THE WELCH COMPANY
440 Davis Court #1602
San Francisco, CA 94111-2496
415 781 5700
rod@welchco.com
S U M M A R Y
DIARY: July 22, 2011 03:45 PM Friday;
Rod Welch
Virus scan on c17 Microsoft reported 2 attacks.
1...Summary/Objective
..............
Click here to comment!
CONTACTS
SUBJECTS
C17 32-bit J Drive Virus Scan 2 Attack Files Found Cleaned Microsoft
1903 -
1903 - ..
1904 - Summary/Objective
1905 -
190501 - Follow up ref SDS 4 0000. ref SDS 3 0000.
190502 -
190503 -
190505 - ..
1906 -
1907 -
1908 - Progress
1909 -
190901 - Background on recent virus protection issues reported on 110713 0658,
190902 - including analysis of firewall considerations. ref SDS 4 HY5H
190904 - ..
190905 - On 110713 at that time found current virus scan definitions
190906 - available on the Internet from...
190907 -
190908 - Microsoft Consumer Security Support Center
190909 -
190910 - http://www.microsoft.com/security/scanner/en-us/
190912 - ..
190913 - Microsoft provides option to download virus scan program and
190914 - definitions that supplement Trend Micro Titanium virus protections,
190915 - and stored in...
190916 -
190917 - g: 00 microsoft virus_scan_64 msert.exe
190919 - ..
190920 - Virus scan on 110713 showed c17 64-bit was clean. ref SDS 4 XG6O
190922 - ..
190923 - Today, concern about virus attack occurred on email from unknow
190924 - source, but seemed like possible interest in SDS. Opening this email
190925 - gave indication of virus problems, in that there was only a single 3
190926 - or 4 char string.
190928 - ..
190929 - After this event today, downloaded updated Microsoft virus
190930 - definitions, and scanned c17 Microsoft Windows 32-bit operating system
190931 - on j: drive.
190933 - ..
190934 - Virus scan on j: drive that has Win 7 32-bit found 2 virus files...
190935 -
190936 - 1. Exploit:Java/CVE-2010-0840.DR
190937 -
190938 - http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Exploit%3aJava%2fCVE-2010-0840.DR
190940 - ..
190941 - Encyclopedia entry.................. updated 110718
190942 - Alert level......................... severe
190943 -
190944 - 2. Rogue:Win32/FakeRean
190945 -
190946 - http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Rogue%3aWin32%2fFakeRean
190948 - ..
190949 - Encyclopedia entry.................. updated 110704
190950 - Alert level......................... severe
190951 -
190952 - Win32/FakeRean is a family of programs that claim to scan for
190953 - malware and display fake warnings of malicious files. They
190954 - then inform the user that they need to pay money to register
190955 - the software in order to remove these non-existent threats.
190957 - ..
190958 - Special Note:
190960 - ..
190961 - Reports of Rogue Antivirus programs have been more prevalent
190962 - as of late. These are programs that generate misleading
190963 - alerts and false detections in order to convince users to
190964 - purchase illegitimate security software. Some of these
190965 - programs may display product names or logos in an apparently
190966 - unlawful attempt to impersonate Microsoft products.
190968 - ..
190969 - This has a huge list of symptoms.
190970 -
190972 - ..
190973 - After completeing this scan did following....
190974 -
190975 - Quick scan
190976 - C:
190977 - H:
190978 - G:
190979 - D:
190980 - E
190981 -
190982 -
190983 -
190984 -
190985 -
190986 -
190987 -
190988 -
190989 -
190990 -
190991 -
190992 -
190993 -
190994 -
1910 -