Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > New Trojan Cuts Off PCs From Security Update Sites

Reply
Thread Tools Display Modes

New Trojan Cuts Off PCs From Security Update Sites

 
 
Mc
Guest
Posts: n/a

 
      07-01-2005
Just found this news article from June 30th. Not sure if it's related to the
issues here.
 
Reply With Quote
 
 
 
 
Mc
Guest
Posts: n/a

 
      07-01-2005
http://www.crn.com/sections/breaking...leId=164904300

By TechWeb News
1:27 PM EDT Thu. Jun. 30, 2005

A new Trojan is using a sophisticated technique to cut off infected
computers from anti-virus and security vendors' update sites, the Finnish
firm F-Secure said Thursday.

It's not uncommon for worms and Trojan horses to sever links to update
sites, but the until recently, said F-Secure, the method has been different:
modifying the Windows HOSTS file to redirect the domains of popular security
vendors to the local host so that the browser returns a blank page or error.

This Trojan, dubbed Fantibag.b by F-Secure (and Fantibag.a by Computer
Associates), however, blocks access by creating packet filtering policies
using the Microsoft RAS packet filtering API. The result: all inbound and
outbound packets between the user's machine and any of the 100+ filtered IP
addresses are then dropped, essentially cutting communication and preventing
updates -- such as new malware signatures -- from being downloaded.

Among the filtered IP addresses are those belonging to Microsoft (including
Windows Update), Computer Associates, F-Secure, McAfee, Sophos, Symantec, and
Trend Micro.

Fantibag.b sports a tenuous connection with the more prevalent Mitglieder
Trojan, said Computer Associates; the former may be downloaded to systems
already compromised by Mitglieder.
 
Reply With Quote
 
Jupiter Jones [MVP]
Guest
Posts: n/a

 
      07-01-2005
There are many types of malware that prevents access to Windows Update.
Also anti virus, anti spyware sites as well as others can be targeted.
That is just one reason why it is important to keep your computer clean and
free of problems.

--
Jupiter Jones [MVP]
http://www3.telus.net/dandemar
http://www.dts-l.org


"Mc" <> wrote in message
news:E36DB673-513F-456F-9B5D-...
> Just found this news article from June 30th. Not sure if it's related to
> the
> issues here.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Desk top short cuts to internet sites Len Urban Windows Vista General Discussion 5 05-12-2009 08:48 PM
RE: A trojan that is redirecting to Google and shopping sites Mick Murphy Windows Vista Performance 0 02-12-2009 02:48 AM
Re: A trojan that is redirecting to Google and shopping sites DL Windows Vista Performance 0 02-11-2009 08:41 AM
security toolbar 7.1 (trojan zlob) joe Windows Vista General Discussion 4 01-01-2008 02:03 PM
Update Error, Security and AV Programs/Sites Wink, Blink & Fail HappyJack Windows Update 0 01-24-2005 02:51 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59