Results 1 to 5 of 5
Like Tree5Likes
  • 3 Post By INDRANIL
  • 2 Post By INDRANIL

Thread: New zero-day Windows kernel vulnerability associated with Duqu Trojan !!!

  1. #1
    The Specialist *
    Overall activity: 36.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,433
    Liked
    900 times
    Points
    51,197

    Angry New zero-day Windows kernel vulnerability associated with Duqu Trojan !!!

    In the continuing saga of the malware known as Duqu, CrySyS Lab at the Budapest University of Technology and Economics has announced it was able to acquire a copy of the "dropper" from one of the victims. Droppers are typically very small, are designed to evade detection by anti-virus and can sometimes contain exploit code used to inject themselves onto the target computer.

    That is why this finding is important. Many analysts still have some doubts as to the relationship between Duqu and Stuxnet, but this piece of the chain of infection was missing. Now with a sample of the missing piece, we can put together a more coherent picture.

    What is a dropper and what does this mean? A dropper is a term used by anti-virus researchers to denote a piece of code that is usually installed onto a computer to download further malicious components.
    The dropper acquired by CrySyS used a Microsoft Word document that targets a zero-day vulnerability in the Windows kernel.

    This is an important distinction, as the vulnerability is not in Microsoft Word itself, meaning this flaw could be exploited through other delivery mechanisms.

    Microsoft has stated it is diligently pursuing a fix for the vulnerability used by this malware and hopes to provide it as soon as possible.
    Open your eyes and always be careful . Umm probably you should wait for the Microsoft fix . Have a nice day .

    Source .
    I don't need to know everything, I just need to know where to find it, when I need it.

  2. #2
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,153
    Liked
    1544 times
    Points
    4,220
    Thanks for the news Indra! How are things going with you my friend?
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  3. #3
    The Specialist *
    Overall activity: 36.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,433
    Liked
    900 times
    Points
    51,197
    Welcome Bear . Very much busy with the daily schedule . Trying to fix that schedule as a flexible one .

  4. #4
    Modern-day Romeo
    Overall activity: 7.0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,205
    Liked
    512 times
    Points
    63,788
    I'd appreciate if someone can provide me more information on the dropper and it's delivery mechanisms because I were to assume it's the same common delivery mechanism, I believe you can still defeat this though denying the initial execution of the dropper. Otherwise,you may block it's outbound connections in the hope to stop it from downloading further malicious components.
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

  5. #5
    Winnie-the-Pooh
    Overall activity: 16.0%

    Join Date
    Oct 2010
    Location
    Planet of people
    Posts
    986
    Liked
    677 times
    Points
    13,365
    Removal tool from Bitdefender

    http://www.duquremoval.com/en.html

    Microsoft Fix It

    http://support.microsoft.com/kb/2639658

    Good luck guys!
    I haven't a notebook...

 

 

Similar Threads

  1. Duqu Trojan revealed to be shape-shifting serial killer
    By Bearcat in forum Spyware/Viruses
    Replies: 7
  2. Microsoft issues Duqu virus workaround for Windows
    By Bearcat in forum Spyware/Viruses
    Replies: 5
  3. IE Windows vulnerability coughs up local files
    By A Guy in forum Spyware/Viruses
    Replies: 0
  4. New Windows Vulnerability Uncovered
    By A Guy in forum General Forum
    Replies: 17
  5. windows vulnerability scan
    By dazofdarlo in forum General Forum
    Replies: 0

Tags for this Thread

All times are GMT +8. The time now is 11:57 PM.