Vista System Restore Rootkit

rites: Microsoft Vista has introduced new implementation for system restore feature.But does this new implementation really make it more reliable?

On 19th,July 2008, I have presented a pure user mode rootkit to hide its file and registry keys from Vista system restore in HIT(hackers in Taiwan) conferrence, which means the Vista system resotre will not help user to restore the given rootkit's file and registry settings although other normal files are restored.

What may be interesting is the theory can also be used for malware to infect system without any popup of modern HIPS thru system restore.

The theory is almost like a "hook" technology in rootkit domain, it injects the system restore flow and provide a fake restore impact to user.Regarding another way -- "DKOM" trick against the system restore, I also have some research results, and might introduce it somewhere later.

Please refer to the following link for the slides : ( it also include protection and detection technology)
http://www.rootkit.com/vault/cardmagic/HIT2008_CardMagic.ppt

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值