Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
MajorGeeks.com - It's like sports for geeks.

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· The Bat! Home Edition 5.4.0
· Photostage Slideshow Software 2.21
· Jajuk 1.10.6
· System Monitor II 17.3
· Ghostery 2.9.5
· LibreOffice Productivity Suite 4.1.0 Beta 1
· Google Chrome Beta 28.0.1500.20
· Hitman Pro 3.7.5.199
· Foxit Reader 6.0.3.0524
· BB FlashBack Express 4.1.6.2745

· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall

There are currently 3575 user(s) online:
Google, Live Search, MSN, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. IObit Malware Fighter
6. JetClean
7. x64 Components
8. SpywareBlaster
9. Windows 8 Codecs
10. Advanced SystemCare Free 6.2.0.254 (0424)
More >>

The plane! The plane! Fantasy Island airplane used to smuggle drugs after show finished (Video)

7-Data-Recovery 3 Day Giveaway - $29.95 Value! (LAST day!)

What's The Best Browser to Protect You against Malware?

Friday Photo Bombs!

Female fan who flipped off Noah in photo identified as Filomena Tobias

Majorgeeks updates website to new CMS and design – didn’t break EVERYTHING

First time setup and installation of an SSD drive

Friday Photo Bombs!

NASA dumping Windows for Linux

World Of Warcraft loses 1.3 million subscribers in 3 months





MajorGeeks.com » News » August 2012 » Kaspersky seeks help in cracking the Gauss trojan

Kaspersky seeks help in cracking the Gauss trojan


Posted on: 08/14/2012 04:16 PM [ Comments ]


Security researchers at Kaspersky Lab are looking to the cryptography community for help in deciphering the Gauss trojan. Despite their best efforts, the researchers have so far been unable to crack an encrypted payload in the trojan's "Godel" module; they hope that members of the cryptology and mathematics communities will be able to extract the hidden payload.

The Gauss trojan spreads via USB drives and infects systems using the well-known LNK exploit. These infected drives include two files – "System32.dat" and "System32.bin" – which are 32- and 64-bit versions of the same code which includes several encrypted sections. Once executed, the trojan first gathers information about the victim's system including running processes, drives and network shares, and save them to another file on the drive named ".thumbs.db", after which other modules are launched.

According to Kaspersky, the malware then tries to decrypt another module using several strings from the system. This payload is intended to run on a specific system; it will only be executed if the strings are found. The researchers at Kaspersky can only speculate as to what this module does until they can crack it: "We have tried millions of combinations of known names in %PROGRAMFILES% and Path, without success." The team say that the trojan appears to be looking for a very specific application that has a name that starts with a special symbol like "~" or is written in an extended character set such as Arabic or Hebrew.

The resource section of the payload is, the researchers say, large enough "to contain a Stuxnet-like SCADA targeted attack code". They also go on to note that all of the security precautions taken by the authors of the trojan seem to indicate that the trojan is after a high-profile target.

Those interested in helping to crack the trojan's payload can find further information, including sample and source data, in a post on Kaspersky's Securelist blog.







Like it? Share it....




Comments
comments powered by Disqus

« Microsoft Surface for Windows RT tablet coming October 26th for $199? · Kaspersky seeks help in cracking the Gauss trojan · Microsoft SkyDrive gets revamp just ahead of Windows 8 release »

MajorGeeks.com » News » August 2012 » Kaspersky seeks help in cracking the Gauss trojan
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition