Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Weekly Brief
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Trojan Horses

Rootkits: Invisible Assault on Windows

These clever attacks are not new, but they pose a growing threat to Windows PCs.

Scott Spanbauer

Monday, May 02, 2005 1:00 AM PDT
Recommend this story?
Photograph: Joe Zeff

According to Microsoft, a type of malware common to Unix-based computers is now becoming more common and more sophisticated in the Windows world. The Trojan-horse-like programs--called rootkits--are extremely hard to detect and can grant a hacker complete control over your PC. Microsoft first warned of them at a security conference in February. Then utility vendor Sysinternals released a rootkit detector called RootkitRevealer, and antivirus vendor F-Secure launched a beta of Blacklight, a rootkit detector and remover that it plans to build into upcoming versions of its security products.

Like Trojan horse programs, rootkits install themselves by exploiting flaws in your PC's network security or by piggybacking onto e-mail messages or downloaded programs. They often open back doors for their remote puppet masters, who may be looking for credit card numbers, a broadband-connected spamming platform, or the simple thrill of the hack. But unlike standard Trojan horses, rootkits infiltrate the operating system at a deeper level, using security privileges to better hide themselves.

Detection Work

Like detecting viruses and worms, trapping rootkits is a cat-and-mouse game. Shortly after F-Secure released Blacklight, the author of a rootkit called Hacker Defender posted a video demonstrating a new version of his rootkit defeating Blacklight and several other defensive tools, including RootkitRevealer.

Since rootkits can work with spyware, viruses, and other malware in blended threats, security vendors are sharpening the tools they'll need for detecting them. According to Russ Cooper, who founded and moderates the NTBugtraq newsletter, looking for the kinds of techniques that rootkits use is a good idea. But Cooper doesn't think that rootkit infections are on the rise. "Rootkits are no more prevalent now than they've ever been," he believes. And as for rootkit removal tools, Cooper remarks that "only a person with very little knowledge would try to remove a rootkit," adding that the one certain cure is to wipe the hard disk and reinstall the OS. Mikko Hypponen, F-Secure's director of antivirus research, mostly concurs with Cooper, but points out that Blacklight can address situations where no known good backup is available.

Rootkit detectors and antivirus programs will continue to look for ways to outhack the hackers. But for now, standard security tools such as a good firewall and up-to-date antivirus protection are the best defense against rootkits.


Recommend this story?
Related Searches: rootkitrootkitsmalwaretrojan
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
Verizon will provide Internet protocol and security services, as well as emergency communications services to help the department respond quickly to disasters. 16-May-2008
Florida's attorney general said on Thursday the state was seeking to fine Verizon for violating service standards. 16-May-2008
The device, known as the Thunder, is to be sold exclusively through Verizon Wireless in the U.S. and Vodafone abroad. 16-May-2008
Hundreds of Grand Theft Auto IV fans eager to get their hands on a free copy of the game have been targeted by a Trojan virus. 16-May-2008
A security researcher has published a demonstration exploit that takes advantage of the download mechanism in Apple's Safari. 16-May-2008
A flood of voracious ants is heading straight for Houston, taking out computers, radios and even vehicles in their path. 16-May-2008
Maps showing noise levels in towns across England were published on Friday in an attempt to reduce the disruption caused by factories, planes, trains and cars. 16-May-2008
Unveiled at the Konami Gamer's Night on Wednesday, Rock Revolution was confirmed for release on Xbox 360, PS3, Wii, and DS. 16-May-2008
A fourth unannounced game, being developed by Resident Evil creator Shinji Mikami, is also in the works. 16-May-2008
According to NPD data released Thursday, Nintendo sold an incredible 714,000 Wiis last month. 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)