
SCOTT SIDEL'S DOWNLOADS
Shining a spotlight on rootkits
Scott Sidel 08.23.2007
Rating: -2.00- (out of 5)




|
A rootkit, like a cloak of invisibility, is a program that conceals the presence of an application on a computer. Installing itself silently, it stays concealed by hiding processes, files, network traffic and other observable information about itself from the computer user. Rootkits typically hide utilities that make it easy for attackers to return to a compromised system. Rootkits aren't easily detected and since no single vendor reliably detects all rootkits, it can be beneficial to work with more than one free rootkit tool.
Sophos Anti-Rootkit is a sophisticated rootkit detector and remover for Windows NT, 2000, XP and 2003. Before scanning, it's strongly recommended to close down all non-essential applications. A rootkit scan can take several minutes on a desktop computer or significantly longer on a server. The scan searches for hidden files, processes, registry keys and values. When the scan finishes, a pop-up screen appears, confirming the status and results of the scan. Click on the suspicious file to display more information about it. The information displayed includes whether the item is recommended for removal. If a suspicious file is recognized it can be safely removed, and if the scanner isn't sure what it is, but considers it suspicious, it can still be removed.
Panda AntiRootkit, like Sophos, has a GUI and allows for command-line options. Also like Sophos, it identifies known rootkits and suspicious rootkit behaviors indicative of unknown rootkits and provides the option of removing them along with their associated registry entries, processes and files. Panda AntiRootkit looks for hidden files, registry entries, drivers, processes, execution hooks and does an excellent job of ferreting out possible rootkits. Panda AntiRootkit runs on Windows 2000, XP and 2003. It does a thorough job of removing dangerous rootkits even when it can't fully identify them.
If one of the rootkit scanners mentioned above doesn't do it for you, you can also run additional rootkit detection and removal tools such as:
McAfee Rootkit Detective is a program designed to detect and clean rootkits and works on XP, 2000 and 2003. However, McAfee strongly recommends its software only be used by knowledgeable individuals at the direction of, and with the support of a representative from McAfee Avert Labs or McAfee Technical. AVG Anti-Rootkit Free provides for rootkit detection and removal and works on Windows 2000 and XP.
Rootkit detection and removal is showing up as part of more anti-virus packages, but these scanners can help provide an additional line of defense against the dark arts.
About the author:
Scott Sidel is an ISSO with Lockheed Martin.
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
 |
 |
|  |
RELATED CONTENT
 |
Malware, Viruses, Trojans and Spyware |
 |
Increase in Gumblar backdoors poses FTP credential problems
|
 |
Hackers to sharpen malware, malicious software in 2010
|
 |
iPhone worm Rickrolls jailbroken phones
|
 |
Israeli Mossad add Trojan Horse to Syrian laptop
|
 |
Schneier-Ranum Face-Off: Is antivirus dead?
|
 |
Modern malware, stealthy botnets, adapt quickly, expert says
|
 |
Computer worm infections up, scareware antivirus down, Microsoft says
|
 |
Web-based attacks skyrocket, pirating sites surge, security firms say
|
 |
Mini guide: How to remove and prevent Trojans, malware and spyware
|
 |
Kaspersky system analyzes malicious URLs on Twitter for malware
|
|
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |