|
Lost+Found: root kit protection, Koobface, Windows 7, Gumblar |
|
|
|
Source: H Security - Posted by anthony
|
HookSafe is intended to make things difficult for rootkits by protecting kernel hooks from manipulation. It relocates the kernel hooks to a central memory space which it then monitors. In order to ensure that it does not itself fall victim to a rootkit, HookSafe runs as a hypervisor, with the protected system running as a guest. Experiments at North Caronlina State University found that HookSafe was able to protect against nine known rootkits.
According to Trend Micro, the authors of Koobface are using hacked Google Reader accounts to spread links to their malware. The infected pages are shared using the "Share" or "Share with note" functions.
Read this full article at H Security
Only registered users can write comments. Please login or register. Powered by AkoComment! |