answersLogoWhite

0


Best Answer

A rootkit is a type of malicious software (malware) designed to gain unauthorized access to a computer system or network and maintain privileged, undetected access to that system. The primary purpose of a rootkit is to enable attackers to control the compromised system while avoiding detection by security mechanisms and antivirus software.

Rootkits typically operate at a low level of the operating system, often directly interacting with the kernel or other core components, which gives them extensive control over the system's behavior. Here are some of the main purposes and functionalities of rootkits:

1. Stealth: Rootkits are designed to hide their presence and activities on the compromised system. They may employ techniques such as concealing files, processes, registry entries, and network connections from system administrators and security tools.

2. Privilege Escalation: Rootkits often exploit vulnerabilities in the operating system or software to gain escalated privileges, allowing them to perform actions that would otherwise be restricted to system administrators or root users.

3. Backdoor Access: Rootkits can create backdoors or remote access points on the compromised system, enabling attackers to remotely control the system, steal sensitive information, install additional malware, or use the system for malicious purposes.

4. Persistence: Rootkits aim to maintain long-term access to the compromised system by installing themselves persistently, even after system reboots or security measures are taken. They may modify system boot processes, system files, or registry settings to ensure their continued presence and functionality.

5. Data Theft and Surveillance: Some rootkits are designed to monitor user activities, capture sensitive information such as login credentials, banking details, or personal data, and send this information to remote servers controlled by attackers.

6. Distributed Denial of Service (DDoS) Attacks: Rootkits can be used as part of botnets—networks of compromised computers—to launch DDoS attacks against targeted websites, servers, or networks, causing disruption or downtime.

Overall, the purpose of a rootkit is to facilitate unauthorized access, control, and manipulation of computer systems for malicious intent. Detecting and removing rootkits can be challenging due to their sophisticated evasion techniques and deep integration into the compromised system. Regular security measures such as antivirus software, intrusion detection systems, and system hardening practices are essential for protecting against rootkit attacks.

User Avatar

Er Keshav Yadav

Lvl 5
1mo ago
This answer is:
User Avatar
More answers
User Avatar

Wiki User

11y ago

Hi,

A rootkit is some kind of a Trojan that gives a hacker/cracker the access to your computer without you knowing it. It can come in a zip file or while Surfing online. Once the rootkit is installed on your computer, it sends a message to the cracker that he/she can now access the host machine. Then the cracker can use that machine as if it was his own.

So why do crackers do it? Well, for starters the challenge is there. Being able to see someone else's computer/ files gives them some weird satisfaction. But more importantly they do it to acquire personal information about the host. (addresses, phone numbers, birthdays, email addresses, bank information etc.) Most of the time they sell this info to other parties that are willing to pay a lot of bucks for it. (although now we give it for free via websites like facebook, if you know what i mean:) ) Another reason is that since they are using someone else's computer, it gives them the freedom to do things that otherwise they would get into trouble with their own machines. (visiting child-porn, hacking websites or chatting/ cybersex with minors). I know people that got into trouble like that.

A rootkit is hard to detect by using conventional antivirus software. Google "anti rootkit software" and you'll run into a bunch of software out there. Run this software regularly on your machine and you should be fine.

This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: What is the purpose of rootkit?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Continue Learning about Computer Science

What programme would you use to gain administrative rights to someones computer?

bot executive android rootkit worm


What is a rootkit virus?

It is a virus that stops your computer at startup. They are very effective because you cant turn on your computer to get rid of it.


What is a backdoor and rootkit virus?

A hole in the security of a system deliberately left in place by designers or maintainers. The motivation for such holes is not always sinister


What should be found in the best internet security software?

The best internet security software should consist of these qualities: Protection for the user, Antivirus capabilities, Firewall, Rootkit capabilities, and it should be able to detect trojans.


What is Rootkits?

Hi, A rootkit is some kind of a Trojan that gives a hacker/cracker the access to your computer without you knowing it. It can come in a zip file or while surfing online. Once the rootkit is installed on your computer, it sends a message to the cracker that he/she can now access the host machine. Then the cracker can use that machine as if it was his own. So why do crackers do it? Well, for starters the challenge is there. Being able to see someone else's computer/ files gives them some weird satisfaction. But more importantly they do it to acquire personal information about the host. (addresses, phone numbers, birthdays, email addresses, bank information etc.) Most of the time they sell this info to other parties that are willing to pay a lot of bucks for it. (although now we give it for free via websites like facebook, if you know what i mean:) ) Another reason is that since they are using someone else's computer, it gives them the freedom to do things that otherwise they would get into trouble with their own machines. (visiting child-porn, hacking websites or chatting/ cybersex with minors). I know people that got into trouble like that. A rootkit is hard to detect by using conventional antivirus software. Google "anti rootkit software" and you'll run into a bunch of software out there. Run this software regularly on your machine and you should be fine.

Related questions

Name two anti-rootkit products?

Rootkit revealer and backlight.


What is a malicious program allows someone to take control of a computer?

Rootkit


Name two anti rootkit products?

rootkit revealer by sysinternals. Backlight by F-secure.


What is an anti-root software?

I believe you are referring to anti-rootkit software. Firstly, a rootkit is something that allows other threats (eg. viruses, spyware) to hide themselves. (Rootkits are often bundled with keyloggers or trojans.) Therefore, conventional anti-virus products cannot remove them because they are hidden. Anti-rootkit software is designed to remove the rootkit.


What programme would you use to gain administrative rights to someones computer?

bot executive android rootkit worm


What two methods does anti-rootkit software use to detect a rootkit?

The software looks for running processes that don't match up with the underlying program filename, and the software compares files, registry entries, and processes provided by the OS to the list it generates from the raw data. If the list differ, a rootkit is suspected.


What are the dangers of a rootkit?

Rootkit is a type of malware that hides its presence while it's active on a computer. Rookit hides other malware too. It can be extremely difficult to remove a rootkit from a computer. However, solid antivirus software usually removes rootkits without any problems. Source: http://deletemalware.blogspot.com


What are the names of some anti-rootkit products?

RootkitRevealer, BackLight


How does rootkit running in user mode normally hide?

A+ pg. 1052: A rootkit running in user mode intercepts the API calls between the time when the API retrieves the data and when it is displayed in a window.


Which type of malware should you ensure that the tool is capable of removing?

Rootkit


What virus software is in use within organization?

'''In fact, RootQuest 1.0.1 can help you. I'd like to give you a full introduction. Rootkits can be able hidden on computers and remain undetected by anti-virus software, RootQuest finds and removes any rootkit that is hidden on your computer using advanced rootkit detection systems. ''' RootQuest is a good solution to detection and remove all rootkit that currenlty running as background services on computer system. Designed for Windows 2000/XP/2003/Vista, the program will monitor system proccesses and remove all rootkit components quickly and securely. Not only is it a great tool for finding rootkits, it also can prevent the installation and infection of many rootkits. Features: * Real-time protection from hackers and crackers. * Auto detect rootkit processes. * Protected resources in the hard drive. * Finds and removes rootkit . * Prevents rootkit being installed. * Scan detection based signature . * Self-protection all rootkit attack Therefore, it is a virus software that can be used within organisation. Hope this help you! http://www.globalfreeware.com/RootQuest-101.html


How does a rootkit running in user mode normally hide?

A rootkit running in user mode intercepts the API calls between the time when the API retrieves the data and when it is displayed in a window. It can prevent Task Manager from displaying the running rootkit process, or might cause Task Manager to display a different name for this process. The program filename might not be displayed in Windows Explorer, the rootkit's registry keys might be hidden from the Registry Editor, or the Registry Editor might display incorrect information.