Rootkits are becoming harder to remove because they are residing deeper in the operating system
Rootkits are more stubborn and are penetrating at the kernel mode level

Rootkits getting more devious

Malware penetrating at the kernel mode level, warns Symantec 

Matt Chapman

Rootkit attacks are becoming harder to remove because they are "residing deeper in the operating system", an antivirus firm warned today.

"Rootkits are continuing to get more stubborn and are penetrating at the kernel mode level where previously they were attacking the user mode level," Ed Kim, director of product management at Symantec, told vnunet.com

Advertisement

Symantec's recent acquisition of VxMS technology from Veritas allowed it to add protection for rootkit attacks to its latest consumer security products, which are due out next month in the UK.

"The software compares files at the OS file system as well as at the NTFS and if we see a difference then we know there is something that is trying to serve itself," said Kim.

"We are able to make a copy of that rootkit, that driver, and once we have a copy it can be clearly identified by our antivirus engines."

Kim explained that once the file is identified it can be renamed so that any items trying to access it are "unstealthed" because they can no longer find that driver.

Symantec has also added phishing detection abilities to its security software and aims to take the practice further than consulting a blacklist of websites.

"Phishing is the number one problem today," Kim said. "Phishing websites come up and down within a few hours and the time it takes to develop a blacklist can be significant."

According to Kim, Symantec has added advanced heuristics technology from its acquisition of Whole Security to Norton Internet Security

"Whole Security had behavioural technologies and was the first to protect eBay users and TD Waterhouse and a number of different banks," said Kim.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Attacks designed to steal a company's entire email directory rose by 30 per cent in August

Email directory harvest attacks rise 30 per cent

Spammers starting early this year

The phishing threat against customers of Barclays Bank shows no sign of easing

No let up in Barclays phishing attacks

More than half of all scam emails targeting the bank

Two-thirds of phishing scams target single US bank

Fifth Third Bank heads August phishing list by a mile

Rootkit use continues to grow

Easier access to malicious technology prompts 600 per cent increase in attacks

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

NetGear ReadyNAS NVX

Review: NetGear ReadyNAS NVX

NetGear's four-bay compact network-attached storage gets a serious speed boost

AMD

AMD adds to six-core Opteron line up

New HE processors promise even lower power consumption

Adobe Systems

Adobe launches ColdFusion 9 and ColdFusion Builder

Firm promises enhanced developer productivity

Primary Navigation