Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Hacktool.WNT, Rootkit TROJ_ROOTKIT, WinNT.RootKit|
|Effects: ||It hides hacker activity on affected computers.|
|First detected on:||Aug. 23, 2003|
|Detection updated on:||Feb. 3, 2004|
NTRootkit is not a virus as such, but a tool used by hackers to hide their activity on affected computers from users.
After gaining remote access to a computer, the hacker installs this tool on the affected machine.
NTRootkit only works on machines with the operating systems Windows NT, 2000 or XP installed, as a service must be loaded for this program to run. The effects of NTRootkit vary, as there are different versions of this tool that carry out different actions.
It is difficult to recognize NTRootkit, as it does not display any warnings or messages that indicate that it has been installed on a computer.