Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

December 17th, 2010, 08:04 GMT · By

Free Microsoft Security Solution Guns for Qakbot Backdoor

SHARE:

Adjust text size:


Security
Enlarge picture
Microsoft extended the capabilities of a free security solution it’s offering to all Windows users so that it can tackle the Win32/Qakbot family of backdoors.

Also known as Bzud, Qbot, and Pinkslipbot, Qakbot is a piece of malicious code with multiple malicious components designed to hand over access and control to an attacker once it has successfully infected a computer.

“Qakbot is composed of several components, including a keylogger, a password stealer and a user-mode rootkit.

“Qakbot is commonly distributed as the payload of what appear to be attacks, mainly targeted at enterprise installations,” revealed Dan Kurc and Aaron Putnam, from the Microsoft Malware Protection Center.

The latest version of the Windows Malicious Software Removal Tool is designed to detect and remove Qakbot from compromised computers.

As is the case with the previous releases, the most recent MSRT variant is offered automatically to Windows users worldwide.

With MSRT, the Redmond company is tackling a selection of malicious code as opposite to all malware, with the software giant adding new detections each month.

“Qakbot starts as a highly obfuscated JavaScript that downloads and runs an installer and user-mode rootkit,” Putnam explained.

“At this point, Qakbot is hidden from the user while it downloads the rest of the Qakbot package. Qakbot next gathers information and steals anything that it can find. This includes login and password, banking information, user keystrokes and information about the local infection.

“All of the gathered information is then encrypted into a custom log file, and uploaded to a remote server via FTP. In addition to all of these capabilities, the Qakbot family also has the ability to update itself to make sure that it's running a recent version of the malware.”

Users that are running genuine versions of Windows 7, Windows XP or Windows Vista can also download Microsoft Security Essentials free of charge from Microsoft.

Microsoft Security Essentials 1.0 is available for download here.

Microsoft Windows Malicious Software Removal Tool is available for download here.

TELL US WHAT YOU THINK:

1,171 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security Essentials 2011 Is Not Microsoft Security Essentials 2.0 or 1.0

Microsoft Security Essentials Served via Windows Update as an Optional Update

Free Windows 7 Setting Pack and Office 2010 Security Baseline – Download from Microsoft

New Microsoft Security Essentials 1.0 and 2.0 Releases

Office 2010 File Validation Security Feature Backported to Office 2007 and 2003

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM