New program attacks Microsoft's AntiSpyware
BankAsh-A also tries to steal users' banking passwords
February 10, 2005 12:00 PM ETIDG News Service -
One month after Microsoft Corp. released a beta version of its new antispyware software (see story), security researchers at Sophos PLC said they have detected the first malware program that seeks to attack it.
The program, named BankAsh-A, tries to disable Microsoft AntiSpyware and delete all files within its folder, Sophos said. It also tries to steal users' banking passwords by installing a keystroke logger that records information typed into online banking sites, according to the antivirus firm.
The program appears to targets users of U.K.-based online banks Barclays Bank PLC, Cahoot, Halifax PLC, HSBC Bank PLC, Lloyds TSB Bank PLC, Nationwide Building Society, National Westminster Bank PLC and Smile, Sophos said.
While there are a number of malware programs that attempt to steal banking passwords, this one is interesting because it seems to single out Microsoft's antispyware software for attack, said Sophos senior technology consultant Graham Cluley. AntiSpyware is designed to protect Windows users from programs that surreptitiously monitor computer users' actions as well as other malicious programs.
Sophos was first made aware of the program yesterday morning, Cluley said. Although the researchers have seen only a handful of incidents of the program out on the Internet, the speed with which hackers targeted Microsoft's AntiSpyware software is concerning, Cluley said.
The software maker began offering the beta of AntiSpyware in early January via free download from its Web site.
Sophos advised Internet users not to download unknown files and to make sure that their antivirus software is updated to protect against attack. Microsoft representatives weren't immediately available to comment on the threat today.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

