<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avira - TechBlog &#187; Virus</title>
	<atom:link href="http://techblog.avira.com/tag/virus/en/feed/en/" rel="self" type="application/rss+xml" />
	<link>http://techblog.avira.com</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 06:38:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Email malware returns</title>
		<link>http://techblog.avira.com/2009/10/20/email-malware-returns/en/</link>
		<comments>http://techblog.avira.com/2009/10/20/email-malware-returns/en/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 12:03:21 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Outbreak]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1320</guid>
		<description><![CDATA[After last weeks outbreak of spam mails with malware with alleged settings for mail software (which still is ongoing, we still receive a lot of those mails) our analysts see a new bunch of emails which contain a trojan as attachment. These mails come with subjects like &#8220;Conflicker.B Infection Alert&#8221; and seem to stem from [...]]]></description>
			<content:encoded><![CDATA[<p>After last weeks outbreak of spam mails with malware with alleged settings for mail software (which still is ongoing, we still receive a lot of those mails) our analysts see a new bunch of emails which contain a trojan as attachment. These mails come with subjects like &#8220;Conflicker.B Infection Alert&#8221; and seem to stem from someone called &#8220;Microsoft Windows Agent&#8221;.</p>
<div id="attachment_1321" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091020-Conflicker-Spam1.png"><img class="size-medium wp-image-1321 " title="091020-Conflicker-Spam1" src="http://techblog.avira.com/wp-content/uploads/2009/10/091020-Conflicker-Spam1-300x222.png" alt="Fig. 1: The malware claims to carry a Conficker removal tool." width="300" height="222" /></a><p class="wp-caption-text">Fig. 1: The email claims to carry a Conficker removal tool.</p></div>
<p>The mail claims that the network where the PC is located is infected with Conficker.B and that the ISP has informed Microsoft about that. The attached tool allegedly offers a free system scan.</p>
<p>The attachment is a FakeAV solution though; also Microsoft would never send out an executable attachment without former consent via email. Do not execute the malware in the zip file from the mail! Avira detects it as <a title="Description of TR/Vilsel.ior" href="http://www.avira.com/en/threats/section/details/id_vir/4552/tr_vilsel.ior.html" target="_blank">TR/Vilsel.ior</a> with the VDF 7.01.06.127.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/20/email-malware-returns/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FastFlux-Malware leading to FakeAV (Update)</title>
		<link>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/</link>
		<comments>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/#comments</comments>
		<pubDate>Fri, 02 Oct 2009 05:30:23 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1245</guid>
		<description><![CDATA[Our researchers found a malicious JavaScript link embedded to the headlines and thread titles in some forums as well as on other web sites after a user notified us about possible issues with a particular forum. The scripts resulted in slowing down forum access which raised suspicion, so we started to analyse what was going [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-465" title="malware_warning" src="http://techblog.avira.com/wp-content/uploads/2008/12/malware_warning.png" alt="malware_warning" width="56" height="53" />Our researchers found a malicious JavaScript link embedded to the headlines and thread titles in some forums as well as on other web sites after a user notified us about possible issues with a particular forum. The scripts resulted in slowing down forum access which raised suspicion, so we started to analyse what was going on.</p>
<p>In those forums there were links embedded in the posts which lead to a JavaScript on a Russian website. A google search with the URL revealed that already more than 100 web pages, especially forums, got infected with that malicious link &#8211; the infection rate is increasing fast. Later another URL with the malware script was identified, which Google reported on more than 16.000 obviously infected web pages.</p>
<div id="attachment_1261" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Encrypted_JS.png"><img class="size-medium wp-image-1261" title="091001-Encrypted_JS" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Encrypted_JS-300x117.png" alt="Fig. 1: The JavaScript is encrypted and obfuscated in several layers." width="300" height="117" /></a><p class="wp-caption-text">Fig. 1: The JavaScript is encrypted and obfuscated in several layers.</p></div>
<p>The JavaScript is trying to exploit several vulnerabilities to silently install malware on affected users&#8217; computers. Among these are exploits for Microsoft Video ActiveX Control Vulnerability (CVE-2008-0015), Microsoft Internet Explorer XML Parsing Vulnerability (CVE-2008-4844), Microsoft Internet Explorer Malformed CSS Memory Corruption Vulnerability (CVE-2009-0076) and some PDF exploits for Firefox and the Internet Explorer. All these exploits are already known and security updates are available. The malware writers obviously assume that a lot of Internet users do not update their systems.</p>
<div id="attachment_1263" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Decrypting_JavaScript.png"><img class="size-medium wp-image-1263" title="091001-Decrypting_JavaScript" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Decrypting_JavaScript-300x167.png" alt="Fig. 2: Decrypting the JavaScript needed some brute force, too." width="300" height="167" /></a><p class="wp-caption-text">Fig. 2: Decrypting the JavaScript needed some brute force, too.</p></div>
<p>That malicious JavaScript is hosted on a fast-flux&#8217;ed domain &#8211; the Internet addresses to which the embedded link points resolves to different locations every few minutes (fast flux as abbreviation from fast fluctuation, see <a title="Wikipedia article on fast flux servers" href="http://en.wikipedia.org/wiki/Fast_flux" target="_blank">Wikipedia</a>). So it doesn&#8217;t help to take down one server as there are plenty of them. Usually infected computers serve the malware.</p>
<div id="attachment_1260" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-fastflux_hosts.png"><img class="size-medium wp-image-1260" title="091001-fastflux_hosts" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-fastflux_hosts-300x245.png" alt="Fig. 2: The domain the JavaScript was loaded from was a fastflux'ed domain." width="300" height="245" /></a><p class="wp-caption-text">Fig. 3: The domain the JavaScript was loaded from was a fastflux&#39;ed domain.</p></div>
<p>The servers are GeoIP-aware. Trying to access them directly with an IP from Deutsche Telekom network resulted in an &#8220;access denied&#8221;, while using a proxy in the USA made the bots deliver the malware.</p>
<div id="attachment_1262" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Shellcode_functions.png"><img class="size-medium wp-image-1262" title="091001-Shellcode_functions" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Shellcode_functions-300x233.png" alt="Fig. 3: The shellcode in the JavaScript finally leads to a FakeAV infection." width="300" height="233" /></a><p class="wp-caption-text">Fig. 4: The shellcode in the JavaScript finally leads to a FakeAV infection.</p></div>
<p>But this malware &#8211; Avira detects it <a title="TR/FraudPack.ams" href="http://www.avira.com/en/threats/section/details/id_vir/4529/tr_fraudpack.ams.html" target="_blank">TR/FraudPack.ams</a> &#8211; is just another downloader. It is encrypted with some layers as well.</p>
<div id="attachment_1266" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Crypter_Greetings.png"><img class="size-medium wp-image-1266" title="091001-FakeAV_Crypter_Greetings" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Crypter_Greetings-300x72.png" alt="Fig. 5: The crypter author sends out greetings to Sunbelt." width="300" height="72" /></a><p class="wp-caption-text">Fig. 5: The crypter author sends out greetings to Sunbelt.</p></div>
<p>One of the encryption layers contains greetings to the company Sunbelt.</p>
<div id="attachment_1265" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Downloader_Strings.png"><img class="size-medium wp-image-1265" title="091001-FakeAV_Downloader_Strings" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Downloader_Strings-300x228.png" alt="Fig. 4: Contents of the FakeAV downloader svcst.exe. " width="300" height="228" /></a><p class="wp-caption-text">Fig. 6: Contents of the FakeAV downloader svcst.exe. </p></div>
<p>It accesses a set of &#8220;double fast-flux&#8217;ed&#8221; domains to fetch the actual malware, a FakeAV and a ftp password stealer which sends the data to guest books on the Internet. These are detected by Avira with generic detection as <a title="TR/Crypt.ZPACK.Gen" href="http://www.avira.com/en/threats/section/details/id_vir/4487/tr_crypt.zpack.gen.html" target="_blank">TR/Crypt.ZPACK.Gen</a> and as <a title="TR/FakeAV.RK" href="http://www.avira.com/en/threats/section/details/id_vir/4530/tr_fakeav.rk.html" target="_blank">TR/FakeAV.RK</a>, while the password uploader gets detected as <a title="TR/Downloader.Gen" href="http://www.avira.com/en/threats/section/details/id_vir/3907/tr_downloader.gen.html" target="_blank">TR/Downloader.Gen</a>.</p>
<div id="attachment_1264" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV.png"><img class="size-medium wp-image-1264" title="091001-FakeAV" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV-300x244.png" alt="Fig. 5: The FakeAV disguises itself as Antivirus Pro 2010." width="300" height="244" /></a><p class="wp-caption-text">Fig. 7: The FakeAV disguises itself as Antivirus Pro 2010.</p></div>
<p>The WebGuard of the Avira Premium and Professional blocks the URLs from where the malicious JavaScript is included and also the malware download URLs. Avira AntiVir also protects users from the downloaded malware.</p>
<p>(Article updated on 6th October to add more details about the malware.)</p>
<p style="text-align: right;">Emanuel Somosan<br />
Moritz Kroll<br />
Engine R&amp;D</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Induc.A Removal Tool</title>
		<link>http://techblog.avira.com/2009/08/24/w32induc-a-removal-tool/en/</link>
		<comments>http://techblog.avira.com/2009/08/24/w32induc-a-removal-tool/en/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 14:28:05 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Avira Removal Tool]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[W32/Induc.A]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1102</guid>
		<description><![CDATA[Last week a virus that infects Delphi development environments and then the compiled Delphi programs was detected and got some media attention &#8211; infected programs were distributed on cover-mount CDs and DVDs on computer magazines and via Download Portals.
