Back in October a rootkit was discovered that exploits a critical security vulnerability in the Windows operating system. We covered a detection and removal tool two days ago that would scan a PC and remove any traces of the Duqu rootkit from a system. Microsoft today has releases a security advisory to give customers “guidance [...]
- Author: Martin Brinkmann
- Comments: 14
Duqu Zero-Day Exploit Discovered, Removal Tool Released
If you have been following security news lately you may have already heard about the Duqu rootkit that combines the technology of the Stuxnet rootkit with a backdoor trojan and keylogger. Duqu has been discovered on October 18 and infection reports have started to come in soon thereafter. Not all security suites and products detect [...]
- Author: Martin Brinkmann
- Comments: 9
Avast aswMBR, Sophos Anti-Rootkit, Free Rootkit Scanners
Windows XP systems are more prone to being infected with rootkits as Microsoft’s latest operating system Windows 7. That’s the result of a study conducted by Avast that surveyed more than 600,000 Windows PCs. Reasons for this higher infection rate are systems that are running the now unsupported service pack 2 and better protection of [...]
- Author: Martin Brinkmann
- Comments: 4
NoVirusThanks Anti-Rootkit Free
It sometimes pays of to occasionally scan a computer system with another virus scanner. We all know that no security software in the world can protect against every known threat. Even if the software catches 99,9% of all malicious files it still means that every 1,000th file slips through. Using another security software to scan [...]
- Author: Martin Brinkmann
- Comments: 8
How To Detect A 64-bit Alureon Rootkit Infection
Alureon, or TDL, TLD3 and Tidserv, is the first rootkit that can infect 64-bit Windows PCs. Before that, only 32-bit systems were affected by rootkits, and many Windows users realized that in February, when Microsoft patch MS10-015 caused infected machines to display a blue screen. It obviously was not Microsoft’s fault back then, which was [...]
- Author: Martin Brinkmann
- Comments: 3
Stuxnet Rootkit Remover
Stuxnet is family of new threats that have emerged in mid July 2010, with the majority of infected computer systems in Iran, Indonesia, India and the US. The rootkit is distributed by direct attacks, email, infected executables and the recently discovered lnk shortcut security vulnerability in Windows. Stuxnet uses the aforementioned .lnk technique to install [...]
- Author: Martin Brinkmann
- Comments: 8
Malware Cause For Blue Screens After Recent Windows Update
Reports about blue screens began to appear on the Internet shortly after the release of this month’s security patches for the Windows operating system. Especially Windows XP users seemed to have been affected by the crashes which were first thought to be linked to the update. Microsoft addressed the issue shortly after reports began to [...]
- Author: Martin Brinkmann
- Comments: 7
Another Fix For Unauthorized Google Redirects [Security]
We posted a solution for one of the causes of unauthorized Google redirects yesterday. These redirects can happen in one browser or multiple ones and are usually related to searches that the user performs in search engines such as Google. Yesterdays redirect was caused by a plugin that got installed on the host computer without [...]
- Author: Martin Brinkmann
- Comments: 4
Trend Micro RootkitBuster
Most security software programs that are available these days provide protection against rootkits as well. There are on the other hand a few security programs that deal solely with rootkits. One of them is Trend Micro’s RootkitBuster which has just been released in a new version which adds the ability to detect rootkits that hook [...]
