Search
Virus Protection

PC Tools Spyware Doctor w/ Antivirus v6.0 FREE DOWNLOAD and VIRUS SCAN      Stopzilla Download - Get Rid of Spyware, Viruses, and Adware Today!

Financial malware attacks will escalate – Help Net Security

Microsoft added detection and removal capabilities for the ZeuS financial malware (also known as Zbot and WSNPoem) to its Malicious Software Removal Tool (MSRT) on 12th of October.

It is meant to help prevent the infection and spread of the most prevalent forms of malware. With MSRT out in the field, Trusteer’s research organization decided to evaluate its effectiveness in detecting and removing ZeuS.

MSRT was tested against hundreds of Zeus files, and found that MSRT detects Zeus 2.0 about half (46%) the time, but is unable to detect the new 2.1 version of this financial Trojan.

The good news is that MSRT has/will be able to kill approximately half of the Zeus population. This detection rate is very respectable since most anti-virus solutions, if not all, have a much lower detection rate. However, this low detection rate also emphasizes how hard it is to remove Zeus.

Zeus also has a significant advantage over MSRT when it comes to committing fraud. Since MSRT does not operate in real-time and only disinfects a machine when it is running, hackers have a golden window of opportunity between the time of a Zeus infection and the next scan by MSRT to siphon off money from the victim's bank account.

Thousands of new computers are infected with Zeus every day, and are instantly analyzed by fraudsters. Truster has found, based on research conducted with more than 70 financial institutions over the past two years that financial fraud usually occurs shortly after a computer is infected with Zeus because sensitive information is immediately transmitted back to the criminals.

In the majority of cases, the ability of MSRT to prevent Zeus-related fraud and data loss will be minimal because the damage has already done by the time it performs its scan.

“Microsoft’s decision to join the fight against financial malware is an important step. Winning the war against criminals requires the participation and cooperation of more software vendors and increased involvement by law enforcement agencies,” said Mickey Boodaei, Trusteer's CEO. “I hope Microsoft's efforts won't stop here since there is a lot more to be done. However. I believe that MSRT will actually serve to further shorten the time between a machine becoming infected and the time it is used to commit fraud. I also expect this will reduce the effectiveness of antivirus solutions, since they typically cannot detect a new variant until a few days after it is released.”

“I also won't be surprised if some financial malware starts targeting MSRT to render it useless. Based on previous activity I have witnessed by financial malware developers, this is very likely. Zeus, and other financial malware, can accomplish this fairly easily since they have a distinct technical advantage over MSRT as they are already running when MSRT starts scanning. This allows the Trojan to easily block MSRT from running altogether. Disabling MSRT will inflict even further damage, since it is effective at detecting and removing many other forms of malware,” Boodaei added.

“Microsoft is working hard and making important contributions towards improving online security with MSRT and Microsoft Security Essentials. However, in the battle against Zeus, I believe Microsoft chose the wrong weapon. What’s needed are real-time, signature-independent solutions and more operating system improvements, if we want to defeat Zeus and others like it,” Boodaei concluded.

This entry passed through the Full-Text RSS service — if this is your content and you're reading it on someone else's site, please read our FAQ page at fivefilters.org/content-only/faq.php
Five Filters featured article: Beyond Hiroshima - The Non-Reporting of Falluja's Cancer Catastrophe.

Comments are closed.

  • Zlob Downloader Trojan
    Do You need help with the zlob trojan virus? Here we have compiled a little info for you about the dangers and effects of the computer trojan, and also have resources for removal tools. […]
  • Smitfraud C Will Hijack Your Background on Your Computer! Read This to Stop It!
    Has the image on your desktop changed to something that you are completely unfamiliar with? The virus known as Smitfraud C could be the cause of something like this. We have the solution to your problems! […]
  • Need to Remove Zlob? Read This First
    Zlob is no joke, and it can be a huge hassle to remove. If you have downloaded on your computer you will want to remove it quickly and have some sort of protection to keep it off. Read on for some tips and resources that I recommend... […]
  • SmitFraud Removal Tool - Know What is Real and Fake!
    Do you have smitfraud and a program called SmitFraudFixTool has been bugging you to download and buy a program to remove the Smitfraud Downloader? You Need to read this article to find out why this program is fake! […]
  • Virtumonde Virus - How Do I Remove Virtumonde Once and For All?
    Virtumonde is a horrible and very aggressive computer virus that is prevalent online today. If you have this virus you need to remove it as soon as you can to stop serious PC problems. […]

Powered by Yahoo! Answers