Rovnix Reloaded: new step of evolution
Written by v2r on February 22, 2012 – 9:10 pm -[More research from our colleagues in Russia] In the beginning of February we found a new modification of our “old friend” Win32/Rovnix (the dropper detected as Win32/Rovnix.B trojan), which is the first bootkit using VBR (Volume Boot Record) infection. An interesting fact is that Rovnix bootkit components were used in ...
READ MORE >>Tags: Aleksandr Matrosov, Blackhole, bootkit, Carberp, CARO, computer security, David Harley, decryption, dropper, ESET North America, ESET Russia, Eugene Rodionov, FS, malware remove, Righard Zwienenberg, rootkit, Rovnix, Rovnix Reloaded, Russia, security software, space, TDL4, TDSS, Trojan, Trojan downloader, VBR, VFAT, virus remove, Win32 Carberp, Win32 Rovnix, Win32/Carberp
Posted in Virus removal tools |
Bootkit Threat Evolution in 2011
Written by v2r on January 3, 2012 – 9:42 am -The year 2011 could be referred to as a year of growth in complex threats. Over the course of this year we witnessed an increase in the number of threats targeting the Microsoft Windows 64-bit platform, and bootkits in particular. Here is a self-explanatory diagram depicting the evolution of bootkit threats over time: And no...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, Carberp, computer security, David Harley, Eugene Rodionov, information, malware remove, MBR, OS, rootkit, Rootkit Hidden Storage, Rovnix, security software, Senior Research Fellow, space, TDL4, TDSS, VBR, virus remove, Win32 Olmasco, Win32/Mebromi, Win32/Olmarik, x64, ZeroAccess
Posted in Virus removal tools |
Carberp white paper: now with added pictures
Written by v2r on December 6, 2011 – 11:05 pm -After our latest blog on Carberp and the Black Hole exploit pack, we thought it would be useful to aggregate the material we've published to date on the topic into a single paper. That actually went up on the white papers page yesterday, but Aleksandr suggested adding some material that we thought would make it (even) more inte...
READ MORE >>Tags: Aleksandr Matrosov, Black Hole, Carberp, computer security, David Harley, Dmitry Volkov, Eugene Rodionov, Exploit, exploit kit, Group-IB, information, malware remove, RBS, remote banking systems, resources, Rovnix, SpyEye, Stop Digging, update, virus remove, white paper, white papers, Win32 Carberp
Posted in Virus removal tools |
Evolution of Win32Carberp: going deeper
Written by v2r on November 21, 2011 – 10:36 pm -[More news from my colleagues in Russia on their analysis of an interesting item of bank-targeting malware.] This month we discovered new information on a new modification in the Win32/TrojanDownloader.Carberp trojan family. This trojan is notorious as one of the most widely spread malicious programs in Russia, stealing money from ...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, computer security, cybercrime, David Harley, Dmitry Volkov, ESET Russia, Eugene Rodionov, Group-IB, malware remove, RDPdoor, Rovnix, Sheldor, SpyEye, virus remove, Win32/Carberp, Zeus
Posted in Virus removal tools |
Evolution of Win32Carberp: going deeper
Written by v2r on November 21, 2011 – 10:36 pm -[More news from my colleagues in Russia on their analysis of an interesting item of bank-targeting malware.] This month we discovered new information on a new modification in the Win32/TrojanDownloader.Carberp trojan family. This trojan is notorious as one of the most widely spread malicious programs in Russia, stealing money...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, computer security, cybercrime, David Harley, Dmitry Volkov, ESET Russia, Eugene Rodionov, Group-IB, malware remove, RDPdoor, Rovnix, Sheldor, SpyEye, virus remove, Win32/Carberp, Zeus
Posted in Virus removal tools |