Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
339 questions
12
votes
13 answers

Make browsing safe for porn surfers

At several places I've done some work at, I have a suspicion that some of the executives browse porn on their work computers. It appears this porn surfing has lead to virus infections on their computers despite the presence of an anti-virus. …
Brett G
  • 2,023
6
votes
4 answers

Is this is a malware invocation of Powershell?

I got a file that was .avi at the fist glance, but then I found out that in fact this is a .lnk file, but it was too late. And the target element attribute of that file is C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoPr -WINd 1 -eXEc…
Yoda
  • 191
2
votes
0 answers

Detecting .Money Ransomware on Windows Server 2019

Problem A few weeks back we got hit with a Dharma Ransomware variant called "Money". We made the incorrect assumption that this variant began right at the time the user opened the malicious attachment or link. Saturday we found out that it was…
Aaron
  • 311
1
vote
0 answers

How to get rid of adfly javascript code to be inserted automatically in my web pages

in my website, adfly's javascript code is inserted automatically after every few hours in index.php and default.php web pages. Every time I remove these unwanted code from both pages manually and that code reappear again after few hours. I have no…
K Ahir
  • 111
1
vote
1 answer

How to add wildcards to Linux Malware Detect ignore_paths

I am using Linux Malware Detect to scan and report on malware, but on a daily basis I receive alerts for malware in users emails (mainly spam folder). I do not want alerts for this, the spam folders are cleaned often, and the users may clean it…
1
vote
1 answer

What are best practices for defense against CryptoLocker type threats in an Active Directory environment?

What are best practices for defense against CryptoLocker type threats in an Active Directory environment? Are there Group Policies that could help? NTFS permissions? Anti-virus software?
Corey
  • 2,081
1
vote
5 answers

Virus that duplicates word documents as exe

We are facing a virus problem on our network, but I'm unable to identify it, so we can't properly deal with it. The symptoms are that the virus duplicates a word document (.doc) generating a new archive with the same name, but with an exe extension,…
Bob Rivers
  • 516
  • 5
  • 13
0
votes
1 answer

Removing a control kit from the server

The server my site is on was infected using the (pardon my obfuscation) Y-E-S E-x-p-l-o-i-t S-y-s-t-e-m It is a "control kit". I found out some info about it from http://cassandrasecurity.com/?p=282 How can I remove this control kit and secure the…
Cyclone
  • 206
  • 3
  • 8
0
votes
5 answers

How to get an email report of whatever the most recent maldet scan is?

The maldet / Rfxn Linux MalDetect docs give this for getting an email report even when nothing was found: -e, --report SCANID email View scan report of most recent scan or of a specific SCANID and optionally e-mail the report to a supplied…
0
votes
0 answers

Suspicious "sys0972500-1.php", I didn't put it on my server

Before 2 days I found inside the httpdocc a new folder which name was css. Inside this folder I found a file named sys0972500-1.php , which it caused send thousands spam emails from my server. I deleted it and today I had the same problem. What…
Andrew
  • 1
0
votes
1 answer

Trying to hunt down malware on my server

Possible Duplicate: My server’s been hacked EMERGENCY A server of mine recently suffered a malware attack. I've since cleaned the server up a bit, upgraded a variety of wordpress installs and timthumb files, and removed a lot of old and archived…
PJ.
  • 213
0
votes
3 answers

Problem for my website, Some attack pages intentionally distribute harmful software

Possible Duplicate: My server's been hacked EMERGENCY Some pages of my website are distributing harmful software. How do I investigate and fix this?
userad
  • 167
0
votes
3 answers

Determine how the worm spread in the network

We had worm infestation problem in our network. I have cleaned all the worms and have taken appropiate steps. I wanted to how do you determine how the worm got spread in the network. Thanks, Gary.. thanks a lot guys for all the interesting…
0
votes
2 answers

Has anyone seen gvtlsysguard.exe in the wild?

has anyone seen this file before "gvtlsysguard.exe" and have any idea what it is? This weekend, I noticed one of my users had this file in their user profile's Local Settings folder and somehow they wrote a registry key to…
Jacob
  • 443
0
votes
2 answers

Heeeelp! False positives from ZoneAlarm Force Field on my website will scare users away

I recently helped create a website for a conference that I am helping to host. We mailed out about 30,000 brochures and are expecting the big wave of traffic to start in a day or two. However, we keep on getting reports from people visiting the…
None
1
2