Alert: Alureon rootkit & 64-bit windows- new

Started by Frands, November 17, 2010, 05:54:24 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Frands

Hi  :)

QuoteRootkit able to bypass kernel protection and driver signing in 64-bit Windows

The 64-bit version of the Alureon rootkit / bot is able to bypass the special security features included in the 64-bit versions of Windows 7 and Vista and insert itself into the system. The tricks used have been known about in theory for several years, but until recently had not been used by malware in the wild. The 32-bit version of Alureon made headlines early this year, when the installation of a Microsoft patch left many systems unable to boot. The problem was caused by the previously unnoticed presence of the rootkit, which the patch effectively unmasked.

The 64-bit version of Alureon (aka. TDL) deactivates checks for driver signing and, even during the boot process, reroutes specific API calls in order to bypass the kernel's PatchGuard mechanism. Driver signing is intended to ensure that Windows only loads drivers from known vendors. PatchGuard is intended to protect the operating system kernel from being modified by malicious code.

More: http://www.h-online.com/security/news/item/Rootkit-able-to-bypass-kernel-protection-and-driver-signing-in-64-bit-Windows-1137225.html

Search: Heise Online : http://www.h-online.com/security/  

Note: If you start the DOS-tool Diskpart via the comando promt in Windows typing ' lis dis ' (without the ' ), you should be able to see a list of all the drives on your computer. If the list is empty your computer may possible be infected by the Alureon rootkit / bot

The rootkit Alureon is also known as : TDSS, TLD3 or Tidserv.
Our greatest glory is not in never falling but in rising every time we fall.
- Confucius
-----
Trend Micro Internet Security


Home Forums:
https://www.landzdown.com/
http://securitygarden.blogspot.dk/
https://www.classicrockforums.com/

Frands

The diskpart looks something like this if things are OK:



Our greatest glory is not in never falling but in rising every time we fall.
- Confucius
-----
Trend Micro Internet Security


Home Forums:
https://www.landzdown.com/
http://securitygarden.blogspot.dk/
https://www.classicrockforums.com/

Frands

I did hadn't seen this tread. Sorry Corinne :rose: :blink: : Read on here as well: http://www.landzdown.com/index.php/topic,47454.0.html
Our greatest glory is not in never falling but in rising every time we fall.
- Confucius
-----
Trend Micro Internet Security


Home Forums:
https://www.landzdown.com/
http://securitygarden.blogspot.dk/
https://www.classicrockforums.com/

Corrine

Two places are better than one!  I'll post a link here from the other topic too. :)


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.