Site Statistics
 
Threads: 3,718
Posts: 16,702
Members: 2,843
Users Online: 9
Newest Member: john253


Go Back   PC101 > PC Software > PC Security

PC Security Stop Spyware, Hackers and Identity thieves. Info re: Viruses, trojans, removal, etc...

Reply
 
LinkBack Thread Tools Display Modes
Old 07-12-2006, 07:33 PM   #1
Lyte
Forum Staff
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,035
Rep Power: 6 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
From Russia With Anything But Love

Trojan Horse? Researchers Warn of Trojan Hearse
A new type of rootkit malware sends personal information to a Russian server.

Robert McMillan, IDG News Service
Tuesday, March 21, 2006


SAN FRANCISCO -- Security researchers at Sana Security are warning of a new type of malicious software designed to steal user names and passwords from Web surfers. The malware, dubbed "rootkit.hearse," uses rootkit cloaking techniques that make it extremely difficult to detect.

Before it can steal information, however, the software must be downloaded onto a user's system. A bad guy can accomplish this by tricking the user into downloading the malicious code or by infecting a computer with some other form of malware. Once installed, it sends the sensitive information to a server in Russia that appears to have been in operation since March 16, Sana said.

How It Works
The software has two components: a Trojan horse application that communicates with the Russian server, and rootkit software that cloaks the malicious software from system tools and antivirus programs. Sana has observed the software being downloaded in conjunction with the Win32.Alcra worm.

Rootkit.hearse uses the same kind of cloaking techniques made infamous by Sony BMG Music Entertainment's XCP (Extended Copy Protection) rootkit software, making it hard to find, according to Sana's chief technology officer, Vlad Gorelik.

Defense
As of late Monday, only five of the 24 security products that Sana tested rootkit.hearse against detected the malware, though that number will undoubtedly change as word gets out. "I'm sure that there are others who are beginning to pick it up at this point," Gorelik said.

The Trojan horse software spends most of its time lurking in the background, but it springs to life to communicate with the Russian server whenever a user hits a Web site that requires authentication. The software can read password information as it is typed or even when it is automatically stored and submitted by tools like Internet Explorer's AutoComplete.

As of today, the Russian server had stored about 35,000 unique user names and log-ins that could be used on about 7000 different Web sites, including banking, auction, and social networking sites, Gorelik said.

Sana informed the Russian Internet service provider for the site in question yesterday, Gorelik said. Sana declined to name that ISP. As of this morning, the Russian site was still operational, he said.

More information on rootkit.hearse can be found here.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Love your PC again. Lyte Motherboards / CPUs / Overclocking 4 02-15-2008 09:43 PM
Why do people love to hate Bill Gates? Ronin News, events, alerts and more! 15 12-28-2006 05:42 PM
For the love or money? antman The Internet 9 09-06-2006 06:16 PM
Latest developments in the AMD-ATI-Intel love triangle - NewsForge Lyte News, events, alerts and more! 0 08-23-2006 04:51 PM
I love google GreenRoom The Internet 11 03-01-2006 03:29 PM



Flex Development


Our partners:



All times are GMT -5. The time now is 08:07 PM.

Powered by vBulletin Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
Design by vBSkinworks

Copyright © PC101 and PC101.com Computer Forum. All rights reserved.