<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title></title>
	<atom:link href="http://hitmanpro.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://hitmanpro.wordpress.com</link>
	<description></description>
	<lastBuildDate>Mon, 16 Jan 2012 08:44:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hitmanpro.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title></title>
		<link>http://hitmanpro.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hitmanpro.wordpress.com/osd.xml" title="" />
	<atom:link rel='hub' href='http://hitmanpro.wordpress.com/?pushpress=hub'/>
		<item>
		<title>HitmanPro repairs rogue DNS server settings</title>
		<link>http://hitmanpro.wordpress.com/2012/01/15/hitmanpro-repairs-rogue-dns-server-settings/</link>
		<comments>http://hitmanpro.wordpress.com/2012/01/15/hitmanpro-repairs-rogue-dns-server-settings/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 23:32:27 +0000</pubDate>
		<dc:creator>Erik Loman</dc:creator>
				<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNSChanger]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=444</guid>
		<description><![CDATA[A few days ago the German government advised internet users to check DNS server settings on their computers. The advice is related to the botnet takedown called Operation Ghost Click which was led by the FBI in November 2011. DNSChanger The botnet was made up of more than 4 million computers in more than 100 countries. The computers are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=444&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A few days ago the German government <a href="https://www.bsi.bund.de/ContentBSI/Presse/Pressemitteilungen/Presse2012/Hilfe-gegen-Schadsoftware_DNS-Changer_10012012.html" target="_blank">advised</a> internet users to check DNS server settings on their computers. The advice is related to the botnet takedown called <a title="Operation Ghost Click" href="http://www.fbi.gov/news/stories/2011/november/malware_110911" target="_blank">Operation Ghost Click</a> which was led by the FBI in November 2011.</p>
<p><strong>DNSChanger</strong><br />
The botnet was made up of more than 4 million computers in more than 100 countries. The computers are infected with malware called DNSChanger. This Trojan changes the DNS settings of the computer and allowed the botnet owners to redirect web browser requests. With these redirects, the botnet owners were able to manipulate internet advertising to generate at least $14 million in illicit fees. In some cases, the malware had the additional effect of preventing users’ anti-virus software and operating systems from updating, thereby exposing infected machines to even more malicious software.</p>
<p><strong>Rogue DNS Servers</strong><br />
In November 2011 the FBI seized the rogue DNS servers and replaced them with legitimate servers in the hope that users who were infected will not have their Internet access disrupted. But these servers will be kept online until March 8, 2012.</p>
<p>The replacement DNS servers recorded 33.000 computers in Germany that are still contacting the rogue DNS servers. This number was large enough for the German government to issue the nationwide advice.</p>
<p><strong>dns-ok.de</strong><br />
To facilitate the nationwide DNS check, the German government launched the website: <a href="http://dns-ok.de">dns-ok.de<br />
</a></p>
<p>If you go to the website and your computer uses rogue DNS server settings then you see this page:</p>
<p><a href="http://hitmanpro.files.wordpress.com/2012/01/red-small.png"><img class="alignnone size-full wp-image-447" title="Red-small" src="http://hitmanpro.files.wordpress.com/2012/01/red-small.png?w=450&#038;h=293" alt="" width="450" height="293" /></a></p>
<p><strong>DE-Cleaner</strong><br />
The page offers a link to <a title="DE-Cleaner" href="https://www.botfrei.de/decleaner.html" target="_blank">botfrei.de</a> which provides DE-Cleaner software which helps users to get rid of the DNSChanger infection (and other malware).</p>
<p>DE-Cleaner comes in three flavors provided by: Avira, Kaspersky and Symantec. A multi-vendor approach, just like HitmanPro.</p>
<p><span style="color:#ff0000;"><strong>The problem</strong></span> with the DE-Cleaner software is that they do not detect or repair rogue DNS server settings: <strong>they leave it up to the user</strong>.</p>
<p>Using rogue DNS server settings is as bad as it gets. Nothing on the internet can be trusted: login information and credit data will be stolen. Its a matter of time (DNSChanger is proof of this). So it is of utmost importance that the computer uses proper DNS server settings. Hence the German call for a nationwide DNS check.</p>
<p><strong>DNS repair</strong><br />
Since DNS is extremely important, HitmanPro scans the DNS server settings of each network adapter in the computer. HitmanPro validates the DNS setting against blacklists and lists the corresponding adapter when its DNS server settings are deemed malicious. A repair of the DNS server setting is then offered, free of charge.</p>
