Symantec has found a new rootkit that hides from Windows XP on the hard drive’s boot sector. Nasty stuff. A traditional rootkit installs as a driver while this new rootkit installs so that it controls the master boot record (MBR) before
The Computerworld story says:
“According to other researchers, including those with the SANS Institute’s Internet Storm Center, Prevx Ltd. and a Polish analyst who uses the alias ‘gmer,’ the rootkit has infected several thousand PCs since mid-December, and is used to cloak a follow-on bank account-stealing Trojan horse from detection as well as to reinstall the identity thief if a security scanner somehow sniffs it out.”
If the rootkit does find its way onto a system, you may be looking at a PC that cannot be repaired but has to be wiped clean. Symantec claims that its antivirus software fights the rootkit by identifying it as a Trojan named Mebroot when the rootkit attempts to install itself. Researchers also suggest checking to see if your PC’s BIOS includes a MBR write-protection feature. If so, they advocate activating it.
Go to Microsoft Subnet for more news, blogs, opinion
More Microsoft Subnet blog posts:Microsoft’s CES news: all about IPTVEnterprise deployment guides for Vista SP1Video: One year, three minutes, many laughs Bill Gates video interview,looking back and forwardBill Gates last full day video
Win free Microsoft training from New Horizons All Micronet blog postsbi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)Sign up for the




