<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-14777922</atom:id><lastBuildDate>Sun, 08 Nov 2009 06:31:09 +0000</lastBuildDate><title>Swatkat's rants</title><description>on general computing, Windows security and more!</description><link>http://swatrant.blogspot.com/</link><managingEditor>noreply@blogger.com (swatkat)</managingEditor><generator>Blogger</generator><openSearch:totalResults>130</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SwatkatsRants" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-1692625681030995172</guid><pubDate>Wed, 02 Sep 2009 03:46:00 +0000</pubDate><atom:updated>2009-09-02T09:21:35.054+05:30</atom:updated><title>twitcurl - C++ twitter API library</title><description>&lt;b&gt;twitcurl &lt;/b&gt;is an open-source pure C++ library for twitter REST APIs. Currently, it has support for most of the twitter APIs and it will be updated to support all the APIs. twitcurl uses &lt;a href="http://curl.haxx.se/"&gt;cURL&lt;/a&gt; library for handling HTTP requests and responses. Building applications using twitcurl is quite easy:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Compile twitcurl source files (twitcurl.h and twitcurl.cpp) and link with cURL library (libcurl.lib) to build twitcurl.lib&lt;/li&gt;&lt;li&gt;Include twitcurl.h in your twitter based application and link to twitcurl.lib and libcurl.lib/libcurl.dll.&lt;/li&gt;&lt;li&gt;Instantiate an object of twitCurl class and use the twitter API wrappers that are exposed as public methods.&lt;/li&gt;&lt;/ol&gt;twitcurl works on all OS (Windows, Linux, Mac etc.) as it is written completely in C++ and the only dependency is cURL (which works on all OSes mentioned earlier). More info about the twitcurl library along with an example program is available here:&lt;br /&gt;&lt;a href="http://code.google.com/p/twitcurl/"&gt;http://code.google.com/p/twitcurl/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-1692625681030995172?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/1l7MKmzo-Rk" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/09/twitcurl-c-twitter-api-library.html</link><author>noreply@blogger.com (swatkat)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-1364039525206443910</guid><pubDate>Sat, 16 May 2009 16:00:00 +0000</pubDate><atom:updated>2009-05-16T22:23:24.328+05:30</atom:updated><title>Wolfram|Alpha launches</title><description>&lt;div&gt;&lt;a href="http://www.wolframalpha.com/"&gt;&lt;b&gt;Wolfram|Alpha&lt;/b&gt;&lt;/a&gt; is finally launched! Wolfram|Alpha is a &lt;i&gt;computational knowledge engine&lt;/i&gt; that to interpret the questions/queries and tries to formulate answers. It is not a search engine, it is a combination of encyclopedia and real-time data mining. Wolfram|Alpha tries to structure the information scattered in world wide web. It could be great for scientific (physics, mathematics etc.) queries as it uses &lt;a href="http://www.wolfram.com/mathematica/"&gt;Wolfram Mathematica&lt;/a&gt; to compute answers. It is still in alpha stage and has a long way to go. Try it out!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;By the way, Wolfram|Alpha has &lt;i&gt;answer to life, the universe, and everything&lt;/i&gt;. It's &lt;a href="http://en.wikipedia.org/wiki/Phrases_from_The_Hitchhiker's_Guide_to_the_Galaxy#Answer_to_Life.2C_the_Universe.2C_and_Everything_.2842.29"&gt;42&lt;/a&gt; ;)&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_g2qoDleHSYA/Sg7lP6mILNI/AAAAAAAAAjU/ouOBE2imm38/s1600-h/42.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://4.bp.blogspot.com/_g2qoDleHSYA/Sg7lP6mILNI/AAAAAAAAAjU/ouOBE2imm38/s320/42.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5336454670070590674" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;And, you will see this when Wolfram|Alpha website traffic exceeds its bandwidth limit:&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/Sg7u2Eae2PI/AAAAAAAAAjc/PuDD8zIW-tY/s1600-h/HAL.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 213px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/Sg7u2Eae2PI/AAAAAAAAAjc/PuDD8zIW-tY/s320/HAL.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5336465221145778418" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Google is working on a similar tool called &lt;a href="http://education.zdnet.com/?p=2543"&gt;Google Squared&lt;/a&gt;, which aims to structure the unstructured information.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-1364039525206443910?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/XyC9YtX69IA" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/05/wolframalpha-launches.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_g2qoDleHSYA/Sg7lP6mILNI/AAAAAAAAAjU/ouOBE2imm38/s72-c/42.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-5970871622157641017</guid><pubDate>Sat, 18 Apr 2009 16:21:00 +0000</pubDate><atom:updated>2009-04-18T21:55:33.287+05:30</atom:updated><title>New rogue: AV Antispyware</title><description>&lt;b&gt;AV Antispyware&lt;/b&gt; is new rogue software that belongs to &lt;a href="http://www.ca.com/securityadvisor/pest/pest.aspx?id=453146855"&gt;MS Antispyware 2009&lt;/a&gt; family. The AV Antispyware installer is dropped by a fake codec hosted at &lt;code&gt;http://lvl-softwares.com (195.88.80.41)&lt;/code&gt; (do NOT visit this site).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/Sen-nCi_cgI/AAAAAAAAAjM/Q15Z7oHMmXE/s1600-h/AVAntispyware.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 319px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/Sen-nCi_cgI/AAAAAAAAAjM/Q15Z7oHMmXE/s320/AVAntispyware.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5326067980994310658" /&gt;&lt;/a&gt;&lt;br /&gt;VirusTotal scan result for the dropper can be found &lt;a href="http://www.ca.com/securityadvisor/pest/pest.aspx?id=453146855"&gt;here&lt;/a&gt;, and AV Antispyware removal guide can be found &lt;a href="http://www.bleepingcomputer.com/virus-removal/remove-av-antispyware"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-5970871622157641017?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/s8lauVJ14Hs" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/04/new-rogue-av-antispyware.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/Sen-nCi_cgI/AAAAAAAAAjM/Q15Z7oHMmXE/s72-c/AVAntispyware.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-123025338413165292</guid><pubDate>Wed, 18 Mar 2009 14:40:00 +0000</pubDate><atom:updated>2009-03-18T20:28:28.793+05:30</atom:updated><title>Waledac's new geo-sensitive social engineering</title><description>&lt;a href="http://www.f-secure.com/v-descs/email-worm_w32_waledac_a.shtml"&gt;Waledac&lt;/a&gt; spammers are using yet another social engineering tactic to spread their malware.  As usual, the spam mails contain link to dubious websites. One of such spam mail can be seen in the following screenshot:&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/ScEJLnFTYBI/AAAAAAAAAio/MgkAtlzPNO8/s1600-h/Waledac_Blast1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 87px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/ScEJLnFTYBI/AAAAAAAAAio/MgkAtlzPNO8/s320/Waledac_Blast1.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5314539130348331026" /&gt;&lt;/a&gt;&lt;br /&gt;These websites look like a Reuters news webpage reporting "powerful bomb blasts" near your area/city, with a video clip embedded in it. To see the video, the site persuades you to download a fake Flash Player.&lt;br /&gt;&lt;br /&gt;These fake websites are geo-sensitive and they figure out the place/city of a visitor (based on visitor's IP address) and report it as the location of "bomb blasts".  This technique is called &lt;a href="http://en.wikipedia.org/wiki/Geo_targeting"&gt;geo-targeting&lt;/a&gt;. An innocuous PC user may fall for this trick by thinking that bomb blasts have really occurred in his/her area and download the fake Flash Player! Following screenshots show the location sensitive website content (check the place where blasts are reported; they change based on the visitor's gepgraphical location):&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/ScEJbZQpGuI/AAAAAAAAAiw/vtY7besxggY/s1600-h/Waledac_Blast2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/ScEJbZQpGuI/AAAAAAAAAiw/vtY7besxggY/s320/Waledac_Blast2.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5314539401515703010" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/ScEJr9WC_BI/AAAAAAAAAjA/v3BC1B2hR10/s1600-h/Waledac_Blast3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/ScEJr9WC_BI/AAAAAAAAAjA/v3BC1B2hR10/s320/Waledac_Blast3.