EFY Times  
Monday, May 21, 2012
 
GO
       Electronics       Infotech      Linux & Open Source       Consumer Electronics      Telecom      BPO      Science & Technology      tech4biz      Tablets      Aadhaar   
 
 
ESET Detected New Version Of Win32/Rovnix rootkit
 
Home >> Infotech >> Trends
 
ESET Detected New Version Of Win32/Rovnix rootkit  
 
   
Rate this news:  (1 Votes)
Tuesday, February 28, 2012 Researchers from global security company ESET have recently found a new modification of infamous Win32/Rovnix Trojan, a rootkit malware targeting Windows OS. Analysts expect an increase in native 64-bit malware, especially rootkits, in 2012.

Win32/Rovnix rootkit was first discovered in 2011 and it was the first bootkit using Volume Boot Record (VBR) infection. New version of Rovnix dropper has been detected by ESET as Win32/Rovnix.B trojan in the beginning of February, 2012.

Threats targeting 32- and 64-bit Windows OS become more and more complicated and sophisticated. Apart from Win32/Rovnix family, there are bootkits like TDL4 (TDSS, Alureon.DX, Olmarik) which facilitates the creation and maintenance of a botnet, ZeroAcces or Win32/Sirefef that replaces some critical files belonging to the OS and hooks kernel structures to make itself invisible to both the OS and security software. By the mid of 2011, rootkit malware had affected more than 5 mln computers worldwide, and India is among TOP-5 countries with high infection rates.





The Win32/Rovnix.B, as other rootkit droppers, is distributed by an affiliation program (Pay Per Install). Affiliates receive between $8 to $160 for every 1,000 installations of such rootkits, the price particularly in India is the lowest in the market.

Previously, Win32/Rovnix was mainly distributed from two domains – malwox.com and netox.biz – with affiliation programs. Affiliates like to choose websites for photo and video storage, games, adult content for planting malware.

When appeared in 2011, Win32/Rovnix established a new trend: modifying the VBR and Bootstrap Code. Using such a technique allowed malware to bypass many security and antivirus programs since the feature makes detecting and removing these threats more difficult. Rovnix bootkit framework has been evolving recently and the new version includes updates to the following components like malicious bootstrap code and kernel-mode driver.

“It seems that the developers of the malware haven’t wasted their time. The key features introduced in the new version are self-defense mechanisms intended to prevent the malware from being detected by antivirus software have been introduced and implementation of hidden storage to store configuration data for the payload has been added. Rovnix relies on its own mechanisms to store data which allows them to counteract forensic analysis and adds additional stealth functionality to counter antivirus software”, says David Harley, Senior Research Fellow at ESET.

Another interesting fact is that the bootkit builder for VBR bootkits like Win32/Rovnix is offered for sale on underground market. For instance, Win32/Carberp, very dangerous banking trojan the most widely spread and in Russia, CIS and some European countries, was upgraded in 2011 and started using Rovnix bootkit components. “It may be that what we are seeing now is a new mass-testing bootkit and in the future this code may be re-used in another malware family”, says David Harley.

ESET researchers predict the significant increasing of new malicious codes targeting 64-bit operation systems in 2012, till now the most dangerous rootkits and bootkits have been targeting mainly 32-bit platforms, though.

“The year 2011 could be referred to as a year of growth in complex threats. Over the course of this year we witnessed an increase in the number of threats targeting the Microsoft Windows 64-bit platform, and bootkits in particular”, says David Harley.

Versions of Microsoft Windows 64-bits were considered resistant against kernel mode rootkits because integrity checks performed by the system code. However, new malware targeting 64-bit Windows (Win64/Olmarik and Win64/Rovnix) was detected last year in the wild. These examples of malware use various methods to bypass kernel-mode code signing policy.

The approach used by rootkits and bootkits allows malware to keep its payload and configuration data secret where antivirus and security software is less likely to find it, what makes these malware a powerful weapon in the hands of cybercriminals.



Print Email Post Comment 
(Total Views: 729)
 
Share
 
 
Infotech News
   
Beware Of The 'Battery Doctor' Android App: BitDefender
Smartphones Led Cellular Market Growth In Q1
Facebook May Allow Kids Under 13 To Join The Site
New Samsung Galaxy SII Units Coming With Android 4.0 In India
ICS Upgrade Coming To All Sony Tablets!
 
 
 
     
     
     
Press Release
     
Half A Billion Dollars Spent on Damage ...
Epson Launches Ist Series Of Portable ...
Adobe Creative Suite 6 Delivers ...
Tata Communications Sweeps The ...
Stronger Focus On Content Development ...
IET’s ‘Present Around The World’ (PATW) ...
Facebook IPO - Comment By Naveen ...
KritiKal Solutions Showcased Latest ...
NCR, Aruba Networks Sign Global ...
Healthkart Acquires Fitness Community ...
Hisilicon Licenses Range Of ARM Mali ...
L&T Infotech Partners With BMC Software ...
GE Lights Up MHA Mahindra Stadium In ...
Nihilent Achieves CMMI-DEV ...
GETIT Partners With Supply Chain And ...
MagicBricks Launches ...
Gartner Says Worldwide IT Outsourcing ...
IESO Goes Live With MetricStream GRC ...
Goose Launches World’s First Fully ...
Samsung E2252 And Lava ARC-1 Up For ...
World’s 1st SIM-based NFC Mobile Device ...
Ericsson India Appoints Its ...
RS Components Adds New TE Utilux ...
Oracle India Launches Special ...
IEEE Intros Standard For Body Area ...
 
Wi2Wi Launches Android
WatchGuard Channel Partner Conference ...
Tanner EDA, Aldec Deliver A/MS Solution
Amkor To Build Global R&D Center In ...
Ittiam Announces New CTO
Atmel Showcases Arduino Development ...
Jabra And Westcon Middle East Group ...
Aerospherical Systems Intros World's ...
Array Networks Named Application ...
Blu-ray Technology On The Rise Across ...
OCZ Enables IceWEB Unified Storage ...
Sony Xperia P Up For Pre-Order At ...
Raghavendra Ramachanderan From Chennai ...
Sam Pitroda Receives Doctor Of ...
Ricoh India Launches Expansion Through ...
Quadra Software Solutions Rceives IT ...
Global LTE Subscriptions To Exceed 40 ...
Pitfalls Of Counterfeit-Part Epidemic ...
3D International, ThreeD Holograms ...
Anchor Electricals Strengthens ...
108 BASE Students Qualify In IIT-JEE ...
25 May: COMSOL Workshop At Bangalore
Spam In April 2012: Junk Mail Gathers ...
Cards & Payments Asia Fortifies Its ...
Go Live With “Zovi Live”
     
     
     
     
     
Most popular
 
 
 
 
Features
Biometrics Market Has Immense Potential In India
With a significant increase in its application areas, the biometric devices market is poised to grow at a CAGR of 42.4 per cent by 2014. We explore if...
Importance Of Calibration For T&M Instruments
The impact of even a small error in measurement can be tremendous in terms of loss in revenue. Hence, even the smallest of errors in delivery (data ac...
 
  View All
Dialogue
 
Indian Tablet Market Is A Key Segment For Us: Logitech
In conversation with EFYTimes, Subrotah Biswas, country manager, Logitech India and South West Asia spoke about the company's product line-up for tabl...
Digital Media Is Directly Measurable: Kenscio
Businesses have understood the consumer behaviour for a long time and are using those channels where consumers are spending time, whether at home, ...
Indian IT- ITes Sector Does Not Need Government Support: NIIT CEO
In an exclusive conversation with EFYTimes.com, Arvind Thakur, CEO, NIIT Technologies spoke about Indian IT and BPO industry and NIIT's perspective ab...
BPO Industry Should Move To Tier II Cities: Infosys
If a company could set up an outsourcing operation in a place like Assam or Guwahati, people would not want to move out. This will help in curbing ...
Customer Intimacy Is A Major Challenge: NetApp
Vikram Shah, president and director (R&D), NetApp India, speaks to Dilin Anand of EFY about his company's operations in India....
   
  View All
Daily App Review
 
Daily App Review: Waze-GPS & Traffic (iOS And Android)
Yes, we have maps and we have step-by-step navigation. But getting traffic details remains a pain in India. Unless you happen to be using Waze....
Daily App Review: Everything.me (Android And iOS)
It runs totally off the Web, needs no installation whatsoever, and does what is unthinkable to many people--gives Google and Bing a run for their mone...
Daily App Review: Discovr People (iOS)
So you have joined Twitter and have no idea about whom to follow. Don't worry, there's an app for that. ...
Daily App Review: Angry Birds Space (Android And iOS)
The flingable fowls are back. And this time, Rovio has finally added a new spin to the game, with some help from gravity. ...
Daily App Review: Nokia Drive 2.0 (Windows Phone)
One of the best navigation apps we have ever seen on a handset can now work in offline mode too. Yep, you can now get directions without a network con...
Daily App Review: Draw Something Free (Android And iOS)
Almost like clockwork, every few months there comes along an app that surprises everyone (including those who love it) by becoming a sensation. Angry ...
Daily App Review: Songify For iOS
Just speak normally. And this app will turn it into a song, complete with music. For free. ...
Daily App Review: Creative Studio (Lumia 800 And 710)
Windows Phone users--or at least those that have a Nokia Lumia 800 or Lumia 710--will be delighted at the news that Nokia has released a free image tw...
Daily App Review: Price of Persia Classic HD (iPad)
You can divide the world into two categories--those have played Prince of Persia and those who do not like playing videogames. And now the classic ver...
Daily App Review: Waze-GPS & Traffic (iOS And Android)
Yes, we have maps and we have step-by-step navigation. But getting traffic details remains a pain in India. Unless you happen to be using Waze....
Daily App Review: PressReader (iPad And Honeycomb)
It was one of the tech fantasies promised to us by sci-fi films--wake up in the morning and you will get the newspaper on a gadget that just needs to ...
Daily App Review: Pixlr-o-matic (Android)
You can say that there are two kinds of people who play around with photo apps on Android--those who keep asking for Instagram for Android and those w...
Daily App Review: Parking Frenzy 2.0 For Android
It is not often that you see Indian games shooting to the top of the popularity lists in the Android Market. Well, Parking Frenzy has managed to do ju...
Daily App Review: Klik For iPhone
Among all the gadgetry on display in Mission Impossible IV, perhaps the most striking was an iPhone app that could identify people who appeared on the...
Daily App Review: Dolphin Browser 7.4 HD (Android)
Dolphin HD, one of the most popular third-party browsers on Android, has just got an update. And with it comes voice recognition. ...
Daily App Review: Clear (iPhone And iPod touch)
Once in a while there comes along an app that some dismiss as being not useful enough, but which still gets downloaded by the thousands because the li...
   
 
Events
 
21 May: National Conclave On Integrated Management ...

23 May: CPBCM Certification Workshop

25 May: Mumbai HR Summit 2012

25 May: COMSOL Multiphysics Seminar

27 May: Middle East Industrial Technology Leadership ...

View All
   
   
 
 

home archives contact us advertise with us
           
Magazines Portals Directories Events News Verticals Educational Institute  
Electronics for You
LINUX for You
Facts for You
Electronics Bazaar
electronicsforu.com
efytimes.com
bpotimes.com
linuxforu.com
Electronics Annual Guide
EFY EXPO
EFY Awards
EduTech Expo
OSIWEEK Expo
Electronics
Infotech
Linux & Open Source
Consumer Electronics
Science & Technology
BPO
EFY Techcenter 
 
 
© Copyright 2012 EFY Enterprises Pvt. Ltd.
All rights reserved. Reproduction in whole or in part in any form or medium without written permission is prohibited.
Usage of the content from the web site is subject to Terms and Conditions