You’ve been iframed

Wednesday, April 2nd, 2008

Injected iframes into legitimate sites are becoming more and more common these days.  One of the latest targets is a Chinese government site at www.zhangzhu.gov.cn: Please note that while the site adminstrators have been notified, the injected iframe is still present in the site at the time of this posting. The iframe ...

F-Secure predicts million viruses by end of 2008

Wednesday, April 2nd, 2008

The amount of new malware has never been higher. Our labs are receiving an average of 25,000 malware samples every day, seven days a week. If this trend continues, the total number of viruses and Trojans will pass the one million mark by the end of 2008. While there are more ...

Guarding the guardians: A story of PGP key ring theft

Thursday, March 27th, 2008

A couple of weeks ago, we received a CHM, or Windows Help file, embedded in e-mail as part of a targeted attack campaign against an NGO. Virus detection was near zero. On Virustotal.com, two solutions actually flagged it as malicious. After decompiling the CHM file, which you can easily do using tools ...

What is fveNotify.exe in Windows Vista?

Saturday, March 8th, 2008

You may see a Startup entry called fveNotify.exe and not know what it's for because the description you see in the msconfig utility is not that clear. Here's the details: File Name: fveNotify.exe Display Name: Microsoft BitLocker Drive Encryption Notification Utility Description: BitLocker Drive Encryption Notification Utility Publisher: Microsoft Corporation Digitally Signed By: Microsoft Windows ...

Click here to become infected

Saturday, March 8th, 2008

Users should be wary of pressing the 'click here to remove' link on spam messages because it serves to confirm to spammers that junk mail messages are being read. Such email addresses can be sold at a premium to other spammers. That's reason enough to simply delete spam messages, but a ...