| |
Subvirt - The Prototype Of The Next Generation Malware By Matija Vidmar In the last few years the most dangerous PC viruses are disappearing. Macro viruses and script viruses are almost extinct.
But meanwhile there was an increase of trojan, backdoor, rootkit and spyware which may be employed to remotely control a PC. There was an increment of that includes spyware programs from 54.2% to 66.4%.
Rootkits are becoming famous. They are used by virus writers to remotely control infected PCs and use them for taking money and perform DDOS attacks.
In the Windows world the rootkit term is usually used to explain viruses and programs that employ a special technique to cover into the system environment. In Unix environment, rootkits are customarily rewritten tools of the operating system that are used to cover data from the users. For instance the ls command can be rewritten so that it doesn't show certain files.
There exist user-mode rootkits and kernel-mode rootkits. User-mode rootkits are fundamentally normal processes that may be simply sensed and eliminated. Kernel-mode rootkits are hidden inside of the operating system itself and caan be extraordinarily hard to perceive and eliminate.
SubVirt is the name of a project directed by Microsoft with the help of the University of Michigan. Now software and detection software have both control of the system at kernel-mode level. Virus writers are trying to find the best way to cover their in front of detection software and maintain at the same time the have maximum control over the machine.
the results of this research is the VMBR, Virtual Machine Based Rootkit. A Virtual Machine is a special software layer that works between the hardware and the operating system. On a Virtual Machine also the operating system runs in user mode. The rootkit would install itself between the operating system and the hardware and would have a total control of the system.
to work, the VMBR needs to start up before the operating system, so it's necessary to change the Master Boot Record to make it work. At computer start up the Virtual Machine would start and then it would run the operating Download and Installation Instructions:
CLICK HERE TO START DOWNLOAD
To download and install Malwarebot please follow these instructions.
1. When the File Download dialog box appears click the .Run . button.

system in a virtual environment. Potentially it can run two operating systems at the same time, the user's Windows and a specially crafted operating system that would be invisible to the Windows system and to the user.
the issue with this type of software is that it might slow down the system. During their tests Microsoft spotted that the system sturtup takes about 30 seconds more with the Virtual Machine and it eats about 3 p.c. of system resources.
it is also significant to indicate the virtual machines that Microsoft used had the size of about one hundred megabytes, which is too much to fit in a typical MBR.
the entire dossier can be downloaded at http://www.eecs.umich.edu/pmchen/papers/king06.pdf
Matija Vidmar is an experienced programmer. He's also interested in computer security, networking and system administration and internet marketing. He owns a tech blog at calibro.candyham.com
|
|