The Security Researchers of Gdata discovered a Malware program that infects a system without the need to install any files, by living in the computer's registry. It is a rare type of malware which
does not create any file on the infected system because it lives in the infected computer's registry, thus making it nearly impossible for out-dated antivirus to detect it.
"All activities are stored in the registry. No file is ever created," said Gdata senior threat researcher Paul Rascagneres, in a blog post. "So, attackers are able to circumvent classic anti-malware file scan techniques with such an approach and are able to carry out any desired action when they reach the innermost layer of the [machine] even after a system re-boot."
To prevent attacks like this, Gdata warned that anti-virus software has to either catch the file before it is executed or preferably before it reaches the customer's email inbox.
As a next line of defence, Gdata said users need to detect the software exploit after the file' execution, or, as a last step, in-registry surveillance has to detect unusual behaviour, block the corresponding processes and alert the user.
via | source
does not create any file on the infected system because it lives in the infected computer's registry, thus making it nearly impossible for out-dated antivirus to detect it.
"All activities are stored in the registry. No file is ever created," said Gdata senior threat researcher Paul Rascagneres, in a blog post. "So, attackers are able to circumvent classic anti-malware file scan techniques with such an approach and are able to carry out any desired action when they reach the innermost layer of the [machine] even after a system re-boot."
To prevent attacks like this, Gdata warned that anti-virus software has to either catch the file before it is executed or preferably before it reaches the customer's email inbox.
As a next line of defence, Gdata said users need to detect the software exploit after the file' execution, or, as a last step, in-registry surveillance has to detect unusual behaviour, block the corresponding processes and alert the user.
via | source

Comments
Post a Comment
Please do not use any abusive word.