<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Anti Rootkit Blog</title>
	<link>http://www.antirootkit.com/blog</link>
	<description>Antirootkit Software, News, Articles and Forums</description>
	<pubDate>Sat, 12 Apr 2008 03:19:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>
	<language>en</language>
			<item>
		<title>A Stormy Valentines Day ahead of us&#8230;</title>
		<link>http://www.antirootkit.com/blog/2008/01/15/a-stormy-valentines-day-ahead-of-us/</link>
		<comments>http://www.antirootkit.com/blog/2008/01/15/a-stormy-valentines-day-ahead-of-us/#comments</comments>
		<pubDate>Tue, 15 Jan 2008 23:09:57 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Debate</category>
	<category>E-Cards</category>
	<category>Other Malware</category>
	<category>Analysis</category>
	<category>Storm Worm</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2008/01/15/a-stormy-valentines-day-ahead-of-us/</guid>
		<description><![CDATA[It looks like the Storm Worm is with us once again.
Emails have been spammed out with a Subject Line that contains one of the following,
Falling In Love with YouSpecial RomanceYou&#8217;re In My ThoughtsSent with LoveOur Love Will LastOur Love is StrongYour Love Has OpenedYou&#8217;re the OneA Toast My LoveHeavenly Love
If a user clicks on the link [...]]]></description>
			<content:encoded><![CDATA[<p>It looks like the Storm Worm is with us once again.</p>
<p>Emails have been spammed out with a Subject Line that contains one of the following,</p>
<p><img id="image115" height="96" alt="loveheart.jpg" src="http://www.antirootkit.com/blog/wp-content/uploads/2008/01/loveheart.thumbnail.jpg" align="left" />Falling In Love with You<br />Special Romance<br />You&#8217;re In My Thoughts<br />Sent with Love<br />Our Love Will Last<br />Our Love is Strong<br />Your Love Has Opened<br />You&#8217;re the One<br />A Toast My Love<br />Heavenly Love</p>
<p>If a user clicks on the link in the email then they are brought to a website that gets unsuspecting users to download their Love ecard. If run, the &#8220;ecard&#8221; will turn the users PC into a bot. The PC will then join the many others in the Storm Worm Botnet.</p>
<p>It seems a bit early for Valentines Day though! Maybe the authors mistakenly released it?</p>
<p>If not, then we could be in for a long run in to Valentines Day.</p>
<p>Keep Safe</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a></p>
<p> </p>
<p><u style=display:none><a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Self-help-credit-repair.html">Self help credit repair</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Credit-repair-attorney.html">Credit repair attorney</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Understanding-credit-report.html">Understanding credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/A-credit-report.html">A credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Commercial-mortgage-refinance.html">Commercial mortgage refinance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Auto-loan-interest-rates.html">Auto loan interest rates</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Consumer-debt-settlement.html">Consumer debt settlement</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Credit-repair-after-bankruptcy.html">Credit repair after bankruptcy</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Uk-credit-card-offer.html">Uk credit card offer</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Debt-consolidation-loan-denver.html">Debt consolidation loan denver</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Health-insurance-premium.html">Health insurance premium</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Online-credit-report.html">Online credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/California-best-refinance-mortgage-rate-california-home-loan.html">California best refinance mortgage rate california home loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/For-credit-reporting.html">For credit reporting</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Card-credit-debt-free.html">Card credit debt free</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Free-equifax-credit-report.html">Free equifax credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Online-credit-scores.html">Online credit scores</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Discover-business-credit-card.html">Discover business credit card</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Instant-experian-credit-report.html">Instant experian credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Auto-home-insurance.html">Auto home insurance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-score-of.html">Credit score of</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Student-loans-without-credit-check.html">Student loans without credit check</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Application-aspen-card-credit.html">Application aspen card credit</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Consumer-credit-report.html">Consumer credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Free-credit-rating-report.html">Free credit rating report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Life-insurance-uk.html">Life insurance uk</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Disability-insurance-canada.html">Disability insurance canada</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Of-fair-credit-reporting.html">Of fair credit reporting</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-free-instant-report.html">Credit free instant report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Auto-loans-for-people-with-bad-credit.html">Auto loans for people with bad credit</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Home-equity-loan-rate.html">Home equity loan rate</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Home-equity-loans-online.html">Home equity loans online</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/New-home-loans.html">New home loans</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/0-credit-card-offers.html">0 credit card offers</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Creditscore.html">Creditscore</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Accept-credit-card-services.html">Accept credit card services</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Fax-payday-loan.html">Fax payday loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Cash-til-payday-loan.html">Cash til payday loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/College-student-loan-consolidation.html">College student loan consolidation</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-card-processing-terminals.html">Credit card processing terminals</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/California-health-insurance-quote.html">California health insurance quote</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Mbna-credit-card-application.html">Mbna credit card application</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-score-management.html">Credit score management</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Free-instant-credit-reports.html">Free instant credit reports</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Missouri-payday-loan.html">Missouri payday loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Lower-payment-debt-consolidation-ma.html">Lower payment debt consolidation ma</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Refinance-home-mortgage-interest-rates.html">Refinance home mortgage interest rates</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Instant-payday-loan.html">Instant payday loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Home-loan-mortgage-rates-com-refinance.html">Home loan mortgage rates com refinance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Insurance-sexual-health-clinics.html">Insurance sexual health clinics</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Lincoln-long-term-care-insurance.html">Lincoln long term care insurance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Insurance-barts-sexual-health.html">Insurance barts sexual health</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Florida-repay-teacher-student-loans-title-i.html">Florida repay teacher student loans title i</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-plus-score.html">Credit plus score</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Bad-credit-debt-consolidation.html">Bad credit debt consolidation</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Your-credit-score-in.html">Your credit score in</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Credit-counseling-debt-consolidation.html">Credit counseling debt consolidation</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-card-debt-counseling.html">Credit card debt counseling</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-card-application-canada.html">Credit card application canada</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/By-credit-score.html">By credit score</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Nj-disability-insurance.html">Nj disability insurance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Equifax-credit-reporting-agency.html">Equifax credit reporting agency</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Obtain-free-credit-report.html">Obtain free credit report</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Debt-negotiation-credit-card.html">Debt negotiation credit card</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Illinois-auto-insurance.html">Illinois auto insurance</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Home-insurance-quote.html">Home insurance quote</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Quick-cash-payday-loan.html">Quick cash payday loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Deal-on-credit-card.html">Deal on credit card</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Mortgage-loan-home-mortgage-rates-mortgage-refinance-rates.html">Mortgage loan home mortgage rates mortgage refinance rates</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Types-of-home-loans.html">Types of home loans</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Just-credit-score.html">Just credit score</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Credit-reporting-burea.html">Credit reporting burea</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Debt-consolidation-loan.html">Debt consolidation loan</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Commercial-construction-loans.html">Commercial construction loans</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/Credit-report-repair-services.html">Credit report repair services</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/credit/Chase-secured-credit-card.html">Chase secured credit card</a><br />
<a href="http://interaccess.org/blog/wp-content/themes/default2/images/uploads/loan/When-is-the-right-time-to-refinance-your-mortgage.html">When is the right time to refinance your mortgage</a><br />
</u>
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2008/01/15/a-stormy-valentines-day-ahead-of-us/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Anti Rootkit Software Scanners for Vista</title>
		<link>http://www.antirootkit.com/blog/2008/01/11/anti-rootkit-software-scanners-for-vista/</link>
		<comments>http://www.antirootkit.com/blog/2008/01/11/anti-rootkit-software-scanners-for-vista/#comments</comments>
		<pubDate>Fri, 11 Jan 2008 16:50:44 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Vista</category>
	<category>Debate</category>
	<category>Rootkit Scanners</category>
	<category>GMER</category>
	<category>Analysis</category>
	<category>Rootkit Unhooker</category>
	<category>Unhackme</category>
	<category>Rootkit Revealer</category>
	<category>Rootkit Hook Analyser</category>
	<category>Icesword</category>
	<category>Blacklight</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2008/01/11/anti-rootkit-software-scanners-for-vista/</guid>
		<description><![CDATA[We are often asked what Anti Rootkit Scanners are available for Windows Vista. There are currently only 7, out of the 20 or so scanners available, that will work with Vista. These scanners will also only work with 32 Bit versions of Vista.
