<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Tech Off - Rootkits on x64 Vista: Are they feasible?</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Tech Off - Rootkits on x64 Vista: Are they feasible?</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Wed, 19 Jun 2013 19:07:16 GMT</pubDate>
	<lastBuildDate>Wed, 19 Jun 2013 19:07:16 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>3</c9:totalResults>
	<c9:pageCount>-3</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Tech Off - Rootkits on x64 Vista: Are they feasible?</title>
		<description><![CDATA[<p>I've noticed my desktop icons seem to be refreshing a lot more than I remember&nbsp;in the past and any suspicious behavior always triggers paranoid malware fears in my mind, but that's beside the point. I was thinking about the rootkit &quot;epidemic&quot; and was wondering
 if they're still a legitimate risk on x64 Vista.<br /><br />As far as I understand, rootkits that effectively hide their presence (i.e. not showing up in the process list, registry,&nbsp;file system, etc.) require a kernel mode component to intercept queries for information that could reveal them and return a modified result
 with themselves omitted.<br /><br />With x64 Vista closing the door on unsigned kernel drivers, is it still possible to have a truly stealthy rootkit (obviously moot if the rootkit is a signed)?<br /><br />Have there been any stories of Vista rootkits in the wild?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/261646#261646</link>
		<pubDate>Fri, 14 Mar 2008 09:36:24 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/261646#261646</guid>
		<dc:creator>TimP</dc:creator>
		<slash:comments>3</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/TimP/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - Rootkits on x64 Vista: Are they feasible?</title>
		<description><![CDATA[<p>I wouldn't expect you are infected with a rootkit.. and what the rootkit does, it tries to fool that host OS into believing its talking directly to the hardware, where as its actually talking to the rootkit, which is acting as&nbsp;'proxy'.<br /><br />The rootkit then has the ability to 'abuse' whatever data it feels nec coming from the kernel..</p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/5c0c8203a07f4ca596359dfa00c17f3d#5c0c8203a07f4ca596359dfa00c17f3d</link>
		<pubDate>Fri, 14 Mar 2008 10:26:06 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/5c0c8203a07f4ca596359dfa00c17f3d#5c0c8203a07f4ca596359dfa00c17f3d</guid>
		<dc:creator>stevo_</dc:creator>
		<slash:comments>3</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/stevo_/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - Rootkits on x64 Vista: Are they feasible?</title>
		<description><![CDATA[<p><blockquote>
<div class="quoteAuthor">TimP wrote:</div>
<div class="quoteBody">&#65279;
<p>I've noticed my desktop icons seem to be refreshing a lot more than I remember&nbsp;in the past and any suspicious behavior always triggers paranoid malware fears in my mind, but that's beside the point. I was thinking about the rootkit &quot;epidemic&quot; and was wondering
 if they're still a legitimate risk on x64 Vista.<br /><br />As far as I understand, rootkits that effectively hide their presence (i.e. not showing up in the process list, registry,&nbsp;file system, etc.) require a kernel mode component to intercept queries for information that could reveal them and return a modified result
 with themselves omitted.<br /><br />With x64 Vista closing the door on unsigned kernel drivers, is it still possible to have a truly stealthy rootkit (obviously moot if the rootkit is a signed)?<br /><br />Have there been any stories of Vista rootkits in the wild?</p>
</div>
</blockquote>
<br /><br />while I have not been spending time on this subject I will say:<br /><br />Yes, they are still &quot;possible&quot; <br /><br />just that the methods used by the cracker will have to be altererd to fit the new OS.<br /><br />I am not so sure that the &quot;signed driver&quot; bit even has much to do with a rootkit --- other than as a way in the door.<br /><br />as for your desktop well... find out what you changed recently.<br /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/49c8f281ef4146938e179dfa00c17fbe#49c8f281ef4146938e179dfa00c17fbe</link>
		<pubDate>Fri, 14 Mar 2008 13:35:35 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/261646-Rootkits-on-x64-Vista-Are-they-feasible/49c8f281ef4146938e179dfa00c17fbe#49c8f281ef4146938e179dfa00c17fbe</guid>
		<dc:creator>figuerres</dc:creator>
		<slash:comments>3</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/figuerres/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>