Csonicgo
This post is probably useless

Posts: 2535
Registered: 03-04 |
FINALLY!
After waiting a week or so for the other AVs and malware scanners to catch up to this ridiculous sunuvabitch, I finally removed every trace of it. Its last line of defense is to mod permissions on registry keys, which is easily dealt with by MBAM. MBAM still can't detect everything, so Spybot- that program everyone forgot about- took care of the rogue keys.
I've done integrity checks on system files and everything seems fine so far. The final nasties appeared to be the backdoor TDSS trojan modified with the Trace Rootkit.
This isn't the first round of a malware rapesuite and it won't be the last. But now that it's getting to be used more often with 0days, it seems like the malware makers aren't doing this for shits and giggles alone.
How long will it be before malware is written to exploit a plugin/browser/buffer/ to install itself, replicate, obfuscate replicants in the registry under tweaked keys, constantly check on its status and phoning home for the latest 0days to hop around an intranet while being able to infect USB keys undetected, so it can come back to infect a host by exploiting another 0day....all the while collecting passwords, performing sneaky Botnet operations, and annoying the shit out of the user with browser hijacks?
|