Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Rootkit Detection Coming to Windows AntiSpyware

    By
    Ryan Naraine
    -
    July 18, 2005
    Share
    Facebook
    Twitter
    Linkedin

      Microsoft plans to integrate rootkit detection technology from its Strider Ghostbuster research project into future versions of the Windows AntiSpyware application, Ziff Davis Internet News has learned.

      Strider Ghostbuster, a prototype tool developed by Microsoft Corp.s Cybersecurity and Systems Management Research Group, provides a straightforward way to detect Windows rootkits by comparing scan results between a clean system and one that may potentially be compromised.

      Details of Microsofts plans remain scarce, but sources say the company has grown increasingly worried about the threat from stealth rootkits.

      The integration is unlikely to happen in time for the next Windows AntiSpyware beta refresh.

      Company officials declined to discuss specific plans going forward. “We have not made any public commitments to include functionality from that project in Microsoft products at this time,” a Microsoft spokesperson said.

      In a recent interview, Mike Nash, corporate vice president at Microsofts Security Business and Technology Unit, was asked if the company plans to include Strider Ghostbuster in Windows AntiSpyware.

      “We cant be specific about that,” Nash said, adding that Microsoft was adopting “a combination of cleaning and blocking” to combat spyware.

      “We need to understand that better,” Nash said.

      While acknowledging the importance of the threat of rootkits, Nash said Microsoft is currently focusing its anti-spyware beta on “bots.”

      On the Strider Ghostbuster Web page, the company has said the tool will be released either as a research prototype or as part of Microsoft products.

      /zimages/3/28571.gifTo read more about how spyware is adopting rootkit technology, click here.

      Word of Microsofts plans comes at a time when security researchers are discovering rootkit-like features in common spyware programs.

      By using rootkit techniques, sophisticated spyware coders are able to gain administrative access to compromised machines to run stealthy updates to the software or reinstall spyware programs after a user deletes them.

      Using a rootkit, a malicious hacker can also perform system scans and modify data without any user interaction.

      Microsoft has already added rootkit-detection to its free malicious software removal tool.

      /zimages/3/28571.gifRead more here about Microsofts rootkit-hunting malware remover.

      The malware remover is capable of detecting four child variants of Hacker Defender (Win32/Hackdef), one of the more notorious rootkit programs.

      According to definitions posted by Computer Associates International Inc., Hacker Defender is a Trojan creation tool that can be used to wrap existing Trojans to make them harder to detect. It can also hide proxy services and back-door functionality, and conceal use of TCP and UDP (User Datagram Protocol) ports for receiving commands from attackers.

      Microsoft isnt the only software vendor targeting rootkits. Finnish anti-virus specialist F-Secure Corp. recently released its BlackLight Rootkit Elimination Technology, while Sysinternals Freeware, a site that offers Windows utilities, also offers RootkitRevealer, a tool capable of finding registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.

      Microsoft Watchs Mary Jo Foley contributed to this report.

      /zimages/3/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Ryan Naraine
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×