View Single Post
  #36  
Old July 16th, 2010, 08:14 AM
Windchild's Avatar
Windchild Windchild is offline
Frequent Poster
 
Join Date: Jun 2009
Posts: 563
Default Re: Rootkit.TmpHider

Quote:
Originally Posted by i_g
First you need a sample of the exploit, of course (it's not an ordinary .lnk file you create using the "Create shortcut" option in Windows Explorer). Then it's enough e.g. to enter the corresponding folder in Total Commander - and the code is started.

A question, as I don't have a sample of this malware: when the code runs, does it run with the privileges of the currently logged in user, or does the vulnerability allow privilege escalation to admin/system? If the exploit only manages to gain the privileges of the current user, then even the very basic measure of running as a limited user would be enough to prevent the infection, seeing how the malware attempts to load drivers and limited users don't have the privilege required for that. That would make this whole big fuss a little less big, at least for those of the Average Users who have been set up with a non-admin account. If you have a sample and can test the malware as a limited user, I'd appreciate it if you could report back whether or not the malware manages to infect the system when executed under a limited account.


Quote:
Originally Posted by sergey ulasen
Hello guys!

While Microsoft is trying to reveal problem, our colleague Alexander Gostev from LK wrote yesterday interesting review about Rootkit.TmpHider. You can read it here:

http://www.securelist.com/en/blog/26...uava_Episode_1

http://www.securelist.com/en/blog/27...uava_Episode_2

http://www.securelist.com/en/blog/27...uava_Episode_3

Interesting stuff! Maybe the digital signature was compromised via outsourcing. That would be... well, sad.
__________________
Save your tears, for your tears will not save you :: Shameless LUA troll