Jul 20, 2008

Microsoft Update Program Being Used By Hackers

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits

free web hosting

Microsoft Update Program Being Used By Hackers

Saint_Michael
Although I am bit surprise that no one really take about way back then, but it seems the hackers and crackers I starting to use the microsoft update downloading to transmit there malware and torjans to compromised computers. The reason being is that the Microsoft update program bypasses firewall security protocals and so when that malware is getting download, your firewall and virus programs will not pick it up. I know a few people turn it off and either download them manually or don't download them at all. So to toss out a warning, when you get he windows update pop up check to see if those are legit files, by either going to microsoft's website and downloading the updates from there or look and read the update bulletins and see if they match up.


Source

Here



Reply

TypoMage
Wow and my dad is always saying make sure to update and now it can not even be safe to update you Pc? Hmm that is kind of messed up? laugh.gif

Reply

jamers
msscan.exe is part of one such trojan

I'm dealing with recovery myself and I need some advice from an admin type guru before taking the destructive way out!

I have server 2000 spk4 and after running trend micros "House Call" to do an online detection and clean up it found and removed all but the "Microsoft Security Update" (MSU) trojan, a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans (according to bleepingcomputer). Before running anything I wanted to stop some processes and try removing manually but my task manager was greyed out, (panic starts to set in). That's when I ran the house call... Then I booted into safe mode and deleted the directory for Microsoft Security Update and ran regedit to remove the MSU keys in both locations as listed by (don't remember the site name) manual removal instructions. OK, feeling better now the reboot and hmmmmm post beep, then pause then another post beep. This is strange, I don't recall having 2 posts but whatever. Wait for login and as soon as I press ctrl alt del the keyboard and mouse hang. Panic is back, feeling like this trojan is locking me out of my server so it can run some nasty mass mailer program or something. Tried booting into safe mode again but now the keyboard does nothing at any time during post. Can't get into safe mode, more panic. Tried booting into bios, can't get into bios, big panic attack. Can't boot from windows CD, don't have recovery disks or setup disks. Tried making them on my other box (win 98SE) but when booting the server with the setup boot disk I get disk IO error. Duh, too much panic I think maybe these disks can't be made on a 98 box and used to setup win2000 because of the different file system. So here I sit wondering if there is a way to get my server back without destroying all my data. I am willing to reinstall Windows if I can but would like to avoid having to install my apps again.

When I boot the server with the ethernet disconnected there is an error starting a service... or something like that. One or more services failed to start.

 

 

 


Reply

75rLs3U4
It's supposed it will happen. The talon d'Achille of Microsoft are the software that "dressed" his operative system. Microsoft has the concept that must fill the OS with software that emulates real antivirus and real firewalls to compete with other software creators.

The problem is that left big holes that let hackers and attackers to take on assault not only the operative system, also the software, documents and everything that is inside of the computer.

I was thinking when Bill Gates left the CEO, maybe the things change to make more strong the software to have a better Windows, Office and other stuff made by the Redmond boys.

But, Mickey Mouse, they bet to still put more garbage instead of software and their systems get bigger and slower. Pretty, but very unusable for the people with old machines.

And this is an advantage for hackers, crackers and other people that likes to found the holes left by the programming team of Redmond. So, I have an advise for they: the smaller: the safest.

If they reduce the components to the core and stay there, will be more difficult to a hacker to found new holes in a smaller footprint operative system. cool.gif

Reply

lilemi
That's crazy, it's the last place I'd expect a hacker to come into your computer by: when my computer tells me to update I always allow it to automatically. My parents are always telling me to value updates over virus scans, because you need to be able to trap the newest viruses... How ironic is that? You download the latest updates to stop the latest viruses, and you get the latest viruses instead! happy.gif As long as McAfee updates don't have viruses though, I'm cool... McAfee is the best virus protection in my opinion and I would *hate* it if I never knew whether I was downloading a virus or virus protection.

Reply

Icarus
Yeah I saw this on another site and didn't think much of it, till I realized the date of the article, and thought, "Oh crap, I might have downloaded it," and turned off Automatic Updates.

Can anyone tell me the name of the malicious files? I don't think I'm infected, but I want to do a search for them just to make sure.

Reply

jamers
QUOTE(Icarus @ Sep 9 2007, 11:01 PM) *
Yeah I saw this on another site and didn't think much of it, till I realized the date of the article, and thought, "Oh crap, I might have downloaded it," and turned off Automatic Updates.

