Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes

Security Watch - Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes posted in the Security & Safety forums; Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes More than 20 percent of all malware removed from Windows XP SP2 (Service Pack 2) systems are stealth rootkits, according to senior ...

JOIN US NOW to remove these Ads

pc help forum number one in the search engines
Post New Thread  Reply
  #1  
Old 01-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes

Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes

More than 20 percent of all malware removed from Windows XP SP2 (Service Pack 2) systems are stealth rootkits, according to senior official in Microsoft Corp.'s security unit.



Jason Garms, architect and group program manager in Microsoft's Anti-Malware Technology Team, said the open-source FU rootkit ranks high on the list of malicious software programs deleted by the free Windows worm zapping utility.

"I can tell you that FU is the fifth most removed piece of malware. We're finding the FU rootkit in many different versions of Rbot," Garms said, referring to the IRC controlled backdoor used to illegally infect Windows PCs with spyware.

In addition to the FU rootkit, Garms said the WinNT/Ispro family of kernel mode rootkits features in the top-five list every month.

WinNT/Ispro, like FU, is often bundled with illegally installed spyware to allow an attacker to modify certain files and registry keys to avoid detection on an infected machine.

"Hacker Defender," another rootkit program that is available for sale on the Internet, has also been detected and deleted regularly.

Garms shared statistics culled from the worm cleansing tool in an interview with Ziff Davis Internet News and warned that the high rate of rootkit infections confirm fears that virus writers are using the most sophisticated techniques to hide malicious programs.

For the most part, the rootkits are being detected and removed from Windows XP (gold) versions but infection rates on XP SP1 and XP SP2 machines are also high.

The Ispro rootkit, for example, was prevalent on 50 percent of all Windows XP machines without a service pack. About 20 percent of all scans of machines running XP SP1 and SP2 also found the rootkit.
The numbers are roughly the same for the FU rootkit while the Win32/HackDef stealth rootkit is lower down on the list, Garms said.

Beyond rootkits, the rate of XP SP2 infections from malware that use social engineering techniques is staggering, Garms said.

"The social engineering tactic is working for virus writers. People are still clicking on attachments and links in IM messages and becoming infected. Even with all the education programs, there's still a large number of customers being tricked everyday," Garms said.


More here:
http://www.eweek.com/article2/0,1895,1896605,00.asp


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] Repairing SP2 ladygreenwitch Windows XP/2000 38 06-02-2007 06:35 AM
[Fixed] Whenever i try to play a video my pc freezes! FyawurX Windows XP/2000 41 12-14-2005 08:42 PM
[FIXED] Library of Spyware and Adware on my PC Tigereye1786 [Fixed] Hijackthis! Logs 61 11-12-2005 06:20 PM
[FIXED] I have no sound all of a sudden... Help! dionhaloulos Sound etc 45 09-15-2005 12:59 AM
[FIXED] Spyware! faithbuilder3 [Fixed] Hijackthis! Logs 42 07-20-2005 05:11 PM


All times are GMT +1. The time now is 03:14 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top