Posts tagged as:

Trojan

Energizer Press Release

Energizer Announces Duo Charger and USB Charger Software Problem
ST. LOUIS, March 5, 2010 /PRNewswire via COMTEX/ — Energizer has been informed by the CERT Coordination Center (CERT) that the Windows software that was referenced and made available via a download with its Duo Charger, Model CHUSB, contains a vulnerability. Energizer introduced the Duo Charger in the United States and the USB Charger in Latin America, Europe and Asia in 2007. Both products charge Nickel Metal Hydride batteries from both a wall outlet and a USB connection. The product included a feature that would allow the user to view the battery charging status on a computer if associated software was installed. The Duo Charger product documentation referenced www.energizer.com/usbcharger to download the software. The site offered downloadable software in both Windows and Apple(R) versions; however only the Windows version contained the vulnerability.

Energizer has discontinued sale of this product and has removed the site to download the software. In addition, the company is directing consumers that downloaded the Windows version of the software to uninstall or otherwise remove the software from your computer. This will eliminate the vulnerability. In addition CERT and Energizer recommend that users remove a file that may remain after the software has been removed. The file name is Arucer.dll, which can be found in the Window system32 directory.

Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software. Additional technical information can be found at http://www.kb.cert.org/vuls/id/154421.

{ 0 comments }

Malware found in Firefox Add-ons

by certifiedbug on February 5, 2010

in Browser

Security Issue on AMO according to Mozilla alert.

Two experimental add-ons, Version 4.0 of Sothink Web Video Downloader and all versions of Master Filer were found to contain Trojan code aimed at Windows users. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen, and Master Filer contained Win32.Bifrose.32.Bifrose Trojan. Both add-ons have been disabled on AMO.

Impact to users

If a user installs one of these infected add-ons, the trojan would be executed when Firefox starts and the host computer would be infected by the trojan. Uninstalling these add-ons does not remove the trojan from a user’s system. Users with either of these add-ons should uninstall them immediately. Since uninstalling these extensions does not remove the trojan from a user’s system, an antivirus program should be used to scan and remove any infections.

Mozilla

In May of 2008 Mozilla admitted that a worm inside a Vietnamese language add-on had gone undetected for months.

Certifiedbug November 23, 2009: Vulnerabilities in Firefox extensions

Edit
Update on AMO Security Issue

{ 0 comments }

Google takes step for Human Rights

January 13, 2010

Google disclosed on their blog that they were hit with a targeted trojan aimed to gain access to Gmail accounts of Chinese human right activists.
We have taken the unusual step of sharing information about these attacks with a broad audience not just because of the security and human rights implications of what we have unearthed, [...]

Read the full article →

New wave of malicious SQL Injections

December 11, 2009

Security researcher Mary Landesman said the attack appears to be a work-in-progress focusing on:

Integer overflow vulnerability in Adobe Flash Player, described in CVE-2007-0071
MDAC ADODB.Connection ActiveX vulnerability described in MS07-009
Microsoft Office Web Components vulnerabilities described in MS09-043
Microsoft video ActiveX vulnerability described in MS09-032
Internet Explorer Uninitialized Memory Corruption Vulnerability – MS09-002

Successful exploit [...]

Read the full article →

MSRT November Threat Reports

November 24, 2009

Microsoft Malware Protection Center

Out of these prevalent threat families worldwide, 8 are password stealers collecting online game credentials, online banking passwords or other user identities of users’ online accounts.
8 of them are fake security products or trojan downloaders for rogues. The MSRT now covers the following most high profile rogues

o Win32/FakeVimes
o Win32/PrivacyCenter
o Win32/FakeScanti
o [...]

Read the full article →

Pirated Windows 7 RC has malware

May 15, 2009

According to Tripp Cox, VP of engineering at security firm Damballa, a pirated version of Windows 7 Release Candidate is infected with a Trojan horse which has created a botnet with tens of thousands of bots under its control.
Apprantly the software is primarily designed to download and install malicious packages under a “pay-per-install” scheme.
The legitimate [...]

Read the full article →

Trojan bundling modified StudiVZ toolbar with backdoor

February 11, 2009

StudiVZ, based in Germany, is a popular social networking platform for students.
A new Trojan (pretending to be a toolbar installer) is spreading that bundles the legitimate toolbar for the German social network “StudiVZ” with a variant of Backdoor-CEP. Among other malicious activities, the backdoor is capable of recording a user’s screen, taking screenshots, and logging [...]

Read the full article →

Trojan targets Firefox users

December 5, 2008

The malware harvests web passwords and logins which it forwards to a domain in Russia.
It drops an executable file (which is a Firefox 3 plugin) and a JavaScript file (detected by Bitdefender as: Trojan.PWS.ChromeInject.A) into the Firefox plugins and chrome folders respectively.
It filters the URLs within the Mozilla Firefox browser and whenever encounter the following [...]

Read the full article →

Malware screensaver “2008BeijingOlympics.scr”

August 10, 2008

When you run the program, it actually displays some nice pictures of some of the Olympic Stadiums, so people may not notice the payload of installing a keylogger onto their computers.The trojan drops two files named ‘wuauct.exe’ and ‘81.dll’, and launches ‘wuauct.exe’ which tries to connect to the IP address in China on port 81 [...]

Read the full article →

Trojan ‘fastmp3player’ fake MP3, MPG files

May 6, 2008

Flagged red at Site Advisor
Internet Storm Center 2008-04-29 Scripts in ASF files
Reported 2008 Apr 07 at Bit Defender as Trojan.Downloader.WMA.Wimad.N
Spreading: very low
Not any more. Helped along by P2P users, this one is now spreading fast. When a user attempts to load one of these MP3 and MPG files, which are fake and contain [...]

Read the full article →