headerphoto

Malware Win32/Renocide – Killed by Microsoft

Kamis, 24 Maret 2011 14:33:59 - oleh : GForce
Malware Win32/Renocide – Killed by Microsoft


Win32/Renocide, a malware program, plants copies of itself in shared folders of file-sharing applications and disguises them as titles of popular games and apps currently shared on popular torrent sites. So Microsoft this week used its Malicious Software Removal Tool to take out the threat, which dates back to at least 2005.


More on Renocide


It is a backdoor-enabled worm that spreads through removable drives, network shares and popular file-sharing applications. It drops copies of itself on all removable drives. It also spreads by scanning machines on an infected computer’s local network and pasting a copy of a file called autorun.inf, which many versions of Windows automatically execute when the drive is attached.


 


How does the infection take place?


It infects the network by scanning the local network using the subnet mask 255.255.0.0 and looking for writeable shares where it can copy itself. It also uses the NETBIOS protocol to look for machines in the local network where it can plant copies of itself.


It can also cause infected machines to connect to remote servers over Internet Relay Chat. In this way  hackers, can send commands  and download other malicious programs. According to Microsoft, Renocide also attempts to monitor the IP address of the infected machine using whatismyip.com. In this way it can tell where the machine has been and whether or not it would be worth sending the worm to that site as well.


 


Malware Rankings


So let’s look at Microsoft’s rankings of recent malware programs and how many machines have been infected.


Here is a list of the Malwares detected.





























































Rank Family Name Threat Count
1 Sality 248,250
2 Rimecud 209,208
3 Taterf 178,421
4 Renocide 167,826
5 Frethog 125,781
6 Bubnix 116,772
7 Vobfus 114,850
8 Conficker 88,636
9 Zbot 78,304
10 FakeSpypro 64,904

Chart 1 – Win32/Renocide, detected files


——————————————-




























































Rank Family Name Machine Count
1 Rimecud 200,267
2 Taterf 160,632
3 Sality 160,579
4 Renocide 123,413
5 Vobfus 107,866
6 Frethog 104,121
7 Bubnix 88,858
8 Conficker 82,192
9 Zbot 72,669
10 FakeSpypro 62,943

Chart 2 – Win32/Renocide, infected machines


 




 

kirim ke teman | versi cetak | Versi PDF

Berita "Komputer Dan Internet" Lainnya

Donation

: U5684711

Login


Username
Password

Register
Forgot Password

Pesan Singkat

Advertisement

Kalender

« Feb 2012 »
M S S R K J S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 1 2 3
4 5 6 7 8 9 10

Hijjrah Date

Rabiul Awal
30
Khamis
1433 HIJRIAH

Banner Link's

Support

Webmail

Masuk ke akun Anda di

Webmail Sasmita.Web.Id

Nama pengguna:
@sasmita.web.id Sandi: Tidak dapat mengakses akun Anda?