Slashdot Mirror


User: mdsc1

mdsc1's activity in the archive.

Stories
0
Comments
2
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2

  1. Re:Detect this.... on Windows Rootkit Wars Escalate · · Score: 1

    Thus why if you follow the directions with older versions of the program, you rename the .exe as well.

  2. Detect this.... on Windows Rootkit Wars Escalate · · Score: 3, Informative

    Did the writers of the rootkit consider that...

    "The reason that there is no longer a command-line version is that malware authors have started targetting RootkitRevealer's scan by using its executable name. We've therefore updated RootkitRevealer to execute its scan from a randomly named copy of itself that runs as a Windows service. This type of execution is not conducive to a command-line interface. Note that you can use command-line options to execute an automatic scan with results logged to a file, which is the equivalent of the command-line version's behavior." http://www.sysinternals.com/Utilities/RootkitRevea ler.html

    Ooops... 1 step ahead of the hackers yet again.