AplusWebMaster
Topic Starter
FYI…
- http://www.f-secure.com/weblog/archives/ar…6.html#00000838
March 22, 2006
"Yesterday we received an interesting email-worm sample, detected as Gurong.a, that uses rootkit techniques to hide its file, process and launch point in the registry. It is based on the infamous Mydoom code and it is in the wild but currently spreading very slowly… Gurong.a modifies the operating system kernel, specifically the system service table and process object structures, so it is a kernel-mode rootkit. What makes it different from other kernel-mode rootkits we have seen is the way it installs the rootkit payload into kernel… F-Secure BlackLight* is able to find and disable Gurong.a…"
* http://www.f-secure.com/blacklight/

- http://www.f-secure.com/weblog/archives/ar…6.html#00000838
March 22, 2006
"Yesterday we received an interesting email-worm sample, detected as Gurong.a, that uses rootkit techniques to hide its file, process and launch point in the registry. It is based on the infamous Mydoom code and it is in the wild but currently spreading very slowly… Gurong.a modifies the operating system kernel, specifically the system service table and process object structures, so it is a kernel-mode rootkit. What makes it different from other kernel-mode rootkits we have seen is the way it installs the rootkit payload into kernel… F-Secure BlackLight* is able to find and disable Gurong.a…"
* http://www.f-secure.com/blacklight/