<?xml version="1.0"?>
<rss version="2.0"><channel><title>News of Doctor Web</title><link>http://news.drweb.com/news/</link><description>Doctor Web news - News of Doctor Web</description><image><url>http://www.av-desk.com/static/drweb_logo_en.gif</url><link>http://news.drweb.com/news/</link><title>Dr.Web anti-virus</title></image><item><title>Centrally managed Dr.Web software boasts higher speed and unique detection technologies</title><link>http://news.drweb.com/show/?i=2431&amp;lng=en&amp;c=5</link><pubDate>Wed, 16 May 2012 17:17:14 GMT</pubDate><description>&lt;p class="b"&gt;May 16, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has updated the Dr.Web Virus Finding Engine to version 7.0 for Dr.Web Enterprise Security Suite, supporting centralized management.&lt;/newslead&gt; The update will be downloaded and installed automatically by solutions with server versions 6.0.3 and 6.0.2. Dr.Web Virus Finding Engine won't be updated if the server version is earlier than 6.0.2.&lt;/p&gt;
&lt;h4&gt; Increased scanning speed&lt;/h4&gt;
&lt;p&gt;A significant boost in scanning speed is one of the key new engine advantages that will be appreciated by users. Dr.Web Virus Finding Engine showed a several-fold increase in speed compared with the previous engine when tested on a 3 terabyte test file collection in Doctor Web's anti-virus lab. A four-fold speed boost was demonstrated on test systems similar to present-day desktop computers. The new virus database format and improved object scanning algorithm allowed the engine to achieve such an impressive result.&lt;/p&gt;
&lt;h4&gt;Performance &lt;/h4&gt;
&lt;p&gt;Another key advantage of the new engine is its dynamic memory allocation that takes into account the overall system performance and current load. The memory is allocated in real time, so scanning and unpacking large files does not slow down other applications. The new engine has also been optimized for multi-core systems.&lt;/p&gt;
&lt;h4&gt;ScriptHeuristic and other detection technologies &lt;/h4&gt;
&lt;p&gt;With the new ScriptHeuristic technology, Dr.Web Virus Finding Engine can quickly identify malicious objects in HTML and PDF documents—the most common sources of virus threats. Routines for extraction and analysis of hidden IFRAME have also been introduced. The signature-based scan takes into account JavaScript syntax.&lt;/p&gt;
&lt;p&gt;The structure entropy technology implemented in the new anti-virus engine is truly unique and serves as an alternative to the signature-based search. It significantly improves malware detection.&lt;/p&gt;
&lt;p&gt;The optimization of the universal extraction technology FLY-CODE, already used in other Dr.Web products, reduces scanning time by nearly one-third. New heuristic analysis algorithms ensure nearly 100% probability for detection of well disguised Trojan horses. An enhancement in Origins Tracing™ allows it to be used to scan DEX-files (Android).&lt;/p&gt;
&lt;p&gt;The update will be downloaded and installed automatically.&lt;/p&gt;</description></item><item><title>Single-user Dr.Web 7.0 Products for Windows Updated</title><link>http://news.drweb.com/show/?i=2438&amp;lng=en&amp;c=5</link><pubDate>Wed, 16 May 2012 00:00:00 GMT</pubDate><description>&lt;p class="b"&gt;May 16, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has released an update for the Scanning Engine service implemented in single-user products Dr.Web Anti-virus and Dr.Web Security Space 7.0.&lt;/newslead&gt;&lt;/p&gt;
&lt;p&gt;This update resolves a Scanning Engine error which may occur in Windows versions for East Asian countries.&lt;/p&gt;
&lt;p&gt;The update will be automatically downloaded by the anti-viruses but applying the update will require a system reboot.&lt;/p&gt;
</description></item><item><title>New worm infects RAR archives</title><link>http://news.drweb.com/show/?i=2440&amp;lng=en&amp;c=5</link><pubDate>Tue, 15 May 2012 00:00:00 GMT</pubDate><description>&lt;p class="b"&gt;May 15, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;The Russian IT security company Doctor Web is informing users about the worm &lt;vir&gt;Win32.HLLW.Autoruner.64548&lt;/vir&gt;, which can infect RAR archives. It can download executables files from a remote server to perform malicious tasks in the compromised system.&lt;/newslead&gt;&lt;/p&gt;
&lt;p&gt;&lt;vir&gt;Win32.HLLW.Autoruner.64548&lt;/vir&gt; spreads as many other worms do: it creates its copy on a disk and places the file autorun.inf into the root directory to launch the worm as soon as the device is connected to the computer. When launched on the infected computer, &lt;vir&gt;Win32.HLLW.Autoruner.64548&lt;/vir&gt; searches disks for RAR archives and places itself into them under one of the following names: secret.exe, AVIRA_License.exe, Warcraft_money.exe, CS16.exe, Update.exe, private.exe, Autoruns.exe, Tutorial.exe, Autorun.exe, Readme.exe, Real.exe, readme.exe, Keygen.exe, or Avast_keygen.exe. In some cases, such a modification damages archives.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/Autoruner.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/Autoruner.1.png"&gt;&lt;/a&gt;&lt;/p&gt;
 
