Welcome | Sign In
CRMBuyer.com
Security

Free Antivirus Download Roots Out Rootkits

Print Version
E-Mail Article
Reprints
Free Antivirus Download Roots Out Rootkits

Rootkits have become a severe threat in comparison to traditional malware because they are often overlooked by conventional antivirus systems. They execute by embedding applications within the operating system, so it is important to correctly distinguish between malicious rootkits and legitimately hidden processes.


Reading the Avaya-Nortel Roadmap requires a navigator
The release of the Avaya-Nortel roadmap has many people wondering what lies ahead for their customer contact initiatives. Join Ovum’s Ian Jacobs and Aspect CTO Gary Barnett to discuss how the integration of two product lines may affect you. Register for the webinar.

Grisoft Software, the developer of AVG Internet security products, introduced Tuesday a free product aimed at detecting and removing rootkits.

Rootkits, a specific malware type which hides in other applications or in a computer's operating system kernel, allow malicious applications to collect passwords and sensitive data from the infected computer without user knowledge. This collected personal information can be used to create spam from the infected computer as well as other criminal activities.

"Rootkits are the latest and greatest threat [to computer security]. We felt it was important to develop this free product now. We have a reputation for doing this," Richard Carlson, managing director of Grisoft, told TechNewsWorld.

Click here for LiveOps

Rootkit Threat

Rootkits have become a severe threat in comparison to traditional malware because conventional antivirus systems often miss the hidden rootkit. They execute by embedding applications within the operating system, which is also an essential application to many necessary programs including antivirus protection, so it is important to correctly distinguish between malicious rootkits and legitimately hidden processes.

Grisoft conducted six months of open beta program testing to ensure AVG Anti-Rootkit is able to protect users and operating systems without the confusion and hassle of false alarms.

Rootkits were originally used by hackers to cover their tracks after unauthorized access to computers. Today, these techniques have been redesigned in order to mask the presence of malicious software used to gather and exploit personal information such as credit card numbers and social security numbers, creating a serious threat to users.

"Rootkits are computer code that attempt to hide their actions and processes, making the job of detecting the code and the harmful processes very difficult," explained Larry Bridwell, vice president of Global Security Strategies for Grisoft. "AVG Anti-Rootkit is developed to detect and destroy rootkits effectively, without bothering users with false alarms."

How It Works

Users must download the stand-alone rootkit detection software to run locally on their computers. It does not make sense to run this type of operation from a Web application, said Carlson.

Grisoft's root kit detection application compares a user's Windows kernel with detailed snapshops of uninfected systems. If anomalies are detected, the software makes changes to correct the problems.

"We take a snapshot of how the file system on a computer should look. The devil is in the details with this process. It has taken us a lot of time to develop a baseline model," said Carlson. "Once we identify what should be present, we can map out the results to compare them to the user's system."

The baseline model is able to show various conditions Grisoft engineers have found to be affected by rootkit installations, said Carlson. Regular updates of the detection engine are needed to keep current with the frequent changes to the Windows kernel and other system files that Microsoft (Nasdaq: MSFT) issues.

Finding Infections

The real problem with effective protecting against rootkits is finding them, Carlson explained. This is something that traditional antivirus programs are not able to do.

Even if an antivirus program detected intrusions in files on the hard drive after scanning every file, it cannot completely remove the altered files. Once the user reboots the computer, the rootkit recreates the necessary files.

"Rootkits fool these antivirus applications and change the kernel so they can operate at ring 0 as hidden files. When a traditional antivirus scan is performed, they find nothing," said Carlson.

Free Philosophy

Grisoft decided to release the free rootkit download now rather than waiting. The company plans to offer a paid version of the rootkit technology in the fall as part of the release of its version 8.0 security suite.

"We didn't want to hold up getting this protection into the hands of 50 million people relying on our free security products," Carlson explained.


Print Version E-Mail Article Reprints More by Jack M. Germain


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Jack M. Germain

The Gaping Hole Where Auto Software Standards Should Be
March 18, 2010
Toyota is not the only car maker navigating around accusations of quality problems with its auto controls, but recent fatalities drove the company into the spotlight. Over the years, Ford, Audi and Nissan had similar troubles. In all cases, government agencies responsible for overseeing consumer safety detoured away from the situation.
Notable Note Apps for Fastidious FOSS Freaks
March 17, 2010
At their heart, note-taking apps perform a very simple function: put letters on the screen. They differ widely, though, in the special features each offers. Tomboy Notes, for example, is the power of WikiText, which keeps multiple notes on any topic organized, no mater how you rename or rearrange them. With Xpad, you can banish sticky notes from your real desktop and keep them neatly inside the computer screen.
New Cisco Router Boasts Breakneck Speeds
March 09, 2010
With its eye on Internet video and new online services that require ever increasing amounts of bandwidth, Cisco has announced its new CRS-3 Carrier Routing System. The company offered up a few examples of just how speedy CRS-3 is: Hypothetically, the system could serve up a copy of every movie ever made in less than four minutes, or facilitate video calls for every person in China simultaneously.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network