Virus Bulletin - April 2008

Editor: Helen Martin

Technical Consultant: John Hawes

Technical Editor: Morton Swimmer

Consulting Editors: Ian Whalley, Nick FitzGerald, Richard Ford, Edward Wilding

2008-04-01

Abstract

Political DDoS around the world (comment); Your computer is now stoned (...again!) (malware analysis); Anti-stealth fighters: testing for rootkit detection and removal (feature); Windows Vista Business Edition SP1 (comparative review)


Comment

Political DDoS around the world

'We have tracked tens of thousands of DDoS attacks ... A subset of [them] appear to be politically motivated.’ Jose Nazario, Arbor Networks

Jose Nazario - Arbor Networks, USA


News

VB2008 conference programme revealed

Three-day programme boasts exceptional line-up of anti-malware and anti-spam expert speakers and caters for both technical and corporate audiences.

Helen Martin - Virus Bulletin, UK


Sullied site stats

Increasing number of legitimate sites hosting malware, compromised sites remaining infected for longer.

Helen Martin - Virus Bulletin, UK


Malware prevalence report

February 2008

The Virus Bulletin prevalence table is compiled monthly from virus reports received by Virus Bulletin; both directly, and from other companies who pass on their statistics.



Malware analysis

Your computer is now stoned (...again!)

Mebroot - the MBR rootkit - is one of the most advanced and stealthiest malware seen to date. It operates in the lowest levels of the operating system, uses many undocumented tricks and relies heavily on unexported functions and global variables. In this article Elia Florio and Kimmo Kasslin track the rise of the MBR rootkit.

Elia Florio - Symantec Security Response, Ireland & Kimmo Kasslin - F-Secure Security Lab, Malaysia


Feature

Anti-stealth fighters: testing for rootkit detection and removal

While it is easy for a good signature-driven product to find a known sample that has not yet been activated, thanks to rootkit technology it is becoming increasingly challenging for products to detect samples once they are running and trying to hide themselves and other malicious components. Andreas Marx and Maik Morgenstern present the results of two recent rootkit detection tests.

Andreas Marx - AV-Test.org, Germany & Maik Morgenstern - AV-Test.org, Germany


Comparative review

VB100 April 2008 - Windows Vista Business Edition SP1

John Hawes wipes the sweat from his brow after completing a comparative review of 40 anti-malware products for Vista. With polymorphic trip-ups, false positives and stability issues in the fray it proved to be a tough test for the products involved.

John Hawes - Virus Bulletin


Calendar

Anti-malware industry events

Must-attend events in the anti-malware industry - dates, locations and further details.



Spam Bulletin

Spam Supplement - April 2008

Anti-spam news; How wise are crowds when assessing phishing websites? (feature)



Quick Links

Poll
The Japanese government is reported to have commissioned a 'defensive virus'. Is 'defensive' malware ever a good idea?
Yes
No
I don't know
Leave a comment
View 11 comments

99 Subscription Promo

VB100 certification
VB100 This month's VB100 test saw some major changes and a radical overhaul of the VB100 test methodology - for the first time allowing products to use their 'cloud' look-up systems. John Hawes has all the details.
See full results.

Virus Bulletin currently has 224,240 registered users.