• Welcome to the new B.I.R.D. Forum. Please be sure to read the "New Member / New Registered ? Please Read" thread in the Coffee Shop. This contains some important information. To become a full member ( £5.90 a year ) simply click on your user name near the top on the right I hope you enjoy the new site ................ Jaws ( John )

Flux Virus

Fat Bert

Registered User
Worth reading and downloading

************************************************

Flux is the name of a new pest spreading covertly through the internet. Flux is a trojan that is making the life of most anti malware vendors much harder.

Flux is a reverse backdoor type of trojan. Reverse means that rather than the infected machine waiting for a connection to be made from outside, the infected machine trys to make the connection itself. Standard trojans are made up of two parts - the server and the client.

The client is downloaded to infect the machine. The server is another pc somewhere in the world that then tries to communicate with the client. The problem with standard trojans is that if the infected machine has a good firewall, then the server cannot connect to the client. So although the machine is infected, no data is transferred to the server from the client.

To overcome the blocked connection, malware writers now use this reverse logic to make the client machine responsible for the connection. Many standard firewalls will block requests coming in from the internet to connect, but do not block about outgoing requests to connect. Trojans like flux can therefore operate even through most firewalls.

The really dangerous thing about Flux is not its ability to use this reverse connection feature, but the way that feature is implemented. Flux introduces a new technique of code injection. Code Injecting is a term that describes ways to execute code in other processes. Until now Code Injection worked by loading a DLL file into a foreign process - much like the cookoo lays an egg in another birds nest. This method (called DLL Injection) is quite easy to detect as the anti-malware program just asks the process which DLLs it uses - a trojan DLL is one that is not on the list generated.

Flux doesn't use a DLL. Flux writes its connection code directly into a host process and executes it there. Apart from the fact that this behaviour would circumwent several Desktop Firewalls, it also makes Flux nearly invisible to current anti malware software because the Flux code isn't linked to any module or DLL of the process and will be simply overlooked by anti malware software. That makes complete cleaning very difficult.

Here at a? we have already thought about trojans using this direct injection method and why we already developed an advanced memory scan for a? v2.0 that can detect trojans using this technique. Version 2.0 is not quite ready for release but due to trojans like Flux we have decided to provide our customers with the advanced memory scan now.

What does all this mean for you?
a? is one of the first anti malware product that is able to detect and deactivate Flux. On top of that we have also developed a special free detection tool. This tool allows users of other anti-malware software to benefit from a? anti-malware technology too. The free tool detects and terminates an active Flux to ensure a proper cleaning of the infection.

http://www.emsisoft.com/en/

download flux and a2, dam good prog to have, checks for virus's and trojans most progs cant detect
 

Centaur

Site Pedant
Club Sponsor
Bollix

like all of these programs it supposedly finds all these problems which it will only remove if you pay the money to buy the full program. f**k off. I am happy with AVG, Spybot and Adaware. Anything can get past them I will format and go again or a new harddrive ai'nt all that expensive!!! :bang:
 

Wolfie

Is a lunp
ran it got 1 trojan and 3 malware things, all of which went past avg, spybot and zonealarm.


cheers bertie.
 

Centaur

Site Pedant
Club Sponsor
Sorry Bert

I have just downloaded the free version. Message to myself..... Don't download after a bottle of first press red wine!!! OOooppppsss c7u8 c7u8
 
Top