Author Topic: Alert: Alureon rootkit & 64-bit windows- new  (Read 854 times)

0 Members and 1 Guest are viewing this topic.

Offline stealthzone

  • Hero Member
  • *****
  • Posts: 565
Alert: Alureon rootkit & 64-bit windows- new
« on: November 17, 2010, 04:54:24 PM »
Hi  :)

Quote
Rootkit able to bypass kernel protection and driver signing in 64-bit Windows

The 64-bit version of the Alureon rootkit / bot is able to bypass the special security features included in the 64-bit versions of Windows 7 and Vista and insert itself into the system. The tricks used have been known about in theory for several years, but until recently had not been used by malware in the wild. The 32-bit version of Alureon made headlines early this year, when the installation of a Microsoft patch left many systems unable to boot. The problem was caused by the previously unnoticed presence of the rootkit, which the patch effectively unmasked.

The 64-bit version of Alureon (aka. TDL) deactivates checks for driver signing and, even during the boot process, reroutes specific API calls in order to bypass the kernel's PatchGuard mechanism. Driver signing is intended to ensure that Windows only loads drivers from known vendors. PatchGuard is intended to protect the operating system kernel from being modified by malicious code.

More: http://www.h-online.com/security/news/item/Rootkit-able-to-bypass-kernel-protection-and-driver-signing-in-64-bit-Windows-1137225.html

Search: Heise Online : http://www.h-online.com/security/  

Note: If you start the DOS-tool Diskpart via the comando promt in Windows typing ' lis dis ' (without the ' ), you should be able to see a list of all the drives on your computer. If the list is empty your computer may possible be infected by the Alureon rootkit / bot

The rootkit Alureon is also known as : TDSS, TLD3 or Tidserv.
Avast! Antivirus 6.0.1000 Home Version
Comodo Firewall
SuperAntiSpyware Pro  
Malwarebytes' Anti-malware Pro
Home Forum: http://www.spywarefri.dk/forum


Offline stealthzone

  • Hero Member
  • *****
  • Posts: 565
Re: Alert: Alureon rootkit & 64-bit windows- new
« Reply #1 on: November 17, 2010, 05:09:25 PM »
The diskpart looks something like this if things are OK:



Avast! Antivirus 6.0.1000 Home Version
Comodo Firewall
SuperAntiSpyware Pro  
Malwarebytes' Anti-malware Pro
Home Forum: http://www.spywarefri.dk/forum


Offline stealthzone

  • Hero Member
  • *****
  • Posts: 565
Re: Alert: Alureon rootkit & 64-bit windows- new
« Reply #2 on: November 17, 2010, 05:13:50 PM »
I did hadn't seen this tread. Sorry Corinne :rose: :blink: : Read on here as well: http://www.landzdown.com/index.php/topic,47454.0.html
Avast! Antivirus 6.0.1000 Home Version
Comodo Firewall
SuperAntiSpyware Pro  
Malwarebytes' Anti-malware Pro
Home Forum: http://www.spywarefri.dk/forum


Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Alert: Alureon rootkit & 64-bit windows- new
« Reply #3 on: November 17, 2010, 05:29:28 PM »
Two places are better than one!  I'll post a link here from the other topic too. :)
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.