Daily Virus Report (Sep 13, 2008) - Rootkit.Win32.RESSDT.eh
- RISING
Sep 13, 2008 one virus needs your attention. It is EH (Rootkit.Win32.RESSDT.eh). This virus is a Rootkit driver, and this virus recovers SSDT (System Service Descriptor Table) on driver layer.  In this way, the self-protection function and monitor function will be disabled, and so, the virus can spread and infect computer system without limitation.  
 
Name: EH (Rootkit.Win32.RESSDT.eh)
Warning level: Dangerous
Category: Rootkit
Affected System: Windows NT/2000/XP/2003

Description:
This is a Rootkit driver, and usually spreads combined with account stealer Trojan. After startup, the virus recovers SSDT (System Service Descriptor Table) on driver layer through service function address and index which are calculated through user layer. So, the virus can disable self-protection function and monitor function of certain antivirus. And then, the viruses which combine with this Rootkit driver can destroy computer system without limitation. It makes computer users suffered.
 
Anti-virus experts suggest that computer users take the following measures to protect against this virus:
1. Install Rising Anti-virus, personal firewall, update in time, and at least 3 times per day for updating Rising.
2. Use Rising Vulnerability Check, patch your computer system in a timely manner as many viruses spread by taking advantage of the system exploits or vulnerabilities.
3. Do not browse suspicious websites, and suspicious inserter; turn off or delete unnecessary system services.
4. Do not receive the suspicious file from QQ, MSN, Email, etc.
5. Open auto-protect and auto-monitor function when accessing to the internet.
6. Put your account information of networks bank, networks game, MSN, QQ, Yahoo Messenger etc, into Rising Application Protection, Rising Application Protection can protect specified applications from attack by malicious programs. A user can apply rules to game software, instant messenger, etc. to customize protection.
 
*You can buy RISING Antivirus here or free download to try.
*If you have any questions about RISING products, please visit Rising support centre  for help.
 
 
 
Products
Rising PC Doctor
Rising Antivirus 2011
Rising Firewall 2011
Rising Internet Security 2011
Rising Online Scanner
Awards & Certifications