New IM Worm Blocks Access to AV Sites

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Security researchers warn that a malicious component distributed by an IM worm cripples antivirus systems and blocks access to many security-related websites.

The attack begins with malicious links spammed on Windows Live Messenger leading users to rogue pages distributing the trojan dropper.

According to BitDefender's Bogdan Botezatu "the payload is presented as multiple sections of Base-16 Unicode data.

"Conversion to ANSI reveals a set of buffers split by a separator. Ignoring the separators and dumping the data reveals an encrypted file packed with UPX."

The trojan attempts to cripple antivirus programs, but not in the traditional way by using a rootkit. Instead, it closes some of the processes which makes user's interaction with the security programs impossible.

Link
 

LoftedAphid86

New Member
Feb 24, 2011
1,107
If it only prevents user interaction, surely security programs like Avast and Norton would be unaffected as they automatically perform actions against malware.
Is this true?
 

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Yes when it will performed against malware then it will blocked quickly.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top