Microsoft has reported a fast-spreading rootkit that can infect both 32bit and 64bit Windows operating systems. The rootkit is spread through drive-by download, which means all a user has to do is visit a webpage hosting an exploit kit to be infected.

[…] variants of Necurs were reported on 83,427 unique machines during the month of November 2012. – Technet Blog

Necurs buries itself deep into systems, allowing it to bypass typical security programs and disable antivirus software. Once it is on the system detection is very difficult, as is removal. Your best bet is to prevent it from ever reaching your system.

Once Necurs infects a machine it can do a lot. It immediately hides itself and takes significant effort to protect itself from detection or removal. It can backdoor the system, allowing remote access to it, install more malware to monetize the system, and hijack your email to send out spam messages.

After infection the only real way to be sure a rootkit like Necurs has been removed is to reformat the system and perform a clean install. Products that use BootCDs may or may not be effective.

Keeping Necurs out of your system is the best way to be safe, as you can’t rely on removal/ detection once it’s on the system. Recently it was reported that when the Blackhole Exploit Kit detects the Chrome browser it tries a social engineering method instead of exploitation, due to Chrome substituting its own PDF plugin and disabling Java by default. Using Chrome is a good way to stay safe, but make sure you keep all of your programs up to date. Be sure to check out EMET for protection against 0-day exploits.



blog comments powered by Disqus

Published

11 December 2012

Category

security

Tags