Security 10816 Published by

Rootkit writers have outfoxed Windows 64-bit PatchGuard protection, Kaspersky Lab reports.



From PCWorld:
A product of the BlackHole Exploit Kit, a hugely successful kit for building malware to hit specific software vulnerabilities, the first element of the attack on a system is straightforward enough, using a downloader to hit the system through two common Java and Adobe Reader software flaws.

On 64-bit Windows systems open to these exploits, this calls a 64-bit rootkit, Rootkit.Win64.Necurs.a., which executes the 'bcdedit.exe -set TESTSIGNING ON command, normally a programming command for trying out drivers during development.
  New Malware Targets 64-Bit Windows