Can anyone tell me the name of the malicious files? I don't think I'm infected, but I want to do a search for them just to make sure.



Well I know msscan.exe is part of a bad trojan.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Similar Topics

Keywords : microsoft update program hackers

  1. Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read - (8)
  2. Windows 7-windows Live Ties - Microsoft is at it again (0)
    In an internal memo Microsoft detailed how it plans to tie Win7 and Windows Live. It seems these
    guys never learn. They don't don't get tired of monopolizing everything. I just pray the
    anti-trust guys will do a good job on this one. Below is part of the blog by Mary Jo Foley about the
    memo titled " Microsoft internal memo details Windows 7-Windows Live ties ": " In
    January, I mentioned an internal Microsoft memo I had seen which provided details of how Microsoft
    plans to more tightly integrate its Windows 7 operating system with Windows Live service...
  3. Hackers Focus Efforts On Firefox, Safari, And Office - (1)
    QUOTE Many people are switching from Internet Explorer to alternative browsers such as Firefox
    and Safari. Though that might make them feel more secure, the shift has also opened new doors for
    bad guys. Case in point: We have no IE bugs to report this month, but both Firefox and Safari have
    been hit hard. So forget the idea that just because you've switched to a new browser,
    you're magically safer. You may be for a time, but to stay safe with any software, you need to
    keep current with fixes. Firefox Holes In a somewhat dubious recognition of Firefox's...
  4. Xp Sp3 - Has microsoft delivered. (5)
    I am one guy who has always beleaved that when MS made XPsp2 they raised the standards for them
    selves. the package was just too good for their own good. When Sp3 came out I didnt hesitate to
    download it and what did I get? The first thing that i noticed was I could no longer use remote
    desktop. i'm sure this has since been rectified in RC2 but it realy turned me off. I never
    realised any gains in the SP. Still on the subject I found Adrian Kingsley-Hughes' blog titled
    ' XP SP3 performance gains - Nothing to write home about ' interesting He wrote: QU...
  5. Best Anti-virus Program? [closed For Redundancy] - (4)
    I want to lnow which one is the best anti-virus program because i'm having serious problems
    regarding all these viruses and spywares.So i want to know which is the best one around which i
    should use...
  6. Iphone Update Disable Hacked Phones - (5)
    After reading the article it is obvious what the update was for besides adding in new services and
    updates, however, it took all of what, two weeks to hack the IPhone? So I doubt it will that long
    to figure out what apple change to disable the hack phones. I found this particular quote amusing,
    "...company officials insisted they were "not proactively" trying to make hacked iPhones useless."
    Heck I would if I knew I would be losing millions of dollars a month on a phone that that was hacked
    and used by another phone provider, but like I said earlier it won't take ...
  7. Hole In Microsoft Messenger Program Requires A Immediate Update - For Users of MSN Messenger 6.2, 7.0 and 7.5 versions of MSN Messenger (0)
    SOURCE Well it seems that Microsoft found a huge hole in MSN Messenger that was bad enough that
    they want people to upgrade to the current Messenger which is Live 8.1 or something like that. As
    for details on the problem they just said the following, "..which let hackers embed malicious code
    in Web chat invitations to users." and that they found this problem in "6.2, 7.0 and 7.5, as well as
    Windows Live Messenger 8.0." Although it was interesting to know that people were actually
    complaining about Live Messenger being a resource hog, well the last time I check msn w...
  8. Myspace Has A Team Of Hackers - (7)
    I found this to be very interesting, a group of hackers routinly attack Myspace to find flaws and it
    looks like they have already started finding them /laugh.gif" style="vertical-align:middle"
    emoid=":lol:" border="0" alt="laugh.gif" /> I find it funny that they actually told Myspace that
    they were going to do this, although I doubt they could find them anyways. /laugh.gif"
    style="vertical-align:middle" emoid=":lol:" border="0" alt="laugh.gif" /> But again they already
    found one which has to do with the url set up of which I won't post because of the legality o...
  9. Phpbb Hackers - LOL (21)
    I got an email today: The following is an email sent to you by an administrator of "KORUPTION OWNZ
    YOUR S****Y SITE". If this message is spam, contains abusive or other comments you find offensive
    please contact the webmaster of the board at the following address: korupted@korupted.com Include
    this full email (particularly the headers). Message sent to you follows:
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Dear members. Your petty website has been hacked. The hacker's
    name is Koruption. Next time dont use a outdated verison of phpbb b***hes So im a bit pissed off
    and chec...
  10. Mcafee Lets Users Download Rootkit Program For Free - (2)
    Since the beginning of 2007 a lot of the security reports I have been reading have mentioning about
    hackers using rootkits to get into people's computers. Google defines a rootkit as a set of
    programs used to hack into a system and gain administrative-level access. Once a program has gained
    access, it can be used to monitor traffic and keystrokes; create a backdoor into the system for the
    hacker's use; alter log files; attack other machines on the network; and alter existing system
