A new rootkit has been found in the wild by and reported by F-Secure. This follows days from when Sana Security found the Rootkit.Hearse rootkit. This time the rootkit code has been bundled with the Bagle worm to make up a new Bagle variants.
This is a new departure for the Bagle worm which has been in existance for a while now. The Bagle worm is very powerful as it is but with the addition of rootkit techniques it makes it more powerful because of its stealth.
The Bagle variants Bagle.GE and Bagle.GF work together to setup a proxy on the infected PC so that the Bagle variant author can use the PC to send out Spam and other criminal related activity. The Bagle.GE variant holds the rootkit code and this in turn hides the files that the Bagle.GF variant uses.
F-Secure has reported that the rootkit code is limited and seems to be a test for worse to come.
Keep Safe
regards
Steo
www.antirootkit.com