Hi malware fighters,
What about the latest developments coming from the Virtumonde authors?
The latest trick they use is file infection to make removal even more difficult. Coming from one of the most notoriously to remove malware, we were not expecting less. They use all the tricks i the book:
notice the differende between trial.exe and trial. exe?!
"Like some other malware this version of Virtumonde enumerates which files are being run at Windows startup. It will check the files and if deemed OK for infection it will start the infection routine.
What Virtumonde is basically doing is creating a Trojan-Dropper. It will drop the original host file into %temp% and start the file from there. Next to that it will drop the Virtumonde component into the system directory.
The dropped DLL in the system directory will do its Virtumonde-tricks as well as look for files to infect(from startup). So, this is not a patcher. This is a virus.
About 4KB of dropper code is prepended in front of the host file. The Virtumonde DLL gets appended to the host file. The DLL is about 32KB large, but the exact size of appended code may vary. It also makes use of an infection marker in the resource section to make sure it does not reinfect the same file time and time again.
The original host file sits unaltered inside the newly created exe which makes disinfection quite easy.
Something tells me that their next attempt is going to be more tricky to handle. Info - KAV"
polonus