&lt;p&gt;In addition, the worm has a payload module. Its body also contains an executable file that &lt;vir&gt;Win32.HLLW.Autoruner.64548&lt;/vir&gt; saves into the Windows folder as mssys.dll. The malicious program registers the library file in the registry. The worm injects the payload code into a copy of its own process. Then the malware connects to a remote server and waits for malicious commands to download and run executable files.&lt;/p&gt;
&lt;p&gt;&lt;vir&gt;Win32.HLLW.Autoruner.64548&lt;/vir&gt; represents a rare category of malicious programs that can infect RAR archives. When unpacking RAR archives, pay attention if suspicious executable files appear in the archive: their accidental launch may harm your computer. The worm's signature has been added to the Dr.Web virus databases.&lt;/p&gt;</description></item><item><title>Dr.Web CureIt! 7.0 beta testing launched</title><link>http://news.drweb.com/show/?i=2401&amp;lng=en&amp;c=5</link><pubDate>Mon, 14 May 2012 13:47:57 GMT</pubDate><description>&lt;p class="b"&gt;May 14, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has released a public beta version of its utility Dr.Web CureIt! 7.0.&lt;/newslead&gt; Dr.Web CureIt! is a popular malicious-software-removal- and system-curing tool combining all the advantages of the alternative commercial products offered by other vendors. The enhanced mode, designed to counter Windows locker programs, and compatibility with other anti-viruses are the key features of this application. This utility incorporates the latest IT security technologies that enable it to neutralize even the most dangerous threats. &lt;/p&gt;
&lt;p&gt;Dr.Web CureIt! 7.0 is not just another update of the popular product but a brand-new generation of a renowned anti-virus security tool. The seventh version features multi-thread scanning and takes full advantage of multi-core systems. The utility is optimized for use with the latest operating systems, which not only allows the scan speed to be increased, but also makes the user experience more comfortable. The stability has also improved significantly. Now it is virtually impossible for the utility to cause a system failure and bring up a BSOD (Blue Screen of Death).&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/screen/en_cureit_scr_004.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/screen/en_cureit_scr_004.1.png" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The seventh version of the curing utility also features a revamped user interface. The program also incorporates an anti-rootkit component that has already been used in versions 7.0 of Dr.Web Anti-virus and Dr.Web Security Space. It  offers new custom scan options to users: now one can individually perform a memory test, scan boot sectors and start-up objects, etc. The seventh version can block a network connection while scanning and shut down the system upon completion.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/screen/en_cureit_scr_007.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/screen/en_cureit_scr_007.1.png" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The application is also able to scan PCs for BIOS kits. Doctor Web recommends that users scan their computers with the seventh version of the curing utility to make sure no new types of malware hide in their system. If you wish to participate in the beta testing, you can download Dr.Web CureIt! 7.0 beta from the &lt;a href="https://www.freedrweb.com/download+cureit+free/beta/"&gt;site&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Dr.Web for Qbik WinGate updated</title><link>http://news.drweb.com/show/?i=2425&amp;lng=en&amp;c=5</link><pubDate>Mon, 14 May 2012 14:14:52 GMT</pubDate><description>&lt;p class="b"&gt; May 14, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has released Dr.Web for Qbik WinGate 6.00.1.&lt;/newslead&gt; The updated build incorporates the Dr.Web Virus Finding Engine and virus database version 7.0, the latest version of the Scanning Engine service and other improvements. &lt;/p&gt;
&lt;p&gt;Dr.Web Virus Finding Engine 7.0 features new malware detection technologies, such as file structure entropy analysis and ScriptHeuristic which enables the anti-virus to detect and neutralize threats embedded in HTML and PDF documents. Other key advantages of the new engine are a manifold increase in scanning speed and dynamic memory allocation that takes into account system performance and current load. The signature-based scan takes into account JavaScript syntax.&lt;/p&gt;
&lt;p&gt;In addition, the anti-spam adds the Dr.Web-SpamREason field containing the e-mail's spam score to the headers of unsolicited messages. A minor issue that caused errors when checking traffic has been resolved. An issue where the wrong path to updated virus databases was written into the Dr.Web's ini file has also been resolved.&lt;/p&gt;
&lt;p&gt;To install Dr.Web 6.00.1 for Qbik WinGate, you need to remove the current version manually and use the updated distribution to install the latest version.&lt;/p&gt;</description></item><item><title>Win32.Rmnet.16 attacks UK and Australia</title><link>http://news.drweb.com/show/?i=2434&amp;lng=en&amp;c=5</link><pubDate>Mon, 14 May 2012 10:56:43 GMT</pubDate><description>&lt;p class="b"&gt;May 14, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;In April 2012 the Russian IT security company Doctor Web &lt;a href="http://news.drweb.com/?i=2374&amp;c=23&amp;lng=en&amp;p=0"&gt;already reported&lt;/a&gt; that a botnet created by hackers using the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; virus exceeded one million infected hosts. Doctor Web's virus analysts have recently noted the spread of the new virus’s modification dubbed &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt;.&lt;/newslead&gt; Its main difference from the previous version is a digital signature used to sign a control server IP-address. The virus makers also updated the virus's functional modules. The vast majority of infection incidents involving &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; occured in the UK and Australia.&lt;/p&gt;
&lt;p&gt;&lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; is written in C and Assembly and consists of several functional modules. The injector that deploys the virus in the system works in exactly the same way as that of &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;: it injects its code into browser processes, saves its driver into a temporary folder and runs it as a Micorsoft Windows Service, then copies the virus body into a temporary directory and startup folder. The body file has a random name and the extension. exe.&lt;/p&gt;
&lt;p&gt;The backdoor payload is also similar to that of &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;. This component can execute commands received from a remote server, in particular, to download and run arbitrary files, update itself, to take screenshots and send them to criminals, and even render the operating system non-operational. However, there are also important differences: &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; uses a digital signature to sign control server IP-addresses which are no longer embedded in the malicious application resources but generated using a special routine. In addition, the module can end processes of the majority of popular anti-virus programs, which makes the malware even more dangerous. Malicious components and configuration files downloaded by the backdoor are stored in an encrypted file with the extension .log while the file name is generated using information about the compromised system. This file is located in the folder% APPDATA%. The module implemented in the modules.dll file loads data from the file with the extension. log and performs all the manipulations with the loaded code in the computer's memory, so the components' code is not decrypted onto the hard drive.&lt;/p&gt;
&lt;p&gt;Like its predecessor, &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; can modify the MBR and encrypt and save its files at the end of the disk. After rebooting, control is transferred to malicious code in the infected boot record, which reads and decrypts modules in the memory and then runs them. This component of the malicious program is dubbed &lt;vir&gt;MBR.Rmnet.1&lt;/vir&gt;. It should be noted that the Dr.Web anti-virus software can restore a boot record, modified by &lt;vir&gt;Win32.Rmnet&lt;/vir&gt;.&lt;/p&gt;
&lt;p&gt;Modules downloaded by &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; from remote command centers also include  Ftp Grabber v2.0, designed to steal passwords stored by popular FTP-clients, its own FTP-server and a spy module.&lt;/p&gt;
&lt;p&gt;The Infection module incorporated into the new version is polymorphic. It is downloaded from a remote site maintained by intruders. The virus infects all exe and dll files found on the disks, including system ones, but, unlike &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;, can not copy itself to removable flash drives.&lt;/p&gt;
&lt;p&gt;Doctor Web virus analysts closely monitor operation of one of the &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; botnets. As of May 11, 2012, this botnet included 55,310 infected hosts and 55.9% of compromised machines are located in the UK. Australia comes second with 40% , the United States and France divide the third place (1.3%) , less than 1% of infected computers are located in Austria, Iran, India and Germany. London accounts for the greatest number of &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; infection incidents (5747 infected PCs, or 10.4%), Sydney ranks second (3120 computers, or 5.6%), followed by Melbourne (2670 cases of infection, or 4.8%), Brisbane (2323 PCs, or 4.2%), Perth (1481 PCs, or 2.7%) and Adelaide (1176 PC, or 2.1%). Around 1.5 of infected hosts are found in Birmingham and Manchester in Britain.  The figure below shows distribution of hosts infected by &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; across the world.&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/pic.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/pic.1.png" alt="The spread of the botnet Win32.Rmnet.16 by country" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align:center" class="em"&gt;The spread of the botnet &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; by country&lt;/p&gt;
&lt;p&gt;In Russia the cases of infection by &lt;vir&gt;Win32.Rmnet.16&lt;/vir&gt; still are rare, but over time this may change. Doctor Web continues to closely monitor activity of the botnet.&lt;/p&gt;</description></item><item><title>Dr.Web Virus Finding Engine Updated</title><link>http://news.drweb.com/show/?i=2436&amp;lng=en&amp;c=5</link><pubDate>Mon, 14 May 2012 00:00:00 GMT</pubDate><description>&lt;p class="b"&gt;May 14, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has updated its Dr.Web Virus Finding Engine to version 7.0.2 incorporated into Dr.Web Anti-virus and Dr.Web Security Space 6.0 and 7.0, Dr.Web Desktop Security Suite, Dr.Web Server Security Suite (except for Dr.Web for Novell Netware file servers), Dr.Web Mail Security Suite, Dr.Web Gateway Security Suite without the Control Center, Dr.Web AV-Desk Internet service, Dr.Web CureIt! and Dr.Web CureNet! as well as Dr.Web LiveCD/LiveUSB system recovery tools.&lt;/newslead&gt;&lt;/p&gt;
&lt;p&gt;Now, the updated engine includes the procedure of heuristic analysis of the disk boot sectors. Bugs related to memory leaks as well as problems occurring when scanning apk (dex) and bzip2 files have been fixed.&lt;/p&gt;
&lt;p&gt;The update will be downloaded and installed automatically.&lt;/p&gt;</description></item><item><title>A New Facebook Scam to Threaten Users</title><link>http://news.drweb.com/show/?i=2421&amp;lng=en&amp;c=5</link><pubDate>Sat, 05 May 2012 14:47:19 GMT</pubDate><description>&lt;p class="b"&gt;May 5, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web, a Russian IT security vendor, warns about a new scheme of scam and fraud to emerge in Facebook, the world's most popular social network. Attackers have adopted the scheme notoriously known to Russian participants of Vkontakte and Odnoklassniki social networks, and created a special application for Facebook called Profile Visitor, which requests access to a user's wall, promising to show the list of those who visited his page.&lt;/newslead&gt; But in fact, this application posts a picture containing a link to the fraudulent website instead. In their turn, the victim's friends on Facebook are notified that they are alleged to have been marked in this picture, which extends the spread of the malicious link.&lt;/p&gt;
&lt;p&gt;When visiting his page on Facebook, a user can have a look at the news feed and find a link to the Profile Visitor allegedly capable of recording and showing visitors of his profile on a special web page. As a rule, that link is published on behalf of a friend of the user, and leads to a Facebook embedded application page. To activate the application, it needs to be allowed to publish content on behalf of the user account. As soon as an unsuspecting victim clicks Allow, a link to the application posted on his behalf will appear on the wall of his profile and in the news feed of all of his friends as well. However, even if the user does not allow Profile Visitor to publish anything on his behalf, everyone who is registered in the list of his friends, will be automatically marked in a "picture", which is actually a Profile Visitor banner link. A notification of the event will be automatically sent out to the contact list on Facebook.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/fbook_01_en.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/fbook_01.1_en.png" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;After that, the victim's browser will automatically open a malicious web page that contains a dynamically changing array of links. Clicking on any of them, the user will be redirected to a variety of fraudulent websites whose content depends on the visitor's IP address. For example, some of them require your credit card details to allow access to the information, while others want you to enter your own phone number into a special form, and then type a code received in a reply SMS in the corresponding field. This method is mostly practiced in regards of Russian-speaking visitors: that's how scammers sign up a victim to a kind of a paid "information service", for the provision of which a certain amount will be debited from a victim's account on a monthly basis.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/fbook_02.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/fbook_02.1.png" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;By clicking on fraudulent links you can get to resources containing pseudo draws promising a variety of prizes, online casinos, psychological tests, individual diet selection services, etc. All of these sites are automatically blocked by the Dr.Web SpIDer Gate filter embedded in Dr.Web products.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/fbook_03.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/fbook_03.1.png" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/may/fbook_04.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/may/fbook_04.jpg" alt="screen" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Previously, these scams have been repeatedly used towards Russian users of Vkontakte and Odnoklassniki social networks, but now network crooks apparently decided to pay attention to residents of foreign countries. Doctor Web strongly recommends Facebook users not install Profile Visitor and not click on the links with this application, which are published in their news feeds, as well as always be cautious and circumspect.&lt;/p&gt;</description></item><item><title>April 2012 Virus Survey: the first ever large-scale botnet for the Mac OS X, the millionth botnet for Windows and the invasion of Trojan coders in Europe</title><link>http://news.drweb.com/show/?i=2415&amp;lng=en&amp;c=5</link><pubDate>Wed, 02 May 2012 17:32:26 GMT</pubDate><description>&lt;p class="b"&gt;May 2, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Users will remember April 2012 as the most intense month in terms of events related to information security threats. In the early month, the Doctor Web experts discovered the first ever large-scale botnet consisting of computers running the Mac OS X operating system.&lt;/newslead&gt; A little later, Doctor Web announced that it took control over the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; botnet, which incorporated more than one million infected computers. In the second half of April, the invasion of Trojan encoders began that first concerned Western Europe inhabitants, and later on — users around the world. These and other significant April events will be reviewed in this survey.&lt;/p&gt;

&lt;h3&gt;Macs under attack globally&lt;/h3&gt;
&lt;p&gt;The first botnet in the history that was created by hackers using &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; malware, literally struck more than 800,000 computers running Mac OS X, and figuratively — numerous informational web portals and a large number of mass media. The news quickly spread all over the world, becoming a sensation.&lt;/p&gt;

&lt;p&gt;Back in late March the Doctor Web virus laboratory received the first reports that the attackers were actively using known Java vulnerabilities to spread malware for Mac OS X. Since this information came with some regularity and from various sources, it was suggested that the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; Trojan that uses Java vulnerabilities can form a botnet on Apple-compatible computers. This malware, like so many other similar ones, has a built-in algorithm for selection of domain names, which are then used by the Trojan as control servers: such an approach, firstly, can significantly increase the network "survivability", and secondly, redistribute the load efficiently between command centers in a timely manner, if the traffic generated by bots exceeds some critical values. On the other hand, this provides an opportunity for information security professionals to "reveal" the method the Trojan is using to choose control centers, and to create a "fake" command server to gather necessary statistics, or even seize control over the network. This approach is called the "sinkhole" and is widely used in anti-virus practices. To test the hypothesis that a botnet running on the Mac OS X platform exists, on April 3, 2012, Doctor Web experts registered a number of &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; control servers domains. Nobody had expected at that time to detect the biggest ever botnet for Mac OS X, given the high reliability and architectural features of this operating system that ensure relative safety for users. However, the reality surpassed all expectations: during the very first hours, Doctor Web-controlled servers recorded activities of more than 130,000 bots; by the morning, their number reached 550,000, and control centres just ceased to process the load. On April 4, 2012, Doctor Web &lt;a href="http://news.drweb.com/show/?i=2341&amp;c=0&amp;p=0&amp;lng=en"&gt;published a press release&lt;/a&gt; to announce the discovery of the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; botnet. This was a real bombshell announcement, being quoted by many authoritative world news agencies and other media within just 24 hours.&lt;/p&gt;

&lt;p&gt;Two simple conditions must be met for a system to get infected with &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;: Java Virtual Machine must be installed in the system, and a user must load a compromised webpage in the browser. These are specifically designed malicious webpages, and compromised resources which virus writers have access to. Malicious code on such a web page loads a Java applet. The applet exploits a Java vulnerability and saves an executable and a .plist file responsible for its launching on the hard drive of the Apple computer. After that, the applet transfers the saved configuration file to the &lt;em&gt;launchd&lt;/em&gt; service that allows it to run the Trojan without user intervention. In fact, users notice nothing at all — they are viewing webpages in their browsers while their Macs are already infected with malware.&lt;/p&gt;

&lt;p&gt;Initially, Doctor Web had information only about some part of botnet that used the modified &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; Trojan, but already on April 16 additional domains whose names are generated based on the date were registered. Since those domains are used by all the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; subversions, the registration of additional domains for control servers allowed to more accurately estimate the malicious network size. Most infected computers reside in the United States (56.6% of infected hosts), Canada comes second (19.8% of infected computers), the third place is taken by the United Kingdom (12.8% infection cases), and Australia with 6.1% is the fourth.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/map2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/map2.1.png"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;On April 4, 2012, Apple released an update to Java to fix a vulnerability used by the &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; Trojan. However, if a computer has already been infected before, the update does not protect a user from malware. Shortly afterwards, the number of infected Macs exceeded 800,000. In spite of this, just a few days later, numerous computer security experts reported a significant reduction in the number of &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; hosts. The joy turned to be premature though: Doctor Web conducted an investigation and found out that there had been an unfortunate error in the experts' calculations. &lt;/p&gt;

&lt;p&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;  uses a sophisticated routine to generate control server names: a larger part of the domain names is generated using parameters embedded in the malware resources, others are created using the current date. The Trojan performs sends consecutive queries at the generated addresses according to its pre-defined priorities. The main domains for &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; command servers were registered by Doctor Web at the beginning of April, and bots first send requests using these names. However, after communicating with servers controlled by Doctor Web, Trojans send requests to the server at 74.207.249.7, controlled by an unidentified third party. This server communicates with bots but doesn't close a TCP connection. As the result, bots switch to the standby mode and wait for the server's reply and, as a consequence, they do not communicate with other command centers, many of which have been specially registered by information security experts. That is why different anti-virus companies delivered contradictory statistics — on the one hand, Symantec and Kaspersky Lab claimed a significant reduction in the number of bots, while on the other hand, data provided by Doctor Web consistently pointed to a significantly larger number of infected computers, with a very weak trend to reduce. The real BackDoor.Flashback.39 growth progress is presented on the chart below:&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/grafik_map_Flashback_en.png"&gt;&lt;img src="https://st.drweb.com/static/new-www/news/2012/april/grafik_map_Flashback_small_en.png" alt="" width="640"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As of April 28, 2012, the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; network had a total of 824,739 bots registered, 334,592 of which were active. &lt;/p&gt;

&lt;p&gt;A file that is downloaded by the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; Trojan on infected computers is of particular interest. This malicious application can be run with administrator privileges or an ordinary user (at the time the payload is applied, the Trojan displays a dialog box for the administrator password to be entered on a Mac screen) and utilizes two types of control servers. Servers belonging to the first group intercept web search traffic and redirect a user to malicious sites controlled by criminals. The second group issues commands to bots to perform backdoor tasks in the compromised system. Doctor Web analysts managed to take over control server domain names known to &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; payload malware and analyse requests sent by bots to servers.&lt;/p&gt;

&lt;p&gt;The first group of control domains is generated using the list found in its configuration data; in addition, another domain name list is generated where resulting names are determined by the current date. The second level domain name is the same, while a top-level domain name can be org,. com,. co.uk,. cn,. in. The Trojan horse sends consecutive requests to control servers according to its generated list. An /owncheck/ or /scheck/ GET request sent to a server contains the infected Mac's UUID in the useragent field. If the reply contains a SHA1 hash value of  the domain name, this domain will be considered as trusted and from the moment on will be used as a command server name. First domains in this category have been successfully taken over by Doctor Web since April 12, 2012.&lt;/p&gt;

&lt;p&gt;Once the malicious program has determined a domain of the first category, it begins to search for a second type domain. The bot uses the list found in its configuration data to send the /auupdate/ GET-request to a number of control servers. The useragent field in these requests contains detailed information on the infected system. If the control server does not return a correct reply, the Trojan uses the current date to generate a string that serves as a hash tag in a search using the address http://mobile.twitter.com/searches?q = # &amp;lt;string&amp;gt;. If the Trojan manages to find a Twitter message containing &lt;em&gt;bumpbegin&lt;/em&gt; and &lt;em&gt;endbump&lt;/em&gt; tags enclosing a control server address, it will be used as a domain name. Doctor Web began to take over domains of this category on April 13, but on the following day, Saturday, April 14, the Twitter account registered by Doctor Web analysts for this purpose was blocked. &lt;/p&gt;

&lt;p&gt;As of April 13, 2012, 30,549 requests containing a UUID were sent to control servers of the first domain name category in 24 hours and 28,284 requests containing a UUID were transmitted to control servers of the second domain name category in the same period of time. Total 95,563 requests containing a UUID were sent to servers meant to control BackDoor.Flashback payload from April 12 till 26, 2012. Below are graphs showing statistics gathered by Doctor Web experts. The data are based on the analysis of daily hits of the &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; botnet payload to the control server on April 13, 2012.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/circle_Platform_en_2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/circle_Platform_en_2.1.png" alt="graph"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/linear_Core_en_39.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/linear_Core_en_39.1.png" alt="graph"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/linear_UUID_en_11.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/linear_UUID_en_11.1.png" alt="graph"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/circle_Admin_en_2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/circle_Admin_en_2.1.png" alt="graph"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Shortly after the &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; was detected, Doctor Web created a special &lt;a href="https://drweb.com/flashback/?lng=en"&gt;information website&lt;/a&gt;dedicated to this threat. On this online resource, owners of Apple-compatible computers can scan their Macs for infection. On the same resource, you can find additional materials and a video presentation on the &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; Trojan, as well as links to a free scanner for Mac OS X that allows you to scan the operating system and delete the Trojan, if detected. Doctor Web is keeping a close eye on any further developments.&lt;/p&gt;

