Home / Software & Gaming / Dangerous 64 bit Rootkit spreading

Dangerous 64 bit Rootkit spreading

A new version of dangerous rootkit Alureon is back – this time in the shape of a 64 bit edition.

We are always dismayed to hear about new security issues, but this one looks to be particularly nasty as it has been designed to specifically target the ever expanding 64 bit versions of Windows.

Help Net Security have posted information detailing that Alureon is the first rootkit which can infect and hide itself in 64 bit Windows builds. In the past running a 64 bit version of Windows has offered some protection from rootkits and other malware executables as the differing memory spaces mean that a 32 bit rootkit attempting a buffer overflow exploit may find it overwrites the wrong part of the memory and fails to run at all. With this latest ‘release' this safety system no longer works.

Microsoft have incorporated security measures such as Kernel Mode Code Signing which prevents unsigned and unauthorised code from accessing kernel memory – unfortunately in this instance Alureon is continuing to thrive and infect systems across the globe by installing a modified Master Boot Record and immediately causing Windows to restart. When this modified MBR is loaded, the rootkit can load its kernel module without the protections kicking in.

KitGuru says: This build of the Rootkit appears to be a beta build as it is not always successful in replicating and spreading, but it is still classed as a very dangerous exploit.

Become a Patron!

Check Also

The Crew 2 will get offline mode update soon

Last year, Ubisoft sparked backlash after it took its original open-world racing game, The Crew, …

4 comments

  1. Wonderful that is all we DONT need 🙁

  2. I wish these tossers would find a new bloody hobby.

  3. Must be some serious players out there building this crap, Apple?

  4. Heh, funny enough I thought the same thing.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!