    tools to circumvent detection. Rootkits are an extreme form of System Modificatio...
  11. Spammers, Hackers Seize On Virginia Tech Shootings - (3)
    Ok to me I consider the sickest form of human idiots ever, bad enough you have some people mocking
    the shooter but now you got people using spam and hacking computers by using the Virginia Tech
    shootings, This person should be found and beating for using a tragic event like this and trying to
    profit from it. The spam/hack goes like this QUOTE If clicked, the link caused a computer to
    automatically download a malicious screensaver, called TERROR_EM_VIRGINIA.scr by Sophos, which
    installs a Trojan horse program that collects banking details, Cluley said. It was a...
  12. Microsoft Rumor... - From my Uncle. (17)
    My uncle said Microsoft are going to be sending viruses out via Windows Updates, he said if you do
    not have a genuine computer and you validate it you may get a virus. He said someone from PC World
    told him. I'm not exactly sure so don't go crazy, but just to tell you it may be true, maybe
    not....
  13. Microsoft Windows Dhcp Client Service Remote Code Execution Vulnerability - (0)
    What it is A exploit in the buggy OS of XP has been found, this one concering DHCP. OS effected
    Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows
    2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced
    Server SP4 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Datacenter Server SP1
    Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft
    Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Professional Microsof...
  14. Microsoft Warns Of Virus Entering Pcs Via Powerpoint - (3)
    QUOTE Microsoft has alerted users of a virus that enters PCs through the PowerPoint program. The
    virus attaches itself to a contaminated presentation that when accessed installs a keylogging
    software on a computer. Users are being warned to take precautions because Microsoft patch that
    guards against the security loophole will still be tentatively released on August 8. Reports say
    the virus has infected relatively few people with the poisoned presentation. Malicious hackers used
    the bug found in PowerPoint 2000, 2002 and 2003. Security experts report that the vir...
  15. Microsoft Ships First Vista Security Patches - yup, got that right -- VISTA (9)
    Microsoft Ships First Vista Security Patches http://www.eweek.com/article2/0,1895,1911406,00.asp
    QUOTE Microsoft Corp. has shipped the first critical security update for Windows Vista, the
    next version of its flagship operating system. Over the weekend, the company released patches for
    beta testers running the Windows Vista December CTP (Community Technology Preview) and Windows Vista
    Beta 1, and warned that the new operating system was vulnerable to a remote code execution flaw in
    the Graphics Rendering Engine. A Microsoft spokesperson told eWEEK that the Vi...
  16. Microsoft Plans Free Anti-Spyware Program - (12)
    Stepping up its fight against computer threats at the risk of alienating security businesses,
    Microsoft announced Tuesday it will give away a program to combat privacy-stealing and PC-clogging
    spyware and other virtual pests. Microsoft co-founder Bill Gates also unveiled plans to release
    antivirus tools for consumers and make a major security upgrade to its Internet Explorer Web
    browser. At the same time, he showed off new software for businesses to combat security threats.
    The moves are part of a wide-ranging effort by the world's largest software maker to impro...
  17. Firefox 1.5 Flaws - For Microsoft User (22)
    I got this information from mailing list. yesterday I didn't know why my pc always heavy to be
    loaded. and now i got the answer read Firefox Flaws For A Simple Way. if you use Mozilla
    Firefox 1.5 as your default browser. type Ctrl+Alt+del or open Task Manager. You will see how much
    memory being used by firefox. QUOTE(www.informationweek.com) On December 8, 2005, we published
    a story that wondered: Firefox 1.5: Not Ready For Prime Time? In response, some 450 (and climbing)
    InternetWeek, InformationWeek, TechWeb Pipelines, and Scot's Newsletter readers ha...
  18. Microsoft Plugs Windows Worm Holes - 14 flaws in Windows... (3)
    http://news.zdnet.com/2100-1009_22-5893344.html?tag=nl.e589 Here is another proof that the words
    'Windows' and 'Security' simply cannot go together... And yet another good reason
    for installing and start using Linux... Cheers! KoYoda...
  19. [exploit] Microsoft Windows 2000 Plug And Play - (1)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit #2 (MS05-039) /*
    HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2 * * Copyright © 2005 houseofdabus. * * (MS05-039)
    Microsoft Windows Plug-and-Play Service Remote Overflow * Universal Exploit + no crash shellcode * *
    .:: ::. * * --------------------------------------------------------------------- * Description: * A
    remote code execution and local elevation of privilege * vulnerability exists in Plug and Play that
    could allow an * attacker who successfully exploited this vulnerability to take * complete con...
  20. [exploit] Microsoft Server Message Block - (SMB) Remote Exploit (MS05-011) (0)
    Microsoft Server Message Block (SMB) Remote Exploit (MS05-011) /* * Windows SMB Client
    Transaction Response Handling * * MS05-011 * CAN-2005-0045 * * This works against Win2k * *
    cybertronic gmx net * http://www.livejournal.com/users/cybertronic/ * * usage: * gcc -o mssmb_poc
    mssmb_poc.c * ./mssmb_poc * * connect via \\ip * and hit the netbios folder! * *
    ***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690, * 0x00000000) * PAGE_FAULT_IN_NONPAGED_AREA *
