Protect you computer and your data


Rootkits - Hidden Hazards On Your System

If you're concerned about security on yourprocess that Windows expects to find running,
computer network, there's a new word to addeither by replacing the process files, or by
to your vocabulary - rootkit. A rootkit is aadding  itself  into  them.
set of utilities installed on your computer
whose purpose is to hide what other programsWith the rootkit in place, the hacker has a
are doing. They've been around for a fewvirtual backdoor into your system. He can
years, but they didn't really hit theread your keystrokes, record passwords,
security spotlight until November 2005. Thatgather information from your network and
was when researchers discovered that some CDschange your data and files. A hacker with
from Sony were installing a rootkit on useraccess to your system through a rootkit can
computers as part of their DRM (Digitalreinstall hacking programs, access your
Rights Management) software. The purpose ofaccounts and your users' accounts and wreak
the rootkit was to prevent the DRM softwaregeneral havoc. It's the ultimate Trojan
from being detected and uninstalled - butbackdoor.
there was an unintended side effect. The
rootkit opened a security hole on thoseOnce a rootkit is installed, it's virtually
computers that couldn't be detected byimpossible to detect and remove. When a virus
standard security software, and left themdetection or spyware program runs, they don't
vulnerable to attacks by malicious softwaresee the rootkit processes - they see the
and  hackers.process that's cloaking it. Some may alter
their own files with the details and stats
That's bad news for users and ITassociated with the files that they're
professionals who depend on virus and spywarereplacing so that operating systems don't
detection programs to alert them to annotice a difference. A sysadmin who is an
invader on their networks. Generally, whenexpert in network security may be able to
you're computer is infected by spyware ordetect it by running system checks from an
malware , it can be detected by monitoringuninfected machine, but most agree that once
your computer activity. You can check thea rootkit has been installed, the only way to
running processes and find programs thatbe sure you've removed it is to wipe the
shouldn't be loaded. You can run a virus ordrive clean and install the operating system.
spyware scanner to find registry keys and
files that fit certain patterns. You canBecause rootkits don't install themselves,
monitor  activity  coming  in over a network.you can block them by blocking attempts to
penetrate your network. One way to effectuate
A rootkit makes all of those defensesthis is to install a spyware or malware
worthless by hiding the keys, files,protection program to help prevent rootkits
processes and communications from yourfrom being installed at the server level or
computer operating system. What your computeron individual desktops. The key is to
can't see, it can't report and you can't fix.practice excellent network security at all
The methods used to hide the files andtimes so that you block the programs that
processes vary and are getting more and moreinstall rootkits.
sophisticated. Most do it by 'hooking' into a



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105