BitDefender Antivirus

BitDefender Antivirus Plus  v10




 Purchased the wrong product/the wrong number of users
the refund policy in case there was purchase the wrong product or a license key with the wrong number of users.

 The Refund Policy
refund policy if purchased too many copies

 BitDefender releases the Downadup removal tool
Short description of the Downadup/Conficker/Kido behaviour:

1. It creates files autorun.inf and RECYCLED\{SID<....>}\RANDOM_NAME.vmx on removable drives and on public network shares

2. It stores itself in the system as a DLL-file with a random name in c:\windows\system32\

3. It registers itself in system services with a random name, creating the following service:

Name: netsvcs

ImagePath: %SystemRoot%\\system32\\svchost.exe -k netsvcs

Then the worm creates the following registry entry:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters\"ServiceDll" = "[PathToWorm]"

4. The worm deletes any user-created System Restore points.

5. It tries to attack network computers via random ports, using Microsoft Windows vulnerability MS08-067. The worm then creates a http server on the compromised computer on a random port, for example:

http://[EXTERNAL IP ADDRESS OF INFECTED MACHINE]:[RANDOM PORT]

6. Upon successful exploitation, the other computer will then connect to this URL and download the worm spreading the infection.

7. Downadup then contacts several domains and tries to download additional files onto the compromised computer.



 Filename Format String Vulnerability
The vulnerability is caused due to a format string error when generating the scan report file. This can potentially be exploited to execute arbitrary code when a file or directory containing format string specifiers in its name (e.g. %.8X%.8X) is scanned.

Showing articles from 31 to 34 of 34

Page 1   Page 2   Page 3   Page 4