Home > Ask the Information Security Experts > Questions & Answers > Have vendors secretly placed rootkits on USB thumb drives?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Have vendors secretly placed rootkits on USB thumb drives?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 October 2007
Sony allegedly is using rootkits on its USB thumb drives. Should I be concerned about rootkits on USB thumb drives, and how can I get rid of them?

>
EXPERT RESPONSE
Whenever you think you have a handle on your computer or network security, another unexpected threat pops up in the headlines. This time, it's rootkits. Not only do we have to worry about getting rootkits from malicious Web sites, emails, adware and spyware, but now a reputable vendor has also been found playing fast and loose with our own security. Yes, Sony, who two years ago was caught secretly installing rootkits from its DVDs (and was fined more than $1 million for the practice), has been caught again. This time, a rootkit has been found in Sony's Micro Vault USM-F fingerprint reader software .

The name "rootkit" comes from the ability of the program to obtain access to the core or "root" of a computer's operating system. Kit users receive unlimited administrative-level privileges, also known as "root privileges." A rootkit is a double-edged sword. As a security tool for system administrators, it's a key resource. It is typically used to hide files, network connections, memory addresses or registry entries from other programs. However, it's also a favorite tool for malicious hackers, who use it to collect an eye-popping assortment of information about a system, including users and passwords.

Since the program is hidden and runs secretly, victims don't necessarily know that they have been infected. Not to bring up the FUD (fear, uncertainty, doubt) monster, but rootkit use has become more popular among reputable companies. Regardless of the source though, if a rootkit is installed on your system, there is the potential for someone to copy or delete important data, install backdoors entry points or log keystrokes to get your passwords. The list of threats is nearly endless.

Fortunately, the AV/malware security vendors such as Symantec Corp., McAfee Inc., and FRISK Software International (F-PROT) have new products that will search a system for rootkits. In addition, Microsoft has a free tool called RootkitRevealer, used exclusively for finding and removing rootkits from a Windows system.

These rootkit removers work in a similar fashion to all common antivirus/malware scaners. First of all, the scanning program has a small database of known rootkit names. When the program scans a hard drive, it compares what it has found against the list. Secondly, the program contains some algorithms that check the behavior of suspect files. This mechanism tries to catch new rootkits that haven't been added to the database yet. In any case, all removal programs have an update capability that downloads the latest signature list.

Since rootkits are intended to work secretly and try to hide themselves, especially when they are actively running, it's best to quit all active programs prior to running a scan. A word of warning though: In no case should you simply delete files that you suspect of being rootkits. You may delete a file that is a necessary part of your system, or only partially delete the rootkit, leaving harmful files still in place. In either case, you may create more problems and cause headaches for your system. What is needed is a specialist rootkit detector. If you suspect you have a rootkit, try one of the various vendors' free rootkit-scanning tools.

More information:

  • Noah Schiffman reveals how some malware creators have shifted from traditional rootkits to stealthier bootkits.
  • See how well network behavior anomaly detection tools can find rootkits and other malware.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Threat Management
    Network security basics: How to prevent common attacks
    Future security threats: Enterprise attacks of 2009
    Cybercrime reports: Security not broken, but breaking at the seams
    Data losses set to soar, KPMG predicts
    Screencast: How to gather host-level data with Network Miner
    Appliance provides network access protection on school campus
    Market Harborough Building Society finds way to monitor users' network traffic
    'Phlashing' attacks
    How to identify network attacks proactively
    Stopping spam brings additional security benefits for cable company

    Enterprise Data Storage
    Local council finds better way to track lost laptops
    Will the rise of SharePoint services lead to increased data loss?
    Scottish NHS trust ensures no repeat of USB data loss
    Finance sector poor at achieving outsourcing success
    Mobile technology may limit harm of laptop data loss
    HSBC loses customer data in the post
    How to lock down USB devices
    Another day, another embarrassing data loss
    How to achieve laptop data security
    Chemical giant says data leakage tools not up to snuff

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
    Serious Organized Crime Agency  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts