Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - These are not the droids you are looking for.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » March 2014 » Gameover Zeus variant harder to kill

Gameover Zeus variant harder to kill


Posted by: Timothy Weaver on 03/01/2014 11:41 AM [ comments Comments ]


According to security researchers from Sophos, the Gameover malware now comes with a rootkit that makes it harder to remove.

Gameover is a computer Trojan based on the infamous Zeus banking malware.

Researchers from Sophos said Thursday in a blog post that the latest trick from the Gameover authors involves using a kernel rootkit called Necurs to protect the malware’s process from being terminated and its files from being deleted.


This latest variant is being distributed via an email with an attachment that purports to be an invoice from HSBC France in a .zip file. The zip file does not contain the virus, but rather a downloader called Upatre which, if run, downloads and installs the banking malware.

If the download is successful, it tries to install the Necurs rootkit. Microsoft issued a patch in 2010 that could thwart the installation. If the rootkit can't install, it then prompts the UAC to ask for Administrator privileges. Users should be alarmed that an invoice is asking for those privileges!!

However, if the user confirms the execution anyway or the exploit is successful in the first place, the rogue driver starts protecting the Gameover components.

The Sophos researchers said: “The rookit greatly increases the difficulty of removing the malware from an infected computer, so you are likely to stay infected for longer, and lose more data to the controllers of the Gameover botnet.”

“Perhaps the two groups are joining forces, or perhaps the Necurs source code has been acquired by the Gameover gang,” the Sophos researchers said. “Whatever the reason, the addition of the Necurs rootkit to an already-dangerous piece of malware is an unwelcome development.”

Zeus variants accounted for almost half of all banking malware seen in 2013.




« Class action suit filed against MtGox · Gameover Zeus variant harder to kill · Random Photo: The need to go on social media explained »




Comments
comments powered by Disqus

MajorGeeks.Com » News » March 2014 » Gameover Zeus variant harder to kill

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition