You have commented 375 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Science & Technology
Proof of Concept Exploit Bypasses AV Programs
2010-05-09
This "virus" has not yet been released into the wild and it appears it is based on a very old general vulnerability.

The difference is that this new exploit uses the a multiprocessor scheduler to switch good software with malware between running threads. IIUC, virus programs do not check for these kinds of swaps in pagable memory before allowing code to execute. The kernal does, but then it does it to regulate which memory space gets written to and it does not distinguish between the two types of software.

So what are we end-users to do about it?
Researchers say they've devised a way to bypass protections built in to dozens of the most popular desktop anti-virus products, including those offered by McAfee, Trend Micro, AVG, and BitDefender.

The method, developed by software security researchers at matousec.com, works by exploiting the driver hooks the anti-virus programs bury deep inside the Windows operating system. In essence, it works by sending them a sample of benign code that passes their security checks and then, before it's executed, swaps it out with a malicious payload.
Posted by:badanov

#6  comments); ?>werwer
Posted by: Barbara Skolaut   2010-05-09 17:41  

#5  comments); ?>werwer
Posted by: Steve White   2010-05-09 15:26  

#4  comments); ?>werwer
Posted by: Skidmark   2010-05-09 13:30  

#3  comments); ?>werwer
Posted by: OldSpook   2010-05-09 11:36  

#2  comments); ?>werwer
Posted by: badanov   2010-05-09 11:08  

#1  comments); ?>werwer
Posted by: Bright Pebbles   2010-05-09 07:40  

00:00