I
iSergiwa
Hello all
In Windows, I know that creating a new folder and name it "CON" is
prohibited (you can try it yourself) but many users who faced this case
(usually by accident) think that it is a windows bug! And many others think
that it's a windows trick or even more; a kind of magic!! << can you believe
that?!!!
In programming, every programmer knows this basic concept, that is using the
programming language "reserved words" as variables' names is prohibited as
they may conflict with eachothers!
In malicious software programming, we may all notice that those sick people
who develop such type of software usually use a simple-but-effective trick
in order to make their malicious programs hidden, unnoticed and hard to be
deleted or stopped! that is giving thire programs names that usually used by
windows system services! Names like services.exe, lsass.exe, winlogon.exe,
svchost.exe…
Well, I'm using Kaspersky Internet Security and I can count those too many
times when KIS asked me to unlock an infected exe file first because it's
being locked by another service or program and can't be deleted instantly.
and I can say that most of those times were because the malicious exe file
has a name of one of windows system services! (Email-Worm.Win32.Brontok.q is
a good examble)
Kaspersky (or any other AV software) has nothing to do with such
"vulnerability" of course, it's all about Microsoft. and yes I name it
"vulnerability" because it helps those sick people to take advantage of it
in spreading their sick programs!
Microsoft must develop a new term and call it "Windows Services Reserved
Names" (WSRN) or something like that and take the steps to prohibit giving
exe files names that are identical with it's own system services. Why NOT?!
such a procedure would help AVs software vendors and make it easy for them
to fight malicious software.
Thank you for reading and being patient
In Windows, I know that creating a new folder and name it "CON" is
prohibited (you can try it yourself) but many users who faced this case
(usually by accident) think that it is a windows bug! And many others think
that it's a windows trick or even more; a kind of magic!! << can you believe
that?!!!
In programming, every programmer knows this basic concept, that is using the
programming language "reserved words" as variables' names is prohibited as
they may conflict with eachothers!
In malicious software programming, we may all notice that those sick people
who develop such type of software usually use a simple-but-effective trick
in order to make their malicious programs hidden, unnoticed and hard to be
deleted or stopped! that is giving thire programs names that usually used by
windows system services! Names like services.exe, lsass.exe, winlogon.exe,
svchost.exe…
Well, I'm using Kaspersky Internet Security and I can count those too many
times when KIS asked me to unlock an infected exe file first because it's
being locked by another service or program and can't be deleted instantly.
and I can say that most of those times were because the malicious exe file
has a name of one of windows system services! (Email-Worm.Win32.Brontok.q is
a good examble)
Kaspersky (or any other AV software) has nothing to do with such
"vulnerability" of course, it's all about Microsoft. and yes I name it
"vulnerability" because it helps those sick people to take advantage of it
in spreading their sick programs!
Microsoft must develop a new term and call it "Windows Services Reserved
Names" (WSRN) or something like that and take the steps to prohibit giving
exe files names that are identical with it's own system services. Why NOT?!
such a procedure would help AVs software vendors and make it easy for them
to fight malicious software.
Thank you for reading and being patient