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5314539686079953938" /&gt;&lt;/a&gt;&lt;br /&gt;As of now, fake webpage is located at &lt;code&gt;yyr.breakingkingnews.com (81.241.128.178)&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/breakingkingnews.com"&gt;whois&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;VirusTotal results of the malware hosted at the above site can be found &lt;a href="http://www.virustotal.com/analisis/c9c6958d7dc4d792db4c66b4f47dd888"&gt;here&lt;/a&gt; and &lt;a href="http://www.virustotal.com/analisis/eef11192d6b3d5e4566b2a79af88145c"&gt;here&lt;/a&gt;. An automated analysis by ThreatExpert can be found &lt;a href="http://www.threatexpert.com/report.aspx?md5=54801ee56a615253cff1e6ac0b6604db"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-123025338413165292?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/MPk10QAoUSw" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/03/waledacs-new-geo-sensitive-social.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_g2qoDleHSYA/ScEJLnFTYBI/AAAAAAAAAio/MgkAtlzPNO8/s72-c/Waledac_Blast1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-2486870212521488705</guid><pubDate>Sun, 15 Mar 2009 17:50:00 +0000</pubDate><atom:updated>2009-03-15T23:28:41.026+05:30</atom:updated><title>SysProt AntiRootkit v1.0.1.0 released</title><description>&lt;div&gt;Another update for SysProt AntiRootkit! The latest version, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;SysProt AntiRootkit v1.0.1.0&lt;/span&gt;, contains few bug fixes and enhancements. The changelog is as follows:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Added a "activity bar" to indicate scan progress&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Optimzed device driver scanning&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Added help file&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Fixed process and driver scanning bugs in Windows 2003 SP1 and SP2&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Get the latest version &lt;a href="http://sites.google.com/site/sysprotantirootkit/"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-2486870212521488705?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/l0fSX7uO95E" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/03/sysprot-antirootkit-v1010-released.html</link><author>noreply@blogger.com (swatkat)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-7454436022418491156</guid><pubDate>Thu, 12 Mar 2009 18:25:00 +0000</pubDate><atom:updated>2009-03-13T00:15:04.642+05:30</atom:updated><title>Yauba - Privacy Safe Search Engine!</title><description>&lt;blockquote&gt;&lt;/blockquote&gt;&lt;a href="http://www.yauba.co.in/"&gt;&lt;b&gt;Yauba&lt;/b&gt;&lt;/a&gt; is a brand new search engine from &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;India&lt;/st1:place&gt;&lt;/st1:country-region&gt;. Yauba's search result quality is great and is comparable to that of Google. Yauba neatly organizes the search results and also shows text/image previews of websites.&lt;br /&gt;&lt;br /&gt;One of the important features of Yauba is its stress of user's privacy and security. Yauba operates in complete &lt;i&gt;incognito&lt;/i&gt; mode and does not collect any personal data. Their privacy policy goes like this!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SblV2rRpQuI/AAAAAAAAAig/NgTdvdGZYE4/s1600-h/Yauba_PrivacyPolicy.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 82px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SblV2rRpQuI/AAAAAAAAAig/NgTdvdGZYE4/s320/Yauba_PrivacyPolicy.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5312371633278239458" /&gt;&lt;/a&gt;&lt;br /&gt;Here's an excerpt from Yauba's site, which tells us about their privacy practices:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Most search engines try to gather and record as much information about their users as possible. They (or their parent companies) operate massive server farms with even more massive databases that secretly record your entire search history, your private contacts, the identity of your family and friends, your personal emails, your conversations and chats, your browsing habits, your physical location, details on the software you use on your computer, your IP address, and much much more. This is no exaggeration. Indeed, if you ever saw exactly how much most search engines actually know about your private details, you would be completely shocked.&lt;br /&gt;&lt;br /&gt;At Yauba, we completely reject the view that search engines somehow need to keep mountains of data on their own users. Instead, we take the exact opposite approach. We do everything we can to protect the privacy of our users.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;This is why we do not keep any record of any of your search terms, browsing habits or any other personally identifiable information.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;This is why we automatically delete any and every piece of personally identifiable information from our servers on a continuous basis.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;This is why we can have the shortest privacy policy (9 words) of any major Internet service in the world.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;This is why you can visit almost every Internet site through the main Yauba service on a completely anonymous basis (with the only exception of file types that use other external third party software or plug-ins for downloading or playing).&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Yauba is still in Beta/Late-Alpha state, and I think it is a very good service. Try Yauba at &lt;span class="Apple-style-span" style="color: rgb(85, 26, 139); text-decoration: underline;"&gt;&lt;a href="http://www.yauba.com/"&gt;http://www.yauba.com/&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-7454436022418491156?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/TnZ_3Ca6yWE" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/03/yauba-privacy-safe-search-engine.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SblV2rRpQuI/AAAAAAAAAig/NgTdvdGZYE4/s72-c/Yauba_PrivacyPolicy.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-1385850648292335791</guid><pubDate>Sat, 07 Mar 2009 20:52:00 +0000</pubDate><atom:updated>2009-03-08T02:37:42.616+05:30</atom:updated><title>SysProt AntiRootkit v1.0.0.9 released</title><description>&lt;div&gt;Here's the latest version of SysProt AntiRootkit. Now, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;SysProt AntiRootkit v1.0.0.9&lt;/span&gt; supports Windows Vista (32 bit)! Check out few screenshots that show SysProt AntiRootkit in action:&lt;/div&gt;&lt;br /&gt;Kernel modules:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SbLfJ5v9j4I/AAAAAAAAAhw/poFDiwRPWQQ/s1600-h/SysProtARK_KM.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SbLfJ5v9j4I/AAAAAAAAAhw/poFDiwRPWQQ/s320/SysProtARK_KM.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5310552271837040514" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SbLgFw7-ecI/AAAAAAAAAiQ/O-JconP2Drw/s1600-h/SysProtARK_KM_Vista.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 229px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SbLgFw7-ecI/AAAAAAAAAiQ/O-JconP2Drw/s320/SysProtARK_KM_Vista.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5310553300263664066" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SSDT hooks:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SbLfVTIN8UI/AAAAAAAAAh4/pZvjU0YH-kY/s1600-h/SysProtARK_SSDT.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SbLfVTIN8UI/AAAAAAAAAh4/pZvjU0YH-kY/s320/SysProtARK_SSDT.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5310552467628224834" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_g2qoDleHSYA/SbLgPjQdruI/AAAAAAAAAiY/freRNTqhmvg/s1600-h/SysProtARK_SSDT_Vista.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 229px;" src="http://4.bp.blogspot.com/_g2qoDleHSYA/SbLgPjQdruI/AAAAAAAAAiY/freRNTqhmvg/s320/SysProtARK_SSDT_Vista.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5310553468390190818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Kernel inline hooks:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SbLfdUIR5II/AAAAAAAAAiA/R1pYKBDU0Z8/s1600-h/SysProtARK_KernelHook.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SbLfdUIR5II/AAAAAAAAAiA/R1pYKBDU0Z8/s320/SysProtARK_KernelHook.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5310552605335872642" /&gt;&lt;/a&gt;&lt;br /&gt;Following list summarizes the changes in &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;SysProt AntiRootkit v1.0.0.9&lt;/span&gt;:&lt;div&gt;&lt;ul&gt;&lt;li&gt;Added Windows Vista support&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Improved device driver detection&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Faster "Kernel Hooks" scan&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Faster "Ports" scan&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;The latest version can be downloaded from &lt;a href="http://sites.google.com/site/sysprotantirootkit/"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;. Supported operating systems are Windows 2000/XP/2003/Vista, 32 bit versions. Feedback is welcome :)&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-1385850648292335791?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/dCZa1J1Vv_c" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/03/sysprot-antirootkit-v1009-released.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_g2qoDleHSYA/SbLfJ5v9j4I/AAAAAAAAAhw/poFDiwRPWQQ/s72-c/SysProtARK_KM.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-5613297452125888652</guid><pubDate>Mon, 26 Jan 2009 14:29:00 +0000</pubDate><atom:updated>2009-01-26T23:24:14.590+05:30</atom:updated><title>New rogue: IE-Security</title><description>&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security&lt;/span&gt; is new rogue software that belongs to &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-111420-0754-99"&gt;IEDefender&lt;/a&gt; family. The IE-Security installer, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;ie.exe&lt;/span&gt;, is hosted at &lt;code&gt;216.240.151.112&lt;/code&gt; and &lt;code&gt;http://ie-security.com (216.240.151.135)&lt;/code&gt;. The user-interface of IE-Security is a rip-off of &lt;a href="http://www.microsoft.com/windows/products/winfamily/defender/default.mspx"&gt;Microsoft Windows Defender&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SX3JGFgJKUI/AAAAAAAAAhU/dE_JZDIfIRo/s1600-h/IE-Security_1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 257px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SX3JGFgJKUI/AAAAAAAAAhU/dE_JZDIfIRo/s320/IE-Security_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5295609843250964802" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;VirusTotal scan result of IE-Security installer can be found &lt;a href="http://www.virustotal.com/analisis/70c7e788714c3fb3ad90862e79bc3470"&gt;here&lt;/a&gt;. By the way, people at IE-Security provide 27x7 support ;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SX3JVRqkNcI/AAAAAAAAAhc/54cOUQmXKL8/s1600-h/IE-Security_2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 257px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SX3JVRqkNcI/AAAAAAAAAhc/54cOUQmXKL8/s320/IE-Security_2.jpg" alt="" id="BLOGGER_PHOTO_ID_5295610104213943746" border="0" /&gt;&lt;/a&gt;&lt;div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238); text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Files dropped by IE-Security installer:&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\ies.s1&lt;/span&gt;&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\ies.s2&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\ies.s3&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\ies.s4&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\iescan.exe&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%PROGRAMFILES%\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security\uninstall.exe&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%USERPROFILE%\Desktop\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security.lnk&lt;/span&gt;&lt;/div&gt;&lt;div&gt;%USERPROFILE%\Start Menu\Programs\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security.lnk&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;where,&lt;/div&gt;&lt;div&gt;%PROGRAMFILES% is &lt;span class="Apple-style-span" style="font-style: italic;"&gt;\Program Files\&lt;/span&gt; directory in root-drive,&lt;br /&gt;&lt;/div&gt;&lt;div&gt;%USERPROFILE% is &lt;span class="Apple-style-span" style="font-style: italic;"&gt;\Documents and Settings\UserName\&lt;/span&gt; directory in root-drive.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Registry keys created by IE-Security installer:&lt;/div&gt;&lt;div&gt;HKEY_CURRENT_USER\Software\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"IE-Security"&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IE-Security&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-5613297452125888652?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/EIbQ8RnvnNI" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/01/new-rogue-ie-security.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_g2qoDleHSYA/SX3JGFgJKUI/AAAAAAAAAhU/dE_JZDIfIRo/s72-c/IE-Security_1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-6598109202346113168</guid><pubDate>Mon, 26 Jan 2009 10:38:00 +0000</pubDate><atom:updated>2009-01-26T18:23:11.797+05:30</atom:updated><title>AntiSpyware 2009 and AntiSpywareBOT: Neighbours in crime!</title><description>Well, &lt;span style="font-style: italic;"&gt;590-B Schillinger Rd. South, Mobile, Al, 36695&lt;/span&gt; seems to be the &lt;a href="http://en.wikipedia.org/wiki/John_Doe"&gt;John Doe&lt;/a&gt; of addresses. Recently &lt;a href="http://blogs.paretologic.com/malwarediaries/index.php/2009/01/23/sweet-home-alabama/"&gt;ParetoLogic blog&lt;/a&gt; posted about the address of the makers of rogueware &lt;a href="http://research.sunbelt-software.com/threatdisplay.aspx?&amp;amp;threatid=448762"&gt;AntiSpyware 2009&lt;/a&gt;. It seems that the headquarters of &lt;a href="http://spywarewarrior.com/viewtopic.php?p=152826"&gt;2Squared&lt;/a&gt;, makers of rogueware &lt;a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=AntiSpywareBot&amp;amp;threatid=234001"&gt;AntiSpywareBOT&lt;/a&gt;, is also located in the same street. Even these guys have got a high-tech, high-profile &lt;a href="http://en.wikipedia.org/wiki/Computer-generated_imagery"&gt;CGI&lt;/a&gt; office ;)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SX2UP9z3b2I/AAAAAAAAAhM/APlpBKpVdKY/s1600-h/AntiSpywareBOT_Office.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 230px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SX2UP9z3b2I/AAAAAAAAAhM/APlpBKpVdKY/s320/AntiSpywareBOT_Office.jpg" alt="" id="BLOGGER_PHOTO_ID_5295551738868625250" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-6598109202346113168?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/XTHwUsjm5WU" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/01/antispyware-2009-and-antispywarebot.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SX2UP9z3b2I/AAAAAAAAAhM/APlpBKpVdKY/s72-c/AntiSpywareBOT_Office.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-7436581105709300828</guid><pubDate>Sat, 17 Jan 2009 18:53:00 +0000</pubDate><atom:updated>2009-01-18T00:54:13.140+05:30</atom:updated><title>Fake Obama websites spreading malware</title><description>&lt;div&gt;Similar to &lt;a href="http://swatrant.blogspot.com/2009/01/fake-ecard-updates.html"&gt;eCard spam&lt;/a&gt; mails, we are now seeing US president-elect Barack Obama themed mails which contain links to fake websites. These sites host a malicious executable and this malware belongs to the same old &lt;a href="http://en.wikipedia.org/wiki/Storm_botnet"&gt;Storm/Waledac&lt;/a&gt; family. One such mail and a fake website (&lt;code&gt;http://donate.superobamadirect.com&lt;/code&gt;) are shown in following screenshots:&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SXIsSnmMCUI/AAAAAAAAAgs/TN3OIutUyUc/s1600-h/FakeObamaSites1.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 126px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SXIsSnmMCUI/AAAAAAAAAgs/TN3OIutUyUc/s320/FakeObamaSites1.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5292341210492176706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SXIsfAHI-_I/AAAAAAAAAg0/AzPJnzkffTg/s1600-h/FakeObamaSites.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SXIsfAHI-_I/AAAAAAAAAg0/AzPJnzkffTg/s320/FakeObamaSites.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5292341423231269874" /&gt;&lt;/a&gt;&lt;br /&gt;These fake sites are hosted using &lt;a href="http://en.wikipedia.org/wiki/Fast_flux"&gt;fast flux&lt;/a&gt; DNS technique - a typical method used by Storm botnet. It can be seen from the following screenshot that the IP address keeps changing frequently:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SXIvcyVnbQI/AAAAAAAAAg8/jLT7OhD5uOk/s1600-h/FakeObamaSites2.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 279px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SXIvcyVnbQI/AAAAAAAAAg8/jLT7OhD5uOk/s320/FakeObamaSites2.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5292344683709033730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;VirusTotal scan result of the malware can be found &lt;a href="http://www.virustotal.com/analisis/932e9178548d6fb39d82a5b5254bf24d"&gt;here&lt;/a&gt;. An automated analysis by ThreatExpert can be found &lt;a href="http://www.threatexpert.com/report.aspx?md5=ad9ccd3227b2ce1883c036819aa7b63f"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-7436581105709300828?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/mx1T3ak_Mwo" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/01/fake-obama-websites-spreading-malware.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SXIsSnmMCUI/AAAAAAAAAgs/TN3OIutUyUc/s72-c/FakeObamaSites1.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-6352902655718177230</guid><pubDate>Wed, 07 Jan 2009 19:50:00 +0000</pubDate><atom:updated>2009-01-08T01:34:30.042+05:30</atom:updated><title>Fake eCard updates</title><description>Fake eCard spam mails continue to circulate even after the new-year excitement is settled down. As usual, these mails contain links to downloadable fake greeting cards that are generally named "card.exe" or "postcard.exe".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SWUJk9PmbPI/AAAAAAAAAgk/j1BLXcEtESg/s1600-h/Waledac_eCard_1.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 102px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SWUJk9PmbPI/AAAAAAAAAgk/j1BLXcEtESg/s320/Waledac_eCard_1.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5288643867936451826" /&gt;&lt;/a&gt;&lt;br /&gt;When executed, these malicious executables turn your PC into a &lt;a href="http://en.wikipedia.org/wiki/Zombie_computer"&gt;zombie machine&lt;/a&gt; that becomes a part of &lt;a href="http://en.wikipedia.org/wiki/Storm_botnet"&gt;Storm/Waledac botnet&lt;/a&gt; (more information can be found &lt;a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231"&gt;here&lt;/a&gt; and &lt;a href="http://blog.threatfire.com/2009/01/ongoing-waledac-botnet-and-spam.html"&gt;here&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SWUIfs2n4YI/AAAAAAAAAgc/7aXVni2EFcE/s1600-h/Waledac_eCard.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SWUIfs2n4YI/AAAAAAAAAgc/7aXVni2EFcE/s320/Waledac_eCard.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5288642678125748610" /&gt;&lt;/a&gt;&lt;br /&gt;Newer variants of fake eCard executables (hosted at &lt;code&gt;http://topgreetingsite.com&lt;/code&gt; - do NOT visit that site! ) are not detected by many AVs as of now (as seen in VirusTotal scan &lt;a href="http://www.virustotal.com/analisis/335792ef8e18daa8f05062a726dc46d9"&gt;here&lt;/a&gt;). An automated analysis of this file is available at ThreatExpert &lt;a href="http://www.threatexpert.com/report.aspx?md5=e26d8006afd9e34cf99d96220c3e3480"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-6352902655718177230?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/BW_IYAJjNi0" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/01/fake-ecard-updates.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_g2qoDleHSYA/SWUJk9PmbPI/AAAAAAAAAgk/j1BLXcEtESg/s72-c/Waledac_eCard_1.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-2197953180289758460</guid><pubDate>Tue, 06 Jan 2009 17:49:00 +0000</pubDate><atom:updated>2009-01-10T16:07:56.953+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Zlob rootkit</category><category domain="http://www.blogger.com/atom/ns#">TDSServ rootkit removal</category><category domain="http://www.blogger.com/atom/ns#">SysProt AntiRootkit</category><title>SysProt AntiRootkit v1.0.0.8 released</title><description>&lt;div&gt;A few key improvements were made in driver detection and disabling mechanisms, and hence here's the latest version of SysProt AntiRootkit :) The &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;SysProt AntiRootkit v1.0.0.8&lt;/span&gt; successfully detects and removes Zlob rootkits (&lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/maltdssa.html"&gt;TDSServ&lt;/a&gt; or &lt;a href="http://www.threatexpert.com/threats/trojan-win32-alureon-gen-j.html"&gt;Alureon&lt;/a&gt; family).&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Similar to the steps followed in the case of GMER (as mentioned in the &lt;a href="http://swatrant.blogspot.com/2008/12/zlob-fake-codec-rootkit-removal.html"&gt;previous post&lt;/a&gt;), SysProt AntiRootkit requires two reboots to completely remove rootkit driver and its Registry entry. Following screenshots show SysProt AntiRootkit detecting Zlob rootkit driver and injected DLL:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SWOa3LO8gSI/AAAAAAAAAgE/Ym5aRR5R4IY/s1600-h/SysProtARK_KernelModules.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SWOa3LO8gSI/AAAAAAAAAgE/Ym5aRR5R4IY/s320/SysProtARK_KernelModules.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5288240660162052386" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SWObLYZDEtI/AAAAAAAAAgM/OTQ2g--eyU4/s1600-h/SysProtARK_DLLs.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SWObLYZDEtI/AAAAAAAAAgM/OTQ2g--eyU4/s320/SysProtARK_DLLs.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5288241007291470546" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Steps to remove Zlob rootkit driver:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Run SysProt AntiRootkit v1.0.0.8 and click "Kernel Modules" tab.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;SysProt AntiRootkit shows rootkit/hidden drivers in red color. Click on the rootkit driver's entry and the click "Disable"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Reboot the PC&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Repeat steps 1 to 3 (SysProt AntiRootkit will detect the same rootkit driver again)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Now, all the malicious files dropped by Zlob should be unrooted and hence "visible" to standard anti-malware scanners.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style=""&gt;More information, changelog and download link for &lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;SysProt AntiRootkit v1.0.0.8&lt;/span&gt; can be found at following locations:&lt;br /&gt;&lt;a href="http://majorgeeks.com/SysProt_AntiRootkit_d5708.html"&gt;MajorGeeks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.softpedia.com/get/Security/Security-Related/SysProt-AntiRootkit.shtml"&gt;Softpedia&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sites.google.com/site/sysprotantirootkit"&gt;SysProt AntiRootkit primary download page&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Feedbacks are welcome :)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-2197953180289758460?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/ZlB4f1eFkas" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2009/01/sysprot-antirootkit-v1008-released.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SWOa3LO8gSI/AAAAAAAAAgE/Ym5aRR5R4IY/s72-c/SysProtARK_KernelModules.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-1319337916993493306</guid><pubDate>Wed, 31 Dec 2008 17:28:00 +0000</pubDate><atom:updated>2009-01-09T23:31:56.959+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Zlob rootkit</category><category domain="http://www.blogger.com/atom/ns#">TDSServ rootkit removal</category><title>Zlob fake codec rootkit removal procedure</title><description>Lately there has been a rise in rootkit based Zlob fake codecs and video players. The rootkit belongs to &lt;a href="http://www.pctools.com/mrc/infections/id/Trojan.TDSServ/"&gt;TDSServ family&lt;/a&gt;, and is quite difficult to remove using standard anti-malware tools. Now, we will see how to remove these rootkit based Zlob malware. This removal procedure holds good for Zlob variants that drop kernel mode rootkits such as &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;BrakePlayer&lt;/span&gt;, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Moon-Player&lt;/span&gt;, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;TurboPlayer &lt;/span&gt;and &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Light-Track&lt;/span&gt; etc.&lt;br /&gt;&lt;br /&gt;The removal process consists of three steps:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Removing rootkit driver file and its Registry entry&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Removing other malware files dropped by Zlob installer&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Removing stray "shell open command" entry (a.k.a malicious autorun.inf file)&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;Download the following tools and install them (do not run them as of now):&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.gmer.net/files.php"&gt;GMER&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.malwarebytes.org/mbam.php"&gt;Malwarebytes' Anti-Malware (MBAM)&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Removing rootkit driver file and its Registry entry:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Launch GMER.exe. As soon as GMER starts, it performs a preliminary system scan. If it finds any traces of rootkit, it will ask you to run a full PC scan. Click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"No"&lt;/span&gt; for this prompt.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Now, click on &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Rootkit/Malware"&lt;/span&gt; tab and then select only &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Services"&lt;/span&gt; checkbox (deselect all other scan options). Click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Scan"&lt;/span&gt; button to start scan. An example is shown in screenshot below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_g2qoDleHSYA/SVus-1Iz7MI/AAAAAAAAAfk/p0pppaxRnIs/s1600-h/GMER_Services_Scan.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 246px;" src="http://4.bp.blogspot.com/_g2qoDleHSYA/SVus-1Iz7MI/AAAAAAAAAfk/p0pppaxRnIs/s320/GMER_Services_Scan.JPG" alt="" id="BLOGGER_PHOTO_ID_5286008783065312450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;GMER should show the rootkit service after the scan. Right-click on that entry and click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Delete Service"&lt;/span&gt;. Click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Yes"&lt;/span&gt; for the prompts that pop up. An example screenshot is shown below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SVuta9NgC3I/AAAAAAAAAfs/yaYxKPuutpA/s1600-h/GMER_Services_DeleteService.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 246px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SVuta9NgC3I/AAAAAAAAAfs/yaYxKPuutpA/s320/GMER_Services_DeleteService.JPG" alt="" id="BLOGGER_PHOTO_ID_5286009266268801906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Reboot the PC.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Run GMER again and repeat steps 1, 2, 3 and 4 &lt;b&gt;again&lt;/b&gt; (GMER will again detect the same rootkit service again).&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Note: If GMER does not detect any rootkit in its preliminary system scan (in Step 1 above), then you may not have kernel-mode rootkit variant of Zlob (or GMER is not detecting it ;)). Proceed to the section below.&lt;br /&gt;&lt;br /&gt;Update: Zlob rootkit driver can also be removed using SysProt AntiRootkit. More information can be found &lt;a href="http://swatrant.blogspot.com/2009/01/sysprot-antirootkit-v1008-released.html"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Removing other malware files dropped by Zlob installer:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Run Malwarebytes' Anti-Malware (MBAM), click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Update"&lt;/span&gt; tab and then click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Check for updates"&lt;/span&gt; button to download latest malware database.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Once the update completes, click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Scanner"&lt;/span&gt; tab and select the &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"Perform full scan"&lt;/span&gt; option. Select all the hard disk partitions (C:\, D:\ etc) and then click &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;"OK"&lt;/span&gt; to start scan.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Once the scan completes, remove all the malware that MBAM may report. An example screenshot is shown below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SVutskk-uVI/AAAAAAAAAf0/FnYNB84A5GA/s1600-h/MBAM_Scan.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 200px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SVutskk-uVI/AAAAAAAAAf0/FnYNB84A5GA/s320/MBAM_Scan.JPG" alt="" id="BLOGGER_PHOTO_ID_5286009568894040402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Reboot the PC.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Removing stray "shell open command" (a.k.a malicious autorun.inf file):&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Go to &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Start Menu&lt;/span&gt; &gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt; Search&lt;/span&gt; option to open Windows Search tool. Make Search to look in &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;sytem/hidden&lt;/span&gt; folders and files. Finally, search for files named &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;autorun.inf&lt;/span&gt;.  An example screenshot is shown below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SVu2wMCZrvI/AAAAAAAAAf8/VnlGlMV-j2Q/s1600-h/Autorun_Search.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 230px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SVu2wMCZrvI/AAAAAAAAAf8/VnlGlMV-j2Q/s320/Autorun_Search.JPG" alt="" id="BLOGGER_PHOTO_ID_5286019526630682354" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;These autorun.inf files contain few commands which instruct Windows Explorer to load a Zlob malware file (generally, &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;%rootdrive%\resycled\boot.com&lt;/span&gt;&lt;/span&gt;) whenever a user double-clicks on drive icons. Delete all the &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;autorun.inf&lt;/span&gt; files found in hard disk partitions (for ex: C:\, D:\ etc)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Reboot the PC.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;Finally, run an online scan at &lt;a href="http://support.f-secure.com/enu/home/ols.shtml"&gt;F-Secure&lt;/a&gt; or &lt;a href="http://housecall.trendmicro.com/"&gt;TrendMicro&lt;/a&gt; to make sure that the PC is clean. Hopefully, the Zlob rootkit will be gone for good by this time!&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-1319337916993493306?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/gBZQD513K6w" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/zlob-fake-codec-rootkit-removal.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_g2qoDleHSYA/SVus-1Iz7MI/AAAAAAAAAfk/p0pppaxRnIs/s72-c/GMER_Services_Scan.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-9143536118511569451</guid><pubDate>Tue, 30 Dec 2008 18:15:00 +0000</pubDate><atom:updated>2008-12-30T23:53:36.690+05:30</atom:updated><title>Rogue security software video tutorials</title><description>This is really hilarious. It seems that the &lt;a href="http://en.wikipedia.org/wiki/Rogue_software"&gt;rogue software&lt;/a&gt; gang decided to improve &lt;a href="http://en.wikipedia.org/wiki/Out-Of-Box_Experience"&gt;OOBE&lt;/a&gt; of their software! They now have video tutorials at &lt;a href="http://in.youtube.com/"&gt;YouTube&lt;/a&gt;, which tell how to run online malware-scan and how to remove malware using their software for FREE! Check out these screenshots of the video:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SVplr67H46I/AAAAAAAAAfc/42O5oR3rpCA/s1600-h/Rogue_On_YouTube.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SVplr67H46I/AAAAAAAAAfc/42O5oR3rpCA/s320/Rogue_On_YouTube.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5285648917898716066" /&gt;&lt;/a&gt;&lt;br /&gt;Here are the links to some videos:&lt;br /&gt;http://www.youtube.com/watch?v=jykJ1erupZ4&lt;br /&gt;http://www.youtube.com/watch?v=FSQ0WpoyZJo&lt;br /&gt;&lt;br /&gt;Video uploaders' profiles:&lt;br /&gt;http://www.youtube.com/user/AntiVirusSpywareMalw&lt;br /&gt;http://www.youtube.com/user/OkThisJustAnti&lt;br /&gt;&lt;br /&gt;The webiste, &lt;code&gt;www.antiviruson.com (89.111.176.21)&lt;/code&gt;, mentioned in those tutorials redirects to another website that hosts &lt;a href="http://swatrant.blogspot.com/2008/12/new-rogue-system-security.html"&gt;System Security&lt;/a&gt; rogue application. Do NOT follow the steps told in those tutorials ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-9143536118511569451?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/53tBnot1bmI" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/rogue-security-software-video-tutorials.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SVplr67H46I/AAAAAAAAAfc/42O5oR3rpCA/s72-c/Rogue_On_YouTube.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-6028788054026710468</guid><pubDate>Sun, 28 Dec 2008 17:35:00 +0000</pubDate><atom:updated>2009-01-01T12:48:28.153+05:30</atom:updated><title>Zlob updates</title><description>Zlob gang does not seem to be in holiday mood. They are churning up more domains to spread their &lt;a href="http://www.stopbadware.org/home/badware"&gt;badware&lt;/a&gt;. Here are some of the new domains:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;94.247.3.232&lt;br /&gt;216.240.151.112&lt;br /&gt;78.159.99.52&lt;br /&gt;www.newdllsolution.com (92.241.163.90)&lt;br /&gt;http://brakeplayer.net (94.247.2.183)&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;One of the site mentioned above, &lt;code&gt;http://brakeplayer.net (94.247.2.183)&lt;/code&gt;, hosts a fake media player installer called &lt;b&gt;BrakePlayer&lt;/b&gt;. This installer actually installs a nasty kernel mode rootkit. Following screenshot shows the kernel mode hooks installed by rootkit driver:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SVfF9wbl3GI/AAAAAAAAAfU/z31DCtSLYh0/s1600-h/brakeplayer_rootkit.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SVfF9wbl3GI/AAAAAAAAAfU/z31DCtSLYh0/s320/brakeplayer_rootkit.