<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Viruses</title>
	<atom:link href="http://blog.mxlab.eu/tag/viruses/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Viruses</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Social network Hi5 subject to malware campaign</title>
		<link>http://blog.mxlab.eu/2009/09/09/social-network-hi5-subject-to-malware-campaign/</link>
		<comments>http://blog.mxlab.eu/2009/09/09/social-network-hi5-subject-to-malware-campaign/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 20:52:19 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Hi5]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=540</guid>
		<description><![CDATA[The social network Hi5, a place where you can connect to your fiends, is target of a malware distribution campaign. MX Lab intercepted emails with the subject &#8221;Jessica would like to be your friend on hi5!&#8221; with an attachment named Invitation Card.zip that includes the archived file attachment.pdf_[many _spaces]___.exe. The From address is invitations@hi5.com but this is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=540&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The social network Hi5, a place where you can connect to your fiends, is target of a malware distribution campaign. MX Lab intercepted emails with the subject &#8221;Jessica would like to be your friend on hi5!&#8221; with an attachment named Invitation Card.zip that includes the archived file attachment.pdf_[many _spaces]___.exe.</p>
<p>The From address is invitations@hi5.com but this is spoofed. The body of the email looks quite genuine and coming from Hi5. If you receive such a message, namely a request to connect from a so called friend, there is normally no file of 244 kB attached to the email.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090909_Hi5_malware.jpg" alt="" width="450" height="356" /></p>
<p>The trojan is known as Win32:Rootkit-gen (Avast), W32/Autorun-AQL (Sophos), GData (Backdoor.Bot.103388) or VirTool:Win32/Injector.gen!AH (Microsoft).</p>
<p>the trojan has the threat characteristics of ZBot &#8211; a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</p>
<p>There are stealth-mode characteristics common to Rootkits and the option to communicate with SMTP engines to send out emails.</p>
<p>The trojan will create the files %System%\javaa.exe, %System%\jushred.exe and %System%\sdra64.exe on an infected system and the processes jushred.exe and javaa.exe will be running.</p>
<p>The hidden files %System%\lowsec\local.ds, %System%\lowsec\user.ds and %System%\lowsec\user.ds.lll and a hidden folder %System%\lowsec are created.</p>
<p>The system services ERSvc (Error Reporting Service) and wscsvc (Security Center) will be stopped and various registry edits will be performed.</p>
<p>The trojan can connect to remote resources on ports 43, 80, 1033 and 1035 and a connection with msnnews.webhop.org will be created.</p>
<p>The built-in SMTP engine will send emails for the distribution of the trojan towards other victims:</p>
<p>From: invitations@hi5.com<br />
Subject: Jessica would like to be your friend on hi5!<br />
Attachment: Invitation Card.zip</p>
<p>From: order-update@amazon.com<br />
Subject: Shipping update for your Amazon.com order 254-78546325-658742<br />
Attachment: Shipping documents.zip (334,919 bytes)</p>
<p>From: e-cards@hallmark.com<br />
Subject: You have received A Hallmark E-Card!<br />
Attachment: Postcard.zip (334,919 bytes)</p>
<p>VirusTotal <a href="http://www.virustotal.com/analisis/d6f18a462d933829f11eb91240c02f92a223078589bebd90f29d7f9fea00afc6-1252496421" target="_blank">permlink</a> and MD5: 4df3cf28fae7b5b02b2d9f4e03b4dbbd.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/540/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=540&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/09/09/social-network-hi5-subject-to-malware-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090909_Hi5_malware.jpg" medium="image" />
	</item>
		<item>
		<title>Managed Anti Virus powered by Trend Mirco</title>
		<link>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/</link>
		<comments>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 15:13:58 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/10/12/49/</guid>
		<description><![CDATA[MX Lab offers a fully managed antivirus and comprehensive security protection against today’s complex, blended threats and web-based attacks using the Trend Micro™ OfficeScan™ technology. Visit MX Lab for more information.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=49&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab offers a fully managed antivirus and comprehensive security protection against today’s complex, blended threats and web-based attacks using the Trend Micro™ OfficeScan™ technology. Visit <a href="http://www.mxlab.be/en/services/managed_antivirus_officescan.html" target="_blank">MX Lab</a> for more information.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/49/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/49/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=49&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>