tag:blogger.com,1999:blog-79196662009-02-20T22:09:14.614-08:00Fermats Security AlertsYou get 'em when I get 'emFermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comBlogger75125tag:blogger.com,1999:blog-7919666.post-1119458244001100542005-06-22T09:37:00.000-07:002005-06-22T09:38:31.220-07:00Spyware Danger Meets Rootkit StealthCool Web Search spyware has gotten nastier and harder to remove. A new variant is using rootkit-like methods to hide from removal attempts.<br /><br />Read more on how the Cool Web Search <a href="http://www.eweek.com/article2/0,1759,1829744,00.asp">Spyware Danger Meets Rootkit Stealth</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111945824400110054?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1119055820289486582005-06-17T17:50:00.000-07:002005-06-17T18:05:46.153-07:00Spyware Floods In Through BitTorrentThe new darling of file trading formats, BitTorrent, is now a distribution point for spyware/adware.<br /><br />The article states that Direct Revenue and Marketing Metrix Group are responsible for the infected files. Check your HiJack This logs for "nail.exe" , "aurora.exe". They will be listed alongside "btdownloadgui.exe".<br /><br />Marketers that use adware/malware like this should be considered lower than lawyers and used car salesman. If you're one of these scumbags please, please, do the world a favor by going home and killing yourself. <br /><br />These are full details on how <a href="http://www.eweek.com/article2/0,1759,1828633,00.asp">Spyware Floods In Through BitTorrent</a><br /><br />Download <a href="http://www.spywareinfo.com/downloads.php?cat=sp#det" target="_blank">HiJack This</a> and others at this Spywareinfo page.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111905582028948658?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1118276480403732622005-06-08T17:21:00.000-07:002005-06-08T17:21:20.446-07:00New Triple virus wears down computer defencesA three way tag team of baddies is out there waiting to turn personal computers into zombies
<br />
<br />Here's where to read more about how the <a href="http://www.newscientist.com/article.ns?id=dn7474&feedId=online-news_atom03">New Triple virus wears down computer defences</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111827648040373262?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1118191221687892362005-06-07T17:40:00.000-07:002005-06-07T17:42:22.273-07:00Spoofing Risk Returns to Mozilla BrowsersWatch surfing trusted sites and strange sites at the same time is the word from Secunia, a Denmark-based security company. New versions of Mozilla browsers have just now been found to have a frame-injection vulnerability.<br /><br />Never fear though, the Mozilla foundation is already looking into it. And take notice, they didn't have anyone arrested or sued for pointing out a vulnerability.<br /><br />Read about how the <a href="http://www.eweek.com/article2/0,1759,1824838,00.asp">Spoofing Risk Returns to Mozilla Browsers</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111819122168789236?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1117829909506235362005-06-03T13:18:00.000-07:002005-06-03T13:18:29.506-07:00WORM_BOBAX.P - Description and solutionAs of June 3, 2005, 1:38 AM PDT (Pacific Daylight Time/GMT -7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_BOBAX.P. TrendLabs has received several infection reports indicating that this malware is spreading in Australia, India, Ireland, Japan, Peru, Singapore, and the United States.
<br />
<br />This memory-resident worm usually arrives on a system as a downloaded file of TROJ_SMALL.AHE. It spreads by sending a copy of TROJ_SMALL.AHE as an attachment to an email message that it sends using its own Simple Mail Transfer Protocol (SMTP) engine.
<br />
<br />The message it sends out contains the following details:
<br />
<br />Subject: {blank}
<br />
<br />Message body: (any of the following)
<br />
<br />• Attached some pics that i found
<br />• Check this out :-)
<br />• Hello,
<br />• I was going through my album, and look what I found..
<br />• Long time! Check this out!
<br />• Osama Bin Laden Captured.
<br />• Remember this?
<br />• Saddam Hussein - Attempted Escape, Shot dead
<br />• Secret!
<br />• Testing
<br />
<br />(followed by any of the following strings)
<br />
<br />• +++ Attachment: No Virus found
<br />• +++ F-Secure AntiVirus - You are protected
<br />• +++ Norman AntiVirus - You are protected
<br />• +++ Norton AntiVirus - You are protected
<br />• +++ Panda AntiVirus - You are protected
<br />• +++ www.f-secure.com
<br />• +++ www.norman.com
<br />• +++ www.pandasoftware.com
<br />• +++ www.symantec.com
<br />
<br />Attachment: (any of the following names followed by a .ZIP extension)
<br />
<br />• bush.1
<br />• funny.1
<br />• joke.1
<br />• pics.1
<br />• secret.2
<br />
<br />When an unsuspecting user executes the Trojan attachment, TROJ_SMALL.AHE downloads WORM_BOBAX.P, and the vicious worm-Trojan cycle continues.
<br />
<br />It also propagates by taking advantage of the Windows LSASS vulnerability. Furthermore, it is capable of modifying the system's HOSTS file in order to prevent users from accessing certain Web sites.As of June 3, 2005, 1:38 AM PDT (Pacific Daylight Time/GMT -7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_BOBAX.P. TrendLabs has received several infection reports indicating that this malware is spreading in Australia, India, Ireland, Japan, Peru, Singapore, and the United States.
<br />
<br />This memory-resident worm usually arrives on a system as a downloaded file of TROJ_SMALL.AHE. It spreads by sending a copy of TROJ_SMALL.AHE as an attachment to an email message that it sends using its own Simple Mail Transfer Protocol (SMTP) engine.
<br />
<br />The message it sends out contains the following details:
<br />
<br />Subject: {blank}
<br />
<br />Message body: (any of the following)
<br />
<br />• Attached some pics that i found
<br />• Check this out :-)
<br />• Hello,
<br />• I was going through my album, and look what I found..
<br />• Long time! Check this out!
<br />• Osama Bin Laden Captured.
<br />• Remember this?
<br />• Saddam Hussein - Attempted Escape, Shot dead
<br />• Secret!
<br />• Testing
<br />
<br />(followed by any of the following strings)
<br />
<br />• +++ Attachment: No Virus found
<br />• +++ F-Secure AntiVirus - You are protected
<br />• +++ Norman AntiVirus - You are protected
<br />• +++ Norton AntiVirus - You are protected
<br />• +++ Panda AntiVirus - You are protected
<br />• +++ www.f-secure.com
<br />• +++ www.norman.com
<br />• +++ www.pandasoftware.com
<br />• +++ www.symantec.com
<br />
<br />Attachment: (any of the following names followed by a .ZIP extension)
<br />
<br />• bush.1
<br />• funny.1
<br />• joke.1
<br />• pics.1
<br />• secret.2
<br />
<br />When an unsuspecting user executes the Trojan attachment, TROJ_SMALL.AHE downloads WORM_BOBAX.P, and the vicious worm-Trojan cycle continues.
<br />
<br />It also propagates by taking advantage of the Windows LSASS vulnerability. Furthermore, it is capable of modifying the system's HOSTS file in order to prevent users from accessing certain Web sites.
<br />
<br />Get the complete picture on <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BOBAX.P">WORM_BOBAX.P - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111782990950623536?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1117829732194941342005-06-03T13:15:00.000-07:002005-06-03T13:15:32.196-07:00WORM_MYTOB.BI - Description and solutionAs of May 31, 2005 9:11 AM PDT (Pacific Daylight Time), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_MYTOB.BI. TrendLabs has received several infection reports indicating that this malware is spreading in Belgium, Japan, Korea, India, United States, United Kingdom, and Germany.
<br />
<br />Similar to other MYTOB variants, this memory-resident worm propagates by sending a copy of itself as an attachment (file size is around 29,868 to 29,882 bytes) to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine. Upon execution, it drops a copy of itself using the file name LIEN VAN DE KELDERRR.EXE in the Windows system folder.
<br />
<br />The email message it sends has the following details:
<br />
<br />Subject: (any of the following)
<br />
<br />- {Random}
<br />- *DETECTED* Online User Violation
<br />- *IMPORTANT* Please Validate Your Email Account
<br />- *IMPORTANT* Your Account Has Been Locked
<br />- *WARNING* Your Email Account Will Be Closed
<br />- Account Alert
<br />- Email Account Suspension
<br />- Important Notification
<br />- Notice of account limitation
<br />- Notice: **Last Warning**
<br />- Notice:***Your email account will be suspended***
<br />- Security measures
<br />- Your email account access is restricted
<br />- Your Email Account is Suspended For Security Reasons
<br />
<br />Message body: (any of the following)
<br />
<br />- Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
<br />- please look at attached document.
<br />- Please read the attached document and follow it's instructions.
<br />- Please see the attachement.
<br />- The original message has been included as an attachment.
<br />- To safeguard your email account from possible termination, please see the attached file.
<br />- To unblock your email account acces, please see the attachement.
<br />- We attached some important information regarding your account.
<br />- We have suspended some of your email services, to resolve the problem you should read the attached document.
<br />- We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached.
