« Spare the environment, spare yourself
You got a nice tie Mr Hacker »

Malware authors messing with SysInternals screensaver

July 14th, 2008

Malware authors seem to be having fun these days. They stole the BSOD screensaver from SysInternals and turned it into malware.

Note the message: “SYSINTERNALS_GREAT_SITE”

The screensaver is injected in two locations: the System32 folder, of course, as well as in the System Restore disk.

 

 SysInternals (now owned by Microsoft) has made some really great tools: Process Explorer, Rootkit Revealer just to name a few.

JSegura

    This entry was posted on Monday, July 14th, 2008 at 10:48 am and is filed under Malware Trends. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




Pages

  • About
  • Contact Us



Archives

  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Botnets (2)
  • Exploits (8)
  • Fake codecs (3)
  • IM threats (1)
  • Keyloggers (1)
  • Malware Trends (16)
  • Phishing (3)
  • Research (2)
  • Rogue software (18)
  • Rootkits (1)
  • Uncategorized (12)
  • Wireless Security (1)



 
 
 

© 2008 ParetoLogic Inc.