&lt;h3&gt;Meet Rmnet — another botnet&lt;/h3&gt;
&lt;p&gt;According to statistics available to Doctor Web, one of the leading places among threats that infect Microsoft Windows workstations, is now occupied by the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; file virus. The virus spreads in various ways, in particular, by exploiting browser vulnerabilities that enable intruders to save and launch executables upon loading webpages. The virus searches for all html files stored on disks and embeds VBScript code into them. Besides, Win32.Rmnet.12 infects all executable files with the .exe extension found on the disks, and is able to replicate itself to removable flash drives. It saves an autorun file and a shortcut to a malicious application into the root folder. This application, in its turn, launches the virus.&lt;/p&gt;

&lt;p&gt;&lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; is a complex multicomponent virus consisting of several modules and capable of self-replication. One of the virus components is a backdoor. Once launched, it tries to determine the Internet connection speed by sending requests to google.com, bing.com and yahoo.com every 70 seconds and analysing responses. Then &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; launches an FTP server on the infected machine, connects to a command center and transmits information about an infected computer. The backdoor can execute commands received from the remote server, in particular, to download and run arbitrary files, update itself, to take screenshots and send them to criminals, and even render the operating system non-operational.&lt;/p&gt;

&lt;p&gt;Another virus component steals passwords fstored by the most popular FTP-clients, such as Ghisler, WS FTP, CuteFTP, FlashFXP, FileZilla, Bullet Proof FTP and others. This information can later be exploited to carry out network attacks or to place various malicious objects on remote servers. Also, &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  takes care to search through user's cookies, so attackers can gain access to the user's accounts at different websites that require authentication. In addition, the module can block access individual sites, and redirect the user to a site controlled by virus writers. One of the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  modifications is also able to make web injections to steal bank account information.&lt;/p&gt;

&lt;p&gt;The botnet comprised of hosts infected with &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; was discovered by Doctor Web as long ago as back in September 2011; soon afterwards, control server names stored in the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; resources were decrypted. After a while, experts analysed the protocol used for communication between bots and control servers which enabled them to determine the number of bots in the network and to control them. On February 14, 2012, Doctor Web's virus analysts succesfully implemented a technoque known as the sinkhole, it was subsequently used to study the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; botnet. Namely, they registered domain names for several servers controlling one of the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; networks and gained full control over that botnet. In late February, another &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; subnet was hijacked this way. Quantatitive dynamics of the botnet controlled by Doctor Web specialists are shown in the chart below.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/graf_1_2_en.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/graf_1_2.1_en.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The greatest number of infected PCs is located in Indonesia comprising 320,014 infected machines, or 27.12%. Bangladesh rates second with 166,172 infected hosts which constitute 14.08% of the botnet size. The third rank is taken by Vietnam (154,415 bots, or 13.08%), followed by India (83,254 bots, or 7.05%), Pakistan (46,802 bots, or 3.9%), Russia (43 153 infected machines, or 3.6%), Egypt (33,261 hosts, or 2.8%), Nigeria (27,877 bots, or 2.3%), Nepal (27,705 bots, or 2.3%) and Iran (23,742 bots, or 2.0%). A sufficiently large number of compromised hosts is found in Kazakhstan (19,773 cases of infection, or 1.67%) and the Republic of Belarus (14,196 bots, or 1.2%). 12,481 compromised hosts, or 1.05% of the total number of &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; bots are located in the Ukraine. A relatively small number of infected computers reside in the U.S. – 4,327 machines, which corresponds to 0.36%. The smallest numbers of compromised hosts are found in Canada (250 computers, or 0.02% of the network's bulk) and Australia (only 46 computers). One infected computer has been found in each of Albania, Denmark, and Tajikistan. &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; botnet geography is shown below.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/map2.jpg" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/map2.mini.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;Encryptors to conquer Europe&lt;/h3&gt;
&lt;p&gt;In April, Europeans had also to face troubles: approximately in the middle of the month, Doctor Web anti-virus lab began to receive reports from foreign users who have suffered from encoder Trojans, and first of all, the &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt; malware. Like other encoders of this family, &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt; searches for user's files, in particular, Microsoft Office documents, music, photos, images and archives on disks available in the infected system, and encrypts them. Once user files are encrypted , the Trojan displays a demand to pay 50 euros or pounds to criminals via Ukash or Paysafecard.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/encoder_screen.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/encoder_screen_450.png" alt="screen"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The Trojan features the English interface, but infections have been registered in Germany, Italy, Spain, England, Poland, Austria, Norway, Bulgaria and other countries. Soon afterwards, alarm reports from residents of Brazil, Argentina and other countries in Latin America started to arrive. The Trojan spread through Europe, including such countries as Croatia, Switzerland, Netherlands, Slovenia and Belgium, France, Hungary and Romania. Doctor Web's engineers managed to decrypt data for virtually all users' requests which indicates the high efficiency of technologies employed for this purpose.&lt;/p&gt;

&lt;p&gt;In late April, a spike distribution of e-mail messages bearing the title "Ute Lautensack Vertrag Nr 46972057" and the attached zip archive with the name of Abrechnung or Rechnung was recorded. Archives contain the Trojan.Matsnu.1 Trojan. Trying to run it leads to the encryption of all the files on the victim's computer disks. Doctor Web experts have analysed Trojan.Matsnu.1 in the shortest time and developed a special utility that allows user data to be decoded. Download this utility for free from &lt;a href="ftp://ftp.drweb.com/pub/drweb/tools/matsnu1decrypt.exe"&gt;ftp://ftp.drweb.com/pub/drweb/tools/matsnu1decrypt.exe&lt;/a&gt;. Remember that if you fell victim to an encoder Trojan, follow these simple guidelines:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Never attempt to solve the problem by reinstallling the operating system.&lt;/li&gt;
	&lt;li&gt;Do not delete any files from the heard drives.&lt;/li&gt;
	&lt;li&gt;Do not try to restore the encrypted data on your own.&lt;/li&gt;
	&lt;li&gt;Contact Doctor Web's anti-virus laboratory and submit a ticket in the Request for curing section. This service is provided free of charge.&lt;/li&gt;
	&lt;li&gt;Attach a file encrypted by the Trojan to the ticket.&lt;/li&gt;
	&lt;li&gt;Wait for a response from a virus analyst. Due to the large number of requests it may take some time.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To minimize the damage from an infection by &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt; and &lt;vir&gt;Trojan.Matsnu.1&lt;/vir&gt; Doctor Web recommends users to timely back up all the files they need for their work.&lt;/p&gt;

&lt;h3&gt;Other "April highlights" and virus threats&lt;/h3&gt;
&lt;p&gt;Compared to what has been described above, all the other information security threats identified and neutralized by Doctor Web experts in April 2012 do not look that sensational and are significantly less dangerous to users. For example, &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt; description has been added to the the virus databases. This malware is designed to steal email client accounts (in particular, from Microsoft Outlook and The Bat!) and transfer data used by the Autocomplete forms feature in web browsers, to attackers. The Trojan spreads over well-known &lt;vir&gt;Backdoor.Andromeda&lt;/vir&gt; botnets.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/dll.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/dll.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt; consists of two components: Delphi-based loader and DLL, which contains a payload. Loader application functions are in general common for this kind of malware: it bypasses a firewall and installs malicious library into the system. Once the library is loaded into an infected computer memory, it takes control of the PC.&lt;/p&gt;

&lt;p&gt;Having control of the PC, the library checks for its own copy on the disk, and writes a value of nine random digits that serves as a unique identifier for the bot, to the system registry. Then the &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt; saves a library to work with SSL, and a zlib library, with which the Trojan compresses its request lines, on the disk. At the same time, the HOST field of requests sent by the bot contains a foreign IP address, which is a characteristic feature of the &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt;. Using a separate dynamic link library to work with zlib and SSL is not also common for malware architectures.&lt;/p&gt;

&lt;p&gt;One of the distinguishing features of the Trojan.Spambot.11349 is that this malware sends a sequence of requests to random IP addresses selected by a special algorithm from a list of subnets stored in the Trojan resources. After that, the &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt; establishes a connection to one of three control servers whose addresses are stored encrypted in the library body, and waits for the configuration file to be received from the server. In case of success, the Trojan creates a request line containing stolen credentials for Microsoft Outlook and The Bat! e-mail clients, packs them with the zlib library and transfers them to a remote server belonging to the attackers. After infecting the system, the &lt;vir&gt;Trojan.Spambot.11349&lt;/vir&gt; checks the possibility to send spam from an infected computer, sending an e-mail message that contains a random set of characters. If the check is successful, the Trojan retrieves data from a remote server for subsequent spamming. As of April 24, the Trojan.Spambot.11349 Trojans sent out emails that contained advertisements for Viagra.&lt;/p&gt;

&lt;p&gt;New threats to the Android mobile operating system also appeared in the past month. Hence, in early April, a family of &lt;vir&gt;Android.Gongfu&lt;/vir&gt; malware was replenished with a new malware instance. An updated modification of the &lt;vir&gt;Android.Gongfu&lt;/vir&gt; was found simultaneously in multiple applications, which were distributed via unofficial software resources. In particular, this Trojan was discovered in a modified Angry Birds Space distribution.&lt;/p&gt;

&lt;p style="text-align: center;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/gonk1.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/gonk1.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Unlike early &lt;vir&gt;Android.Gongfu&lt;/vir&gt; implementations, new versions do not use the Android vulnerability which would allow them to get root privileges in the system without user intervention. Instead, the infected application comes with a step-by-step manual describing how to run the OS with administrator privileges. The manual claims that it is necessary for normal operation of the program and its updating. When launched with administrator privileges &lt;vir&gt;Android.Gongfu&lt;/vir&gt; is able to inject its code into Android system processes including those critical to stable operation of the OS. The Trojan is able not only to convey information about the infected device to criminals and run commands from a remote server, but also covertly download and install other applications.&lt;/p&gt;

&lt;p&gt;In addition, virus writers specialized on mobile platforms began to use the new psychological ploy to spread malicious software — namely, users' concerns about security issues. With the help of various systems that display advertising, attackers show a message for the user to urgently scan a mobile device for viruses. By clicking on this advertising message, the user gets to a site that allegedly scans a mobile device. This site imitates one of the Dr.Web Security Space 7.0 icons and the program appearance. However, by simulating the user interface, the attackers made a mistake in the details: a fake "anti-virus" finds a non-existent threats on a mobile device, such as Trojan.Carberp.60 that belongs to the category of banking Trojans for the Windows, whereas its mobile version does not currently exist. If the user agrees to "neutralize" the threat the &lt;vir&gt;Android.SmsSend&lt;/vir&gt; family Trojan is downloaded to its device.&lt;/p&gt;

&lt;table style="border: 0pt none; width: 100%; text-align: center;"&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td style="width: 50%; padding: 10px;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/SmsSend1.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/SmsSend1.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;td style="width: 50%; padding: 10px;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/SmsSend2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/SmsSend2.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;&lt;td style="padding: 10px;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/SmsSend3.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/SmsSend3.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;td style="padding: 10px;"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/SmsSend4.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/SmsSend4.1.png" alt="screen"&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;All these threats can be successfully detected and neutralized by the Dr.Web anti-virus software, but users are still advised to be careful and not to run programs obtained from unreliable sources.&lt;/p&gt;

&lt;h3&gt;Malicious files detected in mail traffic in April&lt;/h3&gt;
&lt;table class="colborder" align="center" border="1" cellpadding="4" cellspacing="0" width="90%"&gt;&lt;tbody&gt;&lt;tr class="colborder" bgcolor="#deeacc"&gt;&lt;td class="colborder" colspan="3" align="left" nowrap="nowrap"&gt;&amp;nbsp;&lt;b&gt;01.04.2012 00:00 - 30.04.2012 23:00&lt;/b&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;1&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.261"&gt;Trojan.Fraudster.261&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;1.30%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;2&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=SCRIPT.Virus"&gt;SCRIPT.Virus&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;1.11%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;3&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.256"&gt;Trojan.Fraudster.256&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.92%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;4&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Carberp.30"&gt;Trojan.Carberp.30&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.76%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;5&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.252"&gt;Trojan.Fraudster.252&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.70%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;6&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Mayachok.1"&gt;Trojan.Mayachok.1&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.67%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;7&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Shadow"&gt;Win32.HLLW.Shadow&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.67%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;8&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Shadow.based"&gt;Win32.HLLW.Shadow.based&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.65%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;9&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=JS.IFrame.233"&gt;JS.IFrame.233&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.61%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;10&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Tool.InstallToolbar.74"&gt;Tool.InstallToolbar.74&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.61%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;11&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.SMSSend.2726"&gt;Trojan.SMSSend.2726&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.59%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;12&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=JS.Siggen.192"&gt;JS.Siggen.192&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.59%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;13&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.292"&gt;Trojan.Fraudster.292&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.54%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;14&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Adware.Predictad.1"&gt;Adware.Predictad.1&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.53%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;15&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Autoruner.59834"&gt;Win32.HLLW.Autoruner.59834&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.53%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;16&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.SMSSend.2669"&gt;Trojan.SMSSend.2669&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.49%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;17&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=BackDoor.Ddoser.131"&gt;BackDoor.Ddoser.131&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.49%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;18&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Carberp.29"&gt;Trojan.Carberp.29&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.48%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;19&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Adware.Downware.179"&gt;Adware.Downware.179&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.47%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;20&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Autoruner.5555"&gt;Win32.HLLW.Autoruner.5555&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.47%&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;h3&gt;Malicious detected on users' computers in April&lt;/h3&gt;
&lt;table class="colborder" align="center" border="1" cellpadding="4" cellspacing="0" width="90%"&gt;&lt;tbody&gt;&lt;tr class="colborder" bgcolor="#deeacc"&gt;&lt;td class="colborder" colspan="3" align="left" nowrap="nowrap"&gt;&amp;nbsp;&lt;b&gt;01.04.2012 00:00 - 30.04.2012 23:00&lt;/b&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;1&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=SCRIPT.Virus"&gt;SCRIPT.Virus&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.97%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;2&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.261"&gt;Trojan.Fraudster.261&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.97%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;3&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.256"&gt;Trojan.Fraudster.256&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.75%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;4&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.SMSSend.2726"&gt;Trojan.SMSSend.2726&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.67%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;5&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=JS.Siggen.192"&gt;JS.Siggen.192&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.65%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;6&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.292"&gt;Trojan.Fraudster.292&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.63%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;7&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Mayachok.1"&gt;Trojan.Mayachok.1&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.61%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;8&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Carberp.30"&gt;Trojan.Carberp.30&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.59%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;9&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Shadow.based"&gt;Win32.HLLW.Shadow.based&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.55%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;10&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.SMSSend.2704"&gt;Trojan.SMSSend.2704&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.55%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;11&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.Fraudster.252"&gt;Trojan.Fraudster.252&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.53%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;12&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Shadow"&gt;Win32.HLLW.Shadow&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.53%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;13&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Tool.InstallToolbar.74"&gt;Tool.InstallToolbar.74&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.51%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;14&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Adware.Predictad.1"&gt;Adware.Predictad.1&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.49%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;15&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Win32.HLLW.Autoruner.59834"&gt;Win32.HLLW.Autoruner.59834&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.49%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;16&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Tool.Unwanted.JS.SMSFraud.10"&gt;Tool.Unwanted.JS.SMSFraud.10&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.47%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;17&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Trojan.SMSSend.2669"&gt;Trojan.SMSSend.2669&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.47%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;18&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=JS.IFrame.233"&gt;JS.IFrame.233&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.47%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;19&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=Adware.Downware.179"&gt;Adware.Downware.179&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.45%&lt;/td&gt;&lt;/tr&gt;&lt;tr onmouseover="this.bgColor='#eef4e5'" onmouseout="this.bgColor='#ffffff'" class="colborder" bgcolor="#ffffff"&gt;&lt;td class="colborder" width="1%"&gt;20&lt;/td&gt;&lt;td class="colborder"&gt;&lt;a href="http://info.drweb.com/virus/?match=family&amp;amp;family=BackDoor.Ddoser.131"&gt;BackDoor.Ddoser.131&lt;/a&gt;&lt;/td&gt;&lt;td class="colborder"&gt;0.45%&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br/&gt;</description></item><item><title>About anti-virus engine update in Dr.Web products with centralized management</title><link>http://news.drweb.com/show/?i=2400&amp;lng=en&amp;c=5</link><pubDate>Fri, 27 Apr 2012 00:00:00 GMT</pubDate><description>&lt;p class="b"&gt;27 апреля 2012 года&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web is pleased to announce an updated anti-virus engine for the Dr.Web Desktop Security Suite and Dr.Web Server Security Suite with centralized management option, which will be released on May 15, 2012.&lt;/newslead&gt; Server versions 6.0.2 and 6.0.3 will be updated automatically. Dr.Web Virus Finding Engine for versions prior to 6.0.2 will not be updated so Doctor Web strongly recommends installing a mandatory update of the server software for all users.&lt;/p&gt;
&lt;p&gt;Dr.Web Virus Finding Engine 7.0 lets significantly increase the scanning speed. Besides, it features a dynamic memory allocation that operates depending on the system performance and applications running on Windows. The heuristic analyzer incorporated in the new engine can boast of the ScriptHeuristic technology, which enables search and analysis of threats in HTML and PDF documents. This technology makes it possible to extract and process hidden IFRAME elements, while the scanning against the virus databases is now performed taking into account the JavaScript syntax.&lt;/p&gt;
&lt;p&gt;The Dr.Web Virus Finding Engine update will be released on May 15, 2012, and will be downloaded and installed automatically. Users of earlier versions of Dr.Web Enterprise Security Suite servers should upgrade to version 6.0.3. Users of Dr.Web Enterprise Agent for Novell NetWare, Dr.Web Anti-virus for Linux, Dr.Web for UNIX file servers, Dr.Web for UNIX mail servers, Dr.Web for UNIX Internet gateways, Dr.Web for Novell Storage Services, Dr.Web for Mac OS X Server file servers, and Dr.Web Anti-virus for Mac OS X should also upgrade to the latest versions of the corresponding software products if they work in a centralized management mode, so as to avoid potential incompatibility problems.&lt;/p&gt;</description></item><item><title>Doctor Web analyzes objects downloaded by BackDoor.Flashback onto infected Macs</title><link>http://news.drweb.com/show/?i=2410&amp;lng=en&amp;c=5</link><pubDate>Fri, 27 Apr 2012 19:42:42 GMT</pubDate><description>&lt;p class="b"&gt;April 27, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web virus analysts continue to study the first-ever large-scale botnet created by means of &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; and comprised of computers running Mac OS X.&lt;/newslead&gt; Files downloaded by the Trojan horse from servers controlled by criminals have become one of the main subjects for analysis.&lt;/p&gt;





