HomeinetMalware exploits Windows restriction policies

Malware exploits Windows restriction policies

Researchers from Trend Micro have discovered BKDR_VAWTRAK, a banking malware. The malware uses Windows Software Restriction Policies (SRP) to restrict the privileges of security software, including Trend Micro. 

malware

SRP is a feature added to Windows XP and Windows Server 2003 and managed through Group Policy. It is designed to allow administrators to blacklist or whitelist specific executable programs, or to restrict non-privileged users.

Of course, this is not the first time that SRP has been used by malware.

SRP can also be used for Local Policy Editor in any version of Windows:
srp

Now that these policies are translated into registry keys on the systems they are used for, it is possible to create registry keys directly, which Trend Micro reports is what the malware does. In the example above, the registry keys created are shown in HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers.

When the user tries to run the executable file, it is blocked by Windows:

srp-

This allows the malware to take control of the computer, executing only the files it wants. Potentially, up-to-date security software could find the malware, but the malware has blocked it.

Ironically, Microsoft's TechNet describes SRP on the day it was released (in 2002) how it can be used to "fight viruses." Microsoft for ever!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS