RegEdit
New Member
- Reaction score
- 3
- Location
- Pacific Palisades, CA
Can they avoid detection by AutoRuns? I usually look under start ups, pending processes, services, and image hijacks (as I recall) then delete suspicious ones, then hit "refresh" and see if they reappear. If they do then I know a rootkit is still present.You sure as hell won't see many rootkits in Process Explorer.
What folders are you checking in?1. To have a whitelist of known good system files, and
2. To check for Company information in the file.
Just the C:/Windows/System32/ folder?
And are you checking .exe files? .dll files? .sys files?
Do good system files ever get replaced by rootkit files, using the same name?
That white list must be a long one. I guess you note them from a clean install of XP, Vista, 7.
What does OTL stand for?try something like OTL
Last edited: