Intel Security releases detection tool for EFI rootkits

  • 10 March 2017
  • 3 replies
  • 58 views

Userlevel 3
Badge +3
Has Webroot found a way to check user's root kit for the latest CIA invasions?  Apparently there are ways to discover if they've infected a computer but I have no idea which programs are legit and which may not be.  Will it become part of an update soon?

3 replies

Userlevel 7
I would expect that this is known about and that the Threat Researchers have dealt with it/Webroot is on top of this.
 
But we can check by seeing if @ can advise on the subject. ;)
 
Regards, Baldrick
Userlevel 7
Badge +35
The rootkit detection in WSA should pick up on EFI rootkits just as it would a "traditional" rootkit. 
 
-Dan
Userlevel 3
Badge +3
Thanks for the replies.  I asked only because the articles I've read say that the root kits the CIA developed were designed to be undetected by tranditional anti-virus like Webroot.  Intel even created a program to uncover the issue only once it's installed and it uses the original white list from the computer manufacturer to compare.  That's kind of a specific fix, isn't it?  PCWorld lists how to check for infection and I'm wondering how Webroot will be able to accomplish it. 

Reply