Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
>
December, 2008
December, 2008
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
May 2013
(10)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
Just in time for New Year's....
Posted
over 5 years ago
by
mmpc2
Hello again from Melbourne! We've seen another resurgence of Worm:Win32/Conficker , this time as Worm:Win32/Conficker.B . We've already received a number of reports of this new variant from the wild from affected users. Not surprisingly, a majority of the new infections we’re seeing are on machines that are yet to install the MS08-067 update (see our previous posts ' More MS08-067 Exploits ' and ' A Quick Update About MS08-067 Exploits '). This new variant also spreads via network shares by...
Microsoft Malware Protection Center
Namaskar from New Delhi - AVAR 2008
Posted
over 5 years ago
by
mmpc2
Recently I returned from the Association of anti-Virus Asia Researchers Conference (known as AVAR 2008 ) in New Delhi, India. Microsoft was a Gold Sponsor of the conference, at which there were a number of interesting presentations. This was also a great opportunity to meet other researchers in the anti-malware industry. Subratam from MMPC Redmond also attended. As I’d not visited India before, I took some annual leave before the conference so I could visit more of the surrounding area....
Microsoft Malware Protection Center
Now I've Seen It All (Maybe)
Posted
over 5 years ago
by
mmpc2
I've been coding anti-virus routines for 1, 2, 5... 10, 15, 20... a really long time. Starting with the Apple II, before there was even an anti-virus industry, and continuing on the PC (and funnily enough, joining the industry wasn't the obvious choice for me when I left school). In between times, I've analysed viruses for the Commodore 64, Amiga, Macintosh, and Itanium platforms, macros, scripts, things on phones, things on devices... even things on calculators! My website is full of descriptions...
Microsoft Malware Protection Center
MSRT Review - Win32/FakeXPA and Win32/Yektel Rogues
Posted
over 5 years ago
by
mmpc2
As mentioned previously on this blog, we added two “rogue” families to MSRT this month: Win32/FakeXPA and Win32/Yektel . We’ve known that rogues in general have been growing in prevalence for some time and with two months of MSRT data (last month we added a family of rogues called Win32/FakeSecSen ) we’re seeing that confirmed. In analysing the data, however, we have also found some surprises. Here are the numbers: Threat Family Distinct machines cleaned Win32/FakeXPA...
Microsoft Malware Protection Center
The new IE exploits for Advisory 961051, Now Hosted on Pornography Sites
Posted
over 5 years ago
by
mmpc2
Two days ago, we blogged about attacks that involve exploits of the recently discovered vulnerability in Internet Explorer. We would like to give you a quick update about these attacks. Based on our stats, since the vulnerability has gone public, roughly 0.2% of users worldwide may have been exposed to websites containing exploits of this latest vulnerability. That percentage may seem low, however it still means that a significant number of users have been affected. The trend for now is going...
Microsoft Malware Protection Center
Limited Exploitation of Microsoft Security Advisory 961051
Posted
over 5 years ago
by
mmpc2
The MSRC released a security advisory yesterday about a vulnerability in Internet Explorer. Just like our colleagues at the MSRC , we're tracking the situation very closely as we've observed the vulnerability exploited in the wild, however within a relatively limited context. Virtually all the malicious sites we've seen taking advantage of the vulnerability thus far are hosted on a variety of Chinese domains. According to the investigation thus far, the vulnerability affects Windows Internet Explorer...
Microsoft Malware Protection Center
Win32/Yektel - the Other Kind of Rogue
Posted
over 5 years ago
by
mmpc2
In addition to Win32/FakeXPA we added another rogue-related malware family to MSRT this month - Win32/Yektel . Win32/Yektel is a different kind of rogue. Like other rogues, it displays fake warnings about possibly malware or spyware, but rather than pretending to be a security product itself, it tries to blend in with its surroundings. There is a very good reason to target Win32/Yektel and Win32/FakeXPA together: most of the current incarnations of FakeXPA download Yektel. Nevertheless, Yektel works...
Microsoft Malware Protection Center
FakeXPA... Journey of a Rogue
Posted
over 5 years ago
by
mmpc2
Rogue security products have been around for some years, and now they seem to be everywhere. In my previous blog about Trojan:Win32/Antivirusxp I talked about the relationships between rogue products and various other threats. One common behavior of rogue products is their ever-changing domain names and user interfaces. Most rogue products emerge and then disappear into thin air. However, a few persist and remain the "big fish" to catch. This month's addition to MSRT, Trojan:Win32/FakeXPA , is...
Microsoft Malware Protection Center
O Come All Ye Malware
Posted
over 5 years ago
by
mmpc2
Well, after our last post, it certainly didn't take long to see some examples of festive malware from the wild. (You'd almost think that we've seen this kind of behavior before - again and again and again...) In the last couple of days, we (and other AV vendors) have observed the arrival of several new 'merry' malware on the scene. First, we have Worm:Win32/Prolaco.A@mm - this is a worm that spreads via e-mail and peer-to-peer file sharing networks. It also appears to be able to spread via removable...
Microsoft Malware Protection Center
Merry Malware - You’d better watch out, you’d better think twice…
Posted
over 5 years ago
by
mmpc2
With visions of sugarplums dancing through my head constantly from around September onwards, I eagerly (and somewhat obsessively) await the festive season every year. As heralded by my son opening the first box on his advent calendar this morning to liberate the toy hidden within, as far as I am concerned, Christmas is (finally!) upon us. It feels like it gets earlier every year, and this year is no exception – especially as far as the malware authors are concerned. There are several reports that...
Page 1 of 1 (10 items)