Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
0
votes
1 answer

Apache2 Mod_spamhaus Whitelist

We are using Apache2 mod_spamhaus and many customers were banned using the "Post" method. There is no way to deny mod_spamhaus ban continuously our customers making false positive or ban customers only cause their ip is on a range of banned…
User-N
  • 255
  • 1
  • 3
  • 6
0
votes
1 answer

Monitoring "external" worm activity remotely

Some of our computers in our company has been infected with the worm Conficker. We don't know the source of the infection, but I want to monitoring the outside activity to see if we are still infected (we have already "protect" some computers).…
ABu
  • 499
  • 1
  • 6
  • 19
0
votes
2 answers

Server compromised, how deep is the intrusion when PHP files are changed in folder without write permissions

I know there have been a lot of similar questions, but none of them covered this specific question: I found on almost all PHP files on a clients server script injections, it was actually the script mentioned here:…
Larzan
  • 105
  • 4
0
votes
1 answer

sed comand - remove virus from wordpress

I have malicious code in every php file. This malicius code is auto paste at the beginning of file. I want to remove this with UNIX command from console. This is malicious code: I write this RegExp,…
EliaszKubala
  • 127
  • 1
  • 7
0
votes
0 answers

rkhunter reports suspicious activity /bin/usr/wget and killall permissions changed

Sorry about the long post but please bear with me. I'm wondering if my system has been compromised. I've had issues in the past on this VM server with a Linux.BackDoor.Gates.5 Trojan that was DDoSing other servers. I have multiple backups of the VM…
D.Mill
  • 379
  • 5
  • 15
0
votes
1 answer

Host says server is affected by malware, anyone knows this one ? What to do?

My host sent a notification that says server is infected with a malware, it doesn't seem very popular. The Symantec site about this malware shows windows machines as targets, but not CentOS. Anyone knows what this malware does exactly ? What are…
adrianTNT
  • 1,077
  • 6
  • 22
  • 43
0
votes
2 answers

Is this slowloris attack or not?

IP is hidden in apache log for privacy, except last octet. /billing is our application start page. But it doesn't make sense that it sends POST requests, and get 500 response. Or maybe this is legitimate old IE 7 browser who can't handle our site,…
gilbertasm
  • 95
  • 2
  • 13
0
votes
1 answer

How to view traffic operating on a specific port without plugging into egress interface? (Cisco IOS)

I'm trying to track down what host is infected with ZeroAccess on my network. It runs on ports 16464-16471. I would like to find this host without having to connect my laptop to the egress (WAN) interface. (Because it would take down the internet…
Copy Run Start
  • 734
  • 1
  • 9
  • 27
0
votes
2 answers

How do I remove 1 line of code from PHP files containing a specific string?

By coincidence I noticed that quite some of the PHP files of the sites I host have had malware injected: They all have the following line before the original/correct code: What is the best…
Evert
  • 162
  • 1
  • 3
  • 16
0
votes
0 answers

Suspicious "sys0972500-1.php", I didn't put it on my server

Before 2 days I found inside the httpdocc a new folder which name was css. Inside this folder I found a file named sys0972500-1.php , which it caused send thousands spam emails from my server. I deleted it and today I had the same problem. What…
Andrew
  • 1
  • 2
0
votes
1 answer

group policy exception to disallowed

I'm trying to setup a group policy on a domain to block cryptolocker (among others). I'm mostly following the Cryptolocker Prevention Kit (http://community.spiceworks.com/topic/396103-cryptolocker-prevention-kit-updated). Using a 2008R2 DC. However,…
user2891127
  • 181
  • 2
  • 12
0
votes
1 answer

Strange ports on default install of W7

I have a base new install of windows 7, and when I went to look for something else I saw the attached netstat output. What concerns me is that this is Windows + Truecrypt + drivers, nothing else installed. The sequential high ranged ports belonging…
Sabre
  • 425
  • 2
  • 15
0
votes
1 answer

Small business server 2011 standard - applications randomly closing for remote desktop users

Small business server 2011 standard - applications randomly closing for remote desktop users I have an issue where when you are connected through remote desktop (doesn't matter whether you have administrative rights or not). What happens: Any…
Ash King
  • 109
  • 1
0
votes
1 answer

Locating malware on network

I am trying to isolate an email sending malware on my network. The headers are as follows: Received: from z.local.domain (172.18.248.22) by z.local.domain (172.18.248.22) with Microsoft SMTP Server (TLS) id 15.0.712.24 via Mailbox Transport; Mon, 30…
AWippler
  • 1,065
  • 1
  • 12
  • 32
0
votes
1 answer

Almost all of our websites within our server is redirecting to a porno scammy sites

We are having a problem within our server. After transferring the files to a new dedicated server, within only one or two weeks almost every website under our server is redirecting to a porno scammy sites (to be blunt to adultfinder website). Once…
Rei
  • 23
  • 2
  • 7