Windows XP PCs breed rootkit infections


Recommended Posts

Windows XP PCs breed rootkit infections

Three-fourths of all rootkits on decade-old OS, says antivirus firm

Machines running the decade-old Windows XP make up a huge reservoir of infected PCs that can spread malware to other systems, a Czech antivirus company said today.

Windows XP computers are infected with rootkits out of proportion to the operating system's market share, according to data released Thursday by Avast Software, which surveyed more than 600,000 Windows PCs.

While XP now accounts for about 58% of all Windows systems in use, 74% of the rootkit infections found by Avast were on XP machines.

XP's share of the infection pie was much larger than Windows 7's, which accounted for only 12% of the malware-plagued machines -- even though the 2009 OS now powers 31% of all Windows PCs.

Rootkits have become an important part of the most sophisticated malware packages, particularly botnets, because they mask the infection from the user, the operating system and most security software. By installing a rootkit, the hacker insures the compromise goes undetected as long as possible, and that the PC remains available to the botnet's controller for nefarious chores, such as sending spam or spreading malware to other machines.

Avast attributed the infection disparity between XP and Windows 7 to a pair of factors: The widespread use of pirated copies of the former and the latter's better security.

"According to our stats, as many as a third of XP users are running SP2 [service Pack 2] or earlier," said Ondrej Vlcek, the chief technology officer of AVAST, in an interview Thursday. "Millions of people are out of support and their machines are unpatched."

Vlcek assumed that many of the people running XP SP2, which Microsoft stopped supporting with security patches a year ago, have declined to update to the still-supported SP3 because they are running counterfeits.

Although Microsoft serves everyone, even pirates, its monthly security patches and service packs, most security experts believe that users of illegal copies are very hesitant to upgrade or even patch for fear that they'll trigger the black screen and anti-piracy nag notices that Microsoft slaps on screens when it deems a PC is running a counterfeit copy of Windows.

Rootkit%20Numbers.jpg

Vlcek urged users running legal copies to upgrade to XP SP3. "Moving to SP3 is the most basic thing that should be done," he said.

Also in play, said Vlcek, is Windows 7's stronger security, especially the 64-bit version.

"The 64-bit version [of Windows 7] has some technologies that really make it much more difficult for rootkits to infect the computer," said Vlcek, calling out that version's kernel driver-signing feature as key to keeping rootkits off machines.

But that hasn't completely protected Windows 7 64-bit, as Vlcek acknowledged.

"The surprising part to me was that I thought the Windows 7 [number] would be even smaller," Vlcek said.

Rootkits able to infect 64-bit copies of Windows 7 remain relatively rare, but they're certainly not unknown: The first popped up in August 2010, and a massive botnet some have called "practically indestructible" last month used a variant of the same malware to install a 64-bit rootkit on Windows 7.

That malware, which goes by a number of names -- Alureon, TDL, Tidserv and most recently, TDL-4 -- is especially devious, as it installs the rootkit into the Master Boot Record (MBR). The MBR is the first sector -- sector 0 -- of the hard drive, where code is stored to bootstrap the operating system after the computer's BIOS does its start-up checks.

By subverting the MBR, the rootkit is even tougher to detect, since it's already in place by the time the OS and security software are loaded into memory.

Avast found that rootkits which infected the MBR were responsible for 62% all rootkit infections.

Users who suspect that their PC is infected with an MBR-based rootkit can scrub their machine with one of several free rootkit detectors, including Avast's "aswMBR" and Sophos' "Anti-Rootkit."

Source: Computerworld

/pwned only if running as admin. Just run it as limited user and use the built-in RunAs or SuRun (http://www.wilderssecurity.com/showthread.php?t=196737) if you use app that require admin privileges. There's ASLR (http://wehntrust.codeplex.com/) for XP too.

The fact that Windows 7 has a 12% share of the infections shows that MS still has a way to go with idiot-proofing their OS.

I guess one of the problems with security software is that the more often it notifies the user about something, the less likely the user is to read it (and the more likely they are to just click "Yes").

The fact that Windows 7 has a 12% share of the infections shows that MS still has a way to go with idiot-proofing their OS.

I guess one of the problems with security software is that the more often it notifies the user about something, the less likely the user is to read it (and the more likely they are to just click "Yes").

The issue is everyone has java and nobody updates it.

since when did XP have a 58% market share.

http://en.wikipedia.org/wiki/OS_market_share

Even the artifically high values of "Net Market Share" only lists it as 51, while the more realistic median value is 37. Heck even the second highest value after the artificial NMS numbers is 42.1%.

so assumign the rootkit share numbers are more correct than the OS market share numbers they use. the numbers are even more scary for XP. and that would seem more in line with my experiences as well.

The fact that Windows 7 has a 12% share of the infections shows that MS still has a way to go with idiot-proofing their OS.

I guess one of the problems with security software is that the more often it notifies the user about something, the less likely the user is to read it (and the more likely they are to just click "Yes").

There's no cure for stupid.

Java's updater doesn't make it any easier at times.

Yeah, does the 64 bit version of java even have a working updater?

since when did XP have a 58% market share.

The 58% was probably true when the study was conducted and these are the results of that study....or are you really asking when did xp have 58% market share? If that's the case, then probably sometime last year?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Alien Isolation 2 will bring a new protagonist and setting, watch the reveal trailer here by Pulasthi Ariyasinghe Only a few weeks ago, Sega and Creative Assembly dropped a teaser for a new Alien Isolation. Today at Summer Game Fest, Alien: Isolation 2 was officially announced with a new trailer while also confirming a whole lot of information about the setting of this survival horror project. Check out the reveal trailer above. Leaving behind the Sevastopol space station, the sequel will take players to a remote colony world. With a Xenomorph (or more) on the loose, players will be navigating both the surface of the weather-ravaged planet as well as "the claustrophobic confines of the Weyland-Yutani outpost of Kurosaki Station." Interestingly, Creative Assembly is leaving behind Amanda Ripley, the daughter of Alien's Ellen Ripley, as the protagonist too. While it hasn't confirmed a name yet, players will be taking the role of a new character for this new adventure. The setting is also being described as a new hunting ground for the Alien. This will have players improvising and developing new tools to aid in their survival and escape, all to avoid "cinema’s deadliest killer." "It has been over a decade since we created the original Alien: Isolation and I am so excited to show everyone the first glimpse of the sequel," says Al Hope, Creative Director at Creative Assembly. "Our dedicated Survival team at Creative Assembly has been working hard to create a new, evolved Isolation experience continuing the legacy of the Alien franchise, making the eponymous killer smarter, the environment harsher and the chance of survival slimmer." Promising the same deadly tension from the original from over a decade ago, Alien: Isolation 2 is in development for PC, Xbox Series X|S, Nintendo Switch 2, and PlayStation 5. A release date has not been announced yet.
    • With how far Tim Apple's head has been up Trump's ass, there's no way this was done reluctantly.
    • Like the article stated, it's written completely from scratch, unlike the umpteen Chromium clones. It got its start as the browser built-in to the also written-from-scratch SerenityOS.
    • Hello, From looking at the screen shots in your motherboard's manual at https://endownload.colorful.cn/EnDownload/MotherBroard/2022/Intel 600/Manual/Intel 600 Series BIOS English/Intel 600 Series BIOS User Guide.pdf, you go to the ADVANCED option at the top of the BIOS (UEFI) menu, then select SECURITY in the list of options on the left.  From there  you can enable and set the Secure Boot mode. Regards, Aryeh Goretsky  
    • Final Fantasy VII Remake Part 3 is getting a simultaneous release across PC and all consoles by Pulasthi Ariyasinghe Square Enix showed up to the Summer Game Fest presentation today with multiple trailers showing off its next chapter in the Final Fantasy VII Remake saga. The final chapter of this trilogy now has an official name too, with it being dubbed Final Fantasy VII Revelation, following up Final Fantasy VII Remake and Final Fantasy VII Rebirth from recent years. Vincent Valentine, Cid, Cloud, Barret, Tifa, and more showed up in the trailers as they battle against enemies, or 'Weapons,' from the final chapter. "As the world teeters on the brink of annihilation, the final battle against Sephiroth begins," says the trailer description. "A meteor mars the sky, monstrous planetary guardians wreak havoc across the globe, and the fires of war rage. Now, Cloud and his companions must stand against this chaos to not only decide the planet's fate, but bring a legendary conflict to its conclusion." Following the reveal trailer, the show also dropped some gameplay footage that shows off a new way to travel across the open world using the Highwind airship. Players will be able to swap characters on during battles, use tactical mode to synchronize with allies, and summon their entities. Cid Highwind and Vincent Valentine are joining the party this time too. “FINAL FANTASY VII, first released in 1997, has been beloved by fans for many years and has since become a “legend” in its own right," added producer Yoshinori Kitase. "The FINAL FANTASY VII Remake Series that began in 2020 with everyone’s passionate support is finally reaching its climactic finale with FINAL FANTASY VII REVELATION. The story’s final destination represents my emotions spanning thirty years working on this title" One of the biggest revelations of this announcement, however, was the multiplatform release confirmation from the get-go. Square Enix will be releasing Final Fantasy VII Revelation across PC, Xbox Series X|S, Nintendo Switch 2, and PlayStation 5 in Spring 2027 without any timed exclusivity programs.
  • Recent Achievements

    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      485
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      78
    4. 4
      Steven P.
      68
    5. 5
      +Edouard
      61
  • Tell a friend

    Love Neowin? Tell a friend!