Microsoft Updates for January

In the first security bulletin of the year 2009, MS09-001, Microsoft has published several critical updates which resolve 2 privately reported vulnerabilities and a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) protocol. If exploited successfully, an attacking user could execute remote code on the system, and could view, change or delete data, or create new accounts with full user rights.This security update has been rated as critical for all the versions of Microsoft Windows 2000, Windows XP and Windows 2003 and as moderate for all the versions of Windows Vista and Windows Server 2008.We remind you that in order to improve the security level of your computer against known and unknown network vulnerabilities, you can stop or block the access to any network service you don’t use by using a properly configured firewall or by disabling the network services that are not used in the system.Although in PandaSecurity we work daily on how to improve our products in order to protect our clients from these new vulnerabilities, we always recommend to install as soon as possible the security patches published in the Microsoft’s security bulletins, as well as other security updates that may affect other products installed on the same system. MS09-001 – Vulnerabilities in SMB Could Allow Remote Code Execution


original article

Tags:

Posted under Malware Alerts

This post was written by Ted on January 17, 2009

-->

FEATURE: Modern Day Malware & Organised Crime (Tech Digest via Yahoo! UK & Ireland News)

Quarter past nine on a Monday morning. I’m staring at the thick oak beam of long polished table wondering what the hell I’m doing at briefing about internet security. My last journalistic foray into this turgid corner of the tech world had me stuck talking anti-virus software with one of the chief marketing officers at a leading company. I recall a solid 40 minutes of the internet neighbourhood …


original article

Tags:

Posted under Spyware in the News

This post was written by Ted on January 16, 2009

-->

Spyware Case Finally Closed for Teacher Julie Amero (PC World)

Former schoolteacher Julie Amero has paid a $100 fine to end her infamous spyware case. She had been facing 40 years in…


original article

Tags:

Posted under Spyware in the News

This post was written by Ted on January 16, 2009

-->

The pretty Paris Hilton is attacked again!!

Paris Hilton is fashionable. This girl does a bit of everything, she’s a model, an actress, a singer… and she hasn’t only become the target of paparazzis but also of the computer attacks…Several months ago the image of Paris was being used in thousands of spam messages which contained hot videos of this celebrity. However, this was too good to be true and it was actually malware which installed rogue AVs on our computers. This time, cyber-crooks have gone further and Paris Hilton’s official website has been attacked. When accessing this web page, a popup window appears offering visitors the option to download the last update of flash player. When the downloaded file is run, it ends the smss.exe service, which belongs to the Windows NT Session Manager Subsystem. Then, it drops a file in system32 under the name twext.exe, which hooks to the winlogon.exe process and modifies the following Windows Registry entry in order to be run whenever Windows is started: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit" Old type: REG_SZ New type: REG_SZ Old data: C:\WINDOWS\system32\userinit.exe, New data: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe, It is continuously trying to connect to the website you69tube to obtain the file flvideo/.a/.z/cfg.bin, which is no longer available, and it also launches connections to 72.167.37.109.It creates more files and directories, all of them hidden, in %systemroot%\twain_32\user.ds and local.ds (encrypted files) C:\Documents and Settings\NetworkService\Application Data\twain_32\local.dsThis malware has been detected as Trj/Sinowal.VYO.Now the question is: how long would take cyber-crooks to use once again the image of this celebrity? I suppose that it wouldn’t be long.


original article

Tags: ,

Posted under Malware Alerts

This post was written by Ted on January 16, 2009

-->

Webroot(R) Threat Advisory: Searching for Presidential Campaign Videos Puts Users at Risk for Infection (Centre Daily Times)

Webroot, a leading provider of security solutions for the consumer, enterprise and SMB markets, today announced that it has detected malicious software being propagated as campaign videos for John McCain and Barack Obama. Hackers are taking advantage of unsuspecting users during the U.S. Presidential election season by utilizing the Gnutella file sharing network and seeding it with malware …


original article

Tags:

Posted under Spyware in the News

This post was written by Ted on January 15, 2009

-->