Kaspersky Lab has published ratings of malware detected and blocked in August 2010. Exploits and worms that exploit the vulnerability of Windows, as proved in the rating of programs, the most frequently detected on users’ computers, and in rating web-based threats.
First, in August there was a significant increase in exploitation of the vulnerability CVE-2010-2568. For the first time this vulnerability was used in the notorious late July worms Worm.Win32.Stuxnet, after she used the Trojan-dropper, are installed on the infected computer is the latest modification of a known virus Sality – Virus.Win32.Sality.ag. As expected, the attackers immediately “took a turn” a new hole in the most popular in the present version of the OS Microsoft Windows. But second of August Microsoft released patch MS10-046, closing the vulnerability. This update is marked as «Critical», which means the mandatory installation of all users of the system.
For more details about email templates visit the link.
In the rating of programs that are blocked on users’ computers were once three piece of code claimed, one way or another connected with the CVE-2010-2568. Two of them – exploits Exploit.Win32.CVE-2010-2568.d and Exploit.Win32.CVE-2010-2568.b, directly exploiting the vulnerability. Third, Trojan-Dropper.Win32.Sality.r, uses this vulnerability to spread. It generates LNK-sensitive labels with names, attractive to users, and distributes them across the network. When a user opens a pacu, containing a label, is run piece of code claimed.
Both exploit the vulnerability CVE-2010-2568, reached the top 20 most frequently detected on users’ computers in Russia, India and Brazil. The geographical distribution of Trojan-Dropper.Win32.Sality.r similar distribution exploits. Interestingly, India is also a major source of spread of the worm Stuxnet.





