Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
2
votes
2 answers

Data Execution Prevention has closed the program Ms08n.exe

I've got a Windows2003 server which I rebooted recently, and now is nagging me about Data Execution Prevention having closed the program "Ms08n.exe". When I press "close message", the dialog just reappears, an error message occurs stating "Project1…
Nik Reiman
  • 230
  • 3
  • 11
2
votes
1 answer

Compromised printer?

Today the office printer produced three sheets with what seems to be random characters, and in the middle a string random1random2random3random4. This raised a red flag with us. Is this something to be worried about? We use the full stack of Meraki…
JohnBT
  • 31
  • 2
2
votes
3 answers

Suggestions requested on what to cover in seminar on `Recent Trends in Virus & Anti-virus Stratagies`

I'm going to give a seminar on "Recent Trends in Virus & Anti-virus Strategies" as a part of my course work in my Post Graduation. I got two months of time. So, I want to fully utilize this period. I myself chosen this topic because I want to master…
claws
  • 232
  • 3
  • 10
1
vote
1 answer

Server infected by recent cryptojacking malware but different (?) entry point

One of my servers has been infected by this cryptojacking malware (reporting to the very same IP than in the article). It seems known for this malware to propagate through some Confluence vulnerabilities, however my server doesn't run Confluence,…
1
vote
1 answer

Using e-mail on malware infected computer/network

I have an important (+10 outlook accounts) but very ignorant client who refuses to accept that there is malware on the company's computers. Malware that steals Outlook data to send and receive spam. The situation went on a limit, due to the…
André A.
  • 11
  • 1
1
vote
1 answer

Why does my "ps aux" command column now show gibberish?

While using ps aux to find the PID of a process, I came across some output that prevented me from doing so. I've done this before, on this same server, within the last month. Today's output looked like: (Scroll right → → → →) USER PID %CPU…
Robert K
  • 572
  • 1
  • 5
  • 12
1
vote
4 answers

Why are there unknown URLs in router log?

I recently looked at my router log. Why are a lot of requests that I don't send originated from a computer in my home network? They do not look like 3rd-party advertisements / images embedded in a page. The request have patterns, such…
user45685
  • 103
  • 2
1
vote
0 answers

How to get rid of adfly javascript code to be inserted automatically in my web pages

in my website, adfly's javascript code is inserted automatically after every few hours in index.php and default.php web pages. Every time I remove these unwanted code from both pages manually and that code reappear again after few hours. I have no…
K Ahir
  • 111
  • 3
1
vote
1 answer

Is my Windows Server Backup in Azure safe against ransomware attacks?

I am thinking of a backup plan for fast recovery scenario for my windows Azure hosted VM's. My plan is to create a backup disk that is attached to my VM and using Windows Server Backup I create a backup on that disk using Windows Server Backup. I…
1
vote
1 answer

Configuring Applocker to try and prevent randsomware (through email); overkill?

I'm toying around with group policy (Self teaching myself) and have stumbled across applocker which i can certainly see the benefits for certain situations however in every company i've worked for users will NEVER use a specific set of programs,…
Tomsta
  • 131
  • 1
1
vote
1 answer

wanna cry ransomware on LInux ?

Do Linux users bother about wanna cry ransomware. I am not talking about using windows emulation like WINE. All my servers and office desktops are on linux, I am assuming I am safe against at least this ransomware. But I just want to make sure
Ram
  • 227
  • 1
  • 3
  • 5
1
vote
3 answers

Recognize rootkit-taken server

First, I'm not looking for software for detection of rootkits planted into server, as this may and may not work, especially on live system. I'm curious to find out what would be the signs of rootkit takeover of one server. At least what damage and…
Miloš Đakonović
  • 682
  • 3
  • 9
  • 28
1
vote
2 answers

Maldet with ClamAV missing PHP base64_decode() & eval() hacks

I've installed Linux Malware Detect and ClamAV in my CentOS 7 server and seems it's all ok as it hits on the EICAR malware test files and does scheduled scans without issues. The problem comes when I upload a real malware PHP file that I kept from a…
campsjos
  • 125
  • 7
1
vote
0 answers

Script file is created to send junk mails

I have installed Joomla 3.3.6 on my ubnutu server 15.04 on cloud. I have noticed some script file created automatically which is sending some junk mail randomly. I have installed maldetect to check for malware. Recent file detect was…
raj
  • 11
  • 2
1
vote
1 answer

We've had a ransom-ware attack - looking for help/advice

I've recently started working in a small subsidiary of a larger international organisation. My work is on the help desk, and there's 3 developers on the team, and our boss is the manager and acting sysadmin. There's been a high turnover of staff, in…