|
Rootkits are the utilities used by hackers for concealment of the nocuous activity: installations espionage ON, thefts of data, etc. In spite of the fact that they have initially been developed for systems Unix, now there is a growing amount rootkits for Windows, potentially representing serious threat.
According to anti-virus laboratory Panda Software, the growing amount of the nocuous programs known as rootkits, for Windows is noticed. Though there are no data about their massive use for attacks Windows, the present distribution shows, that for short terms they can become the basic means of hackers for performance of their nocuous actions.
PandaLabs, explains, "decisions of safety develop, but the same is done also by hackers in searches of new ways of imperceptible penetration into systems. In spite of the fact that they are not something new, rootkits were anew open as kind nocuous software that can help to carry out imperceptibly to the hacker set of nocuous actions. We saw, how they have been used in a combination with backdoor for an establishment of the removed control over computers.
Rootkit is really classics of nocuous codes as for the first time they have appeared about 10 years ago. They are utilities, which are used by hackers for concealment of the nocuous activity. For this purpose they modify operational system on a computer, and can even replace the basic functions. It means, that they not only hide own presence, but also and actions which are undertaken by the malefactor on the infected computer. Moreover, rootkit can hide presence of other nocuous programs on a computer, simply changing file data, keys of the register or active processes.
Till the present moment rootkits represented a serious problem for environments Unix, platforms for which have been initially developed. Even their name is derivative from ‘ the superuser ’ Unix, known as “root”, possessing the full rights and privileges in system.
How to be protected from rootkits
Best way to reveal rootkit - precautionary measures. A good measure of protection is adequately updated anti-virus decision, which is capable to block penetration of the majority rootkits. Gateway screens also are exclusively useful, as can prevent rootkits to get through not protected ports and to stop their activity if they were already installed on a computer.
Useful tools:
Reveal rootkit
|