A Trojan horse program has been designed to hurt machines that use Microsoft Windows' encrypted file system. The Trojan will "crawl" into the system's payload and hide its protection program - warning by a researcher at security firm McAfee over the past week.
The attack function of this Trojan is two parts: a dialer called Qdial-45 and an encrypted downloader called Spy-Agen.bf. The dialer disconnects the current modem connections, then dials a service to show the content. The downloader uses the Encrypted File System (EFS) to encode and retrieve the updated content from the list of websites on the Internet.
This is the latest malicious program to use encryption mechanisms to hide itself from desktop security software (such as antivirus programs). Last month, security firm Synmatec, which owns SecurityFocus, warned of a virus that could use encryption and an operating system function to hide itself. Other malicious codes, known as ransomware, use encryption mechanisms to "crawl" the file system and hijack file control in victim machines. Distributors This Trojan only offers decryption keys for hijacked files when users pay them a certain fee.
Malware 'crawls' to hide the barrier
A Trojan horse program has been designed to hurt machines that use Microsoft Windows' encrypted file system. The Trojan will 'crawl' into the payload of the system and hide the protection program - warning by a researcher.
4 ★ | 2 Vote
Read More
- Instructions for using Hide My Ass to hide IP
- Barrier protects London from flooding
- Warning Ghimob new banking malware, mobile users cannot remove
- How many types of malware do you know and how to prevent them?
- 10 typical malware types
- Malicious Web Applications: How to detect and block them
- What is Safe Malware? Why is it so dangerous?
- Can a VPN Fight Malware?
- Why is Infostealer malware the biggest new malware concern?
- What is Malware? What kind of attack is Malware?
- The 4 most common ways to spread malware today
- Download Free Hide IP 4.2.0.6: Simple tool to increase security
- Learn about polymorphic malware and super polymorphism
- What is Goldoson Malware? How can you protect yourself?