Our developers created a special version of our Avira Removal Tool which is capable of detecting and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-513" title="antivir_ok" src="http://techblog.avira.com/wp-content/uploads/2009/01/antivir_ok.png" alt="antivir_ok" width="26" height="26" />Last week a virus that infects Delphi development environments and then the compiled Delphi programs was detected and got some media attention &#8211; infected programs were distributed on cover-mount CDs and DVDs on computer magazines and via Download Portals.</p>
<p>Our developers created a special version of our Avira Removal Tool which is capable of detecting and deleting infected programs. You can download the English version <a title="Avira Removal Tool for W32/Induc.A (english)" href="http://dlpro.antivir.com/package/removaltool3/win32/en/removaltool-win32-en.exe" target="_self">here</a> and the German version <a title="Avira Removal Tool for W32/Induc.A (german)" href="http://dlpro.antivir.com/package/removaltool3/win32/de/removaltool-win32-de.exe" target="_self">here</a>!</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/08/24/w32induc-a-removal-tool/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security flaw in Adobe PDF/Flash</title>
		<link>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/</link>
		<comments>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 11:37:50 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1029</guid>
		<description><![CDATA[There are security flaws within Adobe Reader and Acrobat and the Adobe Flash Player which are getting actively exploited on the net currently. The company has published a security advisory where it announces that they are currently investigating the problem and plan an update for the 30th of July.
Avira antivirus solutions already detect the malicious [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-870" title="acrobat_logo" src="http://techblog.avira.com/wp-content/uploads/2009/05/acrobat_logo.png" alt="acrobat_logo" width="31" height="33" />There are security flaws within Adobe Reader and Acrobat and the Adobe Flash Player which are getting actively exploited on the net currently. The company has published a <a title="Security advisory for Adobe Reader, Acrobat and Flash Player" href="http://www.adobe.com/support/security/advisories/apsa09-03.html" target="_blank">security advisory</a> where it announces that they are currently investigating the problem and plan an update for the 30th of July.</p>
<p>Avira antivirus solutions already detect the malicious PDF files as EXP/Pidief.TH and the dropped malware by those documents as TR/Drop.Wmach and TR/Spy.WMach, respectively. Anyhow it is a good idea to take additional security measures until Adobe provides an update.</p>
<p>Adobe recommends to delete or rename the file authplay.dll that ships with the Reader and with Acrobat. Also, enabling Data Execution Prevention (DEP) and activating the User Access Control (UAC) in Windows Vista shall mitigate the risk according to Adobe.</p>
<p>Another solution would be using a different PDF reader and disabling Adobe PDF and Flash within the web browser via its add-ons-manager. The NoScript extension for Firefox also helps preventing Flash applications to run in the browser; it is possible that drive-by-downloads via malicious Flash applications embedded in web sites turn up soon.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hindering debugging &#8211; by doing nothing</title>
		<link>http://techblog.avira.com/2009/07/22/hindering-debugging-by-doing-nothing/en/</link>
		<comments>http://techblog.avira.com/2009/07/22/hindering-debugging-by-doing-nothing/en/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 08:41:23 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Polymorphism]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[W32/Virut]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1022</guid>
		<description><![CDATA[A common technique to make debugging harder and more time-consuming is scrambling the virus code and inserting &#8220;random&#8221; junk code that doesn&#8217;t really do anything useful. One example is the W32/Virut family. Despite already being a couple of years old, it is still one of the most active file infector families around. Its author(s) frequently [...]]]></description>
