Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
>
July, 2010
July, 2010
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
May 2013
(8)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
The Stuxnet Sting
Posted
over 3 years ago
by
mmpc2
For the past week or so, we've been closely tracking a new family of threats called Stuxnet (a name derived from some of the filename/strings in the malware - mrxcls.sys, mrxnet.sys). In the past few days, it has become a popular topic of discussion amongst security researchers and in the media. First and foremost, we have recently released one additional signature for this threat, and urge our readers to be sure that you've got the latest anti-malware definition updates installed. Prevalence...
Microsoft Malware Protection Center
Stuxnet, malicious .LNKs, ...and then there was Sality
Posted
over 3 years ago
by
mmpc2
Today, Microsoft announced plans to release of an out-of-band update to address CVE-2010-2568 (described in Microsoft Knowledge Base Article (2286198) ). As mentioned earlier this month, the Microsoft Malware Protection Center (MMPC), along with other Microsoft Active Protection Program partners, have been keeping a close watch on the use of .LNK files exploiting this vulnerability. As with many new attack techniques, copycat attackers can act quickly to integrate new techniques. Although...
Microsoft Malware Protection Center
Update on the Windows Help and Support Center Vulnerability (CVE-2010-1885)
Posted
over 3 years ago
by
mmpc2
Just a quick post here to provide an update on the attack attempts related to the Help and Support Center vulnerability and to stress the importance of applying the critical update made available today, MS10-042 , which fixes the issue for the two vulnerable operating systems, Windows XP and Windows 2003. A few weeks ago, MMPC reported seeing automated attacks that were identified by the signatures we had deployed in our protection products. These attack attempts have continued to expand and some...
Microsoft Malware Protection Center
How the bad guys use Search Engine Optimization (SEO)
Posted
over 3 years ago
by
mmpc2
Often you read about how, during major news events, the bad guys have commandeered the search engines so if you go looking for more information about the news event, you end up at a page that’s serving you some malware nowadays -- usually some kind of fake antivirus program. But how did the bad guys fake out the search engines to get their sites so high in search to get people to click on them? Let me explain, using a spamming shoe seller as an example of the technique. First, I have...
Microsoft Malware Protection Center
Protection for New Malware Families Using .LNK Vulnerability
Posted
over 3 years ago
by
mmpc2
We’ve added detection for two new malware families using the vulnerability described in SA2286198 . The first, Win32/Vobfus, is actually a family of obfuscated worms that has been around since 2009. According to our fellow researcher Marian Radu, who named the family, the name was derived from the fact that the worm is coded in Visual Basic (VB) and is highly obfuscated: V (isual Basic) + obfus cated = Vobfus We need to emphasize, however, that the first Vobfus samples that we’ve...
Microsoft Malware Protection Center
Bubnix Uses Interesting Obfuscation Scheme
Posted
over 3 years ago
by
mmpc2
This month, we added the Bubnix family to the latest Malicious Software Removal Tool (MSRT) release. WinNT/Bubnix is a complicated spam bot which arrives on an affected computer by way of a downloader, TrojanDownloader:Win32/Bubnix.A . TrojanDownloader:Win32/Bubnix.A is itself often downloaded by variants of Win32/Bredolab and Win32/Harnig in the wild. Generally speaking, it is common for a malicious executable to be transferred in encrypted form by a downloader. In order to increase the apparent...
Microsoft Malware Protection Center
Keeping Kerrigan from Infection
Posted
over 3 years ago
by
mmpc2
"Adun Toridas!" Starcraft fans would recognize that as a famous line from the first Starcraft version, which was released in 1998. Starcraft is a real-time strategy game that became a massive hit worldwide. The release date for its sequel, Starcraft II: Wings of Liberty, is today, the 27th of July. Players can install the game but can only activate their licenses from this day onwards. Surely most gamers out there (including us) are eager to get their hands on this new title, especially if you were...
Page 1 of 1 (7 items)