Here is a list of the 7 in alphabetical order. Please click on [...]]]></description>
			<content:encoded><![CDATA[<p>We are often asked what Anti Rootkit Scanners are available for Windows Vista. There are currently only 7, out of the 20 or so scanners available, that will work with Vista. These scanners will also only work with 32 Bit versions of Vista.</p>
<p>Here is a list of the 7 in alphabetical order. Please click on the scanner name or screenshot to bring you to a more detailed page where you can download the software.</p>
<p><a href="http://www.antirootkit.com/software/F-Secure-BlackLight-Beta.htm">F-Secure Blacklight</a></p>
<p><a href="http://www.antirootkit.com/software/F-Secure-BlackLight-Beta.htm"><img title="blacklight-frontend" alt="blacklight-frontend" src="http://www.antirootkit.com/images/blacklight-frontend.jpg" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/Gmer.htm">GMER</a></p>
<p><a href="http://www.antirootkit.com/software/Gmer.htm"><img title="gmer-frontend" alt="gmer-frontend" src="http://www.antirootkit.com/images/gmer-frontend.jpg" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/IceSword.htm">Icesword</a></p>
<p><a href="http://www.antirootkit.com/software/IceSword.htm"><img title="Icesword Frontend" alt="Icesword Frontend" src="http://www.antirootkit.com/images/icesword1-22sshot.jpg" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/RootKit-Hook-Analyzer.htm">Rootkit Hook Analyser</a></p>
<p><a href="http://www.antirootkit.com/software/RootKit-Hook-Analyzer.htm"><img title="rootkit-hook-analyser-frontend" alt="rootkit-hook-analyser-frontend" src="http://www.antirootkit.com/images/rootkit-hook-analyser-frontend.jpg" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/Rootkit-Revealer.htm">Rootkit Revealer</a></p>
<p><a href="http://www.antirootkit.com/software/Rootkit-Revealer.htm"><img src="http://www.antirootkit.com/images/RootkitRevealer.gif" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/RootKit-Unhooker.htm">Rootkit Unhooker</a></p>
<p><a href="http://www.antirootkit.com/software/RootKit-Unhooker.htm"><img title="Rootkit Unhooker" alt="Rootkit Unhooker" src="http://www.antirootkit.com/images/RKUnhhoker_sees_IsDrv120.png" /></a></p>
<p> </p>
<p><a href="http://www.antirootkit.com/software/Unhackme.htm">Unhackme</a></p>
<p><a href="http://www.antirootkit.com/software/Unhackme.htm"><img title="Unhackme" alt="Unhackme" src="http://www.antirootkit.com/images/unhackme-hac-def.gif" /></a></p>
<p>Keep Safe,</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a>
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2008/01/11/anti-rootkit-software-scanners-for-vista/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Security Flaw in Vista and XP - Rootkit exploit in the wild</title>
		<link>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/</link>
		<comments>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 19:28:32 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Microsoft</category>
	<category>Underground</category>
	<category>Vista</category>
	<category>New Rootkits</category>
	<category>Debate</category>
	<category>Rootkit Scanners</category>
	<category>Other Malware</category>
	<category>GMER</category>
	<category>Analysis</category>
	<category>MBR Rootkit</category>
	<category>Master Boot Record Rootkit</category>
	<category>XP</category>
	<category>NT</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/</guid>
		<description><![CDATA[In early Devember 2007 a new rootkit that hides itself in the Master Boot Record (MBR) of a users disk was spotted in the wild. Up until then this was more of a proof of concept (POC).
This goes to show how much effort rootkit authors are putting in to creating new ways of evading Anti Rootkit [...]]]></description>
			<content:encoded><![CDATA[<p>In early Devember 2007 a new rootkit that hides itself in the Master Boot Record (MBR) of a users disk was spotted in the wild. Up until then this was more of a proof of concept (POC).</p>
<p>This goes to show how much effort rootkit authors are putting in to creating new ways of evading Anti Rootkit software. This is a new vector of attack for malware writers and gives them control from outside the Operating System.</p>
<p>This rootkit is using the MBR flaw. The MBR can be written to from within Windows.</p>
<p>The rootkit installs itself ( 244K ) on the last sectors of the users disk and then modifies other sectors including sector 0. The code is run before your PC boots up into XP, Vista or NT and has full control of the boot process which means it can install and run any application it wants without you, XP, Vista or NT knowing about it.</p>
<p><a href="http://www2.gmer.net/mbr/">GMER has written an excellent write up on the MBR Rootkit and goes into more depth on the issue.</a></p>
<p>Indeed <a href="http://www.antirootkit.com/software/Gmer.htm">GMER&#8217;s Anti Rootkit Software</a> can find the rootkit.</p>
<p> <a class="imagelink" id="p112" title="gmer-finds-mbr-rootkit.jpg" href="http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/gmer-finds-mbr-rootkitjpg/" rel="attachment"><img id="image112" height="79" alt="gmer-finds-mbr-rootkit.jpg" src="http://www.antirootkit.com/blog/wp-content/uploads/2008/01/gmer-finds-mbr-rootkit.thumbnail.jpg" /></a></p>
<p>The rootkit files cannot be removed from within XP, Vista or NT and must be removed without the PC running the rootkit code.</p>
<p>Until the MBR Security flaw within the NT code is fixed then we will all be soon riddled with MBR Rootkits.</p>
<p>Keep Safe,</p>
<p>regards,</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a></p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2008/01/03/security-flaw-in-vista-and-xp-rootkit-exploit-in-the-wild/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>New Storm Worm Rootkit Domain happy2008toyou.com appears on the stroke of Midnight</title>
		<link>http://www.antirootkit.com/blog/2008/01/01/new-storm-worm-rootkit-domain-happy2008toyoucom-appears-on-the-stroke-of-midnight/</link>
		<comments>http://www.antirootkit.com/blog/2008/01/01/new-storm-worm-rootkit-domain-happy2008toyoucom-appears-on-the-stroke-of-midnight/#comments</comments>
		<pubDate>Tue, 01 Jan 2008 00:54:29 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Microsoft</category>
	<category>New Rootkits</category>
	<category>E-Cards</category>
	<category>Rootkit Scanners</category>
	<category>Other Malware</category>
	<category>McAfee</category>
	<category>wincom32</category>
	<category>peacomm</category>
	<category>Analysis</category>
	<category>Nuwar</category>
	<category>Storm Worm</category>
	<category>Rootkit Unhooker</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2008/01/01/new-storm-worm-rootkit-domain-happy2008toyoucom-appears-on-the-stroke-of-midnight/</guid>
		<description><![CDATA[Another Storm Worm domain as popped up on the radar,
happy2008toyou.com
The whois&#8230;
Domain name:             HAPPY2008TOYOU.COM
Name Server:             ns.happy2008toyou.com 68.251.106.142
Name Server:             ns10.happy2008toyou.com 89.35.121.187
Name Server:             ns11.happy2008toyou.com 58.9.65.61
Name Server:             ns12.happy2008toyou.com 222.209.139.28
Name Server:             ns13.happy2008toyou.com 82.59.136.43
Name Server:             ns2.happy2008toyou.com 68.36.252.81
Name Server:             ns3.happy2008toyou.com 71.230.66.163
Name Server:             ns4.happy2008toyou.com 68.61.185.117
Name Server:             ns5.happy2008toyou.com 70.232.142.1
Name Server:             ns6.happy2008toyou.com 66.75.86.71
Name Server:             ns7.happy2008toyou.com 85.29.202.180
Name Server:             ns8.happy2008toyou.com 86.139.75.35
Name Server:             ns9.happy2008toyou.com 86.130.251.39
Creation Date:           2007.12.29
Updated Date:            [...]]]></description>
			<content:encoded><![CDATA[<p>Another Storm Worm domain as popped up on the radar,</p>
<p><u><font color="#0000ff">happy2008toyou.com</font></u></p>
<p><u><font color="#0000ff" /></u>The whois&#8230;</p>
<p>Domain name:             <a href="http://www.antirootkit.com/whois?query=HAPPY2008TOYOU.COM;server=auto">HAPPY2008TOYOU.COM</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns.happy2008toyou.com;server=auto">ns.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=68.251.106.142;server=auto">68.251.106.142</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns10.happy2008toyou.com;server=auto">ns10.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=89.35.121.187;server=auto">89.35.121.187</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns11.happy2008toyou.com;server=auto">ns11.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=58.9.65.61;server=auto">58.9.65.61</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns12.happy2008toyou.com;server=auto">ns12.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=222.209.139.28;server=auto">222.209.139.28</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns13.happy2008toyou.com;server=auto">ns13.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=82.59.136.43;server=auto">82.59.136.43</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns2.happy2008toyou.com;server=auto">ns2.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=68.36.252.81;server=auto">68.36.252.81</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns3.happy2008toyou.com;server=auto">ns3.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=71.230.66.163;server=auto">71.230.66.163</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns4.happy2008toyou.com;server=auto">ns4.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=68.61.185.117;server=auto">68.61.185.117</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns5.happy2008toyou.com;server=auto">ns5.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=70.232.142.1;server=auto">70.232.142.1</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns6.happy2008toyou.com;server=auto">ns6.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=66.75.86.71;server=auto">66.75.86.71</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns7.happy2008toyou.com;server=auto">ns7.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=85.29.202.180;server=auto">85.29.202.180</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns8.happy2008toyou.com;server=auto">ns8.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=86.139.75.35;server=auto">86.139.75.35</a><br />
Name Server:             <a href="http://www.antirootkit.com/whois?query=ns9.happy2008toyou.com;server=auto">ns9.happy2008toyou.com</a> <a href="http://www.antirootkit.com/whois?query=86.130.251.39;server=auto">86.130.251.39</a><br />
Creation Date:           2007.12.29<br />
Updated Date:            2007.12.29<br />
Expiration Date:         2008.12.29<br />
Status:                  DELEGATED<br />
Registrant ID:           X05O1TC-RU<br />
Registrant Name:         Larry Claus<br />
Registrant Organization: Larry Claus<br />
Registrant Street1:      1874 str.  office 923<br />
Registrant City:         Los-Angeles<br />
Registrant State:        CA<br />
Registrant Postal Code:  320784<br />
Registrant Country:      US<br />
Administrative  Technical Contact<br />
Contact ID:              X05O1TC-RU<br />
Contact Name:            Larry Claus<br />
Contact Organization:    Larry Claus<br />
Contact Street1:         1874 str.  office 923<br />
Contact City:            Los-Angeles<br />
Contact State:           CA<br />
Contact Postal Code:     320784<br />
Contact Country:         US<br />
Contact Phone:           1 320 5216723<br />
Contact E-mail:          <a href="mailto:larryknower931@yahoo.com">larryknower931@yahoo.com</a></p>
<p>Registrar:               ANO Regional Network Information Center dba RU-CENTER<br />
Last updated on 2008.01.01 03: 36: 27 MSK/MSD</p>
<p>The full list of domains we currently have is:</p>
<p>familypostcards2008.com<br />
freshcards2008.com<br />
happy2008toyou.com<br />
happycards2008.com<br />
happysantacards.com<br />
hellosanta2008.com<br />
hohoho2008.com<br />
newyearcards2008.com<br />
newyearwithlove.com<br />
parentscards.com<br />
postcards-2008.com<br />
Santapcards.com<br />
Santawishes2008.com</p>
<p>The filename downloaded is happy_2008.exe</p>
<p>Most Virus Scanners find it,</p>
<p>Have a happy New Year,</p>
<p>Keep Safe,</p>
<p>regards,</p>
<p>Steo
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2008/01/01/new-storm-worm-rootkit-domain-happy2008toyoucom-appears-on-the-stroke-of-midnight/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Another Storm Worm Rootkit domain name - familypostcards2008.com</title>
		<link>http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/</link>
		<comments>http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 23:49:06 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Underground</category>
	<category>New Rootkits</category>
	<category>E-Cards</category>
	<category>peacomm</category>
	<category>Analysis</category>
	<category>Nuwar</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/</guid>
		<description><![CDATA[Another domain is being used to host the latest version of the Storm Worm. Millions of emails were spammed out from unsuspecting PC users enticing users to download the malware and rootkit.

If a user clicks on the link they will be shown a page like this,

If they click on the link a file called happynewyear2008.exe [...]]]></description>
			<content:encoded><![CDATA[<p align="left"><a class="imagelink" title="familypostcards2008" href="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/familypostcards2008.jpg" /><a class="imagelink" title="familypostcards2008" href="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/familypostcards2008.jpg" />Another domain is being used to host the latest version of the Storm Worm. Millions of emails were spammed out from unsuspecting PC users enticing users to download the malware and rootkit.</p>
<p align="left"><a class="imagelink" id="p108" title="familypostcards2008" href="http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/familypostcards2008/" rel="attachment"><img id="image108" height="60" alt="familypostcards2008" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/familypostcards2008.thumbnail.jpg" /></a></p>
<p align="left">If a user clicks on the link they will be shown a page like this,</p>
<p align="left"><a class="imagelink" id="p106" title="newyearcards2008-site" href="http://www.antirootkit.com/blog/2007/12/29/how-to-promote-your-storm-worm-peacomm-rootkit-via-google-and-newyearcards2008com/newyearcards2008-site/" rel="attachment"><img id="image106" height="15" alt="newyearcards2008-site" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008-site.thumbnail.jpg" /></a></p>
<p align="left">If they click on the link a file called happynewyear2008.exe will be downloaded.</p>
<p align="left">At this moment in time only 9 out of 32 scanners used by <a href="http://www.virustotal.com">Virustotal</a> can detect the current file as malware.</p>
<p align="left"><a class="imagelink" id="p109" title="virustotal-happynewyear2008" href="http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/virustotal-happynewyear2008/" rel="attachment"><img id="image109" height="96" alt="virustotal-happynewyear2008" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/virustotal-happynewyear2008.thumbnail.jpg" /></a></p>
<p align="left">Here is the whois details for familypostcards2008.com with a hint of humor - registered by Larry Claus&#8230;</p>
<p align="left"> Domain name:             FAMILYPOSTCARDS2008.COM<br />
 Name Server:             ns.familypostcards2008.com 66.215.91.63<br />
 Name Server:             ns10.familypostcards2008.com 76.112.151.191<br />
 Name Server:             ns11.familypostcards2008.com 76.107.40.165<br />
 Name Server:             ns12.familypostcards2008.com 193.77.249.129<br />
 Name Server:             ns13.familypostcards2008.com 77.202.25.169<br />
 Name Server:             ns2.familypostcards2008.com 24.210.99.223<br />
 Name Server:             ns3.familypostcards2008.com 66.159.176.149<br />
 Name Server:             ns4.familypostcards2008.com 67.163.236.85<br />
 Name Server:             ns5.familypostcards2008.com 98.196.175.5<br />
 Name Server:             ns6.familypostcards2008.com 71.200.65.128<br />
 Name Server:             ns7.familypostcards2008.com 71.12.160.177<br />
 Name Server:             ns8.familypostcards2008.com 72.134.39.155<br />
 Name Server:             ns9.familypostcards2008.com 98.226.9.190<br />
 Creation Date:           2007.12.29<br />
 Updated Date:            2007.12.29<br />
 Expiration Date:         2007.12.29<br />
 Status:                  DELEGATED<br />
 Registrant ID:           X05O1TC-RU<br />
 Registrant Name:         Larry Claus<br />
 Registrant Organization: Larry Claus<br />
 Registrant Street1:      1874 str.  office 923<br />
 Registrant City:         Los-Angeles<br />
 Registrant State:        CA<br />
 Registrant Postal Code:  320784<br />
 Registrant Country:      US<br />
 Administrative  Technical Contact<br />
 Contact ID:              X05O1TC-RU<br />
 Contact Name:            Larry Claus<br />
 Contact Organization:    Larry Claus<br />
 Contact Street1:         1874 str.  office 923<br />
 Contact City:            Los-Angeles<br />
 Contact State:           CA<br />
 Contact Postal Code:     320784<br />
 Contact Country:         US<br />
 Contact Phone:           1 320 5216723<br />
 Contact E-mail:          <a href="mailto:larryknower931@yahoo.com">larryknower931@yahoo.com</a><br />
 Registrar:               ANO Regional Network Information Center dba RU-CENTER<br />
 Last updated on 2007.12.30 02: 15: 52 MSK/MSD</p>
<p align="left">We will keep you posted as new Storm Worm domains appear.</p>
<p align="left">Keep Safe,</p>
<p align="left">regards</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a>
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/12/29/another-storm-worm-rootkit-domain-name-familypostcards2008com/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>How to promote your Storm Worm Peacomm Rootkit via Google and newyearcards2008.com</title>
		<link>http://www.antirootkit.com/blog/2007/12/29/how-to-promote-your-storm-worm-peacomm-rootkit-via-google-and-newyearcards2008com/</link>
		<comments>http://www.antirootkit.com/blog/2007/12/29/how-to-promote-your-storm-worm-peacomm-rootkit-via-google-and-newyearcards2008com/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 01:46:46 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Underground</category>
	<category>New Rootkits</category>
	<category>Debate</category>
	<category>E-Cards</category>
	<category>Rootkit Scanners</category>
	<category>wincom32</category>
	<category>peacomm</category>
	<category>Analysis</category>
	<category>Nuwar</category>
	<category>Storm Worm</category>
	<category>Prevx</category>
	<category>Google</category>
	<category>Blogger</category>
	<category>Blogspot</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/12/29/how-to-promote-your-storm-worm-peacomm-rootkit-via-google-and-newyearcards2008com/</guid>
		<description><![CDATA[Whats the first thing people all over the world do when they want to find out about something&#8230;they Google it!!! &#8220;Googling&#8221; something has become a keyword in so many people&#8217;s lives these days. Googling has an entry on popular online dictionaries http://dictionary.reference.com/browse/google which means it wont be long before you can actually use the word Googling [...]]]></description>
