Saturday, May 3, 2008

[Lockergnome] Computer Security ~ May 3, 2008

Lockergnome
Lockergnome's Computer Security ~ May 3, 2008   



LocationMail: LocationMail tells you where e-mail was sent from. It uses the most accurate data in the world to analyze your e-mail, trace it, and look up where the sender was when the message was sent. Find out where your friend was when she e-mailed you, or where a business contact is really writing from. LocationMail integrates seamlessly into Outlook or Outlook Express; once installed, it shows you location information next to each message. LocationMail shows... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

SoundClick: MP3 music files are all over the place. Turn around - there's probably one behind you. Even if you haven't downloaded any of them yourself, you probably have a few on your computer, thanks to various software installations. The MP3 standard is great for keeping the file size down, as well as keeping the quality rather high. What if I told you that you could watch your MP3 files? I'm not talking about visualizations;... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


TrendLabs | Malware Blog - by Trend Micro - One Year Later, Italian Job Still Working Overtime

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. One Year Later, Italian Job Still Working Overtime
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

One Year Later, Italian Job Still Working Overtime

In what may turn out to be an advanced one-year “toast” to the June 2007 mass infection that came to be known as the Italian Job, TrendLabs discovered 90 compromised Italian Web sites (all verified active as of this writing) at around 12:30 AM GMT. The compromised sites are varied; their only common thematic link seems to be the Italian language.

According to Trend Micro analysts, the attack rolls out like this:

1. The compromised Web sites contain obfuscated JavaScript code (detected as JS_AFIR.A) that redirects the browser to the malicious URL http://{BLOCKED}f.com/cgi-bin/index.cgi?grobin (blocked by Web Reputation Services since April 27).

The script checks the Internet Explorer version and language so it will only execute on Italian ones.

2. The said URL redirects to another URL: http://{BLOCKED}r.com/cgi-bin/index.cgi?grb&js=1.

The two malicious sites were found to be hosted in a single IP traced back to San Diego, California.

3. The said sites download TROJ_SINOWAL.CB (detected since April 27) from the same domain. TROJ_SINOWAL.CB then drops BKDR_SINOWAL.CF (detected since May 1), which in turn drops a rootkit component on the affected PC.

This rootkit component modifies certain sectors of the infected hard disk. It also hooks Driver.sys to protect these sectors from read and write operations from AV/security software.

See infection diagram below.

SINOWAL malware variants are known information stealer droppers.

As of this writing, TrendLabs has discovered two forms of this compromise: one is via an injected obfuscated script that redirects to a certain malicious URL, and the other is via a readable iFrame and the same obfuscated script.

It appears that this attack affects sites hosted in Italy by a single hosting provider — the same one that hosted the thousands of sites (mostly travel and leisure) in last year’s large-scale infection. This time, compromised sites include the following:

  • A Johnny Depp fan site
  • The official site of Monica Bellucci (famous Italian model-actress)
  • The Mercedes-Benz club of Italy
  • A fan site of Pearl Jam
  • The official Web page of Sabrina Salerno (Italian singer)

Trend Micro customers are already protected from this threat. Web Threat Protection technology has prevented access to the malicious pages since 27 April 2008. The URLs have already been added to our emergency database and are blocked by WCS (Web Classify Server), making these accessible to customers. Also, the RootkitBuster tool is able to scan the MBR-rootkit component involved in this attack.

Last updated at 7:53 PM GMT, 2 May 2008

ShareThis



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, May 2, 2008

[Lockergnome] Computer Security ~ May 2, 2008

Lockergnome
Lockergnome's Computer Security ~ May 2, 2008   



LiveWire! Broadcast: LiveWire! Broadcast is the ultimate add-on for RealPlayer, RealOne, and Windows Media. Search and connect to any country, culture, or music genre by easily searching over 10,000 live radio stations and 11 Million audio and video streams. LiveWire! Broadcast uses streaming media, playing audio almost instantly, without taking up any hard disk space. LiveWire! Broadcast supports multiple formats so you can use your favorite player. [Get more information | Download A Trial]... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

RecentX: On a normal day of activity on the computer, I'm willing to assume that you probably can't remember every single thing that you did. If you're like me, then you probably have to take care of so many random tasks that you can't even remember all of what you did in the last hour. Short-term memory? What's that? Since a large group of us can't be trusted to completely remember where we've been and what... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive