VadaVaka

Full Version: Spyware that can't be removed, without reformat!
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
http://www.theinquirer.net/?article=21326

Quote:Microsoft warns of future security danger

Kernel Rootkits could be the next bad thing


By Nick Farrell: Friday 18 February 2005, 08:25

A HITHERTO OBSCURE security expert and software colossus, based in Redmond and called Microsoft has warned of a new generation of spyware that is almost impossible to detect.
According to Computerworld, Volish experts told the RSA security conference that system monitoring programs, or "kernel rootkits", are undergoing a transformation at the moment.

Mike Danseglio and Kurt Dillard, both of Microsoft's Security Solutions Group said that the malicious snooping programs are becoming more common and could soon be used to create a new generation of mass-distributed spyware and worms.

Rootkits run quietly in the background and can be spotted by looking for memory processes that are running on the infected system.

However, kernel rootkits, which modify the kernel, or core request processing, component of an operating system, are becoming more common, Vole says.

Newer rootkits can intercept system calls that are passed to the kernel and filter out queries generated by the software. This makes them invisible to administrators and to detection tools, says Danseglio.

Microsoft researchers have developed a tool, named "Strider Ghostbuster" that can detect rootkits by comparing clean and suspect versions of Windows and looking for differences.

However the paper admits that the only way to be sure that you have killed a kernel rootkit is to completely erase an infected hard drive and reinstall the operating system from scratch.

More can be found here


This is a nasty thought. Spyware that can only be removed with a reformat. I really do hope they make laws against stuff like this.
noooooo not the R word NOOOOOOOOOOO.
damnit :\ man i can't belive there are people out there with nothing better to do than to screw with you and your michine, hehe maybe there is so much spyware crap out there that even the spyware makers get spyware sometimes, They better :angry:
Heh. Why not just boot from the OS CD, and reinstall the kernel?
if the kernel is infected, does infect the sytems files after and what not?, then you haveto delete those files with the spyware removal software, right? if correct wich would be faster: reformat or......