Hunting for Rootkits
Posted Mar 1, 2007 5:55 UTC (Thu) by drag
Parent article: Hunting for Rootkits
Not that I am a expert so take it for what it's worth...
It's also probably worth mentioning that these things are only usefull for _detecting_ rootkits.
Removing and disabling rootkits is another problem entirely.
In my opinion once you detect a rootkit, even if it's a stupid dinky one, that you should considure that paticular OS dead. It's not worth the time, effort, or uncertainty its going to take to clean that thing off.
Pull the plug on the computer (don't shutdown) take a image of the harddrive for safe keeping, format the drive and go on with your life.
to post comments)