AplusWebMaster
Topic Starter
FYI…
- http://www.techweb.com/article/printableAr…_section=700028
December 08, 2005
"The sharp rise in rootkits–sneaky software used to conceal malicious code from security programs–is due to spyware and adware purveyors trying to prevent their wares from being easily uninstalled, security experts said Thursday. Finnish-based F-Secure, which has integrated its BlackLight rootkit scanner into its security suite, claimed that since October, the most common rootkit in the wild is the one used by the Apropos spyware program ( http://www.f-secure.com/sw-desc/apropos.shtml ). Apropos uses a silent installer to disguise its planting on the hard drive, and a kernel-mode rootkit to hide from detection, said F-Secure. The rootkit starts automatically early in the boot process–to avoid detection by security software, which typically loads later in the boot-up procedure–and can hide files, directories, registry keys, and Windows processes. Once on the drive, Apropos collects system information and data on the user's browsing habits, then sends the data to servers at ContextPlus, which uses it to deliver targeted pop-up ads to the PC. "Usually rootkit malware tries to avoid detection," wrote Mikko Hypponen, F-Secure's chief incident officer, in the alert. "Apropos, on the other hand, shows the user pop-ups ad nauseam. Therefore, the motive of Apropos is not to use rootkits for hiding itself [but] is designed to prevent uninstallation and removal"…"
>>> http://www.f-secure.com/blacklight/
"…Note: Stand-alone BlackLight beta's expiration has been extended until 1st of January 2006…"

- http://www.techweb.com/article/printableAr…_section=700028
December 08, 2005
"The sharp rise in rootkits–sneaky software used to conceal malicious code from security programs–is due to spyware and adware purveyors trying to prevent their wares from being easily uninstalled, security experts said Thursday. Finnish-based F-Secure, which has integrated its BlackLight rootkit scanner into its security suite, claimed that since October, the most common rootkit in the wild is the one used by the Apropos spyware program ( http://www.f-secure.com/sw-desc/apropos.shtml ). Apropos uses a silent installer to disguise its planting on the hard drive, and a kernel-mode rootkit to hide from detection, said F-Secure. The rootkit starts automatically early in the boot process–to avoid detection by security software, which typically loads later in the boot-up procedure–and can hide files, directories, registry keys, and Windows processes. Once on the drive, Apropos collects system information and data on the user's browsing habits, then sends the data to servers at ContextPlus, which uses it to deliver targeted pop-up ads to the PC. "Usually rootkit malware tries to avoid detection," wrote Mikko Hypponen, F-Secure's chief incident officer, in the alert. "Apropos, on the other hand, shows the user pop-ups ad nauseam. Therefore, the motive of Apropos is not to use rootkits for hiding itself [but] is designed to prevent uninstallation and removal"…"
>>> http://www.f-secure.com/blacklight/
"…Note: Stand-alone BlackLight beta's expiration has been extended until 1st of January 2006…"