&lt;p&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; exploits a Java vulnerability to save an executable and configuration file, responsible for its automatic launching by launchd, onto a hard drive of the compromised Mac. Then BackDoor.Flashback.39 connects to a control server, downloads an executable onto the infected machine and installs it in the system. At this moment the Trojan brings up a dialogue window prompting the user to enter an administrator password. If the user does enter the password, the malicious program runs with elevated privileges, but even if they don't, the Trojan will be saved in the user's home directory and launched with the current user permissions. It will be enough to perform its malicious tasks.&lt;/p&gt;

&lt;p&gt;

The downloaded malignant application interacts with two types of control servers. Servers belonging to the first category intercept web search traffic and redirect the user to malicious sites controlled by criminals. The second group issues commands to bots to perform backdoor tasks in the compromised system. Doctor Web analysts managed to take over control server domain names known to &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; payload malware and analysed requests sent by bots to servers.
&lt;/p&gt;

&lt;p&gt;
Control server names of the first group are generated using the list found in the Trojan’s configuration data; in addition, another domain name list is created where resulting names are determined by the current date. The second level domain name is the same, while a top-level domain name can be org,. com,. co.uk,. cn,. in. The Trojan horse sends consecutive requests to control servers according to its generated list. An /owncheck/ or /scheck/ GET request sent to a server contains the infected Mac's UUID in the useragent field.  If the reply contains a SHA1 hash value of  the domain name, this domain will become trusted and from this moment on will be considered to be a command server name. First domains in this category have been successfully taken over by Doctor Web since April 12, 2012.
&lt;/P&gt;

&lt;p&gt;

Once the malicious program has determined a domain of the first category, it begins to search for a second type domain. The bot uses the list found in its configuration data to send the /auupdate/ GET-request to a number of control servers. The useragent field in these requests contains detailed information on the infected system. The request example can be found below:

&lt;/p&gt;
&lt;p&gt;
&lt;tt&gt;
20|i386|9.8.0|4DE360BE-E79E-5AD6-91CF-D943761B3785|6bbbbfb49b1659ebaaadffa20215bfc787577bd8|001|007|0
&lt;/tt&gt;
&lt;/p&gt;
&lt;p&gt;
Where:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;bot version&lt;/li&gt;
&lt;li&gt;hw.machine)&lt;/li&gt;
&lt;li&gt;kern.osrelease&lt;/li&gt;
&lt;li&gt;Hardware UUID&lt;/li&gt;
&lt;li&gt;payload file SHA1 value&lt;/li&gt;
&lt;li&gt;third-party browser availability bitmask&lt;/li&gt;
&lt;li&gt;constant&lt;/li&gt;
&lt;li&gt;value indicating bot privileges 0 — ordinary user, 1 — privileged user&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;


If the control server does not return a correct reply, the Trojan uses the current date to generate a string that serves as a hash tag in a search using &lt;tt&gt;http://mobile.twitter.com/searches?q=&amp;lt;string&amp;gt;&lt;/tt&gt;. For example, some Trojan versions generate a string of the "rgdgkpshxeoa" format for the date  04.13.2012  (other bot versions can generate a different string). If the Trojan manages to find aTwitter message containing bumpbegin and endbump tags enclosing a control server address, it will be used as a domain name. Doctor Web began to take over domains of this category on April 13, but on the following day, Saturday, April 14, the Twitter account registered by Doctor Web analysts for this purpose was blocked. 

&lt;/p&gt;






&lt;p&gt;
As of April 13, 2012, 30 549 requests containing a UUID were sent to control servers of the first domain name category in 24 hours and 28,284 requests containing a UUID were transmitted to control servers of the second domain name category in the same period of time. Total 95 563 requests containing a UUID were sent to servers meant to control &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; payload from April 12 till 26, 2012. Other statistical data obtained during the 24 hour analysis of requests sent by &lt;vir&gt;BackDoor.Flashback&lt;/vir&gt; payload to control servers on April 13, 2012, is presented on the graph below.

&lt;/p&gt;








&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/linear_UUID_en_11.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/linear_UUID_en_11.1.png" alt="graph" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/circle_Platform_en_2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/circle_Platform_en_2.1.png" alt="graph" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/linear_Core_en_39.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/linear_Core_en_39.1.png" alt="graph" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/circle_Admin_en_2.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/circle_Admin_en_2.1.png" alt="graph" /&gt;&lt;/a&gt;&lt;/p&gt;
 
 
 

</description></item><item><title>Dr.Web for Mac OS X and Dr.Web for Mac OS X Server updated</title><link>http://news.drweb.com/show/?i=2407&amp;lng=en&amp;c=5</link><pubDate>Fri, 27 Apr 2012 12:54:25 GMT</pubDate><description>&lt;p class="b"&gt;April 27, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has updated Dr.Web for Mac OS X and Dr.Web for Mac OS X Server to version 6.0.3. The updated builds incorporate the Dr.Web Virus Finding Engine and virus databases 7.0. The 6.0.3 products support multi-thread scanning and boast improved stability and reliability, and other enhancements.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;Dr.Web Virus Finding Engine 7.0 features new malware detection technologies, such as file structure entropy analysis and ScriptHeuristic which enables the anti-virus to detect and neutralize threats embedded in HTML and PDF documents. Another key advantage of the new engine is a manifold increase in scanning speed. The signature-based scan takes into account JavaScript syntax.&lt;/p&gt;

&lt;p&gt;Version 6.0.3 applications support multi-thread scanning, which also greatly boosts scanning speed. The introduced curing routine for neutralizing active threats stops malicious processes and removes files required for their automatic launching. In addition, the anti-virus is able to neutralize malware, bypassing system file access restrictions. Deleting, moving, and restoring files in the Quarantine is faster now. E-mail files can now be excluded from the list of objects to be scanned. Fixes of known errors have contributed to the installer's greater stability. Dr.Web SpIDer Guard File Monitor uses fewer system resources. In addition, the program notifies the user about the availability of a new version. The optimization of the applications' architecture has improved their stability.&lt;/p&gt;

&lt;p&gt;To update Dr.Web for Mac OS X and Dr.Web for Mac OS X Server to version 6.0.3, download the appropriate distribution from &lt;a href="http://download.drweb.com"&gt;www.drweb.com&lt;/a&gt; and install the program over an existing installation or first remove the previous version.&lt;/p&gt;</description></item><item><title>Beware of dangerous Trojan in spam</title><link>http://news.drweb.com/show/?i=2406&amp;lng=en&amp;c=5</link><pubDate>Thu, 26 Apr 2012 18:20:40 GMT</pubDate><description>&lt;p class="b"&gt;April 26, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;The Russian anti-virus vendor Doctor Web warns Western-European users of a spam mailing that spreads Trojan.Encoder ransomware..&lt;/newslead&gt;.&lt;/p&gt;

