A root kit is a trojan horse virus that modifies operating system code to allow it to grant itself system administrator authority and create a backdoor through which the hacker can access your system. A root kit usually installs utilities that allow the hacker to spawn a remote Shell, login, and start processes to open ports, intercept keystokes, collect data, sniff for usernames and passwords, and scan a network for vulnerabilities to exploit.
Welcome to Bucaro TecHelp!

Welcome to Bucaro TecHelp!
Maintain Your Computer and Use it More Effectively
to Design a Web Site and Make Money on the Web

[About BTH]  [User Agreement]  [Privacy Policy]  [Site Map]  [Contact Form]  [Advertise on BTH]  [News Feed]

Google
Web
This Site

Root Kit - The Hackers Backdoor to Your Computer

Root kit is the latest buzz word in the computer technology world. Root kit refers to a new more insidious kind of computer virus that cannot be detected by anti-virus software. Actually root kits have been known in Unix/Linux systems for many years. The word "root" comes from the "root" account (system administrator) in Linux.

It's just lately that the existence of root kits in Microsoft Windows systems has been exposed. Greg Hoglund, a computer security consultant and authority on Windows root kits believes intruders have been using Windows root kits covertly for years.

A root kit is a trojan horse virus that modifies operating system code to allow it to grant itself system administrator authority and create a backdoor through which the hacker can access your system. A root kit usually installs utilities that allow the hacker to spawn a remote Shell, login, and start processes to open ports, intercept keystokes, collect data, sniff for usernames and passwords, and scan a network for vulnerabilities to exploit.

Any average programmer can write a kernel mode root kit. Hoglund teaches a two-day course on root kits, and by the end of the course, every student is writing their own root kits.

Detecting root kits

Whereas the goal of a common computer virus is to spread itself to other systems, the primary goal of a root kit is self preservation. For example it may regularly check the integrity of it's components and reinstall them if necessary. Conventional viruses operate in user mode, which means they create processes and registry entries visible in system administration utilities.

When a system administrator uses a utility to check for a root kit, the root kit intercepts the system calls and filters out any messages that would expose the root kit. Normal indicators of a program running, such as executable file name, process name, memory usage, or registry settings are invisible. As a result, root kits cannot be detected by conventional detection tools including anti-virus and anti-spyware applications.

The root kit may remain hidden until a system crash reveals the name of one of it's processes as the component that caused the crash. There are several programs available to detect root kits on Unix systems, for example chkrootkit and rkhunter. Microsoft is working on a tool that can detect root kits on Windows systems, however, at the present time the only reliable way to remove a root kit from Windows is to completely erase the hard drive and reinstall Windows from scratch.

One promising Windows root kit detector is the Freeware program RootkitRevealer. RootkitRevealer runs on Windows NT 4 and higher and it lists any Registry, file system, or API discrepancies that may indicate the presence of a root kit. However, RootkitRevealer does not claim to detect every root kit.

Computer Sections

RSS Feed RSS Feed

AntiVirus, Firewall, and Antispyware
Microsoft Security Essentials
Tips to Protect Windows Vista Operating System
A Guide to Understanding Security and Safe Windows Vista Computing
Flash Animations and Videos Install Viruses
Top Tips To Secure Your Online PC
The Complete Malware Prevention, Protection, and Removal Guide
Five Critical Steps to Protect Your Personal Information and Computer
Six Steps to Get and Keep Your Computer Running at Full Speed
Top Eleven Tips for Safe Computing
What is Phishing and How to Safeguard Against It
How Many Spyware Items Are Slowing Down Your Computer?
Avoid the Indigestion of Cookies
Four Tips to Safe Web Browsing
No Software on the Market Removes All Spyware
FREE Antivirus Software : Avast!
FREE Antivirus Software : AVG
What is Spyware?
Root Kit - The Hackers Backdoor to Your Computer
What's a Root Kit and How Hackers Are Getting Into Your Computer With It


TigerDirect
[Site User Agreement]  [Advertise on This site]  [Search This Site]  [Contact Form]
Copyright©2001-2009 Bucaro TecHelp P.O.Box 18952 Fountain Hills, AZ 85269