Showing posts with label Heuristic. Show all posts
Showing posts with label Heuristic. Show all posts

Monday, September 03, 2007

What is a rootkit?

What is a rootkit?

A rootkit is not an exploit — it’s the code or program an attacker leaves behind after a successful exploit. The rootkit then allows the hacker to hide his or her activity on a computer, and it permits access to the computer in the future. To accomplish its goal, a rootkit will modify the execution flow of the operating system or manipulate the data set that the operating system relies on.

Windows operating systems support programs or processes running in two different modes: user mode and kernel mode. Traditional Windows rootkits such as SubSeven and NetBus operate in user mode.

Also known as backdoors or Trojans, user-mode rootkits run as a separate application or within an existing application. They have the same level of system privileges as any other application running on the compromised machine. Since these rootkits operate in user mode, applications such as antivirus scanners can detect the rootkit’s existence if they have a signature file.

A kernel-mode rootkit is remarkably different — and much more powerful and elusive. Kernel-mode rootkits have total control over the operating system and can corrupt the entire system.

By design, kernel-mode rootkits control the operating system’s Application Program Interface (API). The rootkit sits between the operating system and the user programs, choosing what those programs can see and do.

In addition, it uses this position to hide itself from detection. If an application such as an antivirus scanner tries to list the contents of a directory containing the rootkit’s files, the rootkit will suppress the filename from the list. It can also hide or control any process on the rooted system.

Rootkit detection

Methods to detect rootkits fall into two categories: Signature-based and heuristic/behavior-based detection.

Signature-based detection: As its name implies, this method scans the file system for a sequence of bytes that comprise a “fingerprint” that’s unique to a particular rootkit. However, the rootkit’s tendency to hide files by interrupting the execution path of the detection software can limit the success of signature-based detection.
Heuristic/behavioral-based detection: This method works by identifying deviations in normal operating system patterns or behaviors. For example, this method could detect a rootkit by determining that a system with 200-GB hard drive that reports 160 GB of files has only 15 GB of free space available.

Rootkits are hard to detect. But there are programs – including a free one from Grisoft which I have covered in another post.

Wednesday, July 04, 2007

SpywareGuard 2.2

A real-time protection solution against spyware!

SpywareGuard provides a real-time protection solution
against spyware that is a great addition to
SpywareBlaster’s protection method.

An anti-virus program scans files before you open them and
prevents execution if a virus is detected - SpywareGuard
does the same thing, but for spyware! And you can easily
have an anti-virus program running alongside SpywareGuard.

SpywareGuard now also features Download Protection and
Browser Hijacking Protection!

Features Listing:
Fast Real-Time Scanning engine - catch and block spyware
before it is executed (EXE and CAB files supported) with
signature-based scanning for known spyware and
heuristic/generic detection capabilities to catch
new/mutated spyware

Download Protection
Prevent spyware from being download in Internet Explorer

Browser Hijacking Protection
Stop browser hijacking activity in real-time

SG LiveUpdate
Provides an easy updating solution

Small size
With a small size and small definition sizes, download and
updates are quick

Report Capabilities
Keep a detailed log of all spyware detected

Spyware files are blocked before being opened or run -
they are not simply shut down after they are loaded in
memory (and after they have performed their tasks)

It’s a free download and is freeware

Get it here:
http://www.majorgeeks.com/download3045.html

SpywareGuard is compatible with: Windows 98, ME, 2000, XP