Laptopantivirus.microsoft.com » 1-27-2010 12-56-45 PM

1-27-2010 12-56-45 PM


2 Responses to “1-27-2010 12-56-45 PM”

  1. feetsdr says:

    A client of mine started getting warnings from Trend Worry Free on 2/4/10 about trying to get to that IP.

    I’ve thrown most everything I know of at this and haven’t found the cause. Any recommendations on how to get rid of the cause of this!?

    feetsdr@gmail.com

  2. admin says:

    I didn’t have a chance to dig into this piece of malware. It appears to be the normal fake antivirus stuff – which normally comes in via phishing or or XSS off websites. That is – users running random executables.

    To detect it, just look for weird DNS entries for Microsoft or HTTP gets going to non-ms IPs with MS hostnames.

Leave a Reply

You must be logged in to post a comment.