Keyword: microsoft security bulletin ms03-007
78647 Total Search   |   Showing Results : 841 - 860
CVE-2008-3014,MS08-052 Buffer overflow in gdiplus.dll in GDI in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3,
Windows 2000, XP, and Server 2003.) It adds the following registry keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center\Svc HKEY_CURRENT_USER\Software\Aasppapmmxkvs\ -993627007 It adds the following
Execution Vulnerability Over RMI Remote Desktop Protocol Server 1009448 - Microsoft Windows Remote Desktop Protocol (RDP) Brute Force Attempt Suspicious Client Application Activity 1009432 - Tildeb
\ Security Center AntiVirusDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center AntiVirusOverride = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1
\ Security Center AntiVirusDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center AntiVirusOverride = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1
\ Security Center AntiVirusDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center AntiVirusOverride = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1
\ Security Center AntiVirusDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center AntiVirusOverride = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1
\ Security Center AntiVirusDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center AntiVirusOverride = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1
\Users\{user name} on Windows Vista and 7.) It modifies the following registry entries: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE
Vista and 7.) It modifies the following registry entries: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center
CVE-2014-0294 This security update resolves a privately reported vulnerability in Microsoft Forefront. The vulnerability could allow remote code execution if a specially crafted email message is
Other System Modifications This Trojan Spy adds the following registry entries: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center\Svc FirewallDisableNotify = 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
malware onto the affected system, which connect to a remote URL. The diagram above illustrates two recent versions of this attack, both of which appeared after Adobe released a security bulletin in January.
Data%\{random}\SM{random}.exe - detected as TROJ_FAKEAV.MVA %Application Data%\{random}\SMAV.ico %Application Data%\SMSAITAV\SMXPAV.cfg %User Profile%\Application Data\Microsoft\Internet Explorer\Quick
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows Defender\Security Center\ Notification HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows Defender\UX Configuration HKEY_LOCAL_MACHINE\SOFTWARE\Policies
the following registry entries: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallDisableNotify = "1" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center FirewallOverride = "1
Server 2012.) It adds the following registry keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Security Center\Svc HKEY_CURRENT_USER\Software\Yqshjvw HKEY_CURRENT_USER\Software\Yqshjvw\ 1926745233 It adds the
\SOFTWARE\Microsoft\ Security Center AntiVirusDisableNotify = "1" (Note: The default value data of the said registry entry is 0 .) Other Details This backdoor connects to the following possibly malicious URL:
\CurrentControlSet\ services\mssecsvc2.1 DisplayName = "Microsoft Security Center (2.1) Service" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ services\mssecsvc2.1 ObjectName = "LocalSystem" It registers as a system
\CurrentControlSet\ services\mssecsvc2.0 DisplayName = "Microsoft Security Center (2.0) Service" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ services\mssecsvc2.0 ObjectName = "LocalSystem" It registers as a system