Archive for August, 2006

Experts divided over rootkit detection and removal

Monday, August 28th, 2006

The great Rootkit debate has started up again. If you have a rootkit then you should wipe your PC and do a fresh windows installation! That is the advice from many of the security experts around the Internet. Others disagree saying that Antirootkit Software will remove the rootkit and Anti Virus or Anti Spyware software will remove what lies beneath the rootkit. I stand half way down the middle on this one.

Experts from Microsoft have recently said to wipe all the data from your hard drive and do a fresh install of the Operating System because you may never really find out what the rootkit was hiding. I tend to believe that most rootkit infections hide other well known malware such as viruses, keyloggers and spyware. Thus if you uncloak the rootkit and do a scan with any anti-virus or anti spyware it will show you what the rootkit was trying to hide.

I know plenty of people who would rather keep a rootkit on their PC than do a reinstall of the operating system. I then know other people who would jump straight away at doing a fresh install. There are people who use their PC for just browsing the internet and playing card games. To them the presence of a rootkit may manifest itself as popups by virtue of the underlying hidden spyware and this may not be enough for them to wipe their PC. Click on the X of the popup or wipe and reinstall the Operating System. To a newbie or a dontcarebie the thoughts of wiping and reinstalling is too big a job to handle and “sure, we’ll just get Uncle Steo to do it”.

Then you have the people who have to be overly sensitive to the data on PC’s. Banks, Institutions and other high profile companies need to have the upmost confidence in the fact their data is secure from both prying and criminal eyes. To them the cost of wiping and reinstallation of a PC’s OS is fine as long as their data is safe.

So when it comes to Rootkits and whether you should wipe your drive firstly scan your PC with some of the widely available anti rootkit scanners and see if it can uncover the rootkit. Then scan your drive with anti virus and anti spyware scanners and also keep an eye out for unusual files. If you think you have found an unusual file you can upload it onto one of the many online file scanners to check it for maliciousness.

Keep Safe

regards
Steo
www.antirootkit.com

GROMOZON.COM - The strange case of Dr.Rootkit and Mr.Adware

Thursday, August 24th, 2006

Rootkits, more emerging threats

Wednesday, August 2nd, 2006