<br />
<br />Attachment: (any combination of the following file names and extensions)
<br />
<br />File name:
<br />- {random}
<br />- account-details
<br />- document
<br />- document_full
<br />- email-doc
<br />- email-info
<br />- info
<br />- information
<br />- info-text
<br />- instructions
<br />- your_details
<br />
<br />Extension:
<br />- BAT
<br />- CMD
<br />- EXE
<br />- PIF
<br />- SCR
<br />- ZIP
<br />
<br />It gathers target email addresses from the Temporary Internet Files folder, Windows address book (WAB), as well as from files with certain extension names. It may also generate email addresses by using a list of names and any of the domain names of the previously gathered addresses.
<br />
<br />This worm also takes advantage of the LSASS vulnerability to propagate. For more information about the said vulnerability, please refer to the following Microsoft Web page:
<br />
<br />http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
<br />
<br />It opens a random port, allowing a remote user to access and perform malicious commands on affected machines. The said routine provides the remote user virtual control over affected systems, thus compromising system security.
<br />
<br />Moreover, it prevents affected users from accessing several antivirus and security Web sites by redirecting the connection to the local machine. It also terminates several processes.
<br />
<br />This worm also downloads a file, which Trend Micro detects as TSPY_AGENT.H. The downloaded file then drops an adware that Trend Micro detects as ADW_MEDTICKS.A.
<br />
<br />It affects Windows 98, ME, NT, 2000, and XP.
<br />
<br />Get all the details at <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.BI">WORM_MYTOB.BI - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111782973219494134?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1117829602822667882005-06-03T13:13:00.000-07:002005-06-03T13:13:22.870-07:00WORM_MYTOB.AR - Description and solutionAs of May 30, 2005 3:12 AM YEAR TIME PST (PDT/GMT -7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_MYTOB.AR. TrendLabs has received several infection reports indicating that this malware is spreading in Australia, China, Hongkong, India, Japan, Korea, Philippines, Taiwan, United States.
<br />
<br />The following is a brief summary of what this worm is capable of doing:
<br />
<br />This memory-resident worm propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.
<br />
<br />This email message has the following details:
<br />
<br />Subject: (any of the following)
<br />• {Random}
<br />• *DETECTED* Online User Violation
<br />• *IMPORTANT* Please Validate Your Email Account
<br />• *IMPORTANT* Your Account Has Been Locked
<br />• *WARNING* Your Email Account Will Be Closed
<br />• Account Alert
<br />• Email Account Suspension
<br />• Important Notification
<br />• Notice of account limitation
<br />• Notice: **Last Warning**
<br />• Notice:***Your email account will be suspended***
<br />• Security measures
<br />• Your email account access is restricted
<br />• Your Email Account is Suspended For Security Reasons
<br />
<br />Message body: (any of the following)
<br />• Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
<br />• please look at attached document.
<br />• Please read the attached document and follow it's instructions.
<br />• Please see the attachement.
<br />• The original message has been included as an attachment.
<br />• To safeguard your email account from possible termination, please see the attached file.
<br />• To unblock your email account acces, please see the attachement.
<br />• We attached some important information regarding your account.
<br />• We have suspended some of your email services, to resolve the problem you should read the attached document.
<br />• We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached.
<br />
<br />Attachment: (any combination of the following file names and extension names)
<br />
<br />File name:
<br />
<br />• {random}
<br />• account-details
<br />• document
<br />• document_full
<br />• email-doc
<br />• email-info
<br />• information
<br />• info
<br />• info-text
<br />• instructions
<br />• your_details
<br />
<br />Extension name:
<br />
<br />• EXE
<br />• PIF
<br />• SCR
<br />• ZIP
<br />
<br />This worm also takes advantage of the LSASS vulnerability to propagate.
<br />
<br />This worm also has backdoor capabilities. It comes with a built-in Internet Relay Chat (IRC) bot that allows it to connect to a specific IRC server. It then waits for commands from a remote user.
<br />
<br />It also terminates processes, some of which are related to antivirus and security programs.
<br />
<br />More Details on <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.AR">WORM_MYTOB.AR - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111782960282266788?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1117267099572917682005-05-28T00:58:00.000-07:002005-05-28T00:58:19.630-07:00Download Lavasofts Adaware SE 1.06 FreeLavasoft has a new version of Adaware out, SE version 1.06. Download it here <a href="http://www.lavasoftusa.com/support/download/#free">Download Lavasofts Adaware SE 1.06 Free</a>.
