Rootkit Example


The kernel is the heart of an operating system; it provides fundamental services (e.g., input and output control) for every part of the operating system. Microsoft. 2007-02-21. But it's amazing technology that makes rootkits difficult to find. User-mode rootkits run on a computer with administrative privileges.

With a reasonably strong hashing algorithm, there is little chance that someone could make changes in the file without the hash for the changed file being different.

At the same time, however, this added firewall functionality has the potentially deleterious affect of harming network performance. Rootkits allow viruses and malware to "hide in plain sight" by disguising as necessary files that your antivirus software will overlook. This technology has elicited a great deal of apprehension, as virtual rootkits are almost invisible. The secure shell (SSH) program and the C library in Unix and Linux systems are two of the most common targets.

PatchGuard monitors the kernel and detects and stops attempts by code that is not part of the operating system to intercept and modify kernel code.