    * The Client reboots immediately * * Technical Details: * ----------------- * * The driver MRXSMB.S...
  21. [exploit] Microsoft Internet Explorer Com Objects - File Download Exploit (MS05-038) (0)
    Microsoft Internet Explorer COM Objects File Download Exploit (MS05-038)
    /*+++++++++++++++++++++++++++++++++++++++++++++++ Ms05 038 exploit POC Write By ZwelL 2005 8 11
    http://www.donews.net/zwell zwell@sohu.com Some code belongs to Lion(cnhonker), regards to him.
    This code tested on Windows 2003 -----------------------------------------------*/ #include
    #include #pragma comment(lib, "ws2_32") // Use for find the ASM code #define PROC_BEGIN __asm
    _emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm
    _emit 0x90\...
  22. [exploit] Microsoft Windows 2000 Plug And Play - Universal Exploit (0)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit (MS05-039) /* Windows 2000
    universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */
    #include #include #include #include #include #include #include #pragma comment(lib,
    "mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
    {0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
    0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
    0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,
    0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,0x0...
  23. [exploit] Microsoft Windows Remote Desktop Dos - (0)
    Microsoft Windows Remote Desktop Protocol DoS Exploit (MS05-041) // Windows XP SP2
    'rdpwd.sys' Remote Kernel DoS // // Discovered by: // Tom Ferris // tommy
    security-protocols com // // Tested on: // Microsoft Windows XP SP2 // // Usage (SPIKE) :
    ./generic_send_tcp 192.168.1.100 3389 remoteass.spk 1 0 // // 8/9/2005 Security-Protocols.com // //
    This program is free software; you can redistribute it and/or modify it under // the terms of the
    GNU General Public License version 2, 1991 as published by // the Free Software Foundation.
    s_block_start("packet_1...
  24. Microsoft Windows Plug-and-play Exploit - (0)
    wow, you can get this famous vulnerabilty exploit here: http://www.milw0rm.com/id.php?id=1149
    have fun /smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /> ...
  25. Microsoft Internet Explorer "msdds.dll" Remote Cod - Date : 17/08/2005 (1)
    Take a look at this exploit! It's 0-day /tongue.gif' border='0'
    style='vertical-align:middle' alt='tongue.gif' /> Advisory : FrSIRT/ADV-2005-1450 Rated as :
    Critical Note : It is currently unclear whether the "Msdds.dll" library is installed with
    Microsoft Office, Microsoft Visual Studio, or with other applications. More information will be
    provided when further details are available. #!/usr/bin/perl
    ####################################################### # # Microsoft Internet Explorer "Msdds.dll"
    Remote Code Execution Exploit (0day) # # Bindshell on...
  26. Microsoft Windows Plug-and-play Service Remote Ove - (3)
    This is the c code you can compile it with lcc win 32 or gcc or virtual c++ ... /* Windows 2000
    universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */
    #define WIN32_LEAN_AND_MEAN #include #include #include #include #include #include
    #include #pragma comment(lib, "mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
    {0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
    0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
    0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00, 0x30,0x00,...
  27. Microsoft Internet Explorer Javaprxy.dll Vul. - (5)
    Internet Explorer allows users to utilize Windows's COM Objects. A vulnerability with
    javaprxy.dll allows attackers to craft a special HTML code that will cause Internet Explorer to
    execute a remote command by using one of Windows's COM Objects. u can find the patches here :
    http://www.microsoft.com/technet/security/...n/MS05-037.mspx also i just posted the exploit link
    here for educational perposes : http://www.frsirt.com/exploits/20050702.ie...yexploit.pl.php ...
  28. Another Firefox Security Update - Firefox v1.0.3 (6)
    Yes, another update. You can read the fixes at ZDNet or here at the Mozilla Release Notes .
    Before installing v1.0.3 make sure that the directory you've chosen to install into is clean and
    doesn't contain any previous Firefox installations! (known issue) Greetz, Rik©...
  29. Windows Update Email Scam - its a trojen horse (8)
    QUOTE A new scam by hackers has some people believing they are receiving an e-mail about a
    critical update to Windows when in actuality they are installing a Trojan horse, Sophos said on
    Friday. The e-mail directs victims to a fake version of the Windows Update site, where there are
    links to download the malicious "patches." "The email uses the Microsoft branding and style so to
    the casual observer it appears to be legitimate," Gregg Mastoras, Senior Security Analyst at Sophos,
    told BetaNews. If users download the "patches," they are actually installing the Troj/DS...
  30. Firefox Security Update (firefox 1.0.2) - Released 23-03-2005 (14)
    Yesterday Mozilla (foundation) released another security update for Firefox. QUOTE(Mozilla
    Foundation) March 23, 2005, (Mountain View, CA). The Mozilla Foundation, a non-profit organization
    dedicated to preserving choice and promoting innovation on the Internet, today announced a security
    update for its Firefox Web browser. The update is a proactive security release to patch a bug
    identified by Internet Security Systems, a premier security research, products, and services
    company. No known exploits of the bug have been reported prior to the update's release. ...



Looking for microsft, update, program, hackers

Searching Video's for microsft, update, program, hackers
Hackers
Hijack A
Half-million
Sites: Phpbb
Forum Users
Must Read
Windows
7-windows
Live Ties
Microsoft is
at it again
Hackers
Focus
Efforts On
Firefox,
Safari, And
Office
Xp Sp3 Has
microsoft
delivered.
Best
Anti-virus
Program?
[closed For
Redundancy]
Iphone
Update
Disable
Hacked
Phones
Hole In
Microsoft
Messenger
Program
Requires A
Immediate
Update For
Users of MSN
Messenger
6.2, 7.0 and
7.5 versions
of MSN
Messenger
Myspace Has
A Team Of
Hackers
Phpbb
Hackers LOL
Mcafee Lets
Users
Download
Rootkit
Program For
Free
Spammers,
Hackers
Seize On
Virginia
Tech
Shootings
Microsoft
Rumor...
From my
Uncle.
Microsoft
Windows Dhcp
Client
Service
Remote Code
Execution
Vulnerabilit
y
Microsoft
Warns Of
Virus
Entering Pcs
Via
Powerpoint
Microsoft
Ships First
Vista
Security
Patches yup,
got that
right --
VISTA
Microsoft
Plans Free
Anti-Spyware
Program
Firefox 1.5
Flaws For
Microsoft
User
Microsoft
Plugs
Windows Worm
Holes 14
flaws in
Windows...
[exploit]
Microsoft
Windows 2000
Plug And
Play
[exploit]
Microsoft
Server
Message
Block (SMB)
Remote
Exploit
(MS05-011)
[exploit]
Microsoft
Internet
Explorer Com
Objects File
Download
Exploit
(MS05-038)
[exploit]
Microsoft
Windows 2000
Plug And
Play
Universal
Exploit
[exploit]
Microsoft
Windows
Remote
Desktop Dos
Microsoft
Windows
Plug-and-pla
y Exploit
Microsoft
Internet
Explorer
"msdds.
dll"
Remote Cod
Date :
17/08/2005
Microsoft
Windows
Plug-and-pla
y Service
Remote Ove
Microsoft
Internet
Explorer
Javaprxy.dll
Vul.
Another
Firefox
Security
Update
Firefox
v1.0.3
Windows
Update Email
Scam its a
trojen horse
Firefox
Security
Update
(firefox
1.0.2)
Released
23-03-2005
advertisement



Microsoft Update Program Being Used By Hackers



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE