1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Read Me Windows Registry-infecting malware has no files, survives reboots

Discussion in 'Security Updates' started by snoopy, Aug 4, 2014.

  1. snoopy

    snoopy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    1,671
    Location:
    At my computer
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    custom built -
    Antivirus doesn't stand a chance becuase there's nothing for it to scan

    Researchers have detailed a rare form of Windows malware that maintains infection on machines and steals data without installing files.

    The malware resides in the computer registry only and is therefore not easy to detect.

    It code reaches machines through a malicious Microsoft Word document before creating a hidden encoded autostart registry key, malware researcher and black hat exterminator Paul Rascagneres (@r00tbsd) says. It then creates and executes shellcode and a payload Windows binary.

    "All activities are stored in the registry. No file is ever created," Rascagneres said in a post.

    "So, attackers are able to circumvent classic anti-malware file scan techniques with such an approach and are able to carry out any desired action when they reach the innermost layer of [a machine] even after a system re-boot.

    "To prevent attacks like this, anti-virus solutions have to either catch the initial Word document before it is executed (if there is one), preferably before it reached the customer's email inbox."

    More details plus screenshot - http://www.theregister.co.uk/2014/08/04/registryinfecting_rebootresisting_malware_has_no_files/
     
  2. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Maybe the AV companies should have some of our guys working for them.
    Some of our tools can search for this and remove it.
     

Share This Page