Security [CENTRAL] Forum - SCforum.info
23. May 2012., 09:07:24 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11253
Latest: pluskit011
Stats
Total Posts: 15626
Total Topics: 4334
Online Today: 2742
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: New Exploit As Flash Player Upgrade (flashinstaller.exe, Zbot-MGA, Zbot.gen!R)  (Read 3104 times)
0 Members and 4 Guests are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5074


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 26. November 2009., 07:01:56 »



Phishing campaign has hit more than 3.5 million mailboxes, researchers say.

Researchers have detected a new phishing attack that promises to enhance the security of the user's emailbox -- and then downloads a malicious Trojan instead.

The email requests that recipients click on a link in the body of the email to update the "security mode" of their emailboxes, according to researchers at Red Condor, an email security tool vendor.

Users who click on the link are taken to a Website that advises them to update to the latest version of the Macromedia Flash Player by downloading "flashinstaller.exe." This executable is actually a banking Trojan that is known to disable firewalls, steal sensitive financial data, and provide hackers with remote access capabilities, Red Condor says.

The malware is more commonly known as Win32:Zbot-MGA (Avast), W32/Bifrost.C.gen!Eldorado (F-Prot), PWS-Zbot.gen.v (McAfee), or PWS:Win32/Zbot.gen!R (Microsoft), the researchers note.

The spam campaign was detected late on Nov. 20; within the first six hours, Red Condor says it blocked more than 500,000 email messages. So far, the company says it has stopped more than 3.5 million messages belonging to this campaign.

"Protecting inboxes is seen as business-critical, so it is no surprise that spammers and cybercriminals are playing off of email users' growing security concerns with security-focused junk mail," says Tom Steding, president and CEO of Red Condor. Hours after the spam campaign began, only about half of the antivirus products had begun to recognize and block it, Steding says.

"Spam that suggests users update their Flash Player is a common type of scam during the holidays, but it is often associated with viewing a fake e-card or a viral video," Steding observes. "We encourage email users, particularly those returning to full inboxes after the Thanksgiving holiday, to immediately delete these messages and notify their IT administrators."

(darkReading)
Logged

Security [CENTRAL] Forum - SCforum.info
« on: 26. November 2009., 07:01:56 »



 Logged
F3RL
SCF Advanced Member
***

KARMA: 17
Gender: Male
Location: Australia
Posts: 169



« Reply #1 on: 27. November 2009., 09:34:51 »

Just to let you know, the actual or real flash installer's name is 'install_flash_player_ax.exe' (as of 27/11/09)
Triple-click on cancel button if you see any other file name than 'install_flash_player_ax.exe'
Logged

well? understand ma bad English.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5074


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #2 on: 27. November 2009., 09:42:07 »

Just to let you know, the actual or real flash installer's name is 'install_flash_player_ax.exe' (as of 27/11/09)
Triple-click on cancel button if you see any other file name than 'install_flash_player_ax.exe'


Thanks for info. Eric...  Karma Up
Logged

jasonx
SCF Newbie
*

KARMA: 1
Posts: 2


WWW
« Reply #3 on: 27. November 2009., 16:55:41 »

Thank you for sharing. Now I know that now..
Logged

Raviraj
SCF Newbie
*

KARMA: 0
Posts: 1


« Reply #4 on: 22. February 2010., 08:01:34 »

Yes even i have got the same mail regarding the Flash Player update . When i installed the flash player exe file instead of installing the flash player the exe file installs a malicious file Trojan. Its really a bad news. Thanks for updating about this issue.

Colorado Mortgage
Logged
fotis100
SCF Member
**

KARMA: 2
Gender: Male
Age: 40
Location: GREECE
Posts: 29



« Reply #5 on: 12. March 2010., 07:52:47 »

thanks for info
Logged
tuyugi007
SCF Member
**

KARMA: 1
Posts: 26


« Reply #6 on: 14. March 2010., 12:59:01 »

Thanks for the update
Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 19. April 2012., 17:59:48