Posted by John Barrett on November 16, 2011 ·
The improvements in the new TDL4 bootkit versions are suggesting that the original code was outsourced. For example in the older TDL4 versions the computer infection was initialized by infecting the Master Boot Record(MBR) of the hard disk with malicious code and the attempts to fix it were initially thwarted hooking and malforming the disk read-write operations.
In the recent TDL4 versions, the bootkit does not infect the MBR anymore, instead it creates its own primary and hidden partition with [...]
Posted by John Barrett on November 9, 2011 ·
The keyword “antispyware” has around 2000,000 monthly searches in Google search engine and it’s obvious why nowadays when the security related websites are abundant with news about new computer trojans, new dangerous creations which have in fact a unique objective: not to delete Windows installation, not to take over the mouse and keyboard but to spy silently and unnoticed on the victim’s computers or networks, posing a huge risk for all non public data.
If we search in Google [...]
Posted by John Barrett on November 3, 2011 ·
The backdoor trojans from Buterat(Butirat according to Dr.Web security vendor) family appear two years ago on the scene and was improved by its creators with each version. The latest version added new features as self modifying the data in the PE header(the executable file first bytes) in order to modify its hash. This renders unusable or better said ineffective the identification based on file hashes and antivirus detection based on files signature is deceived packing the malware with modified version [...]
Posted by John Barrett on October 26, 2011 ·
In computing terms, a “zombie” is a compromised computer used to perform different nefarious tasks, being controlled remotely by the attacker. Exactly this is a Mac OS X system infected by OSX/Tsunami-A backdoor trojan. It seems to be the same trojan as Troj/Kaiten which infected in the past Linux based systems, only this time ported to Mac OS X operating system. The attackers control the compromised systems via IRC channels and one of the main commands the attacker can gives to it remotely [...]
Posted by John Barrett on September 18, 2011 ·
Now, this story is crazy. Because I am a subscriber for Google Alerts service (among the keywords there are trojan and virus) this evening I have received an email from Google Alerts looking like this :
You can see under Web section this URL address :
http://www.google.com/url?sa=X&q=http://wcbi.com/photos/img/free-download-anti-virus-trojan.php&ct=ga&cad=CAcQAhgAIAEoBDACOABArYfZ8wRIAVgAYgVlbi1VUw&cd=lbdH6A8
Qsxo&usg=AFQjCNG25qrHqtnmCKmhjW5UVTmn4X-xIw
which is [...]
Posted by John Barrett on September 13, 2011 ·
A new virus targeting the computer BIOS was discovered by the chinese security company 360 Safety Center and it was reported that already several thousand of computers in the Chinese space were infected. The BMW virus attacks the computers running 32 bits systems and containing Award BIOS and it tries to infect users posing as a well-known game plug-in offered by malicious websites. The infection strategy is to trick the visitors to turn off first the antivirus software to avoid a possible conflict [...]
Posted by John Barrett on August 31, 2011 ·
Due to their alluring character, the porn websites have a magnetic effect upon people, these are the places where the people let the guard down easiest, clicking blindly on links and buttons, downloading, running, updating all what is requested or offered by these websites in an attempt to achieve more quickly their unique goal in that moment: to watch a porn video clip. It’s not a problem to view a porn video clip as far as the website visitor is +18 and the website is clean of malware, the [...]