Vinzenz Feenstra’s WebLog

August 10, 2006

German HipHop youngster released his first Music video

by @ 5:57 pm. Filed under News, HipHop

Yesterday the 16 years old german hiphop youngster ‘F.R.’ has released his first video ‘Sport’.

Feel free to download it from here and don’t forget to visit his website.

Low Quality Video (28 MB, WMV)

High Quality Video (119 MB, MPEG)

Don’t forget to buy his album ‘Mittelweg’ which is really tight! I have it since 16th June 2006.
Check out the free tracks on his Website www.eff-arr.de

Enjoy the video!

Regards,
Vinzenz

Homepage of F.R.



Tags: , , , , , ,

August 7, 2006

How to remove Trojan.Downloader.uj

by @ 3:23 pm. Filed under News, Downloads, Articles, Security, Tutorials

I have previous posted about the Windows threat ‘Trojan.downloader.uj’ and that I have build a removal help tool for it.

I think it would be best for all if I post here some removal steps for this special threat which is really tricky, since it is a trojan but uses userland rootkit techniques.

Here are the steps:

  1. Download the file "rmdlagentuj.exe" from following location: http://fileserver.ewido.net/public.cgi?id=20845
  2. Execute the file "rmdlagentuj.exe" if it was successful you will get a message dialog where you will be asked to reboot
  3. Reboot your computer (Important!)
  4. Execute a complete system scan with ewido anti-spyware 4.0 ( http://www.ewido.net )

Or you can try Grisoft AVG Anti-Rootkit Beta 1.0.0.13, but be careful it is a beta!
Thats’s all the threat should be removed now.


Aliases for this threat are:

Antivirus Alias
AntiVir TR/Dldr.Agent.uj.1
Authentium W32/Downloader.LTB
Avast Win32:Agent-IU
AVG Downloader.Agent.BAH
BitDefender Trojan.Downloader.FFZ
CAT-QuickHeal TrojanDownloader.Agent.uj
ClamAV Trojan.Downloader.Agent-262
DrWeb Trojan.DownLoader.4316
eTrust-InoculateIT Win32/SillyDL.51200!Trojan
eTrust-Vet Win32/Alureon.Y
Ewido Downloader.Agent.uj
Fortinet RuinDl.G!tr
F-Prot security risk named W32/Downloader.LTB
F-Prot4 W32/Downloader.LTB
Ikarus Trojan-Downloader.Win32.Agent.uj
Kaspersky Trojan-Downloader.Win32.Agent.uj
McAfee Downloader-ASI
Microsoft TrojanDownloader:Win32/Agent.RR
NOD32v2 a variant of Win32/Small.FB
Norman W32/DLoader.NNL
Panda Trj/Ruins.MB
Sophos Troj/RuinDl-G
Symantec Downloader
TheHacker Trojan/Downloader.Agent.uj
UNA TrojanDownloader.Win32.Agent.68D6
VBA32 Trojan.DownLoader.4316

I hope this is helpful.

Regards,

Vinzenz Feenstra



Tags: , , , , , , ,

August 5, 2006

Should we be scared about future rootkits?

by @ 11:36 am. Filed under News, Articles, Security

I was reading  blog entry of Joanna Rutkowska, a really smart and good looking (*fg*) expert in security and rootkits from Poland, and I was really asking myself, should we be scared about rootkits in the future? To give you a short answer: Yes we should!

Ok of course such rootkit can maybe be blocked before they’re installed or while it tries to installs itself or any other malware tries to install it. I am reading about the technology and the evolution of the knowledge in this area for a while and I need to say that it is really scary how fast the evolution moves forward.

Last year I was reading something about DKOM (Direct Kernel Object Manipulation), after thinking about the concept I was sure something like this is comparative easy to detect. Also hooking SSDT, IAT, EAT or using Inline Hooks (Detours) is almost harmless if you know how to get rid of it (see my previous post Trojan.Downloader.uj which is about an userland rootkit)

Anyway this year, only about 6 months later I read something which really scared me. joanna Rutkowska held some presentations about rootkits again and there she demonstrated a rootkit she is calling ‘deepdoor’. After taking a look at what she can do with this threat I was really asking myself how should you detect something like this. Ok there will be some smart guy who will be abled to detect (I am sure there will be one!). But now (ok it was already in June, but it doesn’t matter) she is writing about ‘Blue Pill’. Think about this: You are running VMWare on your computer and host another windows in there. This no great deal, that’s right but what would you say if somebody tells you that you’re hosting VMWare already in a virtual environment?

Huh? That’s really scary. And I must admit that using the name ‘Blue Pill’ is a really good choosen name.

I am right in the beginning in understanding how malware works and how it can be detected and removed but if I read something like this I am really asking myself how should we prevent ourselves from such threats?

I hope that we will be abled to have an idea how to get a ‘Red Pill’ for such threats and are abled to remove or at least to warn the users about such a threat.

Further reading about this subject you can find at:

Edit: (8th August 2006) I found another really interesting blog entry about this at http://www.ryanpmanning.com/?p=56

Be aware! Be scared!
Regards,
Vinzenz Feenstra



Tags: , , , , , ,

August 4, 2006

“Extended Security Links”

by @ 9:48 pm. Filed under News

Hi,

I have created a new page with a list of security links. Please find the page at

http://blog.evilissimo.net/extended-security-links/

I would appreciate comments on it and it would be great if you have links which can be added there.
I will update this page from time to time so that it will stay up-to-date.

Regards,

Vinzenz :)



Tags: , , , , , , , ,

August 1, 2006

Grisoft AVG Anti-Rootkit Beta

by @ 11:56 am. Filed under News, Security

Grisoft AVG Anti-Rootkit 1.0.0.13 Beta released

I am proud to announce that Grisoft has released the AVG Anti-Rookit Beta available at http://beta.grisoft.cz after a registration (which is for free)

It is abled to detect and to remove a lot of rootkits. How good it is you will really know if you have a rootkit on your system ;) The Screenshots below are showing the tests in a VMWare Session where I have installed the Vanquish rootkit which is available at rootkit.com

I really  warn everyone this is a  beta software it may work but you should be careful!

While scanning:

After a scan:

Please report your test results and your opinion about it.

 

Regards,

Vinzenz



Tags: , , , , , , ,

archives:

August 2006
M T W T F S S
« Jul   Oct »
 123456
78910111213
14151617181920
21222324252627
28293031  

internal links:

categories:

Search

other:

Advertisement