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5284910352505887842" /&gt;&lt;/a&gt;&lt;br /&gt;The &lt;a href="http://en.wikipedia.org/wiki/Backdoor_(computing)"&gt;backdoor&lt;/a&gt; component of this rootkit establishes connection with a remote rogue server &lt;code&gt;85.255.112.188&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/85.255.112.188"&gt;whois&lt;/a&gt;). VirusTotal scan results for the installer and rootkit driver files can be found &lt;a href="http://www.virustotal.com/analisis/babfab40f4572b4aaaf0db20dcf4eee9"&gt;here&lt;/a&gt; and &lt;a href="http://www.virustotal.com/analisis/fea2f902beb3a6eaab8cb472cf14ddb2"&gt;here&lt;/a&gt; respectively.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Update:&lt;/b&gt; BrakePlayer removal procedure has been posted &lt;a href="http://swatrant.blogspot.com/2008/12/zlob-fake-codec-rootkit-removal.html"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;. Hope that helps :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-6028788054026710468?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/znAzNmxEPdY" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/zlob-updates_28.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SVfF9wbl3GI/AAAAAAAAAfU/z31DCtSLYh0/s72-c/brakeplayer_rootkit.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-4473427010657956861</guid><pubDate>Fri, 26 Dec 2008 16:18:00 +0000</pubDate><atom:updated>2008-12-26T21:52:33.295+05:30</atom:updated><title>New rogue: System Security</title><description>&lt;b&gt;System Security&lt;/b&gt; is new rogue software. The installer is hosted at &lt;code&gt;http://webnetworksecurity.com (91.211.64.31)&lt;/code&gt;. Here's a screenshot of System Security:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SVUELpOU6aI/AAAAAAAAAfM/qweh5GB4BJA/s1600-h/SystemSecurity.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 224px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SVUELpOU6aI/AAAAAAAAAfM/qweh5GB4BJA/s320/SystemSecurity.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5284134335880161698" /&gt;&lt;/a&gt;&lt;br /&gt;VirusTotal scan results for the installer can be found &lt;a href="http://www.virustotal.com/analisis/988284739f2cf32ec7a58610e4c5fa31"&gt;here&lt;/a&gt;. BleepingComputer has a removal guide &lt;a href="http://www.bleepingcomputer.com/malware-removal/remove-system-security"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-4473427010657956861?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/z2Plg5BDWSA" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/new-rogue-system-security.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SVUELpOU6aI/AAAAAAAAAfM/qweh5GB4BJA/s72-c/SystemSecurity.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-4997408925066826931</guid><pubDate>Mon, 22 Dec 2008 17:20:00 +0000</pubDate><atom:updated>2008-12-22T23:10:53.762+05:30</atom:updated><title>Zlob updates</title><description>Here are some of the new &lt;a href="http://en.wikipedia.org/wiki/Zlob_trojan"&gt;Zlob trojan&lt;/a&gt; spreading domains:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;http://vidzwares.com (92.241.163.90)&lt;br /&gt;http://light-player.net (94.247.2.183)&lt;br /&gt;http://fire-player.net (93.190.140.48)&lt;br /&gt;http://downloadallsoft-now.com (94.247.3.228)&lt;br /&gt;http://myprivatetubes09.net (91.208.0.221)&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;One of the Zlob variant (named &lt;code&gt;wmpcdcs.exe&lt;/code&gt;, hosted at &lt;code&gt;http://myprivatetubes09.net&lt;/code&gt;) uses Microsoft Windows &lt;a href="http://msdn.microsoft.com/en-us/library/aa362708(VS.85).aspx"&gt;Background Intelligent Transfer Service (BITS)&lt;/a&gt; to communicate with rogue servers to transfer data. Since BITS is a trusted Windows component, firewalls don't block it; making it easy for malware to download files from remote servers (info &lt;a href="https://forums.symantec.com/t5/Security-Risks/Malware-Update-with-Windows-Update/ba-p/306452;jsessionid=6450DE08D0CC93B994F7DB8F2D916646#A19"&gt;here&lt;/a&gt; and &lt;a href="http://blog.washingtonpost.com/securityfix/2007/05/malware_using_microsoft_patch.html?nav=rss_blog"&gt;here&lt;/a&gt;). An automated analysis of this malware is available at ThreatExpert &lt;a href="http://www.threatexpert.com/report.aspx?md5=4d4323e8a625b7a5c91a1525190133f5"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-4997408925066826931?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/-alKgt0283M" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/zlob-updates.html</link><author>noreply@blogger.com (swatkat)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-1924903890309826971</guid><pubDate>Sun, 21 Dec 2008 11:54:00 +0000</pubDate><atom:updated>2008-12-21T23:09:31.407+05:30</atom:updated><title>Antivirus 360 featured in top PC magazines and antivirus certification labs!</title><description>No, we are not talking about &lt;a href="http://www.symantec.com/norton360/"&gt;Norton 360&lt;/a&gt;, which is a genuine security software. This is about &lt;b&gt;Antivirus 360&lt;/b&gt;, one of the latest rogue security software (info &lt;a href="http://sunbeltblog.blogspot.com/2008/12/new-rogue-scareware-program-antivirus.html"&gt;here&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Now, gang responsible for Antivirus 360 has gone one step further! Their new site, &lt;code&gt;http://anti-viruspcscanner.com (78.46.216.238)&lt;/code&gt;, claims that Antivirus 360 has been rated as top antivirus solution by reputed websites like &lt;a href="http://computershopper.com/"&gt;Computer Shopper&lt;/a&gt;, &lt;a href="http://www.laptopmag.com/"&gt;LAPTOP Magazine&lt;/a&gt;, &lt;a href="http://www.pcmag.com/"&gt;PC Magazine&lt;/a&gt;, &lt;a href="http://www.computeractive.co.uk/"&gt;Computer Active&lt;/a&gt;, &lt;a href="http://www.pcadvisor.co.uk/"&gt;PC Advisor&lt;/a&gt; and &lt;a href="http://www.cnet.com/"&gt;CNET&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xQD8BHiI/AAAAAAAAAe0/JLcFVT6U37M/s1600-h/Av360_1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xQD8BHiI/AAAAAAAAAe0/JLcFVT6U37M/s320/Av360_1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5282213564956876322" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xdYUQylI/AAAAAAAAAe8/qyIJxsNqaE0/s1600-h/Av360_2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xdYUQylI/AAAAAAAAAe8/qyIJxsNqaE0/s320/Av360_2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5282213793765575250" /&gt;&lt;/a&gt;&lt;br /&gt;Apart from this, they also blatantly display &lt;a href="http://www.virusbtn.com/"&gt;Virus Bulletin&lt;/a&gt;, &lt;a href="http://www.check-mark.com/"&gt;West Coast Labs Checkmark&lt;/a&gt; and &lt;a href="http://www.icsalabs.com/"&gt;ICSA Labs&lt;/a&gt; certifications, which are obviously fake!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xnnmj5GI/AAAAAAAAAfE/hgd2bqGcvYQ/s1600-h/Av360_3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xnnmj5GI/AAAAAAAAAfE/hgd2bqGcvYQ/s320/Av360_3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5282213969667548258" /&gt;&lt;/a&gt;&lt;br /&gt;All these fake recommendations and a deceptive name may lead an innocent PC user to download Antivirus 360 into his/her PC.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SU4voiS0wXI/AAAAAAAAAes/dD-hxmq_u7U/s1600-h/Av360_4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 198px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SU4voiS0wXI/AAAAAAAAAes/dD-hxmq_u7U/s320/Av360_4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5282211786399203698" /&gt;&lt;/a&gt;&lt;br /&gt;As per the site &lt;code&gt;http://anti-viruspcscanner.com (78.46.216.238)&lt;/code&gt;, the company responsible for Antivirus 360 is:&lt;br /&gt;&lt;code&gt;BOLZAR LIMITED Arch. Makariou III. 69. TLAIS TOWER. P.C. 1070. Nicosia, Cyprus.&lt;br /&gt;Contact email: company@Antivirus360pro.com&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;And, it seems that BOLZAR LIMITED (&lt;code&gt;http://bolzar.biz (216.195.62.169)&lt;/code&gt;) develops few other fake security software as well:&lt;br /&gt;&lt;b&gt;Antivirus Security&lt;/b&gt; - &lt;code&gt;http://antivirussecurity-solution.com/ (89.149.255.191)&lt;/code&gt;&lt;br /&gt;&lt;b&gt;Antispyware32&lt;/b&gt; - &lt;code&gt;http://antispyware32.com/ (84.16.231.194)&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;VirusTotal scan result of Antivirus 360 is available &lt;a href="http://www.virustotal.com/analisis/62c8db6da8797579eedf2b39c2d17c04"&gt;here&lt;/a&gt;. An automated analysis of Antivirus 360 is available at &lt;a href="http://www.threatexpert.com/report.aspx?md5=e700015a104159701ab7b486ef609f1c"&gt;ThreatExpert&lt;/a&gt;. Stay away from these rogues :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-1924903890309826971?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/zPq2D5hUsK8" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/12/antivirus-360-featured-in-top-pc.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SU4xQD8BHiI/AAAAAAAAAe0/JLcFVT6U37M/s72-c/Av360_1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">9</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-3774071823957021425</guid><pubDate>Sat, 22 Nov 2008 16:52:00 +0000</pubDate><atom:updated>2008-11-30T15:44:39.035+05:30</atom:updated><title>eCard worm: The new batch!</title><description>After a brief period of inactivity, &lt;a href="http://en.wikipedia.org/wiki/Storm_Worm"&gt;eCard&lt;/a&gt; themed spam mails seem to be back in action. As usual, these mails carry links to malware masqueraded as e-greeting cards. Here are some examples of eCard mails (note that the &lt;code&gt;From&lt;/code&gt; header is spoofed):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_g2qoDleHSYA/SSg6fLvd3eI/AAAAAAAAAV0/ag04-KEbG9A/s1600-h/Ecards_1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 292px;" src="http://4.bp.blogspot.com/_g2qoDleHSYA/SSg6fLvd3eI/AAAAAAAAAV0/ag04-KEbG9A/s320/Ecards_1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5271527671239400930" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SSg6kuY8lZI/AAAAAAAAAV8/qL2U7AGrPYc/s1600-h/Ecards_2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 241px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SSg6kuY8lZI/AAAAAAAAAV8/qL2U7AGrPYc/s320/Ecards_2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5271527766439531922" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This eCard malware is a &lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojzapchasz.html"&gt;mIRC based backdoor&lt;/a&gt;, and most of the AVs detect it. The dropper is actually a &lt;a href="http://en.wikipedia.org/wiki/Self-extracting_archive"&gt;SFX&lt;/a&gt; file, following screenshot shows files bundled in the dropper:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SSg-HJ3fAhI/AAAAAAAAAWM/xwSA4HW_8ME/s1600-h/Ecards_3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 173px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SSg-HJ3fAhI/AAAAAAAAAWM/xwSA4HW_8ME/s320/Ecards_3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5271531656465809938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;When run, the dropper installs an mIRC client and also adds a &lt;a href="http://msdn.microsoft.com/en-us/library/ms644959(VS.85).aspx"&gt;WH_KEYBOARD&lt;/a&gt; message hook to log keystrokes. The mIRC client tries to establish connection with remote servers &lt;code&gt;89.46.165.197&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/89.46.165.197"&gt;whois&lt;/a&gt;) and &lt;code&gt;210.51.167.75&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/210.51.167.75"&gt;whois&lt;/a&gt;). An automated analysis of this malware is avilable at &lt;a href="http://www.threatexpert.com/report.aspx?md5=5170abf4e511aa241d894b4515c1b573"&gt;ThreatExpert&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-3774071823957021425?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/iG2uyFFlaDo" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/ecard-worm-new-batch.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_g2qoDleHSYA/SSg6fLvd3eI/AAAAAAAAAV0/ag04-KEbG9A/s72-c/Ecards_1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-2585138227257289520</guid><pubDate>Thu, 20 Nov 2008 03:51:00 +0000</pubDate><atom:updated>2008-11-20T09:30:43.402+05:30</atom:updated><title>Zlob and Vundo team up!</title><description>Recently, noticed few rogue websites that are pushing both &lt;a href="http://en.wikipedia.org/wiki/Zlob_trojan"&gt;Zlob&lt;/a&gt; fake codec and &lt;a href="http://en.wikipedia.org/wiki/Vundo"&gt;Vundo&lt;/a&gt; trojan. Usually, Vundo trojans spread in the form of keygens or cracks. However, the gang behind Vundo seems to be collaborating with Zlob gang to spread malware in the form of fake codecs!&lt;br /&gt;&lt;br /&gt;Here's one such website, &lt;code&gt;aaibberlinoschlosschn.com.cn (69.61.96.245)&lt;/code&gt;, hosting both Vundo and Zlob. A Zlob installer is offered for download if &lt;code&gt;"Continue"&lt;/code&gt; button is clicked, and a Vundo dropper is delivered when &lt;code&gt;"Download free player"&lt;/code&gt; link is clicked.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SSTf-xqsn3I/AAAAAAAAAVs/s09JF826dNw/s1600-h/Vundo_Zlob.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 270px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SSTf-xqsn3I/AAAAAAAAAVs/s09JF826dNw/s320/Vundo_Zlob.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5270583733507628914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;VirusTotal scan results for Zlob and Vundo droppers are available &lt;a href="http://www.virustotal.com/analisis/21fcd397b6579674e014e259bc3ee358"&gt;here&lt;/a&gt; and &lt;a href="http://www.virustotal.com/analisis/b83e89f45a943d3a0a7505969f20f4de"&gt;here&lt;/a&gt; respectively.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-2585138227257289520?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/C9IQT61S2a0" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/zlob-and-vundo-team-up.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_g2qoDleHSYA/SSTf-xqsn3I/AAAAAAAAAVs/s09JF826dNw/s72-c/Vundo_Zlob.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-7747102925455485560</guid><pubDate>Fri, 07 Nov 2008 17:16:00 +0000</pubDate><atom:updated>2009-01-01T00:08:01.679+05:30</atom:updated><title>Moon-Player</title><description>&lt;b&gt;Moon-Player&lt;/b&gt; is one of the latest fake video codec/player by &lt;a href="http://en.wikipedia.org/wiki/Zlob_trojan"&gt;Zlob&lt;/a&gt;/&lt;a href="http://www.f-secure.com/v-descs/dnschang.shtml"&gt;DNSChaner&lt;/a&gt; gang! Moon-Player installer is dropped by the &lt;i&gt;standard&lt;/i&gt; Zlob fake codec infection technique. An example of a dropper-website and installer is shown here:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SRR5OctD7jI/AAAAAAAAAU0/FC5kMJSf02o/s1600-h/MoonPlayer_1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 313px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SRR5OctD7jI/AAAAAAAAAU0/FC5kMJSf02o/s320/MoonPlayer_1.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265967153433275954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_g2qoDleHSYA/SRR5ZmjLcJI/AAAAAAAAAU8/ZnFmBTeJg2c/s1600-h/MoonPlayer_2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 249px;" src="http://4.bp.blogspot.com/_g2qoDleHSYA/SRR5ZmjLcJI/AAAAAAAAAU8/ZnFmBTeJg2c/s320/MoonPlayer_2.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265967345054740626" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Moon-Player installer is hosted at &lt;code&gt;http://moon-player.com (203.169.164.18)&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/moon-player.com"&gt;whois info&lt;/a&gt;). This particular Zlob variant is highly dangerous as it drops rootkit based spyware and also adds malicious DNS servers. Following &lt;a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis"&gt;HijackThis&lt;/a&gt; entry shows the rogue name servers added to the "NameServer" list of the system:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{27C05F16-264E-4B56-9C02-90A5B7D0A17D}: NameServer = 85.255.112.143;85.255.112.94&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;These name servers are located at Ukraine and whois information can be found &lt;a href="http://whois.domaintools.com/85.255.112.143"&gt;here&lt;/a&gt; and &lt;a href="http://whois.domaintools.com/85.255.112.94"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The rootkit component is a user mode rootkit that hides files by hooking APIs of ntdll.dll. Following screenshots show rooted file and hooked APIs:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SRR5tZLfSQI/AAAAAAAAAVE/VvVEhbDSY_Y/s1600-h/MoonPlayer_3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 106px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SRR5tZLfSQI/AAAAAAAAAVE/VvVEhbDSY_Y/s320/MoonPlayer_3.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265967685063100674" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SRR9p-ezFsI/AAAAAAAAAVk/_7qR2VX0vPE/s1600-h/MoonPlayer_6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 191px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SRR9p-ezFsI/AAAAAAAAAVk/_7qR2VX0vPE/s320/MoonPlayer_6.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265972024403236546" /&gt;&lt;/a&gt;&lt;br /&gt;The rootkit also injects a DLL into few of the standard Windows processes (alg.exe and spoolsv.exe), as shown in below screenshot.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_g2qoDleHSYA/SRR50ViRn0I/AAAAAAAAAVM/eF8z5juMP6w/s1600-h/MoonPlayer_4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://1.bp.blogspot.com/_g2qoDleHSYA/SRR50ViRn0I/AAAAAAAAAVM/eF8z5juMP6w/s320/MoonPlayer_4.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265967804344016706" /&gt;&lt;/a&gt;&lt;br /&gt;The injected DLL &lt;code&gt;C:\Windows\System32\Dll.dll&lt;/code&gt; actually does not exist, and the file that is really injected is &lt;code&gt;C:\Windows\Temp\temp&lt;i&gt;X&lt;/i&gt;.tmp&lt;/code&gt; (where &lt;i&gt;X&lt;/i&gt; is some random number). This can be seen from the DLL information shown by IceSword. It seems that the injected file changes its name in the module list maintained in process PEB, to a dummy/non-existent one.