			<content:encoded><![CDATA[<p>A common technique to make debugging harder and more time-consuming is scrambling the virus code and inserting &#8220;random&#8221; junk code that doesn&#8217;t really do anything useful. One example is the <a title="Updated Virut Detection" href="http://techblog.avira.com/2009/02/10/updated-virut-detection/en/" target="_self">W32/Virut</a> family. Despite already being a couple of years old, it is still one of the most active file infector families around. Its author(s) frequently update the way it tries to hide itself both from AV software and researchers.</p>
<p>It is polymorphic and has been manually adapted and extended by its  author(s) multiple times. While analysing one of the latest W32/Virut variants, we came accross a block in the virus code that couldn&#8217;t be properly disassembled by the used debugger. Looking closer, it turned out that the problematic block of code contained a relatively unusual multi-byte no-operation instruction (NOP).</p>
<div id="attachment_1023" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/07/multi-byte-nop1.png"><img class="size-medium wp-image-1023" title="multi-byte-nop1" src="http://techblog.avira.com/wp-content/uploads/2009/07/multi-byte-nop1-300x68.png" alt="Fig. 1: Modern disassemblers and debuggers can decode the length of the NOP correctly." width="300" height="68" /></a><p class="wp-caption-text">Fig. 1: Even modern disassemblers and debuggers can&#39;t decode the length of the NOP correctly (OllyDbg 1.10).</p></div>
<p>The usual NOP instruction of x86 processors is one byte long (opcode <code>0x90</code>). But there is also a multi-byte NOP with the opcode <code>0x0F 1F</code> which is used in the virus code. The multi-byte NOP can take up to 9 bytes. NOP instructions can get used for padding the code to align it to 8 or 16 byte boundaries &#8211; on modern processors this can speed up the code, mostly for caching reasons.</p>
<p>Intel officially documented this multi-byte NOP in 2006, but it has already been present in older processors for quite a while &#8211; apparently since Pentium Pro, but not the Pentium MMX.</p>
<div id="attachment_1024" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/07/multi-byte-nop2.png"><img class="size-medium wp-image-1024" title="multi-byte-nop2" src="http://techblog.avira.com/wp-content/uploads/2009/07/multi-byte-nop2-300x155.png" alt="Fig. 2: Some disassemblers and debuggers don't cope well with the multi-byte NOP instructions." width="300" height="155" /></a><p class="wp-caption-text">Fig. 2: Older disassemblers and debuggers don&#39;t cope well with the multi-byte NOP instructions (older IDA variant).</p></div>
<p>The author(s) of the W32/Virut malware now use(s) the fact that these multi-byte NOP instructions are still quite unknown to complicate the analysis and to trick disassemblers and emulators. Some commonly used disassemblers and debuggers don&#8217;t support these opcodes. They cannot calculate the correct length of the instruction and as a result aren&#8217;t able to properly &#8220;translate&#8221; the code beyond this point.</p>
<p style="text-align: right;">Markus Hinderhofer<br />
Engine Research &amp; Development</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/22/hindering-debugging-by-doing-nothing/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>File Patcher W32/Tobin</title>
		<link>http://techblog.avira.com/2009/05/12/file-patcher-w32tobin/en/</link>
		<comments>http://techblog.avira.com/2009/05/12/file-patcher-w32tobin/en/#comments</comments>
		<pubDate>Tue, 12 May 2009 05:45:33 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Underground]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[W32/Tobin]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=900</guid>
		<description><![CDATA[While refining and improving our detection of the W32/Tobin file patcher malware we analysed its &#8220;infection&#8221; algorithm closer. Upon execution, it drops a DLL (usually &#8220;nikitob.dll&#8221;) and modifies executable files on the system so that they load the dropped DLL once they get started. So far nothing new or unusual.
W32/Tobin adds a new section named [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-513" title="antivir_ok" src="http://techblog.avira.com/wp-content/uploads/2009/01/antivir_ok.png" alt="antivir_ok" width="26" height="26" />While refining and improving our detection of the W32/Tobin file patcher malware we analysed its &#8220;infection&#8221; algorithm closer. Upon execution, it drops a DLL (usually &#8220;nikitob.dll&#8221;) and modifies executable files on the system so that they load the dropped DLL once they get started. So far nothing new or unusual.</p>
<div id="attachment_903" class="wp-caption alignnone" style="width: 300px"><a href="http://techblog.avira.com/wp-content/uploads/2009/05/importtable.png"><img class="size-full wp-image-903" title="importtable" src="http://techblog.avira.com/wp-content/uploads/2009/05/importtable.png" alt="Fig. 1: The import table" width="290" height="156" /></a><p class="wp-caption-text">Fig. 1: The new import table</p></div>
<p>W32/Tobin adds a new section named &#8220;.lenna&#8221; at the end of the PE file. This section consists of an import table &#8211; such import tables are used by the Windows loader to dynamically load DLLs and provide the corresponding function from them to the started program. The new import table references the dropped DLL &#8220;nikitob.dll&#8221;. At the same time, the import data directory entry in the PE header gets modified to point to the newly attached import table. If there is a bound import table in the executable, W32/Tobin &#8220;removes&#8221; the entry from the data directory by setting it&#8217;s RVA and size to 0.</p>
<div id="attachment_901" class="wp-caption alignnone" style="width: 300px"><a href="http://techblog.avira.com/wp-content/uploads/2009/05/datadirectory_original.png"><img class="size-full wp-image-901" title="datadirectory_original" src="http://techblog.avira.com/wp-content/uploads/2009/05/datadirectory_original.png" alt="Fig. 1: Original data directory address" width="290" height="44" /></a><p class="wp-caption-text">Fig. 2: Original data directory address</p></div>
<div id="attachment_902" class="wp-caption alignnone" style="width: 300px"><a href="http://techblog.avira.com/wp-content/uploads/2009/05/datadirectory_patched.png"><img class="size-full wp-image-902" title="datadirectory_patched" src="http://techblog.avira.com/wp-content/uploads/2009/05/datadirectory_patched.png" alt="Fig. 2: Patched data directory address" width="290" height="44" /></a><p class="wp-caption-text">Fig. 3: Patched data directory address</p></div>
<p>The dropped DLL &#8220;nikitob.dll&#8221; just exports one function, &#8220;NikitaTob&#8221;. Upon calling it, it shows a message box with the text &#8220;NikitaTob&#8221;. The actual virus code is executed automatically when the DLL is loaded.</p>
<div id="attachment_904" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/05/dllexport.png"><img class="size-medium wp-image-904" title="dllexport" src="http://techblog.avira.com/wp-content/uploads/2009/05/dllexport-300x107.png" alt="Fig. 4: The malware dll exports just one function" width="300" height="107" /></a><p class="wp-caption-text">Fig. 4: The malware dll exports just one function</p></div>
<p>Among other things, the import address table is rebuilt to make the patched executable work. In our analysis we didn&#8217;t find further malicious routines in the malware.</p>
<div id="attachment_905" class="wp-caption alignnone" style="width: 114px"><a href="http://techblog.avira.com/wp-content/uploads/2009/05/messagebox.png"><img class="size-full wp-image-905" title="messagebox" src="http://techblog.avira.com/wp-content/uploads/2009/05/messagebox.png" alt="Fig. 5: Upon calling the exported function, W32/Tobin just shows a message" width="104" height="100" /></a><p class="wp-caption-text">Fig. 5: W32/Tobin just shows a message</p></div>
<p>In one of the W32/Tobin samples we found the reference to &#8220;C:\NIKITA\Soft\black_soft\29a\nikitob\Release\nikitob.pdb&#8221;. A short search in our archives turned up an old magazine of the VX group 29A. In the issue from January 2005 there is proof-of-concept code which exactly infects files the W32/Tobin-way. The new section there is called &#8220;.senna&#8221;, and a message box shows the text &#8220;PayLoad&#8221;. It looks like some malware writers used the Proof-of-Concept virus to learn new techniques.</p>
<p>Removing this kind of malware from an infected system isn&#8217;t as simple as it may look on first glance. Simply deleting the dropped DLL doesn&#8217;t work: The infected executables depend upon the DLL now and won&#8217;t start anymore. Most likely the whole system wouldn&#8217;t start up anymore. Since W32/Tobin stores the address of the original import table at the end of the executable, it is possible to restore that value and disinfect the system gracefully.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/05/12/file-patcher-w32tobin/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Last week sum up</title>
		<link>http://techblog.avira.com/2009/04/20/last-week-sum-up/en/</link>
