Update on Google attack

It seems that early reports were wrong about the actual exploit used against Google and 33 other companies. The exploit code has appeared in the hands of many AV companies. It is an IE exploit and a zero-day.

Zero-day means that this was a previously unknown vulnerability, and as far as I can tell, there is no patch for it from MS as yet.

The second stage malware was a script used to insert a malicious DLL . This DLL, the third stage, is called Hydraq (by Symantec) and Roarur (by McAfee). This third stage provides remote access as well as hiding itself.

I'll post more as soon as I can.