<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Free PC Security &#187; Rootkits</title>
	<atom:link href="http://cotojo.wordpress.com/category/rootkits/feed/" rel="self" type="application/rss+xml" />
	<link>http://cotojo.wordpress.com</link>
	<description>This blog has moved to http://freepcsecurity.co.uk</description>
	<lastBuildDate>Wed, 08 Apr 2009 16:37:06 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='cotojo.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/5df84ed03df631a35924ae37bf2f3079?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Free PC Security &#187; Rootkits</title>
		<link>http://cotojo.wordpress.com</link>
	</image>
			<item>
		<title>Virus Alert</title>
		<link>http://cotojo.wordpress.com/2007/11/05/virus-alert/</link>
		<comments>http://cotojo.wordpress.com/2007/11/05/virus-alert/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 11:02:13 +0000</pubDate>
		<dc:creator>cotojo</dc:creator>
				<category><![CDATA[PC Security]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[autoply.exe]]></category>
		<category><![CDATA[Bindo.A]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[Nuwar.HU]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://cotojo.wordpress.com/2007/11/05/virus-alert/</guid>
		<description><![CDATA[Some 30% of computers with a security solution installed scanned last week  were infected with some kind of malware.  In the case of computers without any kind of protection, the figure goes up to 44%. Source: http://www.infectedornot.com
Click Image for full article.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=342&subd=cotojo&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Some 30% of computers with a security solution installed scanned last week  were infected with some kind of malware.  In the case of computers without any kind of protection, the figure goes up to 44%. Source:</strong> <a rel="nofollow" href="http://www.infectedornot.com" target="_blank"><span style="color:#0000ff;">http://www.infectedornot.com</span></a></p>
<p style="text-align:center;"><span style="color:#000000;"><strong><a rel="nofollow" href="http://freepcsecurity.co.uk/2007/11/05/virus-alert/"><img class="aligncenter" title="Free PC Security" src="http://i198.photobucket.com/albums/aa306/cotojo/FPCS.jpg" alt="Free PC Security" width="582" height="140" /></a></strong></span><span style="color:#000000;"><strong>Click Image for full article</strong>.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/cotojo.wordpress.com/342/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/cotojo.wordpress.com/342/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cotojo.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cotojo.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cotojo.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cotojo.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cotojo.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cotojo.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cotojo.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cotojo.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cotojo.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cotojo.wordpress.com/342/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=342&subd=cotojo&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://cotojo.wordpress.com/2007/11/05/virus-alert/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ce1491f304c9e3cc8f602cf54771390b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cotojo</media:title>
		</media:content>

		<media:content url="http://i198.photobucket.com/albums/aa306/cotojo/FPCS.jpg" medium="image">
			<media:title type="html">Free PC Security</media:title>
		</media:content>
	</item>
		<item>
		<title>CoolWebSearch</title>
		<link>http://cotojo.wordpress.com/2007/09/03/coolwebsearch/</link>
		<comments>http://cotojo.wordpress.com/2007/09/03/coolwebsearch/#comments</comments>
		<pubDate>Mon, 03 Sep 2007 11:54:56 +0000</pubDate>
		<dc:creator>cotojo</dc:creator>
				<category><![CDATA[CoolWebSearch]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[AdvancedWindowsCare]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[file-sharing]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[pop-ups]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[Spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[TeaTimer]]></category>
		<category><![CDATA[TrendMicro]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://cotojo.wordpress.com/2007/09/03/coolwebsearch/</guid>
		<description><![CDATA[This is a very nasty and insidious spyware/malware program.  Spyware experts are now saying that the makers are borrowing  code from other malicious programs to install rootkit like features on infected machines.
More recent versions of CWS spyware now have features similar to rootkits which allow the program writers to hide their files on Windows operating [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=95&subd=cotojo&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is a very nasty and insidious spyware/malware program.  Spyware experts are now saying that the makers are borrowing  code from other malicious programs to install <a target="_blank" href="http://cotojo.wordpress.com/2007/08/02/what-is-a-rootkit/"><font color="#0000ff"><strong>rootkit</strong></font></a> like features on infected machines.</p>
<p>More recent versions of CWS spyware now have features similar to rootkits which allow the program writers to hide their files on Windows operating systems.</p>
<p>These new variants can hide their settings in the registry and also hide rootkit files in alternate data streams.</p>
<p>The software is usually installed on a machine by visits to malicious websites or  emails using various ploys to get users to download and install the script.</p>
<p>Once installed, CoolWebSearch will hijack browsers and redirect users to some of the several bookmarks it imports.  When you attempt to change your homepage back again it constantly overwrites it,  it slows down general performance and causes Windows to freeze, crash or reboot, and can also make you victin to a Denial of Service (DOS) attack.</p>
<p>Getting rid of it is now much easier.  TrendMicro have a free <a target="_blank" href="http://us.trendmicro.com/us/products/personal/CWShredder/index.html"><font color="#0000ff"><strong>CoolWebSearch removal program</strong></font></a></p>
<p>Use this utility to get rid of CoolWebSearch and it&#8217;s related programs. </p>
<p>Also download <a target="_blank" href="http://cotojo.wordpress.com/2007/05/23/spybot-search-and-destroy/"><strong><font color="#0000ff">Spybot S&amp;D</font></strong></a> and use its TeaTimer protection, which runs in the background and alerts you to any attempted registry changes.</p>
<p>If you are running Windows, also use  <strong><a target="_blank" href="http://cotojo.wordpress.com/2007/06/21/advanced-windows-care-from-i0bit/"><font color="#0000ff">Advanced Windows Care</font></a></strong>.  Both of these programs will add a large number of changes to your Registry.  This is nothing to be concerned about as the changes are necessary to stop any nasties from attching themselves to your pc and making changes you really don&#8217;t want.</p>
<p>Keep your <a target="_blank" href="http://cotojo.wordpress.com/2007/06/26/lavasoft-ad-aware-2007-free-edition/"><strong><font color="#0000ff">anti-spyware</font></strong></a> up to date and if you click on any links that prompt you to download, read the EULA first.</p>
<p>Check for <a target="_blank" href="http://cotojo.wordpress.com/2007/08/02/avg-anti-rootkit-free/"><strong><font color="#0000ff">rootkits</font></strong></a> on your machine.</p>
<p>As with all programs, regular updates is essential to offer you greater protection.</p>
<p><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></a><a href="http://www.digg.com"></p>
<p style="text-align:center;"><img width="91" src="http://digg.com/img/badges/91x17-digg-button.gif" alt="Digg!" height="17" /></p>
<p><!-- AddThis Bookmark Button BEGIN --></p>
<p align="center"><a target="_blank" href="http://www.addthis.com/bookmark.php" title="Bookmark using any bookmark manager!"><img border="0" width="160" src="http://s9.addthis.com/button2-bm.png" alt="AddThis Social Bookmark Button" height="24" /></a></p>
<p></a></p>
<p align="center"><a target="_blank" href="http://www.bloggingtofame.com/action.php?view=blog&amp;id=996"><img border="0" src="http://www.bloggingtofame.com/images/widgit_02_03.gif" /></a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/cotojo.wordpress.com/95/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/cotojo.wordpress.com/95/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cotojo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cotojo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cotojo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cotojo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cotojo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cotojo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cotojo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cotojo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cotojo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cotojo.wordpress.com/95/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=95&subd=cotojo&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://cotojo.wordpress.com/2007/09/03/coolwebsearch/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ce1491f304c9e3cc8f602cf54771390b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cotojo</media:title>
		</media:content>

		<media:content url="http://digg.com/img/badges/91x17-digg-button.gif" medium="image">
			<media:title type="html">Digg!</media:title>
		</media:content>

		<media:content url="http://s9.addthis.com/button2-bm.png" medium="image">
			<media:title type="html">AddThis Social Bookmark Button</media:title>
		</media:content>

		<media:content url="http://www.bloggingtofame.com/images/widgit_02_03.gif" medium="image" />
	</item>
		<item>
		<title>AVG Anti-Rootkit Free</title>
		<link>http://cotojo.wordpress.com/2007/08/02/avg-anti-rootkit-free/</link>
		<comments>http://cotojo.wordpress.com/2007/08/02/avg-anti-rootkit-free/#comments</comments>
		<pubDate>Thu, 02 Aug 2007 13:30:45 +0000</pubDate>
		<dc:creator>cotojo</dc:creator>
				<category><![CDATA[PC Security]]></category>
		<category><![CDATA[Rootkit Unhooker]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[anti-rootkit]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[file-sharing]]></category>
		<category><![CDATA[Grisoft]]></category>
		<category><![CDATA[IceSword]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[partitions]]></category>
		<category><![CDATA[path]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[Remove]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://cotojo.wordpress.com/2007/08/02/avg-anti-rootkit-free/</guid>
		<description><![CDATA[ May 2008 Important Note: Grisoft have now incorporated this as part of the new AVG Anti-Virus v8.0.1
It is only available in the paid version NOT the free version, so please scroll to the bottom of the page for more Rootkit Removers although the standalone version is available through the download link at the end [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=81&subd=cotojo&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong><span style="text-decoration:underline;"><em> May 2008 Important Note:</em></span> Grisoft have now incorporated this as part of the new</strong> <a href="http://cotojo.wordpress.com/2008/05/05/avg-anti-virus-free-edition-801/" target="_self"><span style="color:#0000ff;">AVG Anti-Virus v8.0.1<br />
</span></a><strong>It is only available in the paid version <span style="text-decoration:underline;"><em>NOT</em></span> the free version, so please scroll to the bottom of the page for more Rootkit Removers although the standalone version is available through the download link at the end of the description.<br />
</strong></p>
<p><strong>Grisoft has developed quite a following with its free (for personal, non-commercial use) security applications, and for good reason.</strong></p>
<p><strong>Now there&#8217;s an anti-rootkit utility in AVG&#8217;s free software stable, too, and for users seeking a minimum of interaction, AVG Anti-Rootkit Free may very well be the Right Tool for the Job.</strong></p>
<p><strong>Grisoft makes its free AVG Anti-Rootkit application available for download. Users download the avgarkt.exe setup file, which features simple installation.</strong></p>
<p><strong>In keeping with the goal to make AVG Anti-Rootkit a very simple tool, the file features a simple .exe install file that triggers a setup wizard.</strong></p>
<p><strong>Users can select between a normal interface (which Grisoft recommends and sets as the default) or a low graphics interface (which is optimized for visually impaired users who rely on screen-reading programs).</strong></p>
<p><strong>Users must accept the AVG Anti-Rootkit Free license agreement before they can use the program to check their Windows system for stealth rootkit programs.</strong></p>
<p><strong>Next, users must specify the location of the AVG Anti-Rootkit Free installation files.</strong></p>
<p><strong>As with most software programs, users must specify the name of the Start Menu Folder. This is the name the AVG Anti-Rootkit application receives on the user&#8217;s Start menu.</strong></p>
<p><strong>Once users have specified all setup information, the free anti-rootkit utility installs itself.</strong></p>
<p><strong>Due to the way most anti-rootkit applications operate, it&#8217;s necessary to reboot Windows to enable proper operation.  AVG&#8217;s free anti-rootkit application is no different.  AVG&#8217;s setup utility gives users the option of rebooting immediately automatically or manually rebooting later.</strong></p>
<p><strong>AVG purposefully keeps its anti-rootkit interface simple.  There are very few options for users to choose, thereby helping simplify the already confusing and complex world of rootkits.</strong></p>
<p><strong>AVG includes concise educational information aimed at helping regular (non-IT professionals) better understand the threat stealth rootkit programs present.</strong></p>
<p><strong>The Learn More tab lists information on what rootkits are and how users can protect their PCs from the stealth threats.  There&#8217;s also a link to Grisoft&#8217;s site where additional computer security information is made available.</strong></p>
<p><strong>Users can check for AVG Anti-Rootkit Free updates using the third tab (About &amp; Update). Clicking the About &amp; Update tab also reveals the current version users have installed.</strong></p>
<p><strong>An interesting note, Grisoft informs users on this third tab why the AVG Anti-Rootkit uses random window titles. The reason is that AVG&#8217;s programmers wanted intentionally to change the name of the window the free anti-rootkit application uses to help thwart detection efforts rootkit hackers might program into their malware.</strong></p>
<p><strong>If users click the Check For New Version button found on the third About &amp; Update tab, they are directed to Grisoft&#8217;s Web site.  Here users will see whether the version they are using is current or whether updates must be downloaded.</strong></p>
<p><strong>The Search For Rootkits tab is the meat of the program and the reason users will download it in the first place.</strong></p>
<p><strong>Clicking the Search For Rootkits button triggers a search of stealth rootkit programs. The free AVG application tracks its progress in the progress bar at the menu&#8217;s bottom.</strong></p>
<p><strong>By default, the Search For Rootkits button only searches critical Windows directories on the root drive.</strong></p>
<p><strong>When no rootkits are found, AVG presents a congratulations window.</strong></p>
<p><strong>When rootkits are found, AVG displays those that are found (with information on the rootkit path and type).  Users can then highlight the rootkit items in question and click the Remove Selected Items button to eliminate the offending files from their Windows systems.</strong></p>
<p><strong>With the In-Depth Search, however, AVG Anti-Rootkit searches for stealth rootkit files on all the hard drives and partitions within a system.</strong></p>
<p><strong>Just as with the simple rootkit search, the AVG Anti-Rootkit Free application tracks its progress as it works.  Should users wish, they can terminate the search using the provided Stop button.</strong></p>
<p><strong>These are all the options a user can select when working with AVG&#8217;s free anti-rootkit program.  By purposefully keeping the application easy to use, AVG engineers have created a free malware detection utility that&#8217;s the Right Tool for regular (personal) users seeking to check their systems for unwanted stealth software.</strong></p>
<p><a href="http://www.pcworld.com/downloads/file/fid,65198-order,1-page,1/description.html" target="_blank"><span style="color:#0000ff;">Download your copy here</span></a><strong><br />
</strong></p>
<p><strong>Do NOT rely upon just this Rootkit finder, use a few others too as they all vary in their search definitions and criteria.</strong></p>
<p><strong>You can find a comprehensive list at </strong><a href="http://www.antirootkit.com/software/index.htm" target="_blank"><span style="color:#0000ff;">AntiRootkit.com</span></a></p>
<p><strong>I recommend the use of</strong> <a href="http://www.antirootkit.com/software/IceSword.htm" target="_blank"><span style="color:#0000ff;">IceSword</span></a> <strong>and</strong> <a href="http://www.antirootkit.com/software/RootKit-Unhooker.htm" target="_blank"><span style="color:#0000ff;">Rootkit Unhooker</span></a>, <strong>but there are many free to use rootkit finders listed.  Check the column on the right to ensure it is Free and do NOT use the Beta versions.</strong></p>
<p><strong>Related Post:</strong><br />
<a href="http://cotojo.wordpress.com/2008/10/06/anti-rootkit-from-panda-free/" target="_self"><span style="color:#0000ff;">Panda Anti-Rootkit Free</span></a></p>
<p style="clear:both;padding-bottom:.25em;text-align:center;"><a title="Bookmark using any bookmark manager!" href="http://www.addthis.com/bookmark.php" target="_blank"><img class="aligncenter" src="http://s9.addthis.com/button2-bm.png" border="0" alt="AddThis Social Bookmark Button" width="160" height="24" /></a></p>
<p style="text-align:center;"><a href="http://technorati.com/faves?sub=addfavbtn&amp;add=http://cotojo.wordpress.com"><img class="aligncenter" src="http://static.technorati.com/pix/fave/tech-fav-1.png" alt="Add to Technorati Favorites" /></a></p>
<p style="text-align:center;"><a title="Join My Community at MyBloglog!" href="http://www.mybloglog.com/buzz/community/cotojo1/"><img class="aligncenter" style="border:0 none;" src="http://www.mybloglog.com/buzz/images/buttons/btn_c21_l.png" alt="Join My Community at MyBloglog!" /></a></p>
<p style="text-align:center;"><a href="http://uk.groups.yahoo.com/group/FreePCSecurity/join"><img class="aligncenter" src="http://us.i1.yimg.com/us.yimg.com/i/yg/img/i/uk/ui/join.gif" border="0" alt="Click here to join FreePCSecurity" /><span style="color:#0000ff;">Click to join FreePCSecurity</span></a></p>
<p style="text-align:center;"><a href="http://www.mywot.com/" target="_blank"><img src="http://i198.photobucket.com/albums/aa306/cotojo/logo_header.png" border="0" alt="WOT Logo" /></a></p>
<h6>© Free PC Security 2007 &#8211; 2008</h6>
<h6>Technorati Tags:<strong> </strong><a rel="tag" href="http://technorati.com/tag/Rootkits" target="_blank"><span style="color:#0000ff;">Rootkits</span></a>, <a rel="tag" href="http://technorati.com/tag/Technology" target="_blank"><span style="color:#0000ff;">Technology</span></a>, <a rel="tag" href="http://technorati.com/tag/Anti-Rootkit" target="_blank"><span style="color:#0000ff;">Anti-Rootkit</span></a>, <a rel="tag" href="http://technorati.com/tag/" target="_blank"><span style="color:#0000ff;">Free Tools</span></a>, <a rel="tag" href="http://technorati.com/tag/Free-PC-Security" target="_blank"><span style="color:#0000ff;">Free PC Security</span></a>, <a rel="tag" href="http://technorati.com/tag/IceSword" target="_blank"><span style="color:#0000ff;">IceSword</span></a>, <a rel="tag" href="http://technorati.com/tag/RootKit-Unhooker" target="_blank"><span style="color:#0000ff;">RootKit-Unhooker</span></a>, <a rel="tag" href="http://technorati.com/tag/Security" target="_blank"><span style="color:#0000ff;">Security</span></a></h6>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/cotojo.wordpress.com/81/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/cotojo.wordpress.com/81/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cotojo.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cotojo.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cotojo.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cotojo.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cotojo.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cotojo.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cotojo.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cotojo.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cotojo.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cotojo.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=81&subd=cotojo&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://cotojo.wordpress.com/2007/08/02/avg-anti-rootkit-free/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ce1491f304c9e3cc8f602cf54771390b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cotojo</media:title>
		</media:content>

		<media:content url="http://s9.addthis.com/button2-bm.png" medium="image">
			<media:title type="html">AddThis Social Bookmark Button</media:title>
		</media:content>

		<media:content url="http://static.technorati.com/pix/fave/tech-fav-1.png" medium="image">
			<media:title type="html">Add to Technorati Favorites</media:title>
		</media:content>

		<media:content url="http://www.mybloglog.com/buzz/images/buttons/btn_c21_l.png" medium="image">
			<media:title type="html">Join My Community at MyBloglog!</media:title>
		</media:content>

		<media:content url="http://us.i1.yimg.com/us.yimg.com/i/yg/img/i/uk/ui/join.gif" medium="image">
			<media:title type="html">Click here to join FreePCSecurity</media:title>
		</media:content>

		<media:content url="http://i198.photobucket.com/albums/aa306/cotojo/logo_header.png" medium="image">
			<media:title type="html">WOT Logo</media:title>
		</media:content>
	</item>
		<item>
		<title>What is a rootkit?</title>
		<link>http://cotojo.wordpress.com/2007/08/02/what-is-a-rootkit/</link>
		<comments>http://cotojo.wordpress.com/2007/08/02/what-is-a-rootkit/#comments</comments>
		<pubDate>Thu, 02 Aug 2007 12:10:23 +0000</pubDate>
		<dc:creator>cotojo</dc:creator>
				<category><![CDATA[PC Security]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[detection]]></category>
		<category><![CDATA[elusive]]></category>
		<category><![CDATA[kernel mode]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[signature file]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://cotojo.wordpress.com/2007/08/02/what-is-a-rootkit/</guid>
		<description><![CDATA[What is a rootkit?
A rootkit is not an exploit — it’s the code or program an attacker leaves behind after a successful exploit. The rootkit then allows the hacker to hide his or her activity on a computer, and it permits access to the computer in the future. To accomplish its goal, a rootkit will modify [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=82&subd=cotojo&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="text-decoration:underline;"><strong>What is a rootkit?</strong></span></p>
<p><strong>A rootkit is not an exploit — it’s the code or program an attacker leaves behind after a successful exploit. The rootkit then allows the hacker to hide his or her activity on a computer, and it permits access to the computer in the future. To accomplish its goal, a rootkit will modify the execution flow of the operating system or manipulate the data set that the operating system relies on.</strong></p>
<p><strong>Windows operating systems support programs or processes running in two different modes: user mode and kernel mode. Traditional Windows rootkits such as SubSeven and NetBus operate in user mode.</strong></p>
<p><strong>Also known as backdoors or Trojans, user-mode rootkits run as a separate application or within an existing application. They have the same level of system privileges as any other application running on the compromised machine. Since these rootkits operate in user mode, applications such as antivirus scanners can detect the rootkit’s existence if they have a signature file.</strong></p>
<p><strong>A kernel-mode rootkit is remarkably different — and much more powerful and elusive. Kernel-mode rootkits have total control over the operating system and can corrupt the entire system.</strong></p>
<p><strong>By design, kernel-mode rootkits control the operating system’s Application Program Interface (API). The rootkit sits between the operating system and the user programs, choosing what those programs can see and do.</strong></p>
<p><strong>In addition, it uses this position to hide itself from detection. If an application such as an antivirus scanner tries to list the contents of a directory containing the rootkit’s files, the rootkit will suppress the filename from the list. It can also hide or control any process on the rooted system.</strong></p>
<p><span style="text-decoration:underline;"><strong>Rootkit detection</strong></span></p>
<p><strong>Methods to detect rootkits fall into two categories: Signature-based and heuristic/behavior-based detection.</strong></p>
<p><strong><span style="text-decoration:underline;">Signature-based detection:</span> As its name implies, this method scans the file system for a sequence of bytes that comprise a “fingerprint” that’s unique to a particular rootkit. However, the rootkit’s tendency to hide files by interrupting the execution path of the detection software can limit the success of signature-based detection.</strong></p>
<p><strong><span style="text-decoration:underline;">Heuristic/behavioral-based detection:</span> This method works by identifying deviations in normal operating system patterns or behaviors. For example, this method could detect a rootkit by determining that a system with 200-GB hard drive that reports 160 GB of files has only 15 GB of free space available.</strong></p>
<p><strong>Rootkits are hard to detect. But there are programs – including a free one from</strong> <a href="http://cotojo.wordpress.com/2008/10/06/anti-rootkit-from-panda-free/" target="_blank"><span style="color:#0000ff;">Panda</span></a> <strong>which I have covered in another post.</strong></p>
<p><strong>Related Post:</strong><br />
<a href="http://cotojo.wordpress.com/2008/10/06/anti-rootkit-from-panda-free/" target="_self"><span style="color:#0000ff;">Panda Anti-Rootkit &#8211; Free</span></a></p>
<p style="text-align:center;"><a href="http://technorati.com/faves?sub=addfavbtn&amp;add=http://cotojo.wordpress.com"><img class="aligncenter" src="http://static.technorati.com/pix/fave/tech-fav-1.png" alt="Add to Technorati Favorites" /></a></p>
<p style="text-align:center;"><a title="Join My Community at MyBloglog!" href="http://www.mybloglog.com/buzz/community/cotojo1/"><img class="aligncenter" style="border:0 none;" src="http://www.mybloglog.com/buzz/images/buttons/btn_c21_l.png" alt="Join My Community at MyBloglog!" /></a></p>
<p style="text-align:center;"><a href="http://uk.groups.yahoo.com/group/FreePCSecurity/join"><img class="aligncenter" src="http://us.i1.yimg.com/us.yimg.com/i/yg/img/i/uk/ui/join.gif" border="0" alt="Click here to join FreePCSecurity" /><span style="color:#0000ff;">Click to join FreePCSecurity</span></a></p>
<p style="text-align:center;"><a href="http://www.mywot.com/" target="_blank"><img src="http://i198.photobucket.com/albums/aa306/cotojo/logo_header.png" border="0" alt="WOT Logo" /></a></p>
<h5>© Free PC Security 2007 &#8211; 2008</h5>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/cotojo.wordpress.com/82/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/cotojo.wordpress.com/82/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cotojo.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cotojo.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cotojo.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cotojo.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cotojo.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cotojo.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cotojo.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cotojo.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cotojo.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cotojo.wordpress.com/82/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cotojo.wordpress.com&blog=916283&post=82&subd=cotojo&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://cotojo.wordpress.com/2007/08/02/what-is-a-rootkit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ce1491f304c9e3cc8f602cf54771390b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cotojo</media:title>
		</media:content>

		<media:content url="http://static.technorati.com/pix/fave/tech-fav-1.png" medium="image">
			<media:title type="html">Add to Technorati Favorites</media:title>
		</media:content>

		<media:content url="http://www.mybloglog.com/buzz/images/buttons/btn_c21_l.png" medium="image">
			<media:title type="html">Join My Community at MyBloglog!</media:title>
		</media:content>

		<media:content url="http://us.i1.yimg.com/us.yimg.com/i/yg/img/i/uk/ui/join.gif" medium="image">
			<media:title type="html">Click here to join FreePCSecurity</media:title>
		</media:content>

		<media:content url="http://i198.photobucket.com/albums/aa306/cotojo/logo_header.png" medium="image">
			<media:title type="html">WOT Logo</media:title>
		</media:content>
	</item>
	</channel>
</rss>