Slashdot Mirror


Windows Rootkit Wars Escalate

An anonymous reader writes "The rootkit wars have started to escalate with a rootkit named Rustock which is able to remain hidden from all the popular anti-rootkit tools. It uses some new techniques including not only putting itself in a ADS (NTFS alternate data stream) which isn't seen by normal file system enumeration tools, but even blocks ADS aware tools from seeing the stream. Works in Vista, too! Analysis in both Symantec and F-Secure blogs."

2 of 342 comments (clear)

  1. if only windows was closed source by Anonymous Coward · · Score: 5, Funny

    If only Windows was closed source, then writing such tools would be difficult. Oh, wait...

  2. Obligatory Star Wars reference by Shadowland · · Score: 5, Funny

    [Yoda]
    Begun, the Rootkit Wars have...
    [/Yoda]