Security Basics mailing list archives

RE: Auditmypc.com


From: <Michele.Nappa () bipop it>
Date: Fri, 10 Mar 2006 08:49:35 +0100

After your positive feedback about adutmipc.com I suspected that something was wrong about consultant's technical 
report that claimed that classes were downloaded from the site mentioned above. 

So I purged Java's cache and I repeated some tests available on the site. The classes were not found again!

At this point I scheduled a mass scanning of Java cache directory and I noticed that another ws had that classes.

They were downloaded from another site that I will publish after some checks.

So could I think that auditmypc.com is not responsible in any way of that classes?

In the meantime the consultant has been invited to have an holiday... and to change is job!

Michele 

-----Original Message-----
From: Alexander Bolante [mailto:alexander.bolante () gmail com] 
Sent: mercoledì 8 marzo 2006 23.40
To: Nappa Michele
Cc: security-basics () securityfocus com
Subject: Re: Auditmypc.com

You'll see various references to the viruses you listed below at the
following website:
http://www.trendmicro.com/vinfo/virusencyclo/alphalisting.asp?NAV=12&ltr=J

Trojans are common w/ websites. Doesn't look harmful to me.

1) Run Disk Cleanup.
2) Run your Spyware Removal Program (e.g. Lavasoft Ad-aware)
*Make sure you update Ad-aware before running
3) Run your Antivirus Program (e.g. Symantec Antivirus)
*Make sure you update your virus definition files before running

Good luck. Cheers!

On 3/8/06, Michele.Nappa () bipop it <Michele.Nappa () bipop it> wrote:
Does anyone knows more about auditmypc.com?. I used their web functionality called "CHECK YOUR PRIVACY" and they 
installed some java classes. Scanning with Microsoft Windows Live Safety Center I noticed among results what this 
tool calls viruses:

* Java/Bytverify
* Trojan:Java/Classloader
* TrojanDownloader:Java/OpenConnection.F

???

Michele Nappa


Nota di riservatezza: il presente messaggio, corredato dei relativi allegati, contiene informazioni da considerarsi 
strettamente riservate ed è destinato esclusivamente al destinatario sopra indicato, il quale è l'unico autorizzato 
ad usarlo, copiarlo e, sotto la propria responsabilità, diffonderlo. Chiunque ricevesse questo messaggio per errore o 
comunque lo leggesse senza esserne legittimato è avvertito che trattenerlo, copiarlo, divulgarlo, distribuirlo a 
persone diverse dal destinatario è severamente proibito ed è pregato di rinviarlo immediatamente al mittente 
distruggendo l'originale. Grazie.


Confidentiality notice: this message, together with its annexes, contains information to be deemed strictly 
confidential and is destined only to the addressee(s) identified above who only may use, copy and, under his/their 
responsibility, further disseminate it. If anyone received this message by mistake or reads it without entitlement is 
forewarned that keeping, copying, disseminating or distributing this message to persons other than the addressee(s) 
is strictly forbidden and is asked to transmit it immediately to the sender and to erase the original message 
received. Thank you.



---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




--
Alexander Bolante | Alexander.Bolante () gmail com

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Tailor your education to your own professional goals with degree 
customizations including Emergency Management, Business Continuity Planning, 
Computer Emergency Response Teams, and Digital Investigations. 

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: