<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Anti-Malware Engineering Team</title><link>http://blogs.technet.com/antimalware/default.aspx</link><description>This blog provides information about what's happening in the anti-malware technology team at Microsoft. We're the team that builds the core antivirus, antispyware, anti-rootkit, and related technology, which is then used across a number of Microsoft products and technologies.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>We have moved!</title><link>http://blogs.technet.com/antimalware/archive/2008/06/19/we-have-moved.aspx</link><pubDate>Fri, 20 Jun 2008 05:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3074764</guid><dc:creator>blogmalware</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/antimalware/comments/3074764.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=3074764</wfw:commentRss><description>&lt;P&gt;To ease navigation and be more in synch with our security colleagues within Microsoft, we have moved to a new blog address: &lt;A href="http://blogs.technet.com/mmpc"&gt;http://blogs.technet.com/mmpc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We hope you like the new look. Please remember to redirect any links to our new web address.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3074764" width="1" height="1"&gt;</description></item><item><title>When SQL Injections Go Awry, Incident Case Study</title><link>http://blogs.technet.com/antimalware/archive/2008/05/30/when-sql-injections-go-awry-incident-case-study.aspx</link><pubDate>Sat, 31 May 2008 04:37:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063951</guid><dc:creator>blogmalware</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/antimalware/comments/3063951.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=3063951</wfw:commentRss><description>&lt;div class="ExternalClass3C616A3D172D4A47870683FA9E436D75"&gt;   &lt;div class="ExternalClass250D619EB4B04B579423BF0B9E0CDDA5"&gt;     &lt;p&gt;It seems to be the &amp;quot;in-thing&amp;quot; these days - using an automated tool to perform SQL injections against vulnerable sites across multiple domains. Although the attack method isn't new, some sites are hit multiple times, as evident by a corruption of the injection code when one attacker overwrite a previously injected record. Below, you can see cached search results when searching for a specific known script injection:&lt;/p&gt;      &lt;p&gt;       &lt;br /&gt;&lt;a href="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_1_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="272" alt="image_1" src="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_1_thumb.png" width="533" border="0" /&gt;&lt;/a&gt;         &lt;br /&gt;&lt;em&gt;Image 1: Search results indicating embedded scripts - multiple attacks&lt;/em&gt;&lt;/p&gt;      &lt;p&gt;&lt;em&gt;         &lt;br /&gt;&lt;/em&gt;In the above highlighted portion, note the beginning of an original script tag injection being superimposed with another script tag injection. Below, you can see the effect of multiple attacks on another site and as evident in the page source:&lt;/p&gt;      &lt;p&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_2_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="70" alt="image_2" src="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_2_thumb.png" width="513" border="0" /&gt;&lt;/a&gt;         &lt;br /&gt;&lt;em&gt;Image 2: HTML source indicating multiple embedded script tags from various SQL injection attacks          &lt;br /&gt;&lt;/em&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;Speaking of SQL injections however, one has to wonder - what's all the hype? What are attackers after or what is their motive? It would seem that there are several motives, but one motive that may (or not) be surprising is the uprising in injecting code that executes multiple exploits in an attempt to download and execute game password stealers. Let me say that again - game password stealers. &lt;/p&gt;      &lt;p&gt;We continue to monitor injected scripts, and add detections to cover various iterations - the threats are detected as &amp;quot;&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H" target="_blank"&gt;Trojan:JS/Redirector&lt;/a&gt;&amp;quot;:&lt;/p&gt;      &lt;p&gt;       &lt;br /&gt;&lt;a href="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="285" alt="image" src="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_thumb.png" width="410" border="0" /&gt;&lt;/a&gt;         &lt;br /&gt;&lt;em&gt;Image 3: Microsoft Forefront Client (FCS) Security Warning alert&lt;/em&gt;         &lt;br /&gt;&lt;/p&gt;      &lt;p&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;Our friends over at ShadowServer have compiled a list of offending domains that are either compromised and don't know it, or are under control of an attacker and are hosting (or did host) malicious scripts or executables. Below is a list as of May 14 2008 of domains, courtesy of this link:        &lt;br /&gt;&lt;a title="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514" href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514"&gt;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514&lt;/a&gt;&lt;/p&gt;      &lt;table cellspacing="0" cellpadding="2" width="297" border="0"&gt;&lt;tbody&gt;         &lt;tr&gt;           &lt;td valign="top" width="163"&gt;             &lt;p&gt;&lt;font size="2"&gt;Domain&lt;/font&gt;&lt;/p&gt;              &lt;p&gt;&lt;font size="2"&gt;nihaorr1.com                  &lt;br /&gt;free.hostpinoy.info                   &lt;br /&gt;xprmn4u.info                   &lt;br /&gt;nmidahena.com                   &lt;br /&gt;winzipices.cn                   &lt;br /&gt;sb.5252.ws                   &lt;br /&gt;aspder.com                   &lt;br /&gt;11910.net                   &lt;br /&gt;bbs.jueduizuan.com                   &lt;br /&gt;bluell.cn                   &lt;br /&gt;2117966.net                   &lt;br /&gt;s.see9.us                   &lt;br /&gt;xvgaoke.cn                   &lt;br /&gt;1.hao929.cn                   &lt;br /&gt;414151.com                   &lt;br /&gt;cc.18dd.net                   &lt;br /&gt;yl18.net                   &lt;br /&gt;kisswow.com.cn                   &lt;br /&gt;urkb.net                   &lt;br /&gt;c.uc8010.com                   &lt;br /&gt;rnmb.net                   &lt;br /&gt;ririwow.cn                   &lt;br /&gt;killwow1.cn                   &lt;br /&gt;qiqigm.com                   &lt;br /&gt;wowgm1.cn                   &lt;br /&gt;wowyeye.cn                   &lt;br /&gt;9i5t.cn                   &lt;br /&gt;computershello.cn                   &lt;br /&gt;z008.net                   &lt;br /&gt;b15.3322.org                   &lt;br /&gt;direct84.com                   &lt;br /&gt;caocaowow.cn                   &lt;br /&gt;qiuxuegm.com                   &lt;br /&gt;firestnamestea.cn                   &lt;br /&gt;a.ka47.us                   &lt;br /&gt;a188.ws                   &lt;br /&gt;qiqi111.cn&lt;/font&gt;&lt;/p&gt;           &lt;/td&gt;            &lt;td valign="top" width="132"&gt;             &lt;p align="right"&gt;&lt;font size="2"&gt;Approximate # of                  &lt;br /&gt;Pages Injected                   &lt;br /&gt;&lt;/font&gt;&lt;font size="2"&gt;468,000                  &lt;br /&gt;444,000                   &lt;br /&gt;369,000                   &lt;br /&gt;140,000                   &lt;br /&gt;75,000                   &lt;br /&gt;69,000                   &lt;br /&gt;62,000                   &lt;br /&gt;47,000                   &lt;br /&gt;44,000                   &lt;br /&gt;44,000                   &lt;br /&gt;39,000                   &lt;br /&gt;39,000                   &lt;br /&gt;33,000                   &lt;br /&gt;20,000                   &lt;br /&gt;17,000                   &lt;br /&gt;15,000                   &lt;br /&gt;15,000                   &lt;br /&gt;13,000                   &lt;br /&gt;13,000                   &lt;br /&gt;9500                   &lt;br /&gt;7000                   &lt;br /&gt;6000                   &lt;br /&gt;4000                   &lt;br /&gt;3600                   &lt;br /&gt;3500                   &lt;br /&gt;2800                   &lt;br /&gt;2500                   &lt;br /&gt;2300                   &lt;br /&gt;1600                   &lt;br /&gt;1200                   &lt;br /&gt;1100                   &lt;br /&gt;900                   &lt;br /&gt;800                   &lt;br /&gt;700                   &lt;br /&gt;600                   &lt;br /&gt;500                   &lt;br /&gt;230&lt;/font&gt;&lt;/p&gt;           &lt;/td&gt;         &lt;/tr&gt;       &lt;/tbody&gt;&lt;/table&gt;      &lt;p&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;I was reviewing the 'qiqi111.cn' attack and learned that the malicious script requested files from these domains: 'pigzd.cn' and 'dota11.cn'. I decided to follow the white rabbit, taking the first domain and I began to retrieve the malicious script 'am6.htm' (identified already as &amp;quot;Exploit:JS/Repl.B&amp;quot;).&lt;/p&gt;      &lt;p&gt;The script 'am6.htm' contains a handful of attack methods, attempting exploits to download and execute more code:        &lt;br /&gt;&lt;/p&gt;      &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_4_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="528" alt="image_4" src="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/WhenSQLInjectionsGoAwry_10476/image_4_thumb.png" width="666" border="0" /&gt;&lt;/a&gt;&amp;#160;&amp;#160; &lt;br /&gt;&lt;em&gt;Image 4: Source code of 'am6.htm' illustrating the attack methods          &lt;br /&gt;          &lt;br /&gt;&lt;/em&gt;&lt;/p&gt;      &lt;p&gt;       &lt;br /&gt;I know what you're saying, &amp;quot;what the heck, what are all these iframes?&amp;quot;, so let's take a quick look at them:&lt;/p&gt;      &lt;ol&gt;       &lt;li&gt;This attack focuses on systems that have not applied &lt;strong&gt;Microsoft Security Bulletin MS06-014&lt;/strong&gt;. The attack specifically targets a Microsoft Data Access Components (MDAC) ADO ActiveX Control &amp;quot;RDS.DataSpace&amp;quot; in order to execute arbitrary code, or in this case, another Web hosted script - identified as &amp;quot;&lt;em&gt;&lt;strong&gt;TrojanDownloader:JS/Psyme.BA&lt;/strong&gt;&lt;/em&gt;&amp;quot; - it tries to retrieve and execute an online game password stealer as a file named &amp;quot;mm.exe&amp;quot; (from the domain 'gf.ccves.cn')           &lt;br /&gt;&lt;/li&gt;        &lt;li&gt;This attack executes the ActiveX control for RealPlayer - this method also allows execution of code - identified as &amp;quot;&lt;em&gt;&lt;strong&gt;Exploit:HTML/Repl.D&lt;/strong&gt;&lt;/em&gt;&amp;quot;           &lt;br /&gt;&lt;/li&gt;        &lt;li&gt;This attack exploits a &lt;strong&gt;0 day vulnerability&lt;/strong&gt; in an Avatar ActiveX control for Ourgame GLWorld named &amp;quot;C:\Program Files\GlobalLink\Game\Share\GLAvatar.ocx&amp;quot; and referenced by its control &amp;quot;GLAVATAR.GLAvatarCtrl.1&amp;quot; - when the ActiveX control executes, it loads a script that contains a vulnerability against another ActiveX Control contained in 'GLIEDown2.dll', a library component of GLWorld; there isn't yet a CVE (Common Vulnerabilities) ID for this vulnerability, thus it's considered &amp;quot;0 day&amp;quot;. &lt;a href="http://www.securityfocus.com/bid/29118/info" target="_blank"&gt;It was issued a Bugtraq ID 29118&lt;/a&gt;, and as of the time of this writing there, public awareness of the vulnerability seems somewhat low, and not well discussed other than this blog entry, &lt;a href="http://blog.trendmicro.com/chinese-weekend-compromise/" target="_blank"&gt;and one from Trend Micro&lt;/a&gt; - the HTML file 'axlz.htm' is identified as &amp;quot;&lt;em&gt;&lt;strong&gt;Exploit:JS/Gdow.A&lt;/strong&gt;&lt;/em&gt;&amp;quot;           &lt;br /&gt;          &lt;br /&gt;Incidentally, there are other known exploits components of GLWorld (&lt;a href="http://www.ourgame.com/"&gt;www.ourgame.com&lt;/a&gt;):           &lt;br /&gt;* &lt;a href="http://www.frsirt.com/english/advisories/2008/0427" target="_blank"&gt;Multiple Buffer Overflow Vulnerabilities within &amp;quot;HanGamePluginCn18.dll&amp;quot;&lt;/a&gt; referenced by this control:           &lt;br /&gt;HanGamePluginCn18.HanGamePluginCn18.1           &lt;br /&gt;          &lt;br /&gt;* &lt;a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5722" target="_blank"&gt;Stack-based Buffer Overflow Vulnerability within &amp;quot;GLChat.ocx&amp;quot;&lt;/a&gt; referenced by this control:           &lt;br /&gt;GLCHAT.GLChatCtrl.1           &lt;br /&gt;          &lt;br /&gt;* &lt;a href="http://www.securityfocus.com/bid/29118" target="_blank"&gt;Ourgame 'GLIEDown2.dll' ActiveX Control Remote Code Execution Vulnerability&lt;/a&gt; referenced by this control:           &lt;br /&gt;GLIEDown.GLIEDown.1           &lt;br /&gt;&lt;/li&gt;        &lt;li&gt;This attack exploits a vulnerability in Baofeng Storm StormPlayer ActiveX control - identified as &amp;quot;&lt;em&gt;&lt;strong&gt;Exploit:Win32/Senglot.J&lt;/strong&gt;&lt;/em&gt;&amp;quot;           &lt;br /&gt;&lt;/li&gt;        &lt;li&gt;This last method is an attack against an ActiveX control for Xunlei Thunder DapPlayer - this file was not available at the time of this writing &lt;/li&gt;     &lt;/ol&gt;      &lt;p&gt;So with five opportunistic attacks, the odds increase in favor of acquiring some Internet nasties and we will continue to monitor these attacks.&lt;/p&gt;      &lt;h5&gt;Additional Resources&lt;/h5&gt;      &lt;p&gt;During our research, we analyzed some of the malicious scripts. More details about these scripts are available at our Microsoft Malware Protection Center Encyclopedia:        &lt;br /&gt;&lt;a title="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H" href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H&lt;/a&gt;         &lt;br /&gt;&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.I"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.I&lt;/a&gt;         &lt;br /&gt;&lt;a title="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H" href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.J"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.J&lt;/a&gt;         &lt;br /&gt;&lt;a title="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.H" href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.K"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.K&lt;/a&gt;         &lt;br /&gt;&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.L"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.L&lt;/a&gt;         &lt;br /&gt;&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.M"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.M&lt;/a&gt;         &lt;br /&gt;&lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.N"&gt;http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan:JS/Redirector.N&lt;/a&gt; &lt;/p&gt;      &lt;p&gt;       &lt;br /&gt;Additional resources and recommendations are available from the Security Vulnerability Research &amp;amp; Defense team: &lt;a href="http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx"&gt;http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx&lt;/a&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;       &lt;br /&gt;and from Bala Neerumalla, Microsoft Corporation, who discusses common coding mistakes in ASP code that can lead to SQL Injections in the following article:&amp;#160; &lt;a href="http://msdn.microsoft.com/en-us/library/cc676512.aspx"&gt;http://msdn.microsoft.com/en-us/library/cc676512.aspx&lt;/a&gt;&lt;/p&gt;      &lt;p&gt;&amp;#160;&lt;/p&gt;      &lt;p&gt;&amp;#160;&lt;em&gt;-- Patrick Nolan&lt;/em&gt;&lt;/p&gt;   &lt;/div&gt; &lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3063951" width="1" height="1"&gt;</description></item><item><title>Oderoor - all it's Kraked up to be?</title><link>http://blogs.technet.com/antimalware/archive/2008/05/21/oderoor-all-its-kraked-up-to-be.aspx</link><pubDate>Thu, 22 May 2008 06:12:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3058999</guid><dc:creator>blogmalware</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/antimalware/comments/3058999.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=3058999</wfw:commentRss><description>&lt;p&gt;Greetings from (sorta) sunny Melbourne, Australia! We&amp;#8217;re the newest addition to Microsoft&amp;#8217;s Security Research and Response global team. In arbitrary seating order we have: Jakub Kaminski, Scott Molenkamp, Hamish O&amp;#8217;Dea, Heather Goudey, Raymond Roberts, David Wood, Chun Feng, Oleg Petrovsky, Hermineh Tchagatzbanian, Hil Gradascevic and Matt McCormack. In the same order we have: Skinny Latte w/ 1, Espresso, Skinny Latte w/1, Skinny Latte w/1, Latte w/1, Hot Chocolate, Latte, Cappuccino, Cappuccino and Latte. Try carrying all those coffees at once &amp;#8211; it&amp;#8217;s not easy. &lt;/p&gt;  &lt;p&gt;After our inclusion of the Win32/Nuwar (alias Storm) family last September (&lt;a href="http://blogs.technet.com/antimalware/archive/2007/09/20/storm-drain.aspx" target="_blank"&gt;http://blogs.technet.com/antimalware/archive/2007/09/20/storm-drain.aspx&lt;/a&gt;) and the dent we put in the Win32/Cutwail (alias Pandex) network in January this year, we thought we&amp;#8217;d continue the anti-spam motif by targeting the Win32/Oderoor (ominously dubbed &amp;#8216;Kraken&amp;#8217;) network. Research shows botnets with cooler names are way scarier. &lt;/p&gt;  &lt;p&gt;&amp;#8220;Spam networks you say?&amp;#8221; &amp;#8220;Why spam networks?&amp;#8221; &amp;#8211; Oh, convenient question random person! Glad you asked! In our recently published Security Intelligence Report (&lt;a href="http://www.microsoft.com/security/portal/sir.aspx"&gt;http://www.microsoft.com/security/portal/sir.aspx&lt;/a&gt; *) it was found that around 96% of inbound messages to Exchange Hosted Services were blocked because they had spam on them. Spam all &lt;i&gt;over&lt;/i&gt; them. The SIR also found that approximately 80% of all spam that (tries to) go through Hotmail is from a botnet of some sort. I know it&amp;#8217;s hard to believe, but those are &lt;i&gt;graphs&lt;/i&gt; and &lt;i&gt;charts&lt;/i&gt; people. Graphs with &lt;i&gt;bars&lt;/i&gt;. Bars of &lt;i&gt;truth&lt;/i&gt;. Research shows that statistics never lie. &lt;/p&gt;  &lt;p&gt;Since the bad guys aren&amp;#8217;t paying for the hardware or bandwidth, they can send spam to their hearts content. All that&amp;#8217;s needed is one in every few billion emails to fool someone into buying the pills (which don&amp;#8217;t work by the way...) or giving up their bank account details (some nice man from Nigeria emailed them personally!) to make it a worthwhile industry. &lt;/p&gt;  &lt;p&gt;In case you weren&amp;#8217;t aware, the always interesting Joe Stewart over at SecureWorks recently published a list of the top spam botnets (&lt;a href="http://secureworks.com/research/threats/topbotnets/"&gt;http://secureworks.com/research/threats/topbotnets/&lt;/a&gt;). As is to be expected our old friends Nuwar and Cutwail were there, along with &lt;b&gt;&lt;i&gt;THE KRAKEN&lt;/i&gt;&lt;/b&gt;. Joe&amp;#8217;s estimate was that the size of the network was around 185,000 nodes, and spewing around 9 billion emails per day. Research shows that 9 billion emails is, in fact, a large number of emails. There was some contention over at the Damballa (http://www.damballa.com ) camp, who thought the network was more like 400,000 nodes strong. Either way, that is a lot of infected machines. &lt;/p&gt;  &lt;p&gt;Being the helpful lads they are, the guys over at DVlabs (&lt;a href="http://dvlabs.tippingpoint.com/"&gt;http://dvlabs.tippingpoint.com/&lt;/a&gt;) thought they&amp;#8217;d get to the bottom of the &amp;#8216;Mystery of the Disappearing Botnet Nodes&amp;#8217; and take a peek at the network from the inside (&lt;a href="http://dvlabs.tippingpoint.com/blog/2008/04/28/kraken-botnet-infiltration"&gt;http://dvlabs.tippingpoint.com/blog/2008/04/28/kraken-botnet-infiltration&lt;/a&gt;). Whilst this doesn&amp;#8217;t really help us with the number estimate, they did manage to obtain 65,000 unique infected IP addresses, so now we only have to account for the other missing 125,000-335,000 nodes. With so many nodes around you&amp;#8217;d figure people would be tripping over them all over the place. Sadly not. :( &lt;/p&gt;  &lt;p&gt;When we first identified Oderoor as a distinct family back in September 2007, links to the bots were being spammed through IM and the files themselves were encrypted to the wazoo (well, they still are doing both of those things). It didn&amp;#8217;t take long for us to get a hold of the situation, but for the most part vendor detection remained very low. For months afterwards, we were one of the few vendors to be detecting new variants as they came in (turns out we had got samples from as far back as May that year, however the encryption was fairly rudimentary). As is to be expected, the family shone brightly on our radar and was being considered for MSRT inclusion at around the time that Joe published his article. So it all worked out rather nicely :). &lt;/p&gt;  &lt;p&gt;Finally, our perspective on the Win32/Oderoor botnet; what MSRT has found. The numbers tend to go up and down, so I&amp;#8217;ve included the first week wrap-up. Extrapolating (since we know how these things tend to pan out), we can probably expect in the order of 300k distinct machines this month that were cleaned of Oderoor. &lt;/p&gt;  &lt;div align="center"&gt;   &lt;table class="MsoNormalTable" style="margin-left: -21.85pt; width: 226.3pt; border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" cellspacing="0" cellpadding="0" width="302" border="0"&gt;&lt;tbody&gt;       &lt;tr style="height: 15pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;         &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 226.3pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-alt: solid windowtext 1.0pt; mso-border-bottom-alt: solid windowtext .5pt" valign="bottom" nowrap="nowrap" width="302" colspan="3"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; text-align: right" align="right"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Win32/Oderoor MSRT removals-first week                  &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr style="height: 15pt; mso-yfti-irow: 1"&gt;         &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/td&gt;          &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Detections &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="92"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Machines &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr style="height: 15pt; mso-yfti-irow: 2"&gt;         &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Total: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;463619 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="92"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;254073 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr style="height: 15.75pt; mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;         &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15.75pt; mso-border-bottom-alt: solid windowtext 1.0pt; mso-border-left-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext .5pt" valign="bottom" nowrap="nowrap" width="115"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Average/Day: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15.75pt" valign="bottom" nowrap="nowrap" width="94"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;66231 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15.75pt" valign="bottom" nowrap="nowrap" width="92"&gt;           &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;36296 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;            &lt;p&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/div&gt;  &lt;div align="center"&gt;&amp;#160;&lt;/div&gt;  &lt;p&gt;So our size estimate is somewhere in the middle of the SecureWorks and Damballa numbers. Of course &lt;i&gt;our&lt;/i&gt; numbers are not the definitive answer. Whilst we run on 500 million machines and can get a pretty good idea of what&amp;#8217;s going on, there are still a lot of machines out there that aren&amp;#8217;t running MSRT; possibly because they don&amp;#8217;t have automatic updates turned on.**&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;Question: How do these numbers compare to &amp;#8216;Storm&amp;#8217; in the first few days? &lt;/p&gt;  &lt;p&gt;Answer: Pretty close :) &lt;/p&gt;  &lt;p&gt;If we take a look at the first week removal results from Nuwar, we can get an idea of the relative size of the network. The Cutwail removal numbers are included to complete the spam trio. I&amp;#8217;ve also included the graph because graphs are impressive.    &lt;br /&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="2" width="742" border="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="329"&gt;         &lt;table class="MsoNormalTable" style="margin-left: 6.75pt; width: 226.3pt; margin-right: 6.75pt; border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-table-overlap: never; mso-table-lspace: 9.0pt; mso-table-rspace: 9.0pt; mso-table-anchor-vertical: paragraph; mso-table-anchor-horizontal: column; mso-table-left: left; mso-table-top: .05pt" cellspacing="0" cellpadding="0" width="302" align="left" border="0"&gt;&lt;tbody&gt;             &lt;tr style="height: 15pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 226.3pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-alt: solid windowtext 1.0pt; mso-border-bottom-alt: solid windowtext .5pt" valign="bottom" nowrap="nowrap" width="302" colspan="3"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; text-align: right; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly" align="right"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Win32/Nuwar MSRT removals &amp;#8211; first week                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 1"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Detections                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Machines                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 2"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Total:                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;536581                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;319169                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Average:                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;76654                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: column; mso-element-top: .05pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;45596                        &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;           &lt;/tbody&gt;&lt;/table&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;br /&gt;          &lt;table class="MsoNormalTable" style="margin-left: 6.75pt; width: 226.3pt; margin-right: 6.75pt; border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-table-overlap: never; mso-table-lspace: 9.0pt; mso-table-rspace: 9.0pt; mso-table-anchor-vertical: paragraph; mso-table-anchor-horizontal: margin; mso-table-left: left; mso-table-top: 70.6pt" cellspacing="0" cellpadding="0" width="302" align="left" border="0"&gt;&lt;tbody&gt;             &lt;tr style="height: 15pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 226.3pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-alt: solid windowtext 1.0pt; mso-border-bottom-alt: solid windowtext .5pt" valign="bottom" nowrap="nowrap" width="302" colspan="3"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; text-align: right; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly" align="right"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Win32/Cutwail MSRT removals &amp;#8211; first week &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 1"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Detections &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Machines &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 2"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Total: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;213165 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;91290 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;              &lt;tr style="height: 15pt; mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;               &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 86.55pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: .5pt; mso-border-top-alt: 1.0pt; mso-border-left-alt: 1.0pt; mso-border-right-alt: .5pt; mso-border-color-alt: windowtext; mso-border-style-alt: solid" valign="bottom" nowrap="nowrap" width="115"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;Average: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: medium none; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 70.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="94"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;30452 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;                &lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: medium none; padding-left: 5.4pt; padding-bottom: 0in; border-left: medium none; width: 69.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext 1.0pt; mso-border-right-alt: solid windowtext 1.0pt" valign="bottom" nowrap="nowrap" width="93"&gt;                 &lt;p class="MsoNormal" style="margin-bottom: 0pt; line-height: normal; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-top: 70.6pt; mso-height-rule: exactly"&gt;&lt;span lang="EN-AU" style="color: black; mso-ascii-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-hansi-font-family: calibri; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-au"&gt;&lt;font size="2"&gt;13040 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;                  &lt;p&gt;&lt;/p&gt;               &lt;/td&gt;             &lt;/tr&gt;           &lt;/tbody&gt;&lt;/table&gt;          &lt;p&gt;&amp;#160;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="411"&gt;         &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/OderoorallitsKrakeduptobe_10D1D/image_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="221" alt="image" src="http://blogs.technet.com/blogfiles/antimalware/WindowsLiveWriter/OderoorallitsKrakeduptobe_10D1D/image_thumb.png" width="313" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;So it would appear the Win32/Oderoor network is slightly smaller that the Win32/Nuwar network &amp;#8211; around the 80% mark. It should be noted that the Nuwar numbers are a lower-bound (due to the way we detect them), so in reality it is likely slightly smaller again. The detections per machine are higher for Nuwar because there was/is more components than Oderoor&amp;#8217;s standalone executable. Speaking of the standalone executable - as tends to happen with these things, the Oderoor authors put out a new version the day after MSRT&amp;#8217;s release: Backdoor:Win32/Oderoor.gen!E. We love these games of cat and mouse. Vendor detection is still a bit sketchy.&lt;/p&gt;  &lt;p&gt;And how well did Oderoor fare with respect to the other families in MSRT this month? It made the top 4 which is &lt;i&gt;very&lt;/i&gt; impressive considering the other types of malware that are being targeted: &lt;/p&gt;  &lt;div align="left"&gt;   &lt;table cellspacing="0" cellpadding="2" width="199" align="center" border="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" align="center" width="77"&gt;&lt;font size="2"&gt;#1&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="120"&gt;&lt;font size="2"&gt;Win32/Zlob&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="75"&gt;&lt;font size="2"&gt;#2&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="122"&gt;&lt;font size="2"&gt;Win32/Vundo&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="74"&gt;&lt;font size="2"&gt;#3&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="123"&gt;&lt;font size="2"&gt;Win32/Renos&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="73"&gt;&lt;font size="2"&gt;#4&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="124"&gt;&lt;font size="2"&gt;&lt;em&gt;Win32/Oderoor&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="73"&gt;&lt;font size="2"&gt;#5&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="124"&gt;&lt;font size="2"&gt;Win32/Busky&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="73"&gt;&lt;font size="2"&gt;#6&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="124"&gt;&lt;font size="2"&gt;Win32/Rbot&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" align="center" width="73"&gt;&lt;font size="2"&gt;#7&lt;/font&gt;&lt;/td&gt;          &lt;td valign="top" align="center" width="126"&gt;&lt;font size="2"&gt;Win32/Cutwail&lt;/font&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/div&gt;  &lt;p&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;We&amp;#8217;re in contact with the guys over in DVLabs who are going to take a look at their data to see if they noticed a drop from inside the network after MSRT&amp;#8217;s release. We&amp;#8217;re eagerly awaiting a post on their blog (&lt;a href="http://dvlabs.tippingpoint.com/blog"&gt;http://dvlabs.tippingpoint.com/blog&lt;/a&gt;). &lt;/p&gt;  &lt;p&gt;So was that Kraken botnet all it was Kraked up to be? I think yes. If we look at hype vs MSRT results, this botnet received a lot less hype than Nuwar&amp;#8217;s network, but achieved pretty high infection numbers. If anything, it might even be understated. However hype is dependent on a botnet having something that makes it unique and interesting, such as Nuwar&amp;#8217;s distributed peer-to-peer architecture. Encrypted communications over port 447 are &lt;i&gt;ok&lt;/i&gt; but peer-to-peer is better I reckon. So perhaps it was just the right amount of hype. Juuuust right. &lt;/p&gt;  &lt;p&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;All Kraked out, &lt;/p&gt;  &lt;p&gt;Matt McCormack &lt;/p&gt;  &lt;p&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;* - watch the Bret and Vinny show while you&amp;#8217;re there. Vinny is our boss. He&amp;#8217;s alright. &lt;/p&gt;  &lt;p&gt;**- Seriously, running un-patched computers and being connected to the Internet is asking for trouble. It really is such a bad idea. It takes next to no time for an un-patched machine to get infected by some worm or another; this is one of the reasons we release MSRT to try and clean up the eco-system.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3058999" width="1" height="1"&gt;</description></item><item><title>Microsoft acquires Komoku</title><link>http://blogs.technet.com/antimalware/archive/2008/03/20/microsoft-acquires-komoku.aspx</link><pubDate>Thu, 20 Mar 2008 21:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3016672</guid><dc:creator>blogmalware</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/antimalware/comments/3016672.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=3016672</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Today, Microsoft announced the acquisition of Komoku to add to Forefront and Windows Live OneCare's technological capabilities.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I would like to take this opportunity to review the year since my "Hello World" blog post and again provide insight on where we will be going.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;A year ago, I noted our test results were "not stellar" :-). We were lacking VB100 certification, and independent test results placed us ten to fifteen points behind where we hoped to score.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I then promised that we were going to do our best to obtain the VB100 every time after. And while always concentrating on what was important—the malware most likely to affect our users—we brought our test scores on par with the rest of the industry. This year is going well, and we now have test results again to see how we delivered on those promises.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Virus Bulletin continues its bi-monthly VB100 Awards, and both Forefront and Windows Live OneCare have obtained VB100 Awards each time they were considered, five in total.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That is no simple task as many products, some sporting incredible streaks previously, managed to have that streak broken in that time.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We continue to maintain our certifications by ICSA Labs (www.icsalabs.com) and West Coast Labs (www.westcoastlabs.org).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Additionally, we now seek and obtain “Cleaning” certification.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That means malware removal is now also being certified.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;In the area of test scores, we attained the level where we are competitive in our detection rates.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;AV-Comparatives (www.av-comparatives.org), which had rated us a Fail with 82.4% last year, now rates our detection as Advanced at 93.9%.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;At the same time, AV-Test (www.av-test.org) shows our detection rate to be 97.8%. This is above most of the other products listed, including those we consider our peers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Last year, I had said, "You will see our results gradually and steadily increase until they are on par with the other majors in this arena.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And soon after, they will need to catch up to us!"&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I think we are somewhere between those two sentences.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;But, why the difference between the two scores?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Isn’t that a significant difference?&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;AV-Test used malware exclusively from the two months prior to its test.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;AV-Comparatives, on the other hand, used malware stemming up to three years past.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The higher detection of more recent malware highlights our dedication to protect our users from malware that they will more likely encounter.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Malware older than a year, or even six months, that hasn't been seen in that time, is not likely to be encountered again.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Malware writers are more keen to create new malware that none of the security products detect than to reuse old malware that some already detect.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This issue of meaningful testing is an area that the newly forming Anti-Malware Testing Standards Organization (AMTSO) seeks to address.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;So, are we “stellar” yet?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That would imply that we are satisfied with where we are.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, the obvious answer is that we will never feel satisfied.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;AV-Test.org tests more than just malware detection.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There are criteria where we still need to improve.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Among them are rootkit detection, generic/proactive capabilities and response time.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Response time is a component in how we support our users.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Now, with fully staffed Research Labs in &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:City w:st="on"&gt;Dublin&lt;/st1:City&gt; (headed by &lt;st1:PersonName w:st="on"&gt;Katrin Totcheva&lt;/st1:PersonName&gt;) and &lt;st1:City w:st="on"&gt;Melbourne&lt;/st1:City&gt; (headed by Jakub Kaminski) and beefing up &lt;st1:place w:st="on"&gt;&lt;st1:City w:st="on"&gt;Redmond&lt;/st1:City&gt;&lt;/st1:place&gt; with the addition of &lt;st1:PersonName w:st="on"&gt;Joe Hartmann&lt;/st1:PersonName&gt;, we are well suited to do our best to support our users.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;And now back to the acquisition of Komoku.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The addition of Komoku, especially its talented core of researchers, will add to our proactive capabilities in detecting zero-day vulnerabilities and improve rootkit detection.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We are very excited and hope soon to conquer these next challenges.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;-- Jimmy Kuo&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;For additional information visit: &lt;SPAN style="COLOR: #1f497d"&gt;&lt;A href="http://blogs.technet.com/forefront/archive/2008/03/20/microsoft-acquires-komoku.aspx"&gt;&lt;FONT color=#800080&gt;http://blogs.technet.com/forefront/archive/2008/03/20/microsoft-acquires-komoku.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3016672" width="1" height="1"&gt;</description></item><item><title>MBR rootkit: VirTool:WinNT/Sinowal.A report</title><link>http://blogs.technet.com/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx</link><pubDate>Fri, 11 Jan 2008 04:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2733817</guid><dc:creator>blogmalware</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/antimalware/comments/2733817.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=2733817</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;This week you may have heard or read about a new rootkit that has been reported in the wild that uses the Master Boot Record (MBR) as its Auto-Start Entry Point (ASEP).&amp;nbsp; The malware is being called &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.A" target=_blank mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.A"&gt;&lt;FONT face="Times New Roman" size=3&gt;VirTool:WinNT/Sinowal.A&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;.&amp;nbsp; First we want to let you know that if you use any of the Microsoft antivirus technologies (Windows Live OneCare, Forefront Client Security, Forefront Security for Exchange or Windows Live OneCare Safety Scanner), you are already protected from this threat as of definition version 5364.0 and higher.&amp;nbsp; Next, we want to talk about the use of the MBR as an ASEP by which to kick off the malware loading process and some of the interesting consequences of using this technique.&lt;SPAN lang=EN-AU style="mso-fareast-font-family: 'Arial Unicode MS'; mso-ansi-language: EN-AU"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;There are several binaries in the wild which try to install this rootkit. All the known variants are detected by Microsoft antimalware products using two generic signatures: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!C" target=_blank mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!C"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;PWS:Win32/Sinowal.gen!C&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT face="Times New Roman" size=3&gt; and &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!D" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!D"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;PWS:Win32/Sinowal.gen!D&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;This malware attempts to modify the MBR so that it can control what gets read from the disk into memory and execute very early in the boot process.&amp;nbsp; After the modified MBR is executed, it reads additional malicious code into memory which modifies the NT kernel to force it to load a malicious driver that has been stored at the end of the physical disk (The driver will not be visible while the infected OS is running.).&amp;nbsp; Once the driver is loaded into the kernel, it behaves just like a standard kernel mode rootkit, providing covert and stealth network backdoor functionality by hooking low level APIs to attempt to avoid detection.&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Here are some interesting things about this malware:&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;First, the installer for this rootkit needs to modify the MBR in order to ensure that the rootkit can persist across reboots.&amp;nbsp; It does this by using the CreateFile API attempting to open “\Device\Harddisk0\DR0” for write access.&amp;nbsp; Using the CreateFile API in this way (for direct / raw disk access) requires administrative privileges as mentioned in this KB article: &lt;/FONT&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;A href="http://support.microsoft.com/kb/q100027"&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-size: 12.0pt"&gt;&lt;SPAN style="mso-prop-change: 'Jimmy Kuo' 19000000T0000"&gt;http://support.microsoft.com/kb/q100027&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;.&amp;nbsp; So if you are logged into Windows as a standard user or if you are using Windows Vista with UAC enabled, even if you accidentally run the malware installer or it runs via some exploit code, it will be running with insufficient privilege to modify the hard disks MBR; thus it will not be able to persist a system restart.&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Next, the perceived strength of this new rootkit, its lack of a visible footprint in the registry and file system due to the use of the MBR as the ASEP, is also a big weakness!&amp;nbsp; If you suspect that you have a system that is infected with this rootkit, to prevent it from loading, all that is required is to write a known-good copy of a master boot record back to the disk to prevent the rootkit driver from being loaded on the next reboot!&amp;nbsp; Fortunately, we have made that a fairly painless process with the Windows Recovery Console and the ‘fixmbr’ command!&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Here are some instructions for using the Windows Recovery Console:&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Windows XP instructions: &lt;A href="http://support.microsoft.com/kb/314058"&gt;http://support.microsoft.com/kb/314058&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt; (just type ‘fixmbr’ in the console)&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Windows Vista instructions: &lt;A href="http://support.microsoft.com/kb/927392"&gt;http://support.microsoft.com/kb/927392&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt; (just type ‘bootrec.exe /fixmbr’ at the console)&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoCommentText style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face="Times New Roman"&gt;After restoring a known-good MBR to the hard drive, you should be able to start Windows and perform an on-line antivirus scan to detect and remove any of the malware components or any other malware that may have been installed on the system and hidden by the rootkit. You can use the Windows Live OneCare Safety Scanner at &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://safety.live.com/" mce_href="http://safety.live.com/"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face="Times New Roman"&gt;http://safety.live.com&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face="Times New Roman"&gt; to perform such a scan. It includes all the signatures for this malware.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;The main driver makes outbound HTTP connections to a particular hard-coded IP address or domain. We presume this is so that it can receive instructions and/or register with its overseer. It may also be able to receive instructions which allow it to act as an HTTP proxy, or to download and execute further malware. The malware makes similar connections to a number of domains which appear to be pseudo-randomly generated.&lt;SPAN lang=EN-AU style="mso-ansi-language: EN-AU"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;More information about this malware is available in our virus encyclopedia write ups:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;VirTool:WinNT/Sinowal.A: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.A" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.A"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.A&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;VirTool:WinNT/Sinowal.B: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.B" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.B"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/Entry.aspx?name=VirTool:WinNT/Sinowal.B&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;PWS:Win32/Sinowal.gen!C: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!C" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!C"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!C&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;PWS:Win32/Sinowal.gen!D:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!D" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!D"&gt;&lt;SPAN style="COLOR: windowtext; TEXT-DECORATION: none; text-underline: none"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/Entry.aspx?name=PWS:Win32/Sinowal.gen!D&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;H3 style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;Support&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;TABLE class=MsoNormalTable style="mso-cellspacing: 0in; mso-yfti-tbllook: 160; mso-padding-alt: 0in 0in 0in 0in" cellSpacing=0 cellPadding=0 border=0 class="MsoNormalTable"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" vAlign=top&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #a6a6a6"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 6pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent"&gt;
&lt;P style="LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" vAlign=top&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #a6a6a6"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;•&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 6pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent"&gt;
&lt;P style="LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;Customers in the U.S. and Canada can receive technical support from &lt;/SPAN&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=21131" mce_href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;Microsoft Customer Support Services&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt; at 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2; mso-yfti-lastrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" vAlign=top&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #a6a6a6"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;•&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0in; BORDER-TOP: #ece9d8; PADDING-LEFT: 6pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; PADDING-TOP: 0in; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent"&gt;
&lt;P style="LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit &lt;/SPAN&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=21155" mce_href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;International Help and Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;-- Robert Hensing and Scott Molenkamp&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;This is a case where the Microsoft Malware Protection Center (MMPC) worked closely with the Microsoft Security Response Center (MSRC) to analyze the threat and develop guidance and mitigations. Rob "EL CONQUISTADOR" Hensing (Microsoft Security Technology Unit) and Scott Molenkamp (Microsoft Malware Protection Center, Australia) contributed to this blog in an effort to share this information with customers and partners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2733817" width="1" height="1"&gt;</description></item><item><title>Microsoft Security Intelligence Report (January – June 2007) is Now Available</title><link>http://blogs.technet.com/antimalware/archive/2007/10/24/microsoft-security-intelligence-report-january-june-2007-is-now-available.aspx</link><pubDate>Thu, 25 Oct 2007 00:05:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2245139</guid><dc:creator>blogmalware</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/antimalware/comments/2245139.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=2245139</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;One of the Microsoft Malware Protection Center’s (MMPC) goals is to share the valuable data, insights and expertise we have with customers on a regular basis in an effort to help customers better understand the changes occurring in the threat landscape and improve their defenses accordingly.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We just released the third volume of our threat report, called the Security Intelligence Report (SIR). The SIR shares the conclusions drawn by our research team using data gathered from the Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Windows Live OneCare, Windows Live OneCare safety scanner, Exchange Hosted Services, and Forefront Client Security (FCS).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The net of this, is threat related data from several hundred million Windows based systems.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The MMPC partners with several groups within Microsoft to make the SIR a unique threat report.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The Microsoft Security Response Center (MSRC), the Trustworthy Computing (TwC) group and numerous product groups all contribute to the report.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In this volume of the SIR, the MSRC has written a couple of sections on software vulnerability disclosures and exploits.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here’s an example of one observation by the MSRC:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The number of disclosed vulnerabilities across the software industry continues to climb, with more than 3,400 new vulnerabilities disclosed in 1H07. But according to the &lt;SPAN class=msoDel&gt;&lt;DEL cite=mailto:Jeff%20Williams dateTime=2007-10-23T14:25&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;FONT color=#ff0000&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DEL&gt;&lt;/SPAN&gt;data we’ve gathered this number actually represents a decrease from 2H06, the first period-to-period decline in total vulnerabilities since 2003.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Another trend identified by the MSRC is that while the number of vulnerabilities continues to increase, the ratio of exploit code available for those vulnerabilities is on a slight decline.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;We have been listening to feedback from customers, partners and analysts regarding what they liked in past releases of the SIR and what they thought could be improved.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Based on that feedback we have made some big changes in this new volume of the SIR that I hope readers will like.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Please keep the feedback coming!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some of the changes we made in the new SIR include:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;The report includes a new section on Software Vulnerability Exploits, which is authored by the MSRC.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;The report now has a new look and feel which includes an executive summary as well as customer guidance (strategies, mitigations, and countermeasures) in each section of the report&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;A ten page “Key Findings Summary” is also available which provides an executive summary of the 92 page SIR.&amp;nbsp; This summary is available in the following languages: Chinese (Simplified), Chinese (Traditional), English, French, German, Italian, Japanese, Korean, Portuguese (Brazil), Russian, Spanish&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;From the data in the SIR we can see that the trends continue in a direction that indicates attackers are financially motivated and are adjusting their tactics along with constantly modifying the threats, both malicious and potentially unwanted (you can read more about what distinguishes each of these in the report)&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;they use to support this goal.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some examples of findings in the new SIR:&lt;SPAN class=msoDel&gt;&lt;DEL cite=mailto:Tim%20Rains dateTime=2007-10-23T15:00&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/DEL&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;Significant increases in categories, such as Trojan downloaders, potentially unwanted software (which includes rogue security software), and exploits, suggest that distribution of potentially unwanted software is less and less a matter of a normal affiliate model and more often malicious and/or criminal in method and intent.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;The MSRT removed significantly more malware in 1H07 than in previous periods.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It removed malware from 1 out of every 217 computers in 1H07, compared to 1:409 in 2006 and 1:359 in 2H05.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;We found 65% less Potentially Unwanted Software and 60% less malware on computers running Windows Vista than on computers running Windows XP SP2.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;You can read more in the SIR: &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/sir" mce_href="http://www.microsoft.com/sir"&gt;&lt;FONT face="Times New Roman" size=3&gt;www.microsoft.com/sir&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Vinny Gullotto&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2245139" width="1" height="1"&gt;</description></item><item><title>Back from Vienna/VB2007</title><link>http://blogs.technet.com/antimalware/archive/2007/10/20/back-from-vienna-vb2007.aspx</link><pubDate>Sat, 20 Oct 2007 11:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2211410</guid><dc:creator>blogmalware</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/antimalware/comments/2211410.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=2211410</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Hi again, WOW so a month now since the VB2007 Conference in Vienna, Austria.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Vienna was beautiful! &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Where has the time gone, since then!?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I couldn’t let too much more time pass before saying a few words, as I’m finally off the road to be able to sit and gather some thoughts on it.&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;We (The Microsoft Malware Protection Center, a.k.a The MMPC) were a platinum sponsor of this year’s conference and many folks from the team traveled far and wide to get there from our Ireland, Australia, and U.S. labs to attend and present at the event.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;I want to thank all who attended my Sponsor's Presentation at the conference.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;During the presentation I gave an overview of Microsoft’s entry into the anti-virus market, how we have been working to continually improve our research and response capabilities, and also introduced some of the key industry hires we have made over the past year.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;As usual, it was great to see everyone; the best and brightest folks in the anti-malware industry who do this work; keep you protected and informed and talk about what’s been, what’s next and what needs to be done.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It also gave attendees the chance to meet and discuss important issues with some of our researchers, including Jimmy Kuo, Katrin Totcheva, and Jakub Kaminski, all who’ve been in attendance at VB for years. Folks also got to meet some of the team who attended for the first time, like Alex Carp, Kyle Larsen and Todd Gaiser.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;We had some productive discussions with attendees regarding new threats to Internet users, anti-virus testing methodologies, how the MMPC is evolving, and where the best restaurants in Vienna are located. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: Wingdings; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;&lt;SPAN style="mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;J&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Much discussion went into how to transform the WildList to better represent the real threats of today. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Those conversations, as I’m sure you can imagine, were quite lively and just an opinion or two were shared.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;We look forward to the changes that are likely to develop from these discussions.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I really enjoyed the session on sample sharing that Dmitry Gryaznov and Joe (Feech) Telafici presented, as well as the discussions that followed – &lt;/FONT&gt;&lt;A style="mso-comment-reference: s_1; mso-comment-date: 20071019T1215"&gt;&lt;FONT face=Calibri&gt;especially the interview Feech gave to the “BBC” &lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-comment-continuation: 1"&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: Wingdings; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;&lt;SPAN style="mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;J&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-comment-continuation: 1"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;The explosive growth in malware presents some interesting engineering challenges, like in the area of storage that the anti-malware industry needs to address.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;Onward we continue to go, both as a collective industry and as individual organizations, to drive these programs and change forward. I’m looking forward to see how some of these conversations play out; I clearly plan to have the MMPC at the forefront (hehe) of those conversations, as we have had many customers tell us they want and expect us to be there. They can count on it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;October and November are busy months for us…stay tuned!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;Vinny Gullotto&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2211410" width="1" height="1"&gt;</description></item><item><title>Storm Drain</title><link>http://blogs.technet.com/antimalware/archive/2007/09/20/storm-drain.aspx</link><pubDate>Fri, 21 Sep 2007 03:35:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2004650</guid><dc:creator>blogmalware</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.technet.com/antimalware/comments/2004650.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=2004650</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;Over the past few months, there has been talk about a wave of malware known commonly as “Storm”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;“Storm” has been noted to be responsible for Distributed Denial of Service (DDoS) attacks, mass phishing emails, spam, botnets, and all sorts of online malicious activity.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;While the name “Storm” was adopted by press, security companies had already adopted a myriad of names for the set of malware that encompasses this attack.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here at Microsoft, we refer to certain components as Win32/Nuwar and others as Win32/Tibs.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Other names such as Zhelatin and shorter names associated with brief attacks have also been used, such as e-card or nfltracker.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As I noted, there are many different components, each with its own specialized functionality, so over time, many names have been used.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;In August, Microsoft’s Malware Protection Center (MMPC), the group of researchers responsible for each month’s additions to the Malicious Software Removal Tool (MSRT), decided to add this family to the September MSRT release based on its prevalence.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The MSRT updates are released monthly in conjunction with Microsoft’s security software updates, and are free to the public in an effort to remove prevalent malware from the Windows eco-system and improve everyone’s ability to enjoy the Internet.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;With more than 350 million machines around the world that run this program, it requires great care and planning to release each new version.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;After much work and testing, we made this month’s MSRT available for download September 11, and nowafter one week, we would like to share some of the statistics with you.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But before I do, the researcher in me requires that I give you the caveats.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;First, MSRT is targeted against very specific known malware.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is well known that the “Storm” attacks are engineered by criminals who update their malware frequently.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As a result, we are in an endless chase.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But that doesn’t mean we shouldn’t try to make things better.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also, once we decide to take on a family in the MSRT, we continue the assault on that family moving forward, so we will keep at it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Because of all the testing that has to be done, we have to freeze our signature additions weeks in advance to make sure we have ample time to do the testing required to release a product as error free as possible (since even a small percentage of errors will impact thousands or millions of people).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;Finally, to the numbers (numbers as of 2PM Tuesday, PDT).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;The Renos family of malware has been removed from 668,362 distinct machines.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The Zlob family has been removed from 664,258 machines.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And the Nuwar family has been removed from 274,372 machines.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In total, malware has been removed by this month’s MSRT from 2,574,586 machines.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;So, despite some public concern in the press and among researchers about the “Storm” worm, it ranks third among the families of malware whose signatures have been added to the MSRT.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&lt;o:p&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;Another antimalware researcher who has been tracking these recent attacks has presented us with data that shows we knocked out approximately one-fifth of “Storm’s” Denial of Service (DoS) capability on September 11&lt;SUP&gt;th&lt;/SUP&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Unfortunately, that data does not show a continued decrease since the first day.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We know that immediately following the release of MSRT, the criminals behind the deployment of the “Storm” botnet immediately released a newer version to update their software.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To compare, one day from the release of MSRT, we cleaned approximately 91,000 machines that had been infected with any of the number of Nuwar components.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Thus, the 180,000+ additional machines that have been cleaned by MSRT since the first day are likely to be home user machines that were not notably incorporated into the daily operation of the “Storm” botnet.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Machines that will be cleaned by MSRT in the subsequent days will be of similar nature.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;The effort by criminals who try to usurp machines on the Internet for their criminal enterprise continues.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The September release of the MSRT probably cleaned up approximately one hundred thousand machines from the active “Storm” botnet.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Such numbers might project that the strength of that botnet possibly stood at almost half a million machines with an additional few hundred thousand infected machines that the “Storm” botnet perhaps were not actively incorporating.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;Unfortunately, “the virus you are most likely to be infected with is the one that you most recently cleaned” because people with a habit of doing something are likely to repeat whatever they did.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Despite so many machines having been cleaned recently by MSRT, the “Storm” botnet will slowly regain its strength.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This highlights the importance that MSRT is only effective if it is used in conjunction with a real-time antimalware program or package.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;As I said before, once we set our sights on a particular malware family, we will continue in that fight.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, we await the next release of MSRT when hopefully, we will take another bite out of crime.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;--&amp;nbsp; Jimmy Kuo&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2004650" width="1" height="1"&gt;</description></item><item><title>Malware Protection Center Portal v1 Live!</title><link>http://blogs.technet.com/antimalware/archive/2007/07/09/malware-protection-center-portal-v1-live.aspx</link><pubDate>Tue, 10 Jul 2007 07:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1491550</guid><dc:creator>blogmalware</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/antimalware/comments/1491550.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=1491550</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Hey all, if you recall, back in April we released the &lt;I style="mso-bidi-font-style: normal"&gt;PREVIEW&lt;/I&gt; version of our new portal affectionately known as the Microsoft Malware Protection Center Portal.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Since then we’ve received loads of feedback from customers and partners on what they like about the portal and the features they really want to see now and in the future. All of it great stuff!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The official Version 1 of the Microsoft Malware Protection Center Portal is now live!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;You can check it out here:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/" mce_href="http://www.microsoft.com/security/portal/"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Some of the features you asked for and we included are:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Access to our malware encyclopedia.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; mso-add-space: auto"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;When you need to do some research on a particular threat or family you can search or browse our encyclopedia and get the details we’ve written about on it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Download our antivirus and/or our antispyware signatures.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; mso-add-space: auto"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;We recommend updating daily, the products will do it for you, BUT if want you can do it yourself for the Forefront client or Windows Defender products&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;both the 32 bit and 64 bit systems.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Threat and Potentially Unwanted Software Telemetry.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; mso-add-space: auto"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;The portal provides information on the top threats and potentially unwanted software that we are observing and that’s being reported to us by YOU. Each top ten category&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;provides links to read up on those listed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Tools and Resources.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; mso-add-space: auto"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;We have a collection of links to tools and resources that we think can be useful and interesting to you including blogs and the Microsoft Security Intelligence Report.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Microsoft Security Intelligence Report.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; mso-add-space: auto"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;And of course no blog would be complete without me mentioning the SIR, we have a page dedicated to hosting the various reports we produce:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal/SIR.aspx" mce_href="http://www.microsoft.com/security/portal/SIR.aspx"&gt;&lt;FONT face="Times New Roman" size=3&gt;http://www.microsoft.com/security/portal/SIR.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;And last but not least we have the &lt;B style="mso-bidi-font-weight: normal"&gt;Sample Submission&lt;/B&gt; feature! You got a file that you think is infected and want to know for sure?? Upload it to us, we’ll take a look and let you know.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;This is just the start – literally a v1 release.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As always we want to hear what you think about the portal – the good, the bad, and the ugly (don’t be shy).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Please send us feedback and let us know which features you want to see in future releases.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="mailto:mpcfb@microsoft.com" mce_href="mailto:mpcfb@microsoft.com"&gt;&lt;FONT face="Times New Roman" size=3&gt;mpcfb@microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: 'Courier New'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Take care, more soon!!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Vinny &lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1491550" width="1" height="1"&gt;</description></item><item><title>My TechEd Summer Vacation</title><link>http://blogs.technet.com/antimalware/archive/2007/06/29/teched-microsoft-security-intelligence-report-webcast.aspx</link><pubDate>Fri, 29 Jun 2007 21:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1397545</guid><dc:creator>blogmalware</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/antimalware/comments/1397545.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=1397545</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Hi again, just recently returned from MS TechEd in Orlando, oh it was HOT!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;It was great to get a chance to meet some customers and partners face to face and discuss what’s happening at a more granular level today in the enterprise.