<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gizmophobe Technology &#38; Gaming &#187; Malware Threats</title>
	<atom:link href="http://www.gizmophobe.co.uk/tag/malware-threats/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gizmophobe.co.uk</link>
	<description>Games - Gadgets - DVD - Plasma - HD - WIFI</description>
	<lastBuildDate>Wed, 25 Jan 2012 09:39:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>GFI Software Announces Top 10 Malware Threats for February</title>
		<link>http://www.gizmophobe.co.uk/gfi-software-announces-top-10-malware-threats-for-february/</link>
		<comments>http://www.gizmophobe.co.uk/gfi-software-announces-top-10-malware-threats-for-february/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 07:32:08 +0000</pubDate>
		<dc:creator>Alan</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[February malware threats]]></category>
		<category><![CDATA[Malware Threats]]></category>
		<category><![CDATA[Trojan horses]]></category>

		<guid isPermaLink="false">http://www.gizmophobe.co.uk/?p=1433</guid>
		<description><![CDATA[Statistics from GFI Software anti-virus and malware product ThreatNet show that there has been an increase in the amount of attacks launched by rogue security software as well as a continued existence of Trojan horses.  The leading IT solutions provider to SMEs announced this week the top ten threats to businesses during the past month<a class="rmore" href="http://www.gizmophobe.co.uk/gfi-software-announces-top-10-malware-threats-for-february/">&#160;&#160; Read More ...</a>
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Statistics from GFI Software anti-virus and malware product ThreatNet show that there has been an increase in the amount of attacks launched by rogue security software as well as a continued existence of Trojan horses.  The leading IT solutions provider to SMEs announced this week the top ten threats to businesses during the past month of February.  The database comes from monthly scans that the VIPRE antivirus runs along with data from its own built in antispyware tool titled CounterSoy.</p>
<p>The trend seen last summer that Trojan horses are a major threat continued through last month with statistics from ThreatNet revealing that Trojans composed six of the top ten threats to computers during the month.  The number one threat detected by the software a total of 22.97% times was the Trojan Win32.Generic!BT.  This is a slight increase by about 1% for January and December.<br />
These Trojans are downloaders associated with rogue security programs known as “scareware”. Once they are on a user’s system, these programs perform a fake scan of a victim’s computer for malware then display false warnings that the machine is infected in an attempt to convince victims to purchase fake security software.</p>
<p>“The Security Shield rogue has become very noticeable, with many comments posted to our <a href="http://rogueantispyware.blogspot.com/2010/12/how-to-remove-security-shield.html" target="_blank">Rogue Security software</a> blog regarding this particular infection,” said Chris Boyd, senior threat researcher at GFI Labs. “These types of attacks notoriously cause a great deal of stress for the victim in addition to simply infecting their computer.”</p>
<p>While Trojans continue to be the most common threat detected, GFI Labs researchers are also seeing a rise in lesser-known attack vectors. Although they are not as common, these forms of attack are especially dangerous because most users may not know how to spot them.</p>
<p>&#8220;PDF exploits continue to be problematic, showing a small increase since January. February has also seen continued use of fake Java applet installs to infect PCs with malware, <a href="http://sunbeltblog.blogspot.com/2011/02/alureon-gatecrashes-vegas.html" target="_blank">Alureon</a> infected videogame patches distributed on P2P networks and <a href="http://sunbeltblog.blogspot.com/2011/02/scammers-go-phishing-on-playcom.html" target="_blank">phishing attempts</a> targeting customers of the popular online retailer Play.com,” said Boyd. “With new attacks popping up every day, users need to always stay cautious and research programs they plan to download when there is any doubt.”</p>
<p>ThreatNet is GFI Lab’s monitoring system that retrieves real-time data from VIPRE installations. Statistics come from tens of thousands of machines running VIPRE.</p>
<p>Top 10 detections for February</p>
<p>Detection Type Percent</p>
<p>Trojan.Win32.Generic!BT Trojan 22.97<br />
Trojan-Spy.Win32.Zbot.gen Trojan 3.46<br />
Trojan.Win32.Generic.pak!cobra Trojan 2.89<br />
Zugo LTD (v) Adware 2.52<br />
Fraudtool.Win32.Securityshield.ek!c (v) Trojan 2.00<br />
Trojan.Win32.Generic!SB.0 Trojan 1.72<br />
INF.Autorun (v) Trojan 1.66<br />
Worm.Win32.Downad.Gen (v) Worm 1.48<br />
Pinball Corporation (v) Adware 1.19<br />
Exploit.PDF-JS.Gen (v) PDF exploit 0.83</p>
<p>To see a graphical comparison of the top 10 most prevalent malware infections between January 2011 and February 2011, please visit:<a title="Goes to website of: http://images.gfi.com/Feb2011_Chart.jpg" href="http://images.gfi.com/Feb2011_Chart.jpg" target="_blank">http://images.gfi.com/Feb2011_Chart.jpg</a></p>
<img src="http://www.gizmophobe.co.uk/?ak_action=api_record_view&id=1433&type=feed" alt="" /><p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.gizmophobe.co.uk/gfi-software-announces-top-10-malware-threats-for-february/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Memory Sticks becoming a big source of Malware</title>
		<link>http://www.gizmophobe.co.uk/memory-sticks-becoming-source-malware/</link>
		<comments>http://www.gizmophobe.co.uk/memory-sticks-becoming-source-malware/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 17:39:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Malware Threats]]></category>
		<category><![CDATA[Memory Stick Trojans]]></category>
		<category><![CDATA[top e-threats]]></category>

		<guid isPermaLink="false">http://www.gizmophobe.co.uk/?p=835</guid>
		<description><![CDATA[According to BitDefender, the biggest risk to computer users is currently Trojan.AutorunINF.Gen, a generic family of malware abusing the Autorun feature in Microsoft Windows operating systems. By default, every removable storage device features an autorun.ini script that instructs the computer which file to execute when the device is plugged in. Malware authors are now tampering<a class="rmore" href="http://www.gizmophobe.co.uk/memory-sticks-becoming-source-malware/">&#160;&#160; Read More ...</a>
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://www.bitdefender.co.uk/" target="_blank">BitDefender</a>, the biggest risk to computer users is currently Trojan.AutorunINF.Gen, a generic family of malware abusing the Autorun feature in Microsoft Windows operating systems. By default, every removable storage device features an autorun.ini script that instructs the computer which file to execute when the device is plugged in. Malware authors are now tampering with these files to make it launch various malicious applications.</p>
<p>Trojan.Clicker.CM ranks second in BitDefender’s top ten e-threats list for November. This is mostly found on websites hosting illegal applications such as cracks, key generators and serial numbers for popular commercial software applications. The Trojan is mostly used to force advertisements inside the users’ browser in order to boost their advertisement revenue.</p>
<p>Ranking third this month is Win32.Worm.Downadup.Gen. The worm relies on the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (MS08-67) in order to spread on other computers in the local network and restricts users’ access to Windows Update and security vendors’ web pages. Newer variants of the worm also install rogue antivirus applications.</p>
<p>Trojan.Wimad takes the fourth place. The Trojan mostly exploits the capability of ASF files to automatically download the appropriate codec from a remote location in order to deploy infected binary files on the host system.</p>
<p>Exploit.PDF-JS.Gen is a generic detection for specially crafted PDF files which exploit different vulnerabilities found in Adobe PDF Reader&#8217;s Javascript engine, in order to execute malicious code on a user&#8217;s computer. Upon opening an infected PDF file, a specially crafted Javascript code triggers the download of malicious binaries from remote locations. The threat ranks fifth this month.</p>
<p>Win32.Sality.OG ranks sixth. It is a polymorphic file infector that appends its encrypted code to executable files (.exe and .scr binaries). In order to hide its presence on the infected machine, it deploys a rootkit and attempts to kill antivirus applications installed locally.</p>
<p>Seventh place goes to Trojan.Autorun.AET, a malicious code spreading via the Windows shared folders, as well as through removable storage devices. The Trojan exploits the Autorun feature implemented in Windows for automatically launching applications when an infected storage device is plugged in.</p>
<p>Worm.Autorun.VHG is an Internet /network worm that exploits the Windows MS08-067 vulnerability in order to execute itself remotely using a specially crafted RPC (remote procedure call) package (an approach also used by Win32.Worm.Downadup). The worm ranks eighth in this month’s top ten.</p>
<p>In ninth position, Trojan.Inject.RA is a password-stealing Trojan that mostly targets Lineage II computer players. This specific variant has a key logging component that intercepts users’ keystrokes and sends them to a remote attacker via HTTP or SMTP protocols.</p>
<p>Trojan.Downloader.Bredolab.AZ ranks tenth in this month’s list. Disguised as a Microsoft Word document, the Trojan drops a DLL file and registers it as a Browser Helper Object. Trojan.Downloader.Bredolab.AZ monitors users’ keyboard input via a key logging component and sends the data to a website located in Russia.</p>
<p>BitDefender’s November 2009 top ten e-threats list includes:</p>
<p>1.	Trojan.AutorunINF.Gen	        8.45<br />
2.	Trojan.Clicker.CM	        7.87<br />
3.	Win32.Worm.Downadup.Gen	        5.62<br />
4.	Trojan.Wimad.Gen.1	        5.00<br />
5.	Exploit.PDF-JS.Gen	        3.23<br />
6.	Win32.Sality.OG	                2.57<br />
7.	Trojan.Autorun.AET	        2.05<br />
8.	Worm.Autorun.VHG	        1.59<br />
9.	Trojan.Inject.RA	        1.45<br />
10.	Trojan.Downloader.Bredolab.AZ	1.20<br />
OTHERS	                        60.97</p>
<p>To stay up-to-date on the latest e-threats, sign-up for BitDefender&#8217;s RSS feeds <a href="http://www.bitdefender.co.uk/site/Using-Rss-Feeds.html" target="_blank">here.</a></p>
<img src="http://www.gizmophobe.co.uk/?ak_action=api_record_view&id=835&type=feed" alt="" /><p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.gizmophobe.co.uk/memory-sticks-becoming-source-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest Malware Threats</title>
		<link>http://www.gizmophobe.co.uk/latest-malware-threats/</link>
		<comments>http://www.gizmophobe.co.uk/latest-malware-threats/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 10:35:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Malware Threats]]></category>
		<category><![CDATA[Top 10 Malware Threats]]></category>

		<guid isPermaLink="false">http://www.gizmophobe.co.uk/?p=713</guid>
		<description><![CDATA[Web-based e-threats continue to dominate during the first month of 2009, according to BitDefender’s Top Ten analysis. Leading the pack was Trojan.Clicker.CM with a share of 5.40 percent. This device displays a significant number of commercial pop-up windows in the background of the user’s Web browser in order to lure the user to click. The<a class="rmore" href="http://www.gizmophobe.co.uk/latest-malware-threats/">&#160;&#160; Read More ...</a>
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Web-based e-threats continue to dominate during the first month of 2009, according to BitDefender’s Top Ten analysis. Leading the pack was Trojan.Clicker.CM with a share of 5.40 percent. This device displays a significant number of commercial pop-up windows in the background of the user’s Web browser in order to lure the user to click. The aim is to generate profits for advertisements registered within a pay-per-click system. To display the ads successfully, the Trojan uses several functions that bypass the Norton® Internet Security Pop-up Blocker.</p>
<p>Trojan Wimad.Gen.1 and Trojan.Downloader.Wimad.A succeeded in raising 6.88 percent in January, making them some of the most common e-threats in the wild. Part of a very large family, these Trojans are spread with the aid of a network of malicious websites. Usually distributed via e-mail spam campaigns as a 3.5 MB .wma attachment and bearing the name of some popular artists, the disguised Trojan automatically opens the Web browser in order to retrieve the “appropriate” codec, which is, in effect, another piece of adware – Adware.PlayMp3z.A.</p>
<p>As predicted by BitDefender’s E-Threat Landscape Report, the exploits increased their volume in the last month, holding no less than 4 positions and almost 12 percent in the current Top 10. For instance, Trojan.Exploit.SSX abuses vulnerable sites when a malicious SQL code is injected into their databases. The result is an invisible iFrame element that redirects the user to an infected Web site that attempts to download and install several malicious payloads.</p>
<p>Last but not least, autorun infectors and downloaders occupied the remaining positions, with another noteworthy comeback of Packer.Malware.NSAnti.1 with its 2.09 percent. This malware with worm functionality spreads via infected Web sites or through maliciously crafted autorun.inf files within removable devices. NSAnti corrupts Internet Explorer® behavior and steals user names and passwords for online games, such as Silkroad Online or Lineage.</p>
<p>“The beginning of 2009 showed two important trends,” said Head of BitDefender Antimalware Research, Sorin Dudea. “First, that Web-based distributed malware is still the most successful type of e-threat in the wild and secondly: that previous productive breeds are back with the same or even higher percentage. This confirms that the level of user awareness in terms of system security remains very low for defensive activities, such as patching the OS with the latest fixes, updating security suites or surfing the Web cautiously.”</p>
<p>BitDefender’s January 2009 Top 10 E-Threat list includes:</p>
<p>1.	Trojan.Clicker.CM                     	5.40%<br />
2.	Trojan.Wimad.Gen.1                  4.32%<br />
3.	Trojan.AutorunINF.Gen            	4.22%<br />
4.	Trojan.Downloader.Js.Agent.F   3.79%<br />
5.	Trojan.Exploit.ANPI                   3.59%<br />
6.	Trojan.Exploit.SSX                     3.36%<br />
7.	Exploit.SinaDLoader.A               2.70%<br />
8.	Trojan.Downloader.Wimad.A    	2.56%<br />
9.	Exploit.HTML.Agent.AO            	2.30%<br />
10.	Packer.Malware.NSAnti.1        	2.09%</p>
<p>Other malware                             	65.67%</p>
<p>For More information see <a title="Goes to website of: www.bitdefender.co.uk" href="http://www.bitdefender.co.uk/" target="_blank">www.bitdefender.co.uk</a></p>
<img src="http://www.gizmophobe.co.uk/?ak_action=api_record_view&id=713&type=feed" alt="" /><p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.gizmophobe.co.uk/latest-malware-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

