When the hammer falls - effects of successful widespread disinfection on malware development and direction

Matt McCormack Microsoft

  download slides (PDF)

The arms race between the anti-virus industry and concerted malware developers continues to escalate. Microsoft's Malicious Software Removal Tool (MSRT) is executed on over half a billion computers every month, giving it a huge execution base and an unparalleled view of malware operations. In their first month of targeting by MSRT, the Win32/Cutwail and Win32/Nuwar families yielded an infection spread of almost half a million distinct machines between them. MSRT's monthly release provides a unique snapshot of the Windows ecosystem, and of the sledgehammer effect the tool has on the targeted families; an effect that can hardly be ignored by the malware's authors. With so much money at stake, it appears that the Malware developers do not go down without a fight.

This paper couples analysis of the major malware families targeted by MSRT with the telemetry it gathers, in order to provide a perspective on how malware authors quickly respond to the massive impact on their networks after each release. Analyses of the techniques used to evade the MSRT are presented. A look at the engineering evolution of each of these families with respect to MSRT releases is also explored.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 190,995 registered users.