« Home | Getting Started Guide to Internet Video » | Something Fun For All You Bubble Poppers » | Linux Graphics Goodness » | Fix Stuck LCD Panel Pixels (Maybe) » | The Uber List of Live Linux CD's » | The "Right" Way To Fix a Malware Infection Is To C... » | Microsoft is Giving Away Virtual Server » | How To Record CD Images (The Free Way) » | Free Password Manager » | Free TiVo For The Internet » 

Tuesday, July 18, 2006 

Get Ready For The New Nasty Round of Rootkits


I came across this article while reviewing some Digg posts. In a nutshell, it looks like some Russians have come up with a way to have their malware be even better at avoiding detection than the normal run-of-the-mill rootkits. Ths new one called Rustock is polymorphic, scans for installed rootkits detectors, and changes it behavior accordingly. F-secure has apparently developed a tool to detect this called Blacklight.

Another scanner worth of mention here is Rootkit Revealer by Sysinternals. Sysinternals provides an awesome site with a bunch of free tools for all you windows sysadmins. I highly recommend checking it out. FYI, these tools were developed by the guy (Mark Russinovich) that discovered Sony's rootkit. Here is Mark's blog post that started all of the hubbub.

Anyway, the battle between the white hats and the black hats continue...