		<comments>http://techblog.avira.com/2009/04/20/last-week-sum-up/en/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 07:02:19 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=854</guid>
		<description><![CDATA[The last week has been quite busy even though it was Easter holiday season. Microsoft released 8 security bulletins with Updates for the affected software last Tuesday. 5 of them are rated critical and concern Wordpad and the Office Text converters, Windows HTTP services, DirectShow, Internet Explorer and Excel. The security hole in PowerPoint is [...]]]></description>
			<content:encoded><![CDATA[<p>The last week has been quite busy even though it was Easter holiday season. Microsoft released <a title="Microsoft Overview of April 2009 Black Tuesday" href="http://www.microsoft.com/technet/security/bulletin/ms09-apr.mspx" target="_blank">8 security bulletins</a> with Updates for the affected software last Tuesday. 5 of them are rated critical and concern Wordpad and the Office Text converters, Windows HTTP services, DirectShow, Internet Explorer and Excel. The security hole in PowerPoint is still unpatched though. Apply those patches immediately if you haven&#8217;t done so yet as exploit code for those vulnerabilities is publicly available.</p>
<p>The conficker worm started <a title="Conficker downloads updates" href="http://www.avira.de/en/security_news/wurm_conficker.html" target="_blank">downloading </a>updates. Interestingly it doesn&#8217;t use some of those 50.000 domains it generates on daily basis, but a Peer-to-Peer-network which it has functionality built-in for. Users of Avira security solutions are safe from the threat as the new variants spread this way got generically detected as TR/Crypt.XPACK.gen. Additionally, our Virus Lab added the detection Worm/Conficker.D so the malware can be better identified.</p>
<p>The media got hit by reports about a juvenile bored programmer who wrote and released 5 Twitter worms in short time. As excuse he told the media, he got no answer or reaction from Twitter  when contacting them. After that, some web design company found his skills to be impressing and hired him. I wouldn&#8217;t want my web page be programmed by someone writing malware though.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/04/20/last-week-sum-up/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New PowerPoint vulnerability gets exploited</title>
		<link>http://techblog.avira.com/2009/04/03/new-powerpoint-vulnerability-gets-exploted/en/</link>
		<comments>http://techblog.avira.com/2009/04/03/new-powerpoint-vulnerability-gets-exploted/en/#comments</comments>
		<pubDate>Fri, 03 Apr 2009 05:36:07 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[e-Crime]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability warning]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=841</guid>
		<description><![CDATA[Microsoft warns of a new unpatched security vulnerability in PowerPoint. According to their security advisory, PowerPoint 2000, 2002 and 2003 up to Service Pack 3 are affected; so is PowerPoint 2004 for Macs. Currently cyber criminals are abusing specially prepared documents to infect computers in companies. This is how the so-called GhostNet started a few [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft warns of a new unpatched security vulnerability in PowerPoint. According to their <a title="Microsoft Security Advisory for new vulnerability in PowerPoint" href="http://www.microsoft.com/technet/security/advisory/969136.mspx" target="_blank">security advisory</a>, PowerPoint 2000, 2002 and 2003 up to Service Pack 3 are affected; so is PowerPoint 2004 for Macs. Currently cyber criminals are abusing specially prepared documents to infect computers in companies. This is how the so-called GhostNet started a few years ago as well.</p>
<p>Good news is that PowerPoint Viewer 2003 and 2007 as well as Office 2007 seem to be unaffected. If you get PowerPoint presentations by mail, only open them with these versions. Anyhow it seems a good idea to first check whether you expected that presentation from exactly that sender and if in doubt, contact the sender to verify it was really him sending the document.</p>
<p>As administrator of a company network you might want to setup a <a title="MOICE - filtering Office Documents in order to sanitize them" href="http://support.microsoft.com/kb/935865" target="_blank">MOICE filter</a> for incoming documents to sanitize them so they can&#8217;t lead to dangerous actions on the client PCs.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/04/03/new-powerpoint-vulnerability-gets-exploted/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What to do against Psyb0t</title>
		<link>http://techblog.avira.com/2009/03/30/what-to-do-against-psyb0t/en/</link>
		<comments>http://techblog.avira.com/2009/03/30/what-to-do-against-psyb0t/en/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 06:17:59 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=831</guid>
