Conceal other malware, notably password-stealing key loggers and computer viruses. Appropriate the compromised machine as a zombie computer for attacks on other computers. (The attack originates from the compromised system or network.) Discovering most rootkits is difficult because so much information about the attacks that led to their being installed is deleted or suppressed; considerable time, effort and technical expertise are required.

  1. As stated previously, if a rootkit has been installed in a compromised system, rebuilding the system is almost always the best course of action.
  2. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis.
  3. Rootkits allow someone, legitimate or otherwise, to administratively control a computer.
  4. Rootkits in particular now represent what might safely be called the ultimate malware threat.

Rootkits have two primary functions: remote command/control (back door) and software eavesdropping. This combined approach forces attackers to implement counterattack mechanisms, or "retro" routines, that attempt to terminate antivirus programs.

First, rootkit writers are aware that these tools must evade detection by anti-virus and anti-spyware software and thus include mechanisms within the rootkit code that they write that enable them to evade detection. Rootkits allow viruses and malware to "hide in plain sight" by disguising as necessary files that your antivirus software will overlook. According to McAfee, the use of stealth techniques in malware has increased by over 600 percent since 2004.

Rootkits allow viruses and malware to "hide in plain sight" by disguising as necessary files that your antivirus software will overlook.

A rootkit is a collection of tools (programs) that enable administrator-level access to a computer or computer network.

Activity on certain ports is another possible rootkit indicator.

