its source code, in nome di Chuck Norris (translation: “in the name of Chuck Norris”), this botnet infects vulnerable DSL [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Botnet Rises in the Name of Chuck Norris

ZeuS and PDF Exploits: Two Baddies Team Up
Posted in Information and Removal on 2 March 2010

Trend Micro recently came across a .PDF file sample that exploits a vulnerability that was discovered as early as mid-2009. The specially crafted .PDF file detected as TROJ_PIDIEF.SML contains malicious JavaScript in its code that uses the getAnnots() method to corrupt an affected system’s memory.

It is interesting to note that its final payload is [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

ZeuS and PDF Exploits: Two Baddies Team Up

Spam Quarantine Notification = Spam
Posted in Information and Removal on 2 March 2010

Spammers are clearly becoming more and more creative as they try new ways to bypass our anti-spam filters. Just recently, we received a spammed message disguised as a spam quarantine notification message from a competitor.

To the untrained eye, the email looks quite convincing. However, closer inspection of the message properties reveals that while the email [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Spam Quarantine Notification = Spam

Spammers Target Antivirus Companies
Posted in Information and Removal on 2 March 2010

A new wave of spammed messages posing as mail service notifications targeted antivirus companies, including Trend Micro. These messages ask the receivers to update their mailbox settings by opening and executing the attachment.

The two samples above TrendLabs obtained were sent to domains that belonged to Trend Micro. The file attachment does not contain any mailbox [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Spammers Target Antivirus Companies