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The issues they face are of course at the heart of what we’re providing solutions for and allows us to reprioritize where needed to make sure we’re addressing things daily as that’s how fast we see things happening at the moment, as I know others do as well. Oh the day of the boot sector infector are long behind us and the pace at which we all must move now is at lightning speed, ya gotta love it!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Some of the important questions and issues we discussed included things like Rootkit technology, naming conventions and the overall breadth of the problem today around spyware and what next generation of threats would we see.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;In addition, there were many concerns about the never ending Bot problem and of course how the Microsoft Malware Protection Center will continue to grow to support customers globally.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;My commitment to them was to return in some way shape or form and update them on our progress in these areas through this blog and next year at TechED&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The customers that attended the presentation seemed a bit overwhelmed by the data we put together in our last Security Intelligence Report.&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: red"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;When I returned back to Redmond, one of the first things I did was go to the TechNet recording studios and record a Security Intelligence Report webcast.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you don’t have the time to read the full report (&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AF816E28-533F-4970-9A49-E35DC3F26CFE&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AF816E28-533F-4970-9A49-E35DC3F26CFE&amp;amp;displaylang=en"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=AF816E28-533F-4970-9A49-E35DC3F26CFE&amp;amp;displaylang=en&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; ) this webcast is an easy way to hear about all the findings in the report and come up to speed on the malware trends we have been observing.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Check it out!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A title=http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032340085&amp;amp;Culture=en-US href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032340085&amp;amp;Culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032340085&amp;amp;Culture=en-US"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;FONT color=#0000ff&gt;http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032340085&amp;amp;Culture=en-US&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;There is more to come…stay tuned.&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Vinny Gullotto&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1397545" width="1" height="1"&gt;</description></item><item><title>VB 100 Test Results Are In...</title><link>http://blogs.technet.com/antimalware/archive/2007/06/04/we-got-the-vb100.aspx</link><pubDate>Mon, 04 Jun 2007 21:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1145564</guid><dc:creator>blogmalware</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/antimalware/comments/1145564.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=1145564</wfw:commentRss><description>&lt;P class=MsoPlainText style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Consolas size=3&gt;As I mentioned in my last blog post, our researchers and engineers in the Microsoft Malware Protection Center have been focusing their efforts on protecting customers from current, in the wild threats, and established an undertaking to achieve the next VB100 award.&amp;nbsp; Today Virus Bulletin announced the results of their latest tests and Windows Live OneCare as well as Forefront Client Security have both been awarded their VB100 award.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Consolas size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;A href="http://www.virusbtn.com/vb100/index" mce_href="http://www.virusbtn.com/vb100/index"&gt;&lt;FONT color=#0000ff&gt;http://www.virusbtn.com/vb100/index&lt;/FONT&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;-- Jimmy Kuo&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1145564" width="1" height="1"&gt;</description></item><item><title>Continuing to move forward – the Microsoft Malware Protection Center</title><link>http://blogs.technet.com/antimalware/archive/2007/05/15/continuing-to-move-forward-the-microsoft-malware-protection-center.aspx</link><pubDate>Wed, 16 May 2007 02:03:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:972828</guid><dc:creator>blogmalware</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/antimalware/comments/972828.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=972828</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Fresh off our visit to &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;Japan&lt;/st1:place&gt;&lt;/st1:country-region&gt;, where we discussed issues important to the Microsoft Malware Protection Center, we continue to move forward with our goal of being a premier anti-virus research and response center (R&amp;amp;R).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Last week’s news of our new global response centers has been well received and that’s excellent! &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;It’s important for our customers that we succeed at the set of goals we’ve declared and get ourselves into a leadership position not only to support the applications we are delivering, but to fine tune some of the processes we’ve created to better support our partners, the industry and the community at large who rely on MS and others to protect them from today’s threats.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;When I arrived 8 months ago, MS had the makings of a team that was poised to break through to the next level of R&amp;amp;R. There were some key elements missing; I believe we have added those in the past 6 months and are prepared to see our goal realized. One of the key elements we added was opening the new centers in &lt;st1:City w:st="on"&gt;Dublin&lt;/st1:City&gt; and &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Tokyo&lt;/st1:place&gt;&lt;/st1:City&gt;, and we have plans to add more centers soon. In addition, the new portal, which may be the most significant change, is now a home to display the day to day workings of the team, as well as be a place everyone can visit to see what we uncovered and track.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Check it out! &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/portal" mce_href="http://www.microsoft.com/security/portal"&gt;&lt;FONT face=Calibri size=3&gt;www.microsoft.com/security/portal&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;On a more important note, our detection numbers are continuing upwards. I know this is a subject of ongoing interest for many, and we continue to push the team hard in this area because in the end it will be the most visible measure of our success.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Calibri size=3&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;We just once again had the OneCare product ICSA and West Coast Labs certified AND Forefront is now WestCoast Labs certified and is in the process of being ICSA certified as well. We feel very confident that we’ll achieve the VB100 Award, for both products as well when the results are published in June, by Virus Bulletin. This to me will exemplify the work we’ve been focusing on and continue to do so.&lt;/P&gt;&lt;/FONT&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;And finally, we established some key areas and defined a set of benchmarks imperative for us to achieve world class response credibility. This, of course, is the essential element given today’s targeted attacks are more advanced than ever before.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;We’ve applied the basic principles our partners, that come before us have to provide world class response to customer queries (including automated responses and queue processing to customer submissions and of course analysts globally to respond regionally) and we have the added element that is unique to MS, which is the insight into the more than 400 million Windows users worldwide.&lt;SPAN style="COLOR: #1f497d"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;These customers have consistently asked us to provide support to the ever growing threat of viruses, worms, Trojans and unwanted programs that plague their environments today.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;I’d ask that you continue to check back as we provide updates straight from the labs as well as from those watching and monitoring our success. Just this past week we released a new volume of our Security Intelligence Report.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The report outlines the trends that we have observed in the malicious software and potentially unwanted software landscapes over the last six months (&lt;/FONT&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkID=88436&amp;amp;clcid=0x409" mce_href="http://go.microsoft.com/fwlink/?LinkID=88436&amp;amp;clcid=0x409"&gt;&lt;FONT face=Calibri size=3&gt;http://go.microsoft.com/fwlink/?LinkID=88436&amp;amp;clcid=0x409&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;We have a lot more in store and a lot more that we can be counted on to deliver.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Vinny Gullotto&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=972828" width="1" height="1"&gt;</description></item><item><title>Hello world</title><link>http://blogs.technet.com/antimalware/archive/2007/03/15/hello-world.aspx</link><pubDate>Fri, 16 Mar 2007 04:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:696000</guid><dc:creator>blogmalware</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/antimalware/comments/696000.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=696000</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;printf(“hello world\n”);&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;This is Jimmy Kuo of the Microsoft Security Research &amp;amp; Response team (MSRR).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;(What a wonderful thing to say and see written down.).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Recently, there have been some tests that have brought into question the detection capability of Windows Live OneCare.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Customers and partners have asked us to address these concerns and because the detection capability in Windows Live OneCare is the responsibility of the MSRR team I’d like to address those concerns.&amp;nbsp; &lt;EM&gt;(Addendum: The OneCare team has just posted their comments on this issue on their blog at &lt;/EM&gt;&lt;A href="http://windowsonecare.spaces.live.com/"&gt;&lt;EM&gt;http://windowsonecare.spaces.live.com/&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; )&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;When we think about priorities we put our customers first and in doing that we ask ourselves, “What do our clients want?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What do they need?”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;In my years in this business, the answer to the first question is some form of, “I want to be able to sleep soundly each night knowing that when I wake up, my world hasn’t fallen apart.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And if something does happen, I can rely on my vendor to easily resolve it for me.”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To that end customers using Windows Live OneCare are supported by Customer Support and Service and the MSRR team.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Through those two channels they have the support structure needed to address any service request that comes to us at any hour of the day from anywhere in the world.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT size=3&gt;What our clients “need” is for us to identify what things are important and be sure to address them before they become an issue for our users.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is why MSRR is focused on adding detections for the most prevalent and active malware in the wild and we do that &lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;by combining our breadth of data with experienced malware researchers and automated analysis techniques to rapidly respond to the&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;threats that will have the greatest impact to our customers. &lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;To that end, while the recent detection numbers were not stellar, we look to ICSA Labs (&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.icsalabs.com/" mce_href="http://www.icsalabs.com/"&gt;&lt;FONT face="Times New Roman" size=3&gt;www.icsalabs.