<br />
<br />Scroll down the page to the section titled "Adaware SE Personal" The only choice of download sites is C/Net's Download.com<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111726709957291768?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1116619243156763802005-05-20T13:00:00.000-07:002005-05-20T13:00:43.186-07:00Malicious Bots Hide Using Rootkit CodeGood article on rootkits at the link below. Windows XP/2K are vulnerable to these, whereas Win 9x is not. There are a couple of products for detecting and removing rootkits. One is Systernals freeware Rootkit Revealer. available at <a href="http://www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml" target="_blank">Rootkit Revealer</a>
<br />
<br />The other is F-Secures Blacklight. This is a timelimited beta product. It will stop functioning on July 1st 2005. After that I assume F-Secure will begin charging. Blacklight has to have .NET installed for its GUI. The beta is located here <a href="http://www.f-secure.com/blacklight/try.shtml" target="_blank">Blacklight</a>
<br />
<br /><a href="http://www.eweek.com/article2/0,1759,1816972,00.asp">Malicious Bots Hide Using Rootkit Code</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111661924315676380?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1116101930580146202005-05-14T13:18:00.000-07:002005-05-14T13:18:50.583-07:00Windows 2K Security Patch This patch fixes the "Greymagic" Bug In Windows 2000 Pro, Server and Advanced Server. This bug allows the preview pane, or Web view, in Windows Explorer to be targeted to launch malicious code on machines running Windows 2000 Professional, Windows 2000 Server and Windows 2000 Advanced Server.
<br />
<br />Microsoft said its Windows 98, Windows 98 SE (Second Edition) and Windows ME (Millennium Edition) operating systems were also affected, but because the bug isn't rated "critical," patches were not released.
<br />
<br />Microsoft where security comes first huh? You can download the patch for Win 2k at the link below.
<br />
<br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F-44FF-9B53-30277C196923&displaylang=en" target="_blank">Download details: Security Update for Windows 2000 (KB894320)</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111610193058014620?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1116100213512642982005-05-14T12:50:00.000-07:002005-05-14T12:56:28.573-07:00Firefox 1.0.4 UpdateThe update to fix the java exploit in Firefox is out. Go download it at the link below. As always after you download the install package go to control panel | add/remove then scroll down and select your current version of Mozilla Firefox and then click Remove to uninstall it.<br /><br />Now don't panic, your settings will remain in place. After the uninstall is done just install the new version of Firefox and open it up. Any themes, extensions, plugins, personal settings, homepages or whatever will be there ready to use. If you turned off java and javascript then click tools | options | web features and check both the boxes and you're good to go.<br /><br /><a href="http://www.mozilla.org/products/firefox/">Firefox 1.0.4 Update</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111610021351264298?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115869601557151442005-05-11T20:46:00.000-07:002005-05-11T20:46:41.626-07:00Zero-Day Firefox Exploit Sends Mozilla Scrambling Yes Virginia, it's true. There's a hole in Firefox. It's being fixed as we speak but for now make sure you have the latest update to Sun's Java. (Control Panel then click the Java icon and select update.)Then in an open Firefox browser window click tools | options | web features and uncheck Java and java script. This will give the maximum protection. Of course it will make browsing a real pain in the ass since every freaking web site on the net these days seems to have to java something or other. Personally I just turn it on when I really need it for some idiot page. I remember when using Javascript in your page code meant your page was a security risk.
<br />
<br /><a href="http://www.eweek.com/article2/0,1759,1814056,00.asp">Zero-Day Firefox Exploit Sends Mozilla Scrambling</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111586960155715144?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115868852422228082005-05-11T20:33:00.000-07:002005-05-11T20:34:54.486-07:00WORM_WURMARK.J - Description and solutionThe worms crawl in , the worms crawl out... Sheesh, here's another one that'll clutter up my inbox with crap. I really wish people would use protection on the internet. The infection rate is getting worse than a Asian whorehouse.<br /><br />As of May 11, 2005 4:30 AM (Pacific Daylight Time/GMT -8:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_WURMARK.J. TrendLabs has received several infection reports indicating that this malware is spreading in France, India, Taiwan, and Singapore.<br /><br />This memory-resident worm propagates via email messages. Upon execution, it drops a copy of itself in the Windows system folder using a random file name.<br /><br />It also drops a randomly named (Dynamic Link Library) DLL file in the Windows system folder, which is a component of < I >IESpy</u>, a spyware program. <br /><br />This worm has a keylogging capability. It saves the logs typed by the user in a dropped random DLL file. <br /><br />It drops several .ZIP files in the Windows system folder as email attachment.<br /><br />This worm propagates by sending a copy of itself via email. The email message contains the following details:<br /><br />Subject: (any of the following)<br />-details <br />-girls <br />-image <br />-love<br />-message<br />-music<br />-news <br />-photo <br />-pic <br />-readme<br />-resume <br />-screensaver<br />-song<br />-video <br /><br />Attachment: (any of the following file names)<br />-details.zip<br />-girls.zip <br />-image.zip <br />-love.zip<br />-message.zip<br />-music.zip<br />-news.zip <br />-photo.zip <br />-pic.zip <br />-readme.zip<br />-resume.zip <br />-screensaver.zip<br />-song.zip<br />-video.zip <br /><br />TrendLabs will be releasing the following EPS deliverables:<br /><br />TMCM Outbreak Prevention Policy - 174 (uploaded)<br />Official Pattern Release - 2.625.00<br />Damage Cleanup Template - 596<br /><br />For more information on WORM_WURMARK.J, you can visit our Web site at:<br />http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WURMARK.J<br /><br /><a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WURMARK.J">WORM_WURMARK.J - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111586885242222808?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115751512512767852005-05-10T11:58:00.000-07:002005-05-10T11:58:32.553-07:00WORM_MYTOB.EG - Description and solutionFast on the heels of MYTOB.ED comes the EG variant. Read up and watch what you open.
<br />
<br />Subject: (any of the following)
<br />- *IMPORTANT* Please Validate Your Email Account
<br />- *IMPORTANT* Your Account Has Been Locked
<br />- {random}
<br />- Email Account Suspension
<br />- Notice: **Last Warning**
<br />- Notice:***Your email account will be suspended***
<br />- Security measures
<br />- Your email account access is restricted
<br />- Your Email Account is Suspended For Security Reasons
<br />
<br />Message body: (any of the following)
<br />- Account Information Are Attached!
<br />- Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
<br />- please look at attached document.
<br />- To safeguard your email account from possible termination, please see the attached file.
<br />- To unblock your email account acces, please see the attachement.
<br />- We have suspended some of your email services, to resolve the problem you should read the attached document.
<br />- {random}
<br />
<br />Attachment: (any of the following file names)
<br />- {random}
<br />- document_full
<br />- email-doc
<br />- email-info
<br />- email-text
<br />- IMPORTANT
<br />- information
<br />- info-text
<br />- your_details
<br />
<br />(any of the following extensions)
<br />- BAT
<br />- CMD
<br />- EXE
<br />- PIF
<br />- SCR
<br />- ZIP
<br />
<br />It gathers target email addresses from the Temporary Internet Files folder, Windows address book (WAB), as well as from files with certain extension names. It may also generate email addresses by using a list of names and any of the domain names of the previously gathered addresses.
<br />
<br />This worm has backdoor capabilities, which allow a remote user to perform malicious commands on the affected machine. The said routine provides remote users virtual control over affected systems, thus compromising system security.
<br />
<br />Moreover, it prevents users from accessing several antivirus and security Web sites by redirecting the connection to the local machine.
<br />
<br /><a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.EG">WORM_MYTOB.EG - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111575151251276785?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115670647642603312005-05-09T13:30:00.000-07:002005-05-09T13:30:47.710-07:00WORM_MYTOB.ED - Description and solutionAnother day, another new worm. Read all about it folks, and as always, do your updates.
<br />
<br /><a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.ED">WORM_MYTOB.ED - Description and solution</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111567064764260331?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115147310084942192005-05-03T12:04:00.000-07:002005-05-03T12:12:58.173-07:00Trend Micro Alert - WORM_Sober.sI've been getting a lot of notifications from my ISP that messages containing this worm have been sent to my accounts. Be careful out there and as always; Update, Update, Update! <br /><br />As of May 2, 2005, 11:50 AM (Pacific Daylight Time/GMT -7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_SOBER.S. <br />TrendLabs has received numerous infection reports indicating that this malware is spreading in Germany and the U.S.A.<br /><br />This worm spreads by mass-mailing copies of itself using its own SMTP (Simple Mail Transfer Protocol) engine. It gathers its target recipients from files with certain extensions names. Notably, it avoids sending messages to addresses that contain specific strings. <br />Using social engineering techniques, it sends out an email supposedly sent by the soccer organization FIFA, informing recipients that they have won tickets for the upcoming FIFA World Cup 2006 in Germany.<br /><br />The email it sends out has the following details:<br /><br />From: (any of the following) <br />. Admin <br />. hostmaster <br />. info <br />. postmaster <br />. register <br />. service <br />. webmaster <br /><br />Subject: (any of the following German subjects) <br />. Glueckwunsch: Ihr WM Ticket <br />. Ich bin's, was zum lachen ;) <br />. Ihr Passwort <br />. Ihre E-Mail wurde verweigert <br />. Mail-Fehler!* <br />. WM Ticket Verlosung*WM-Ticket-Auslosung <br /><br />(or any of the following English subjects) <br />. Re: <br />. Your Password <br />. Registration Confirmation <br />. Your email was blocked <br />. mailing error <br /><br />Message body: (any of the following) <br /><br />. Passwort und Benutzer-Informationen befinden sich in der beigefuegten Anlage. <br />*-* http://www. <br />*-* MailTo: PasswordHelp <br /><br />. Diese E-Mail wurde automatisch erzeugt <br />Mehr Information finden Sie unter http://www. <br /><br />. Folgende Fehler sind aufgetreten: <br /><br />. Fehler konnte nicht Explicit ermittelt werden <br /><br />. End Transmission <br /><br />. Aus Datenschutzrechtlichen Gruenden, muss die vollstaendige E-Mail incl. Daten gezippt & angehaengt werden. Wir bitten Sie, dieses zu beruecksichtigen. <br /><br />. Auto ReMailer# [ <br /><br />. Nun sieh dir das mal an! <br />Was ein Ferkel .... <br /><br />. Herzlichen Glueckwunsch, <br />--- FIFA-Pressekontakt: <br />ok ok ok,,,,, here is it <br />r die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei. <br />Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang. <br />ok2006 <br />Team <br />St. Rainer Gellhaus <br />error- <br />--- Pressesprecher Jens Grittner und Gerd Graus <br />--- FIFA Fussball-Weltmeisterschaft 2006 <br />--- Organisationskomitee Deutschland <br />--- Tel. 069 / 2006 - 2600 <br />--- Jens.Grittner@ok2006.de <br />--- Gerd.Graus@ok2006.de <br /><br />. Account and Password Information are attached! <br />Visit: http://www. <br /><br />. AntiVirus Service <br />**** WebSite: . <br /><br />Attachment: (any of the following) <br />. mail_info.zip <br />. okTicket-info.zip <br />. LOL.zip <br />. _PassWort-Info.zip <br />. autoemail-text.zip <br /><br /><br />TrendLabs will be releasing the following EPS deliverables:<br /><br />TMCM Outbreak Prevention Policy 171<br />Official Pattern Release 2.611.00<br />Damage Cleanup Template 588<br /><br /><br />For more information on WORM_SOBER.S, you can visit our Web site at:<br />http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBER.S<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111514731008494219?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1115145597809794952005-05-03T11:39:00.000-07:002005-05-03T11:39:57.810-07:00Beware How You GoogleI'm back from vacation and ready to alert you again. So here's a real nasty one that can result from a simple mistyping of Google's name in your browsers address bar. Read this one closely folks.
<br />
<br /><a href="http://www.eweek.com/article2/0,1759,1790348,00.asp">Beware How You Google</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111514559780979495?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111998803598545582005-03-28T00:33:00.000-08:002005-03-28T00:33:23.600-08:00New Jeans - WORM_JEANS.AFrom the Trend Micro Weekly Virus Report
<br />
<br />New Jeans - WORM_JEANS.A (Low Risk)
<br />
<br />WORM_JEANS.A is a memory-resident worm that attempts to propagate via email with itself as an attachment, using its own Simple Mail Transfer Protocol (SMTP) engine. It may use a polymorphic engine to drop a file containing the source code of the worm, and then recompile it to produce a different
<br />appearance. While the inclusion of source code in the worm is not new behavior (BAGLE variants included this), the recompilation of the dropped source code is. This "courier virus" behavior is described as the worm being able to carry within itself, its whole source code and eventually dropping and recompiling it in the infected computer to create new variants of itself. It infects computers running Windows 98, ME, NT, 2000, and XP.
<br />
<br />Upon execution, the worm drops a copy of itself as INCUBATOR.SCR in the Windows folder or BIGFISH.SCR in the Windows system folder. It creates registry entries
<br />that allow it to automatically execute at every system startup. It also adds registry entries such that when certain applications are executed, this worm runs instead of the programs selected.
<br />
<br />This worm attempts to propagate via email. It searches for target email addresses in files with the following file name extensions:
<br />
<br /> * .asp
<br /> * .htm
<br /> * .xml
<br />
<br />It retrieves SMTP servers in the system registry, and then attempts to send a copy of itself as an attachment using its own SMTP engine. The email message that it attempts
<br />to send, contains the following details (however, due to bugs in its code, this worm is not able to execute this propagation routine):
<br />
<br />From: Don Quijote y Sancho Panza
<br />Subject: juas juas cuidadin con el attachhhhrrrr!!!!!
<br />Message body: juas juas juas peaso de bicho que lleva el attach!!! juas juas!!! ;D
<br />Vallez\29a
<br />Attachment: soyunpeasodebichooooooo.scr
<br />
<br />This worm may also display a message box with the following:
<br />
<br />Win32.Genome coded by ValleZ/29a
<br />
<br /><a href="http://www.trendmicro.com/en/security/report/overview.htm" target="_blank">New Jeans - WORM_JEANS.A</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111199880359854558?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111658213194631152005-03-24T01:56:00.000-08:002005-03-24T02:09:25.463-08:00Mozilla Foundation Security AdvisoriesAnother new update/version of Firefox. Why another 4+ meg download so soon? To repair three problems.<br />MFSA 2005-32 Drag and drop loading of privileged XUL<br />MFSA 2005-31 Arbitrary code execution from Firefox sidebar panel<br />MFSA 2005-30 GIF heap overflow parsing Netscape extension 2<br /><br />Go get it Folks. <a href="http://www.mozilla.org/products/firefox/" target="_blank"> Download Firefox 1.0.2</a> <br /><br />Oh and as always with Firefox, even though there is no admonishment to do so on the download site, I have found it better to uninstall the old version before installing the new. Yes, your prefs and customizations will still be there so don't worry. After all, this ain't M$ crapware.<br /><br /><a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html" target="_blank">Mozilla Foundation Security Advisories</a><br /><br />If you use Mozilla's Thunderbird email program (and you should!) there's an update to version 1.0.2 for it also.<br /><a href="http://www.mozilla.org/products/thunderbird/" target="_blank"> Download TBird 1.0.2</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111165821319463115?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111475543989610952005-03-21T23:12:00.000-08:002005-03-21T23:15:20.650-08:00Security Flaws in McAfeeYeah and Symantec just patched one also. Big corporate structures make for slow reaction times and bottom lines drive software releases.<br /><br />I'll stick with AVG thank you.<br /><br /><a href="http://news.yahoo.com/news?tmpl=story&cid=75&u=/nf/20050321/tc_nf/31510&printer=1" target="_blank">Security Flaws in McAfee AntiVirus</a><br /><br />and on a related note, you might want to read this article as well. A bit dated in security terms but still interesting in light of the McAfee and Symantec flaws.<br /><br /><a href="http://www.newsfactor.com/story.xhtml?story_id=29188" target="_blank">Security Flaws Found in McAfee AntiVirus</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111147554398961095?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111355497902310272005-03-20T13:51:00.000-08:002005-03-20T13:51:37.903-08:00FTC Says Anti-Spyware Vendor Shut DownIf you purchased Spyware Assassin you had better read this. The free scan returned bogus spyware reports and apparently the program sold did not actually remove any spyware.
<br />
<br />Of course why anybody would willingly purchase spyware removers when Spybot S&D and Adaware can had for free boggles my mind. Even M$ has a free spyware removal giveaway.
<br />
<br /><a href="http://www.eweek.com/article2/0,1759,1775506,00.asp" target="_blank">FTC Says Anti-Spyware Vendor Shut Down</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111135549790231027?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111351666246967432005-03-20T12:47:00.000-08:002005-03-20T12:47:46.246-08:00SPIT Into This, PleaseIf it ain't SPAM it's SPIT.
<br />
<br />For landline phone users the no call list provided some relief from the idiot telemarketers. But if you're into using your broadband connection for a phone line (a la Vonnage) get ready for a flood of unwanted calls. Read the article below to see what's coming to your internet phone line.
<br />
<br /><a href="http://www.eweek.com/print_article2/0,2533,a=147925,00.asp" target="_blank">SPIT Into This, Please</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111135166624696743?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111348998635794412005-03-20T12:03:00.000-08:002005-03-20T12:03:18.636-08:00Sysinfo.orgHere's a handy page to have around to check on entries in your Registry. Of course registry hacking is not for the faint of heart, as it can and will decimate your system if you screw up. Consider this carefully before using this resource. Always make a backup of your registry first. If you don't backup first, I have NO sympathy for your dumb ass.
<br />
<br /><a href="http://www.sysinfo.org/" target="_blank">Sysinfo.org</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111134899863579441?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111183534801519792005-03-18T14:05:00.000-08:002005-03-18T14:05:34.803-08:00Trend Micro's Weekly Virus ReportAntispyware Killer - TROJ_ASH.A (Low Risk)
<br />
<br />TROJ_ASH.A is a destructive, memory-resident Trojan that terminates and deletes all files related to Microsoft Windows Antispyware. It also steals information related to online banking Web sites, by monitoring a user's Internet transactions at certain online banking sites. It runs on Windows 95, 98, ME, NT, 2000, and XP.
<br />
<br />This memory-resident Trojan arrives in a system as the file ASH.DLL, in the Windows system folder. It may also be downloaded by the user from the Internet. Before installation, the Trojan checks whether Microsoft Windows Antispyware is installed. If found, it attempts to terminate and delete all files related to this application.
<br />
<br />This Trojan steals information related to online banking Web sites, by monitoring the user’s Internet transactions and waiting for the user to access the following online banking sites:
<br />
<br /> * https://ibank.barclays.co.uk
<br /> * https://ibank.cahoot.com
<br /> * https://olb2.nationet.com
<br /> * https://online.lloydstsb.co.uk
<br /> * https://www.bankofscotlandhalifax-online.co.uk
<br /> * https://www.ebank.hsbc.co.uk
<br /> * https://www.ebank.hsbc.co.uk
<br /> * https://www.millenniumbcp.pt
<br /> * https://www.ukpersonal.hsbc.com
<br />
<br />When the Trojan detects visits to any of these banking sites, it displays a spoofed .HTML page to trick the user into entering their account information. The stolen data is then sent to a remote user.
<br />
<br />The Trojan then drops the following log files in the Windows folder, to store the information it gathers from the user:
<br />
<br /> * Email.log
<br /> * Pass.log
<br /> * Req.log
<br />
<br />In addition to gathering user IDs and passwords, it also gathers email addresses found in the user's system. It gathers email addresses from files with the following extensions:
<br />
<br /> * .*ht*
<br /> * .adb
<br /> * .asp
<br /> * .dbx
<br /> * .doc
<br /> * .eml
<br /> * .msg
<br /> * .oft
<br /> * .ph*
<br /> * .pl*
<br /> * .rtf
<br /> * .tbb
<br /> * .tx*
<br /> * .uin
<br /> * .vbs
<br /> * .wab
<br /> * .xls
<br /> * .xml
<br />
<br />This Trojan also terminates certain processes, and modifies the HOSTS files. These HOSTS files contain the mappings of IP addresses to host names. This file is loaded into the computer’s memory at startup. Windows checks this file before it connects to a requested Web site. If a requested Web site is listed in the HOSTS file, any attempt to connect to this site is redirected back to the local machine (which is your computer’s IP address). It also blocks other applications from connecting to the Internet, as long the Web site that it attempts to connect to, is listed in the HOSTS file.
<br />
<br />HOSTS files are useful for blocking ads, banners, cookies, and known malicious Web sites. However, this technique is now being employed by various malware to prevent users from accessing antivirus and security related Web sites.
<br />
<br />This Trojan adds many lines in the system's HOSTS file, preventing a user from accessing the listed Web sites. View the complete list of terminated processes and lines added.
<br />
<br />If you would like to scan your computer or TROJ_ASH.A or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://housecall.trendmicro.com/
<br />
<br />TROJ_ASH.A is detected and cleaned by Trend Micro pattern file #2.497.00 and above.
<br />
<br />3. Top 10 Most Prevalent Global Malware
<br />(from March 11 to March 17, 2005)
<br />
<br /> 1. HTML_NETSKY.P
<br /> 2. WORM_NETSKY.P
<br /> 3. JAVA_BYTEVER.A
<br /> 4. TROJ_SMALL.SN
<br /> 5. TROJ_DFC.A
<br /> 6. JAVA_BYTEVER.B
<br /> 7. SPYW_GATOR.D
<br /> 8. TROJ_BAGLE.BG
<br /> 9. WORM_RBOT.GEN
<br /> 10. TROJ_STARTPA.A
<br />
<br /><a href="http://www.trendmicro.com/en/security/report/overview.htm">Trend Micro's Weekly Virus Report</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111118353480151979?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.comtag:blogger.com,1999:blog-7919666.post-1111014288269569782005-03-16T15:04:00.000-08:002005-03-16T15:04:48.270-08:00Are You Safer With Firefox?Good article to read, especially if you're new to Firefox. Here's one excerpt to show you why:
<br />
<br />"In Firefox for Windows you can set the options at Tools| Options | -Advanced-|Software Update to check Firefox servers periodically for updates to the program. It will find version 1.0.1, but all it will do is download the whole program and start the installer. On the Linux version you can only update Extensions and Themes, not the program code."
<br />
<br /><a href="http://www.pcmag.com/print_article2/0,2533,a=147669,00.asp">Are You Safer With Firefox?</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7919666-111101428826956978?l=fermatssecurity.blogspot.com'/></div>FermatsEnigmahttp://www.blogger.com/profile/02237469043234469231noreply@blogger.com