: Does anyone have any ideas about how to detect an NT rootkit without
: professional-level tools in the field? Assume,hypothetically that you
: have no net access, a CD and possibly infected machine.
:
: What do you do?
:
A rootkit checker will be a good start. There's a free one here, along with some possibly intresting links.
http://www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml
Jonathan
###
for(74,117,115,116){$::a.=chr};(($_.='qwertyui')&&
(tr/yuiqwert/her anot/))for($::b);for($::c){$_.=$^X;
/(p.{2}l)/;$_=$1}$::b=~/(..)$/;print("$::a$::b $::c hack$1.");