Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
1
vote
1 answer

String search and replace across an entire database

After an exploit on an ASP.NET site, the client was left with a specific string of malware code sprayed across the entire database, multiple columns of multiple tables. The prepended string is consistent and doesn't change from table to table, so…
tylerl
  • 15,055
  • 7
  • 51
  • 72
1
vote
1 answer

Folders on our server2003-share are being "hidden", replaced by .exe files

We have had following problem on our Windows2003 server for weeks now, every day the folder on our share are being made hidden and replaced by .exe files with the same names as the original folders. I can "Un-hide" them and hide or remove the .exe…
Otto Ardeby
  • 11
  • 1
  • 2
1
vote
1 answer

Anti-Malware Antivirus for Linux Web Server?

Does anyone have experience running anti-virus software on a Linux web server, especially CentOS, and what do you recommend? I'm interested in putting it on a web server we have as one more method for detecting and preventing website compromises…
sa289
  • 1,318
  • 2
  • 18
  • 44
1
vote
1 answer

Hyper-V or VMware - Find all modifications/changes made between 2 Snapshots

I would like to use either Hyper-V or Vmware in order to find out after taking a Clean Base snapshot and a modified snapshot and what the modifications/differences and what was changed between the two images. VMware ThinApp is the closest thing I…
brink668
  • 11
  • 1
1
vote
2 answers

Got a malware on my hosting provider which infect JavaScript files .. how do I find the entry point?

This morning some sites which are hosted on the server as me started triggering malware alerts and started to redirect traffic to external sites. I've found out that a line of packed javascript was added to many js files across the server. What the…
h3.
  • 189
  • 3
  • 9
1
vote
4 answers

Recurring virus infection on a domain workstation

One of our users is having a recurring problem with a virus. It has happened to this user on two different machines, in each instance infecting the same program with the same virus. Malware bytes detects the malware, and yesterday I cleaned the…
kafka
  • 547
  • 2
  • 15
  • 27
1
vote
2 answers

Program to log when files are written to a folder

One of our companies server seems to have fallen victim to a php backdoor attack. I've managed to located and close several holes, but one seems to persist that is writing a php/webshell backdoor into our C:/windows/temp. Microsoft Security…
NSjonas
  • 113
  • 4
1
vote
2 answers

One machine blocked from a single server, and only when it's at this physical location?

I host an e-commerce website for a client who suddenly is unable to access it from his computer. He can ping the server, he can SSH in, but cannot load the website in any browser we've tried: IE, Firefox, Chrome, Opera. Other machines at this…
rymo
  • 513
  • 1
  • 3
  • 13
1
vote
4 answers

sendmail sending mail to recipients I don’t know of; possible spam host

Recently I did an audit of my machine with logwatch and found out that my machine sends around 582 mails everyday. STATISTICS ---------- Messages To Recipients: 582 Addressed Recipients: 582 Bytes Transferred: 444985 Messages No…
Quintin Par
  • 4,373
  • 11
  • 49
  • 72
1
vote
2 answers

Amazon EC2 Morto worm and Windows RDP

We run an Amazon EC2 Windows instance and recently received an email from Amazon warning us that RDP is open to everybody and there is a new threat in the wild that may exploit this. The security group of the server in question allows access to RDP…
1
vote
1 answer

Restrict number of parallel connections on Apache server

I'm on an Ubuntu server running Apache2. I would like to protect myself against (d)dos and syn flood attacks and therefore try to limit the number of parallel connections per client IP. I've heard iptables can do this job, and I've had a look at…
sqren
  • 249
  • 1
  • 13
1
vote
1 answer

How can I limit Googlebot's crawl rate?

I have a problem with one of my servers. Google opens lots of http connections to the apache server and basically performs a slowloris attack. This netstat call results in the following output netstat -plant|grep :80|awk '{print $5}'|cut -d:…
Philip
  • 165
  • 3
  • 13
1
vote
0 answers

Scan a NAS Device with Microsoft Forefront Endpoint Protection

We are having problems with viruses sneaking through our virus scanner and onto our NAS and I want to scan the whole NAS. If I attempt to run a scan on the whole drive using the GUI for Forefront Endpoint Protection it sits at the initial screen…
1
vote
2 answers

addthis_widget detected as virus

We use sunbelts VIPRE enterprise systems, and I was alerted to almost every computer in the company having this and being quarantined. Is anyone familiar with addthis_widget.js. It detects it as a trojan.js.redirector.bg , I'm not sure if this is a…
Jeff
  • 1,089
  • 5
  • 26
  • 46
1
vote
7 answers

I am starting to think that Prevx.com isnt a legit site...but heres my long-winded question

I apologize in advance for the long-winded post. I posted it all because I believe its informative and may be useful. Also, I posted my question at the end. Moments ago I was RDC to a file server in my home (from inside my home). I had opened…
cop1152
  • 2,656
  • 3
  • 21
  • 32