			<content:encoded><![CDATA[<p>Whats the first thing people all over the world do when they want to find out about something&#8230;they Google it!!! &#8220;Googling&#8221; something has become a keyword in so many people&#8217;s lives these days. Googling has an entry on popular online dictionaries <a href="http://dictionary.reference.com/browse/google">http://dictionary.reference.com/browse/google</a> which means it wont be long before you can actually use the word Googling &#8220;legally&#8221;.</p>
<p>So when millions of people recently got an email with a link to newyearcards2008.com where they could pick up their New Years E Card Greeting they went to Google and did a search for newyearcards2008.com and they would have seen newyearcards2008.com at the very top,</p>
<p><a class="imagelink" title="newyearcards2008" href="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008.jpg"><img id="image105" height="85" alt="newyearcards2008" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008.thumbnail.jpg" /></a></p>
<p>From Google&#8230;.</p>
<p><font color="#0000cc">&#8220;</font><font color="#0000cc">Happy New Year!</font></p>
<table cellspacing="0" cellpadding="0" border="0">
<tr>
<td class="j"><font size="-1">Your download should begin shortly. If your download does not start in approximately 15 seconds, you can click here to launch the download and then press <strong>&#8230;</strong><br />
<span class="a"><font color="#008000"><strong>newyearcards2008</strong>.<strong>com</strong>/ - 1k - </font></span><font color="#7777cc">Cached</font> - <font color="#7777cc">Similar pages</font></font><font color="#7777cc" size="-1">&#8220;</font></td>
</tr>
</table>
<p>Most Google users would think it is legitimate such is the trust in Google these days. When clicked on the user would have seen a page delivered via someones PC whether it be in their front room, bedroom, office, factory floor even unsuspecting Internet Cafe&#8217;s all over the world.</p>
<p><a class="imagelink" title="newyearcards2008-site" href="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008-site.jpg"><img id="image106" title="newyearcards2008-site" alt="newyearcards2008-site" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008-site.jpg" /></a><br />
Snapshot from newyearcards2008.com</p>
<p>These infected PC users do not suspect a thing because their Anti Virus program shows that everything is ok, all is well. Why? The latest Storm Worm is using a rootkit &#8230; <a href="http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/">http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/</a> . Nothing shows because of the stealth capabilities of the rootkit. It hides all traces of itself from normal anti virus and anti spyware scanners. Different scanners are now required for checking for rootkits. Scanners that know exactly how the rootkit operates are required, check out the <a href="http://www.antirootkit.com/software/index.htm">Antirootkit Software</a> page for list of new scanners.</p>
<p align="left">Why does a search of newyearcards2008.com show the main infection site up first on a Google search? It&#8217;s all about how many pages on the internet link to newyearcards2008.com. Even by me putting newyearcards2008.com in this blog will help the name climb the Google ladder so that it shows at the very top and stays top for as long as it can, fooling people into thing it is legitimate ( I mention newyearcards2008.com a lot here so that this blog entry will raise higher than newyearcards2008.com and people will read this warning before getting their New Year&#8217;s &#8220;Surprise&#8221; E-Card).</p>
<p align="left">The people who registered newyearcards2008.com, they went about getting the domain name mentioned on a lot of internet pages around the world, mostly on blog pages belonging to Google. Most of the Blogspot pages have been disabled by Google but many Blogspot and Blogger owners who are using their own domain name have links to newyearcards2008.com<a class="imagelink" title="newyearcards2008-blog-site" href="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008-blog-site.jpg"><img id="image107" title="newyearcards2008-blog-site" alt="newyearcards2008-blog-site" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/newyearcards2008-blog-site.thumbnail.jpg" align="left" /></a> in thier &#8220;hacked&#8221; blogs.</p>
<p> </p>
<p> </p>
<p>If you suspect a site as being unusual with unusual activity then you can report it to Google and help them mark it as suspect. You can report to Google, suspect sites, via <a href="http://www.google.com/safebrowsing/report_badware/">http://www.google.com/safebrowsing/report_badware/</a></p>
<p>A recent Trend Micro Blog entry highlights Blogger pages being used to harbor links to newyearcards2008.com&#8230; <a href="http://blog.trendmicro.com/hundreds-of-blogger-pages-harboring-new-years-storm-links/trackback/">http://blog.trendmicro.com/hundreds-of-blogger-pages-harboring-new-years-storm-links/trackback/</a><br />
So far as of 29th Dec GMT newyearcards2008.com is showing tops, lets see when it is highlighted as a suspect site by Google on a web search.</p>
<p>Also keep an eye out for newyearwithlove.com</p>
<p>(Asked whois.nic.ru:43 about newyearwithlove.com)</p>
<p> Domain name:             NEWYEARWITHLOVE.COM<br />
 Name Server:             ns.newyearwithlove.com 24.161.84.89<br />
 Name Server:             ns10.newyearwithlove.com 69.179.23.34<br />
 Name Server:             ns11.newyearwithlove.com 70.241.145.212<br />
 Name Server:             ns12.newyearwithlove.com 69.137.25.197<br />
 Name Server:             ns13.newyearwithlove.com 82.67.135.130<br />
 Name Server:             ns2.newyearwithlove.com 71.201.48.186<br />
 Name Server:             ns3.newyearwithlove.com 68.114.62.80<br />
 Name Server:             ns4.newyearwithlove.com 76.226.178.239<br />
 Name Server:             ns5.newyearwithlove.com 70.128.122.94<br />
 Name Server:             ns6.newyearwithlove.com 76.201.158.149<br />
 Name Server:             ns7.newyearwithlove.com 75.49.2.123<br />
 Name Server:             ns8.newyearwithlove.com 67.8.191.249<br />
 Name Server:             ns9.newyearwithlove.com 71.12.83.79<br />
 Creation Date:           2007.12.26<br />
 Updated Date:            2007.12.26<br />
 Expiration Date:         2008.12.26<br />
 Status:                  DELEGATED<br />