&lt;p&gt;The number of requests to Doctor Web's  Technical support service from Western European users, who received an e-mail  with the subject "Ute Lautensack Vertrag Nr 46972057" has increased in the last 24 hours. The e-mail contains the following text:&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Sehr geehrte(r) Ute Lautensack,&lt;br&gt;
Sie haben sich für unseren Mail Upgrade eingetragen und wir freuen uns Sie als unseren frischen Teilnehmer zu begrüssen Sie können jetzt bis zu 500 Mitteilungen pro Monat frei versenden und Ihr Speicherplatz erhöht sich um 5 Gb.&lt;br&gt;
&lt;br&gt;
433,29 Euro für Registration werden Ihnen pro 12 Monate im Vorraus von Ihrem Bankkonto abgeschrieben. Entnehmen Sie die Rechnungsdaten bitte dem Anhang, dort finden Sie auch die Erläuterung für Ihre 2 Wochen Kündigungsfrist.  
&lt;br&gt;&lt;br&gt;
Mit freudlichen Grüssen&lt;br&gt;
Ihr Kundenservice&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;An archive file named Abrechnung or Rechnung can be attached to the message. If the attached application is launched, the Trojan encrypts files found on hard disks. &lt;/p&gt;
&lt;p&gt;A warning from Doctor Web: do not open attachments in these e-mails! If the Trojan has encrypted files on your computer, follow the guidance below to avoid loss of valuable information:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Notify the police.&lt;/li&gt;
	&lt;li&gt;Never attempt to solve the problem by reinstallling the operating system.&lt;/li&gt;
	&lt;li&gt;Do not delete any files from the heard drives.&lt;/li&gt;
	&lt;li&gt;Do not try to restore the encrypted data on your own.&lt;/li&gt;
	&lt;li&gt;Contact Doctor Web's virus laboratory When file a request, select Request for curing. This service is provided free of charge.&lt;/li&gt;
	&lt;li&gt;Attach a file encrypted by the Trojan to the ticket.&lt;/li&gt;
	&lt;li&gt;Wait for a response from a virus analyst. Due to the large number of requests it may take some time.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Dr.Web Enterprise Agent for Novell NetWare updated</title><link>http://news.drweb.com/show/?i=2395&amp;lng=en&amp;c=5</link><pubDate>Thu, 26 Apr 2012 09:36:06 GMT</pubDate><description>&lt;p class="b"&gt;26 April, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has updated Dr.Web Enterprise Agent 6.002 for Novell Netware incorporated into Dr.Web Server Security Suite.&lt;/newslead&gt;&lt;/p&gt;
&lt;p&gt;The update resolves issues that could arise if the Dr.Web Enterprise Security Suite Control Center were unavailable.&lt;/p&gt;
&lt;p&gt;To install the update, stop the drwebnw module in the Dr.Web anti-virus’s console and run the unload nwesag command Then replace the nwesag.nlm file found in the agent installation directory with the new one and use the load nwesag command to restart the agent.&lt;/p&gt;</description></item><item><title>New Dr.Web for Symbian OS released</title><link>http://news.drweb.com/show/?i=2388&amp;lng=en&amp;c=5</link><pubDate>Wed, 25 Apr 2012 00:00:00 GMT</pubDate><description>&lt;p class="b"&gt;April 25, 2012&lt;/p&gt;
&lt;p class="b"&gt;&lt;newslead&gt;Doctor Web has released Dr.Web for Symbian OS 6.00.2.&lt;/newslead&gt; The updated version of the product includes bug fixes and improvements.&lt;/p&gt;
&lt;p&gt;Dr.Web for Symbian OS is an anti-virus application designed to protect mobile phones running Symbian from various threats. This software allows you to scan the device "on the fly", check files transmitted via GPRS/Infrared/Bluetooth/Wi-Fi/USB connections, as well as during synchronization with a PC, including APK, ZIP, SIS, CAB, RAR, and JAR archives. Dr.Web for Symbian OS also incorporates anti-spam to protect mobile users from SMS spam.&lt;/p&gt;
&lt;p&gt;Dr.Web 6.00.2 for Symbian OS is compatible with Symbian Belle, features French language support, and is now free of issues that previously caused occasional system crashes during the scanning of directories. Users can download the update from &lt;a href="https://download.drweb.com/?lng=en"&gt;Doctor Web's site&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Doctor  Web doesn't register significant decrease in BackDoor.Flashback.39 bot number</title><link>http://news.drweb.com/show/?i=2386&amp;lng=en&amp;c=5</link><pubDate>Fri, 20 Apr 2012 18:53:55 GMT</pubDate><description>&lt;p&gt;&lt;strong&gt;April  20, 2012&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;newslead&gt;Doctor Web's virus analysts continue to monitor the  largest to date Mac botnet &lt;a href="http://news.drweb.com/show/?i=2341?lng=en"&gt;discovered by Doctor Web on April 4, 2012&lt;/a&gt;. The  botnet statistics acquired by Doctor Web contradicts recently published reports  indicating a decrease in the number of Macs infected by &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;  The number is still around 650,000.&lt;/newslead&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;According to Doctor Web, 817 879 bots connected to the &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; botnet at one time or another and average 550 000 infected machines interact with a control server on a 24 hour basis. On April 16, 717004 unique IP-addresses and 595816 Mac UUIDs were registered on the &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; botnet while on April 17 the figures were 714 483 unique IPs and 582405 UUIDs. At the same time infected computers, that have not been registered on the &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; network before, join the botnet every day. The chart below shows how the number of bots on the &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; botnet has been changing from April 3 to April 19, 2012.&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/en_grafik_map_Flashback_20_ap.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/en_grafik_map_Flashback_20_ap_mini.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;However recent publications  found in open access report a reduction in the number&lt;strong&gt; &lt;/strong&gt;of &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; bots.  Typically, these materials are based on analysis of statistics acquired from  hijacked botnet control servers. Doctor Web's analysts conducted a research to  determine the reasons for this discrepancy.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; &lt;/strong&gt;uses  a sophisticated routine to generate control server names: a larger part of the  domain names is generated using parameters embedded in the malware resources,  others are created using the current date. The Trojan sends consecutive queries  to servers according to its pre-defined priorities. The main domains for&lt;strong&gt; &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; &lt;/strong&gt;command servers  were registered by Doctor Web at the beginning of April, and bots first send  requests to corresponding servers. On April 16th additional domains whose names  are generated using the current date were registered. Since these domain names  are used by all &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; variants, registration of additional control  server names has allowed to more accurately calculate the number of bots on the  malicious network, which is indicated on the graph.  However, after communicating with servers  controlled by Doctor Web, Trojans send requests to the server at 74.207.249.7,  controlled by an unidentified third party. This server communicates with bots  but doesn't close a TCP connection.  As  the result, bots switch to the standby mode and wait for the server's reply and  no longer respond to further commands. As a consequence, they do not  communicate with other command centers, many of which have been registered by  information security specialists. This is the cause of controversial statistics  — on one hand, Symantec and Kaspersky Lab reported a significant decline in the  number of &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; bots,  on the other hand, Doctor Web repeatedly indicated a far greater number of bots  which didn’t tend to decline considerably. The image below shows how a  TCP-connection to the command center makes a &lt;strong&gt;&lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt;&lt;/strong&gt; bot freeze.&lt;/p&gt;

&lt;p style="text-align:center"&gt;&lt;a href="http://st.drweb.com/static/new-www/news/2012/april/TCP_stream.png" class="preview"&gt;&lt;img src="http://st.drweb.com/static/new-www/news/2012/april/TCP_stream.1.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Doctor Web once  gain warns Mac OS X users of the &lt;vir&gt;BackDoor.Flashback.39&lt;/vir&gt; threat and strongly  recommends you to install Java updates and scan the system to determine whether  it has been infected. For more information about BackDoor.Flashback detection  and neutralization visit &lt;a href="https://www.drweb.com/flashback/?lng=en"&gt;https://www.drweb.com/flashback/&lt;/a&gt;. To remove the  Trojan, you can use &lt;a href="http://www.freedrweb.com/drweb+mac+light/?lng=en"&gt;Dr.Web for Mac OS X Light&lt;/a&gt; available free of charge.&amp;nbsp;&lt;/p&gt;</description></item><item><title>Trojan.Encoder habitat widens</title><link>http://news.drweb.com/show/?i=2381&amp;lng=en&amp;c=5</link><pubDate>Thu, 19 Apr 2012 19:09:21 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;April 19, 2012&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;newslead&gt;The number of countries affected by the  &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt;, malware continues to grow. While at first computers  compromised by the Trojans were mainly found in Russia and other CIS countries,  systems located in several European countries came under threat on April 9-10.  Now Doctor Web receives support requests from Latin America (Brazil and  Argentina), as well as European countries such as France, Belgium, Switzerland,  Netherlands, Croatia, Slovenia, Hungary and Romania.&lt;/newslead&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;This Trojan encoder version is the first  one featuring the English interface and spreading widely outside Russia. First  reports concerning &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt; from Western-European users were received  on April 9-10 2012, mostly from Germany, Italy, Spain, England, Poland,  Austria, Norway and Bulgaria.&lt;/p&gt;
&lt;p&gt;The encoder searches for user's files, in particular, Microsoft Office  documents, music, photos, images and archives on disks available in the  infected system and then encrypts them. Once user files are encrypted , the  Trojan displays a demand to pay 50 euros or pounds to criminals via Ukash or  Paysafecard. Currently five English-language versions of the Trojan are known  to Doctor Web. They differ only in the encryption keys but operate in a similar  manner. &lt;/p&gt;
&lt;p&gt;Recently, Doctor Web's technical support  service has received requests related to &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt; from users living in  Brazil, Argentina and other Latin American countries. The Trojan spread through  Europe, including such countries as Croatia,  Switzerland, Netherlands, Slovenia,  Belgium, France, Hungary  and Romania.  Doctor Web's engineers managed to decrypt data for virtually all users'  requests which indicates the high efficiency of technologies employed for this  purpose.&lt;/p&gt;
&lt;p&gt;The Slovenian branch of the Computer  Emergency Response Team has been one of organizations that contacted Doctor Web  to share encoder neutralization experience. Currently CERT has successfully  joined the effort supported by technologies and information from Doctor Web to  tackle the outbreak.&lt;/p&gt;
&lt;p&gt;Doctor Web once again reminds users of the  simple rules to follow if your computer has been infected with  &lt;vir&gt;Trojan.Encoder.94&lt;/vir&gt;:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Never attempt to solve the problem by  reinstallling the operating system.&lt;/li&gt;
  &lt;li&gt;Do not delete any files from the heard  drives.&lt;/li&gt;
  &lt;li&gt;Do not try to restore the encrypted data on  your own.&lt;/li&gt;
  &lt;li&gt;Contact Doctor Web's technical support.  When file a request, select Cure request. This service is provided free of  charge.&lt;/li&gt;
  &lt;li&gt;Attach a doc or. txt file encrypted by the  Trojan to the ticket.&lt;/li&gt;
  &lt;li&gt;Wait for a response from a virus analyst.  Due to the large number of requests it may take some time.&lt;/li&gt;
  &lt;/ul&gt;
  &lt;/p&gt;</description></item><item><title>Single-user Dr.Web  7.00 products for Windows updated</title><link>http://news.drweb.com/show/?i=2373&amp;lng=en&amp;c=5</link><pubDate>Thu, 19 Apr 2012 12:35:56 GMT</pubDate><description>&lt;p&gt;&lt;strong&gt;April 19, 2012&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;newslead&gt;Doctor Web has updated the Scanning Engine service, GUI scanner, language packs, and Dr.Web Anti-rootkit Service incorporated into the seventh version of Dr.Web Security Space and Dr.Web Anti-virus for Windows.&lt;/newslead&gt; The update adds several new features and corrects known errors.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In particular, when searching for rootkits, the scanner now takes into account user-defined exceptions. The list of files and directories created by the user for a custom scan can be cleared with a single click, and in the scanner’s dialogue box, it’s now possible to select multiple items to add to the list of those items to be scanned. The Dr.Web Anti-rootkit Service component has improved procedures for finding and neutralizing active threats and features a faster anti-rootkit scanning speed. A scanning issue that arose when a target object path string contained diacritical marks and non-Latin characters has been resolved. Minor errors found in the components have been corrected.&lt;/p&gt;

