ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

McAfee launches free anti-rootkit tool

Tom Espiner ZDNet.co.uk

Published: 27 Jul 2007 15:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security vendor McAfee has released a free anti-rootkit tool.

Rootkit Detective, which has been in beta since January, will "help computer users clean their machines of increasingly prevalent hidden malicious code known as rootkits," McAfee said in a statement. Rootkit Detective was launched on Thursday.

Cybercriminals use rootkits to hide malware on compromised PCs. The use of rootkits is increasing rapidly, with 3,284 last year increasing to 7,325 in the first half this year, said McAfee. Since the initial beta release of Rootkit Detective in January, the application has been downloaded over 110,000 times, said the company.

"Rootkit Detective offers the most comprehensive rootkit-detection capabilities available today," said Ahmed Sallam, lead research architect at McAfee. "We have achieved extremely high levels of accuracy, using various techniques to find anything that hides itself on a computer."

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

According to McAfee, malicious rootkits, which are often custom-built, are sold on the black market. The software is often used to hide a backdoor on a computer that lets hackers access systems stealthily. They are typically email-borne. Signs of a rootkit compromise include sudden slowdowns and suspicious network activity.

Rootkit Detective lets administrators examine operating systems, uncovering hidden processes, registry entries and files, and lets users remove or disable these files upon system reboot.

McAfee has a disclaimer on its download site saying the tool should only be used by "knowledgeable individuals" to prevent deletion of vital files. The tool can also scan the integrity of a PC's kernel memory and display any modification, which may also point to a system compromise.

McAfee uses samples submitted by users of the free tool to develop anti-rootkit signatures for its paid-for security products.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
23 out of 25 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment