Is it possible that malawere "crisis" could infect Mac os x?

How can I discover if adobe flash player just installed is totally genuine?
OSX Crisis, discovered last month, was soon found to be cross-platform – detecting whether the OS is Windows or Mac, and responding accordingly. Now Symantec believes it may also be the first malware that attempts to spread onto a virtual machine.
Apart from virtual machines, Symantec has discovered that it can drop from an infected Windows device onto a connected Windows Mobile device. It’s not yet sure whether Android or iPhone devices can be similarly infected, but is conducting further analysis.
However, the ability to spread to VMware is new. It doesn’t use a vulnerability in VMware, but the nature of all virtual machines: ultimately they’re all just a file or series of files on the disk of the host machine. Crisis looks for a VMware virtual machine image on the infected host computer. If it finds one, it mounts the image and then copies itself onto the image by using a VMware Player tool.
Because the virtual machine is just files, it doesn’t even have to be operational to get infected – the files can usually be directly manipulated or mounted even when the virtual machine is not running. Researchers have become accustomed to malware trying to hide from virtual machines because this is what they use to analyze malicious code. Crisis reverses this behavior.
What is not clear, however, is whether this behavior is specifically intended to target the virtual machines of malware researchers – in which case we have to wonder why – or whether it is the first signs of serious attempts to colonize the growing number of virtual installations.
SecurityWatch makes an interesting observation here. “There are hints that Crisis originally began life as part of a commercial malware package sold mostly in the US and Europe before being packaged for hacker forums. The company behind the commercial version, Remote Control System DaVinci, targets the software for government surveillance, Myers [Lisa Myers of Intego] wrote. Priced at 200,000 Euros, it's unlikely Crisis will be ever used in anything other than targeted attacks, she said.”
This would lend argument to both possibilities. Either the ‘target’ is one or more security researchers, or it is the first attempts by malware writers to be able to target specific businesses or government departments that operate with a virtualized infrastructure. Either way, says Symantec, it may be “the next leap forward for malware authors.”
This article is featured in:
Internet and Network Security  •  Malware and Hardware Security  •  Wireless and Mobile Security

iaco77 wrote:
Either way, says Symantec, it may be “the next leap forward for malware authors.”
Yes, Symantec and other AV developers release these scare tacics often to try to sell AV software.
Cheers
Pete

Similar Messages

  • Is it possible that Exchange UM could be configure with two call managers over the same sip?

    Hi,
    I have Cisco call manager 8.2 integrated with Microsoft Exchange Server 2010 Unified Messaging.
    Call manager has primary and secondary server. I created a sip trunk and linked primary CUCM with Exchange. Users can leave and get voice mails.
    Problem: In case that primary server is down (WAN is down) the users registered on secondary server but they cannot contact to Exchange Unified Messaging.
    I added  new UM Dial Plan with the same pilot and associated it to the secondary CUCM server. UM answered but do not recognize the extension number "is not a valid mailbox extension".
    Is it possible that Exchange UM could be configure with two call managers over the same sip, the same pilot number, different associated UM servers and get access to the same voice mail boxes?
    If not:
    Does exist a way to configure Exchange UM that will work if one CUCM server is down?
    Thank you,
    Peter

    Hi,
    I have Cisco call manager 8.2 integrated with Microsoft Exchange Server 2010 Unified Messaging.
    Call manager has primary and secondary server. I created a sip trunk and linked primary CUCM with Exchange. Users can leave and get voice mails.
    Problem: In case that primary server is down (WAN is down) the users registered on secondary server but they cannot contact to Exchange Unified Messaging.
    I added  new UM Dial Plan with the same pilot and associated it to the secondary CUCM server. UM answered but do not recognize the extension number "is not a valid mailbox extension".
    Is it possible that Exchange UM could be configure with two call managers over the same sip, the same pilot number, different associated UM servers and get access to the same voice mail boxes?
    If not:
    Does exist a way to configure Exchange UM that will work if one CUCM server is down?
    Thank you,
    Peter

  • Is it at all possible that a Nano could ruin headphones?

    I'm going to expose my lack of knowledge about audio equipment, so apologies if this is a stupid question.
    I've had three pairs of headphones all have the sound coming out of the right "phone" become extremely quiet within the past two months. As two pairs were Sony's and one was Apple's buds, I know it's not the brand. The only thing I can think of as common amongst them all is that I used them with my Nano.
    The symptom is exactly the same in all cases... the sound coming from the right side is extremely faint. I've NEVER had the volume above 50%, so I know I'm not blowing them out.
    Any thoughts? Suggestions?
    I should point out that this is NOT the other problem people have mentioned, where their right side would start buzzing on heavy bass output. This is consistent diminished sound, to the point that if I have the right earbud alone in, I can't hear anything out of it if there's any ambient noise.
    Also, the headphones in question have this problem if I plug them into other devices, but they all first occurred while they were in my Nano.
    Thanks!
    15 PowerBook G4 FW800   Mac OS X (10.4.2)  

    I have no idea if my Nano is ruining them.
    I acknowledge that it's entirely possible that all three sets have died in similar ways within the a relatively short period of time independent from my Nano.
    But put more simply...
    Within the past 2 months, I've had 3 different sets of headphones have one of the buds become very quiet, to the point where they're basically producing no sound, with seemingly no rhyme or reason. I don't have the volume up above 50%, so I know they weren't blown out. I also know it's not a problem with the Nano's output, since these headphones have the same problem with other audio devices after the problem came up having used them with the Nano initially.
    So my question is... is it possible that my Nano is the thing that's causing this to happen?
    As for the original earphones that came with the Nano... I'm using them now. No problems so far. But I prefer to use in-ear buds because they help eliminate ambient noise and thus allow me to keep the volume on the Nano lower.

  • Is it possible that after 3 years my Mac computer damaged the port to my camera?  I have not always disconnect it properly using eject before disconnecting. I have 2 cameras that are Sony CyberShot and they both shut down when I connect to the computer.

    Is it possible that after 3 years my MacBook has damaged the port on my camera?  I thought I had a battery problem with both my Sony CyberShot cameras (they are they same age).  I had trouble getting the cameras to come on but then when it did come on after charging repeatedly, it turned off when I connected it to the computer to download pictures.  I ordered 2 new batteries and the camera came on but went off immediately when I connected it to the computer.  After that, the camera would not come back on.  Help please!

    John, thanks for the email so quickly.
    I too hope I haven't tried "everything" either but I am reasonably technical.  I had done what you suggested to do before but I did both again.
    Ethernet is yellow in the left side bar.  In the right pane it's status says Connected but then below it says "Ethernet has a self-assigned IP address and will not be able to connect to the Internet."
    I have tried the assist me menu and Network Status has Ethernet Green, Network settings Yellow, ISP Green, and Internet and Server Red and Failed for both.  I have turned things off and on, checked cables, deleted all locations and tried restting them up but to no avail.  I even disconnected everything and connected the mac directly into the cable modem itself and the thing still will not connect.
    Thoughts???

  • Is it possible that my iMovie could be corrupted and needs a re-install?

    I'm still struggling with multiple problems/issues. I recently imported video files that apparently +iMovie did not like!+ They imported with no apparant problem. Upon play back though, my entire computer froze.
    I'm now having new problems, in that, If I try to import more than 3 clips at a time, my computer freezes up... (iMovie compatible clips, not the ones that made it crash).
    As a test, I re-installed iMovie on another drive, and was able to successfully import the same group of clips (about 15 at once) that had caused the computer to freeze, without the computer freezing. Unfortunately though, the clips when viewed were jerky. This could be a result of this iMovie version being 7.1.1, not the most current version, which is 7.1.4.
    This is due to an entirely different problem, in that, even though I have the most current version of Quick Time 7.5 (149.5), I wasn't able to down load the iMovie update for 7.1.2 or 7.1.4, because the download was stopped accompanied with a message stating that I needed Quick Time 7.5 to proceed, which as I stated, I already do have.
    Any advice or suggestions?
    I'm just wondering if I somehow damaged the iMovie app. when I imported those unfriendly clips?

    If you sent the iPhone to Apple to be refurbished, then the iPhone you received back is very likely NOT the phone you sent. Check the paperwork that came with the refurbished unit.

  • Is it possible that Verizon could have screwed things up more than this?

    I contacted Verizon 10 days ago about internet and cell phone service the person I spoke with told me that Verizon did not offer internet in Illinois and I should call something called Frontier Communications
    I should have taken this as a sign that I shouldn't do business with Verizon
    Instead I went to your office on State street in Chicago. I was told that
    Verizon does in fact have internet, they have an arrangement with ComCast. I was told
    if I signed a 2 year contract, the first 6 months would be  $20 a month and then the price
    would be $40 a month for rest of the contract.
    I signed up and was given an account number and a number to call ComCast
    When  I spoke to Comcast, I was told that there was no agreement with Verizon
    I went back to Verizon, Verizon called Comcast. Now Comcast was saying there was a agreement but the terms were different
    It was now $20 a month for 6 months, but no contract. After 6 months there was no guarantee what could happen
    to the price. There could be another promotion,  it could go up
    I agreed reluctantly and signed up
    The earliest appointment was the following Monday.
    I had to leave work early for the appointment. I won't get paid for this missed time
    I was given a time frame for when the ComCast Technician would show up. He was late; he arrived after the timeframe
    I had ordered wireless internet. I know I ordered wireless because I discussed this with the comcast rep when I placed the order
    We talked about how many devices could use the wireless at the same time, how far I could be from the router, whether there was a separate router and modem or if it was one unit, if I could buy my own rather than rent it, etc.
    The technician did not have wireless equipment with him. He said the order didn't indicate that it was wireless.
    I asked if he could install what he had since I had been waiting almost a week for the internet and then I could go to their office to swap it
    He said no, a technician had to install it. If he installed what he had and they sent out another technician later with a wirelss router
    they would charge me a second installation charge
    The worst part though, is the earliest they can have someone back out is Wednesday ,ten more days later
    That means almost three weeks with no internet at home and I have to take off from work again and lose more pay to wait for the technician again
    I do computer support. I'm on call for work. If I get called out at night and don't have internet, I have to go downtown in the middle of the night

    I understand that you are frustrated with the yes/no/yes regarding internet through Verizon.  I am assuming you are referring to DSL or fiber optic internet with Wi-Fi, since you state the internet service is actually provided by Comcast.  That is as far as my understanding goes.  Your post is titled "Is it possible that Verizon could have screwed things up more than this," but the rest of your complaints (please understand I do not argue the validity of your anger or frustration) are, in fact, regarding services rendered (or not) by Comcast.
    I used to have a bundle with Centurylink internet, Directv satellite, and Verizon Wireless.  I got a separate bill from Verizon but I got a discount for the Centurylink and Directv bill by linking my cell phone numbers and creating a "triple play."  Centurylink had ridiculous scheduling issues with their techs, and it took five calls and two weeks to actually get the internet hooked up, at 1.5 mbps as the lines couldn't accommodate the 10 mbps the rep offered.  I was upset with Centurylink, not Verizon.  I had upgraded my cell phones through Centurylink, but if/when I had any issues, I called Verizon.
    The issues you are describing are not within Verizon's control, which should have been clear when you had to speak with Comcast to set up the account and order.  You need to call Comcast to resolve it, and the sooner the better.  I had a horrible time trying to recoup money I paid to Directv after breaking the bundle, and eventually Centurylink refunded my money since the were the ones refusing to release my payments to Directv, saying I had a bundle but they could not discuss billing for Directv service. Almost all companies have a window for refunds and billing disputes, and Centturylink gave me the runaround until I demanded escalation.  Once the dispute period is over you don't have a leg to stand on for credits or anything else.  I had to get noisy to get results, and you might have to as well.
    Step one is calling Comcast and placing the blame where it belongs, then work toward a solution to rectify the lost time and frustration.

  • When I open Firefox a screen comes up that says register for "Inbox". I do not want to. I cannot deleate this and cannto figure out how to uninstall. Is it possible that I could speak with a live person that can help me.

    I would like to delete the "inbox" screen from coming up when I open Firefox. I might help if I could speak with a person.

    Hello BassoonPlayer,
    Since you are using one of the the school's Macbooks, it is quite possible that the time and date are not properly set on the computer that you are using.  FaceTime will not work if you do not have the proper time zone set up for the location that you are in.  This past week, there were a two other Macbook users I've helped by simply telling them to set the Date/Time properly.  By the way, you described your problem very well, which makes it easier for us to help you.  Hope this solves your problem -- if not, post back and I can suggest other remedies.
    Wuz

  • TS5362 When I typed in -/Library/Keychains/  in the Go To Folder box, I got the message back that the folder could not be found.  Possibly to add to that, when I did a permissions repair I got this message "SUID file sys/Lib/CoreS...has been modified...

    When I typed in -/Library/Keychains/  in the Go To Folder box, I got the message  that the folder could not be found.  Possibly related to that, when I did a permissions repair I got this message "SUID file sys/Lib/CoreS...has been modified and will not be repaired.  How can I undo the problems that Mavericks 10.9.1 seems to have caused?

    1. You need to type or paste in ~/Library/Keychains/ and not -/Library/Keychains/.
    2. If the repair permissions message refers to ARDAgent, it's normal.
    (95401)

  • Is it possible that someone could redirect someones  email account, and screen the messages over the internet without their knowledge.

    Is it possible that someone could redirect someones  email account, and screen the messages without their knowledge.

    Call it phishing or not, any website designed to emulate another with the primary goal of obtaining one's personal information through deception is easily accomplished. You called it a façade, which is as good an description as any. It can be performed with most an hour of work, and uploaded to any server willing to host it. They have been known to be attached to legitimate websites, often educational institutions for which security is lax, and in which many people with too much time on their hands have sufficient privileges to modify the site at will.
    Constructing a more elaborate website that faithfully reproduces a secure webmail page populated with functional links would simply take more effort with probably more individuals working on it, but it is by no means beyond the realm of possibility.
    Perhaps the Apple Genius was describing something different, or not, but the point is that it is certainly possible for someone to screen or otherwise view your email messages. It's simple, given just a couple of pieces of your account information. The most common means of obtaining that information is through deception, a low-tech social exploit that has been with us for thousands of years.

  • Just wondering is it possible that someone could send them self a MSG but then change the senders number on the MSG??

    Just wondering is it possible that someone could send them self a MSG but then change the senders number on the MSG??

    Partipie88 wrote:
    Although could anyone do it if they knew or found out how??
    Yep, but again, not as easily done as it once was. Since it's illegal in most of the world & most carriers have provisions in place to stop such, you really need to know what you're doing to do such.

  • I have an IMac and opened an email that may have been infected with a virus. How do I check my IMac for a possible virus?

    I have an IMac and opened an email that may have been infected with a virus. How do I check my IMac for a possible virus? What does PPC mean?

    You would be better posting this in the Lion forum.
    https://discussions.apple.com/community/mac_os/mac_os_x_v10.7_lion?view=discussi ons
    It's possible you email contained a virus, but unlikely.  There haven't been any reports of email viruses effecting the mac. 
    My understanding is the Apple provides security updates for all malware including viruses.
    There have been reports of a --
    -- Phoney virus checking program
    -- flash malware.
    ppc -- Power PC.   An older computer processor used by Apple.  Last Mac shipped with PPC was in 2006.
    I've read about two virus checking programs for the mac. One is clamav.  The rest are either junk or malware.
    http://www.clamav.net/lang/en/
    Security update.
    http://support.apple.com/kb/HT1222

  • Re AD002357145UK I have just subscribed to Adobe Send. I am sure that v revently I used Adobe Send Now for free. Is that still possible (which means I could cancel AdobeSendNow subscription) or do I have to subscribe to Adobe Send to carry out file transf

    Re AD002357145UK I have just subscribed to Adobe Send. I am sure that v revently I used Adobe Send Now for free. Is that still possible (which means I could cancel AdobeSendNow subscription) or do I have to subscribe to Adobe Send to carry out file transfer. Incidentally I have Adobe Creative Suite. Thanks. Nadim Othman

    [topic moved to Adobe Send forum]

  • Everytime i try to call using facetime, it says it might be a phising website, no idea what is this, this never happened before, is it possible that my ipad mini could havebeen hacked. Please help

    I have been using facetime for past two months and everything was working fine, but yeaterday when i tried calling someone using facetime the a meesage appeared which said " warning this might be a phishing website" then two options are give either to ignore or go back.
    I don't know what to do, can somebody please help me , is it possible that my ipad mini is hacked

    Thanx Allan for that info,but still why does this message appears every time i call someone using Facetime
    Thank you
    Munish

  • I have an imac osx 5 mos.old. First time today I can not open my desktop folder/files. I need to read them. Message is: appleworks 6 quit unexpectedly. I need to read them. Is it possible that new software downloaded yesterday is problem?

    I have an imac osx 5 months old. For the first time today I can not open my desktop folders which are very important to me. How can I open these folders.
    The message when I click on the folder is "appleworks 6 quit unexpectedly". I can not open the folder. Is it possible that new software installed could cause the problem when I get the message "new softward available for your computer, install now. Maybe I should never install upgrade. Please help in layman's language how to open my folders. Thanks.

    X423424X wrote:
    The curious thing here is that on the one hand the code cannot be loaded so how could the trojan code be ever executed.  But you would expect the "Unexpectedly quit" message if the intel trojan did get executed in a ppc app.  So this begs the question when (and how) does the trojan code get executed in conjunction with launching an app?
    I understand code injected into a specific app like safari that uses the global environment variable to access the code in /Users/Shared.  But I don't understand how that code could be executed by attempting to run an randomly chosen ppc app.  Unless of course   other code has been injected is in a more critical place than just safari and that is scary.
    Some of this was explained to us a few weeks back by an infected user who reverse engineered the code, working with Intego to figure out why he was being re-directed on Google searches. At the time, nobody believed much of anything he was saying, but F-Secure explains it more fullly in this analysis. Note that there is a filter component to keep it from loading code into apps that would be unstable, so watch for the next variant to filter out ppc only apps.
    In a related matter, I got word from the PC side of the house that similar techniques are being used by drive-by infections that were injecting code into a running app which would disappear when they quit the app. A one-time infection, so to speak. Makes it really hard to even know you were temporarily infected, let alone how, why, what damage, etc.

  • Is it possible that a document (in this case an Appleworks or Movie Magic Screenwriter) can be lost forever, but it's contents somehow remain as other file types elsewhere? I have an old hard drive and I need to locate the contents of these files.

    I have a 20 gig hard drive from a 2001 iBook. When my iBook crashed back in '04, there was a screenplay on there that was not saved anywhere else. It has tremendous sentimental value to me, and I would really like to retrieve it. I've ran some data recovery software that's uncovered a gargantuan amount of data, most of it being completely unreadable to me.
    Additionally, I have found an AppleWorks file that could be the script, but it is ZERO bytes in size, and Pages won't even open it, saying that it is not a valid AppleWorks file.
    So I'm curious...is it possible that the document is lost, but somehow the contents of it are somewhere else on the drive as metadata in other unreadable formats. And if that's the case, how would I go about translating the unreadable data back into something that IS readable? 

    Hello,
    toddisalive wrote:
    Additionally, I have found an AppleWorks file that could be the script, but it is ZERO bytes in size, and Pages won't even open it, saying that it is not a valid AppleWorks file.
    if the size of this file is really ZERO bytes, either the original file contained an empty data fork and a resource fork which was stored elsewhere (*) or the file is too damaged to retrieve anything. Moreover, as AppleWorks never generates file with empty data fork, at least to my knowledge, ....
    Concerning the Movie Magic ScreenWriter files, the application seems to exist for Yosemite http://www.write-bros.com/movie-magic-screenwriter.html ( but it seems "expensive"  and I do not know if it accepts to import old files )....
    (*) maybe in .TOTO or __MACOSX/.TOTO if the filename is TOTO

Maybe you are looking for