Anti-rootkit safeguards and methods of their bypassing

Aleksander Czarnowski AVET

  Technical stream: Thursday 12 October 2006, 09:40 - 10:20.

With the XP and 2003 lines of the Windows operating system Microsoft introduced several safeguards aiming at protecting the system form malware including rootkits. This paper will look into the technical aspects of those safeguards, analyse their efficiency and weaknesses. In addition, the impact of the introduction of these safeguards on rootkit technology will be analysed. Secondly, further safeguards proposed and included in the x64 platform and Vista operating system will be inspected.

All of this is done to try to answer the simple question: is the era of kernel rootkits coming to an end on Windows platforms?


Poll

Should AV software check search engine results for malicious sites even before the user clicks on them?
Yes
No
I don't know

Leave a comment
View 8 comments

vb2008-sidebar

Malware Prevalence

NetSky |#####################|
Agent |#############|
Rays/Traxg/Wukill |#########|
Mytob |########|
OnlineGames |#######|
 View this month's full report
Virus Bulletin currently has 129,047 registered users.