One would have to know how this rootkit was infecting machines. This would also mean that MS would have also known this security exploit existed. I relaize as is often the case with large corporations there is often little colaboration on issues which certain departments see as 'their's'. MS needs to learn this valuable lesson if they are serious about changing their image which is still tarnished by Vista & Windows ME releases. The release first then do dammage control later mantra is one which is just not an option any longer. A great example is Google with Buzz. There are certain features which BUZZ is missing such as a DISABLE option up until yesterday or today. These features being omitted is just out of character for Google which is why I think they can get away with it, just this once. As sad as it is to say people will compare google's poor handling of Buzz to a common occurance with Microsoft.

On a side note I fully agree with the two posters above. MS needs to release potentially one or both of the following. The first is an easy to use one click removal tool for this rootkit and the second is alter the patch code for MS10-015 and add in a check prior to patch install.

Reply

The content of this field is kept private and will not be shown publicly.

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy