morph3us.org

Entries tagged as malware

Quicksearch

Categories

Syndication

Blogroll

Tagged entries

Entries tagged as malware

Finding hidden drivers in Windoze NT

  (Monday, February 13. 2006)
Lately I had an idea to simply detect loaded kernel drivers which hide their presence after their execution. I'm sure this method is already known/used but because I never read of it I decided to write it down.

You have to reboot your box and start the system with enabled boot logging - hit F8 before Windoze boot screen and select the entry "Enable Boot Logging". Another possibilty to boot with enabled logging is to hand the /BOOTLOG option to the Windoze kernel as a parameter by editing the `boot.ini' file.

Continue reading this entry..
Comment (1) | Trackbacks (0)
(Page 1 of 1, totaling 1 entries)