Virus Bulletin - October 2010

Editor: Helen Martin

Technical Consultant: John Hawes

Technical Editor: Morton Swimmer

Consulting Editors: Ian Whalley, Nick FitzGerald, Richard Ford, Edward Wilding

2010-10-01

Abstract

Changing times (comment); It's just spam, it can't hurt, right? (malware analysis); Rooting about in TDSS (malware analysis); Anti-unpacker tricks - part thirteen (technical feature); On the relevance of spam feeds (feature); Things to come (review feature); VB100 comparative review on Windows Server 2003 (comparative review)


Comment

Changing times

‘Ten years ago the idea of malware writing becoming a profit-making industry simply wasn’t on the radar.' Helen Martin, Virus Bulletin

Helen Martin - Virus Bulletin


News

Overall fall in fraud, but online banking losses rise

Leading trade association reveals that banking and credit card fraud in the UK fell overall in 2009, with a decrease in all areas apart from online banking.

Helen Martin - Virus Bulletin, UK


Cybersecurity Awareness Month

Seventh National Cybersecurity Awareness Month in the US.

Helen Martin - Virus Bulletin, UK


Dip in Canadian Pharmacy spam

Levels of Canadian Pharmacy spam drop following closure of notorious spam affiliate.

Helen Martin - Virus Bulletin, UK


Malware prevalence report

August 2010

The Virus Bulletin prevalence table is compiled monthly from virus reports received by Virus Bulletin; both directly, and from other companies who pass on their statistics.



Malware analyses

It's just spam, it can't hurt, right?

One nice summer’s day, emails started flooding into Gabor Szappanos's mailbox with a spam-like message and a suspicious-looking attachment. The messages promised news on the latest FIFA World Cup scandal, so he took a look. In fact, the messages were not only distributing spam, but also members of the Bredolab family, and were doing so using the infamous Gumblar distribution architecture. Gabor describes the working of the attack.

Gabor Szappanos - VirusBuster, Hungary


Rooting about in TDSS

During the course of their research into the TDSS rootkit, Aleksandr Matrosov and Eugene Rodionov developed a universal utility for dumping the rootkit’s hidden file system. Here they provide the details [1]

Aleksandr Matrosov - ESET, Russia & Eugene Rodionov - ESET, Russia


Technical feature

Anti-unpacker tricks – part thirteen

Last year, a series of articles described some tricks that might become common in the future, along with some countermeasures. Now, the series continues with a look at tricks that are specific to the IDA plug-in, IDA Stealth.

Peter Ferrie - Microsoft, USA


Feature

On the relevance of spam feeds

Claudiu Musat and George Petre explain why spam feeds matter in the anti-spam field and discuss the importance of effective spam-gathering methods.

Claudiu Musat - BitDefender, Romania & George Petre - BitDefender, Romania


Review feature

Things to come

New anti-malware companies and products seem to be springing up with increasing frequency at the moment, many reworking existing detection engines into new forms, adding new functions, as well as several that are working on their own detection technology, aiming to take on the entrenched big names at their own game. John Hawes take a quick look at a few of the up-and-coming products which he expects to see taking part in the VB100 comparatives in the near future.

John Hawes - Virus Bulletin, UK


Comparative review

VB100 – Windows Server 2003

This month the VB test team put 38 products through their paces on Windows Server 2003. John Hawes has the details of the VB100 winners and those who failed to make the grade.

John Hawes - Virus Bulletin


Calendar

Anti-malware industry events

Must-attend events in the anti-malware industry - dates, locations and further details.



Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 2 comments

Jobs Career Sidebar

VB2012
VB2012 VB2012 will take place 26 - 28 September 2012 at the Fairmont Dallas hotel, Dallas, TX, USA.

Virus Bulletin currently has 225,307 registered users.