&lt;p&gt;The update will be automatically downloaded by the anti-viruses, but applying the update will require a system reboot.&lt;/p&gt;</description></item><item><title>Rmnet.12 created a million Windows computer botnet</title><link>http://news.drweb.com/show/?i=2374&amp;lng=en&amp;c=5</link><pubDate>Wed, 18 Apr 2012 19:27:41 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;April 18, 2012&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;newslead&gt;Doctor Web—a Russian anti-virus  company—reports an outbreak of the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; virus that enabled attackers  to create a botnet incorporating over million infected computers. &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  infects Windows PCs, performs backdoor tasks and steals passwords stored by  popular ftp clients. The passwords may later be used used to mount network  attacks and infect websites. &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; processes commands from a remote  server which may include bringing down the OS.&lt;/newslead&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;First entries related to &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  were added to the Dr.Web virus database in September 2011. From this point on  Doctor Web's analysts followed closely the development of this threat. The  virus penetrates computers in different ways: via infected flash drives,  with  infected executable files, as well  as using special scripts embedded into html-documents— they save the virus to  the computer when one opens a malicious web page in the browser window. A  signature for the VBScript code was added into the Dr.Web virus database as  VBS.Rmnet.&lt;/p&gt;
&lt;p&gt;&lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; is a complex multicomponent  virus, consisting of several modules and capable of self-replication. When  launched, &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; checks which browser is set as a system default browser  (if not detected, the virus targets Microsoft Internet Explorer), and injects  its code into the browser process. Then it uses the hard drive serial number to  generate its own file name, saves itself into the autorun folder of the current  user and assigns the attribute &amp;quot;hidden&amp;quot; to its file. The virus's  configuration file is saved into the same folder. Then, the virus uses an embedded  routine to determine the name of a control server and tries to connect to it.&lt;/p&gt;
&lt;p&gt;One of the virus components is a backdoor.  Once launched, it tries to determine the Internet connection speed: it sends  requests at google.com, bing.com and yahoo.com at 70 second intervals and  analyses responses. Then &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; launches an FTP server on the infected  machine, connects to a remote server and transmits information about the  infected system to intruders. The backdoor can execute commands received from  the remote server, in particular, to download and run arbitrary files, update  itself, to take screenshots and send them to criminals, and even render the  operating system non-operational.&lt;/p&gt;
&lt;p&gt;Another virus component steals passwords stored  by most popular FTP-clients, such as Ghisler, WS FTP, CuteFTP, FlashFXP,  FileZilla, Bullet Proof FTP and others. This information can later be exploited  to carry out network attacks or to place various malicious objects on remote  servers. Also, &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; takes care to search through user's cookies, so  attackers can gain access to the user's accounts at different sites that  require authentication. In addition, the module can block access to specified sites,  and redirect the user to a site controlled by virus writers. One of the  &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  modifications is also  able to make web injections to steal bank account information.&lt;/p&gt;
&lt;p&gt;The virus spreads in various ways: by  exploiting browser vulnerabilities that enable intruders to save and launch  executables upon loading a web-page. The virus searches for all html files  stored on disks and embeds VBScript code into them. In addition, &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;  infects all executable files with the .exe extension found on the disks and is  able to copy itself to removable flash drives. It saves an autorun file and a  shortcut to a malignant application into the root folder on a flash drive. This  application launches the virus.&lt;/p&gt;
&lt;p&gt;The botnet comprised of hosts infected with  &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; was discovered by Doctor Web as long ago as in September 2011  when the first virus sample fell into the hands of virus analysts. They soon  decrypted names of control servers found in &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; resources. After a  while analysts decrypted the protocol used for communication between bots and  control servers which enabled them to determine the number of bots and to  control them. On February 14, 2012 Doctor Web's virus analysts created a  sinkhole, (it was subsequently used to study the BackDoor.Flashback.39 botnet),  namely, registered domain names for several servers controlling one of  &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; networks and gained full control over the botnet. In late  February, another &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; subnet was hijacked this way.&lt;/p&gt;
&lt;p&gt;At first, the number of bots was relatively  small and reached several hundred thousand, however, the number grew by and by.  As of April 15, 2012, the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; botnet is comprised of 1,400,520  infected hosts and is growing steadily. &lt;/p&gt;
&lt;p&gt;The network growth progress is presented on  the graph below.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="news/2012/april/graf_1_2_en.png" class="preview"&gt;&lt;img src="news/2012/april/graf_1_2.1_en.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The greatest number of infected PCs is  located in Indonesia  - 320,014 infected machines, or 27.12%. Bangladesh rates second with  166,172 infected hosts which constitue 14.08% of the botnet size. The third  rank is taken by Vietnam  (154,415 bots, or 13.08%), followed by India  (83,254 bots, or 7.05%), Pakistan  (46,802 bots, or 3.9%), Russia  (43 153 infected machines, or 3.6%), Egypt  (33,261 hosts, or 2.8%), Nigeria  (27,877 bots, or 2.3%), Nepal  (27,705 bots, or 2.3%) and Iran  ( 23,742 bots, or 2.0%). A sufficiently large number of compromised hosts is  found in the Republic of Kazakhstan (19 773 cases of infection, or 1.67%) and  the Republic of Belarus (14,196 bots, or 1.2%). 12 481 compromised hosts or  1.05 of the total number of bots are located in the Ukraine. A relatively small  number of infected computers reside in the U.S. – 4327 machines, which  corresponds to 0.36%. The smallest numbers are found in Canada (250 computers, or 0.02% of the network's  bulk) and Australia  (only 46 computers). One infected computer has been found in Albania, Denmark,  and Tajikistan  each. &lt;/p&gt;
&lt;p&gt;&lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; botnet geography is shown  below.&lt;/p&gt;
&lt;p style="text-align:center"&gt;&lt;a href="news/2012/april/map2.jpg" class="preview"&gt;&lt;img src="news/2012/april/map2.mini.png" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It should be noted that Doctor Web has full  control over the &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; viral network, so attackers can no longer  access it and harm infected computers. To prevent &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt; from infecting  the system, Doctor Web recommends you to use state-of-the-art anti-virus  software and keep its virus definitions up to date. If your system has already  been compromised by the virus &lt;vir&gt;Win32.Rmnet.12&lt;/vir&gt;, you can use the utility &lt;a href="http://freedrweb.com/cureit/?lng=en"&gt;Dr.Web CureIt!&lt;/a&gt; or &lt;a href="http://freedrweb.com/livecd/?lng=en"&gt;Dr.Web LiveCD&lt;/a&gt; to remove it.&lt;/p&gt;</description></item><item><title>Dr.Web Enterprise Agent for Novell Netware updated</title><link>http://news.drweb.com/show/?i=2360&amp;lng=en&amp;c=5</link><pubDate>Tue, 17 Apr 2012 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;strong&gt;April 17, 2012&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;newslead&gt;Doctor Web has updated Dr.Web Enterprise Agent 6.00.2 for Novell NetWare.&lt;/newslead&gt; The updated agent supports Novell NetWare 4.11, 4.2, 5.1, 6.0 and 6.5. Versions 3.12 and 3.2 are not supported. The update also fixes several errors.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;These include issues related to launching the scanner under Novell Netware 4.x, agent authorization by the anti-virus server under Novell Netware 4.2, and updating virus databases to Version 7.0.&lt;/p&gt;
&lt;p&gt;To install the update, stop the `drwebnw’ module in the Dr.Web anti-virus’s console and run the `unload nwesag’ command. Then replace the nwesag.nlm file found in the agent installation directory with the new one and use the `load nwesag’ command to restart the agent.&lt;/p&gt;
</description></item></channel></rss>

