Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
Major Geeks.com- Feel the Geek.. BE the Geek!

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· RadioCast 1.0
· Speak-A-Message 9.1.0
· PRTG - Free Network Monitor 13.2.3.2134
· VarieDrop 1.2.1.0
· 7-Data Recovery 2.0.01 (3 day giveaway)
· iSpy 5.0.9.0
· Sublight 4.0.4887
· DVDFab Passkey Lite 8.0.9.9
· x264 Video Codec 2334
· J. River Media Center 18.0.189

· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall

There are currently 3707 user(s) online:
Google, Live Search, MSN, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. IObit Malware Fighter
6. JetClean
7. x64 Components
8. Windows 8 Codecs
9. SpywareBlaster
10. Advanced SystemCare Free 6.2.0.254 (0424)
More >>

What's The Best Browser to Protect You against Malware?

The plane! The plane! Fantasy Island airplane used to smuggle drugs after show finished (Video)

Friday Photo Bombs!

Female fan who flipped off Noah in photo identified as Filomena Tobias

Majorgeeks updates website to new CMS and design – didn’t break EVERYTHING

First time setup and installation of an SSD drive

Friday Photo Bombs!

NASA dumping Windows for Linux

World Of Warcraft loses 1.3 million subscribers in 3 months

Pay attention to the Kiss Cam (Video)





MajorGeeks.com » News » August 2012 » Bafruz Backdoor Disables Antivirus, Intercepts Communications With Social Media Sites

Bafruz Backdoor Disables Antivirus, Intercepts Communications With Social Media Sites


Posted on: 08/15/2012 04:12 PM [ Comments ]


There's a new family of malware that's using a complex set of capabilities to disable antimalware and listen in on sessions between users and some social networks. Bafruz is essentially a backdoor trojan that also is creating a peer-to-peer network of infected computers.

This month's Microsoft Malicious Software Removal Tool (MSRT) release will include the Win32/Bafruz family. Bafruz’s capabilities include the ability to uninstall antivirus and security products, intercept social media communications sites like Facebook and Vkontakte, install Bitcoin mining software, and perform denial of service attacks. It also communicates with other infected machines across a peer-to-peer protocol in order to download new components onto host machines, according to the Microsoft Malware Protection Center.

The payload seems to start by terminating a long list of security processes listed in its code. It then displays a fake system alert that looks like that of any standard rogue AV attack. The difference, according to Microsoft, is that this fake-alert isn’t asking for money to remove a threat. All it wants is for infected users to reboot their machines. If a user complies with the alert and clicks the ‘remove’ option, it will cause the computer to reboot in safe mode where Bafruz can remove the components of any anti-virus products.

Even if a user doesn’t click the reboot option, Bafruz will execute a force reboot into safe mode anyway. Microsoft claims that Bafruz’s list of AV and security processes is actually used by the backdoor component to disable any AV products once booted in safe mode. Once the reboot is complete users will see this message.

Microsoft believes the alerts are tailored specifically to mimic a variety of security products. The warnings the Microsoft researchers saw purport to come from MSE. They warn that Bafruz may in fact be capable of masquerading as any number of security products you might have installed on your machine.

The presence of any of the following files is a tell-tale sign of infection: btc_server.exe, client_8.exe, ddhttp.exe, gbot_loader.exe, iecheck12.exe, loader2.exe, loader_rezerv.exe, udp.exe, and/or w_distrib.exe%windir%\proc_list1.log. There are also a number of registry modifications you’ll want to look out for, which can be found here.







Like it? Share it....




Comments
comments powered by Disqus

« Verizon offers two defenses of indefensible $5 fee · Bafruz Backdoor Disables Antivirus, Intercepts Communications With Social Media Sites · Serious vulnerabilities left in Adobe Reader after huge patch »

MajorGeeks.com » News » August 2012 » Bafruz Backdoor Disables Antivirus, Intercepts Communications With Social Media Sites
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition