Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

July 6th, 2007, 11:03 GMT · By

Crimea Virus Hacks the Windows Operating System

SHARE:

Adjust text size:



Enlarge picture
W32/Crimea is a virus that reinvents hacking the Windows File Protection via an undocumented feature of the mitigation Microsoft set up in order to protect critical Windows system files. McAfee Avert Labs revealed that Crimea does not take the traditional approach to circumventing the Windows File Protection but that instead, the malware makes use of one of Microsoft's own application programming interfaces in order to compromise the operating system. Under normal conditions, only Microsoft can alter, edit, replace or delete critical system files from the Windows
Operating System via Windows Service Pack (Update.exe); hotfixes installed using Hotfix.exe; operating system upgrades using Winnt32.exe and Windows Update. Traditional approaches to taking down the Windows File Protection involved patching SFC.dll and SFC_OS.dll.

"Malware authors have found an alternate method with help of undocumented functions in SFC_OS.dll itself. The SetSfcFileException function disables the WFP for a particular file for one minute normally. This is the time needed by the malware to do their work successfully!!! Now the system is back in form but is infected by the malware. Even though these techniques were out for more than a year, we are seeing these techniques used by malware these days," revealed McAfee Avert Labs describing the method implemented by Crimea to compromise system file imm32.dll and to infect the whole computer.

McAfee claims that the malware authors have turned Microsoft's own tools against the Windows platform. Through the SFC_OS.dll function, Crimea will infect Windows system DLL file imm32.dll and make it load additional malicious content by altering the import routine.

"One might start thinking, why in the world should Microsoft provide such APIs in Windows that makes the operating system vulnerable to many malware. One of the reasons could be to update system files and install the patches. But it does provide a way for the malware to infect the system easily. Fate it seems, Microsoft is providing a way to disable their own protection using their own APIs," McAfee Avert Labs added.
FILED UNDER:
Windows
W32/Crimea
WFP
McAfee

TELL US WHAT YOU THINK:

3,400 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


McAfee Finds Windows Live OneCare... Amusing

Windows Vista Hardcore Fan Names Newborn Girl... Vista

Windows Vista Multilingual User Interface

Windows Vista Hardware Assessment Tool Available

Windows Vista Service Pack 1 - So What?

READER COMMENTS:


Comment #1 by: vishwas7777@gmail.com on 31 Dec 2011, 06:45 UTC reply to this comment

if we make this dll file readonly then the problem occurs or not

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM