MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Rootserv - uses Kernel Mode Root Kit Techniques

There's been a rash of new Bagles launched lately and one key variant can download a more potent root kit on the infected PC if the website is operational. F-Secure is reporting one new variant per day, so have the cream cheese ready ...

New Bagle Variants
http://www.f-secure.com/weblog/archives/archive-062006.html#00000905
http://www.sophos.com/pressoffice/news/articles/2006/06/baglekl.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBAGLE%2EFU
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ff@mm.html

Rootserv - uses Kernel Mode Root Kit Techniques
http://www.sarc.com/avcenter/venc/data/trojan.rootserv.html

Trojan.Rootserv is a Trojan horse that uses kernel mode root kit technology to hide processes, files and registry entries. It also ends and prevents from running various security-related processes.

Only published comments... Jun 22 2006, 12:52 AM by Harry Waldron

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems