BitDefender Shows How Conficker, Downadup and Other Worms Make the April's Top 10 E-Threats Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/7 8:22:57
2009/11/7 8:22:57
2009/11/7 0:09:48
2009/11/6 20:09:28
Our Partners
Downloads
Antivirus : BitDefender Shows How Conficker, Downadup and Other Worms Make the April's Top 10 E-Threats
Posted by Max on 2009/5/6 15:30:00 (630 reads)
Antivirus

BitDefender released the ten most prevelant threats facing Internet users in the month of April. The top is still dominated by Trojans, as it was in March. These threats rely solely on tricking users to spread the e-threat, and they occupy seven of the ten positions this month.

Only a couple of worms, exploits and viruses break up the "trojan parade."

Highlighting the importance of the Web as the infection vector du jour, in tenth position we find a "silent" trojan that gets injected into vulnerable, legitimate websites. It is only used to make visitors' browsers load exploit code, such as those detected by BitDefender as Exploit.SWF.Gen and Trojan.Exploit.ANPW in sixth and fifth place respectively (this combination actually exists and is found mainly on Chinese malicious websites.)

Trojan.Peed.Gen (aka the venerable Storm Worm) racks up 1.81-percent of detections for April, but is now a dropped component for a different threat. This could be a sign that while it is still useful, this worm has outlived its effectiveness as an infector and is now only being used for the control functionality it provides to an attacker.

A newcomer occupies the eigth spot -- Trojan.KillAV.PT. This threat is a "utility" malware, which kills any antivirus or security process it can find (from a long list) on the target machine, preventing them from running. The threat then decrypts and executes a downloader, which in turn downloads and installs a game password stealer.

Ranking seventh, Win32.Sality is the only true virus in the April top ten. Win32.Sality is a polymorphic file infector which modifies executable files (.exe and .scr) appending its encripted body at the end of files in a newly created section. Its other means of spreading is a new -- yet old -- method, linking to an infected executable from the Autorun.INF file found on removable media or network shares, a trick that has served the much newer Downadup aka Conficker.

The Conficker worm occupies fourth place, under the Win32.Worm.Downadup.Gen. Its capabilities are well known by now, but the fact that it is still spreading vigourously enough to take up 3.05% of detections by itself is something of a surprise after all this time.

"We can only hope the high detection rate is due to the people who were previously infected finally running an antivirus," explained Sorin Dudea, Head of BitDefender Antimalware Research. "However, we expect the reality is more along the lines of the worm being replicated by a sizeable network of infected machines."

Two rather old adware trojans, Wimad and Clicker occupy the third and second spots.

Trojan.AutorunINF.Gen occupies first place. It is not a single e-threat, but rather a generic name for trojans which use the Autorun.INF spreading mechanism outlined above, but for which a specific signature has not been added.

"We're pretty pleased with having this kind of generic, no-human-in-the-loop detection work, and work well," said Mr. Dudea. "The future of reliable antivirus detection depends on adapting to new e-threats in real time and such techniques pave the way there."

BitDefender's April 2009 Top 10 E-Threat list includes:

Pos.    Name                         %
1.      Trojan.AutorunINF.Gen       9.0
2.      Trojan.Clicker.CM          8.47
3.      Trojan.Wimad.Gen.1         5.68
4.      Win32.Worm.Downadup.Gen    3.05
5.      Trojan.Exploit.ANPW        2.84
6.      Exploit.SWF.Gen             2.4
7.      Win32.Sality.OG             2.1
8.      Trojan.KillAV.PT           1.91
9.      Dropped:Trojan.Peed.Gen    1.81
10.     Trojan.Exploit.SSX         1.74
Other malware             60.99

About BitDefender®
BitDefender is the creator of one of the industry's fastest and most effective lines of internationally certified security software. Since its inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Fore more details please visit http://www.bitdefender.com




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.