Rootkit May Be Behind Windows Blue Screen
L3sPau1 writes "A rootkit infection may be the cause of a Windows Blue Screen of Death issue experienced by Windows XP users who applied the latest round of Microsoft patches. It appears that the affected Windows PCs had the rootkit infection prior to deploying the Microsoft patches. Researcher Patrick W. Barnes, investigating the issue, has isolated the infection to the Windows atapi.sys file, a driver used by Windows to connect hard drives and other components. Barnes identified the infection as the Tdss-rootkit, which surfaced last November and has been spreading quickly, creating zombie machines for botnet activity."
That's one way of forcing users to take care of an infection.
After all, there's no way that their malware tool could have spotted it, or the update could have checksummed the files before patching them.
If they put half as much effort into their anti-malware activities as they do into their DRM regime, the world would be a better place. We'd all have unicorns, and a pot of gold.
If you were blocking sigs, you wouldn't have to read this.
Will the windows SFC (System File Checker) tool find this altered file?
If a man isn't willing to take some risk for his opinions, either his opinions are no good or he's no good
The issue appears to be the result of an infected driver relying on some internal bits of the kernel that were patched. It's actually the author of the software that infected the driver that's causing the problem.
The infected driver was _NOT_ part of the Windows update and the update had no dependency on that driver.
This is not Microsoft's fault.
While I'm all for free speech, I do prefer that the speaker have some soft of expertise on the topic.
Do you have any evidence or are you just spouting off bullshit? No need to answer, it's a rhetorical question.
Seriously though, guys/girls like yourself need to get a fucking grip. When you say "M$" you sound like a tool. When you cry foul when there is none you sound like a tool. When you make baseless accusations against someone because they are trying to inform people of a potential rootkit problem you sound like a tool.
Summary: You sound like a tool and people won't listen. So any future complaint or criticism, however legitimate, will simply be ignored.
And what happens when the rootkit bypasses the operating system access to that file and returns the expected results? This is a rootkit after all.
And HOW exactly should they check if the system has been infected by a rootkit that shows the patcher a file that matches the checksum?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Checksums, 'nuff said...
Apps: Calc this for me...
rootkit: errrrrr.... ?
Apps: Busted, fscker! *and warns user*.
Here be signatures
Won't work. To take your analogy a bit farther...
The thief is the rootkit, you're the kernel, and the patch is the police.
The thief is already in, hiding behind the sofa with a gun pointed at your head. The officer knocks on your door and asks if you're being robbed. The answer is 'no'.
A rootkit can invade the lowest-level of the Virtual File System, so when a patcher running in user space asks for the checksum of the file it's about to patch, it gets a 'clean' result, even if the -real- file on the disk is something entirely different.
There are a lot of misconceptions about what rootkits really are. I encourage anyone to take a few hits of LSD and explain physics to me, or perform surgery on themselves while under the influence, that's about the closest thing I can compare to patching or rootkit detection on a system that's already compromised.
"Sometimes, I think Trent just needs a cup of hot chocolate and a blankie." -Tori Amos on Nine Inch Nails
Because ANY law WILL be abused, full stop. You make it so everyone has to have an "Internet License" and no longer can posts anon, you know what you will get? "Oh you posted something mean! don't you remember the Myspace suicide girl? No net for you!" "How dare you speak out against dear leader! Don't you support our troops? No net for you!"
If you passed crap like that pretty soon the entire net would be nothing but the Home Shopping network. "Gee isn't product X swell? It sure is Biff!" because you won't dare say anything that could get your driver's license revoked. The problem with comparing the Internet to IRL is that it isn't real folks. It is easy to show some guy had a BAC equal to falling down drunk and was doing 80 in a 30 and needs his license revoked.
But with the Internet the "rules" would end up getting written by politicians pandering to the PC police and every interest group with a checkbook. The "think of teh childrenz!" groups alone would try to turn everything into Mr. Rogers while the bible thumpers would want everything to be Jesusland, and of course the Scientology nuts would have your license for daring to even THINK the word Xenu. yeah, no thanks, I'll stick with what we got now, thanks anyway. I haven't seen a bug since 98, and working PC repair I can say you just can't fix stupid.
ACs don't waste your time replying, your posts are never seen by me.