Webroot Threat Blog – Internet Security Threat Updates from Around the World

WEBROOT – INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS

Menu

Skip to content
  • Products
  • Support
  • Community & Resources
  • Partners
  • About Webroot
  • About the Bloggers

Tag Archives: Batserv

Malware Load Points Raise the Complexity Bar

Posted on June 9, 2011 by glhaldeman

By Andrew Brandt

Add to FacebookAdd to DiggAdd to Del.icio.usAdd to StumbleuponAdd to RedditAdd to BlinklistAdd to TwitterAdd to TechnoratiAdd to Yahoo BuzzAdd to Newsvine

When malware ends up on an infected machine, one of the first things it will do is to ensure that it will start up again after the victim reboots their computer. For a criminal it makes sense. After all, what good is malware that stops working after a reboot?

In Windows, there are tons of ways for malware to accomplish this small but critical task, most of which involve the Registry. Technical folks call the Registry keys that are used for this purpose load points or auto-start locations. There’s even a pretty good free app from Microsoft that will show you everything configured to start itself up using any of these load points.

The Threat Research Analysts here use their knowledge of load points to fine-tune definitions. Increasingly, we have to kill a load point then reboot the computer to remove a piece of malware. I wanted to call attention to some odd load point trends, where load points are stacked like dominoes, so the action that starts the execution process is several steps removed from the actual execution.

Continue reading →

39.923932 -105.118490

Tell your friends:

  • Facebook
  • Twitter
  • Google +1
  • LinkedIn
  • Reddit
  • Email
  • More
  • Pinterest
  • Digg
  • StumbleUpon

Like this:

Like Loading...
Posted in Ad-clickers, Botnet activity, Firefox, hijack search results, Internet Explorer, Rogue Security Products, Search engines, Stupid malware tricks, Threat Research, Trojans | Tagged %appdata%, auto-start locations, Batserv, conima.exe, HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows, HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\software\classes\exefile\shell\open\command, HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\firefox.exe\shell\open\command, HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\iexplore.exe\shell\open\command, HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run, load points, Local Account Authority Service, LocalAccountAuthority.bat, lssas.exe, manager.exe, rogue antivirus, Rogue Security Products, Run Key, start points, Trojan-Clicker-Batserv, Windows auto-start locations, windows load points, Windows start points, Wireshark Antivirus | 4 Comments

Connect With Us

Enter your email address to subscribe to this blog and receive notifications of new posts by e-mail.

Join 772 other followers

Archives

Menu

  • Privacy Statement
  • Send Us Feedback
Blog at WordPress.com. | Theme: Customized Able by Automattic.
Follow

Get every new post delivered to your Inbox.

Join 772 other followers

Powered by WordPress.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.
%d bloggers like this: