Anti Rootkit

http://AntiRootkit.Net

Entries for August, 2007

Kaspersky Anti-Virus 2007


Leave a Comment

Vanquish rootkit on Windows Vista


Leave a Comment

Microsoft Security Update?

Microsoft has released Advance Notification for June 2007.
As while, a trojan spam is masquerating as Microsoft Security Update now. The content of spams is about Security Update for Internet Explorer. Of course, it’s a trojan, Kaspersky detects it as Trojan-Downloader.Win32.Agent.avk.
The spams are as the following:
From: “MSIE Update” security14@microsoft.com
Subject: Microsoft Security Update
Body:
Microsoft Security Bulletin MS06-31
Cumulative Security [...]

Leave a Comment

Ecard and Zhelatin

Some days ago, we reported that Zhelatin worm masqueraded as Greeting card spams. Today, we receive new spams which masquerade as Ecard. Be careful please.
The spams are as the following:
Subject: You’ve received a postcard from a family member!
Body:
Good day.
Your family member has sent you an ecard from .hk.
Send free ecards from .hk with your choice [...]

Leave a Comment

IRC-Worm.Win32.Agent.a

summer2008.zip
We just received a new worm spreading via MSN from a friend. The file name is “summer2008.zip”. In the zip file, it contains a .scr file “summer2008.scr”. This worm also can send out different messages with multiple languages. It also adds the Chinese language pronunciation this time. Kaspersky detects it as Backdoor.Win32.IRCBot.acd (old name: IRC-Worm.Win32.Agent.a)
This [...]

Leave a Comment

Email-Worm.Win32.Sober.aa

Worm.Win32.Sober.aa
We received some spams about a variant of Email-Worm.Win32.Sober today. It spreads via English and German spams. Everyone should be careful.
The English spams are as the following:
From: Webmaster@microsoft.com
Subject: Error in your eMail
Body:
Your eMail has occurred an unknown error on our Server. Please read your mail and check the text.
The full email is attached!
。auto mailerdaemon X.Path [...]

Leave a Comment

Warezov.mp via ICQ

We’ve received some reports that Warezov.mp(aka Stration) is now spreading via ICQ. We’ve got two domains about this variant, they are “auterfunmdasetion.com” and “buheradesunme.com”. We hope ICQ users can block these domains.
The variant sends out as the following link via ICQ:
http://133.buheradesunme.com//166/
http://2849.buheradesunme.com//166/
http://4047.auterfunmdasetion.com//3660/
When clicks these links, the file “flash.exe” or “pic.pif” will be downloaded.
The size of this [...]

Leave a Comment

  • Categories

  • Meta

  • Sponsors