Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
May 2013
(9)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
MSRT January 2013 - Ganelp
Posted
4 months ago
by
msft-mmpc
To start the new year, we have added the Win32/Ganelp and Win32/Lefgroo families of worms to the January release of the Malicious Software Removal Tool . Win32/Ganelp spreads via removable drives, uploads stolen information and downloads arbitrary files from remote FTP servers. We have had detection signatures for this family for approximately 2 years and it continues to be prevalent, as seen in Figure 1. Figure 1: Ganelp monthly report volume January 2011 to December 2012. What we...
Microsoft Malware Protection Center
Customer-focused prioritization
Posted
4 months ago
by
msft-mmpc
Our guiding vision at the Microsoft Malware Protection Center (MMPC) is to keep every customer safe from malware. Both our research team and automated systems work around the clock in an effort to achieve this vision. The volume of threats that attackers are developing continues to increase. For example, last month we collected and analyzed 20 million new potential malware files. Six percent of these files were classified as malware. From that six percent, just over 100,000 files resulted in the...
Microsoft Malware Protection Center
Fake apps: Behind the effective social strategy of fraudulent paid-archives
Posted
4 months ago
by
msft-mmpc
In my previous blog " Fake apps and the lure of alternative sources ," I discussed a fraudulent scheme that takes advantage of known, legitimate and free applications. Unlike rogues and ransomware which use threats and force to influence their victims, the social engineering techniques employed by a fake installer are less aggressive yet, interestingly, more deceptive. This technique is widely used in the Win32/Pameseg family – our detection for a family of "paid archives" that present as...
Microsoft Malware Protection Center
Update signature definitions to resolve performance issues in definitions starting with 1.141.2400.0
Posted
4 months ago
by
msft-mmpc
Some users of Microsoft antimalware products have reported a performance issue with signature definition versions starting with 1.141.2400.0 (12/21/2012 1920 UTC). The current definition files, since 1.141.2639.0 (12/27/2012 0625 UTC), resolve this issue. If you have a signature set in the affected range, please update to the current definition files . Shannon Sabens MMPC
Microsoft Malware Protection Center
Korean gaming malware - served 3 ways
Posted
4 months ago
by
msft-mmpc
Recently, we’ve seen similar activities being performed by different malware that monitor online Korean applications. Mostly, the applications they monitor are card games, such as those in Figure 1. Figure 1: Examples of online Korean games that are being monitored. (Source: http://www.hangame.com ) The following applications are monitored if found running on the system: LASPOKER.EXE h ighlow2.exe baduki.exe duelpoker.exe HOOLA3.exe poker7.exe FRN.exe ...
Microsoft Malware Protection Center
MSRT December '12 - Phdet
Posted
5 months ago
by
msft-mmpc
Phdet is the family which has been added to the December 2012 release of the Malicious Software Removal Tool . Phdet is a family of backdoor trojans that have the ability to perform distributed denial of service (DDoS) attacks. The bot can be found online, going by the formal name of "Black Energy". The DDoS bot has existed for a number of years, with initial detections added in 2007. An attacker can build and configure binaries to perform different actions, and can specify the frequency...
Microsoft Malware Protection Center
The "hidden" backdoor - VirTool:WinNT/Exforel.A
Posted
5 months ago
by
msft-mmpc
Recently we discovered an advanced backdoor sample - VirTool:WinNT/Exforel.A . Unlike traditional backdoor samples, this backdoor is implemented at the NDIS (Network Driver Interface Specification) level. VirTool:WinNT/Exforel.A implements a simple private TCP/IP stack and hooks NDIS_OPEN_BLOCK for the TCP/IP protocol, as shown in Figure 1. Figure 1: Hooked functions in NDIS_OPEN_BLOCK This means that backdoor-related TCP traffic will be diverted to the private TCP/IP stack and delivered...
Microsoft Malware Protection Center
Unexpected reboot: Necurs
Posted
5 months ago
by
msft-mmpc
Necurs is a prevalent threat in the wild at the moment - variants of Necurs were reported on 83,427 unique machines during the month of November 2012. Necurs is mostly distributed by drive-by download. This means that you might be silently infected by Necurs when you visit websites that have been compromised by exploit kits such as Blackhole . So what does Necurs actually do? At a high level, it enables further compromise by providing the functionality to: Download additional malware...
Microsoft Malware Protection Center
MSRT November '12 - Weelsof around the world
Posted
5 months ago
by
msft-mmpc
Win32/Weelsof is part of a large malware family called ransomware, which is different from your traditional trojans and worms. Ransomware’s main goal is to financially benefit from every infected user and force them to pay. We included Win32/Weelsof in our November release of the Malicious Software Removal Tool . Malware entry point The user can be infected by this malware by visiting a compromised or malicious website. The website may have been compromised by exploits or injected...
Microsoft Malware Protection Center
Another way Microsoft is disrupting the malware ecosystem
Posted
5 months ago
by
msft-mmpc
Like it or not, in today’s world, online advertising plays a large and important role in supporting the web. Pay-per-click (PPC) advertising, born in 1998, created a system whereby advertisers only pay when potential customers click on an advertisement's link. This system allowed companies to target very specific market segments, better gauge sales campaign performance and to only pay for what was clicked. This helped drive demand for publishers. Publishers are those people with websites or...
Page 4 of 44 (439 items)
«
2
3
4
5
6
»