Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
>
October, 2008
October, 2008
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
May 2013
(10)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
Rogue Antivirus - A Closer Look at Win32/Antivirusxp
Posted
over 5 years ago
by
mmpc2
2
Comments
Fake (or rogue) security applications have been a cause of confusion and problems for users for some years. These applications generally display fake warnings and malware detections in order to entice users to buy the application and thus ‘disinfect’ their system. Over time, the mechanisms used to avoid detection and distribute these applications have become more complex - code obfuscation is now common, and botnets are utilized for widespread distribution. Win32/Antivirusxp is one of these rogues...
Microsoft Malware Protection Center
The Cost of Free $oftware
Posted
over 5 years ago
by
mmpc2
1
Comments
Today we stumbled upon an interesting file. The file in question, " wrar380CorporateEdition.exe " (md5: f054f5a1bcb79098916c80b28e4f2bec), appears to be the install kit for the WinRar archiver. Upon closer inspection, it is actually a self-extract cab installer containing 2 files: "wrar380.Regged.exe" "Setup_ver1.1808.0.exe" When the installer is run, both files execute. While the file "wrar380.Regged.exe" is actually WinRAR, the other file is actually... malware. A closer look at "Setup_ver1...
Microsoft Malware Protection Center
Malware Writer Wants an Eye-to-Eye With Us
Posted
over 5 years ago
by
mmpc2
1
Comments
Zlob has been around for quite some time now and it is still evolving rapidly. If we thought of Zlob as a car, it has gone through the equivalent of several overhaulings... Zlob constantly changes its decryption, obfuscation, and structure. As is our everyday routine, we were looking at several new variants of Zlob this morning and found this interesting message inside one of them: "I want to see your eyes the man from Windows Defender's team" It's the first time we've seen the Zlob writers include...
Microsoft Malware Protection Center
Email Scam Targets Microsoft Customers
Posted
over 5 years ago
by
mmpc2
1
Comments
Email scams are a common way to spread malware and/or steal personal information. Some great guidelines to help you protect yourself from such scams are outlined here: http://www.microsoft.com/protect/computer/viruses/email.mspx We have recently found out about the latest in an ongoing string of email scams that target Microsoft customers. This particular scam contains the Backdoor:Win32/Haxdoor trojan as an attachment. We have seen a few emails targeting Microsoft customers that look like the...
Microsoft Malware Protection Center
SQL Injection - New Approach for Win32/FakeXPA?
Posted
over 5 years ago
by
mmpc2
(often known as "Antivirus 2009"). One night while browsing, a message box popped up asking me to do a "security scan". As a researcher, I wouldn't let this pass me by. After going through my opened tabs I narrowed down the culprit to a forum I had open at the time. "View Source" showed a 1x1 pixel IFRAME pointing to hxxp://***.info/users/***/1.php The position of this IFRAME is a little strange. It appears several times on the page, and each time right after the title of the forum. It appeared...
Microsoft Malware Protection Center
Uprooting Win32/Rustock
Posted
over 5 years ago
by
mmpc2
This month we added a family of rootkit-enabled trojans to MSRT - Win32/Rustock Win32/Rustock is a multi-component family of rootkit-enabled backdoor trojans, which were historically developed to aid in the distribution of 'spam' e-mail. First discovered sometime in early 2006, Rustock has evolved to become a prevalent and pervasive threat. Recently we've seen it associated with the incidence of rogue security programs. This might indicate that the Rustock family of trojans has gained some traction...
Microsoft Malware Protection Center
Trojan Writers Drive BMW
Posted
over 5 years ago
by
mmpc2
Why is malware that targets online games so prevalent these days? Why is there an interesting saying in China: "Trojan writers drive BMW" ("写木马, 开宝马")? The writers and distributors of trojans that steal passwords and account details from popular online games have been making huge profits. Why and how can they make huge profits from writing and distributing trojans that target online games? My paper " Playing with shadows - exposing the black market for online game password theft " presented...
Microsoft Malware Protection Center
SWF for Malware Deployment
Posted
over 5 years ago
by
mmpc2
More and more each day I see SWF files being sent to us as a potential part of a malware deployment chain. Most of the times it is not the case, but because of these special cases where the submitter was actually right, I decided to write this entry. I’ve been spending part of today tracking down some SWF files that are part of “the dark side”. What I found out is that, excluding flash exploits, SWFs are mainly used as redirectors: Most common case, directly linking to the target webpage...
Microsoft Malware Protection Center
Get Protected, Now!
Posted
over 5 years ago
by
mmpc2
Microsoft released a security update today that fixes a vulnerability that affects all supported versions of Windows. On some versions of Windows, an unauthenticated attacker can remotely execute code on a vulnerable computer. Basically if file sharing is enabled and the security update is not installed yet, the computer is vulnerable. File sharing is enabled in several scenarios though it is disabled by default in XP SP2 and newer operating systems. See the " Security Vulnerability Research &...
Microsoft Malware Protection Center
Win32/Rustock Hide and Seek – MSRT Telemetry
Posted
over 5 years ago
by
mmpc2
In his 10/18 blog post , Oleg provided great insights about the distribution, installation and payload of Win32/Rustock which was added to MSRT 10/14 release. As of 10/29 MSRT has removed this rootkit from 99,418 distinct machines. Breakdown of these removals by regions is shown as below. Country/Region distinct machined cleaned United States 41,305 France 6,295 Spain 5,987 Italy 5,033 United Kingdom ...
Page 1 of 2 (12 items)
1
2