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Times New Roman" size=3&gt;), West Coast Labs (&lt;/FONT&gt;&lt;A href="http://www.westcoastlabs.org/" mce_href="http://www.westcoastlabs.org/"&gt;&lt;FONT face="Times New Roman" size=3&gt;www.westcoastlabs.org&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Times New Roman" size=3&gt;), and Virus Bulletin (&lt;/FONT&gt;&lt;A href="http://www.virusbtn.com/" mce_href="http://www.virusbtn.com/"&gt;&lt;FONT face="Times New Roman" size=3&gt;www.virusbtn.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;) to make sure we are covering what is most important.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;ICSA Labs and West Coast Labs are certification bodies (ICSA Labs in the &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:country-region w:st="on"&gt;United States&lt;/st1:country-region&gt;, West Coast Labs in &lt;st1:place w:st="on"&gt;Europe&lt;/st1:place&gt;).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Virus Bulletin is the industry rag, but they have the most highly respected and longest running tests, and in so doing, set many of the industry’s testing standards.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We will keep on working with these certification bodies to maintain our certifications, and to acquire the VB100 Award each time we are tested by Virus Bulletin.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We missed capturing a VB100 in the last test because&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;we missed one virus.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, as a result we have adopted new methodologies to remedy that.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The methodology we adopted is to look more closely at families of viruses that have been found to be “in the wild” (ITW) (found actively spreading among users).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This means someone working off the same code base is actively spreading the malware of this family, and thus more of the same family will likely become ITW in the future.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And we want to be able to detect them with signatures we write today rather than after they’ve been loosed upon the public.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Furthering on the previous concept, we look to many other feeds that tell us similar things.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The MSRT (Windows Malicious Software Removal Tool) is one that can tell us which families are more active so we can anticipate more of those future variants.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;That still leaves many samples of malware that the recent tests showed that we still do not detect.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As I noted, there is data that can tell us which, if any, of that set is truly important (those actively being spread ITW) and those are added ASAP.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The rest are being worked on and as promised, our numbers will get better and better.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Because, another thing that I know that our clients want, especially the system admins who use our product, is, “I want you to keep my boss off my back so I can have time to do my job!”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And even if the company networks are running smoothly, the boss will see those test results, and bug the admins about them.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So it’s also about making sure our customers *feel* better protected when using our products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;So while we concentrate on what’s truly important (malware actively being spread ITW), we will also be bringing up these other test detection numbers. You will see our results gradually and steadily increase until they are on par with the other majors in this arena.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And soon after, they will need to catch up to us!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;st1:PersonName w:st="on"&gt;Vinny Gullotto&lt;/st1:PersonName&gt;, General Manager of Microsoft Security Response and Research, tells me that he’ll be following up on this post within the next week and talk about some of the additional steps we are taking to continue growing our world class research and response team.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;He and I are both accustomed to working in, and building, world class response teams and know that Microsoft is committed to creating one that serves our customers, works with the anti-malware community, and supports the eco-system as a whole.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Hopefully, I’ve provided some insight into the workings of how we are prioritizing and focusing on the work we do to support our users, presently and in the future.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We know that we are in a service industry.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We’re ramping up to be able to handle that and Microsoft is making sure our customers are in good hands by hiring some of the best and brightest in the antivirus industry.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For our current users, we have certification bodies that make sure we are doing what’s necessary and important.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And we have other monitors to determine what’s spreading and thus are confident that we can protect our users against anything they might encounter in real life.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And we will &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;bring our numbers up as we know our customers want that to feel better protected, and, well, to get &lt;I style="mso-bidi-font-style: normal"&gt;our&lt;/I&gt; bosses off &lt;I style="mso-bidi-font-style: normal"&gt;our&lt;/I&gt; backs.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: Wingdings; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;&lt;SPAN style="mso-char-type: symbol; mso-symbol-font-family: Wingdings"&gt;J&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=696000" width="1" height="1"&gt;</description></item><item><title>Virus Bulletin 2006</title><link>http://blogs.technet.com/antimalware/archive/2006/10/30/virus-bulletin-2006.aspx</link><pubDate>Tue, 31 Oct 2006 00:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:488006</guid><dc:creator>blogmalware</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/antimalware/comments/488006.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=488006</wfw:commentRss><description>&lt;P&gt;A contingent from our antimalware team attended the &lt;A class="" href="http://www.virusbtn.com/conference/vb2006/index" mce_href="http://www.virusbtn.com/conference/vb2006/index"&gt;Virus Bulletin&lt;/A&gt; conference in Montreal, Canada two weeks ago- 12 of us in all.&amp;nbsp; Matt Braverman and I were both presenters and I also moderated a panel discussing progress made by the &lt;A class="" href="http://www.antispywarecoalition.org/" mce_href="http://www.antispywarecoalition.org/"&gt;Anti-Spyware Coalition&lt;/A&gt;.&amp;nbsp; &lt;BR&gt;&lt;/P&gt;
&lt;P&gt;My paper entitled "&lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0b6321d4-0e65-4133-85e7-44e666cc245a&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0b6321d4-0e65-4133-85e7-44e666cc245a&amp;amp;displaylang=en"&gt;I Know What You Did Last Logon&lt;/A&gt;" was a look into monitoring software from the perspective of privacy and the boundaries of appropriate versus inappropriate use for such technology.&amp;nbsp; I examined this from several angles including a discussion of several court cases that illustrate both sides of the discussion.&amp;nbsp; I also drilled into several pieces of malware for a more detailed discussion of the technical methods employed by monitoring software.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Matt's paper, entitled "&lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e0f27260-58da-40db-8785-689cf6a05c73&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e0f27260-58da-40db-8785-689cf6a05c73&amp;amp;displaylang=en"&gt;Behavioral Modeling of Social Engineering-Based Malicious Software&lt;/A&gt;"&amp;nbsp;focuses on malware that leverages social engineering to infect a computer. It reviews techniques used both in the past and present and uses up-to-date data from the MSRT to differentiate those social engineering techniques which have been particularly successful. For example, we've found that using "generic conversation" techniques in an email seems to be one of the most effective ways to attract a user to executing an attachment to that email. Such techniques usually leverage short email subjects and bodies (e.g. "Here is that document you asked for") to try and replicate conversations that may have occurred "in real life" between the email recipient and the sender which the email may spoof.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Copies of both papers are now available through the download center, let us know what you think.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;-- Jeff Williams&lt;BR&gt;Security Research &amp;amp; Response&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=488006" width="1" height="1"&gt;</description></item><item><title>Security Intelligence Report</title><link>http://blogs.technet.com/antimalware/archive/2006/10/26/security-intelligence-report.aspx</link><pubDate>Fri, 27 Oct 2006 04:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:480118</guid><dc:creator>blogmalware</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/antimalware/comments/480118.aspx</comments><wfw:commentRss>http://blogs.technet.com/antimalware/commentrss.aspx?PostID=480118</wfw:commentRss><description>&lt;P&gt;This week at RSA Europe in Nice, France we released a report detailing the security landscape for the first half of 2006. The report lays out details collected through our various antimalware technologies. The report highlights a number of trends such as a reduction in the number&amp;nbsp;of rootkits and trojans detected by the Malicious Software Removal Tool (MSRT)&amp;nbsp;compared to the second half of 2005, social engineering as a popular and successful method of malware distribution, the frequency that specific potentially unwanted software is kept or removed and specific locales which have the highest instance of infection.&lt;/P&gt;
&lt;P&gt;Some of the key points we think our readers will be interested in are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Threats against consumers and businesses are continuing to become more targeted and motivated by financial gain, with backdoor Trojans and bots continuing to comprise a significant percentage of the malicious software detected by Microsoft anti-malware offerings; &lt;/LI&gt;
&lt;LI&gt;Social engineering continues to be a popular means of spreading malware, especially when sent over e-mail and peer-to-peer (P2P) networks; &lt;/LI&gt;
&lt;LI&gt;Rootkits are likely to continue to be popular for targeted, stealth intrusions. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The data used to identify these trends comes primarily from the Malicious Software Removal Tool and Windows Defender as well as Windows Live OneCare, Windows Live One Care safety scanner, and Microsoft Exchange Hosted Filtering. In the six months covered by the report these tools cleaned nearly 27 million pieces of malware or potentially unwanted software and blocked hundreds of millions of infected email messages.&lt;/P&gt;
&lt;P&gt;Based on the data we analyzed and trends observed we also make specific recommendations for how you can better protect the systems that you manage.&lt;/P&gt;
&lt;P&gt;You can find the full report &lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=1C443104-5B3F-4C3A-868E-36A553FE2A02&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=1C443104-5B3F-4C3A-868E-36A553FE2A02&amp;amp;displaylang=en"&gt;here&lt;/A&gt;. We welcome your feedback.&lt;/P&gt;
&lt;P&gt;Matt Braverman, Jeff Williams &amp;amp; Ziv Mador&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=480118" width="1" height="1"&gt;</description></item></channel></rss>