|
||||||||||||||||||
![]() ![]() ![]() |
W32.Bolzano
|
W32.Bolzano is a new virus that replicates
under Windows 95 and Windows NT infecting Portable Executable applications
with EXE or SCR extensions.
From the replication point of view, there
is nothing much remarkable about the first few versions of Bolzano viruses.
In order for the virus to attempt the attack,
it needs administrative rights on a Windows NT Server or Windows NT Workstation
during the initial infiltration. Therefore it is not a major security risk,
but still is a potential threat. Viruses can always wait until the Aministrator
or someone with the equivalent rights logs on. In such a case, W32.Bolzano
has the chance to patch ntoskrnl.exe, the Windows NT kernel, located in
the WINNT\SYSTEM32 directory. The virus modifies only 2 bytes in an undocumented
security API called SeAccessCheck that is part of ntoskrnl.exe. This way
Bolzano is able to give full access to all users to each file regardless
of its Protection, whenever the machine is booted with the modified kernel.
This means that a Guest -having the lowest possible rights on the system-
will be able to read and modify all files including files that are normally
accessible only by the Administrator. This is a
Unfortunately the consistency of ntoskrnl.exe
is checked in only one place. The loader, ntldr, is supposed to check it
when it loads ntoskrnl.exe into physical memory during machine boot-up.
If the kernel gets corrupted ntldr is supposed to stop loading ntoskrnl.exe
and display an error message even before a "blue screen" appears. In order
to avoid this particular problem W32.Bolzano also patches the ntldr so
that no error message will be displayed and Windows NT will boot just fine
even if its checksum does not match with the original. Since no code checks
the consistency of ntldr itself, the patched kernel will be loaded without
notification to the user. Since ntldr is a hidden, system, read-only file
W32.Bolzano changes the
| ||||||||
|
|
|||||||||
| [an error occurred while processing this directive] |
|
Howdy!!! Welcome to the McCann's PooR Farm I'm not with any school or schools, Just a disable grandpa with 17 grand kids, 1 Great grand Kid Sorry! about all of the adds, Our Cost just keeping going up. Please click on one of them and help us out. or Send $1.00 U.S. to: McCann's Poor Farm 20509 Lawrence 2207 Aurora, Mo. 65605-7275 Thank You, Junior McCann Webmaster and the GrandKids See what the experts have to say about the McCann's Poor Farm Web Page Legal Disclaimer - We Are in no way connected with any School and or Companies linked to this page. Links are provided as a courtesy only. |
Argentina, Australia, Austria, Belarus, Belgium, Bermuda, Brazil, Brunei Darussalam, Bulgaria, Canada, Chile, Columbia, Costa Rica, Croatia, Croatia/Hrvatska, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Korea, Korea, Republic of, Latvia, Lebanon, Lithuania, Luxembourg, Macedonia, Malaysia, Mexico, Moldova, Netherlands, New Calendonia, New Zealand, Norway, Old style Arpanet, Papua New Guinea, Peru, Philippines, Poland, Portugal, Romania, Russian Federation, Saudi Arabia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Turkey, Uganda, Ukraine, United Arab Emirates, United Kingdom, United States, Uruguay, USA Government, USA Military, Viet Nam |
|
Tell A Friend about this Page |
Tell me when this page is updated |
|
|
Put a Link on your Web Page
- Legal Disclaimer - |