Sub Main Menu
news
sport
lifestyle
entertainment
business
property
3:02AM Wednesday 15 October, 2008 Sunshine Coast weather Late thunder min 17° - max 26°
'Blogs Central
Blog Central: Technofile As president of the Sunshine Coast Computer Club for more than a decade, Peter Daley has answered more computing questions than he would care to remember. He also helps run a technology help line service called www.technologypals.com.au giving people help over the phone. .

What on earth is a rootkit?

October 18 | Peter Daley

Stop giggling! This blog has nothing to do with a kit to improve your sex life – in fact, it would probably have the opposite effect!

So what are rootkits? They are super stealth hacks that are hidden from most virus checkers and spyware detectors.

Trouble is, large numbers of computers using the Windows operating systems are being infected with rootkits. I do a lot of computer troubleshooting and repairs, and in the last few weeks I have been finding an increasing number of computers infected with them.

So you've been diligent, and kept your virus, spyware and firewall protections up to date, but one of the family has decided to use one of the music-sharing systems, or visited a site, and your computer has been hacked through your web browser.

Hidden inside your supposedly safe computer is a super stealth rootkit.

You can run your virus checker or spyware removal tools till the cows come home, but you won't find anything.

You need to run this special tool called rootkitrevealer which can be found here.

Most of you are going to find the information on the rootkitrevealer page gobbledegook. Read it if you feel you will understand some, or just cut to the chase and go to the bottom of the page and download the Rootkitrevealer.zip file.

It is a compress zip file, so save it onto your computer and unpack it. Then run the Rootkitrevealer.exe file on you computer.

If you have no understanding of the last two lines in the above paragraph, you're in over your head, and should immediately stop all internet banking on your home or work computers.

Change your banking password immediately and stick to phone banking or physically go to the bank. This type of basic security knowledge is essential to your banking and business security on the internet.

Most people's faith in computer security is unfounded, and based on poor information.

So, you run Rootkitrevealer on you computer (by the way, there are more steps involved to run rootkitrevealer on Vista at present), and you get discrepancy results. What do they mean?

The best I can tell you, in brief, is to look to the end of discrepancy lines, and you may need to widen the column to see them – items like SAC, SAI are normal, as are entries that may refer to your virus checker name (eg Symantecs, which is Norton's anitvir, or Nero, a CD burning program).

Most clean computers will only have a few normal discrepancies as described above. The more discrepancies, the more likely the breach to your computer security. Most people will not have a clue what are normal discrepancies and what are abnormal, but anything over about four or five is suspicious.

All I can say is take a deep breath, and read this free book on stress management.

If you find any rootkits, getting rid of them is another story. Have you got all afternoon?

I really feel that most of you out there should stop internet banking and use phone banking or go physically to the bank. I have been demonstrating the use of Rootkitrevealer to Sunshine Coast Computer Club members.

Recent Comments

on 24 October, 2007 at 4 p.m. ( Suggest removal )
When running Rootkitrevealer it is important to turn off your Antivirus software. Right click on antivirus product icon in the system tray, (bottom right hand corner of the open screen of your windows computer), and in the pop up that appears, select exit, or close. The antivirus program will restart the next time the computer is turned on.

Otherwise you may get a list of discrepancies that are created by the antivirus program scanning activities that are not rootkits.

Have your say

We welcome comments on our stories and blogs - after all it's your site. Please note comments are moderated, should be on-topic and not abusive