<p><strong>Bottom line</strong><br />
Besides DE-Cleaner, most Antivirus products do not check the DNS server settings of the computer. The reason for this is beyond anybody&#8217;s guess. HitmanPro 3 checks the DNS server settings since its incarnation and provides a convenient way for the average computer user to get rid of the malware and repair DNS server settings in just one single pass.</p>
<p>Since the DNSChanger botnet was made up of more than 4 million computers, with 500.000 computers in the US and 33.000 in Germany, there are a lot more computers that still use the rogue DNS server settings. So run a scan with <a href="http://www.surfright.nl/downloads" target="_blank">HitmanPro</a> before March 8, 2012 or you might not be able to use the internet &#8211; the FBI will shutdown the replacement DNS servers on that day.</p>
<p><strong>Video</strong><br />
We have made a video to illustrate the whole proceedings:</p>
<span style="text-align:center; display: block;"><a href="http://hitmanpro.wordpress.com/2012/01/15/hitmanpro-repairs-rogue-dns-server-settings/"><img src="http://img.youtube.com/vi/_NRPFVCrabc/2.jpg" alt="" /></a></span>
<p>Note: we&#8217;ve made the video with Hitman Pro 3.5 as this version supports the German language.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/444/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=444&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2012/01/15/hitmanpro-repairs-rogue-dns-server-settings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4dbd0777f4d9fb42a2ae295d2be92cdc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">erikloman</media:title>
		</media:content>

		<media:content url="http://hitmanpro.files.wordpress.com/2012/01/red-small.png" medium="image">
			<media:title type="html">Red-small</media:title>
		</media:content>
	</item>
		<item>
		<title>HitmanPro 3.6</title>
		<link>http://hitmanpro.wordpress.com/2011/12/23/hitmanpro-3-6/</link>
		<comments>http://hitmanpro.wordpress.com/2011/12/23/hitmanpro-3-6/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 14:47:56 +0000</pubDate>
		<dc:creator>Erik Loman</dc:creator>
				<category><![CDATA[Release]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=426</guid>
		<description><![CDATA[With great pleasure we announce the release of HitmanPro 3.6. The highlights of this release are a brand new Remnant Scan, a new Scheduler with more options, a new Shell Extension, revamped graphics and many improvements which make this release the best release yet. For the complete list of changes see the below changelog. Changelog Hitman Pro [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=426&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>With great pleasure we announce the release of HitmanPro 3.6.</p>
<p>The highlights of this release are a brand new Remnant Scan, a new Scheduler with more options, a new Shell Extension, revamped graphics and many improvements which make this release the best release yet.</p>
<p>For the complete list of changes see the below changelog.</p>
<div></div>
<div><a href="http://hitmanpro.files.wordpress.com/2011/12/hitmanpro360.png"><img class="alignnone size-full wp-image-427" title="HitmanPro 3.6.0" src="http://hitmanpro.files.wordpress.com/2011/12/hitmanpro360.png?w=450&#038;h=357" alt="" width="450" height="357" /></a></div>
<div></div>
<p><strong>Changelog</strong></p>
<ul>
<li>Hitman Pro is now called HitmanPro. On Twitter use #HitmanPro.</li>
<li>NEW: Added Scanning for Malware Remnants.<br />
This new feature scans the File System and Registry for common malware related paths (files, folders, keys). The Remnant Scan combines a multi-threaded local scan with cloud based confirmation. In 3.6.0 we are detecting only a few hundred remnants; more will be added to the cloud in the coming weeks. We are still fine tuning the tooling on the back end.</li>
<li>NEW: Added new Scheduler to allow scanning Daily, At Startup, Mon, Tue, Wed, Thu, Fri, Sat, Sun at specific times. The scheduler is a process called hmpsched.exe.</li>
<li>NEW: Shell integration by using a Shell Extension which adds an icon to the context menu and also allows multiple selected files to be scanned.</li>
<li>NEW: Added &#8216;Goto location&#8217; to context menu to highlight the file in Windows Explorer.</li>
<li>NEW: Added &#8216;Show information&#8217; to context menu to expose more internal information to the end user. Tip: the information can be copy-pasted.</li>
<li>NEW: Added third opinion scan using VirusTotal.<br />
To use this feature you enter your personal VirusTotal Public API Key on the Advanced tab under Settings.</li>
<li>NEW: Added detection for files signed with weak Authenticode signatures (RSA 512-bit keys).<br />
See also: <a href="http://blog.fox-it.com/2011/11/21/rsa-512-certificates-abused-in-the-wild/" target="_blank">http://blog.fox-it.com/2011/11/21/rsa-512-certificates-abused-in-the-wild/</a></li>
<li>NEW: Added chevrons to highlight items in the result list that are running [PID] or start by [Run], [Service] or [Driver].</li>
<li>NEW: Added detection and repair for the HOSTS file that was altered by malware.</li>
<li>NEW: Added /clean command line switch to automatically quarantine and remove malware.</li>
<li>NEW: Added the option to disable the automatic upload of suspicious files to the Scan Cloud.</li>
<li>IMPROVED: Cloud Assisted Miniport Hook Bypass</li>
<li>IMPROVED: Detection and removal of Sinowal, Mebroot rootkit</li>
<li>IMPROVED: Removal of TDL4 (and variants) on systems where Boot Configuration Data (BCD) was persistently malformed by TDL4. Removing TDL4 from those systems could cause a non-bootable system (BSOD). HitmanPro now repairs BCD before removing TDL4 (or variants).</li>
<li>IMPROVED: NTFS Parser to work better with heavily fragmented files.</li>
<li>IMPROVED: Direct Disk Access now always scans using the lowest possible level.</li>
<li>IMPROVED: Firefox and Chrome cookie scan.</li>
<li>CHANGED: For regular users Early Warning Scoring (EWS) is no longer available from the Next button. Expert users can re-enable the EWS scan mode on the Advanced tab under Settings.</li>
<li>INFO: 3.6.0 is currently only available in English.</li>
</ul>
<p>Hitman Pro 3.5 users will not be automatically upgraded since 3.6.0 is currently only available in English. Automatic upgrade of Hitman Pro 3.5 will occur with version 3.6.1.</p>
<p>Installing HitmanPro 3.6 will automatically upgrade an existing Hitman Pro 3.5 installation.</p>
<p><strong>Downloads</strong><br />
32-bit: <a href="http://dl.surfright.nl/HitmanPro36.exe">http://dl.surfright.nl/HitmanPro36.exe</a><br />
64-bit: <a href="http://dl.surfright.nl/HitmanPro36_x64.exe">http://dl.surfright.nl/HitmanPro36_x64.exe</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/426/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=426&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/12/23/hitmanpro-3-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4dbd0777f4d9fb42a2ae295d2be92cdc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">erikloman</media:title>
		</media:content>

		<media:content url="http://hitmanpro.files.wordpress.com/2011/12/hitmanpro360.png" medium="image">
			<media:title type="html">HitmanPro 3.6.0</media:title>
		</media:content>
	</item>
		<item>
		<title>AV-Comparatives Malware Detection Comparative</title>
		<link>http://hitmanpro.wordpress.com/2011/10/02/av-comparatives-malware-detection-comparative/</link>
		<comments>http://hitmanpro.wordpress.com/2011/10/02/av-comparatives-malware-detection-comparative/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 16:56:55 +0000</pubDate>
		<dc:creator>herbertw</dc:creator>
				<category><![CDATA[Statistics]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=408</guid>
		<description><![CDATA[AV-Comparatives, an Austrian Non-Profit-Organization, which is providing independent Anti-Virus software tests free to the public,  recently released the results of their “On-demand detection of malicious software”, where 20 well known Antivirus products were compared. The 10 highest scoring products detected between 97.3% and 99.7% of the test set of over 200,000 malicious files, which means [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=408&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>AV-Comparatives, an Austrian Non-Profit-Organization, which is providing independent Anti-Virus software tests free to the public,  recently released the results of their “<em>On-demand detection of malicious software</em>”, where 20 well known Antivirus products were compared.</p>
<p>The 10 highest scoring products detected between 97.3% and 99.7% of the test set of over 200,000 malicious files, which means that on average over 2,000 (!) malicious files were not detected.</p>
<p>And if you are not using one of the Antivirus products in the top-10 but one of the other products (including some very well known names), you might even be at bigger risk.</p>
<p>See <a title="AV-Comparatives on-demand detection" href="http://www.av-comparatives.org/images/stories/test/ondret/avc_od_aug2011.pdf" target="_blank">http://www.av-comparatives.org/images/stories/test/ondret/avc_od_aug2011.pdf</a> for the full test report.</p>
<p>Click<a title="SurfRight Hitman Pro download" href="http://www.surfright.com/downloads" target="_blank"> here</a> to check what your Antivirus product might have missed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/408/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/408/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/408/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=408&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/10/02/av-comparatives-malware-detection-comparative/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/97697d653b19f6873ebc05a3c6e51e43?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertw</media:title>
		</media:content>
	</item>
		<item>
		<title>ZeroAccess rootkit strikes back</title>
		<link>http://hitmanpro.wordpress.com/2011/07/15/zeroaccess-rootkit-strikes-back/</link>
		<comments>http://hitmanpro.wordpress.com/2011/07/15/zeroaccess-rootkit-strikes-back/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 23:38:43 +0000</pubDate>
		<dc:creator>herbertw</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[TDL3]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=370</guid>
		<description><![CDATA[Malware that actively fights back against removal is not uncommon. But the authors of the ZeroAccess rootkit found a unique way to strike back at its adversary: it instructs an antivirus program to terminate itself. The ZeroAccess rootkit uses advanced stealth tactics, similar to the infamous TDL3 rootkit. The ZeroAccess rootkit itself is hiding, but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=370&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Malware that actively fights back against removal is not uncommon. But the authors of the ZeroAccess rootkit found a unique way to strike back at its adversary: it instructs an antivirus program to terminate itself.</p>
<p>The ZeroAccess rootkit uses advanced stealth tactics, similar to the infamous TDL3 rootkit. The ZeroAccess rootkit itself is hiding, but it&#8217;s payload is not.  It actually is very visible to the user as it redirects e.g. Google Search results in your web browser.</p>
<p>Most antivirus programs are hardened against termination by an external (malicious) process. But it turns out that most antivirus programs are not that tough against themselves.</p>
<p>When an antivirus program tries to scan one of ZeroAccess’s rootkit components, the rootkit strikes back by injecting (from kernel-mode) a small piece of malicious code into the antivirus process space. The code will effectively call the <a href="http://msdn.microsoft.com/en-us/library/ms682658(v=vs.85).aspx" target="_blank">ExitProcess</a> function.<br />
The rootkit then queues the code to be run by the antivirus process by means of an <a href="http://msdn.microsoft.com/en-us/library/ms681951(v=vs.85).aspx" target="_blank">APC</a> (asynchronous procedure call). As soon as one of the threads of the antivirus process becomes idle, the queued code executes and ExitProcess is called: the antivirus program terminates itself.</p>
<p>In addition to the self-termination of the antivirus process, the rootkit also changes the access rights (DACL) of the antivirus program’s EXE file so that it cannot be restarted. This leaves the computer unprotected against new malware infections as well.</p>
<span style="text-align:center; display: block;"><a href="http://hitmanpro.wordpress.com/2011/07/15/zeroaccess-rootkit-strikes-back/"><img src="http://img.youtube.com/vi/61f7Kp18mbk/2.jpg" alt="" /></a></span>
<p>Hitman Pro 3.5.9 build 127 contains protection against these types of malicious code injections and monitors and restores the DACL on its EXE file. Users of Hitman Pro will automatically be updated to the latest version in the next few days.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/370/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=370&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/07/15/zeroaccess-rootkit-strikes-back/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/97697d653b19f6873ebc05a3c6e51e43?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertw</media:title>
		</media:content>
	</item>
		<item>
		<title>Hitman Pro removes Popureb.E</title>
		<link>http://hitmanpro.wordpress.com/2011/06/30/hitman-pro-removes-popureb-e-2/</link>
		<comments>http://hitmanpro.wordpress.com/2011/06/30/hitman-pro-removes-popureb-e-2/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 15:11:12 +0000</pubDate>
		<dc:creator>herbertw</dc:creator>
				<category><![CDATA[Release]]></category>
		<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=343</guid>
		<description><![CDATA[The latest release of Hitman Pro 3.5.9 &#8211; build 126 &#8211; will remove the infamous Trojan &#8220;Popureb&#8221; without the need to reinstall the operating system as previously advised by Microsoft. Malware like Popureb overwrites the hard drive&#8217;s Master Boot Record (MBR), the first sector &#8211; sector 0 &#8211; where code is stored to bootstrap the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=343&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The latest release of Hitman Pro 3.5.9 &#8211; build 126 &#8211; will remove the infamous Trojan &#8220;Popureb&#8221; without the need to reinstall the operating system as previously <a title="Rootkit infection requires Windows reinstall, says Microsoft" href="http://www.computerworld.com/s/article/9217953/Rootkit_infection_requires_Windows_reinstall_says_Microsoft" target="_blank">advised</a> by Microsoft.</p>
<p>Malware like Popureb overwrites the hard drive&#8217;s Master Boot Record (MBR), the first sector &#8211; sector 0 &#8211; where code is stored to bootstrap the operating system after the computer&#8217;s BIOS completed its start-up checks. The rootkit hides the MBR by hooking the DriverStartIo of the harddisk driver atapi.sys, making it effectively invisible to both the operating system and most security software.</p>
<p>The <strong><a title="Cloud Assisted Miniport Hookup Bypass" href="http://hitmanpro.wordpress.com/2011/06/16/cloud-assisted-miniport-hook-bypass/" target="_blank">Cloud Assisted Miniport Hook Bypass</a></strong> technology that was added to Hitman Pro in an earlier release this month is designed to detect these sophisticated rootkits. Our Cloud Assisted Miniport Hook Bypass is capable of detecting and removing the Popureb bootkit.</p>
<p>Build 126 of Hitman Pro 3.5 contains a new Tool Action: <strong>Replace with standard MBR</strong>.</p>
<p><a href="http://hitmanpro.files.wordpress.com/2011/06/replacewithstandardmbr1.png"><img class="alignnone size-full wp-image-362" title="Replace with standard MBR" src="http://hitmanpro.files.wordpress.com/2011/06/replacewithstandardmbr1.png?w=450&#038;h=354" alt="" width="450" height="354" /></a></p>
<p>This new action offers users a means to overwrite a non-standard MBR with a standard MBR returning it to a clean state. This new Tool Action is only available to users when scanning a system with Hitman Pro in Early Warning Scoring (EWS) mode. Users do not need to use the Windows Recovery Console to return the MBR to a clean state.</p>
<p>A beta version of Hitman Pro 3.5.9 build 126 can be downloaded here:</p>
<p>32-bit: <a href="http://dl.surfright.nl/HitmanPro35beta.exe">http://dl.surfright.nl/HitmanPro35beta.exe</a><br />
64-bit: <a href="http://dl.surfright.nl/HitmanPro35beta_x64.exe">http://dl.surfright.nl/HitmanPro35beta_x64.exe</a></p>
<p>UPDATE: Click <a title="Hitman Pro removing Popureb" href="http://www.youtube.com/watch?v=MBP9luBLz9I" target="_blank">here</a> to view Hitman Pro in action against Popureb.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/343/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/343/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/343/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=343&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/06/30/hitman-pro-removes-popureb-e-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/97697d653b19f6873ebc05a3c6e51e43?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertw</media:title>
		</media:content>

		<media:content url="http://hitmanpro.files.wordpress.com/2011/06/replacewithstandardmbr1.png" medium="image">
			<media:title type="html">Replace with standard MBR</media:title>
		</media:content>
	</item>
		<item>
		<title>Hitman Pro 3.5.9 build 124</title>
		<link>http://hitmanpro.wordpress.com/2011/06/16/hitman-pro-3-5-9-build-124-2/</link>
		<comments>http://hitmanpro.wordpress.com/2011/06/16/hitman-pro-3-5-9-build-124-2/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 14:39:45 +0000</pubDate>
		<dc:creator>herbertw</dc:creator>
				<category><![CDATA[Release]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=325</guid>
		<description><![CDATA[The main purpose of Hitman Pro 3.5.9 build 124 is the addition of the Cloud Assisted Miniport Hook Bypass feature. “In the past weeks, we noticed an increase in highly advanced rootkits such as Mebroot, Sinowal and TDL4 who were trying to defeat detection by Hitman Pro” according to Mark Loman, CEO of SurfRight. “With [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=325&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The main purpose of Hitman Pro 3.5.9 build 124 is the addition of the <a title="Cloud Assisted Miniport Hook Bypass" href="http://hitmanpro.wordpress.com/2011/06/16/cloud-assisted-miniport-hook-bypass/">Cloud Assisted Miniport Hook Bypass</a> feature.</p>
<p>“<em>In the past weeks, we noticed an increase in highly advanced rootkits such as Mebroot, Sinowal and TDL4 who were trying to defeat detection by Hitman Pro</em>” according to Mark Loman, CEO of SurfRight. “<em>With this new release we are able to better detect and remove these sophisticated threats.</em>”</p>
<p>The most important features in this new version are:</p>
<ul>
<li>Cloud Assisted Miniport Hook Bypass feature.</li>
<li>Mebroot/Sinowal detection and removal.</li>
<li>Removal of new variant of Trojan Vundo.</li>
<li>Master Boot Record (MBR) protection when restoring infected MBR to counter rootkit watchdogs.</li>
<li>Repair for BCD testsigning. Testsigning is a feature of 64-bit Windows that, when enabled, allows loading of non-signed drivers on 64-bit Windows. Testsigning is typically abused by 64-bit bootkits.</li>
</ul>
<p>The full release notes and changelog of Hitman Pro 3.5.9 build 124 can be found on <a title="Hitman Pro changelog" href="http://www.surfright.com/hitmanpro/whatsnew" target="_blank">www.surfright.com/hitmanpro/whatsnew</a>.</p>
<p>Existing users of Hitman Pro will automatically be updated to the latest version in the next few days.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/325/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/325/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=325&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/06/16/hitman-pro-3-5-9-build-124-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/97697d653b19f6873ebc05a3c6e51e43?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertw</media:title>
		</media:content>
	</item>
		<item>
		<title>Cloud Assisted Miniport Hook Bypass</title>
		<link>http://hitmanpro.wordpress.com/2011/06/16/cloud-assisted-miniport-hook-bypass/</link>
		<comments>http://hitmanpro.wordpress.com/2011/06/16/cloud-assisted-miniport-hook-bypass/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 13:31:16 +0000</pubDate>
		<dc:creator>Erik Loman</dc:creator>
				<category><![CDATA[Release]]></category>
		<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=294</guid>
		<description><![CDATA[The toughest types of malware are rootkits. Rootkits embed themselves deep in the operating system where they hide for antivirus software. The longer a rootkit stays alive on a computer, the more profit the malware authors make because the computer is under their control. Highly advanced rootkits like the TDSS family (TDL, Alureon.DX, Olmarik) and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=294&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The toughest types of malware are rootkits. Rootkits embed themselves deep in the operating system where they hide for antivirus software. The longer a rootkit stays alive on a computer, the more profit the malware authors make because the computer is under their control.</p>
<p>Highly advanced rootkits like the TDSS family (TDL, Alureon.DX, Olmarik) and new variants of Mebroot and Sinowal work on both 32-bit and 64-bit versions of Windows and infect the Master Boot Record (MBR). This means that these so called Bootkits start before Windows boots up, which gives the bootkit an obvious advantage. Any protection mechanism imposed by Windows (or antivirus that is loaded by Windows) can be defeated (the program that is started first, can have control over the others).</p>
<p>Once Windows is booting, the rootkit attaches a filtering mechanism to the hard disk driver. This filter gives the rootkit complete control over the hard drive. For example, when an antivirus tries to read the MBR (sector 0) of the hard drive (to see if it is infected), the rootkit will simply serve a regular MBR so that it appears that the MBR is clean. Hence, the rootkit is undetected.</p>
<p>Now in order to read the actual infected MBR you need get around the rootkit’s filtering mechanism.</p>
<p>For this you need to know two things:</p>
<ol>
<li>The hard disk miniport driver that is hooked <em>(e.g. atapi.sys, iaStor.sys, nvstor32.sys, amdsata.sys, etc.)</em></li>
<li>How the rootkit is hooking into it</li>
</ol>
<p>When you know the exact hard disk driver that is in use, you are able to communicate directly with it, reading around the hooks of the rootkit.</p>
<p>The problem is that there are literally thousands of different brands, types and versions of hard disk drivers and they all need to be addressed differently. This is where Cloud Assisted Miniport Hook Bypass comes in.</p>
<p><strong>Cloud Assisted Miniport Hook Bypass</strong> collects hard disk miniport driver information from clean computers and stores a representation of this information (a fingerprint of a few bytes) in the Cloud. When Hitman Pro detects a hook on the hard disk driver, it consults the Cloud on how to work around it. This allows Hitman Pro to read around the rootkit’s filtering and effectively reading the actual infected sectors. This works for ANY hard disk driver and not just the common ones.</p>
<p>If you run Hitman Pro with Early Warning Scoring (a mode for experts) on a Mebroot infected system you can see Cloud Assisted Miniport Hook Bypass in action. If the yellow sticky mentions <em>bypassed</em> then Hitman Pro should be able to detect presence of the rootkit:</p>
<p style="text-align:center;"><a href="http://hitmanpro.files.wordpress.com/2011/06/camhb.png"><img class="size-full wp-image-295 aligncenter" title="Cloud Assisted Miniport Hook Bypass in action" src="http://hitmanpro.files.wordpress.com/2011/06/camhb.png?w=450" alt=""   /></a></p>
<p>The yellow sticky only appears in Early Warning Scoring scan. In the Default Scan or Quick Scan the sticky is not displayed because non-expert users have no idea what a kernel-mode hook is. Of course, when an infected MBR is detected it is listed, regardless of the chosen scan.</p>
<p><strong>Cloud Assisted Miniport Hook Bypass</strong> collectively helps Hitman Pro users to combat the toughest malware threat: Rootkits.</p>
<p>Available in Hitman Pro 3.5.9 (or newer).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/294/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=294&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/06/16/cloud-assisted-miniport-hook-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4dbd0777f4d9fb42a2ae295d2be92cdc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">erikloman</media:title>
		</media:content>

		<media:content url="http://hitmanpro.files.wordpress.com/2011/06/camhb.png" medium="image">
			<media:title type="html">Cloud Assisted Miniport Hook Bypass in action</media:title>
		</media:content>
	</item>
		<item>
		<title>1 out of 3 users with up-to-date antivirus software are still infected with malware</title>
		<link>http://hitmanpro.wordpress.com/2011/05/23/1-out-of-3-users-with-up-to-date-antivirus-software-are-still-infected-with-malware/</link>
		<comments>http://hitmanpro.wordpress.com/2011/05/23/1-out-of-3-users-with-up-to-date-antivirus-software-are-still-infected-with-malware/#comments</comments>
		<pubDate>Mon, 23 May 2011 05:55:39 +0000</pubDate>
		<dc:creator>herbertw</dc:creator>
				<category><![CDATA[Statistics]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=290</guid>
		<description><![CDATA[The survey was conducted between January 1st and March 31st 2011 with 489,469 users who scanned their computer using SurfRight&#8217;s Hitman Pro 3 Behavioral Scan. While nearly two thirds of users (320,279) had an up-to-date antivirus program installed, some 169,190 users had not. Of even greater concern was that 101,498 (32 percent) of those with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=290&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The survey was conducted between January 1st and March 31st 2011 with 489,469 users who scanned their computer using SurfRight&#8217;s Hitman Pro 3 Behavioral Scan. While nearly two thirds of users (320,279) had an up-to-date antivirus program installed, some 169,190 users had not. Of even greater concern was that 101,498 (32 percent) of those with the latest antivirus software were found to be infected with malware.</p>
<p>See <a href="http://www.surfright.com/press" target="_blank">www.surfright.com/press</a> for the full results.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/290/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=290&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/05/23/1-out-of-3-users-with-up-to-date-antivirus-software-are-still-infected-with-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/97697d653b19f6873ebc05a3c6e51e43?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertw</media:title>
		</media:content>
	</item>
		<item>
		<title>TDL4 bootkit reinstates 64-bit infection capability</title>
		<link>http://hitmanpro.wordpress.com/2011/05/02/tdl4-bootkit-reinstates-64-bit-infection-capability/</link>
		<comments>http://hitmanpro.wordpress.com/2011/05/02/tdl4-bootkit-reinstates-64-bit-infection-capability/#comments</comments>
		<pubDate>Mon, 02 May 2011 14:07:23 +0000</pubDate>
		<dc:creator>Erik Loman</dc:creator>
				<category><![CDATA[Release]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[TDL3]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=270</guid>
		<description><![CDATA[Microsoft released security update KB2506014 on April 12 to address a vulnerability which allowed unsigned drivers to be loaded by 64-bit Windows. The TDSS/Alureon rootkit family, where TDL4 is a part of, was one of the more advanced rootkits that abused this vulnerability to load the rootkit during Windows boot up. TDL4 is also known as the Google [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=270&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft released security update <a title="Update for the Windows Operating System Loader" href="http://www.microsoft.com/technet/security/advisory/2506014.mspx" target="_blank">KB2506014</a> on April 12 to address a vulnerability which allowed unsigned drivers to be loaded by 64-bit Windows. The TDSS/Alureon rootkit family, where TDL4 is a part of, was one of the more advanced rootkits that abused this vulnerability to load the rootkit during Windows boot up. TDL4 is also known as the Google Redirect Virus.</p>
<p>TDL4 infects the Master Boot Record (MBR) and effectively loads before Windows boot up. This gives so called bootkits the upper hand in countering the protection mechanisms introduced by 64-bit Windows.</p>
<p>We started to see this new variant a few days ago when we received reports that Hitman Pro was no longer able to remove the TDL4 rootkit. Hitman Pro was detecting the presence of the rootkit but it was no longer able to determine its load point, which is needed for the rootkit’s removal. The reports also outline that the few dedicated TDSS removal tools from other vendors were also having difficulties to detect and remove it, which is a clear indication that we are dealing with a new variant.</p>
<p>Key survival strategy for rootkits is that they must be undetectable by antivirus software. TDL4 does so by attaching itself to the hard disk (at the lowest level) and filtering all read/write operations. When antivirus software reads data from the drive, the rootkit just serves clean uninfected data, effectively blinding antivirus and internet security software.</p>
<p>In order to detect the presence of rootkits like TDL4 an antivirus must get around the rootkit’s filtering. Only then the actual infected disk sectors can be read and inspected.</p>
<p>Hitman Pro’s Direct Disk Access technology is specifically made to get around such rootkit techniques by scanning computers at a much deeper level. Many of our first-time users are infected with the TDL4 rootkit, despite up-to-date protection software from renowned security vendors. Even though these vendors frequently write reports about this threat, the rootkit does not appear in any top threat list because most products lack the technology to detect and remove it.</p>
<p>Hitman Pro 3.5.8 build 121 is able to detect and remove the latest TDL4 bootkit variant. A beta version can be downloaded from here:</p>
<p><strong>32-bit</strong>: <a href="http://dl.surfright.nl/HitmanPro35beta.exe">http://dl.surfright.nl/HitmanPro35beta.exe</a><br />
<strong>64-bit</strong>: <a href="http://dl.surfright.nl/HitmanPro35beta_x64.exe">http://dl.surfright.nl/HitmanPro35beta_x64.exe</a></p>
<p><strong>Changelog (Build 121)</strong></p>
<ul>
<li>Added detection and removal of latest TDL4 bootkit</li>
<li>Improved behavioral scan</li>
<li>Improved removal engine</li>
<li>Added Indonesian language</li>
<li>Updated Czech language</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/270/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=270&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/05/02/tdl4-bootkit-reinstates-64-bit-infection-capability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4dbd0777f4d9fb42a2ae295d2be92cdc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">erikloman</media:title>
		</media:content>
	</item>
		<item>
		<title>Sitecom and SurfRight release Sitecom Cloud Security</title>
		<link>http://hitmanpro.wordpress.com/2011/04/01/sitecom-and-surfright-release-sitecom-cloud-security/</link>
		<comments>http://hitmanpro.wordpress.com/2011/04/01/sitecom-and-surfright-release-sitecom-cloud-security/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 14:32:17 +0000</pubDate>
		<dc:creator>surfright</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hitmanpro.wordpress.com/?p=257</guid>
		<description><![CDATA[SurfRight and Sitecom have released Sitecom Cloud Security, a unique and innovative security service that protects all devices in a home network against cyber crime. Sitecom Cloud Security is integrated in the new Pure E-motion &#124; X-serie 2.0 gigabit (modem) routers of Sitecom. The router checks each URL request and each file download through our [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=257&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>SurfRight and Sitecom have released Sitecom Cloud Security, a unique and innovative security service that protects all devices in a home network against cyber crime. Sitecom Cloud Security is integrated in the new Pure E-motion | X-serie 2.0 gigabit (modem) routers of Sitecom.</p>
<p>The router checks each URL request and each file download through our servers on the Internet (the Cloud) after the service is activated. The user does not need to install anything. Dangerous websites are blocked by the router including phishing sites and sites that are hosting viruses or other malicous content. Users are also protected against downloading files that contain viruses, spyware or other malware. The service can also block advertisement that will improve browsing experience and will load web site content faster. Sitecom Cloud Security is powered by the proven technology of Hitman Pro.</p>
<p>See <a href="http://www.surfright.com/home/press/sitecom-cloud-security" target="_blank">www.surfright.com/home/press/sitecom-cloud-security</a> for more details.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hitmanpro.wordpress.com/257/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hitmanpro.wordpress.com/257/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hitmanpro.wordpress.com/257/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hitmanpro.wordpress.com&amp;blog=12016419&amp;post=257&amp;subd=hitmanpro&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hitmanpro.wordpress.com/2011/04/01/sitecom-and-surfright-release-sitecom-cloud-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f4ccfaabfe9001fcfae185cd1f2cea9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">surfright</media:title>
		</media:content>
	</item>
	</channel>
</rss>
