Search
Virus Protection

PC Tools Spyware Doctor w/ Antivirus v6.0 FREE DOWNLOAD and VIRUS SCAN      Stopzilla Download - Get Rid of Spyware, Viruses, and Adware Today!

Hijacking Windows System Restore for cybercrime profits – ZDNet


Latest Post | Last 10 Posts | Archives


Previous Post: Modern banker malware undermines two-factor authentication

Hijacking Windows System Restore for cybercrime profits

Posted in:

  • Anti Virus
  • Arbitrary Code Execution
  • Botnets
  • Browsers
  • Complex Attacks
  • Data theft
  • Exploit code
  • Locally Running Web Servers
  • Malware
  • Passwords
  • Patch Watch
  • Phishing
  • Responsible disclosure
  • Rootkits
GENEVA -- Cyber crime gangs in China are penetrating the hard disk recovery cards on computers in Internet cafes and using a combination of zero-day flaws, rootkits and ARP spoofing techniques to steal billions of dollars worth of online gaming credentials. According to Microsoft anti-virus researcher Chun Feng (left), five generations of the Win32/Dogrobot malware family have perfected the novel rootkit technique to hijack System Restore on Windows -- effectively allowing the malicious file to survive even after the compromised machine is reverted to its previous clean state. At the Virus Bulletin 2009 conference here, Feng provided a fascinating look at the techniques used by Dogrobot, which is directly linked to the lucrative underground trading of online gaming assets like passwords and virtual property. According to data presented by Feng, the Dogrobot family has caused more than USD$1.2 billion in losses to Chinese Internet cafes. He explained that earlier Dogrobot used disk-level I/O file manipulation to penetrate System Restore but, as the malware evolved, it started using a "backdoor" that already exists in the System Restore functionality.  A third generation introduced extensive unhooking code to thwart the protection offered by security programs and avoid removal. Along the way, Feng discovered that newer variants were tweaked to get around security software and strengthen the code's ability to maintain persistent stealth on compromised Windows computers. In China, Internet cafes are very popular among the online gaming crowd where the use of USB sticks with account credentials is the norm.  Dogrobot takes advantage of this, abusing the USB AutoRun functionality on older machines to propagate. He explained that the malware author has found success exploiting zero-day ActiveX vulnerabilities and other flaws in Windows OS and third-party software -- especially RealPlayer and WebThunder. The attackers also use ARP cache poisoning to send malicious ARP packets to instruct other machines within the same LAN to download Dogrobot samples.

posted by Ryan Naraine
September 23, 2009 @ 9:30 am

Previous Post: Modern banker malware undermines two-factor authentication


Last 10 posts:

more Posts (Archives)

WordPress Mobile Edition available at alexking.org.

powered by WordPress.

Comments are closed.

  • Zlob Downloader Trojan
    Do You need help with the zlob trojan virus? Here we have compiled a little info for you about the dangers and effects of the computer trojan, and also have resources for removal tools. […]
  • Smitfraud C Will Hijack Your Background on Your Computer! Read This to Stop It!
    Has the image on your desktop changed to something that you are completely unfamiliar with? The virus known as Smitfraud C could be the cause of something like this. We have the solution to your problems! […]
  • Need to Remove Zlob? Read This First
    Zlob is no joke, and it can be a huge hassle to remove. If you have downloaded on your computer you will want to remove it quickly and have some sort of protection to keep it off. Read on for some tips and resources that I recommend... […]
  • SmitFraud Removal Tool - Know What is Real and Fake!
    Do you have smitfraud and a program called SmitFraudFixTool has been bugging you to download and buy a program to remove the Smitfraud Downloader? You Need to read this article to find out why this program is fake! […]
  • Virtumonde Virus - How Do I Remove Virtumonde Once and For All?
    Virtumonde is a horrible and very aggressive computer virus that is prevalent online today. If you have this virus you need to remove it as soon as you can to stop serious PC problems. […]

Powered by Yahoo! Answers