This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MSRT analysis report - 3.5M Trojans...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
June 12, 2006
"Backdoor Trojans are a clear and present danger to Windows machines, Microsoft said Monday as it released the first-ever analysis of data collected by the 15-month run of its Malicious Software Removal Tool, a utility that seeks out and destroys over five-dozen malware families. According to Microsoft's anti-malware engineering team, Trojans that, once installed, give an attacker access and control of a PC, are a "significant and tangible threat to Windows users." Of the 5.7 million unique PCs from which the Malicious Software Removal Tool (MSRT) has deleted malware, 3.5 million of them – 62 percent – had at least one backdoor Trojan… Since it debuted in January 2005, the MSRT has been run some 2.7 billion times on an increasing number of PCs. In March 2006, the last month for which data was compiled, 270 million unique systems ran the tool, which is automatically downloaded and run on systems with Windows/Microsoft Update turned on. Over those 15 months, the MSRT found malware on one in every 311 computers…"

:huh: :ph34r: :(
FYI…

- http://isc.sans.org/diary.php?storyid=1441
Last Updated: 2006-06-23 16:31:21 UTC
"…One security trade publication clearly misread the summary and posted a misquote (62% of computers infected with backdoor). That is not what the report states. The 62% number is the percentage of machines that had malware removed from them by MSRT AND had a backdoor installed on them. Restated more than ½ of the machines where an infection was detected and removed also had remote control backdoors on them. No surprise there really. Although there are ways for the hackers to use a system without a backdoor tool installed for the most part the hackers want to be able to remotely upgrade and control systems they have compromised…
It's reactive and only comes into play after the fact of infection. Since it is also fairly limited in the malware it detects and the signatures are usually only updated once a month I don't know of any current antivirus package that would miss a virus that MSRT would detect. So I do not agree this provides defense in depth. I do however see serious benefit to running MSRT. It certainly has contributed to the effort of getting infected systems cleaned.
Some other fun facts I gleaned from this report:
> MSRT only removes live malware or malware that will be autorun during a reboot.
> 1 computer in 355 had malware that was recognized and removed.
> 5% of the root kits removed were WinNT/F4IRootkit (aka the sony root kit) with about 420k removals from 250k machines.
> 35% of the computer infected were infected via the end user clicking or opening something.
> 20% of the computers cleaned had been infected sometime in the past.
So if you have a little time and you are interested in malware propagation I recommend reading this report."

- http://tinyurl.com/fy8x9

.