		<description><![CDATA[Some hype established around the malware known as Psyb0t. It is unusual as it doesn&#8217;t infect windows machines, but MIPS-based Internet-routers and DSL-modems &#8211; which are very widespread. (This is only half of the story. There is a windows malware floating around which starts infecting the Internet gateway; this malware is detected and removed by [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-513" title="antivir_ok" src="http://techblog.avira.com/wp-content/uploads/2009/01/antivir_ok.png" alt="antivir_ok" width="26" height="26" />Some hype established around the malware known as Psyb0t. It is unusual as it doesn&#8217;t infect windows machines, but MIPS-based Internet-routers and DSL-modems &#8211; which are very widespread. (This is only half of the story. There is a windows malware floating around which starts infecting the Internet gateway; this malware is detected and removed by Avira AntiVir though.)</p>
<p>In our analysis we found plenty of interesting strings in the Psyb0t-variant 2.9L.</p>
<div id="attachment_832" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/03/090330-psyb0t-disassembled.png"><img class="size-medium wp-image-832" title="090330-psyb0t-disassembled" src="http://techblog.avira.com/wp-content/uploads/2009/03/090330-psyb0t-disassembled-300x191.png" alt="Fig. 1: Disassembled Psyb0t and the function graph." width="300" height="191" /></a><p class="wp-caption-text">Fig. 1: Disassembled Psyb0t and its function graph.</p></div>
<p>This malware is quite sophisticated and has a whole lot of functions which a bot master may need. Psyb0t connects to an IRC-Server and can be controlled from there.</p>
<p>It tries to exploit weak passwords on devices reachable via the Internet and contains an extensive list of default passwords and some often used passwords, too. Also it attacks SQL servers and software like PHPMyAdmin. So it doesn&#8217;t only infect Netcomm-DSL-Modems as has been reported on the media sometimes, but can break into plenty of other MIPS-based devices from other brands as well &#8211; even in OpenWRT installations, if they use some insecure service versions.</p>
<p>How can you detect if your router is infected? There is no easy way to tell. But the malware adds a firewall rule to block telnet connections (<span style="color: #0000ff;">iptables -A INPUT -p tcp &#8211;dport 23 -j DROP</span>). So if there is a telnet deamon running on your router and you can&#8217;t reach it, it would be a bad sign.</p>
<p>How to get rid of an infection? You have to connect via wired network to your Internet gateway in this situation. Fetch the latest firmware version available from a different network, maybe at a neighbour&#8217;s place or at a friend&#8217;s. Then you usually have to initiate a hard reset on the Internet gateway. Most devices reset their settings to the default ones when pressing the reset knob for 10 seconds, then pulling the power plug and reinserting the plug again.</p>
<p>After that, first change the default password to a good and safe one &#8211; you know the drill: Small and capital letters, special characters and numbers in most random fashion. Then upgrade the firmware to the most recent version. After that you can start configuring your Internet gateway again.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
<p style="text-align: right;">Markus Hinderhofer<br />
R&amp;D Engine Team</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/03/30/what-to-do-against-psyb0t/en/feed/en/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malware writers rig up against Sandboxes</title>
		<link>http://techblog.avira.com/2009/03/16/malwarewriters-rig-up-against-sandboxes/en/</link>
		<comments>http://techblog.avira.com/2009/03/16/malwarewriters-rig-up-against-sandboxes/en/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 10:39:46 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=793</guid>
		<description><![CDATA[While analysing a recent version of the often adapted Trojan Dropper CeeInject we stumbled over following message in the malware (in plain text):
Hi  Dear sniffer
If you want to find the net
You better put some effort in doing it
Because anubis wont do the job for you
Bitch.
Anubis is a sandbox system reachable on the Internet where [...]]]></description>
			<content:encoded><![CDATA[<p>While analysing a recent version of the often adapted Trojan Dropper CeeInject we stumbled over following message in the malware (in plain text):</p>
<blockquote><p>Hi  Dear sniffer<br />
If you want to find the net<br />
You better put some effort in doing it<br />
Because anubis wont do the job for you<br />
Bitch.</p></blockquote>
<p>Anubis is a sandbox system reachable on the Internet where you can upload suspicious executable files to. Those are run in a safe environment and changes done to the system during that run are shown after a few minutes. Obviously, malware authors are upset about those sandboxes and now start to prepare their binaries so that the malicious activity is not detectable by them anymore.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/03/16/malwarewriters-rig-up-against-sandboxes/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
