Author Topic: Sneaky parasytic virus injects Winlogon.exe beyond change!  (Read 2658 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Sneaky parasytic virus injects Winlogon.exe beyond change!
« on: January 07, 2008, 08:32:40 PM »
Hi malware fighters,

Infecting users through malicious codecs and films is a very popular thing to do for malcreants, these infections are often hard to detect. Virusresearchers now found a new variant of thet Kibik virus that injects itself as an a part of Winlogon.exe that is not used. Unlike other malware it does not change the size of the file that way. It does not leave any traces in the Windows registry nor does it change other files. Still the malware is loaded every time the machine starts.

Once infected the attacker has full control over the machine, as the malware starts to download other malware files. This variant is being spread by codecs, but other versions also are available as web exploit. McAfee calls this malware a "sneaky parasytic virus", and only few anti-malware products detect it.
See: http://www.avertlabs.com/research/blog/index.php/2008/01/04/w32kibikb-seeking-them-out-from-your-codecs-and-winlogonexe/

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Sneaky parasytic virus injects Winlogon.exe beyond change!
« Reply #1 on: January 07, 2008, 09:18:27 PM »
A new variant of thet Kibik virus that injects itself as an a part of Winlogon.exe that is not used.
I know Outpost Pro firewall check injection codes... but I don't know how it works?
Is there a way to get protected against code injection?

only few anti-malware products detect it.
Which are?
The best things in life are free.

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2118
Re: Sneaky parasytic virus injects Winlogon.exe beyond change!
« Reply #2 on: January 07, 2008, 09:23:46 PM »
I'm starting to hate these things recently. Sneaky injectors, Bho's recently are spreading all over the net and it's harder and harder to detect these nasty things...  >:( Sorry for off-topic but soon I'll doo the best thing to protect myself - to cut a dsl wire  ;D ;D ;D

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: Sneaky parasytic virus injects Winlogon.exe beyond change!
« Reply #3 on: January 07, 2008, 09:42:11 PM »
Hi Ylap,

Was this the firewall you had in mind?

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2118
Re: Sneaky parasytic virus injects Winlogon.exe beyond change!
« Reply #4 on: January 07, 2008, 09:53:38 PM »
Even the same model and firmware version  ;D