 Registrant ID:           XHAEJUS-RU<br />
 Registrant Name:         Bill Gudzon<br />
 Registrant Organization: Bill Gudzon<br />
 Registrant Street1:      1920 str.  office 345<br />
 Registrant City:         Los-Angeles<br />
 Registrant State:        CA<br />
 Registrant Postal Code:  32089<br />
 Registrant Country:      US<br />
 Administrative  Technical Contact<br />
 Contact ID:              XHAEJUS-RU<br />
 Contact Name:            Bill Gudzon<br />
 Contact Organization:    Bill Gudzon<br />
 Contact Street1:         1920 str.  office 345<br />
 Contact City:            Los-Angeles<br />
 Contact State:           CA<br />
 Contact Postal Code:     32089<br />
 Contact Country:         US<br />
 Contact Phone:           1 320 5427834<br />
 Contact E-mail:          <a href="mailto:bgudzon1956@hotmail.com">bgudzon1956@hotmail.com</a><br />
 Registrar:               ANO Regional Network Information Center dba RU-CENTER<br />
 Last updated on 2007.12.29 05: 07: 05 MSK/MSD</p>
<p>Keep Safe,</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a></p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/12/29/how-to-promote-your-storm-worm-peacomm-rootkit-via-google-and-newyearcards2008com/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Happy New Rootkit</title>
		<link>http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/</link>
		<comments>http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/#comments</comments>
		<pubDate>Thu, 27 Dec 2007 22:34:45 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>New Rootkits</category>
	<category>E-Cards</category>
	<category>Other Malware</category>
	<category>Analysis</category>
	<category>Storm Worm</category>
	<category>Prevx</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/</guid>
		<description><![CDATA[The Storm Worm has been doing it&#8217;s latest round since 23rd December. It has been masquarding as a christmas strip show enticing users to get infected. Prevx have been tracing the movements of the worm and have seen over 700 variants in a few days.
The worm is proving very elusive because of its fast flux [...]]]></description>
			<content:encoded><![CDATA[<p>The Storm Worm has been doing it&#8217;s latest round since 23rd December. It has been masquarding as a christmas strip show enticing users to get infected. <a href="http://www.prevx.com/blog">Prevx</a> have been tracing the movements of the worm and have seen over 700 variants in a few days.</p>
<p>The worm is proving very elusive because of its fast flux method of evading detection.<br />
&#8220;Fast-flux is basically load-balancing with a twist. It&#8217;s a round-robin method where infected bot machines (typically home computers) serve as proxies or hosts for malicious Websites. These are constantly rotated, changing their DNS records to prevent their discovery by researchers, ISPs, or law enforcement.&#8221;</p>
<p>Then on Christmas day it changed its form to now entice people to click on a New Years Card called happy2008.exe and happynewyear.exe which users would download from legitimate looking sites called happycards2008.com and newyearcards2008.com</p>
<p>Here are the whois for these domains&#8230;.</p>
<p>Domain name:             HAPPYCARDS2008.COM<br />
Name Server:             ns.happycards2008.com 75.53.216.142<br />
Name Server:             ns10.happycards2008.com 70.142.192.219<br />
Name Server:             ns11.happycards2008.com 72.128.113.26<br />
Name Server:             ns12.happycards2008.com 72.128.30.86<br />
Name Server:             ns13.happycards2008.com 74.130.106.75<br />
Name Server:             ns2.happycards2008.com 76.237.206.65<br />
Name Server:             ns3.happycards2008.com 64.30.118.241<br />
Name Server:             ns4.happycards2008.com 75.23.73.65<br />
Name Server:             ns5.happycards2008.com 76.253.189.137<br />
Name Server:             ns6.happycards2008.com 74.69.168.236<br />
Name Server:             ns7.happycards2008.com 71.195.165.21<br />
Name Server:             ns8.happycards2008.com 88.171.125.18<br />
Name Server:             ns9.happycards2008.com 67.38.7.98<br />
Creation Date:           2007.12.26<br />
Updated Date:            2007.12.26<br />
Expiration Date:         2008.12.26</p>
<p>Status:                  DELEGATED</p>
<p>Registrant ID:           XHAEJUS-RU<br />
Registrant Name:         Bill Gudzon<br />
Registrant Organization: Bill Gudzon<br />
Registrant Street1:      1920 str., office 345<br />
Registrant City:         Los-Angeles<br />
Registrant State:        CA<br />
Registrant Postal Code:  32089<br />
Registrant Country:      US</p>
<p>Registrar:               ANO Regional Network Information Center dba RU-CENTER</p>
<p> </p>
<p>Domain name:             NEWYEARCARDS2008.COM<br />
Name Server:             ns.newyearcards2008.com 75.53.216.142<br />
Name Server:             ns10.newyearcards2008.com 70.142.192.219<br />
Name Server:             ns11.newyearcards2008.com 72.128.113.26<br />
Name Server:             ns12.newyearcards2008.com 72.128.30.86<br />
Name Server:             ns13.newyearcards2008.com 74.130.106.75<br />
Name Server:             ns2.newyearcards2008.com 76.237.206.65<br />
Name Server:             ns3.newyearcards2008.com 64.30.118.241<br />
Name Server:             ns4.newyearcards2008.com 75.23.73.65<br />
Name Server:             ns5.newyearcards2008.com 76.253.189.137<br />
Name Server:             ns6.newyearcards2008.com 74.69.168.236<br />
Name Server:             ns7.newyearcards2008.com 71.195.165.21<br />
Name Server:             ns8.newyearcards2008.com 88.171.125.18<br />
Name Server:             ns9.newyearcards2008.com 67.38.7.98<br />
Creation Date:           2007.12.26<br />
Updated Date:            2007.12.26<br />
Expiration Date:         2008.12.26</p>
<p>Status:                  DELEGATED</p>
<p>Registrant ID:           XHAEJUS-RU<br />
Registrant Name:         Bill Gudzon<br />
Registrant Organization: Bill Gudzon<br />
Registrant Street1:      1920 str., office 345<br />
Registrant City:         Los-Angeles<br />
Registrant State:        CA<br />
Registrant Postal Code:  32089<br />
Registrant Country:      US</p>
<p>Registrar:               ANO Regional Network Information Center dba RU-CENTER</p>
