New generation of rootkits now in the wild.

Discussion in 'Computer Security' started by ffreeloader, Jul 18, 2006.

  ffreeloader

    ffreeloader

    Some sites are calling this the "invisible" rootkit as it uses Alternate Data Streams (ADS) as one its techiniques of keeping itself hidden. ADS is a way of hiding files from the Windows interface. A file hidden in ADS will not show up in disk usage stats, Windows explorer, or from the cmd prompt. It takes special tools to find them.

    You can read the rest of the article on cio.com's CIO Tech Informer
  Bluerinse
    Honorary Member

    Bluerinse

    Interesting Freddy!

    For those that might want to read a bit more about NTFS ADS and how easy they are to create and manipulate, there is a good article here...