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_g2qoDleHSYA/SRR57duSBPI/AAAAAAAAAVU/4Fp2t_kjc3w/s1600-h/MoonPlayer_5.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://2.bp.blogspot.com/_g2qoDleHSYA/SRR57duSBPI/AAAAAAAAAVU/4Fp2t_kjc3w/s320/MoonPlayer_5.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5265967926800942322" /&gt;&lt;/a&gt;&lt;br /&gt;VirusTotal scan result of the installer can be found &lt;a href="http://www.virustotal.com/analisis/69242f771ae8c05f174ee3dc7e54f790"&gt;here&lt;/a&gt;. An automated analysis of the installer can be found at this ThreatExpert &lt;a href="http://www.threatexpert.com/report.aspx?md5=6ab295c2804c53b33a2a1f2a6ffc5b37"&gt;page&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Update:&lt;/span&gt; A Zlob (Moon-Player and other fake video players)  rootkit removal tutorial has been posted &lt;a href="http://swatrant.blogspot.com/2008/12/zlob-fake-codec-rootkit-removal.html"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-7747102925455485560?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/dI4tmhE4l18" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/moon-player.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SRR5OctD7jI/AAAAAAAAAU0/FC5kMJSf02o/s72-c/MoonPlayer_1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">12</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-6086989336425625817</guid><pubDate>Mon, 03 Nov 2008 16:07:00 +0000</pubDate><atom:updated>2008-11-04T07:18:54.707+05:30</atom:updated><title>SysProt AntiRootkit v1.0.0.7 released!</title><description>Here's a quick update on SysProt AntiRootkit. Various improvements were made in SSDT hook detection and hidden files scanning feature. And as a result, here's the latest release - &lt;b&gt;SysProt AntiRootkit v1.0.0.7&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Download SysProt AntiRootkit v1.0.0.7 from &lt;a href="http://majorgeeks.com/SysProt_AntiRootkit_d5708.html"&gt;&lt;b&gt;MajorGeeks&lt;/b&gt;&lt;/a&gt;. Your feedback is welcome :)&lt;br /&gt;&lt;br /&gt;Supported operating systems: Windows 2000/XP/2003 32 bit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-6086989336425625817?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/yuWTYQpKPSU" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/sysprot-antirootkit-v1007-released.html</link><author>noreply@blogger.com (swatkat)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-8862587700257632754</guid><pubDate>Sun, 02 Nov 2008 18:11:00 +0000</pubDate><atom:updated>2008-11-04T07:16:45.056+05:30</atom:updated><title>SysProt AntiRootkit v1.0.0.6 released!</title><description>Here comes the latest version of &lt;b&gt;SysProt AntiRootkit&lt;/b&gt;, with various improvements over the previous version. Following list summarizes the improvements in &lt;b&gt;SysProt AntiRootkit v1.0.0.6&lt;/b&gt;:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Improved hidden drivers and services detection&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Improved driver/service disabling feature&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Improved process killing mechanisms&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Added DLLs view for processes (double-click on a process to see loaded DLLs)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Brand new hidden and locked files/folder scanning&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Color coded display (hidden items are displayed in red color)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Ability to filter the display to show only hidden items&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Various optimizations in driver for better performance and stability&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Here are some screenshots which show SysProt AntiRootkit v1.0.0.6 in action:&lt;br /&gt;Processes view:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3uNVX6XLI/AAAAAAAAAUE/4ZdGMFYKzZw/s1600-h/ProcessView.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3uNVX6XLI/AAAAAAAAAUE/4ZdGMFYKzZw/s320/ProcessView.jpg" alt="" id="BLOGGER_PHOTO_ID_5264125452309126322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DLLs of a process:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3ujKd3nnI/AAAAAAAAAUM/AZihUpN41hY/s1600-h/ProcessDLLView.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3ujKd3nnI/AAAAAAAAAUM/AZihUpN41hY/s320/ProcessDLLView.jpg" alt="" id="BLOGGER_PHOTO_ID_5264125827338444402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hidden drivers:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3uyvTRN4I/AAAAAAAAAUU/R08RZBF00Rs/s1600-h/HiddenDrivers.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3uyvTRN4I/AAAAAAAAAUU/R08RZBF00Rs/s320/HiddenDrivers.jpg" alt="" id="BLOGGER_PHOTO_ID_5264126094924134274" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hidden and locked files:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3u39bM-uI/AAAAAAAAAUc/9phHou1Izhc/s1600-h/FilesScan.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3u39bM-uI/AAAAAAAAAUc/9phHou1Izhc/s320/FilesScan.jpg" alt="" id="BLOGGER_PHOTO_ID_5264126184614853346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SSDT hooks:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3yKHarFaI/AAAAAAAAAUk/TuAjbiOT238/s1600-h/SSDTHooks.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3yKHarFaI/AAAAAAAAAUk/TuAjbiOT238/s320/SSDTHooks.jpg" alt="" id="BLOGGER_PHOTO_ID_5264129795069515170" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Download SysProt AntiRootkit v1.0.0.6 from &lt;a href="http://majorgeeks.com/SysProt_AntiRootkit_d5708.html"&gt;&lt;b&gt;MajorGeeks&lt;/b&gt;&lt;/a&gt;. Feedback is welcome :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-8862587700257632754?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/AEGH8vtLiU4" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/sysprot-antirootkit-1006-released.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SQ3uNVX6XLI/AAAAAAAAAUE/4ZdGMFYKzZw/s72-c/ProcessView.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-3867757421250230508</guid><pubDate>Sun, 02 Nov 2008 08:47:00 +0000</pubDate><atom:updated>2008-11-02T15:22:57.078+05:30</atom:updated><title>MSoftCodec</title><description>&lt;b&gt;MSoftCodec&lt;/b&gt; is yet another fake codec belonging to &lt;a href="http://en.wikipedia.org/wiki/Zlob_trojan"&gt;Zlob trojan&lt;/a&gt; family. The dropper, &lt;code&gt;MSoftCodec.exe&lt;/code&gt;, is hosted at &lt;code&gt;1st-download-software-base.net (206.51.225.218)&lt;/code&gt; (&lt;a href="http://whois.domaintools.com/1st-download-software-base.net"&gt;whois info&lt;/a&gt;). As of now, detections are poor as demonstrated by this &lt;a href="http://www.virustotal.com/analisis/ee2d148bda3879077a17457e4404ef1e"&gt;VirusTotal scan&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-3867757421250230508?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/LUIoWsVpq9Y" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/11/msoftcodec.html</link><author>noreply@blogger.com (swatkat)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-14777922.post-3794927408608486572</guid><pubDate>Sun, 26 Oct 2008 08:36:00 +0000</pubDate><atom:updated>2008-10-26T14:15:41.262+05:30</atom:updated><title>Fake DivX codec</title><description>Here's a new Zlob fake codec variant, which touts itself as &lt;a href="http://en.wikipedia.org/wiki/DivX_Media_Format"&gt;DivX codec&lt;/a&gt;. The dropper is named as &lt;b&gt;DivXCodecPKG.7.exe&lt;/b&gt; and is hosted at &lt;code&gt;http://softawe-download-forpc.com (66.232.126.78)&lt;/code&gt;. Whois information for this domain can be found &lt;a href="http://whois.domaintools.com/softawe-download-forpc.com"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_g2qoDleHSYA/SQQse1wpNhI/AAAAAAAAATU/wcJepDDGYoA/s1600-h/DivXCodecPKG7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 195px;" src="http://3.bp.blogspot.com/_g2qoDleHSYA/SQQse1wpNhI/AAAAAAAAATU/wcJepDDGYoA/s320/DivXCodecPKG7.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5261379173014386194" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As of now, detection by AVs are not good. VirusTotal scan result can be found &lt;a href="http://www.virustotal.com/analisis/35f09863d60416e75119c1dda51c3ce2"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14777922-3794927408608486572?l=swatrant.blogspot.com'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SwatkatsRants/~4/Syu9kHgtpRc" height="1" width="1"/&gt;</description><link>http://swatrant.blogspot.com/2008/10/fake-divx-codec.html</link><author>noreply@blogger.com (swatkat)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_g2qoDleHSYA/SQQse1wpNhI/AAAAAAAAATU/wcJepDDGYoA/s72-c/DivXCodecPKG7.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item></channel></rss>
