Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
0
votes
1 answer

Resolving the "Windows cannot access the specified device path or file" error

A user is reporting they might have a virus, although it might be related to their reinstalling zone alarm. I don't physically have access to the computer though. They are running Windows XP. When they try to launch any program form explorer they…
Jim McKeeth
  • 1,906
  • 4
  • 20
  • 21
0
votes
1 answer

How to get rid of ebury malware / trojan on Centos / cpanel

I have a server with cPanel installed on Centos 5.9. Three days ago, my server provider told me I'm infected by "Ebury Trojan". I read a lot of things saying that the openSSH server coming with cPanel may be infeted and how to detect it. Some says…
Marm
  • 141
  • 3
  • 6
0
votes
3 answers

watch file to see whos accessing/writing it and log it

I am facing some malware problems on my webserver. I updated third party software such as Wordpress to the latest version, disabled root logins and my users password complex enough but still someone or something is changing my index.php files,…
NovumCoder
  • 163
  • 1
  • 7
0
votes
1 answer

Malicious HTTP Post reuqest decoding

I have this request in my traffic, which is posting data to a malicious php file. T 212.193.229.17:60601 -> 9.9.9.9:80 [A] POST /images//sh.php HTTP/1.0. Host: dpfremovalwarrington.co.uk. X-Real-IP: 10.3.29.93. X-Forwarded-For:…
Farhan
  • 4,269
  • 11
  • 49
  • 80
0
votes
1 answer

Centos5 /tmp/.xzibit Displays multiple viruses in clamav, Can I delete this directory safely?

Possible Duplicate: How do I deal with a compromised server? I did a scan on my entire vps finding the folder above with a good amount of viruses. Can I safely delete this folder? Can I through ssh or is there a way I need to do it through the…
kilrizzy
  • 121
  • 4
0
votes
1 answer

Trying to hunt down malware on my server

Possible Duplicate: My server’s been hacked EMERGENCY A server of mine recently suffered a malware attack. I've since cleaned the server up a bit, upgraded a variety of wordpress installs and timthumb files, and removed a lot of old and archived…
PJ.
  • 203
  • 1
  • 4
  • 10
0
votes
1 answer

Compromised web server/multiple domains

Possible Duplicate: My server’s been hacked EMERGENCY Earlier today I found a lot of weird files on one of my servers (running Ubuntu Server 10.04), which I can't understand how they got there. Probably some sort of XSS-injection, need to dig…
anon
  • 11
  • 3
0
votes
1 answer

Google and Yahoo redirect my site to malware, but direct url works fine. Any computer

Possible Duplicate: My server’s been hacked EMERGENCY I can go directly to the site doublewing.org or www. without issue, but if I click on the link in google or yahoo it redirects to spam sites. Swagbucks works though! This is not on a single…
wmbf86
  • 155
  • 1
  • 7
0
votes
3 answers

Site harmed by malware -or is it a server problem?

I have a site which is got harmed by this "spywarepc.info" and showing "Your site has been attacked by a Malware" :( ... don't even know what is this ? so i have opened spywarepc.info in a browser but it's not opening. My site has been blocked…
kevn
0
votes
1 answer

Our clients site is redirecting to a pill scammy site

Possible Duplicate: My server's been hacked EMERGENCY We've usually host our clients site, but we aren't hosting this one. The website itself (weddle-funeral.com) works just fine. if you load google and search for weddle funeral stayton oregon -…
Xhynk
  • 101
  • 3
0
votes
2 answers

How do you remove the "ffsearcher" trojan?

Does anyone have any experience in removing the ffsearcher trojan. One of our systems is infected. The virus scanner doesn't detect it, but our websense program is detecting all the internet activity from it. I am trying to determine how to remove…
jherlitz
  • 1,058
  • 1
  • 18
  • 25
0
votes
1 answer

What is causing ping sweep?

I am spotting ping sweeps on our firewall log originating from our Windows 2003 SP2 x64 server. The traffic shows sequential pings sent to private ranges only. Eg: 192.168.1.1 192.168.1.2 192.168.1.3 ... 192.168.255.254 I have run a virus scan on…
0
votes
1 answer

Allowing any file to upload on server and security risks

We are having a project that allows users to backup there data to server through php upload,running on Linux server. If users upload any executable file it will be automatically renamed to some other name after the upload and removes execute…
ananthan
  • 1,510
  • 1
  • 18
  • 28
0
votes
1 answer

identity and rectify port scanning activities on CentOS

Possible Duplicate: My server's been hacked EMERGENCY My Linux (CentOS 5.x) machine seem to have been attacked. Port scanning activities were traced to it. However, the ports (to be) scanned were only 8080. As a temporary measure, I have updated…
pi.
  • 249
  • 3
  • 9
0
votes
2 answers

strange tcp network connections 149.9.1.16:ircd

Possible Duplicate: My server's been hacked EMERGENCY I am seeing strange tcp connection 149.9.1.16:ircd ans it is running perl service and that process is creating huge load on server IPV4 TCP 3u MYIP:58449 -> 149.9.1.16:ircd …
lakshman
  • 1
  • 1