Endpoint Protection

 View Only
  • 1.  UltraDefragFraud!gen2

    Posted Jun 29, 2011 11:57 AM

    My Customer would like to know what vector is this coming through?

    He has the following from:  http://www.symantec.com/security_response/writeup.jsp?docid=2011-061711-5145-99

     

     

    UltraDefragFraud!gen2Risk Level 1: Very LowDiscovered: June 17, 2011
    Updated: June 17, 2011 11:51:45 AM
    Type: Security Assessment Tool
    Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 UltraDefragFraud!gen2 is a heuristic detection used to detect risks associated with the UltraDefraggerFraud family.

    Files that are detected as UltraDefragFraud!gen2 are a security risk. We suggest that any files you believe are incorrectly detected be submitted to Symantec Security Response. For instructions on how to do this using Scan and Deliver, read Submit Virus Samples.

    Discovered: June 17, 2011
    Updated: June 17, 2011 11:51:45 AM
    Type: Security Assessment Tool
    Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 UltraDefragFraud!gen2 is a heuristic detection used to detect risks associated with the UltraDefraggerFraud family.

     

    Antivirus Protection DatesInitial Rapid Release version pending
    Latest Rapid Release version June 17, 2011 revision 008
    Initial Daily Certified version pending
    Latest Daily Certified version June 17, 2011 revision 020
    Initial Weekly Certified release date June 22, 2011
    Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.Threat AssessmentWildWild Level: Low
    Number of Infections: 0 - 49
    Number of Sites: 0 - 2
    Geographical Distribution: Low
    Threat Containment: Easy
    Removal: Easy
    DamageDamage Level: Low
    DistributionDistribution Level: Low



  • 2.  RE: UltraDefragFraud!gen2

    Posted Jun 29, 2011 12:08 PM

    Hi Stan,

    This threat is getting in by visiting certain web sites  This is a drive-by download.

    Here is a great video that explains how this threat works.

    http://bit.ly/m81vSz

    http://www.symantec.com/security_response/writeup.jsp?docid=2010-112113-1147-99&tabid=2

     

    Cheers,

    Thomas

     



  • 3.  RE: UltraDefragFraud!gen2

    Posted Jun 30, 2011 05:03 AM

    Hi Stan,

     

    This Security Response blog describes quite well how the scam works.  "Trojan Feigns Failures to Increase Rogue Defragger Sales"  I have given it a "thumbs up" - please do the same if you agree!

     

    Thanks and best regards,

     

    Mick



  • 4.  RE: UltraDefragFraud!gen2

    Posted Jul 01, 2011 11:29 AM

    New detection for this threat, pending release -

    UltraDefragFraud!gen4 is a heuristic detection used to detect risks associated with the UltraDefraggerFraud family.

    http://www.symantec.com/business/security_response/writeup.jsp?docid=2011-070114-1719-99