Showing posts with label Spyware. Show all posts
Showing posts with label Spyware. Show all posts

Tuesday, December 18, 2012

New Viruses as reported

The recent developments that hackers are adopting to target the systems are pretty interesting.  The Batchwiper as detected by the Iranian CERT and the Trojan as reported with evade technology are the two recent developments.  The Batch Wiper though can be contained with certain precautionary measures, but the Trojan with evade technology would certainly be something that would create a widespread Havoc.  

With the evade technology the Anti-Virus Firms would need time and research to ensure that the right set of detection & quarantine techniques are used so as not to jeopardize the O/S routines that the Trojans use to evade the AV.

Specifically with the Trojan that is reported and that waits for the left Mouse Click routine to execute the commands is one tricky case.  Certainly, we can't stop using mouse with the fear of the Trojan getting executed.....

Time to look out and dig deeper around these aspects to ensure that the corporate as well as home users are impacted the least.....

Tuesday, June 2, 2009

Mysterious New Virus / Spyware / Grayware

Strange but true,

Yesterday I happen to identify a new virus / spyware / grayware that is interestingly a mysterious stuff.  I suddenly suspected something fishy on my machine and the initial diagonosis using Trend Micro revealed Nothing.  I restarted my machine and there while the processes were being started saw a new process - "Beast.Exe" being initiated.

Tried looking for beast.exe in the location where the process was getting triggered for, result - Nill.

Trend Micro, Symantec and McAfee, seemingly the leading AV don't have any signatures for it.  Interesting isn't that?

Well the steps followed then were - 

1. Used sysinternals Process Explorer to identify the processes running - Beast.exe was indeed running
2. Location of Beast.exe was confirmed to be - C:\DATA\FILES, the entire tree being Hidden Directory and with misleading Folder Icons.
3. Beast.Exe not visible at the Location, though is present and to unveil that I used - Simple File Shredder that I use to wipe the data (that was not a smart move, that was interestingly accidental discovery)
4. Killed the Process using sysinternals Process Explorer 
5. Wiped the traces of Beast.exe from the reported folder using Simple File Shredder.

Symptoms and impacts are something that I didn't actually make note of, but a slight research on goolgle reveals that the it impacts the Microsoft Office Files and corrupts them.  Though I was working on some Excel Sheets when the incident happened, luckily they were opened from Outlook and were residing in the "temp" folder.

As stated above, it was interesting to not find any definition from the three leading AV product companies.