Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Hijacking Windows System Restore for cybercrime profit

28 Sep 2009   #1
reghakr

Windows 7 Pro & Vista Home Premium
 
 
Hijacking Windows System Restore for cybercrime profit

Cyber crime gangs in China are penetrating the hard disk recovery cards on computers in Internet cafes and using a combination of zero-day flaws, rootkits, and ARP spoofing techniques to steal billions of dollars worth of online gaming credentials.

According to a Microsoft anti-virus researcher, five generations of the Win32/Dogrobot malware family have perfected the novel rootkit technique to hijack System Restore on Windows — effectively allowing the malicious file to survive even after the compromised machine is reverted to its previous clean state.

At the Virus Bulletin 2009 conference in Geneva, he provided a look at the techniques used by Dogrobot, which is directly linked to the lucrative underground trading of online gaming assets like passwords and virtual property. According to data presented by Feng, the Dogrobot family has caused more than USD$1.2 billion in losses to Chinese Internet cafes. He explained that earlier Dogrobot used disk-level I/O file manipulation to penetrate System Restore but, as the malware evolved, it started using
a “backdoor” that already exists in the System Restore functionality.

A third generation introduced extensive unhooking code to thwart the protection offered by security programs and avoid removal. Along the way, he discovered that newer variants were tweaked to get around security software and strengthen the code’s ability to maintain
persistent stealth on compromised Windows computers.

In China, Internet cafes are very popular among the online gaming crowd where the use of USB sticks with account credentials is the norm. Dogrobot takes advantage of this, abusing the USB AutoRun functionality on older machines to propagate. He explained that the malware author has found success exploiting zero-day ActiveX vulnerabilities and other flaws in Windows OS and third-party software — especially RealPlayer and
WebThunder. The attackers also use ARP cache poisoning to send malicious ARP packets to instruct other machines within the same LAN to download Dogrobot samples.

More........Hijacking Windows System Restore for cybercrime profits | Zero Day | ZDNet.com
My System SpecsSystem Spec
Reply

Thread Tools


Similar help and support threads
Thread Forum
System restore, I cant restore my computer with a windows 7 disc
I am trying to completely wipe my computer clean by using the windows 7 disc. Problem is i cant get the disc to boot on star up.
Backup and Restore
Windows won't startup, System Repair and System Restore failed.
Gateway DX4720-03, Windows 7 HP 64-bit. Living is south FL can be a bitch when the rains come as there often is a ton of accompanying lightening that plays havoc with the electrical system, even though I have surge protectors inside and outside the house. We just had some very heavy rains with...
General Discussion
Microsoft profit dips despite Windows 8 sales boost
BBC News - Microsoft profit dips despite Windows 8 sales boost
News
System Restore - Restore system settings and previous versions of file
estore system settings and previous versions of file is greyed out on my system, I may have disabled a required service for this, can anyone point me to the right direction for this? As I'm about to try the X-Fi MB2 mod again as the last time I tried it my system was messed up that it wont even...
Backup and Restore
Windows 7 system restore point. Can't create / restore .
Hi Ok I borke world recored for formating windows 7 , the last 2 months . The problem is ; Windows System restore keep freezing , I'm not trying to do system restore , but when I try to install/remove a software , windows try to create restore point , making the installation/removing...
Backup and Restore
Windows 7 System restore problem no restore points
I have seen numerous people are having this problem but I have not been able to find a solution that works for me. I figured I would post my own problem and maybe somebody could recommend a solution. I have been trying to use Windows System Restore on Windows 7 Home Premium. I have created...
Backup and Restore


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 08:44.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App