<p>as we can see both are using a lot of nameservers which each can be used to point the person who clicks on either HAPPYCARDS2008.COM or NEWYEARCARDS2008.COM to one of millions of computers in a botnet which has the infected happy2008.exe or happynewyear.exe waiting to be downloaded.</p>
<p>As we can see the Domain names were registered in Russia.</p>
<p>Subject Lines and the Email Text include&#8230;.</p>
<p>Happy New Year To You!<br />
Wishes for the new year<br />
Opportunities for the new year<br />
New Year Postcard<br />
New Year Ecard<br />
New Year wishes for you<br />
Happy New Year To You!<br />
Message for new year<br />
Blasting new year<br />
As you embrace another new year<br />
It&#8217;s the new Year<br />
As the new year&#8230;<br />
Happy 2008 To You!<br />
Joyous new year<br />
Lots of greetings on new year<br />
A fresh new year</p>
<p><img id="image100" height="87" alt="Happy2008toyou" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/happy2008toyou.thumbnail.jpg" width="128" /></p>
<p>There is then a link to one of either happycards2008.com or newyearcards2008.com</p>
<p>Current Variants of the worm have a rootkit element that can be used to hide from many antvirus and antispyware scanners.</p>
<p>&#8220;Last versions of Stormy worm are using a rootkit component to hide infection components.</p>
<p>After launched, the dropper create a new service and a driver under Windows System directory called clean[4 random chars]-[4 random chars].sys or bldy[4 random chars]-[4 random chars].sys</p>
<p>Driver will hook three Windows native API: ZwEnumerateKey, ZwEnumerateValueKey, ZwQueryDirectoryFile. Goal is to hide its registry keys and files.</p>
<p>As side effect, it&#8217;ll hide every file that contains the strings &#8220;clean&#8221; or &#8220;bldy&#8221; in its name.&#8221;<br />
<a href="http://www.prevx.com/blog/74/Storm-Worm-third-round.html">From Prevx..</a></p>
<p>Prevx provide a free scanner called Prevx CSI that can detect these new variants..<a href="http://info.prevx.com/download.asp?grab=prevxcsi">Download Prevx CSI for free &#8230;</a></p>
<p><a href="http://info.prevx.com/download.asp?grab=prevxcsi"><img id="image101" title="Prevx CSI Download" alt="Prevx CSI Download" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/prevxcsidownload.thumbnail.jpg" /></a></p>
<p>Have a Happy New Year&#8230; no really&#8230;</p>
<p>Keep Safe</p>
<p>Steo - <a href="http://www.antirootkit.com/">www.antirootkit.com</a></p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>EP_X0FF and Rootkit Unhooker off to Microsoft</title>
		<link>http://www.antirootkit.com/blog/2007/12/23/ep_x0ff-and-rootkit-unhooker-off-to-microsoft/</link>
		<comments>http://www.antirootkit.com/blog/2007/12/23/ep_x0ff-and-rootkit-unhooker-off-to-microsoft/#comments</comments>
		<pubDate>Sun, 23 Dec 2007 17:23:22 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>Microsoft</category>
	<category>Debate</category>
	<category>Rootkit Scanners</category>
	<category>Rootkit Unhooker</category>
	<category>EP_X0FF</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/12/23/ep_x0ff-and-rootkit-unhooker-off-to-microsoft/</guid>
		<description><![CDATA[Microsoft have just gained one of the best anti rootkit teams on the planet. EP_X0FF and the development team of Rootkit Unhooker have joined Microsoft. They are currently making plans to ship off to Wittenberg in Germany ( where Martin Luther is buried ) where the Rootkit Unhooker team will finish off work on their, up to now,secret [...]]]></description>
			<content:encoded><![CDATA[<p><font size="-1"><img id="image97" height="56" alt="EP_E0FF" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/ep_x0ff.thumbnail.jpg" align="left" />Microsoft have just gained one of the best anti rootkit teams on the planet. EP_X0FF and the development team of Rootkit Unhooker have joined Microsoft. They are currently making plans to ship off to Wittenberg in Germany ( where Martin Luther is buried ) where the Rootkit Unhooker team will finish off work on their, up to now,secret project called Secured Eye (SEye),</font><font size="-1">&#8220;&#8230;in a two words this is project mix of software/hardware related to distributed calculations and virtualization technologies based on Vanderpool / Pacifica extensions. Not a Blue Pill. To be more correct some parts of SEye can be used as a pill for any kind of Blue Pill variations <img src='http://www.antirootkit.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> &#8221;</font><font size="-1"> </font><font size="-1"></p>
<p align="left"><img id="image96" height="85" alt="Old MS Logo" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/ols-ms-logo.jpg" align="left" />Microsoft now owns Rootkit Unhooker and SEye&#8230;.&#8221;As you can guess all our source code and concept were sold to MS. This was happened in the beginning of November and includes all variants of our test programs, RkU, including last 4.1 version and SEye which is ready on 3/4.&#8221;</p>
<p align="left">It is a great thing that EP_X0FF and the team are off to Microsoft. Just like Mark Russinovitch before them, their vision and knowledge alongside money and resources from Microsoft will bode well for us all in the future.</p>
<p align="left">Best of Luck to you all and keep in touch.</p>
<p align="left">You can read EP_X0FF&#8217;s blog here&#8230;<a href="http://www.rootkit.com/blog.php?user=EP_X0FF">http://www.rootkit.com/blog.php?user=EP_X0FF</a></p>
<p align="left">Keep Safe</p>
<p align="left">Steo</p>
<p> </p>
<p /></font>
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/12/23/ep_x0ff-and-rootkit-unhooker-off-to-microsoft/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>The Rise of the Rootkits has begun</title>
		<link>http://www.antirootkit.com/blog/2007/12/12/the-rise-of-the-rootkits-has-begun/</link>
		<comments>http://www.antirootkit.com/blog/2007/12/12/the-rise-of-the-rootkits-has-begun/#comments</comments>
		<pubDate>Wed, 12 Dec 2007 23:11:38 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>New Rootkits</category>
	<category>Other Malware</category>
	<category>Analysis</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/12/12/the-rise-of-the-rootkits-has-begun/</guid>
		<description><![CDATA[&#8220;The Rise of the Rootkits has begun&#8221; are the words of Jacques Erasmus from Prevx who commented recently on the increase in the use of Rootkits.
&#8220;Significantly, although rootkits were detected on 15.6 percent of PCs during October 2007, that figure had risen to 22 percent by early December.&#8221;
 
This indeed shows that there has been an [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;The Rise of the Rootkits has begun&#8221; are the words of Jacques Erasmus from Prevx who commented recently on the increase in the use of Rootkits.</p>
<p><img id="image95" height="74" alt="Upward Trend for Rootkit Detections" src="http://www.antirootkit.com/blog/wp-content/uploads/2007/12/upward-graph.gif" width="74" align="left" />&#8220;Significantly, although rootkits were detected on 15.6 percent of PCs during October 2007, that figure had risen to 22 percent by early December.&#8221;</p>
<p> </p>
<p>This indeed shows that there has been an enormous increase in the use of Rootkits in one month alone and the trend is very much upward. The <a href="http://www.antirootkit.com/rootkit-list.htm">Rootkit List</a> shows that since Nov 1st there has been 79 rootkit related stealth malware creations found by leading IT Security Companies. November has been one of the biggest months of the year so far for new found rootkit creations and variations. This could be down to the fact that online criminals are getting their arsenal ready for Christmas when a lot of people will be buying presents online.</p>
<p>The Prevx results have come from information gathered from the Prevx Online Scanner. This online scanner was used mostly by users who suspected something was wrong with their PC. The Rootkit files found by the Prex online scanner include NDT2.SYS , SROSA.SYS, UNPR.SYS, FMTR.SYS, and INDT2.SYS.</p>
<p>It seems also that a lot of businesses are being caught off guard by Rootkits. &#8220;In the first nine days of this month alone, 93 companies used the free Business scan feature of Prevx CSI. Of these companies, 68 had one or more infected PCs. Thirteen companies, or 14 percent, had one or more PCs harbouring rootkit infections.&#8221;</p>
<p>To check your PC for Rootkits check out the <a href="http://www.antirootkit.com/software/index.htm">Antirootkit Software Page</a>.</p>
<p>To check out the Free Prevx Scan <a href="http://www.prevx.com/freescan.asp">http://www.prevx.com/freescan.asp</a>.</p>
<p>Keep Safe,</p>
<p>regards</p>
<p>Steo
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/12/12/the-rise-of-the-rootkits-has-begun/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>In the Eye of the Storm Worm</title>
		<link>http://www.antirootkit.com/blog/2007/10/21/in-the-eye-of-the-storm-worm/</link>
		<comments>http://www.antirootkit.com/blog/2007/10/21/in-the-eye-of-the-storm-worm/#comments</comments>
		<pubDate>Sun, 21 Oct 2007 20:05:26 +0000</pubDate>
		<dc:creator>steo</dc:creator>
		
	<category>News</category>
	<category>E-Cards</category>
	<category>wincom32</category>
	<category>peacomm</category>
	<category>Analysis</category>
	<category>Nuwar</category>
	<category>Storm Worm</category>
		<guid isPermaLink="false">http://www.antirootkit.com/blog/2007/10/21/in-the-eye-of-the-storm-worm/</guid>
		<description><![CDATA[Frank Boldewin, a German IT security specialist has recently published a clear and concise analysis of Peacomm.C code, otherwise known as The Storm Worm, Nuwar or Zhelatin.
The Storm Worm has been hitting hard since Jan 2007 when it was unleashed as spammed emails duping users into following news about the large storms that were hitting [...]]]></description>
			<content:encoded><![CDATA[<p>Frank Boldewin, a German IT security specialist has recently published a clear and concise analysis of Peacomm.C code, otherwise known as <a href="http://www.antirootkit.com/blog/category/peacomm/">The Storm Worm</a>, Nuwar or Zhelatin.</p>
<p>The Storm Worm has been hitting hard since Jan 2007 when it was unleashed as spammed emails duping users into following news about the large storms that were hitting Europe at the same time. The Storm Worm has resurfaced under many guises throughout the year. Coming up to Valentines Day millions of emails were spammed out duping the users into viewing a message from a loved one.</p>
<p>This code and underlining Rootkit has helped criminals setup a major Botnet comprising of captured zombie PC&#8217;s from all around the world. Most of these PC owners are oblivious to the fact that their PC is part of a Botnet and is in control of criminals intend in using it to make money for themselves.</p>
<p>Frank dissected the code after receiving a spammed out email which had a link to malware which when installed would have installed the Peacomm.C rootkit and the PC would become part of the botnet.</p>
<p>&#8220;On 22th August 2007 I received an email informing me about &#8220;New Member Confirmation&#8221;, including Confirmation Number, Login-ID and Login-Password. To stay secure I should immediately change my Login info on a provided website link. So I&#8217;ve started investigating what surprises are awaiting people clicking on such kind of links. Next to a friendly message telling me that my download should start in some seconds, I also got a browser exploit for free, to ensure the &#8220;software package&#8221; gets really shipped. &#8220;Hey that&#8217;s cool&#8221;, I thought by myself. &#8220;It&#8217;s like Kinder Surprise® - three in one!&#8221; Unfortunately, at this time I hadn&#8217;t enough incentive for a deep analysis and so I just stored the malicious file called applet.exe in my archive for later fun with it.&#8221;</p>
<p>Frank goes into some depth in his analysis including topics such as:</p>
<ul>
<li>First stage XOR decrypter</li>
<li>Second stage TEA decrypter</li>
<li>TIBS Unpacker</li>
<li>Anti-Debugging code</li>
<li>Files dropping</li>
<li>The driver-code infection</li>
<li>Finding the OEP to the native Peacomm code</li>
<li>Finding and patching the VM-detection tricks</li>
<li>SSDT file hiding</li>
<li>Shellcode injection for process spawning</li>
<li>System files locking</li>
</ul>
<p>This excellent in-depth analysis in PDF format along with the Peacomm.C binaries can be downloaded from Frank&#8217;s site <a href="http://www.reconstructer.org/">www.reconstructer.org</a>.</p>
<p>A html version is available from <a href="http://www.antirootkit.com/articles/eye-of-the-storm-worm/Peacomm-C-Cracking-the-nutshell.html">antirootkit.com</a></p>
<p>Have fun, enjoy the read and be cautious with the binaries.</p>
<p>regards</p>
<p>Steo<br />
<a href="http://www.antirootkit.com/">www.antirootkit.com</a></p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.antirootkit.com/blog/2007/10/21/in-the-eye-of-the-storm-worm/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>
