Posts tagged as:

Trojan

Graham Cluley’s blog.
Trojan horse suspected of contributing to 2008 Madrid aircrash

Authorities investigating the 2008 Madrid air crash, which resulted in the deaths of 154 people, have discovered that a central computer system used to monitor technical problems in aircraft was infected with Trojan horses.

The final report from crash investigators is not due to be presented until December, and it’s very probable that there will be found to be other contributing factors to what was a horrific accident beyond the malware infection by Trojan horses.

However, next time someone tries to convince you that the people who write malware aren’t really doing anyone any serious harm – remember this case.

http://www.sophos.com/blogs/gc/g/2010/08/20/trojan-horse-suspected-contributing-2008-madrid-aircrash/

{ 0 comments }

Energizer Press Release

Energizer Announces Duo Charger and USB Charger Software Problem
ST. LOUIS, March 5, 2010 /PRNewswire via COMTEX/ — Energizer has been informed by the CERT Coordination Center (CERT) that the Windows software that was referenced and made available via a download with its Duo Charger, Model CHUSB, contains a vulnerability. Energizer introduced the Duo Charger in the United States and the USB Charger in Latin America, Europe and Asia in 2007. Both products charge Nickel Metal Hydride batteries from both a wall outlet and a USB connection. The product included a feature that would allow the user to view the battery charging status on a computer if associated software was installed. The Duo Charger product documentation referenced www.energizer.com/usbcharger to download the software. The site offered downloadable software in both Windows and Apple(R) versions; however only the Windows version contained the vulnerability.

Energizer has discontinued sale of this product and has removed the site to download the software. In addition, the company is directing consumers that downloaded the Windows version of the software to uninstall or otherwise remove the software from your computer. This will eliminate the vulnerability. In addition CERT and Energizer recommend that users remove a file that may remain after the software has been removed. The file name is Arucer.dll, which can be found in the Window system32 directory.

Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software. Additional technical information can be found at http://www.kb.cert.org/vuls/id/154421.

{ 0 comments }

Malware found in Firefox Add-ons

February 5, 2010

Security Issue on AMO according to Mozilla alert. Two experimental add-ons, Version 4.0 of Sothink Web Video Downloader and all versions of Master Filer were found to contain Trojan code aimed at Windows users. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen, and Master Filer contained Win32.Bifrose.32.Bifrose Trojan. Both add-ons have been disabled on [...]

Read the full article →

Google takes step for Human Rights

January 13, 2010

Google disclosed on their blog that they were hit with a targeted trojan aimed to gain access to Gmail accounts of Chinese human right activists. We have taken the unusual step of sharing information about these attacks with a broad audience not just because of the security and human rights implications of what we have [...]

Read the full article →

New wave of malicious SQL Injections

December 11, 2009

Security researcher Mary Landesman said the attack appears to be a work-in-progress focusing on: Integer overflow vulnerability in Adobe Flash Player, described in CVE-2007-0071 MDAC ADODB.Connection ActiveX vulnerability described in MS07-009 Microsoft Office Web Components vulnerabilities described in MS09-043 Microsoft video ActiveX vulnerability described in MS09-032 Internet Explorer Uninitialized Memory Corruption Vulnerability – MS09-002 Successful [...]

Read the full article →

MSRT November Threat Reports

November 24, 2009

Microsoft Malware Protection Center Out of these prevalent threat families worldwide, 8 are password stealers collecting online game credentials, online banking passwords or other user identities of users’ online accounts. 8 of them are fake security products or trojan downloaders for rogues. The MSRT now covers the following most high profile rogues o Win32/FakeVimes o [...]

Read the full article →

Pirated Windows 7 RC has malware

May 15, 2009

According to Tripp Cox, VP of engineering at security firm Damballa, a pirated version of Windows 7 Release Candidate is infected with a Trojan horse which has created a botnet with tens of thousands of bots under its control. Apprantly the software is primarily designed to download and install malicious packages under a “pay-per-install” scheme. [...]

Read the full article →

Trojan bundling modified StudiVZ toolbar with backdoor

February 11, 2009

StudiVZ, based in Germany, is a popular social networking platform for students. A new Trojan (pretending to be a toolbar installer) is spreading that bundles the legitimate toolbar for the German social network “StudiVZ” with a variant of Backdoor-CEP. Among other malicious activities, the backdoor is capable of recording a user’s screen, taking screenshots, and [...]

Read the full article →

Trojan targets Firefox users

December 5, 2008

The malware harvests web passwords and logins which it forwards to a domain in Russia. It drops an executable file (which is a Firefox 3 plugin) and a JavaScript file (detected by Bitdefender as: Trojan.PWS.ChromeInject.A) into the Firefox plugins and chrome folders respectively. It filters the URLs within the Mozilla Firefox browser and whenever encounter [...]

Read the full article →

Malware screensaver “2008BeijingOlympics.scr”

August 10, 2008

When you run the program, it actually displays some nice pictures of some of the Olympic Stadiums, so people may not notice the payload of installing a keylogger onto their computers.The trojan drops two files named ‘wuauct.exe’ and ’81.dll’, and launches ‘wuauct.exe’ which tries to connect to the IP address in China on port 81 [...]

Read the full article →