Articles Archive for 5 March 2010

Av-guru.net
Posted in Information and Removal on 5 March 2010

Having Av-guru.net browser hijacker on your computer means that you will find yourself constantly redirected to the malicious domain that distributes Antivirus Soft rogueware. Getting infected by this hijacker may pass through your attention because Av-guru.net uses affiliated trojans to install everything unnoticeably. Once in a new computer, Av-guru.net makes useful configurations to the browser [...]

Pc-winlive.com
Posted in Information and Removal on 5 March 2010

PC users should remember that they must avoid Pc-winlive.com domain because it’s yet another instrument to distribute Windows Defender 2010 malware. To achieve fraudulent commercial goals, Pc-winlive.com simulates scanning computers for malware infections and offers purchasing Windows Defender 2010 “licensed” software at the end of the whole game. It also hijacks infected PCs browser and [...]

Win32/Bancdido
Posted in CA Security Advisor on 5 March 2010

 

On the Road to 7.0: File and Registry Activity
Posted in Information and Removal on 5 March 2010

Once you pop into the old good Host Protection, now renamed Proactive Protection for what it really is, you’ll see a tab neighboring to also familiar Process activity. That will be another monitor of what’s going on in your system - File and Registry Activity Monitor. In other words one can choose a process displayed in Process activity and see what sort of operations it triggers.

An invaluable aid for advanced users, the monitor provides a big picture of (as you may have guessed) current file and registry activity. The user can analyze every active process, its path and time as well as track registry modifications in order to take action with Outpost’s ample functionality.

In Process Activity one may right-click on a process and choose to terminate, quarantine or – monitor activity for it – that’s when the new feature jumps in. The Monitor provides nifty filtering options so that you can exclude or include running processes and concentrate on what’s precisely of interest at the moment.

Besides, using Start/Stop monitor buttons you may opt to take a snapshot of the monitor’s records for deeper analysis.


The concept of such tool traces back to Mark Russinovich with his Filemon and Regmon utilities, afterwards replaced with Process Monitor, now part of Microsoft’s product offering. Although Outpost’s File and Registry Activity Monitor was based on a similar principle, the specifics in our case is that the module is part of a comprehensive security solution and, backed with other log and protection tools, it provides a deeper insight.

You’ll soon be able to judge for yourself as the public beta of Outpost 7 is a stone’s throw away from now.

Stay tuned!

Pavel Goryakin, Agnitum

Mariposa Botnet Perpetrators Captured
Posted in Information and Removal on 5 March 2010

Following the shutdown of the Mariposa botnet recently, three alleged members of the group behind the said botnet were finally arrested last week by the Spanish Police, although they are still pursuing another suspect that may still be at large somewhere in South America.
The Mariposa botnet was one of the largest botnets to date. It [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Mariposa Botnet Perpetrators Captured

open letter to the metasploit community
Posted in Information and Removal on 5 March 2010

dear metasploit community,first, please direct your attention to the following video as it demonstrates the very thing i’d like to speak to you about:as members of the metasploit community, you are no doubt aware of the various legitimate uses for meta…

Adware:W32/Popmenu
Posted in F-Secure on 5 March 2010

This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.

Application:W32/WinVNC
Posted in F-Secure on 5 March 2010

A legitimate application that may introduce additional security risks or be used for malicious purposes.

Adware:W32/Doubled.gen!C
Posted in F-Secure on 5 March 2010

This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.

Rootkit:W32/Xanti.gen!A
Posted in F-Secure on 5 March 2010

A program or set of programs which hides itself by subverting or evading the computer’s security mechanisms, then allows remote users to secretly control the computer’s operating system.