Torrent Invites! Buy, Trade, Sell Or Find Free Invites, For EVERY Private Tracker! HDBits.org, BTN, PTP, MTV, Empornium, Orpheus, Bibliotik, RED, IPT, TL, PHD etc!



Results 1 to 2 of 2
Like Tree1Likes
  • 1 Post By Laxus

Thread: Banking malware using Windows to block anti-malware apps

  1. #1
    Extreme User
    Laxus's Avatar
    Reputation Points
    111729
    Reputation Power
    100
    Join Date
    Mar 2014
    Posts
    3,448
    Time Online
    252 d 12 h 22 m
    Avg. Time Online
    1 h 38 m
    Mentioned
    304 Post(s)
    Quoted
    52 Post(s)
    Liked
    4874 times
    Feedbacks
    46 (100%)

    Banking malware using Windows to block anti-malware apps

    BKDR_VAWTRAK is using Software Restriction Policies to restrict security software.

    A trojan that's currently doing the rounds in Japan is using Windows itself to try to defeat security software on infected machines.

    Trend Micro reports that the BKDR_VAWTRAK malware, which steals credentials used for online banking at some Japanese banks, is using a Windows feature called Software Restriction Policies (SRP) to prevent infected systems from running a wide range of security programs, including anti-virus software from Microsoft, Symantec, and Intel. A total of 53 different programs are blocked by the malware.

    SRP is intended to give corporate administrators greater control over the software that systems can run. Normally configured through Group Policies, administrators can both whitelist and blacklist applications. Applications can be identified in several ways; by their cryptographic hash, digital signature, their download source, or simply their path on the system.

    BKDR_VAWTRAK is using this last method, the path, to block access to security software.

    The result is ironic. SRPs are intended to enhance system security by preventing the use of undesirable software. Here, they're being used to reduce system security by preventing the use of desirable software.

    While Trend Micro says this isn't the first malware to use this technique to prevent detection and removal, it's significant because BKDR_VAWTRAK has become widespread in Japan.
    FiDeLiTo likes this.

  2. #2
    Donor
    pachanga boys's Avatar
    Reputation Points
    3566
    Reputation Power
    73
    Join Date
    May 2014
    Posts
    115
    Time Online
    1 d 20 h 5 m
    Avg. Time Online
    N/A
    Mentioned
    52 Post(s)
    Quoted
    31 Post(s)
    Liked
    97 times
    Feedbacks
    10 (100%)
    Hmmmmm not news, but interesting. More Citadel junk I suppose!


Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •